Your privacy matters to us. This Privacy Policy explains how Meristem Securities Limited and its licensed subsidiaries (together referred to as “the Meristem Group”, “we”, “us”, or “our”) collect, use, protect, and share your personal data when you use our digital platforms (website and mobile app), or any of our products and services. We are committed to handling your information responsibly, transparently, and in accordance with applicable data protection laws. This means we only collect the information we need, use it for clear and lawful purposes, keep it secure, and give you control over how it is used.
This Policy applies to all personal data processed across our digital platforms and in the course of providing our services. We process your personal data in accordance with the Nigeria Data Protection Act 2023 (NDPA) and other applicable laws. Please note that the NDPA may be amended, updated, or replaced from time to time. We will ensure that our privacy practices continue to comply with the current legal requirements. This Privacy Policy supplements and should be read alongside our General Terms and Conditions of Use.
We encourage you to read this Policy carefully, so you understand how your personal data is handled and the choices available to you. If you have any questions, our Data Protection Officer [insert email] is available to assist you.
This Policy applies to:
This Policy does not apply to data processed by third-party websites or applications that may be linked to or integrated with the Platform. Please review the privacy policies of those third parties separately.
Because we operate as a group, your personal data may be shared within the Meristem Group where necessary to provide integrated services, manage risk, and meet regulatory obligations. Each subsidiary processes personal data in accordance with applicable law and this Privacy Policy.
2.1 Data Controller: The Group and its relevant licensed subsidiaries act as Data Controllers in respect of Personal Data collected and processed through the Platform. For the avoidance of doubt, the specific Data Controller in respect of data processed for a particular Service is the subsidiary licensed to provide that Service, and the Group acts as the overarching Data Controller for Platform-level data processing activities.
2.2 Data Protection Officer: In compliance with Article 32 of the NDPA, the Group has appointed a Data Protection Officer (DPO) responsible for overseeing data protection strategy, ensuring compliance with the NDPA and related regulations and guidelines, serving as the primary point of contact with the NDPC, and handling Data Subject inquiries and complaints.
In this Privacy Policy, the following terms shall have the meanings set out below. Capitalised terms not defined here bear the meanings given to them in our General Terms and Conditions of Use.
When you register for an account, apply for services, or interact with any of our digital platforms, we collect personal data that you provide, including:
When you use any of our digital platforms, the following technical and usage data is collected automatically:
We may receive personal data about you from the following external sources:
We only collect information that is relevant and necessary for the services you request.
We process your personal data strictly for defined, explicit, and legitimate purposes, and only where a valid lawful basis exists under the NDPA and other applicable laws.
Depending on the nature of our relationship with you and the context of the processing activity, our legal bases may include:
Our primary processing activities and their legal bases are set out below.
| Purpose of Processing | Legal Basis of Processing |
|---|---|
| Identity verification, KYC onboarding, and ongoing customer due diligence | Legal obligation |
| Account creation, management, and authentication | Contract |
| Delivery of all financial services | Contract; Legal obligation |
| Processing and settling financial transactions | Contract |
| Credit assessment and risk evaluation for lending products | Contract; Legitimate interests |
| Fraud prevention, AML/CFT transaction monitoring, and security | Legal obligation; Legitimate interests |
| Mandatory regulatory reporting (NFIU, SEC, CBN, FIRS, CAC, others) | Legal obligation |
| Sanctions screening, PEP monitoring, and watchlist checks | Legal obligation |
| Sharing data with licensed credit bureaus in connection with credit products | Legal obligation (CBN guidelines); Legitimate interests |
| Service-related communications, transaction alerts, and account notifications | Contract; Legal obligation |
| Customer support and formal complaint handling | Contract |
| Marketing our services to existing clients | Legitimate interests |
| Marketing our services to prospective clients | Consent |
| Product personalisation and suitability profiling for investment services | Contract; Legitimate interests |
| Cookie-based analytics and Website personalisation | Consent |
| IP-based approximate location for fraud detection | Legitimate interests |
| Automated decision-making (credit scoring, fraud detection) | Contract; Legal obligation; Legitimate interests |
| Audit, legal proceedings, and regulatory defence | Legal obligation; Legitimate interests |
5.1.1 Consent Withdrawal: Where processing is based on your consent, you have the right to withdraw that consent at any time by contacting the DPO or through the Platform's privacy settings. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal. Please note that withdrawal of consent for certain types of processing (e.g., processing necessary for regulatory compliance) may affect our ability to provide Services to you.
5.1.2 Sensitive Personal Data: For sensitive personal data, we only process where:
We ensure that each processing activity is assessed against the appropriate lawful basis prior to collection or use, and that the chosen basis is documented, proportionate, and consistent with the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, and accountability under the NDPA.
As a regulated financial services group, we are required by Nigerian law to collect, use, retain, and in some cases disclose certain personal data. These obligations are part of the legal framework designed to keep the financial system safe, transparent, and secure.
What this means for you is that we may process information such as your identification details, contact information, transaction records, financial information, and beneficial ownership details in order to meet regulatory and reporting requirements, prevent fraud, money laundering, and other financial crimes, comply with tax and corporate governance rules; and support supervisory oversight by relevant authorities.
Where the law requires it, we may share relevant information with regulatory, supervisory, or law enforcement authorities without seeking your prior consent. We only do this when we are legally obligated to.
We limit such processing to what is strictly necessary and apply appropriate technical and organisational safeguards to protect your data from unauthorised access, misuse, or alteration. We also retain your information only for as long as required by applicable legal and regulatory record-keeping rules.
