Privacy Notice
Effective date: 18 August 2026 · Last updated: 18 August 2026
How BTCMarts collects, uses, shares, secures, retains and responds to rights concerning personal data.
Service
Effective date
18 August 2026
Primary jurisdiction
Federal Republic of Nigeria
Status
Publication draft - requires legal and regulatory review
IMPORTANT OPERATOR COMPLETION NOTE
Before publication, BTCMarts must insert the operator’s full legal name, CAC registration number, physical address, support email, privacy contact, complaints contact, and verified regulatory or licensing status. Nothing in this document should be read as claiming a licence or approval that has not been formally granted.
Quick-use summary
Read this document before using the relevant BTCMarts service.
Keep transaction confirmations and use only verified BTCMarts channels.
Contact BTCMarts promptly if information is wrong, a device or account is compromised, or you need to exercise a right.
Bracketed operator and contact fields must be completed before publication.
1. Who this notice covers
This Privacy Notice explains how BTCMarts processes personal data relating to visitors, account holders, Bitcoin customers, power-sharing subscribers, collectible buyers and sellers, Activity Key holders, agents, partners, outlet visitors, beneficiaries and support contacts. The legal operator named in the published notice is the data controller for the purposes described here, unless a specific notice identifies another controller.
2. Data we collect
Identity and profile data: name, date of birth, photograph, signature, nationality, government identifier, address, occupation, business details, beneficial ownership and verification results.
Contact and account data: email, phone, login records, authentication factors, preferences, communications, referrals, agent or partner identifiers and account status.
Financial and transaction data: bank or mobile-money details, masked payment data, Bitcoin wallet addresses, transaction hashes, quotes, amounts, timestamps, commissions, fees, refunds, subscriptions, collectibles orders, power-sharing allocations and service history.
Technical and security data: IP-derived information, device and browser details, session identifiers, security events, approximate location where permitted, cookie identifiers, fraud signals and audit logs. BTCMarts should minimise raw IP retention and may keep a keyed security hash where appropriate.
Outlet and support data: CCTV where clearly signposted, call or chat records, complaints, incident reports, device condition, delivery information, survey responses and consent records.
3. How data is obtained
We receive data directly from you; from agents or partners acting through authorised workflows; from banks, payment processors, blockchain analytics, identity-verification providers, public registers, sanctions and politically exposed person databases; from devices and browsers; and from the public blockchain. Agents must not submit another person’s data without authority and notice.
4. Purposes and lawful bases
Contract: create and secure accounts; quote, process and record transactions; provide subscriptions, power-sharing allocations, collectible fulfilment, Key functionality, agent attribution, commissions, refunds and support.
Legal obligation and public interest: KYC, AML/CFT/CPF checks, sanctions screening, suspicious-activity review, record keeping, tax and regulator responses, law-enforcement cooperation and protection of vulnerable persons.
Legitimate interests: prevent fraud, secure systems, improve services, manage disputes, audit agent conduct, measure network performance and send limited service-related communications, balanced against your rights.
Consent: optional marketing, certain cookies, precise device permissions, promotional communications, and any processing for which law requires consent. Consent can be withdrawn prospectively.
Vital interests or legal claims: respond to urgent safety incidents, protect life, establish or defend claims, or prevent serious harm where legally permitted.
5. Automated checks
BTCMarts may use rules, risk scores and third-party tools to flag unusual transactions, duplicate accounts, compromised devices, sanctions exposure or document inconsistencies. A flag may delay or refer a transaction for human review. BTCMarts should not make a solely automated decision producing legal or similarly significant effects unless a lawful basis and required safeguards apply. You may request human review where applicable.
6. Sharing and processors
We may share the minimum necessary data with banks, payment and payout providers, blockchain or wallet infrastructure providers, identity and fraud vendors, cloud and communications providers, power-sharing partners, delivery providers, professional advisers, auditors, insurers, tax authorities, regulators, courts, law enforcement and counterparties where needed to complete an authorised service.
