Skip to main content

Elemoni – Your Smart Loan Solution

Privacy Policy

Last updated August 2026

Introduction

Elemoni Limited [“Elemoni”] is a financial services organisation offering lending and finance. In line with emerging regulatory requirements mandating transparency and accountability in data handling, Elemoni is committed to safeguarding the rights and privacy of all individuals whose data it processes. 

Elemoni processes Personal Data relating to potential clients, existing clients, employees [including applicants, current and former staff ], contractors, vendors, website and application users, and other business contacts (“Data Subjects”).

This Policy formalizes Elemoni’s commitment to compliance with the NDPR 2019 and outlines our principles for collecting, using, storing, and securing Personal Data. It seeks to:

a) Ensure clarity on how Personal Data must be processed and Elemoni’s expectations
for those acting on its behalf.
b) Comply with applicable Data Protection Laws and recognised best practices.
c) Protect our reputation by safeguarding the rights and privacy of Data Subjects.
d) Prevent risks associated with Personal Data breaches and non-compliance.

PERSONAL DATA PROTECTION PRINCIPLES

Elemoni adheres to the following principles as prescribed by the NDPC:
a. Process lawfully, fairly, and transparently.
b. Collect only for specified, explicit, and legitimate purposes.
c. Limit to what is adequate and necessary for the stated purposes.
d. Keep accurate and up-to-date.
e. Retain only for as long as necessary.
f. Ensure security through technical and organisational measures.
g. Guard against foreseeable hazards and fraud risks

CONSENT

Where no other Legal Basis exists, Elemoni shall obtain the Data Subject’s Consent
before processing.

  • Consent must be informed, freely given, specific, and expressed through affirmative
    action.
  •  Data Subjects shall be informed of their right to withdraw Consent at any time,
    without affecting the lawfulness of prior processing.
  • Consent shall be renewed when processing for purposes not initially disclosed.
  • No Consent will be sought or accepted for unlawful, harmful, or discriminatory
    purposes.
  • Elemoni shall seek Consent before transferring data to third parties.

Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the site or use our services.

Elemoni collects the following categories of information:

  • Personal Data such as name, age, email address, phone number, physical contact information, personal description, photograph, username, password, other registration information, and, depending on the service used, financial information such as Bank Verification Number, credit card or bank account details;
  • Transactional Information relating to the Data Subject’s activities on the applications provided by Elemoni [the “App”], including products or services purchased, content generated by the Data Subject or linked to their account, billing details, and other information provided in connection with service requests;
  • Personal Information provided through information pages, correspondences, chats, complaints, customer service channels, or obtained from other social media applications or services;
  •  Verification Data requested as part of Elemoni’s verification process [e.g., identification documents, utility bills to confirm address, or responses to additional questions to verify identity];
  • Third-Party Data obtained from lawful sources such as demographic information, navigation data, credit check reports, or additional details from credit bureaus;
  • Device and Interaction Data including device ID, device type, unique device identifiers, geo-location information, operating system, connection details, page view statistics, IP address, and standard web log data;
  • Stored Device Information such as contact lists, call logs, SMS logs, social media contacts, photographs, videos, or other digital content;
  •  App Usage Data including details of visits to the App, traffic data, location data, weblogs, and other communications data

Elemoni may collect or be provided with the above information through:

  • completion of forms on the App;
  • correspondence via email, chat, or other channels;
  • registration to use the App;
  • subscription to any Elemoni service;
  • sharing of data through the App’s social media features;
  • participation in competitions, promotions, or surveys;
  • reporting of issues relating to the App or Elemoni’s services

Communications sent by users to Elemoni [via email or other means] may be retained to process inquiries, respond to requests, and improve services. When customers access Elemoni’s services, Elemoni’s servers automatically record information sent by the user’s browser when visiting a website.

Elemoni collects the above information to provide the Data Subject with access to the App and services, and to ensure a seamless and efficient user experience. Such information may be used to:

  •  assesses creditworthiness and determine credit limits;
  •  provide access to the App, services, and customer support;
  • resolves complaints and disputes, recover debts, and troubleshoot issues;
  • prevents, detect, and investigate prohibited or unlawful activities and enforce
    Elemoni’s Terms and Conditions;
  • customise, measure, and enhance content, advertising, and services;
  •  informs the Data Subject about services, deliver targeted marketing, updates, and promotional offers based on preferences;
  • verifies information for accuracy and confirm details with third parties;
  • contacts the Data Subject via authorised telephone numbers;
  • provides any other services requested as stated at the point of data collection.