If you apply for a credit facility or lending product, we are required to share certain credit information about you with licensed credit reference bureaus in Nigeria, in accordance with regulatory guidelines issued by the Central Bank of Nigeria. This may include your identification details, information from your credit application, facility terms, outstanding balances, repayment history, and any missed or late payments.
Credit reference bureaus may make such information available to other authorized financial institutions and eligible credit providers for the purpose of assessing your creditworthiness, verifying information provided in future applications, preventing fraud, and meeting regulatory compliance obligations.
We share only information that is necessary, ensure it is accurate and up to date, and transmit it securely in line with data protection standards. You have the right to request a copy of your credit report directly from the relevant credit bureau and to dispute any incorrect information through their established correction process.
We may process your personal data to provide you with information about our products, services, promotions, and events that may be relevant to your interests.
If you are already a client, we may contact you about services that are similar or related to those you currently use. We do this to keep you informed about updates, improvements, or additional offerings that may benefit you.
If you are a prospective client, or if we wish to contact you about new types of products or through new marketing channels, we will first ask for your consent where required by law.
You are always in control of your marketing preferences. You can opt out of receiving marketing communications at any time by updating your preferences in your account settings, clicking the unsubscribe link in any marketing message, or contacting our Data Protection Officer.
If you choose to opt out of marketing messages, you will still receive important service-related communications necessary to manage your account or fulfil our contractual obligations to you.
We use cookies to make your experience on our website smoother and more convenient. If you create an account with us, cookies help manage the signup process, keep your session active while you're logged in, and support general account administration. This ensures the Website works properly and your interactions are seamless. Further details can be found in our Cookies Policy.
When you use our website, we automatically detect your approximate location (country or city) from your IP address. We do not collect precise GPS data or track your exact movements.
We use this information only to keep your account and our systems secure, such as spotting unusual logins, preventing fraud, and protecting against unauthorized access. This helps us maintain a safe and reliable service for you.
Your approximate location is not used for advertising, profiling, or detailed tracking, and we keep it only as long as needed for security and compliance purposes.
Our mobile app (App) requests access to certain device features and data to deliver its services. The permissions we may request, and the purposes for which they are used, are as follows:
You may manage individual App permissions at any time through your device's settings application. Revoking a required permission may make the corresponding App feature unavailable. Our App permissions data practices comply with the data minimisation principle under the NDPA.
We primarily process your personal data in Nigeria. However, certain services, including foreign currency investments, international custodial arrangements, cloud hosting, or cross-border transactions, may require your data to be transferred outside Nigeria.
Where this happens, we comply with the NDPA by ensuring appropriate safeguards are in place, such as approved contractual protections or transfers to countries recognised as providing adequate protection.
You may contact our Data Protection Officer for more information about these safeguards.
We keep your personal data only for as long as it is needed to provide our services, manage your account, fulfil our legal obligations, resolve disputes, prevent fraud, and protect our legitimate business interests.
The length of time we retain data depends on the type of information, the services you use, and the requirements of law and regulation. For example, some records may be kept longer to comply with tax, accounting, anti-money laundering, or audit obligations.
When your personal data is no longer needed, we securely delete, anonymise, or archive it, and take steps to protect it from unauthorized access or misuse.
We take your privacy and security seriously. We use a range of technical and organisational measures to keep your personal data safe, including secure servers, encryption, access controls, staff confidentiality obligations and regular system monitoring.
Only authorised staff and trusted service providers can access your information, and they are required to handle it securely and confidentially. For sensitive personal data, additional safeguards including strict access controls and enhanced encryption are applied.
While no system can be completely risk-free, we take every reasonable step to protect your personal data from unauthorized access, loss, or misuse, so you can use our services with confidence. At the same time, you are responsible for keeping your device, the App, and your login credentials secure.
You have control over your personal data and can exercise rights under the NDPA and applicable laws. These include the right to:
Except in scenarios where automated decision making is permissible as provided under the NDPA, you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similar significant effects concerning you. However, where we use automated systems to make decisions or assess information about you, such as evaluating credit applications, detecting potential fraud, or tailoring services and recommendations based on your usage patterns, or for profiling to understand your preferences, improve our services, or manage risk, we do not make important decisions about you solely by automated means without human oversight, unless required by law.
To exercise any of the rights listed here, you can contact our Data Protection Officer using the details provided in Section 2.2. We will respond promptly and in line with applicable laws.
Our products and services are primarily designed for adults. However, in certain circumstances, we may collect and process the Personal Data of minors (individuals under the age of 18) where a parent or legal guardian is operating a financial account or purchasing a financial product for the benefit of the minor (e.g., a minor's stockbroking account, trust account, fund management account).
In such cases:
By providing a minor's information to us, you confirm that you are the parent or legal guardian of that minor and have the legal authority to consent to the collection and processing of the minor's Personal Data for the specified purpose.
If you are a parent or guardian and you have questions about how your child's information is being processed, please contact our Data Protection Officer using the details in Section 2.2.
Where you have concerns relating to how we process your personal information, or require any clarification on this policy, please notify us through our Data Protection Officer. We will respond to your concerns within 30 days of receiving your notice.
You also have a right to lodge a complaint directly with the supervisory authority, Nigeria Data Protection Commission (NDPC) where you suspect any misconduct or violations of the rights listed in this policy. Email: info@ndpc.gov.ng.
We may update this Privacy Policy from time to time to reflect changes in our services, technology, or legal obligations. When we make significant changes, we will notify you through our digital platforms so you are aware of updates that may affect how your personal data is handled. By continuing to use our digital platforms after updates are published, you acknowledge that you have read the revised Privacy Policy and accept its terms. We encourage you to review this Privacy Policy periodically to stay informed about how we protect and use your information.