Legal and privacy
Privacy Policy
This policy explains how First Heritage Microfinance Bank Limited collects, uses, shares, retains and protects personal data. It also explains the rights available to data subjects and how to contact the Data Protection Officer.
insured byQuick guide
What this policy covers
Personal data collected by the bank
Read this section02How the bank uses personal data
Read this section03Mandatory information for banking and regulatory purposes
Read this section04Sharing with regulators and service providers
Read this section05Retention and security statements
Read this section06Cookies and technical website information
Read this section07Data-subject rights
Read this section08Data breaches and remediation
Read this section09Privacy enquiries, complaints and rights requests
Read this sectionPrivacy Policy details
How we protect and use personal data
This policy applies to customers, applicants, guarantors, representatives, website visitors and other people whose personal data is processed by First Heritage Microfinance Bank Limited.
Personal data collected by the bank
First Heritage Microfinance Bank Limited collects personal data needed to provide secure banking services and manage its relationship with customers, applicants, guarantors, representatives, website visitors and other people who interact with the bank.
The information collected includes:
- Identity and contact information: name, date of birth, gender, photograph, signature, residential or business address, telephone number and email address.
- Identification and verification information: government-issued identification, Bank Verification Number (BVN), National Identification Number (NIN), proof of address, tax information and other Know Your Customer records required by law.
- Account and financial information: account details, balances, transaction history, payment instructions, beneficiaries, income, employment or business information and source-of-funds information.
- Product and application information: information supplied for savings, deposits, investments, loans, guarantor arrangements, security and supporting documents.
- Service and communication information: enquiries, complaints, correspondence and records of support provided by telephone, email, in person or through the website.
- Technical website information: IP address, browser and device details, cookies, pages viewed and information entered after Live Chat is opened.
Personal data is received directly from you and, where lawful, from authorised representatives, guarantors, employers, identity and credit-reference sources, payment networks, regulators, public records and service providers.
Back to policy guideHow the bank uses personal data
The bank uses personal data to:
- open, administer and maintain accounts and other banking relationships;
- process transactions, payment instructions and service requests;
- assess applications and manage savings, deposit, investment and credit products;
- provide customer support and communicate service, security or account information;
- carry out identity checks, fraud prevention, credit assessment and risk management;
- meet anti-money-laundering, counter-terrorist-financing, tax, banking and regulatory obligations;
- maintain business records, exercise legal rights and respond to disputes, complaints or lawful requests; and
- operate, secure and improve the website and customer-service channels.
Processing is based on the performance of a contract or steps requested before a contract, compliance with legal obligations, the bank's legitimate interests, public-interest duties, protection of vital interests, or consent where consent is required. Consent can be withdrawn for future processing that relies on consent, without affecting processing already carried out lawfully.
Back to policy guideMandatory information for banking and regulatory purposes
Banking laws and regulatory requirements require the bank to obtain and maintain accurate customer-identification and transaction records. Depending on the product or service, required information includes proof of identity and address, BVN, NIN, source of funds, occupation or business information, tax information, beneficial ownership details and supporting application documents.
When legally required information is not provided or cannot be validated, the bank cannot open or continue the affected account, complete the relevant transaction or provide the requested service. The bank also updates customer information as required to keep regulatory records accurate.
Back to policy guideSharing with regulators and service providers
The bank shares personal data only for a lawful banking, operational or regulatory purpose. Recipients include:
- the Central Bank of Nigeria, Nigeria Deposit Insurance Corporation, Nigeria Data Protection Commission, law-enforcement bodies, courts, tax authorities and other public authorities acting within their legal powers;
- payment systems, correspondent institutions and other financial institutions involved in processing transactions;
- identity-verification, credit-reference, fraud-prevention, insurance, recovery and security providers, where applicable;
- technology, hosting, communications, Live Chat, document-management, professional-advisory and other service providers supporting the bank; and
- another organisation involved in a lawful restructuring, merger, transfer or protection of the bank's legal rights.
