Privacy Policy

How Meristem Securities Limited and its licensed subsidiaries collect, use, protect, and share your personal data.

Last Update At: 18 August, 2026

Your privacy matters to us. This Privacy Policy explains how Meristem Securities Limited and its licensed subsidiaries (together referred to as “the Meristem Group”, “we”, “us”, or “our”) collect, use, protect, and share your personal data when you use our digital platforms (website and mobile app), or any of our products and services. We are committed to handling your information responsibly, transparently, and in accordance with applicable data protection laws. This means we only collect the information we need, use it for clear and lawful purposes, keep it secure, and give you control over how it is used.

This Policy applies to all personal data processed across our digital platforms and in the course of providing our services. We process your personal data in accordance with the Nigeria Data Protection Act 2023 (NDPA) and other applicable laws. Please note that the NDPA may be amended, updated, or replaced from time to time. We will ensure that our privacy practices continue to comply with the current legal requirements. This Privacy Policy supplements and should be read alongside our General Terms and Conditions of Use.

We encourage you to read this Policy carefully, so you understand how your personal data is handled and the choices available to you. If you have any questions, our Data Protection Officer [insert email] is available to assist you.

1.Scope

This Policy applies to:

  • All individuals who access or use the Platform, whether as registered Users or visitors.
  • All individuals whose Personal Data is provided to us by corporate clients, including directors, officers, beneficial owners, authorised signatories, and counterparties.
  • Prospective clients and enquirers who contact us through the Platform or otherwise, and
  • Beneficiaries and estate stakeholders in connection with Trust services.

This Policy does not apply to data processed by third-party websites or applications that may be linked to or integrated with the Platform. Please review the privacy policies of those third parties separately.

Because we operate as a group, your personal data may be shared within the Meristem Group where necessary to provide integrated services, manage risk, and meet regulatory obligations. Each subsidiary processes personal data in accordance with applicable law and this Privacy Policy.

2.Data Controller and Data Protection Officer

2.1 Data Controller: The Group and its relevant licensed subsidiaries act as Data Controllers in respect of Personal Data collected and processed through the Platform. For the avoidance of doubt, the specific Data Controller in respect of data processed for a particular Service is the subsidiary licensed to provide that Service, and the Group acts as the overarching Data Controller for Platform-level data processing activities.

2.2 Data Protection Officer: In compliance with Article 32 of the NDPA, the Group has appointed a Data Protection Officer (DPO) responsible for overseeing data protection strategy, ensuring compliance with the NDPA and related regulations and guidelines, serving as the primary point of contact with the NDPC, and handling Data Subject inquiries and complaints.

3.Definitions

In this Privacy Policy, the following terms shall have the meanings set out below. Capitalised terms not defined here bear the meanings given to them in our General Terms and Conditions of Use.

Consent
means a freely given, specific, informed, and unambiguous indication of your wishes, given by a clear affirmative action, signifying agreement to the processing of Personal Data relating to you.
Data Controller
means Meristem Securities Limited and/or the relevant licensed subsidiary that determines the purposes and means of processing your Personal Data.
Data Processor
means any person or entity that processes Personal Data on behalf of the Data Controller under a binding data processing agreement.
Data Subject
means the identified or identifiable natural person to whom Personal Data relates.
NDPA
means the Nigeria Data Protection Act 2023, as amended or replaced from time to time.
NDPC
means the Nigeria Data Protection Commission established under the NDPA.
Personal Data
means any information relating to an identified or identifiable natural person, including name, identification number, location data, online identifier, or factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.
Processing
means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction.
Sensitive Personal Data
means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, data concerning sex life or sexual orientation, or data relating to criminal convictions and offences.
DPO
means the Data Protection Officer appointed by the Group in accordance with the NDPA.

