Overview
Africa Acquisition Limited ("Africa Acquisition", "we", "us") operates the acquisition marketplace at africaacquisition.com. We are bound by the Nigeria Data Protection Regulation (NDPR) 2019, the Nigeria Data Protection Act (NDPA) 2023, Kenya's Data Protection Act 2019, South Africa's POPIA, Ghana's Data Protection Act 2012, and Egypt's PDPL, across the jurisdictions we operate in.
This Policy applies to all users: buyers browsing listings, sellers listing businesses, visitors to our website, and applicants to list or transact through our platform.
We act as data controller for data processed in connection with your account. Where we process data on behalf of sellers or buyers (for example, in data room document storage), we act as data processor under their instruction.
Information we collect
What you provide directly
- Account data: name, email address, phone number, password
- Profile data: professional background, company name, country of residence
- KYC documents: government-issued ID, business registration (CAC, RDB, CIPC, etc.), bank statements, utility bills
- Seller data: business descriptions, financial statements, traffic analytics, customer data, and legal documents uploaded to data rooms
- Communications: messages sent via our platform messaging system
- Payment data: bank account details for escrow (processed by Paystack or Stripe — we never store full card numbers)
- Survey responses, support tickets, and voluntary feedback
Collected automatically
- Log data: IP address, browser type, operating system, referring URLs, pages visited, time on page
- Device data: device type, screen resolution, operating system version, unique device identifiers
- Usage patterns: features used, listings viewed, NDA requests made, search queries
- Performance data: page load times, errors, platform health signals
From third parties
- Identity verification partners: results of KYC checks
- Payment processors: transaction confirmations, payment status, fraud signals (Paystack, Stripe)
- Business registries: company status from CAC, RDB, CIPC, and equivalents
- Google Sign-In: name, email, and profile picture if you sign in via Google OAuth
How we use your data
We process your data only where we have a lawful basis to do so.
| Data category | Purpose | Legal basis |
|---|---|---|
| Account data | Creating and managing your account, authentication | Contract |
| KYC documents | Identity verification, Trust Badge, AML compliance | Legal obligation |
| Listing data | Publishing listings, enabling data rooms, buyer matching | Contract |
| Transaction data | Escrow processing, fund release, invoices | Contract |
| Usage analytics | Improving features, personalising matching | Legitimate interest |
| Communication data | Deal notifications, support responses | Contract / Consent |
| Marketing data | Weekly market digest (opt-in only) | Consent |
| Fraud signals | Detecting fraudulent listings and payments | Legitimate interest |
Specifically, we use your data to:
- Create and maintain your buyer or seller account
- Verify your identity and business credentials through KYC
- Display listings to qualified buyers and match you with acquisition opportunities
- Facilitate the full deal pipeline: NDA signing, due diligence, LOI, escrow, and close
- Send transactional emails (deal updates, payment confirmations, KYC status) — these cannot be opted out of while your account is active
- Send marketing communications only with your explicit consent
- Detect and prevent fraud, money laundering, and misrepresentation
- Comply with legal and regulatory obligations, including AML and financial regulations
- Improve platform features and our buyer-matching algorithm
- Resolve disputes through our mediation process
Security
Technical measures
- All data in transit encrypted with TLS 1.3+
- Data at rest encrypted with AES-256 on AWS infrastructure
- KYC documents stored in access-controlled, encrypted S3 buckets
- Data room documents are watermarked and access is logged per document
- Production database access requires multi-factor authentication
- Quarterly third-party penetration tests; critical findings resolved within 48 hours
Organisational measures
- Data access restricted to team members who need it (least privilege principle)
- Annual data protection and security training for all staff
- Data Processing Register maintained and reviewed quarterly
- Incident response plan in place; affected users notified within 72 hours of a breach
Data retention
We retain your data as long as needed to provide our services, comply with legal obligations, resolve disputes, and enforce our agreements.
| Data category | Purpose | Legal basis |
|---|---|---|
| Account data | Account duration + 3 years after deletion | Legal obligation |
| KYC documents | 7 years from last transaction (AML) | Legal obligation |
| Transaction records | 7 years from completion (tax/audit) | Legal obligation |
| Data room documents | As agreed; default 2 years post-close | Contract |
| Platform messages | 2 years after last message in thread | Legitimate interest |
| Usage analytics | 26 months (GA default) | Legitimate interest |
| Marketing consent | Until unsubscribed or consent withdrawn | Consent |
| Support tickets | 2 years after resolution | Legitimate interest |
After account deletion, we anonymise or delete personal data within 30 days, except where legal retention obligations apply (KYC and transaction records under AML law).
Your rights
Under the NDPR, NDPA, and equivalent laws across our operating jurisdictions, you have the following rights:
Right of access
Request a copy of all personal data we hold about you, including categories, sources, and purposes.
Right to rectification
Require correction of inaccurate or incomplete personal data without undue delay.
Right to erasure
Request deletion where we no longer have a lawful basis. Some data must be retained for legal compliance.
Right to restrict processing
Ask us to limit how we use your data while you contest its accuracy or object to processing.
Right to data portability
Receive your data in a structured, machine-readable format for transfer to another provider.
Right to object
Object to processing based on legitimate interests, including for marketing or profiling.
Right to withdraw consent
Where processing is based on consent, withdraw it at any time without affecting past processing.
Right to complain
Lodge a complaint with the NDPC or the relevant supervisory authority in your country.
To exercise any right, email privacy@africaacquisition.com. We respond within 30 calendar days. Identity verification may be required for sensitive requests.
Third-party services
These third-party services are integrated into our platform. Each has its own privacy policy:
International transfers
Africa Acquisition operates across 15+ countries and uses service providers in the United States and European Union. When transferring personal data internationally, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses (SCCs) approved by relevant data protection authorities
- Adequacy decisions where recognised by applicable law
- Data processing agreements with all international service providers containing NDPR-compliant transfer mechanisms
- Compliance with NDPC guidance on cross-border transfers, including any notification or approval requirements
Children's privacy
Our services are not directed at individuals under 18. We do not knowingly collect personal data from minors. If you are under 18, do not create an account or submit personal information through our platform.
If we become aware we have collected data from a person under 18 without verifiable parental consent, we will immediately delete that information. Please contact privacy@africaacquisition.com if you believe we may have collected data from a minor.
Policy changes
We may update this Privacy Policy to reflect changes in our practices, technology, or legal requirements. For material changes — those significantly affecting your rights or how we process your data — we will:
- Send an email notification to all registered users at least 14 days before the change takes effect
- Display a prominent notice on the platform for 30 days after the change
- For changes requiring re-consent, request your explicit consent before processing under new terms
Continued use of our platform after a revised policy's effective date constitutes acceptance. If you disagree with a material change, you may request deletion of your account before it takes effect.
Contact & Data Protection Officer
Data Protection Officer
privacy@africaacquisition.com
Legal enquiries
legal@africaacquisition.com
Postal address
Africa Acquisition Limited Victoria Island, Lagos, Nigeria
Regulatory authority
Nigeria Data Protection Commission (NDPC) www.ndpc.gov.ng
We aim to respond to all privacy requests within 30 calendar days. Complex requests may take up to 90 days; we will notify you of any extension.