Legal
Data Protection
Our obligations under the Nigeria Data Protection Act 2023, your rights in practice, and the honest limits of what we can undo.
1. Our commitment
Bolar handles money and identity for people whose daily income depends on both. We treat that as a serious responsibility rather than a compliance exercise.
This page sets out how we meet the Nigeria Data Protection Act 2023 ("NDPA") and its subsidiary legislation, and how to hold us to it. It sits alongside our Privacy Policy, which describes what we collect and why.
2. Controller or processor
Which role we play depends on the information:
- We are the controller for collector accounts, identity verification, payout instructions, website enquiries and newsletter subscriptions. We decide why and how that information is used.
- We are a processor for information an operator holds about their own business and staff, and which they instruct us to handle on their behalf. In that case the operator is the controller and their own privacy notice applies.
Where an operator and Bolar jointly determine how collector information is used, we allocate responsibilities in a written agreement, and you may exercise your rights against either of us.
3. The principles we work to
The NDPA requires personal information to be handled lawfully and fairly; collected for specified purposes; adequate and not excessive; accurate and kept up to date; kept no longer than necessary; and held securely. In practice that means:
- We ask for the minimum needed to pay someone and prove a collection happened.
- We do not repurpose collection data for anything we have not told you about.
- We let people correct their own details rather than making them ask.
- We delete what we no longer need, on a schedule, rather than keeping it indefinitely by default.
4. Your rights, and how to use them
Every right below is free to exercise. We respond within one month, and will tell you if a complex request needs longer.
| Right | What it means | How to use it |
|---|---|---|
| Be informed | Know what we hold and why | Read the Privacy Policy, or ask us |
| Access | Get a copy of your information | In-app, or ask the DPO |
| Rectification | Correct anything wrong | Edit in-app, or ask the DPO |
| Erasure | Have information deleted | Ask the DPO — see section 5 for limits |
| Restriction | Pause a use while a dispute is resolved | Ask the DPO |
| Object | Stop a use based on legitimate interests | Ask the DPO |
| Portability | Receive your data in a reusable format | Ask the DPO |
| Withdraw consent | Stop anything you consented to | Unsubscribe link, or ask the DPO |
| Automated decisions | Ask for a human review | Ask the DPO |
We may need to confirm your identity first, so that nobody else can obtain your information by pretending to be you.
5. Permanent records and the right to erasure
This is the part most policies would bury. We would rather you knew before you signed up.
Bolar writes every collection to a permanent, independently verifiable record. That is deliberate: it is what turns a collector's work into proof that cannot be taken away, and what makes an operator's carbon credits trustworthy to a buyer. The same property means those entries cannot be edited or deleted by anyone, including us.
So a request to erase everything cannot be honoured in full. What we can do:
- Delete your account and profile — name, phone number, payout destination, language and support history, subject to the retention periods the law imposes on financial records.
- Sever the link between you and the permanent collection entries, so what remains records that a collection happened, not who made it.
- Stop all further processing — no more messages, no further use of your information.
What remains is a record of material, weight, location, time and amount. We design those entries to avoid carrying identifying information for exactly this reason. have counsel confirm this analysis against the final architecture
The NDPA also permits us to retain information where we must keep it to meet a legal obligation or to establish or defend a legal claim.
6. Retention schedule
| What | Kept for | Why |
|---|---|---|
| Collector and operator account details | While active, then period | Disputes and support |
| Payment and transaction records | per Nigerian financial and tax law | Legal obligation |
| Identity verification records | per payment regulation | Legal obligation |
| Permanent collection entries | Indefinitely, by design | Proof of work and credit verification — see section 5 |
| Website enquiries and demo requests | period | Answering you |
| Newsletter subscription | Until you unsubscribe | Consent |
| Access and security logs | period | Security and fraud investigation |
7. Security measures
- Encryption in transit and at rest.
- Role-based access, granted on need and reviewed regularly.
- Logging of administrative access to personal information.
- Separation of payout authority from ordinary account access.
- Automatic retry and refund of failed payout instructions, so money is never left in limbo.
- Supplier contracts requiring equivalent protection.
- Staff training before access is granted.
8. If something goes wrong
We maintain an incident procedure. Where a personal data breach is likely to result in a risk to people's rights and freedoms we notify the Nigeria Data Protection Commission within 72 hours of becoming aware of it. Where the risk is high, we tell the affected people directly, in plain language, and say what they should do.
We keep a record of every breach, including ones we decide are not notifiable, and why.
9. Processors and sub-processors
We use other companies to run parts of the service — payment partners, identity verification, hosting and infrastructure. Each is bound by a written contract requiring them to act only on our instructions, protect the information, and delete or return it when the work ends.
A current list of sub-processors is available on request. The two that handle information submitted through this website are:
- Vercel Inc. — hosting and delivery of this website.
- Web3Forms — relays the demo request, collection-point waitlist, contact and newsletter forms to our inbox. It receives whatever you type into those forms.
add payment, identity-verification and infrastructure sub-processors, and confirm the hosting jurisdiction of each
10. Cross-border transfers
Bolar is built for Nigeria and we keep personal information in Nigeria wherever we can. Some infrastructure providers operate outside it.
Where personal information leaves Nigeria we rely on one of the NDPA's permitted grounds — an adequacy determination by the NDPC, contractual safeguards providing an equivalent level of protection, or your explicit consent — and we record which applies. list destination countries and the ground relied on — note that the website host (Vercel) and the website form relay (Web3Forms) both process outside Nigeria, so both belong in this list
11. Impact assessments and by-design
We carry out a data protection impact assessment before launching anything that is likely to carry high risk — new identity verification, new payment rails, or any new use of collection data.
New features start from the least information that will do the job. That is why a carbon credit buyer receives evidence about collections rather than about collectors, and why milestone badges record achievement rather than identity.
12. Data Protection Officer and complaints
We have appointed a Data Protection Officer responsible for overseeing this framework and answering your questions.
- Name: add DPO name
- Email: add DPO email
- Post: Bolar Technologies, add registered address, Lagos, Nigeria
If we have not resolved your concern, you may complain to the Nigeria Data Protection Commission, which supervises compliance with the NDPA and can investigate and impose sanctions. Complaining to us first usually gets a faster result, but it is not a precondition.