4.Personal Data We Collect

4.1 Data You Provide Directly

When you register for an account, apply for services, or interact with any of our digital platforms, we collect personal data that you provide, including:

  • Identity and contact data: full legal name, date of birth, gender, nationality, residential address, email address, telephone number(s) and employment information.
  • Identity verification and KYC data: government-issued identification documents (National Identity Card, International Passport, Driver's Licence), Bank Verification Number (BVN), National Identification Number (NIN), and Tax Identification Number (TIN)
  • Financial data: bank account details, investment holdings, income information, source of wealth declarations, Investment preferences and risk profile and transaction history.
  • AML/CFT compliance data: Politically Exposed Person (PEP) status, beneficial ownership information and sanctions screening declarations.
  • Account and Beneficiary information: next of kin and beneficiary details;
  • Corporate data (for corporate accounts): company name, registration number, Memorandum and Articles of Association, board resolutions, and identification of directors and beneficial owners.
  • Communications data: Correspondence and communications between you and the Group, whether by email, in-app messaging, telephone, or written correspondence, Call recordings (where calls are recorded for quality assurance, regulatory compliance, or dispute resolution purposes, with appropriate notice to callers), Chat transcripts from the Platform's support features; and Feedback, survey responses, enquiries and complaints submitted to us.
  • Trust and Estate Data: For Users engaging Trust Services, we additionally collect: Information about beneficiaries, settlors, testators, and estate stakeholders, Details of assets, properties, and financial interests forming part of a trust or estate, Will documents, trust deeds, letters of administration, and court orders, Family relationship information; and Succession and estate planning instructions.
  • Service preferences and account settings: notification preferences, information contained in forms, correspondence and investment mandates, and platform configurations.
  • Sensitive Personal Data: We may, in limited circumstances, process the following categories of Sensitive Personal Data:
    1. Biometric data (fingerprints or facial recognition data) for identity verification and platform authentication. However, we do not store biometric data.
    2. Health data, to the extent voluntarily disclosed in connection with estate planning, will drafting, or related services.
    3. Data relating to criminal convictions and offences, in connection with AML/CFT due diligence and sanctions screening; and
    4. Politically Exposed Person (PEP) status, which may reveal political opinions or affiliations.

4.2 Data Collected Automatically

When you use any of our digital platforms, the following technical and usage data is collected automatically:

  • Browser and device data: IP address, browser type and version, operating system, device model and network type
  • Usage data: pages accessed, features used, session duration, navigation/click patterns, search queries, crash reports and error logs.
  • Authentication data: login timestamps, session identifiers, and records of failed authentication attempts
  • Approximate location data: geographic location at the country or city level, derived from your IP address for security and fraud detection purposes (no GPS data is collected through the Website)
  • Cookie and tracking data: cookie identifiers, session storage data, and analytics interaction data as described in our Cookies Policy.
  • Biometric authentication data (for mobile app): our app receives only a pass/fail response from your device's biometric system. No biometric templates, fingerprint images, or facial geometry data are transmitted to or stored by us.

4.3 Data Received from Third Parties

We may receive personal data about you from the following external sources:

  • Licensed credit reference bureaus in connection with credit assessments
  • Sanctions screening databases and PEP monitoring services
  • Other licensed financial institutions and financial intermediaries, including fund managers, investment houses, finance companies, and other capital market operators, in connection with inter-institutional transactions, portfolio transfers, securities settlement, co-investment arrangements, or other operational and regulatory interfaces between regulated entities.
  • Introducers, brokers, and professional advisers acting on your behalf with your authority.
  • Employers or referees (where required)
  • Regulators and public registries including the Corporate Affairs Commission (CAC), land registries, the Securities and Exchange Commission (SEC) and Central Bank of Nigeria (CBN).
  • Identity verification providers
  • Payment processors and settlement systems

We only collect information that is relevant and necessary for the services you request.

5.How and Why We Use Your Personal Data

5.1 Purposes and Legal Basis

We process your personal data strictly for defined, explicit, and legitimate purposes, and only where a valid lawful basis exists under the NDPA and other applicable laws.

Depending on the nature of our relationship with you and the context of the processing activity, our legal bases may include:

  • Performance of a contract – where processing is necessary to enter into, administer, or perform our contractual obligations to you, or to take steps at your request prior to entering into a contract.
  • Compliance with legal obligations – where we are required to process or disclose personal data to satisfy statutory, regulatory, supervisory, or court-mandated requirements.
  • Legitimate interests – where processing is necessary for our legitimate business interests (or those of a third party), provided such interests are not overridden by your fundamental rights and freedoms. This may include risk management, fraud prevention, internal administration, security monitoring, and service improvement. Where we rely on legitimate interests as our legal basis, we have carried out a legitimate interest assessment to ensure our interests do not override your rights and freedoms.
  • Consent – where required by law or where no other lawful basis applies, in which case you retain the right to withdraw your consent at any time, subject to legal or contractual limitations.
  • Vital interests or public interests – where processing is necessary to protect life, ensure public safety, or perform a task carried out in the public interest or in the exercise of official authority, as permitted by law.

