This Privacy Notice explains how the relevant NCDF company collects and uses personal information when you visit our websites, access resources, submit an enquiry, request a meeting, report a concern or communicate with us before a formal client relationship begins.
A separate or supplemental notice may apply when a company accepts you as a client, investor, issuer, mandate participant, employee, supplier or other stakeholder. Where notices differ, the notice specific to the relevant relationship and processing activity applies.
The controller is the NCDF company that determines why and how personal information is used for the relevant activity. The applicable controller may be:
| Controller | Typical processing role | Contact |
|---|---|---|
| [GROUP WEBSITE OPERATOR] | General website operation, routing platform administration, security and Group-level communications where applicable. | [CONTACT] |
| NCDF Commercial Services Limited | Commercial advisory, diagnostic, readiness, growth, market-entry and implementation enquiries or engagements. | [CONTACT] |
| NCDF Securities Limited | Capital-markets enquiries, due diligence, accepted transaction mandates and related legal/regulatory obligations. | [CONTACT] |
| NCDF Investment Management Plc | Investment, portfolio, fund, treasury and institutional enquiries, onboarding and accepted mandates. | [CONTACT] |
| NCDF Technology Infrastructure & Services Limited | Technology strategy, digital-product, systems-integration, workflow, data-infrastructure, investor data-room, cybersecurity-control and managed-platform enquiries or accepted engagements. | [CONTACT] |
Where one company routes information to another, each company remains responsible for the processing it controls. We will identify the responsible company or provide further notice where the position is not obvious.
| Category | Includes |
|---|---|
| Identity and contact | Name, title, organisation, email, telephone, country, correspondence address where needed and preferred contact method. |
| Professional and authority | Role, employer, adviser status, authority to act, represented client, sponsor or decision-making responsibility. |
| Enquiry and objective | Client type, pathway, service interest, decision, target timing, message, meeting preferences and route history. |
| Business and transaction context | Organisation, sector, funding purpose, amount band, use of proceeds, readiness stage, project or market-entry context. |
| Technology-service and systems context | Business requirements, system inventories, architecture, integrations, user roles, data flows, hosting, vendors, security controls, incidents, service levels, support records and implementation dependencies. |
| Investment and institutional context | Objective, amount band, time horizon, liquidity need, experience, governance, policy and reporting requirements. |
| Jurisdiction and compliance | Country of residence/incorporation, relevant jurisdictions, eligibility indicators, conflicts, due-diligence information and screening results where required. |
| Technical and usage | IP address, device/browser, pages viewed, referral source, cookie choices, security events and form metadata, subject to cookie controls. |
| Communications and records | Emails, meeting notes, call records where lawful and notified, documents, support requests, complaints, fraud reports and consent records. |
| Special or sensitive information | Only where necessary and lawful, for example identity verification, financial/criminal-risk information or accessibility needs. We do not request sensitive documents through the first-contact form. |
The lawful basis depends on the purpose, the controller and the circumstances. Legal / Privacy must confirm the final basis for each activity. We may use personal information as permitted by applicable law for the following purposes:
| Purpose | What we do | Indicative legal basis - confirm before publication |
|---|---|---|
| Respond and route | Acknowledge the enquiry, clarify the need, identify the responsible company and assign an owner. | Steps requested before a contract; legitimate interests; consent where appropriate. |
| Assess fit, readiness and eligibility | Review service fit, authority, country, readiness, conflicts and initial eligibility or suitability factors. | Steps requested before a contract; legal obligation; legitimate interests. |
| Due diligence and compliance | Complete KYC/KYB, screening, source-of-funds/wealth, sanctions, fraud, regulatory and recordkeeping checks where required. | Legal obligation; public interest/regulatory requirement; legitimate interests; other lawful basis. |
| Provide and manage services | Scope, contract, deliver, invoice, report, support and administer an accepted engagement or mandate. | Contract; legal obligation; legitimate interests. |
| Secure systems and prevent fraud | Authenticate, monitor, detect abuse, investigate incidents and protect clients, staff, systems and rights. | Legal obligation; legitimate interests; vital/public interests where applicable. |
| Handle support, complaints and rights | Acknowledge, investigate, respond, escalate and keep appropriate records. | Legal obligation; contract; legitimate interests. |
| Improve services and website | Analyse non-excessive usage, test usability, manage capacity and improve content and routes. | Legitimate interests; consent for non-essential cookies/technologies. |
| Send approved communications | Send insights, education and event invitations where you have opted in or another lawful basis applies. | Consent or other basis permitted for the communication and recipient. |
| [CONFIRM ROW LABEL - "Corporate an..." cut off] | [CONFIRM DESCRIPTION - cut off in screenshot] | [CONFIRM - text ended "...ests; contract." in screenshot] |
We do not sell personal information. We do not transfer enquiry data to an investor, lender or counterparty merely because a visitor selected a capital pathway.
