Privacy Policy

Personal Data

Under the Nigeria Data Protection Regulation, personal data is defined as:

“Any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person”.


Who Is Responsible for Your Personal Information?

Firmus Microfinance Bank is your data controller and is responsible for processing your personal information described in this Privacy Policy. FirmusMFB uses the personally identifiable information you provide to communicate with you in response to your enquiries, to provide the services you request, and to manage your account. Any personally identifiable information gathered by FirmusMFB will be used for these purposes only. We will not disclose or divulge such data outside of FirmusMFB, other than to third party providers that assist us in providing the services. FirmusMFB does not share, sell, rent or trade personally identifiable information with third parties for their promotional purposes.


Why does FirmusMFB need to collect and store personal data?

In order for us to provide you with a service, we need to collect personal data. When you sign up for any FirmusMFB Online Solution or other FirmusMFB service or promotion that requires registration, we ask you for personal information (such as your name, email address and an account password). For certain services, such as our payment services, we require your debit or credit card information. We typically do not store this information and when we do, we maintain the data in encrypted form on secure servers. We may combine the information you submit under your account with information from other FirmusMFB services or third parties in order to provide you with a better experience and to improve the quality of our services. In any event, we are committed to ensuring that the information we collect, and use is appropriate for this purpose, and does not constitute an invasion of your privacy. In terms of being contacted for marketing purposes FirmusMFB would contact you for additional consent.


Will FirmusMFB share my personal data with anyone else?

FirmusMFB only shares personal information with other companies or individuals in the following limited circumstances:


  • We have your We require consent for the sharing of any sensitive personal information
  • We provide such information to our subsidiaries, affiliated companies or other trusted businesses or persons for the purpose of processing personal information on our behalf. We require that these parties agree to process such information based on our instructions and in compliance with the Nigeria Data Protection Regulation and any other appropriate confidentiality and security measures. When they no longer need your data to fulfil this service, they will dispose of the details in line with FirmusMFB We have a good faith belief that access, use, preservation or disclosure of such information is reasonably necessary to (a) satisfy any applicable law, regulation, legal process or enforceable governmental request, (b) enforce applicable Terms of Service, including investigation of potential violations thereof, (c) detect,


prevent, or otherwise address fraud, security or technical issues, or (d) protect against imminent harm to the rights, property or safety of FirmusMFB, its users or the public as required or permitted by law.

  • If FirmusMFB becomes involved in a merger, acquisition, or any form of sale of some or all of its assets, we will provide notice before personal information is transferred and becomes subject to a different privacy policy.


How will FirmusMFB use the personal data it collects about me?

FirmusMFB will process (collect, store and use) the information you provide in a manner compatible with the Nigeria Data Protection Regulation (NDPR). We review our data collection, storage and processing practices to ensure that we only collect, store and process the personal information needed to provide or improve our services. We will endeavour to keep your information accurate and up to date, and not keep it for longer than is necessary, but we depend on our users to update or correct their personal information whenever necessary. FirmusMFB is required to retain information in accordance with the law, such as information needed for income tax and audit purposes. How long certain kinds of personal data should be kept may also be governed by specific business-sector requirements and agreed practices. Personal data may be held in addition to these periods depending on individual business needs.

FirmusMFB only processes personal information for the purposes described in this Privacy Policy and/or the supplementary privacy notices for specific services. In addition to the above, such purposes include:


  • Providing our services to users, including the display of customized content;
  • Auditing, research and analysis in order to maintain, protect and improve our services;
  • Ensuring the technical functioning of our network; and
  • Developing new

You can find more information about how we process personal information by referring to the supplementary privacy notices for particular services.


Log information

When you access FirmusMFB services, our servers automatically record information that your browser sends whenever you visit a website.


User communications

When you send email or other communications to FirmusMFB, we may retain those communications in order to process your inquiries, respond to your requests and improve our services.


Affiliated sites

We offer some of our services in connection with other web sites e.g. Websites of our subsidiaries. Personal information that you provide to those sites may be sent to Firmus Microfinance Bank Limited in order to deliver the service. We process such information in accordance with this Privacy Policy. The affiliated sites may have different privacy practices and we encourage you to read their privacy policies.