Prior to collecting Personal Data, Elemoni shall provide the Data Subject with the following information as stated in its Privacy and Security Policy:

  •  Elemoni’s identity and contact details;
  • the email address of the Data Protection Officer [DPO];
  • the purposes and legal basis for processing the Personal Data;
  • the legitimate interests pursued by Elemoni or any authorised third party;
  • the recipients or categories of recipients of the Personal Data [if any];
  • where applicable, notice of transfer to a foreign or third country and the existence or absence of an adequacy decision by NITDA;
  • the Data Subject’s rights to access, rectify, erase, restrict processing, object to
    processing, and to data portability;
  • the right to withdraw consent at any time by uninstalling the App, without affecting prior lawful processing;
  • the right to lodge a complaint with NITDA or any other relevant authority;
  • whether provision of Personal Data is statutory, contractual, or necessary to enter into a contract, and the possible consequences of failure to provide such data;
  • where further processing for a new purpose is intended, prior notice of such purpose and any relevant information.
  • Personal Data must be accurate and, where necessary, kept up to date.
  • Personal Data shall be recorded in the appropriate files.
  • Incomplete records can lead to inaccurate conclusions; the Data Subject shall ensure
    that all relevant records are complete and accurate where applicable.
DATA PROCESSING

Elemoni shall ensure that all Personal Data processing activities are conducted lawfully

Processing shall be deemed lawful where at least one of the following conditions applies:

  • The Data Subject has given explicit consent for the processing of their Personal Data for one or more specific purposes;
  •  Processing is necessary for the performance of a contract to which the Data Subject is a party, or for taking steps at the Data Subject’s request prior to entering into a
    contract;
  • Processing is necessary to comply with a legal obligation to which Elemoni, as the Controller, is subject;
  • Processing is necessary to protect the vital interests of the Data Subject or another natural person; or
  • Processing is necessary for the performance of a task carried out in the public interest or in the exercise of an official mandate vested in Elemoni.
DATA SUBJECTS’ RIGHTS

Data Subjects have enforceable rights in relation to how Elemoni handles their
Personal Data. These rights include the following:

  • Where the legal basis for processing is consent, withdraw such consent for further processing by uninstalling the Elemoni application;
  • Object to the processing of Personal Data in limited circumstances;
  • Request rectification of inaccurate data or completion of incomplete data;
  • Restrict processing in specific situations, such as where there is a valid dispute concerning accuracy;
  • Not be subject to decisions based solely on automated processing, including profiling, except where necessary for entering into or performing a contract with Elemoni,
    explicitly consented to by the Data Subject, or authorised by law and subject to appropriate safeguards;
  • Prevent processing likely to cause damage or distress to the Data Subject or others;
  • Receive notification of a Personal Data breach where such breach is likely to result in a high risk to their rights and freedoms;
  • Lodge a complaint with NITDA or any other relevant regulatory authority;
  • Request access to, and deletion of, Personal Data held by Elemoni; and
  • Exercise any other rights granted under applicable Data Protection Laws
REQUESTS
  • Elemoni shall take appropriate measures to provide any information relating to data processing in a concise, transparent, intelligible, and easily accessible format, using
    clear and simple language, especially where the information is directed to a child.
  • Information may be provided through electronic means.
  • Elemoni shall verify the identity of any individual making a data-related request.
    Where there is reasonable doubt as to the requester’s identity, Elemoni may require additional information necessary to confirm identity.
  • All Data Subject requests shall be immediately forwarded to the Data Protection Officer at dpo@elemoni.com.
  • Information provided to a Data Subject, as well as related communications or actions taken, shall be provided free of charge. However, where a request is manifestly unfounded or excessive,particularly due to its repetitive nature, Elemoni may:
    a. Charge a reasonable fee based on administrative costs; or
    b. Issue a written refusal to act on the request, copying NITDA on every such occasion.
  • Elemoni shall not allow third parties to obtain a Data Subject’s Personal Data without proper authorisation. For example, spouses do not have automatic access to their partner’s data, and parents do not have automatic access to their child’s data unless permitted under law.
  •  Elemoni shall not alter, conceal, block, or destroy Personal Data once a request for access has been made. The Data Subject shall first contact info@elemoni.com before any changes are made to Personal Data subject to an access request.
  • Elemoni is subject to the Data Subject’s consent and applicable privacy laws when advertising to existing clients, potential clients, and any other potential users of our services. If such individuals wish Elemoni to stop sending marketing messages or modify their preferences, they may do so by:
    a. Clicking the opt-out link in any marketing message sent;
    b. Using the notification switch-off feature in the application settings;
    c. Contacting us at any time via info@elemoni.com.
    Where an individual opts out of receiving marketing messages, this will not affect the processing of their Personal Data for legitimate service-related purposes.
DATA SECURITY

Elemoni shall implement and maintain appropriate administrative, technical, and physical safeguards to protect Personal Data, taking into account the risks to Data Subjects arising from unauthorised or unlawful Processing, as well as from accidental loss, destruction, or damage to such data.

