Data Privacy Notice
Updated at:
1. Introduction & Data Privacy Notice
Growth and Development Asset Management Limited (operating through Growth and Development Asset Management Limited) ("we," "our," "us," or "the company") is a licensed financial institution operating in compliance with the Central Bank of Nigeria (CBN) and the Nigeria Data Protection Act 2023 (NDPA). Our mission is to provide quick, secure, and responsive financial services to individuals, NYSC members, employed youth, and small & medium scale enterprises (SMEs).
1.1 Why We Collect Your Personal Data
To deliver essential financial services, we collect and process certain personal data necessary to:
- Provide financial products, credit facilities, and investment services.
- Comply with legal and regulatory obligations under CBN, NDPA 2023, and AML/CFT guidelines.
- Enhance platform security, identity verification, and fraud prevention.
- Ensure operational efficiency and customer excellence.
We may use automated document processing technologies and trusted third-party service providers to extract and verify information from documents submitted during onboarding, identity verification, fraud prevention, and regulatory compliance (including BVN, NIN, utility bills, and bank statements). For privacy inquiries, contact our Data Protection Officer (DPO) at: dpo@pebbles.com.
1.2 Data Minimization Principle
We adhere strictly to the Data Minimization Principle, ensuring that we only collect and process personal data that is relevant, adequate, and limited to what is strictly necessary for specified purposes.
1.3 Your Trust is Our Priority
We are committed to:
- Safeguarding your information using advanced encryption and security controls.
- Ensuring complete transparency in how we collect, use, and share data.
- Empowering you with full control over your personal data under the NDPA 2023 and GDPR (where applicable).
2. About This Privacy Policy
This Privacy Policy outlines:
- What personal data we collect.
- Why we collect it and our lawful bases.
- How we store, process, and protect your data.
- How you can access, manage, rectify, or request deletion of your information.
3. Legal Framework & Scope
3.1 Legal Framework
This Privacy Policy is established in compliance with:
- Section 37 of the Constitution of the Federal Republic of Nigeria (CFRN) 1999 (as amended) – Guaranteeing the right to privacy.
- The Nigeria Data Protection Act (NDPA) 2023 – Governing personal data collection, processing, and storage.
- General Data Protection Regulation (GDPR) – Where applicable for international data subjects.
- CBN regulations and other applicable data privacy laws.
3.2 Scope of Policy
This policy applies to clients, platform users, job applicants, staff, vendors, and website visitors interacting with GDL+ or Growth and Development Asset Management Limited.
4. What We Do & Purpose of Data Collection
4.1 Loan & Credit Services
We offer customized credit solutions designed to meet personal and business financial needs.
Why We Need Your Data: To assess creditworthiness, verify identity, compute debt-to-income affordability, comply with lending regulations, and manage loan repayments.
4.2 Treasury & Investment Products
Investment and savings products structured to maximize returns securely.
Why We Need Your Data: To process investment applications, maintain account registers, and satisfy financial reporting requirements.
5. DPO & Employee Responsibilities
5.1 Role of the Data Protection Officer (DPO)
Our designated DPO is responsible for:
- Maintaining timely policy updates and ensuring NDPA 2023 compliance.
- Supervising data processing activities and audit trails across all digital platforms.
- Handling Data Subject Access Requests (DSARs), privacy complaints, and regulatory reporting.
- Overseeing technical and organizational security controls.
Contact DPO: dpo@pebbles.com.
6. Core Data Processing Principles
In accordance with Section 24 of the NDPA 2023 and Article 5 of the GDPR, we adhere to:
- Fair, Lawful, and Transparent Processing: Consent or statutory legal bases required for all processing.
- Specified Purpose Limitation: Data collected only for predefined, communicated financial purposes.
- Data Minimization: Restricted strictly to necessary data fields.
- Accuracy & Currency: Regular steps taken to keep records accurate.
- Security & Confidentiality: Protection against unauthorized access, disclosure, or alteration.
- Data Protection Triad: Maintaining Confidentiality, Integrity, and Availability.