Some service providers, advisers, counterparties or NCDF operations may be located outside the country where you are based. Where personal information is transferred internationally, the responsible controller will use a transfer mechanism and safeguards required by applicable law, taking account of the destination, purpose, recipient and risk.
We keep personal information only for as long as reasonably necessary for the purpose collected, legal and regulatory requirements, claims, security and approved records management. Retention depends on the relationship, document type, applicable company and law.
| Record | Draft publication statement |
|---|---|
| Unsuccessful or inactive enquiry | [RETENTION PERIOD / CRITERIA], unless a longer period is required for security, complaint, legal or regulatory reasons. |
| Marketing preference | Until consent is withdrawn, the communication becomes inactive or the approved review period expires; suppression records may be retained to respect an opt-out. |
| Client / mandate record | For the period required by the responsible company's legal, regulatory, contractual and records-retention obligations. |
| Complaint / fraud / incident | For the period necessary to investigate, resolve, evidence action and meet legal, regulatory or claims requirements. |
| Website and security logs | For the approved security and operational period, minimised and access-controlled. |
We use risk-based organisational and technical measures designed to protect personal information against unauthorised access, loss, misuse, alteration or disclosure. Measures may include access control, multi-factor authentication, least privilege, encryption, monitoring, secure configuration, change control, staff obligations, vendor controls, backups, incident response and secure document intake. The precise controls depend on the service, data, system and agreed responsibility model.
No internet transmission or storage system is completely secure. You should use verified channels, protect credentials and notify us promptly if you suspect an unauthorised communication or disclosure.
The website may use rules to display relevant form fields, assign a route or flag a submission for review. These rules do not by themselves create a mandate, investment recommendation, credit decision or final acceptance decision. Where a legally significant decision uses solely automated processing, the responsible company will provide the information and safeguards required by applicable law.
We use cookies and similar technologies as described in the Cookie Notice. Essential technologies support security and functionality. Non-essential analytics, preference or marketing technologies are used only in accordance with the applicable consent and preference controls.
Subject to applicable law, conditions and exemptions, you may have rights to:
To make a request, use [DATA-RIGHTS FORM / PRIVACY CONTACT]. We may need to verify identity and authority proportionately. We will not request a password, one-time code or unnecessary account credential.
Marketing consent is optional and separate from an enquiry. You can unsubscribe using the link in an approved message or contact us. We may keep a limited suppression record so that we can respect the opt-out.
The Website and services are not directed to children unless a specific service and notice expressly state otherwise. Do not submit information about a child through a general enquiry form unless it is necessary, lawful and you have appropriate authority. Contact the Privacy team before providing sensitive information about a minor.
Questions or requests may be sent to [PRIVACY / DPO CONTACT]. If you are dissatisfied with our response, you may complain to the Nigeria Data Protection Commission or another competent authority, subject to applicable law.
We may update this notice to reflect changes in law, processing, services, systems or companies. The current version and effective date will be shown on the Website. We will provide additional notice of material changes where appropriate.