Privacy Policy
How we collect, use, share and protect your information.
This Privacy Policy explains how Deela Digital Services Limited, trading as Deela, collects, uses, discloses, stores and protects personal data when you visit deelapay.com, join our waitlist, contact us, download or use the Deela application, create or participate in a deel, communicate with another user, submit identity information or otherwise use our services.
This Policy is intended to comply with the Nigeria Data Protection Act 2023 (the “NDPA”), the Nigeria Data Protection Act - General Application and Implementation Directive 2025 (the “GAID”), and other applicable Nigerian privacy and data-protection requirements.
1. Who we are
Deela Digital Services Limited (RC 9654122), trading as “Deela” (“Deela”, “we”, “us” or “our”), operates a digital platform that helps buyers and sellers agree transaction terms, pay through licensed financial-service partners, communicate, provide evidence, and release or refund funds according to agreed conditions and applicable dispute rules.
For the processing described in this Policy, Deela is generally the data controller. A bank, payment service bank, payment processor, identity-verification provider or other regulated provider may also act as an independent controller for processing it is legally required to determine itself. Its own privacy notice will apply to that processing.
Registered office and place of business: 5B Johnson Street, Ilupeju, Lagos, Nigeria.
Privacy and data-subject requests: privacy@deelapay.com
Data Protection Officer contact: privacy@deelapay.com
General enquiries: hello@deelapay.com
2. Scope
This Policy applies to personal data processed through:
- deelapay.com and any Deela webpage that links to this Policy;
- the Deela mobile application and future versions of it;
- account registration, identity verification, payment, payout and deal-management functions;
- in-app chat, customer support, complaints, disputes and investigations;
- waitlists, product updates and marketing communications; and
- interactions with our authorised staff, contractors and service providers.
It does not govern a third party’s independent processing where that third party provides its own privacy notice.
3. Personal data we collect
Depending on how you use Deela, we may process the following categories.
3.1 Information you provide
- Account and contact data: full name, phone number, email address, username, account preferences and communication choices.
- Identity and KYC data: date of birth, residential address, Bank Verification Number (BVN), National Identification Number (NIN), government-issued identity document, proof of address, photograph and verification results. Where biometric data is required, it will be processed only on an applicable lawful basis and with any additional safeguards required by law.
- Financial and transaction data: bank name, account number, verified account name, virtual-account details, payment references, deal value, fees, payout details, refunds, chargebacks and transaction history. Deela does not intend to store complete payment-card credentials where those are entered directly into a payment provider’s secure interface.
- Deal and marketplace data: item or service description, price, terms, delivery or inspection period, photographs, delivery status, counterparty details and other information included in a deel.
- Communications and evidence: in-app messages, support messages, complaints, call or correspondence records, photographs, receipts, tracking information, documents and other dispute evidence.
- Waitlist and marketing data: email address, source of sign-up, consent or opt-out record and engagement with communications.
- Information about other people: information you provide about a counterparty, delivery recipient or representative. You must have authority to provide it and should give the person access to this Policy where appropriate.
3.2 Information collected automatically
- Device and technical data: device type, operating system, app version, IP address, language, time zone, device or app identifiers and push-notification token.
- Usage data: screens viewed, features used, button interactions, dates and times, session information and referral source.
- Security and diagnostic data: authentication events, failed login attempts, transaction-PIN events, fraud signals, error logs, crash reports and records required to detect or investigate misuse.
- Cookies and similar technologies: technologies required for security, network management, accessibility, session continuity and other essential functions. Non-essential analytics, advertising or tracking technologies will be used only after an applicable consent choice has been presented.
3.3 Information received from third parties
We may receive personal data from licensed banks, payment service banks and processors; identity-verification providers; fraud-prevention providers; delivery or logistics services involved in a deel; a transaction counterparty; public or official sources used for lawful verification; and regulators, courts or law-enforcement authorities.