Providers must be bound by confidentiality, security, purpose limitation and data-processing obligations appropriate to their role. Agents receive only the data needed for attribution and service; they may not copy, sell or reuse customer information.
7. International transfers
Where data is transferred outside Nigeria, BTCMarts will use a lawful transfer mechanism and assess the destination, recipient and safeguards. Measures may include adequacy recognition, contractual clauses, binding arrangements, encryption, access controls and transfer-risk assessment. You may request information about applicable safeguards, subject to security and confidentiality limits.
8. Retention
BTCMarts retains data only for as long as reasonably necessary for the stated purpose, legal compliance, security, disputes and audit. Proposed operating schedule: unsuccessful onboarding data up to 12 months unless risk or law requires longer; account and service data for the account life plus 6 years; transaction, KYC and AML records for at least the legally required period after the relationship or transaction; security logs generally 12-24 months; CCTV generally 30-90 days unless linked to an incident; marketing consent until withdrawal plus a suppression record.
The final schedule must be validated against applicable SEC, AML, tax, consumer and limitation rules. Data subject deletion requests do not override mandatory retention or legal holds.
9. Security
Controls may include encryption in transit and at rest, least-privilege access, multifactor authentication, password hashing, wallet and payment segregation, logging, secure development, vulnerability management, backups, vendor reviews, staff training, incident response and periodic testing. No system is risk-free. Users must protect devices and credentials and report suspected compromise immediately.
10. Your rights
Subject to the Nigeria Data Protection Act and lawful limits, you may request confirmation and access; correction; deletion; restriction; objection; portability; withdrawal of consent; information about transfers; and review of certain automated decisions. You may also complain to BTCMarts or the Nigeria Data Protection Commission.
Submit requests to [PRIVACY EMAIL]. We will verify identity, respond within applicable time limits, explain any refusal and not discriminate for exercising a right. An authorised representative may act with adequate proof.
11. Children, cookies and third parties
The Services are not directed to persons under 18. If we learn that a child’s data was collected without lawful authority, we will restrict and delete it as appropriate.
Essential cookies support security and sessions. Analytics or advertising cookies should be disabled until valid choice is obtained where required. Third-party sites and wallets have their own notices; BTCMarts is not their controller merely because a link is provided.
12. Incidents, changes and contact
BTCMarts will assess personal-data breaches, contain harm, document decisions, and notify the NDPC and affected persons where the legal threshold is met. We may update this notice and will highlight material changes.
Controller: [FULL LEGAL NAME], [ADDRESS], CAC [NUMBER]. Privacy contact/DPO: [NAME OR ROLE], [EMAIL], [PHONE]. Complaints may also be made to the Nigeria Data Protection Commission at https://ndpc.gov.ng/.
Regulatory references
These references are provided for transparency and do not convert this draft into legal advice.
Nigeria Data Protection Act 2023 - Nigeria Data Protection Commission: https://ndpc.gov.ng/resources/
Nigeria Data Protection Act General Application and Implementation Directive 2025: https://ndpc.gov.ng/wp-content/uploads/2025/07/NDP-ACT-GAID-2025-MARCH-20TH.pdf
SEC Nigeria Rules on Issuance, Offering Platforms and Custody of Digital Assets (2022): https://home.sec.gov.ng/our-mandate/regulation/rules-and-regulations/
SEC Nigeria digital-assets and crypto-assets information: https://sec.gov.ng/our-mandate/development/business-insights/sec-policies-on-cryptocurrency-and-crypto-assets/
Nigeria Sanctions Committee - applicable AML/CFT laws: https://nigsac.gov.ng/OtherLaws
Document control
Version 1.0 | Effective 18 August 2026 | Owner: [BTCMARTS LEGAL/COMPLIANCE ROLE] | Next review: 18 August 2027 or earlier upon material legal, product or operational change.