Service providers receive only the information needed for their duties and are required to protect it. Where personal data is transferred outside Nigeria, the bank applies a lawful transfer mechanism and appropriate safeguards required by applicable data-protection law.
Back to policy guideRetention and security statements
The bank keeps personal data for the duration of the banking relationship and for the additional period required by banking, anti-money-laundering, tax, accounting, legal and regulatory obligations. Retention also reflects the purpose for which the data was collected, the sensitivity of the information, operational needs and the time allowed for legal claims. Personal data is securely deleted, anonymised or archived when it is no longer required.
Security measures include access controls, staff confidentiality, secure storage, system monitoring, backups, physical safeguards and encryption or other technical controls where appropriate. Access is limited to authorised people with a business need. No system can be guaranteed to be completely secure, so the bank continually reviews and strengthens its safeguards.
Back to policy guideCookies and technical website information
The website uses cookies and similar technologies needed for core functions, security, user preferences and service performance. Where optional analytics or similar technologies are enabled, the website provides the controls required by applicable law. Browser settings can be used to block or delete cookies, although essential website functions can be affected.
Opening Live Chat loads a third-party chat service. After it is opened, the provider receives technical information such as IP address, browser and device details, the page being viewed and information entered into the chat. Do not send a PIN, password, one-time password, full card details or other authentication information through Live Chat.
Back to policy guideData-subject rights
Subject to applicable law, a data subject can:
- receive clear information about the processing of personal data;
- request access to and a copy of personal data held by the bank;
- request correction of inaccurate or incomplete information;
- request deletion or restriction of processing where the legal conditions are met;
- object to processing based on legitimate interests or direct marketing;
- receive qualifying personal data in a portable format;
- withdraw consent where processing depends on consent;
- request human review of a qualifying decision based solely on automated processing; and
- submit a complaint to the bank or the Nigeria Data Protection Commission.
These rights are not absolute. A request can be limited where the bank must keep or use information to comply with law, protect another person, prevent fraud, establish legal claims or perform a valid banking obligation. The bank verifies the identity and authority of a person making a rights request before releasing or changing personal data.
Back to policy guideData breaches and remediation
The bank maintains processes to detect, contain, investigate and remediate personal-data breaches. Each incident is assessed for its nature, scope, affected information and potential impact. The bank records the incident, strengthens safeguards and notifies the Nigeria Data Protection Commission and affected data subjects where notification is required by law.
If you believe personal data connected with the bank has been lost, disclosed, altered or accessed without authorisation, contact the Data Protection Officer promptly. Include enough information to identify the incident, but do not send passwords, one-time passwords, PINs or full card details.
Back to policy guidePrivacy enquiries, complaints and rights requests
Send privacy enquiries, complaints and data-subject rights requests to the Data Protection Officer using the contact details below. Include your name, preferred contact details, relationship with the bank and a clear description of the request. The bank requests additional identification only where needed to protect personal data and establish the requester's authority.
The Data Protection Officer handles the request and communicates the outcome within the period required by applicable law. If you remain dissatisfied, you can submit a complaint to the Nigeria Data Protection Commission.
This policy is updated when the bank's processing activities or legal obligations change. The current version is published on this page.
Back to policy guideThird-party website services
Live Chat and external services
Opening Live Chat loads a third-party chat service. The service may receive technical information such as your IP address, browser and device details, the page you are viewing and information you choose to type.
Do not share sensitive authentication or card information in chat.Contact the DPO
Privacy inquiries and rights requests
Use the Data Protection Officer contact for privacy inquiries, complaints and rights requests.
Data Protection Officer
Adebayo Adekeye
Data Protection OfficerFIRST HERITAGE MICROFINANCE BANK LIMITEDP.M.B 1012, Omu-Aran Road, Opposite C.C.C. School, Oro-Ago, Kwara Stateadebayoadekeye@firstheritagemfb.com+234 810 035 4570