Our primary processing activities and their legal bases are set out below.

Purpose of ProcessingLegal Basis of Processing
Identity verification, KYC onboarding, and ongoing customer due diligenceLegal obligation
Account creation, management, and authenticationContract
Delivery of all financial servicesContract; Legal obligation
Processing and settling financial transactionsContract
Credit assessment and risk evaluation for lending productsContract; Legitimate interests
Fraud prevention, AML/CFT transaction monitoring, and securityLegal obligation; Legitimate interests
Mandatory regulatory reporting (NFIU, SEC, CBN, FIRS, CAC, others)Legal obligation
Sanctions screening, PEP monitoring, and watchlist checksLegal obligation
Sharing data with licensed credit bureaus in connection with credit productsLegal obligation (CBN guidelines); Legitimate interests
Service-related communications, transaction alerts, and account notificationsContract; Legal obligation
Customer support and formal complaint handlingContract
Marketing our services to existing clientsLegitimate interests
Marketing our services to prospective clientsConsent
Product personalisation and suitability profiling for investment servicesContract; Legitimate interests
Cookie-based analytics and Website personalisationConsent
IP-based approximate location for fraud detectionLegitimate interests
Automated decision-making (credit scoring, fraud detection)Contract; Legal obligation; Legitimate interests
Audit, legal proceedings, and regulatory defenceLegal obligation; Legitimate interests

5.1.1 Consent Withdrawal: Where processing is based on your consent, you have the right to withdraw that consent at any time by contacting the DPO or through the Platform's privacy settings. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal. Please note that withdrawal of consent for certain types of processing (e.g., processing necessary for regulatory compliance) may affect our ability to provide Services to you.

5.1.2 Sensitive Personal Data: For sensitive personal data, we only process where:

  1. You have given your explicit consent, where required and where such consent is valid under the NDPA.
  2. Processing is required to comply with a legal obligation to which we are subject.
  3. Processing is necessary for the establishment, exercise, or defence of legal claims; or
  4. Processing is carried out in the course of our legitimate AML/CFT, fraud prevention, and regulatory compliance activities as authorised under applicable law.

We ensure that each processing activity is assessed against the appropriate lawful basis prior to collection or use, and that the chosen basis is documented, proportionate, and consistent with the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, and accountability under the NDPA.

5.2 Regulatory Reporting Obligations

As a regulated financial services group, we are required by Nigerian law to collect, use, retain, and in some cases disclose certain personal data. These obligations are part of the legal framework designed to keep the financial system safe, transparent, and secure.

What this means for you is that we may process information such as your identification details, contact information, transaction records, financial information, and beneficial ownership details in order to meet regulatory and reporting requirements, prevent fraud, money laundering, and other financial crimes, comply with tax and corporate governance rules; and support supervisory oversight by relevant authorities.

Where the law requires it, we may share relevant information with regulatory, supervisory, or law enforcement authorities without seeking your prior consent. We only do this when we are legally obligated to.

We limit such processing to what is strictly necessary and apply appropriate technical and organisational safeguards to protect your data from unauthorised access, misuse, or alteration. We also retain your information only for as long as required by applicable legal and regulatory record-keeping rules.

5.3 Credit Bureau Sharing

If you apply for a credit facility or lending product, we are required to share certain credit information about you with licensed credit reference bureaus in Nigeria, in accordance with regulatory guidelines issued by the Central Bank of Nigeria. This may include your identification details, information from your credit application, facility terms, outstanding balances, repayment history, and any missed or late payments.

Credit reference bureaus may make such information available to other authorized financial institutions and eligible credit providers for the purpose of assessing your creditworthiness, verifying information provided in future applications, preventing fraud, and meeting regulatory compliance obligations.