7. Consent & Legal Bases Beyond Consent
We process your data based on explicit consent, contractual necessity, legal/regulatory obligations, or legitimate business interests. Where processing relies on consent, you may withdraw consent at any time without affecting the lawfulness of prior processing.
8. Scope of Data Collection
The table below outlines categories of personal data collected, purposes, and lawful bases:
| S/N | Purpose of Collection | Type of Data Collected | Lawful Basis |
|---|---|---|---|
| 1 | Identification & KYC | Full name, phone number, email, address, gender, DOB, BVN, NIN, utility bills, next of kin. | Legal Obligation / Contract |
| 2 | Notifications & Support | Contact details (phone number, email address). | Consent / Contract |
| 3 | Financial & Credit History | Bank account details, BVN, financial statements, loan history, credit bureau reports. | Legal Obligation / Contract / Legitimate Interest |
| 4 | Employment & NYSC | Employer name, job title, income details, NYSC call-up/state details. | Contract / Legitimate Interest |
| 5 | Transaction Processing | Repayment schedules, mandate references, payment gateway logs. | Contract / Legal Obligation |
| 6 | Technical & Cookies | IP address, browser type, device OS, session tokens, analytics cookies. | Legitimate Interest / Consent |
8.1 Sensitive Information
Biometric or enhanced security verification data is processed strictly under explicit consent and regulatory risk controls. We take extra security precautions including encryption at rest and in transit.
8.2 Automated Decision-Making & Credit Assessment
We use automated risk models and licensed credit bureau queries to evaluate creditworthiness and loan eligibility. You have the right to request human review of automated credit assessments by contacting our DPO.
9. Technical Information, Cookies & Opt-Out
When you visit or interact with GDL+, we collect technical data such as IP address, browser type, and interaction patterns to maintain session security, prevent fraud, and optimize performance.
Cookies remember your preferences (e.g. login credentials, theme) and measure aggregate site traffic via Google Analytics and Microsoft Clarity. You have full control over optional cookies and can choose Decline or customize your preferences anytime via our Cookie Consent banner.
10. Data Retention Timelines & Security
| S/N | Record Type | Retention Period | Justification |
|---|---|---|---|
| 1 | KYC & Customer Records | Duration of account + up to 10 years post closure | CBN statutory legal retention requirements |
| 2 | Employment & Contract Records | Up to 7 years post termination | Audit, tax compliance & legal dispute obligations |
| 3 | Transaction & Profile Data | Duration of service + regulatory retention | Contractual service delivery & fraud prevention |
| 4 | Technical Security Logs | As necessary for cybersecurity monitoring | IT infrastructure & threat defense |
10.1 Data Breach Notification
In the event of a security incident posing a high risk to user rights, Growth and Development Asset Management Limited is legally mandated to report the breach to the Nigerian Data Protection Commission (NDPC) within 72 hours and notify affected data subjects promptly.
11. Data Subject Rights & DSAR Requests
Under the NDPA 2023 (Sections 34-35) and GDPR (Articles 15-22), you possess the following rights:
- Right to Access & DSAR: Request a copy of your personal records held by Growth and Development Asset Management Limited.
- Right to Rectification: Correct or update inaccurate data.
- Right to Erasure ("Right to be Forgotten"): Request data deletion when retention periods expire.
- Right to Object & Restrict: Object to automated profiling or marketing communications.
- Right to Data Portability: Request data transfer in a structured machine-readable format.
To submit a Data Subject Access Request (DSAR), email dpo@pebbles.com. We respond within 30 days free of charge.
12. Remediation & Escalation
If you have any complaints or concerns regarding data processing, please submit them to our DPO. We acknowledge receipt within 48 hours and aim to resolve concerns within 7 business days.
If you are unsatisfied with our response, you may escalate your complaint to the Nigeria Data Protection Commission (NDPC) at info@ndpc.gov.ng.
13. Contact Details & Data Controller
Data Controller: Growth and Development Asset Management LimitedAddress: No 1, Afolabi Lesi Street, Ilupeju, Lagos
DPO Email: dpo@pebbles.com
General Support Email: support@pebbles.com