1. Introduction

Tabs and Co LTD trading as “Tabs Global” (“Tabs Global”, “we”, “us”, or “our”) is a company incorporated under the laws of the Federal Republic of Nigeria. We provide financial technology infrastructure and payment services to enterprise and business customers.

This Privacy Policy (“Policy”) explains how we collect, use, store, share and protect personal data when you:

  • access our website (www.tabsglobal.com);
  • use our products or services; or
  • interact with us as a client, prospective client, partner, supplier, or authorised representative of a business customer.

For the purposes of applicable data protection laws, including the Nigeria Data Protection Act, 2023 (“NDPA”), Tabs Global acts as a data controller, unless it explicitly acts as a data processor on behalf of a customer under a separate written agreement.

Where we process personal data of individuals located in the United Kingdom or the European Union in connection with cross-border transactions, we also comply with the UK General Data Protection Regulation (“UK GDPR”) and the EU General Data Protection Regulation (“GDPR”), as applicable, in addition to our obligations under the NDPA.

We may update this Policy from time to time. Material changes will be notified via email. Previous versions are available on request.

2. Scope of this policy

This Policy applies to personal data relating to:

  • authorised users and representatives of our business customers;
  • counterparties, beneficiaries, or payees where relevant to payment processing;
  • visitors to our website; and
  • business contacts, partners, and suppliers.

Nothing in this Policy is intended to limit any rights available to individuals under applicable data protection legislation in their jurisdiction of residence.

Where Tabs Global processes personal data on behalf of a customer in its capacity as a data processor, such processing is governed by a separate data processing agreement or equivalent contractual arrangement between Tabs Global and the relevant customer.

Our services are designed for business use and are not directed at individuals under 18 years of age.

3. Information we collect

We may collect and process the following categories of personal data:

3.1 Information you provide

  • Name, job title, and business contact details
  • Company name and business address
  • Identification and verification information required for compliance, which may include government-issued identification documents (including Bank Verification Number (BVN) and National Identification Number (NIN) where applicable), proof of residential or business address, Corporate Affairs Commission (CAC) registration and constitutional documents, and beneficial ownership or control information, as required under applicable KYC, AML and sanctions laws
  • Communications with us (emails, calls, and support correspondence)

3.2 Information we collect automatically

  • IP address and device identifiers
  • Log and access records relating to use of our services
  • Website usage data collected through cookies or similar technologies

3.3 Information from third parties

We may receive personal data from third parties in connection with the provision of our services and our compliance with applicable laws. This may include:

  • compliance, screening, and verification data from sanctions screening providers, politically exposed persons (PEP) and watchlist databases, adverse media and risk intelligence services and other regulated or reputable third-party compliance service providers;
  • information received from financial institutions, payment networks, clearing partners, or other payment service providers involved in the processing or settlement of transactions; and
  • personal data provided by business customers relating to their authorised users, counterparties, beneficiaries, or payees, where necessary to perform contracted services.

Such data is processed only for the purposes described in this Policy.

4. How we use personal data

We process personal data for the following purposes:

  • providing, operating and maintaining our services;
  • onboarding customers and authorised users, including identity verification through BVN, NIN, and other national verification systems in line with applicable Central Bank of Nigeria (CBN) requirements;
  • complying with legal and regulatory obligations, including financial crime prevention;
  • processing, reconciling and settling transactions;
  • detecting, preventing, and investigating fraud, misuse or security incidents;
  • communicating with customers and authorised representatives;
  • improving and developing our services, systems and infrastructure; and
  • establishing, exercising or defending legal claims.

We may use automated processing and analytical tools, including transaction monitoring, risk scoring and sanctions screening systems, to support the purposes described above. These systems are used to assist decision-making and are subject to appropriate human review and oversight.

Tabs Global does not make decisions based solely on automated processing that produce legal or similarly significant effects on individuals, except where permitted by applicable law.

5. Legal bases for processing

We process personal data only where permitted by law, including where processing is necessary for:

  • performance of a contract with our customers;
  • compliance with legal obligations, including regulatory and supervisory requirements;
  • legitimate interests, such as service improvement, business continuity, and security; and
  • consent, where required under applicable law (for example, certain marketing activities).

For completeness, we process personal data as necessary to maintain system security, detect and respond to incidents, investigate suspected misuse and comply with regulatory and legal obligations, including through logging, monitoring and incident response activities.

6. Data location and international processing

Tabs Global is headquartered in Nigeria. Data may also be accessed and processed by our personnel or service providers based in other jurisdictions in which our staff or vendors operate, for operational, compliance and support purposes.

The NDPA restricts the transfer of personal data outside Nigeria unless the transfer is made under a mechanism recognised by the NDPA, including an adequacy decision, binding corporate rules, a code of conduct, a certification mechanism, contractual clauses offering an equal or adequate level of protection, or the data subject’s consent. Where we transfer personal data outside Nigeria, we document the legal basis for the transfer and the safeguards applied, and, where required, notify the Nigeria Data Protection Commission (NDPC) of the measures in place.