Recognising the critical importance of data security, Elemoni shall:

  •  develops and enforce security measures, including but not limited to, protecting systems from hacking attempts;
  • set up firewalls and implement robust email protection systems;
  • store data securely, with access granted only to specifically authorised individuals;
  • utilize encryption technologies to protect stored and transmitted data;
  •  maintains and enforce organisational policies for handling personal and other
    sensitive or confidential data; and
  • provides continuous training and capacity building for all staff members.

Elemoni shall comply with all applicable provisions of this Policy and shall not attempt to circumvent the administrative, physical, or technical safeguards implemented in accordance with applicable Data Protection Laws and standards.

REPORTING A PERSONAL DATA BREACH

Elemoni shall report any Personal Data Breach where there is a risk to the rights and freedoms of a Data Subject. Appropriate internal procedures shall be in place to manage suspected breaches, and notifications shall be made to Data Subjects and/or relevant regulatory authorities as legally required. Elemoni shall not be liable for any Personal Data Breach resulting from:

  • events beyond Elemoni’s reasonable control, including but not limited to:
    i. acts of God [e.g., fires, explosions, earthquakes, floods, droughts, tidal waves];
    ii. acts or threats of terrorism;
    iii. war, invasion, acts of foreign enemies, mobilisation, requisition, or embargo;
    iv. rebellion, revolution, insurrection, military or usurped power, or civil war;
  •  the transfer of a Data Subject’s Personal Data to a third party at the Data Subject’s instruction;
  • the use of a Data Subject’s Personal Data by any third party designated by the Data Subject; and
  •  incorrect or outdated Personal Data provided by the Data Subject during their use of Elemoni’s services.
TRANSFER TO A FOREIGN COUNTRY AND LIMITATIONS ON THE TRANSFER OF PERSONAL DATA
  • Elemoni shall comply with the Regulation, and any transfer of Personal Data: whether undergoing processing or intended for processing after transfer to a foreign country or an international organisation shall be subject to the provisions of the Regulation.
  • Where a Data Subject’s Personal Data is to be transferred to a country outside Nigeria, Elemoni will implement adequate measures to ensure the security of such data. In particular, Elemoni will conduct a detailed assessment to determine whether the destination country is included in the NITDA White List of countries with adequate
    data protection laws.
  • If the destination country is not on the White List, Elemoni will only transfer Personal Data out of Nigeria under one of the following conditions:
    a. The Data Subject’s consent has been obtained;
    b. The transfer is necessary for the performance of a contract between Elemoni and the Data Subject, or for the implementation of pre-contractual measures at the Data
    Subject’s request;
    c. The transfer is necessary for the conclusion of a contract between Elemoni and a third party in the interest of the Data Subject;
    d. The transfer is necessary for reasons of public interest;
    e. The transfer is required for the establishment, exercise, or defence of legal claims;
    f. The transfer is necessary to protect the vital interests of the Data Subject or other persons, where the Data Subject is physically or legally incapable of giving consent.
  • Provided that the Data Subject has been clearly informed through explicit warnings of the specific data protection principle[s] likely to be violated in the event of transfer to a third country, this provision shall not apply where the Data Subject is answerable in duly established legal proceedings for any civil or criminal claim in that third country.
  • Elemoni will take all necessary steps to ensure that any transfer of Personal Data is carried out in a safe and secure manner. Details of the protection measures in place for such transfers will be made available to the Data Subject upon request.
  • Where the recipient country is not on the White List and none of the conditions outlined above is met, Elemoni will seek approval from NITDA and the Office of the Honourable Attorney General of the Federation [HAGF] before effecting such transfer.
TRAINING AND AUDIT
  • Elemoni shall ensure that all employees undergo adequate training on Data Protection Laws. We shall also periodically test our systems and processes to asses the effectiveness of this Policy and our level of compliance.
  •  Elemoni will conduct data privacy-related training on a regular basis and will periodically review systems and processes under our control to ensure they comply with this Policy.
DIRECT MARKETING
  • Elemoni is subject to the Data Subject’s consent and applicable privacy laws when advertising to existing clients, potential clients, and any other potential users of our services. If such individuals wish Elemoni to stop sending marketing messages or modify their preferences, they may do so by:
    a. Clicking the opt-out link in any marketing message sent;
    b. Using the notification switch-off feature in the application settings;
    c. Contacting us at any time via info@elemoni.com.
    Where an individual opts out of receiving marketing messages, this will not affect the processing of their Personal Data for legitimate service-related purposes.
SHARING PERSONAL DATA
  • In the absence of consent, a legal obligation, or another lawful basis for processing, Personal Data will not generally be disclosed to third parties unrelated to Elemoni except for reports to credit bureaus or contact information shared with collections
    agencies if a user fails to meet loan obligations.
  • Without a court order, law enforcement agencies and their agents have no automatic right of access to Personal Data records. Voluntary disclosure may, however, be permitted for the prevention or detection of crime or for apprehending offenders. Data Subjects should refer law enforcement agents seeking such data to Elemoni’s Data Protection Officer.
  • Sharing Personal Data for research purposes may be permissible if appropriate safeguards are in place. For guidance or clarification, please contact the Data Protection Team at info@elemoni.com.
RETENTION OF RECORDS

