Back

Onyx Marketplace Privacy Policy

Onyx Marketplace is operated by Sapphire Virtual Network Limited and 4 Core Integrated Services Limited, Nigerian Companies committed to safeguarding personal information in compliance with the Nigeria Data Protection Act (NDPA) 2023.

Effective Date: [To be determined] | Last Updated: [To be determined]

This Privacy Policy explains how we collect, use, store, share, protect, and manage personal information belonging to Buyers, Vendors, prospective customers, and users of the Onyx platform.

By accessing or using Onyx (website, mobile application, Vendor Dashboard, or APIs), you consent to the practices outlined in this Policy.

1. SCOPE OF THIS PRIVACY POLICY

This Privacy Policy applies to all individuals and entities that access or interact with the Onyx Marketplace platform, including:

  • Buyers who purchase or intend to purchase products or services listed on Onyx
  • Vendors and business partners who list, promote, or sell products on the platform
  • Users who browse, search, or interact with the website, mobile application, or any other digital interface
  • Buy Now Pay Later (BNPL) or installment financing users
  • Third-party service providers and partners, such as logistics providers, lenders, identity verification partners, payment processors, and fraud-prevention partners

This Policy governs all categories of personal and business data collected through Onyx' digital infrastructure, including account registration, payment transactions, vendor verification, product transactions, customer support, and automated data collection technologies.

2. WHAT DATA WE COLLECT

Onyx collects and processes personal and business information necessary to operate the marketplace, verify user identities, fulfill transactions, and comply with legal obligations:

2.1 Identity & Contact Information

Full legal name, mobile phone number, email address, date of birth, residential or delivery address, and gender (optional).

2.2 Vendor & Business Information (KYB)

Registered business name, CAC registration or RC number, Tax Identification Number (TIN), business addresses, corporate contact details, identity documents of directors, and product certifications (NAFDAC, SONCAP, etc.).

2.3 Financial & Transactional Information

Tokenized payment card details, bank account details for Vendor payouts, wallet activity, transaction records including payments, refunds, disputes, and BNPL repayment records.

2.4 BNPL/Installment Financing Data

Bank Verification Number (BVN) when necessary, credit profile, income estimates, employment details, KYC documentation, and risk assessments.

2.5 Device & Technical Information

IP address, geolocation, device identifiers, browser type and version, operating system, mobile app activity, crash logs, cookies, and tracking pixels.

2.6 Behavioral & Analytics Data

Search queries, purchase history, user preferences, engagement logs, time spent on pages, and clickstream data.

2.7 Customer Support & Communications

Call recordings, chat transcripts, emails, complaint submissions, resolution logs, and public feedback or ratings.

3. HOW WE USE PERSONAL DATA

Onyx processes personal data for lawful, specific, and legitimate purposes:

3.1 Deliver Marketplace Services

Account creation and management, order processing, delivery and logistics operations, vendor settlements, and platform display functionality.

3.2 Identity Verification & Compliance

KYC/KYB verification, product and vendor compliance checks, and regulatory obligations under Nigerian law.

3.3 BNPL/Installment Financing

Credit eligibility assessment, lender interaction facilitation, repayment management, and fraud and identity protection.

3.4 Improve User Experience

Homepage and interface personalization, product recommendations, platform analytics, and performance and security optimization.

3.5 Marketing & Communications

Promotional messages, surveys and feedback requests, and targeted advertising. Users may opt out at any time via account settings.

3.6 Platform Safety, Security & Fraud Prevention

Fraud detection and monitoring, user protection, vendor monitoring and enforcement, and policy and legal enforcement.

4. LEGAL BASIS FOR PROCESSING DATA

Onyx processes personal data in accordance with the Nigeria Data Protection Act (NDPA), the Nigeria Data Protection Regulation (NDPR), and applicable laws:

4.1 Consent

For marketing communications, cookies and similar technologies, and optional data fields. Users may withdraw consent at any time.

4.2 Contract Performance

Processing necessary to fulfill contractual obligations including account management, order processing, payments, delivery, vendor settlements, and BNPL financing.

4.3 Legal Obligation

Compliance with NDPA, FCCPA, AML/CFT, Cybercrime laws, tax reporting, vendor verification, lawful government requests, and anti-fraud obligations.

4.4 Legitimate Interest

Platform safety and integrity, improving functionality, conducting analytics, preventing financial loss, and protecting users from security risks.

4.5 Public Interest or Legal Mandates

Processing required for public safety, fraud investigations, or responding to lawful government directives.

5. HOW WE SHARE PERSONAL DATA

Onyx does not sell or trade personal data. Data may only be shared with trusted third parties where necessary, with all parties bound by strict confidentiality obligations and NDPA-compliant processing terms:

5.1 Lenders / BNPL Partners

Limited personal and financial information shared for credit evaluation, repayment management, fraud detection, and regulatory compliance.

5.2 Logistics & Delivery Partners

Customer name, delivery address, phone number, and order details necessary for delivery operations only.

5.3 Vendors

Limited Buyer information to fulfill orders, process deliveries, provide post-purchase support, and handle warranties. Vendors are prohibited from contacting customers outside Onyx-approved channels.

5.4 Payment Processors

Secure, NDPA-compliant payment processors manage card transactions, direct debit mandates, wallet operations, and settlements. Full card details are tokenized and never stored on Onyx servers.

5.5 Regulatory & Government Authorities

Disclosures made where required by law, including NDPA, FCCPC, SON, NAFDAC, AML/CFT legislation, and valid court orders.

5.6 Technology & Infrastructure Providers

Cloud hosting, server and database providers, cybersecurity systems, analytics tools, and customer support technologies. These providers may only process data on Onyx' behalf.