We share only information that is necessary, ensure it is accurate and up to date, and transmit it securely in line with data protection standards. You have the right to request a copy of your credit report directly from the relevant credit bureau and to dispute any incorrect information through their established correction process.

5.4 Marketing Communications

We may process your personal data to provide you with information about our products, services, promotions, and events that may be relevant to your interests.

If you are already a client, we may contact you about services that are similar or related to those you currently use. We do this to keep you informed about updates, improvements, or additional offerings that may benefit you.

If you are a prospective client, or if we wish to contact you about new types of products or through new marketing channels, we will first ask for your consent where required by law.

You are always in control of your marketing preferences. You can opt out of receiving marketing communications at any time by updating your preferences in your account settings, clicking the unsubscribe link in any marketing message, or contacting our Data Protection Officer.

If you choose to opt out of marketing messages, you will still receive important service-related communications necessary to manage your account or fulfil our contractual obligations to you.

6.Website Specific Data Practices

6.1 Cookies and Tracking Technologies

We use cookies to make your experience on our website smoother and more convenient. If you create an account with us, cookies help manage the signup process, keep your session active while you're logged in, and support general account administration. This ensures the Website works properly and your interactions are seamless. Further details can be found in our Cookies Policy.

6.2 Approximate Location Data

When you use our website, we automatically detect your approximate location (country or city) from your IP address. We do not collect precise GPS data or track your exact movements.

We use this information only to keep your account and our systems secure, such as spotting unusual logins, preventing fraud, and protecting against unauthorized access. This helps us maintain a safe and reliable service for you.

Your approximate location is not used for advertising, profiling, or detailed tracking, and we keep it only as long as needed for security and compliance purposes.

7.Device Permissions and App Specific Practices

Our mobile app (App) requests access to certain device features and data to deliver its services. The permissions we may request, and the purposes for which they are used, are as follows:

  • Camera: required for document capture (KYC document upload) and QR code scanning. Accessed only when you actively use the relevant feature.
  • Location Services: optional; used for fraud detection and verification of transaction origin. Precise location collected only during active use unless you grant 'always on' permission.
  • Contacts: optional; used to suggest transfer beneficiaries from your contact list. Contact data is not stored on our servers without your explicit consent.
  • Device Storage: required for saving downloaded statements and transaction confirmations.
  • Notifications: required to deliver push notifications. Can be revoked at any time through device settings.

You may manage individual App permissions at any time through your device's settings application. Revoking a required permission may make the corresponding App feature unavailable. Our App permissions data practices comply with the data minimisation principle under the NDPA.

8.Who We Share Your Personal Data With

We only share your personal data when it is necessary to provide services, comply with the law, or meet legitimate business needs. We never sell, rent, or trade your information. We may share your data with:

  • Subsidiaries and Affiliates within the Meristem Group: To provide integrated services, manage risk, and meet legal obligations.
  • Regulators and authorities: When required by law for reporting, supervision, tax compliance, or fraud prevention.
  • Licensed credit reference bureaus: To support facility applications, assess repayment history, and evaluate creditworthiness.
  • Approved service providers: Such as cloud providers, payment processors, document management services, cybersecurity and fraud detection vendors, and customer support platforms. These providers process your data securely and only on our instructions.
  • Professional advisers: Lawyers, auditors, or consultants who are bound by confidentiality obligations.
  • Courts and law enforcement: When required by a court order, subpoena, or lawful directive.
  • Successors: In case of a merger, acquisition, or asset sale, under strict confidentiality safeguards.

In all cases, we limit data sharing to what is necessary and ensure appropriate safeguards are in place to protect your information.

9.International Transfers

We primarily process your personal data in Nigeria. However, certain services, including foreign currency investments, international custodial arrangements, cloud hosting, or cross-border transactions, may require your data to be transferred outside Nigeria.

Where this happens, we comply with the NDPA by ensuring appropriate safeguards are in place, such as approved contractual protections or transfers to countries recognised as providing adequate protection.

You may contact our Data Protection Officer for more information about these safeguards.

10.How Long We Retain Your Data

We keep your personal data only for as long as it is needed to provide our services, manage your account, fulfil our legal obligations, resolve disputes, prevent fraud, and protect our legitimate business interests.

