Home Legal Privacy Policy
CBN · 9PSB · NDPR Compliant

Your data.
Your control.

Effective: 1 March 2026
~22 min read
Applies to all users nationwide

The short version: We collect the data we need to run a payments product. We never sell your data. Your biometrics never leave your device. You can request, correct, or delete your data at any time. We comply with CBN, 9PSB, and all major privacy regulations. Read on for the full picture.

Version 3.1
March 2026
Your rights at a glance
Right to Access
Right to Correct
Right to Erase
Right to Portability
Right to Object
Data Minimisation
Last updated: 14th March 2026 — Version 3.1 supersedes all prior versions
Section 01

Who We Are & This Policy

This Privacy Policy is issued by Pressend Solutions Inc., a Nigerian corporation ("Pressend", "we", "our", "us"). We operate the Pressend payment platform, mobile applications, merchant services, and all associated digital products.

This Policy explains how we collect, use, store, share, and protect personal data when you use our Services. It applies to all users — consumers, merchants, beneficiaries, and job applicants — globally. Where region-specific laws (CBN, NDPR) impose additional obligations, we describe those in dedicated sections.

Our Data Protection Officer (DPO) can be reached at dpo@pressend.xyz. Our national representative address is Pressend Solution., Flat 1, Udeh Philip, Along Tina Nweze Street, Abakaliki

Section 02

What We Collect

We collect only the data necessary to operate a secure payment service. Here is a full account of the categories we collect and why.

Data You Provide Directly
Data CategoryExamplesWhy Collected
Identity DataFull name, date of birth, national ID numberKYC / legal compliance
Contact DataEmail address, phone number, home addressAccount management, comms
Financial DataBank account details, card numbers (tokenised), transaction historyPayment processing
Authentication DataHashed PINs, session tokens (never plaintext passwords)Account security
Profile DataDisplay name, profile photo, preferencesPersonalisation
Communication DataSupport messages, dispute descriptions, feedbackCustomer support
Data Collected Automatically
Data CategoryExamplesWhy Collected
Device DataDevice model, OS version, unique device ID, hardware identifiersSecurity, fraud detection
Usage DataFeature interactions, screens visited, tap patternsProduct improvement
Location DataGPS (when Panic Mode enabled or WalkOut active), approximate region otherwiseSafety, store matching
Network DataIP address, connection type, carrier informationFraud detection, security
Transaction MetadataTimestamps, terminal IDs, NFC session tokens, transfer reference numbersProcessing, dispute resolution
What We Do Not Collect

We do not collect raw biometric data from our servers (see Section 3). We do not collect your social media profiles unless you connect them. We do not purchase third-party data about you. We do not track your behaviour on other apps or websites via advertising SDKs.

Section 03

Biometric Data

Pressend handles Biometric Data with exceptional care. This section explains exactly how Face Pay, Palm Pay, and fingerprint data are handled. These practices comply with the Illinois Biometric Information Privacy Act (BIPA), GDPR Article 9, and all applicable biometric data regulations.

Your Face /
Palm
Your
Device Only
Secure
Enclave
Match Score
Only → Server
  • Biometric templates (face geometry maps, palm vein hashes) are generated and stored exclusively on your enrolled device within the hardware-secured enclave (Apple Secure Enclave or Android StrongBox).
  • Pressend's servers never receive, store, or process raw biometric data. What is transmitted is a one-time encrypted match confirmation that cannot be reverse-engineered into biometric information.
  • Biometric data is automatically purged from your device if you disable the feature, delete the app, or factory-reset your device.
  • You can withdraw biometric consent at any time by removing your biometric enrolment in Pressend Settings. This does not affect prior authorised transactions.
  • We will never sell, license, profit from, or disclose your biometric data to any third party for any commercial purpose.
  • Biometric data is not included in data portability exports because it does not reside on our servers.
Section 04

How We Use Your Data

We use the data we collect for the following specific purposes. We do not use your data for purposes beyond those listed without obtaining fresh consent or establishing a new legal basis.

PurposeData UsedLegal Basis
Processing payments and transfersFinancial, identity, device dataContract performance
Identity verification (KYC)Identity, contact dataLegal obligation
Fraud detection and preventionTransaction, network, device dataLegitimate interests
Panic Mode alerts and GPS sharingLocation, contact listVital interests / consent
WalkOut basket trackingIn-store video (anonymised), item dataContract performance
Posthumous fund disbursementBeneficiary data, account balanceConsent / contract
Customer supportCommunication, transaction historyContract performance
Product improvementUsage data (aggregated, anonymised)Legitimate interests
Legal and regulatory complianceIdentity, financial dataLegal obligation
Marketing communicationsContact, preference dataConsent (opt-in only)
No Selling. Ever.

Pressend does not sell personal data to advertisers, data brokers, or any third party. We do not use your payment behaviour to build advertising profiles. Our business model is built on service fees — not your data.