4. Why we process personal data and our lawful bases
We process personal data only for specified, explicit and lawful purposes. The principal purposes and lawful bases are set out below.
| Purpose | Data commonly involved | Lawful basis |
|---|---|---|
| Create and administer an account; authenticate a user; provide requested features | Account, contact, device and authentication data | Performance of a contract or steps requested before entering a contract |
| Create, fund, administer, release, refund and record a deel | Account, deal, transaction, bank and counterparty data | Performance of a contract; legal obligation where applicable |
| Verify identity, apply transaction tiers and satisfy KYC, AML, counter-terrorist-financing, sanctions and regulatory requirements | Identity, KYC, financial and transaction data | Legal obligation; substantial public interest where recognised by law; contract where necessary; consent only where legally required |
| Prevent fraud, scams, account takeover, money laundering, prohibited transactions and platform abuse | Account, device, usage, communications, deal, transaction and fraud-signal data | Legal obligation; legitimate interests in protecting users, the platform and the financial system |
| Provide chat, customer support, complaints handling and dispute resolution | Account, communications, deal, transaction and evidence data | Performance of a contract; legitimate interests in resolving complaints and protecting legal rights |
| Produce AI-assisted risk indicators, scam warnings, listing assistance, support responses and dispute summaries | Deal text, permitted message content, support content and relevant transaction context | Contract where needed to provide the feature; legitimate interests, following an assessment; consent where required by law |
| Send operational messages, security alerts, receipts and changes to the service | Account, contact and transaction data | Performance of a contract; legal obligation; legitimate interests for essential service communications |
| Send product news, promotions or waitlist updates | Contact, preference and engagement data | Consent. You may withdraw it at any time without affecting other services |
| Secure, test, audit and improve the service | Device, usage, diagnostic, security and limited account data | Legitimate interests in service security, reliability and improvement, subject to an assessment and appropriate safeguards |
| Establish, exercise or defend legal claims and respond to lawful requests | Any data relevant to the matter | Legal obligation; legitimate interests; establishment, exercise or defence of legal claims |
Where we rely on legitimate interests, we assess the necessity and proportionality of the processing, the reasonable expectations of users, and the effect on their rights. You may object as described in section 11.
Accepting or acknowledging this Policy is not consent. Whenever consent is legally required, Deela will request it separately, clearly and specifically; keep an appropriate record; and provide a method of withdrawal that is as easy as giving consent. Refusing optional consent will not prevent access to unrelated features.
5. Sensitive personal data and identity verification
KYC and financial identifiers require heightened protection. Deela limits access to authorised personnel and providers, masks sensitive identifiers in user-facing interfaces where appropriate, and shares only the minimum information reasonably necessary for verification, compliance and service delivery.
We do not use consent to avoid a legal obligation. If identity verification is required by law or by a regulated payment partner, withdrawing an optional consent will not require deletion of records that must be retained or prevent processing on another valid lawful basis. If a legally required verification cannot be completed, we may be unable to open an account, increase a transaction tier or provide a regulated feature.
6. Artificial intelligence and automated processing
Deela may use artificial-intelligence systems to assist with scam and fraud detection, deal-risk indicators, message warnings, listing suggestions, customer-support responses and neutral summaries of dispute materials.
These tools may analyse deal descriptions, permitted in-app message content, transaction context, user-provided evidence and fraud indicators. We do not intentionally send BVN, NIN or identity-document images to a general-purpose AI provider unless this is specifically necessary, lawful, disclosed and appropriately safeguarded.
An AI flag or summary is advisory. Deela does not rely solely on an automated output to make a final decision that produces legal or similarly significant effects, such as permanently closing an account or finally deciding entitlement to disputed funds, without an applicable legal exception and required safeguards. Where a decision significantly affects you, you may request human review, provide your point of view and challenge the outcome by contacting support@deelapay.com or privacy@deelapay.com.
Deela evaluates high-risk and emerging-technology processing through a Data Privacy Impact Assessment where required and applies data minimisation, testing, human oversight, access control, monitoring and other proportionate safeguards.