The length of time we retain data depends on the type of information, the services you use, and the requirements of law and regulation. For example, some records may be kept longer to comply with tax, accounting, anti-money laundering, or audit obligations.

When your personal data is no longer needed, we securely delete, anonymise, or archive it, and take steps to protect it from unauthorized access or misuse.

11.How We Protect Your Personal Data

We take your privacy and security seriously. We use a range of technical and organisational measures to keep your personal data safe, including secure servers, encryption, access controls, staff confidentiality obligations and regular system monitoring.

Only authorised staff and trusted service providers can access your information, and they are required to handle it securely and confidentially. For sensitive personal data, additional safeguards including strict access controls and enhanced encryption are applied.

While no system can be completely risk-free, we take every reasonable step to protect your personal data from unauthorized access, loss, or misuse, so you can use our services with confidence. At the same time, you are responsible for keeping your device, the App, and your login credentials secure.

12.Your Rights Under This Policy

You have control over your personal data and can exercise rights under the NDPA and applicable laws. These include the right to:

  • Access your data: Request a copy of the personal data we hold about you.
  • Correct inaccuracies: Ask us to update or correct any incorrect or incomplete information.
  • Delete your data: Request deletion of your personal data, where allowed by law or contractual obligations.
  • Restrict processing: Ask us to limit how we use your personal data in certain situations.
  • Object to processing: Object to certain types of processing, including marketing communications.
  • Withdraw consent: Where processing is based on your consent, you can withdraw it at any time provided that withdrawing your consent shall not affect any processing we carried out lawfully before your withdrawal.
  • Data portability: Request that your personal data be transferred to another service provider, where applicable.

Except in scenarios where automated decision making is permissible as provided under the NDPA, you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similar significant effects concerning you. However, where we use automated systems to make decisions or assess information about you, such as evaluating credit applications, detecting potential fraud, or tailoring services and recommendations based on your usage patterns, or for profiling to understand your preferences, improve our services, or manage risk, we do not make important decisions about you solely by automated means without human oversight, unless required by law.

To exercise any of the rights listed here, you can contact our Data Protection Officer using the details provided in Section 2.2. We will respond promptly and in line with applicable laws.

13.Children's Data

Our products and services are primarily designed for adults. However, in certain circumstances, we may collect and process the Personal Data of minors (individuals under the age of 18) where a parent or legal guardian is operating a financial account or purchasing a financial product for the benefit of the minor (e.g., a minor's stockbroking account, trust account, fund management account).

In such cases:

  • The parent or legal guardian acts as the data controller for the minor's information and provides the necessary consent on behalf of the minor.
  • We will only collect the minor's information that is strictly necessary to establish and maintain the account or product, such as the minor's name, date of birth, and other details required to verify the minor's identity in compliance with Know Your Customer (KYC) regulations.
  • The minor's data will be used solely for administering the specific account or product and for complying with applicable legal and regulatory requirements (e.g., anti-money laundering checks, tax reporting). It will not be used for unrelated marketing purposes without separate, explicit consent from the parent or guardian.

By providing a minor's information to us, you confirm that you are the parent or legal guardian of that minor and have the legal authority to consent to the collection and processing of the minor's Personal Data for the specified purpose.

If you are a parent or guardian and you have questions about how your child's information is being processed, please contact our Data Protection Officer using the details in Section 2.2.

14.Remedies

Where you have concerns relating to how we process your personal information, or require any clarification on this policy, please notify us through our Data Protection Officer. We will respond to your concerns within 30 days of receiving your notice.

You also have a right to lodge a complaint directly with the supervisory authority, Nigeria Data Protection Commission (NDPC) where you suspect any misconduct or violations of the rights listed in this policy. Email: info@ndpc.gov.ng.

15.Updates to this Policy

We may update this Privacy Policy from time to time to reflect changes in our services, technology, or legal obligations. When we make significant changes, we will notify you through our digital platforms so you are aware of updates that may affect how your personal data is handled. By continuing to use our digital platforms after updates are published, you acknowledge that you have read the revised Privacy Policy and accept its terms. We encourage you to review this Privacy Policy periodically to stay informed about how we protect and use your information.