6. COOKIE & TRACKING TECHNOLOGIES

Onyx uses cookies, pixels, tags, and similar tracking technologies to enhance user experience and optimize platform performance:

6.1 Types of Cookies We Use

  • Essential Cookies: Required for login, account management, shopping cart, and security
  • Performance & Analytics Cookies: Track page load times, monitor crashes, and analyze browsing patterns
  • Functional Cookies: Remember preferences like language settings and saved addresses
  • Advertising & Targeting Cookies: Support relevant promotions, retargeting, and campaign effectiveness

6.2 User Control Over Cookies

Users can accept all cookies, reject non-essential cookies, or manage categories via the Cookie Preference Center. Note that disabling certain cookies may affect platform functionality.

7. DATA RETENTION POLICY

Personal data is stored only as long as necessary to meet legitimate business, legal, and regulatory purposes in compliance with NDPR, Money Laundering (Prohibition) Act, FCCPA, and applicable laws:

Data CategoryRetention PeriodNotes
Financial & transactional recordsMinimum 5 yearsTax, AML, regulatory requirements
Vendor & Buyer account informationActive period + 2 yearsExtended if required by law or disputes
Customer support & complaintsResolution + 2 yearsDefense against claims or disputes
BNPL/Installment financing dataAgreement + regulatory periodCredit risk and repayment history
Cookies & analytics dataUp to 12 monthsPlatform optimization and personalization

Upon reaching the end of retention periods, data is securely deleted, anonymized, or archived with restricted access.

8. DATA SECURITY MEASURES

Onyx adopts a multi-layered security framework aligned with global best practices, NDPR requirements, and industry standards:

8.1 Encryption and Data Protection

TLS 1.2/1.3 protocols for in-transit encryption, strong encryption algorithms for data at rest, payment tokenization, and data masking and pseudonymization.

8.2 Access Management & Controls

Role-Based Access Control (RBAC), Multi-Factor Authentication (MFA), Principle of Least Privilege, and regular access reviews.

8.3 Monitoring, Threat Detection, and Logging

Continuous monitoring, audit logging, threat intelligence, and AI-driven threat detection systems.

8.4 Incident Response & Breach Management

Formalized Incident Response Plan, breach notification to affected parties and NITDA, post-incident analysis, and user support.

9. INTERNATIONAL DATA TRANSFERS

Onyx may transfer personal data outside Nigeria for cloud hosting, analytics, payment processing, and BNPL financing. All transfers are governed by NDPR 2023 and include:

  • Transfer Impact Assessments (TIAs) before international transfers
  • Standard Contractual Clauses (SCCs) and Data Processing Agreements (DPAs)
  • Data minimization and purpose limitation
  • Strong encryption for international transfers
  • Users maintain all NDPR rights even if data is processed outside Nigeria

10. USER RIGHTS UNDER NDPA 2023

Under the Nigeria Data Protection Act (NDPA 2023), all users are entitled to:

  • Right of Access: Request to view personal data held by Onyx
  • Right to Rectification: Request corrections to inaccurate or incomplete data
  • Right to Withdraw Consent: Withdraw consent for specific processing activities
  • Right to Deletion: Request permanent deletion of personal data where legally permissible
  • Right to Restrict or Object to Processing: Request temporary restriction or object to processing
  • Right to Data Portability: Request data transfer in machine-readable format
  • Right to Opt-Out of Direct Marketing: Opt out of promotional messages and advertisements
  • Right to Report Violations: Report data protection concerns to the Nigeria Data Protection Commission (NDPC)

11. CHILDREN'S PRIVACY

Onyx is committed to protecting the privacy and safety of minors:

  • Onyx does not knowingly collect personal data from individuals under 18 years of age
  • If data from a minor is inadvertently collected, it will be immediately deleted
  • Parents or guardians may contact Onyx to request deletion of child data
  • Vendors are prohibited from marketing to or collecting data from minors
  • Age verification is implemented during registration and checkout

12. DATA BREACH MANAGEMENT

In the event of a data breach, Onyx will:

  • Promptly assess the nature, scope, and potential impact
  • Implement immediate containment measures
  • Conduct thorough investigation and root cause analysis
  • Notify affected individuals and the Nigeria Data Protection Commission (NDPC) as required
  • Take corrective and remedial measures to prevent recurrence
  • Document all actions and maintain records for audit purposes

13. THIRD-PARTY LINKS & EXTERNAL SITES

Onyx may provide links to external websites or third-party services. Key points:

  • Onyx does not own, operate, or manage third-party sites
  • We are not responsible for the content, security practices, or privacy policies of external sites
  • Users should review the terms and privacy policies of third-party sites
  • Onyx shall not be liable for losses resulting from use of third-party sites

14. CHANGES TO THIS PRIVACY POLICY

Onyx reserves the right to revise, amend, or update this Privacy Policy at any time:

  • Updated versions will be published with a revised "Last Updated" date
  • Material changes will be communicated via email, in-app notifications, or dashboard alerts
  • Continued use of the platform after updates constitutes acceptance of the revised terms
  • Material changes may require explicit acknowledgment via the platform

15. CONTACT INFORMATION

For questions, concerns, or requests related to this Privacy Policy or data protection matters, contact us through:

Data Protection Officer (DPO)

  • DPO Email: dpo@Onyx.com — for official data protection and privacy matters
  • Support Email: support@Onyx.com — for general platform support and queries
  • Physical Address: [To be determined]

Onyx is committed to acknowledging all privacy-related inquiries promptly. Data rights requests will be processed in accordance with NDPA timelines and regulatory requirements.

Platform Operated By: Sapphire Virtual Network Limited and 4 Core Integrated Services Limited

By using the Onyx platform, you acknowledge that you have read, understood, and consented to the practices outlined in this Privacy Policy. Your continued use constitutes ongoing acceptance of these privacy practices.