We implement appropriate safeguards to ensure that personal data remains protected when accessed across jurisdictions, including contractual, technical, and organisational measures.

Where required under Article 27 of the UK GDPR or EU GDPR because we process personal data of individuals located in the UK or EU, Tabs Global has appointed representatives. Data subjects may contact Tabs Global or its UK or EU representatives (where appointed) regarding matters related to the processing of personal data.

Representative details for the United Kingdom and the European Union are available on request from legal@tabsglobal.co.

7. Sharing of personal data

We may share personal data with:

  • regulated financial institutions and payment partners involved in transaction processing;
  • partner banks, payment institutions, or other regulated financial counterparties in the jurisdictions in which transactions are initiated, processed, or settled;
  • compliance, identity verification and fraud-prevention service providers;
  • professional advisers, including legal, audit and accounting firms;
  • the Central Bank of Nigeria (CBN), the Nigeria Data Protection Commission (NDPC), the Nigerian Financial Intelligence Unit (NFIU), other regulators, courts, or law enforcement authorities where legally required; and
  • other entities within the Tabs Global group, and service providers acting under contractual obligations of confidentiality and data protection.

We do not sell personal data or share it for third-party marketing purposes.

8. Data security

We maintain appropriate technical and organisational security measures designed to protect personal data against unauthorised access, loss, misuse or alteration, including:

  • access controls and role-based permissions;
  • encryption and secure communications protocols;
  • monitoring and logging of system activity; and
  • periodic security reviews and risk assessments.

These measures are supported by internal information security policies, employee training, and incident response procedures designed to protect the confidentiality, integrity and availability of personal data.

In the event of a personal data breach likely to result in a risk to the rights and freedoms of data subjects, we will notify the NDPC without undue delay and, where feasible, within 72 hours of becoming aware of the breach, and will notify affected data subjects where required under the NDPA.

Access to personal data is restricted to personnel who require it for legitimate business purposes.

9. Data retention

We retain personal data only for as long as necessary to:

  • fulfil the purposes described in this Policy;
  • comply with legal, regulatory and accounting requirements; and
  • resolve disputes or enforce contractual obligations.

Retention periods vary depending on the nature of the data and applicable legal requirements. Certain personal data may be retained for longer periods where required under applicable financial services, anti-money laundering, sanctions, tax or accounting laws in applicable jurisdictions. In such cases, data will be retained only for the minimum period required by law. As a general guide, and in accordance with the Money Laundering (Prevention and Prohibition) Act, 2022 and applicable CBN AML/CFT regulations, transaction records, customer due diligence materials, and know-your-customer documentation are typically retained for a minimum of five (5) years following the end of the relevant business relationship or completion of the transaction.

10. Your rights

Subject to applicable law, including the NDPA, you may have the right to:

  • be informed about how your personal data is processed;
  • access personal data held about you;
  • request correction of inaccurate or incomplete personal data;
  • request deletion of personal data, subject to legal and regulatory retention obligations;
  • restrict or object to certain processing activities, including processing based on legitimate interests;
  • withdraw consent at any time, where processing is based on consent;
  • request data portability, where applicable; and
  • not be subject to decisions based solely on automated processing, where such decisions produce legal or similarly significant effects, except as permitted by law.

Depending on your location, you may lodge a complaint with:

  • the Nigeria Data Protection Commission (NDPC);
  • the Information Commissioner’s Office (ICO) in the United Kingdom, where the UK GDPR applies; or
  • the relevant supervisory authority in an EU Member State, where the GDPR applies.

We encourage you to contact us first so we can address concerns promptly and transparently.

11. Cookies

Our website uses cookies and similar technologies to ensure the website functions properly, to maintain security, and to analyse how the website is used. Cookies are small text files that are placed on your device when you visit a website. We use both strictly necessary cookies and analytical cookies.

Strictly necessary cookies are required for the operation of our website and cannot be disabled through our systems. These cookies are used, for example, to enable core functionality, maintain security, and prevent fraudulent activity.

Analytical cookies help us understand how visitors interact with our website by collecting information such as pages visited, time spent on the site, and error messages. This information is used only to improve website performance and user experience.

Where required by applicable law, we will obtain your consent before placing non-essential cookies on your device. You can manage or withdraw your cookie preferences at any time through your browser settings or through any cookie preference tool made available on our website.

Further information about cookies, including how to control or delete them, is available through your browser’s help function.

12. Contact us

If you have questions about this Policy or wish to exercise your data protection rights, please contact:

Tabs and Co LTD (trading as Tabs Global)
EMAIL legal@tabsglobal.co
REGISTERED OFFICE Lekki, Lagos, Nigeria