Privacy notice
Acreed Insights privacy notice
This notice explains how Acreed Insights Limited collects, uses, shares and protects your information when you use the Acreed Insights platform — including business verification, the Acreed Credibility Score and certificate, applications to funders, and post-funding monitoring. It is written to meet the Nigeria Data Protection Act 2023 (NDPA) and the General Application and Implementation Directive 2025 (GAID).
Who we are
Acreed Insights Limited (RC 9357855), Lagos, Nigeria, is the data controller for the personal information processed on the platform. You can reach our data protection contact at legal@acreedinsights.com.
What we collect
Account details: your name and email address. Business details: your business name, CAC registration (RC) number, tax identification number (TIN), operating address and sector. Identity details for each named director: name, National Identification Number (NIN), Bank Verification Number (BVN), a photo of a government-issued ID, a passport photograph, and a selfie taken during verification. Financial details: bank statement data you connect (read-only), and, with your consent, your credit-bureau report. Documents you choose to upload as evidence, including any tax clearance certificate you provide. We also keep records of activity on your account.
Identity checks and biometrics
To prove that a verified identity really belongs to the person presenting it, we run three checks: that your government ID is a genuine document, that your selfie is of a live person rather than a photograph, and that the face in your selfie matches the photo on your ID. We also check that the name printed on your ID agrees with your NIN and BVN records. These checks are performed by our identity-verification provider, Dojah. Your selfie passes through our systems only to be sent for checking and is then discarded — we never store it. We keep only the outcome of each check and a confidence value. We ask for your explicit consent before this processing begins, and we will tell you if a check does not pass.
If an identity check does not pass, your verification will stop and we will not be able to issue your certificate. This decision is made automatically. You can ask us to review it — contact us and a member of our team will look at your case.
Tax compliance
We confirm that your business is registered for tax using its registration number. If you provide a tax clearance certificate, we read it to check that it is issued to your business and which assessment years it covers — the document is read by an automated system, and we keep the outcome and the details we read from it. We also look through the bank statements you have connected for payments to tax authorities, so that a business which pays its taxes gets credit for it. If we cannot find any, we tell you, so you can connect the account you pay from. We never share your tax documents with anyone outside Acreed except a funder you apply to.
Your directors
A certificate describes a business, so we check everyone who directs it, not only the person who applies. We take each director’s name and position, and we ask each director to confirm their own identity — we send them a private link, and they enter their own identity number themselves rather than you entering it for them. We check that identity against the national records and, where they consent, their credit record. Each director sees what is being checked and agrees to it before anything runs. A director who does not complete their checks is simply recorded as unverified; we do not proceed on their behalf.
Why we use it, and our lawful bases
We use your information to verify your identity and your business against official records, to analyse your connected bank statements, to compute your Acreed Credibility Score and issue your certificate, to share your application with the funders you choose to apply to, to monitor funded facilities where monitoring has been agreed, to operate and secure the platform, and to send you service communications. We rely on your consent for the verification checks (including the biometric check and the credit-bureau pull), on performance of our terms of service for operating your account, and on our legitimate interest in keeping the platform secure and preventing fraud.
Who we share it with
Verification providers acting on our instructions: Dojah (identity, registry and biometric checks), Mono (read-only bank statement access) and licensed credit bureaus (your credit report, with your consent). The funders you apply to see your application, your score and band, the verification outcomes, and the documents you provided as part of your application — including your government ID and passport photograph, which funders are required to hold for their own regulatory checks. Funders themselves are verified before they can receive any of this: we check a funder’s registered legal name and RC number against the CAC corporate registry, hold the regulatory licence reference they declare, and a person on our team approves each funder before it can list, invite, or open applications. We do not pass on your NIN or BVN as separate data, though these numbers may appear on the ID document itself. Service providers that host our infrastructure and send our email operate under data processing agreements. If you publish your certificate, anyone with its link can see your business name, score, band, sector, state and validity dates — it never shows personal identifiers. We do not sell your information.
Bank access is read-only, and yours to revoke
Connecting a bank account gives us read-only access to statement data through Mono. We cannot move money. You can disconnect any account you have connected, at any time, from the verification screen: we instruct our banking provider to cancel the connection, which ends their permission to share your transactions with us, and we remove the account from your profile so it is never read again. Your cash-flow analysis is then recalculated from the accounts that remain, or removed entirely if none do. If our provider does not confirm the cancellation immediately, we keep asking until they do.
When monitoring ends
Monitoring runs while your loan does. When your final repayment is recorded, monitoring ends automatically: we stop reading your bank account and the facility closes. Your funder can also end it earlier — for example if you settle the loan directly with them — and we will tell you when they do, and why.
You can withdraw your permission for monitoring at any time and we stop collecting new information immediately. Because your funder is relying on that information, we tell them that you have switched it off. We do not tell them why, and your loan is unaffected — withdrawing permission is your right and is not a default or a breach.
Deleting your data
You can delete your account from your settings. This removes your business profile, the verifications we ran and their results, the documents you uploaded, your certificate — its public link stops working — and your score history, and it disconnects any bank account you had connected. It happens immediately and cannot be reversed: we cannot restore your data afterwards, and neither can our support team.
There is one situation where we cannot delete your data straight away: while a funder is still monitoring a loan you hold with them. Their monitoring rests on the loan agreement between you, not on your permission to us, so it does not end when you ask us to forget you. Monitoring ends by itself when your final repayment is recorded; if the loan has already ended some other way, your funder can close the monitoring, and you can delete your account straight afterwards. We tell you which funder it is and what would release it.
We keep a record of the consents you gave and withdrew, and of the fact that the account was deleted. We are required to keep these, and they contain no details of your business.
How we protect it
Regulated identifiers such as NIN, BVN and account details are encrypted at rest. Access is limited by strict tenant isolation, so one customer can never read another’s data. Traffic to and from the platform is encrypted in transit.
Where your information is held
Some of our service providers store data outside Nigeria. Where information is transferred abroad we take steps to ensure it is protected to the standard the NDPA requires.
How long we keep it
We keep your information while your account is active and for as long as a certificate issued to your business remains verifiable, then for any period the law requires us to retain records. If you close your account or ask us to delete your data, we remove it promptly except where we are legally required to keep it.
Your rights
Under the NDPA you can ask us to access, correct or delete your information, restrict or object to its use, receive a copy in a portable form, or withdraw a consent at any time (withdrawing consent stops future processing; it does not undo checks already run). Contact us at legal@acreedinsights.com — and you also have the right to complain to the Nigeria Data Protection Commission.
Questions: legal@acreedinsights.com