7. Who receives personal data
We disclose personal data only where necessary and lawful, including to:
- licensed banks, payment service banks, payment processors and payout providers, to receive, safeguard, transfer, reconcile, refund or pay out funds and meet financial-sector obligations;
- identity-verification and fraud-prevention providers, to verify identity, bank details and risk indicators;
- the other party to a deel, for information reasonably required to perform the transaction, confirm delivery, communicate or resolve a dispute;
- cloud-hosting, secure-storage, communications, email, SMS, push-notification, analytics, customer-support and cybersecurity providers;
- AI providers, for the limited functions described in section 6 and subject to contractual and technical restrictions;
- professional advisers, auditors, insurers and Data Protection Compliance Organisations, where they need the information to perform their duties;
- regulators, courts, law-enforcement agencies and other competent authorities when disclosure is required or permitted by law; and
- a buyer, investor or successor in a proposed merger, financing, restructuring or sale, subject to confidentiality and lawful-use restrictions.
Providers that process personal data on Deela’s instructions must be subject to written data-processing terms, confidentiality duties, appropriate security requirements and restrictions on further use. Some regulated providers may process data as independent controllers under their own legal duties.
We do not sell personal data.
8. International transfers
Some cloud, communications, support or AI providers may process limited personal data outside Nigeria, including in the United States. Before making a cross-border transfer, Deela will document the destination, categories of data, purpose, recipient and applicable transfer basis.
We will make a transfer only where permitted by sections 41 to 43 of the NDPA and the GAID, including where:
- the NDPC has recognised an adequate level of protection;
- the transfer is covered by a cross-border data-transfer instrument approved by the NDPC; or
- a specific statutory ground applies, such as explicit informed consent after disclosure of relevant risks, necessity for a contract involving the data subject, important public interest, legal claims or protection of vital interests.
We also apply contractual, organisational and technical safeguards appropriate to the risk. You may contact privacy@deelapay.com to request information about the applicable safeguard, subject to lawful confidentiality restrictions. If a transfer cannot be made lawfully, Deela will not make it.
9. Retention
We keep personal data only for as long as reasonably necessary for the stated purpose and applicable legal, regulatory, accounting, fraud-prevention and claims requirements.
| Record category | Normal retention period |
|---|---|
| Incomplete or unsuccessful pre-contract onboarding | Up to 6 months, unless retention is justified for fraud prevention, a complaint or a legal claim |
| Account and profile records | While the account is active and generally for 5 years after closure |
| KYC, AML and transaction records | At least 5 years after the transaction or end of the business relationship, or longer where applicable law or a competent authority requires it |
| Deal records, chat and dispute evidence | While needed to perform the deel and generally for 5 years after completion or final resolution |
| Customer-support and complaint records | Generally 3 years after the matter is closed, or longer if linked to a transaction, regulatory matter or legal claim |
| Security, authentication and diagnostic logs | Generally 12 months, unless required for an active investigation, security incident or legal obligation |
| Waitlist and direct-marketing records | Until you opt out or after 24 months without meaningful engagement; suppression records may be kept to respect an opt-out |
| Consent and compliance records | For the duration of the processing and an appropriate period afterwards to demonstrate compliance |
When a retention period ends, we securely erase or irreversibly anonymise the data unless preservation is required by law, a regulator, a court order, an unresolved dispute or the establishment, exercise or defence of legal claims. Account deletion does not override mandatory retention.
10. Security and personal-data breaches
Deela uses risk-based technical and organisational measures designed to protect confidentiality, integrity and availability. These measures include, where appropriate, encryption in transit, encryption or equivalent protection at rest, role-based and need-to-know access, masking of sensitive identifiers, secure development and change controls, authentication controls, logging and monitoring, backups, vendor due diligence, staff confidentiality and training, vulnerability management and incident-response procedures.
No system is completely secure. If a personal-data breach is likely to create a risk to individuals’ rights and freedoms, Deela will notify the NDPC within 72 hours of becoming aware of it, where required. Where the breach creates a high risk, we will also inform affected individuals as soon as reasonably practicable and provide guidance to reduce harm, unless a lawful exception applies. We maintain records of personal-data breaches and remedial actions.