Section 05

Legal Basis for Processing

Under 9PSB and equivalent frameworks, we process personal data only where we have a valid legal basis. The bases we rely upon are:

  • Contract Performance: Processing necessary to provide the payment services you've signed up for. Without this, we cannot operate your account.
  • Legal Obligation: AML/KYC checks, transaction record-keeping for tax authorities, responding to lawful government requests.
  • Legitimate Interests: Fraud detection, security monitoring, product analytics (where your interests do not override ours). We document and regularly review these assessments.
  • Consent: Marketing communications, biometric enrolment, Panic Mode location sharing with emergency contacts, and Posthumous Configuration. You may withdraw consent at any time without affecting prior processing.
  • Vital Interests: Sharing location data with emergency services during an active Panic Mode alert where life may be at risk.
Section 06

Sharing Your Data

We do not sell your data. We share it only with the following categories of recipients, and only to the extent necessary:

  • Payment processors and banking partners — to complete the financial transactions you initiate (e.g. card network operators, correspondent banks). These entities are bound by PCI-DSS and equivalent standards.
  • Identity verification providers — KYC and AML screening partners who verify your identity during onboarding. Data shared is limited to what is legally required.
  • Cloud infrastructure providers — AWS and GCP host Pressend's backend infrastructure. Both operate under binding data processing agreements with appropriate security certifications.
  • Fraud and security vendors — risk scoring services that help us detect unusual transaction patterns. These vendors process anonymised or pseudonymised data.
  • Emergency contacts (Panic Mode) — only the contacts you personally designate, only when Panic Mode is activated by you.
  • Law enforcement and regulators — where required by law, valid court order, or where we believe disclosure is necessary to prevent imminent harm.
  • Beneficiaries (Posthumous Config) — only after the inactivity threshold is reached and beneficiary identity is verified.
What We Will Never Do

We will never share your data with advertisers, data brokers, or third-party marketers. We will never disclose data to governments without a valid legal instrument except to prevent imminent risk to life. We will always notify you of disclosures where legally permitted to do so.

Section 07

Data Transfers

Pressend operates nationwide. Your personal data may be transferred to and processed in states outside your home jurisdiction, including the United States, the United Kingdom, the European Union, and Singapore. We ensure such transfers comply with applicable law through the following mechanisms:

Section 08

Data Retention

We retain your data only for as long as necessary for the purpose it was collected, or as required by law. Below are our standard retention periods:

Account & identity data
Duration of account + 7 years
AML / legal obligation
Transaction records
7 years from transaction
Tax / regulatory
Biometric templates
Device only — deleted on removal
On-device only
Support communications
3 years from last contact
Dispute resolution
WalkOut session footage
72 hours
Dispute window only
Usage / analytics data
13 months (aggregated indefinitely)
Product development
Posthumous Config data
Until disbursement + 10 years
Legal / beneficiary
Fraud investigation data
10 years from case close
Legal proceedings

Upon account deletion, we anonymise or delete personal data within 30 days, except where retention is required by law or is necessary for pending dispute resolution.

Section 09

Security

We apply financial-grade security practices to protect your data. Our measures include:

  • AES-256 encryption at rest for all personal data stored on our servers.
  • TLS 1.3 for all data in transit between your device and Pressend infrastructure.
  • Hardware Security Modules (HSMs) for cryptographic key management.
  • Zero-trust network architecture — no internal service trusts another without explicit authentication.
  • Annual third-party penetration tests and SOC 2 Type II audit.
  • PCI-DSS Level 1 certification for payment card data environments.
  • Bug bounty programme at security@Pressend.xyz — responsible disclosure rewarded.

In the event of a personal data breach affecting your rights and freedoms, we will notify you within 72 hours of becoming aware of the breach, as required by GDPR Article 33.

Section 11

Children's Privacy

Pressend is not directed to or intended for use by anyone under the age of 18. We do not knowingly collect personal data from children. If you believe a child under 18 has created a Pressend account, please contact us immediately at legal@Pressend.xyz and we will investigate and delete the account promptly.

Section 12

Exercising Your Rights

You have the following rights over your personal data. Most can be exercised directly from the Pressend app under Settings → Privacy. For requests not supported in-app, contact our DPO at dpo@Pressend.xyz. We will respond within 30 days (GDPR) or 45 days (CCPA).

Access Your Data
Request a full export of all personal data Pressend holds about you, in a machine-readable format.
Settings → Privacy → Export Data
Correct Your Data
Update or correct inaccurate personal data held by Pressend through your account settings.
Settings → Account → Edit
Erase Your Data
Request deletion of your account and personal data, subject to legal retention obligations.
Settings → Account → Delete Account
Withdraw Consent
Withdraw consent for any optional processing — marketing, analytics, biometrics — at any time.
Settings → Privacy → Consent
Data Portability
Receive your data in a structured, machine-readable format for transfer to another service.
Email dpo@Pressend.xyz
Lodge a Complaint
If you're unhappy with how we've handled your data, you can escalate to your local data protection authority.
Email dpo@Pressend.xyz first
Section 15

Changes to This Policy

We review this Privacy Policy at least annually and whenever there are material changes to our data practices, applicable law, or our products. When we make material changes, we will notify you by email and in-app at least 30 days before changes take effect. For significant changes to how we handle Biometric Data, we will request fresh explicit consent.

The date at the top of this page reflects when the policy was last updated. Previous versions are available on request from dpo@Pressend.xyz.

Section 16

Contact Our DPO

For any privacy question, data rights request, or concern about how we handle your personal data, contact our Data Protection Officer:

DPO Emaildpo@Pressend.xyz
Privacy Emailprivacy@Pressend.xyz
Postal AddressData Protection Officer, Pressend Solutions., Flat 1, Udeh Philip - Tina Nweze street, Abakaliki
Bug/Security Reportssecurity@Pressend.xyz

Questions about your privacy?

Our DPO responds to all enquiries personally within 2 business days. No bots, no form letters.