Legal

Privacy Policy

Last updated: May 2026

01 — Overview

Who we are

Komply is a compliance intelligence service for African fintech startups. We help early-stage financial technology companies understand and navigate Nigerian regulatory frameworks including CBN, NDPC, SEC Nigeria, FIRS, NCC, and FATF cross-border requirements.

This privacy policy explains how we collect, use, store, and protect the personal and business data you share with us when you use our website, submit a request for access, or use our client portal. We are committed to protecting your data in accordance with the Nigeria Data Protection Act 2023 (NDPA) and the regulations of the Nigeria Data Protection Commission (NDPC).

02 — Data collection

What we collect

We collect only what we need to provide our compliance services. This includes:

Contact information

Your name, work email address, and company name when you submit a request for access or create a portal account.

Business information

Your company's stage, business model, product description, existing licenses, applicable regulatory frameworks, and compliance concerns — shared during onboarding and maintained in your client profile.

Compliance data

Gap analysis results, licensing roadmap progress, remediation task status, and audit readiness information generated as part of our service delivery.

Usage data

Standard web server logs including IP address, browser type, pages visited, and timestamps. We do not use third-party analytics or advertising trackers.

Communications

Records of emails and messages exchanged between you and the Komply team in connection with service delivery.

03 — Data use

How we use your data

Our lawful basis for processing your data is contractual necessity — we process your data because you have entered into or are seeking to enter into a service agreement with Komply. We use your data to:

Review and respond to your access request

Set up and maintain your compliance portal account

Generate and deliver gap analysis reports, licensing roadmaps, and audit readiness assessments

Send regulatory alerts relevant to your business profile

Communicate with you about your compliance status and service updates

Improve our service and regulatory intelligence coverage

We do not use your data for advertising, sell it to third parties, or share it with any party not directly involved in delivering your Komply service.

04 — Data sharing

Who we share your data with

We share your data only with the following third-party processors who help us deliver our service. Each processor operates under a Data Processing Agreement and handles your data only as instructed by Komply.

Supabase

Our database, authentication, and storage provider. Your data is stored on Supabase's servers in the EU (Stockholm region) and encrypted at rest.

Resend

Our email delivery provider. Used to send access confirmations, regulatory alerts, and service notifications.

Anthropic (Claude API)

Used to power our automated gap analysis engine. Your business profile data is sent to Claude's API to generate compliance analysis. Anthropic does not train on API data by default.

05 — Retention

How long we keep your data

We retain your data for as long as your Komply account is active and for 90 days after account closure. After 90 days, we permanently delete all personal and business data associated with your account from our systems and those of our processors.

Access request data from visitors who did not become clients is retained for 12 months and then deleted.

06 — Your rights

Your data rights

Under the Nigeria Data Protection Act 2023, you have the following rights regarding your personal data:

Right of access — request a copy of all data we hold about you

Right to rectification — request correction of inaccurate data

Right to erasure — request deletion of your data at any time

Right to portability — request your data in a structured, machine-readable format

Right to object — object to processing of your data for specific purposes

To exercise any of these rights, email us at privacy@komply.co. We will respond within 30 days.

07 — Security

How we protect your data

We implement the following technical and organisational measures to protect your data:

All data encrypted at rest using AES-256 encryption

All data in transit encrypted via TLS 1.2+

Row Level Security enforced on all database tables — clients can only access their own data

Authentication required to access all client and admin portal pages

Access to production systems limited to authorised Komply personnel only

In the event of a data breach, we will notify affected individuals and the NDPC within 72 hours of discovery, in accordance with NDPA 2023 requirements.

08 — Contact

Questions about this policy

If you have any questions about this privacy policy or how we handle your data, contact us at:

Komply

privacy@komply.co

We may update this policy periodically. Material changes will be communicated to active clients via email. The date at the top of this page reflects the most recent update.