Legal

Data Protection Policy (GDPR-Style)

Last updated: 1 September 2026

This Data Protection Policy sets out how FarmX handles personal data in line with recognised data-protection principles, including those in the Nigeria Data Protection Act 2023 (enforced by the Nigeria Data Protection Commission) and, where they apply to you, comparable standards such as the EU/UK General Data Protection Regulation. It applies alongside our Privacy Policy. Where this policy refers to a right or obligation that does not apply in your jurisdiction, we still aim to meet the standard described here as a matter of good practice.

1. Definitions

  • Personal data — any information relating to an identified or identifiable person.
  • Processing — any operation on personal data, including collecting, storing, using, sharing, and deleting.
  • Controller — the party that decides why and how personal data is processed. FarmX is the controller for the data described here.
  • Processor — a party that processes personal data on the controller's instructions.
  • Data subject — the individual the personal data is about.

2. Data-protection principles

We process personal data:

  • lawfully, fairly and transparently;
  • only for specified, explicit and legitimate purposes, and not in a way incompatible with them;
  • limited to what is adequate, relevant and necessary;
  • accurately, and kept up to date, with inaccurate data corrected or erased without delay;
  • kept in a form that identifies you for no longer than necessary;
  • securely, protected against unauthorised or unlawful processing, loss, destruction or damage;
  • and we take responsibility for, and can demonstrate, compliance with these principles.

3. Categories of personal data we process

  • identity data (name, date of birth, identity-document data);
  • contact data (email, phone, address);
  • financial data (bank account details, transaction and balance history);
  • verification data (identity-check and bank-name-check results, and any documents you upload);
  • referral / network data (your referrer, downline relationships, commission records);
  • technical and usage data (IP address, device, log and activity data, cookie identifiers);
  • communications data (support messages, chat transcripts).

4. Lawful bases for processing

  • Performance of a contract — running your account and Wallet, processing deposits, applying Returns, executing transfers and withdrawals, and operating the Referral Programme for participants.
  • Compliance with a legal obligation — identity verification, anti-money-laundering checks and record-keeping, tax reporting, responding to lawful requests from authorities.
  • Legitimate interests — preventing and investigating fraud and abuse, securing and improving the Platform, managing risk, and enforcing our agreements. We balance these interests against your rights and freedoms.
  • Consent — non-essential cookies and certain marketing communications. You can withdraw consent at any time without affecting processing already carried out.
  • Vital interests / public interest — rarely, for example to help prevent serious harm or crime.

5. Sensitive personal data

We try to avoid processing sensitive categories of personal data. Identity documents may contain such data incidentally; we handle them with additional safeguards and restricted access, and keep them only as long as required for verification and legal record-keeping.

6. Your rights

Subject to applicable law and to exceptions (for example where we must retain data to meet AML or tax obligations, or where a request is manifestly unfounded or excessive), you have the right to:

  • be informed about how we use your data (this policy and the Privacy Policy);
  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased where there is no lawful reason for us to keep it;
  • restrict processing in certain circumstances;
  • receive your data, or have it sent to another controller, in a structured, commonly used, machine-readable format, where processing is based on consent or contract and carried out by automated means;
  • object to processing based on our legitimate interests, and to direct marketing at any time;
  • not be subject to a decision producing legal or similarly significant effects that is based solely on automated processing, without a right to human review (see section 7);
  • withdraw consent where we rely on it.

To exercise a right, contact us through the Contact page, marked for the Data Protection / Legal team. We may ask you to verify your identity. We aim to respond without undue delay and in any event within 30 days, and will tell you if we need longer because a request is complex. We do not charge a fee unless a request is excessive or repetitive.

7. Automated decision-making and profiling

We use automated tools to screen transactions and accounts for fraud and money-laundering risk. These tools can trigger a hold, a request for more information, or a manual review. Where an automated check materially affects you, you can ask for a human to review the decision by contacting us.

8. Processors and data sharing

We use written agreements with our processors that require them to process personal data only on our instructions, keep it secure and confidential, assist us with data-subject requests, and delete or return it at the end of the engagement. The categories of recipients are listed in the Privacy Policy.

9. International transfers

Where personal data is transferred to a country without an equivalent level of protection, we put in place a lawful transfer mechanism, such as standard contractual clauses or an adequacy decision where one is available, and additional safeguards where needed.

10. Retention

We keep personal data only as long as necessary for the purpose it was collected and to meet legal requirements. As a general guide:

  • account, transaction and financial records — for the life of the account and then for the minimum period required by applicable financial, tax and anti-money-laundering law (commonly at least five to seven years after the relationship ends);
  • identity-verification records — for the period required by anti-money-laundering law;
  • marketing preferences — until you opt out or ask us to delete them;
  • technical logs — for a limited period appropriate to security and troubleshooting.

At the end of the applicable period we delete the data or irreversibly anonymise it.

11. Security

Our measures include encryption of data in transit, role-based access on a need-to-know basis, a separate Transaction PIN for sensitive actions, activity monitoring, staff confidentiality obligations, supplier due diligence, and regular review of our controls. No system is completely secure, and we cannot guarantee absolute security.

12. Personal data breaches

If a personal data breach occurs, we will assess and contain it, keep an internal record, notify the relevant supervisory authority where the law requires (in Nigeria, the Nigeria Data Protection Commission), and notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.

13. Data-protection contact and Data Protection Officer

Data-protection queries and requests should be sent through the Contact page, marked for the Data Protection / Legal team. Where FarmX is required to appoint a Data Protection Officer or Compliance Organisation, its contact details will be published on the Platform.

14. Complaints

If you are concerned about how we handle your personal data, please contact us first so we can try to put it right. You also have the right to complain to the data-protection authority for your jurisdiction — in Nigeria, the Nigeria Data Protection Commission.

15. Changes

We may update this policy. The current version, with its last-updated date, is always on the Platform. Material changes will be notified by a reasonable means.

FarmX uses cookies to keep you signed in, secure the site and understand how it is used. learn more

Allow