You should protect your device, one-time codes and transaction PIN and notify support@deelapay.com promptly if you suspect unauthorised access.
11. Your rights
Subject to the NDPA and lawful limitations, you may:
- be informed about how your personal data is processed;
- request confirmation and access to personal data held about you;
- request correction of inaccurate, incomplete or misleading data;
- request erasure where the data is no longer required, consent has been withdrawn and no other basis applies, or the processing is unlawful;
- request restriction of certain processing;
- object to processing based on legitimate interests;
- object at any time to direct marketing;
- withdraw consent at any time, as easily as it was given, without affecting earlier lawful processing;
- receive eligible data in a structured, commonly used and machine-readable format and request transmission where technically feasible;
- request human intervention, express your point of view and challenge an eligible automated decision; and
- lodge a complaint with the Nigeria Data Protection Commission or seek another remedy available by law.
You may update certain profile information or request account deletion in the app. You may also send a request to privacy@deelapay.com. Please describe the right you wish to exercise and provide enough information for us to verify your identity without collecting excessive additional data.
We will acknowledge and address requests without constraint or unreasonable delay and within any period prescribed by applicable law. We do not ordinarily charge for a request, but may take lawful steps where a request is manifestly unfounded or excessive. If we cannot comply fully, we will explain the reason and available complaint options.
12. Marketing, cookies and communication choices
Operational messages about security, transactions, receipts, disputes and material service changes are part of the service and are not direct marketing.
We will seek consent before sending electronic direct marketing where required. You can withdraw that consent through the unsubscribe facility in a message or by contacting privacy@deelapay.com.
Necessary cookies or similar technologies may operate without a separate opt-in only to the extent permitted by the GAID. For all other cookies or tracking tools, we will present a conspicuous choice to accept or reject them and explain their purpose. You can later change or withdraw your choice through the available preference control.
13. Children
Deela is intended only for people aged 18 or older. We do not knowingly open accounts for children or intentionally collect their personal data. Where age is uncertain, we may apply proportionate age-verification measures. If you believe a child has provided personal data to Deela, contact privacy@deelapay.com so we can investigate, restrict the account and erase data where legally appropriate.
14. Account closure and deletion
You may request closure or deletion through the app or by contacting support@deelapay.com. Before closure, active deels, refunds, disputes, negative balances and lawful investigations may need to be resolved. We will delete or anonymise data that is no longer required, while retaining records that must be preserved under section 9.
Closing an account does not withdraw a complaint, remove another user’s legitimate transaction record or prevent Deela from using necessary information to protect users, comply with law or defend a legal claim.
15. Complaints and internal remediation
If you believe we have infringed your privacy rights, contact our privacy function first at privacy@deelapay.com. Include a description of the concern, relevant dates and the remedy requested. We will investigate and communicate our response as promptly as reasonably practicable.
You may complain directly to the Nigeria Data Protection Commission without first contacting Deela:
Nigeria Data Protection Commission (NDPC)
No. 12 Dr Clement Isong Street, Asokoro, Abuja, Nigeria
Email: info@ndpc.gov.ng
Telephone: +234 (0) 916 061 5551
Website and complaint services: https://ndpc.gov.ng and https://services.ndpc.gov.ng/breach/
Nothing in this Policy limits a right to seek a civil or other remedy available under Nigerian law.
16. Changes to this Policy
We may update this Policy when our service, providers or legal obligations change. We will publish the revised version with a new effective date and provide prominent or direct notice of a material change where appropriate. Where a change requires new consent, we will request it before the affected processing begins.
17. Contact
Deela Digital Services Limited (RC 9654122), trading as Deela
5B Johnson Street, Ilupeju, Lagos, Nigeria
Privacy and Data Protection Officer: privacy@deelapay.com
Support: support@deelapay.com
General enquiries: hello@deelapay.com
