Summary: DebtRecovery.ng is committed to protecting the privacy of all individuals whose data we process — including institutional clients, their borrowers, and visitors to this website. This policy explains what data we collect, why we collect it, and your rights under the Nigeria Data Protection Regulation (NDPR) 2019.
01
Who We Are
DebtRecovery.ng is a professional debt recovery and portfolio management company registered and operating in Nigeria. We provide tele-collections, field recovery, legal enforcement, asset tracing, and related services to banks, microfinance institutions, fintech companies, and other lending institutions across all 36 states and the FCT.
For the purposes of Nigerian data protection law, DebtRecovery.ng acts as both a Data Controller (for data collected directly through this website and from clients) and a Data Processor (when processing borrower data on behalf of our lending institution clients).
02
Data We Collect
From website visitors and enquirers:
- Name, email address, phone number, and company/institution name (submitted via our contact form)
- Messages and enquiry details you choose to provide
- Technical data: IP address, browser type, pages visited, time on site (via cookies — see Section 10)
From lending institution clients (via service agreements):
- Borrower contact details (name, phone, address) as provided in portfolio handoff files
- Loan account information (outstanding balance, due dates, product type)
- Communication history relevant to recovery activities
We do not collect: passwords, payment card details, or sensitive personal data (health, religion, political views) unless explicitly required and agreed in writing for a specific service.
03
How We Use Your Data
We use data collected through this website to:
- Respond to enquiries and service requests submitted via our contact form
- Communicate with prospective and existing institutional clients about our services
- Send service updates, regulatory insights, and recovery-related communications (only with your consent)
- Improve this website's performance and user experience
We use borrower data provided by our lending institution clients to:
- Conduct authorised debt recovery activities on behalf of the client institution
- Contact borrowers through agreed channels (phone, SMS, field visits) using CBN-compliant scripts
- Record and report recovery activities to the client institution
- Comply with applicable Nigerian law, court orders, or regulatory instructions
04
Legal Basis for Processing
Under the NDPR 2019, we process personal data on the following lawful grounds:
- Contractual necessity — processing required to fulfil our service agreements with lending institution clients
- Legitimate interests — processing for enquiry management, client communication, and website improvement, where this does not override individual rights
- Legal obligation — processing required to comply with Nigerian law, CBN regulations, or court orders
- Consent — for marketing communications, where you have specifically opted in
For borrower data processed on behalf of lending institution clients, the lawful basis rests with the client's existing lending agreement with the borrower, and our Data Processing Agreement with the client institution.
05
Data Sharing
We do not sell personal data to any third party. We may share data in the following limited circumstances:
- With lending institution clients — recovery activity reports, contact logs, and case outcomes relating to their own borrower portfolios
- With accredited law firm partners — when a debt is escalated to legal enforcement, under a formal data processing agreement
- With licensed field agents — name and contact address only, for the purpose of authorised field visits, under strict confidentiality obligations
- With regulatory authorities — when required by Nigerian law, the CBN, NITDA, or a court of competent jurisdiction
- With IT and cloud service providers — who process data on our behalf under binding agreements and NDPR-compliant data processing terms
All third parties who access personal data on our behalf are required to maintain appropriate security measures and may only process data for the specific purposes we have authorised.
06
Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected:
- Website enquiry data — up to 24 months from last contact, or until you request deletion
- Active client and case data — for the duration of the service engagement plus 7 years, in accordance with Nigerian financial record-keeping requirements
- Borrower recovery data — for the period agreed in our Data Processing Agreement with the client institution, typically not exceeding 7 years from case closure
- Website analytics — aggregated and anonymised after 26 months
When data is no longer required, it is securely deleted or anonymised.
07
Your Rights
Under the NDPR 2019, individuals whose data we process have the following rights:
- Right to access — request a copy of personal data we hold about you
- Right to correction — request correction of inaccurate or incomplete data
- Right to erasure — request deletion of your data, subject to legal retention obligations
- Right to object — object to processing based on legitimate interests or for direct marketing
- Right to restrict processing — request that we limit how we use your data while a dispute is resolved
- Right to data portability — receive your data in a structured, machine-readable format
- Right to withdraw consent — at any time, where processing is based on your consent
To exercise any of these rights, contact our Data Protection Officer using the details in Section 12. We will respond within 30 days. If you believe your rights have been violated, you may also lodge a complaint with NITDA (National Information Technology Development Agency), Nigeria's data protection supervisory authority.
08
Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, or disclosure. These measures include:
- Encrypted data transmission (HTTPS/TLS) across all web-facing systems
- Access controls limiting data access to authorised personnel only
- Staff training on data protection obligations and CBN conduct guidelines
- Periodic security reviews and vulnerability assessments
- Secure data destruction procedures when retention periods expire
While we take all reasonable precautions, no data transmission over the internet is completely secure. If you believe your data has been compromised, please contact us immediately.
09
Third-Party Links
This website may contain links to third-party websites (including payment providers, regulatory bodies, or partner platforms). We are not responsible for the privacy practices of those websites and encourage you to review their privacy policies before submitting any personal data.
10
Cookies
This website uses cookies — small files stored on your device — to improve your browsing experience. We use:
- Essential cookies — necessary for the site to function (e.g., session management). Cannot be disabled.
- Analytics cookies — to understand how visitors use our site and identify areas for improvement. You may opt out via your browser settings.
- Preference cookies — to remember your choices (e.g., blog view preference). These are stored locally and not transmitted to our servers.
You can control cookie settings in your browser at any time. Disabling cookies may affect some site functionality.
11
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable Nigerian law. Where changes are material, we will notify active clients directly. The date of the most recent revision is always shown at the top of this page.
Continued use of our services after any changes takes effect constitutes your acceptance of the revised policy.