Under what circumstances will FirmusMFB contact me?

Our aim is not to be intrusive, and we undertake not to ask irrelevant or unnecessary questions. Moreover, the information you provide will be subject to rigorous measures and procedures to minimize the risk of unauthorized access or disclosure.


Can I find out the personal data that Firmus Microfinance Bank Limited holds about me?

FirmusMFB at your request, can confirm what information we hold about you and how it is processed. If

FirmusMFB does hold personal data about you, you can request the following information:


  • Contact details of the data protection officer, where
  • The purpose of the processing as well as the legal basis for
  • If the processing is based on the legitimate interests of FirmusMFB or a third party, information about those interests.
  • The categories of personal data collected, stored and
  • Recipient(s) or categories of recipients that the data is/will be disclosed
  • If we intend to transfer the personal data to a third party or international organization, information about how we ensure this is done securely. The Attorney General of the Federation will approve sending personal data to some countries because they meet a minimum standard of data protection. In other cases, we will ensure there are specific measures in place to secure your information.
  • How long the data will be
  • Details of your rights to correct, erase, restrict or object to such
  • Information about your right to withdraw consent at any
  • How to lodge a complaint with the supervisory authority (NITDA).
  • Whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, as well as whether you are obliged to provide the personal data and the possible consequences of failing to provide such data.
  • The source of personal data if it wasn’t collected directly from
  • Any details and information of automated decision-making, such as profiling, and any meaningful information about the logic involved, as well as the significance and expected consequences of such processing.


What other data privacy rights do you have?

Although not always absolute, you also have some other rights. At any point, while FirmusMFB is in possession of or processing your personal data, you, the data subject, have the right to:

  • Any details and information of automated decision-making, such as profiling, and any meaningful information about the logic involved, as well as the significance and expected consequences of such processing.
  • Correct your data in our custody that is inaccurate or
  • Ask for the data we hold about you to be erased from our
  • Restrict processing of your personal data where certain conditions
  • Have the data we hold about you transferred to another
  • Object to certain types of processing, such as direct marketing
  • Object to automated processing like profiling, as well as the right to be subject to the legal effects of automated processing or profiling.

Where a third party is involved in the processing of your personal data, all of the above requests will be forwarded, as appropriate, to the FirmusMFB Data Protection Officer.


What forms of ID will I need to provide in order to access this?

FirmusMFB accepts the following forms of ID (but not limited to) when information on your personal data is requested: International Passport, driving license, national identity card, permanent voter card.


Third Party Links

Our site may contain links to third party websites. If you follow a link to any of these websites, please note that these websites have their own terms and privacy policies and that we do not accept any responsibility or liability for them. By registering at FirmusMFB you may receive follow-up contact and offers from third party companies as you have agreed to do by accepting this Privacy Policy and, while we only work with selected partners, we are not responsible for the services or representations of third parties.


Because we are not responsible for any representations or information or warranties or content on any website of any third party (including websites linked to this website or websites facilitated by us), we do not exercise control over third parties’ privacy policies and you should refer to the privacy policy of any such third party to see how such party protects your privacy.



When you use our website and the services provided by us, you may be given an access number, username, password and/or Personal Identification Number (PIN). You are responsible for maintaining the secrecy and confidentiality of your username, access card, password and/or PIN.


Changes to this Privacy Policy

We reserve the right, in our sole discretion to update, modify or amend (including without limitation, by the addition of new terms and conditions) this Privacy Policy from time to time with or without notice. You therefore agree to review the Privacy Policy whenever you visit our website, for any such change. Save as expressly provided to the contrary in this Privacy Policy, the amended version of the Privacy Policy shall supersede and replace all previous versions thereof.


Which Laws Apply?

This Privacy Policy will be governed by and construed and interpreted in accordance with the laws of the Federal Republic of Nigeria


More information

Please do not hesitate to get in touch with us via the contact page on our website if you have any questions or queries regarding our privacy policy.

To contact our Data Protection Officer, kindly address your request to “The Data Protection Officer” at The QBA Place, KM 47, Ajah Epe Express Way, Farm Bus-stop, Lekki Ajah, Lagos or send an email to


Who to Contact?

Should you have any queries, please contact us, FirmusMFB, on 08023060703 or