Privacy Policy

Privacy Policy

Last Updated: 4 July 2023

DATA PROTECTION AND PRIVACY STATEMENT FOR PAYTRO.CO

GLOSSARY

A. LAWFUL BASIS

 

“Comply with a legal or regulatory obligation” means processing your personal data where it is necessary for compliance with a legal or regulatory obligation that we are subject to.

 

“Consent” means any freely given, specific, informed, and unambiguous indication of your wishes by which you, through a statement or a clear affirmative action, signify agreement to the processing of your Personal Data.

 

“Performance of Contract” means processing your data where it is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into such a contract.

 

“Supplier” means a person or organization that produces or manufactures goods or materials that are then sold to our Users.

 

“User” means a person who is accessing, browsing, or interacting with our website.

 

 

  1. Who are we?

Paytro.co (“we”, “us” and “our”) is a trusted and user-friendly e-commerce vendor for electronics and other good. We believe that technology enhances our lives, making it more convenient, connected, and enjoyable. That’s why we carefully curate a wide range of electronics, from smartphones and laptops to smart home devices and accessories, to bring you the latest innovations from top brands you know and love. Our services are provided through our website. 

Paytro.co is committed to and respects each user’s right to privacy. This Policy explains what we do with your personal data, whether we are in the process of introducing ourselves to you, recommending or advertising our products. 

This Privacy Policy applies to the personal data of our Website Users, Suppliers, and other people whom we will contact in order to find out more about the quality of our services or whom they indicate is a reference or contact in accordance with the National Information Technology Development Agency Act 2007 (the “Act”) and the Nigeria Data Protection Regulation (NDPR) 2019 (the “Regulation”) as amended or updated from time to time, in Nigeria.

For the purpose of the NDPR and this policy, we are the ‘data controller’. This means that we are responsible for deciding how we hold and use personal data about you. However, depending on the relevant transaction, we may act as the “data administrator/processor”. We are required under the NDPR to notify you of the information contained in this privacy policy. The policy document is available on our website https://paytro.co/. If you have any questions about this privacy policy, you can contact us in the following ways:

Email address: contact@paytro.co. (or you can contact our Data Protection Contact by emailing info@nitda.com.ng

Address: 1625B Saka Jojo Street, off Idejo Victoria Island, Lagos.

Telephone number: 08185692626

You have the right to make a complaint at any time to the National Information Technology Development Agency (NITDA) or Nigeria Data Protection Bureau (NDPB) Office, the Nigerian supervisory authority for data protection issues. We would, however, appreciate the chance to address your concerns before you approach the agencies, so please contact us in the first instance.

  1. Information we may collect

We may collect and process the following data about you:

  1. Where you are a User, we collect the information necessary to be able to process payments or refunds, make delivery of purchased goods and perform other lawful acts. This information may include your name private and corporate email address, postal address and telephone number; financial information; payment history and identity documentation.

 

  1. Where you are a Supplier, we collect the following types of data (collectively Supplier Data):
    • Identity Data and Contact Data of Supplier personnel;
    • Supplier bank account details; and
    • details about payments to Suppliers and other details of goods and/or services provided to us by Suppliers.

 

  1. Technical Data includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access our Website.
  2. Marketing and Communications Data includes your preferences in receiving marketing from us and our third parties and your communication preferences.

Where we need to collect personal data by law, or under the terms of a contract we have with you and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with our services). In this case, we may have to cancel a service you have with us, but we will notify you if this is the case at the time. 

  1. How is your personal data collected?

We collect your personal data either from you or third parties through:

  1. Direct interactions: You may give us your Identity and Contact Data by filling in forms or by corresponding with us by post, phone, email, or otherwise. This includes personal data you provide when you:
    • apply for our services;
    • create an account on our website;
    • request notifications and adverts to be sent to you; or –       give us some feedback.
  2. Our provision of services to you. We may collect Identity Data, Contact Data from you as a result of our providing our services to you.
  3. Automated technologies or interactions. As you interact with our website, we may automatically collect Technical Data about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs, and other similar technologies. We may also collect User Data and Supplier Data from you (as applicable) through our use of software and other technological solutions which we use to provide services to our Users.

 

        4.How we use the information

We may use your information in the following way and in consideration of the applicable legal basis under the NDPR which we rely on to use your information:

  1. User Data: The main reason for using your personal details is to enable us to provide the services requested via our website. The more information we have about you and, your preference, the more bespoke we can make our services to suite you. Where appropriate and in accordance with local laws and requirements, we will also use your personal data for things like marketing our services to you. Where appropriate, we will seek your consent to undertake some of these activities. The lawful basis for this is the Performance of a contract with you.
  2. Supplier data: To register you as a new Supplier, placing orders for and subsequently receiving goods and/or services from you. The lawful basis for this is the Performance of a contract with you.
  3. To deliver relevant Website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you.
  4. We use your data to help us to improve your experience of using our website or our mobile apps, for example by analyzing your recent product search criteria to help us to present similar or closely related products to you that we think you’ll be interested in. In addition, we use your data to provide you with the service you registered for or the services you participated in, for example sending you a newsletter or taking part in an online survey.

We may anonymize your personal information in such a way that you may not reasonably be re-identified by us or any other company. We may use this anonymized information for any other purpose.