Elemoni shall retain all Personal Data for a period of five (5) years, after which such information will be archived where necessary.

CHANGES TO THIS POLICY

Elemoni reserves the right to amend or update this Policy at any time without prior notice to the Data Subject.

Purpose

The purpose of this Policy is to ensure that necessary records and documents of Elemoni Limited [the “Company”] are adequately protected and maintained. It also ensures that
records no longer required are managed in accordance with the Central Bank of Nigeria [“CBN”] regulations and other applicable laws, rules, and regulations. This Policy aims to
assist employees in understanding their obligations regarding the retention of customer data and related documents

Policy

This Policy outlines Elemoni Limited’s approach to the retention and disposal of customer records/data and general Company documents.

Applicability

This Policy applies to all records generated in the course of the Company’s operations, including both original documents and reproductions

The Law

The CBN Anti-Money Laundering and Combating the Financing of Terrorism in Banks and Other Financial Institutions in Nigeria Regulations 2013 mandates that a financial institution shall maintain all necessary records of transactions for at least five [5] years after the completion of the transaction, or for a longer period as required by regulators. This requirement applies regardless of whether the account or business relationship is ongoing or has been terminated.

Nature of Records/Data

The records of transactions to be maintained by the Company include:

  •  Records of customers’ and beneficiaries’ names, addresses, or other identifying information normally recorded by the intermediary prior to entering a contract with
    the Company;
  • Nature and date of the transaction;
  • Type and amount of currency involved; and
  • Type and identifying number of any account involved in the transaction.

Mode of Preservation or Retention

Customer records or data shall be preserved and retained confidentially (subject to exceptions under applicable confidentiality laws), securely with access controls, and with
ease of retrieval, whether stored in-house or externally. Measures are implemented to ensure the physical security of records [where applicable], including the selection of a secure record room, firefighting devices, and access controls. Records may be maintained in electronic form. In the event of a switch to a new electronic system, all records from the old system must be migrated to the new system, ensuring accessibility of all historical records.

Request by the Authorities

Upon a request for customer records or data from applicable regulatory authorities, such as
the CBN, judicial, or law enforcement authorities [subject to the provision of a required
warrant], the Company shall ensure that all customer transaction records and information
are made available promptly to such authorities.

Destruction of Records/Data

All records or data generated in the course of the Company’s business activities that are not required to be retained must be safely destroyed or discarded as soon as practicable. Records/data may be destroyed at the end of the preservation period. The destruction process must preserve the confidentiality of any information contained within, if required. A record itemizing all destroyed records shall be maintained.

Responsibility

Department heads are responsible for monitoring the implementation of this Policy.

Policy Enforcement

Failure to comply with this Policy may result in disciplinary action against the concerned employee. Questions regarding the enforcement of this Policy should be directed to
Departmental Heads or the Head of Legal and Compliance of the Company.

Review and Amendment

This Policy shall be reviewed as needed to ensure compliance with applicable laws, rules, and regulations. Periodic reviews will be conducted, and amendments may be made as
deemed necessary.

Interpretation

In the event of any conflict between the provisions of this Policy and any applicable laws or regulations, such laws or regulations shall prevail. Any subsequent amendments or
modifications to such laws or regulations shall automatically apply to this Policy. For any clarification regarding this Policy, kindly contact the Compliance team.