        5. Promotional offers from us

We may use your Identity, Contact, User, Technical, Usage, and Profile Data to form a view of what we think you may want or need, or what may be of interest to you. This is how we decide which products, services, and offers may be relevant for you.

You will receive marketing communications from us if you have requested information from us or purchased services from us and, in each case, you have not opted out of receiving that marketing. You can ask us to stop sending you marketing messages at any time by contacting us at any time. 

Where you opt out of receiving these marketing messages, this will not apply to personal data provided to us because of a service purchase, service experience, or other transactions. 

 

        6.   Change of Purpose

We will only use your personal data for the purposes for which we collected it unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us. 

If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so. 

Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.

        7.   Disclosure of Data

We only share and disclose your information in the following situations

  1. for the purposes set out in the table in paragraph 4 above.
  2. Compliance with Laws: We may disclose your information where we are legally required to do so in order to comply with applicable law, governmental requests, a judicial proceeding, court order, or legal process, such as in response to a court order or a subpoena (including in response to public authorities to meet national security or law enforcement requirements).
  3. Vital interests and Legal Rights: We may disclose your information where we believe it is necessary to investigate, prevent, or take action regarding potential violations of our policies, suspected fraud, situations involving potential threats to the safety of any person, and illegal activities, or as evidence in litigation in which we are involved.
  4. We may disclose your information to third-party service providers to ensure the effective provision of our services to you. All of our third-party service providers are required to take commercially reasonable and appropriate security measures to protect your personal data. We only permit our third-party service providers to process your personal data for specified purposes and in accordance with our instructions.
  5. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.

With your consent, we may disclose your personal information for any other purpose.

 

        8.How long will we retain your data

All personal information shall be retained, stored, and destroyed by us in line with legislative and regulatory guidelines. We only retain your information for as long as is necessary for us to use your information as described above or to comply with our legal obligations. However, please be advised that we may retain some of your information after you cease to use our services, for instance, if this is necessary to meet our legal obligations, such as retaining the information for tax and accounting purposes.

When determining the relevant retention periods, we will take into account factors including: our contractual obligations and rights in relation to the information involved;

  1. legal obligation(s) under applicable law to retain data for a certain period of time;
  2. statute of limitations under applicable law(s);
  3. (potential) disputes;
  4. if you have made a request to have your information deleted; and
  5. guidelines issued by relevant data protection authorities.

Otherwise, we securely erase your information once this is no longer needed.

        9.Security and Storage of your data

Safeguarding personal data and respecting the confidentiality of your information is important to us. All information you provide to us is stored securely and we take necessary steps, including putting in place appropriate technical and organizational measures to protect your personal data. While we have security measures in place to protect against the loss, misuse, and alteration of personal data under our control we cannot guarantee that loss, misuse, or alteration of personal data will not occur. We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so. 

10.Using our Electronic Channels

Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorized access. Our websites may include links to external websites operated by other organizations which may collect personal data about you when you visit them. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for the privacy practices of any third-party websites. Please check these policies before you submit any personal data to these websites.

11.International data transfers

Information that we collect may be stored, processed, and transferred between any of the countries in which we operate in order to enable us to use the information in accordance with this policy. Any such information transferred to other countries shall be in compliance with the relevant laws as highlighted above.

  1. What rights do you have in relation to the data we hold on you?

By law, you have several rights when it comes to your personal data. This is briefly described below, you may refer to the appropriate laws, regulations, or regulators for further guidance. Please note that these rights are applied in accordance with the appropriate legal basis.

It is important that the personal data we hold about you is accurate and current. Should your personal information change, please notify us of any changes of which we need to be made aware by contacting us, using the contact details provided.

Rights

What they mean

The right to be informed

You have the right to be provided with clear, transparent and easily understandable information about how we use your information and your rights. This is why we’re providing you with the information in this Policy.

The right of access

You have the right to obtain access to your information (if we’re processing it), and certain other information (similar to that provided in this Privacy Policy). This is so you’re aware and can check that we’re using your information in accordance with data protection law.

The right to rectification

You may be entitled to have your information corrected if it’s inaccurate or incomplete.

The      right    to             restrict processing

When processing is restricted, we can still store your information, but may not use it further. We keep lists of people who have asked for further use of their information to be ‘blocked’ to make sure the restriction is respected in future.

The right to data portability

You have rights to obtain and reuse your personal data for your own purposes across different services. 

The right to object to processing

You have the right to object to certain types of processing, including processing for direct marketing or if you no longer want to be contacted with potential opportunities. Kindly reach out to us via the contact details provided at the top of this policy if you wish to exercise this right.

The      right    to             withdraw consent

If you have given your consent to anything we do with your personal data, you have the right to withdraw your consent at any time (although if you do so, it does not mean that anything we have done with your personal data with your consent up to that point is unlawful). This includes your right to withdraw any consent to us using your personal data for marketing purposes. 

 

We usually act on requests and provide information free of charge, but may charge a reasonable fee to cover our administrative costs of providing the information for:

  • baseless or excessive/repeated requests, or
  • further copies of the same information.

Alternatively, we may be entitled to refuse to act on the request. Please consider your request responsibly before submitting it. We’ll respond as soon as we can. Generally, this will be within thirty (30) days from when we receive your request but, if the request is going to take longer to deal with, we’ll come back to you and let you know.

 

13. Changes to This Privacy Policy 

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and making it available at our offices. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective as of the date it is made public.

Main Menu