Privacy policy
Last Updated: October 2, 2025
1. Introduction
Brass takes the privacy of your information very seriously. This Policy explains how and for what purposes we may use the information collected from you via the Site.
Additional information on our Privacy Policy may be found on our Sites and within Frequently Asked Questions (FAQs) as set out on the Sites.
Please read this Policy carefully. By using the Site and any services we offer via the Site, you are agreeing to be bound by this Policy with respect to the information collected about you via this Site.
2. Personal information collected
- name, username, gender, date of birth;
- Contact information (e.g. email address, postal address, telephone number);
- passport photo, nationality, identity card;
- BVN; NIN
- occupation;
- Utility bill;
- Your interests;
- Financial Information (e.g., account number, card number and expiry date);
- Business Information (e.g. business name, description, industry, address, business online presence);
- Signature;
- and any other information that may be required in order to provide the relevant services.
Although it is not compulsory to give us this information, if you do not, we may not be able to provide you with the full range of services that Brass has to offer.
3. Your Data Protection Rights
- Right of Access - You can request confirmation of whether we process your personal information and, if so, obtain a copy.
- Right to Rectification - You can request correction of inaccurate or incomplete personal information.
- Right to Erasure ("Right to be Forgotten") - You can request that we delete your personal information, subject to our legal and regulatory obligations.
- Right to Restriction of Processing - You can request that we restrict the way we use your personal information in certain circumstances.
- Right to Object - You can object to the processing of your personal information for direct marketing or where we rely on legitimate interests as the basis for processing.
- Right to Data Portability - You can request a copy of your personal information in a structured, commonly used, and machine-readable format, and request that we transmit it to another controller.
- Right to Withdraw Consent - Where processing is based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
In addition, where you believe your rights have been violated, you can issue a data subject Standard Notice to Address Grievance (SNAG) to us through the details provided in the “Contact Us” section.
You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) or your local data protection authority if you are based outside Nigeria.
4. Lawful Basis for Processing Personal Information
- Consent
Where you have given us explicit permission to process your personal information for a specific purpose. Example: subscribing to receive marketing communications.
NB: You may withdraw your consent at any time by contacting us. - Contractual Necessity
Where processing is necessary for the performance of a contract we have with you or to take steps at your request prior to entering into a contract. Example: opening and managing your account, or providing services you request. - Legal Obligation
Where processing is necessary for compliance with a legal or regulatory obligation. Example: record-keeping to meet Anti-Money Laundering (AML), Counter-Terrorism Financing (CTF), tax, or reporting obligations. - Legitimate Interests
Where processing is necessary for our legitimate business interests or those of a third party, provided that your fundamental rights and freedoms are not overridden. Example: fraud prevention, ensuring network and information security, improving services, or conducting business analysis.
5. Use of collected information
The information we collect may also be used to: provide our additional Services which you may subscribe to and customer support; process transactions and send notices about your transactions; verify your identity, including during account creation and password reset processes; resolve disputes, collect fees, and troubleshoot problems; manage risk, or to detect, prevent, and/or remediate fraud or other potentially prohibited or illegal activities; detect, prevent or remediate violations of policies or applicable user agreements; improve the offering of our Services to you by customising your user experience; measure the performance of our Services and improve their content and layout; manage and protect our information technology infrastructure; provide service update notices, and deliver promotional offers based on your communication preferences; contact you at any telephone number, by placing a voice call or through text (SMS) or email messaging; perform creditworthiness and solvency investigation, and compare information for accuracy and verify it with third parties.
We may also contact you via electronic means to notify you regarding your account, to troubleshoot problems with your account, to resolve a dispute, to collect fees or monies owed, to poll your opinions through surveys or questionnaires, or as otherwise necessary to service your account.
Conclusively, we may contact you with the information provided as necessary to enforce our policies, applicable law, or any agreement we may have with you. When contacting you via phone, to reach you as efficiently as possible we may use autodialled or pre-recorded calls and text messages. Where applicable and permitted by law, you may decline to receive certain communications.
6. Record Retention
The broad categories of AML/CFT-related records are:
- Customer identification and verification documents.
- Transaction records, including currency transaction reports.
- Suspicious transaction reports, together with supporting documentation.
- AML/CFT-related records may be maintained by way of original documents, stored in microfiche, and in computerized or electronic form, subject to the provisions of the law on what is acceptable as evidence.
The Compliance Officer or other designated officer shall be responsible for ensuring that all AML/CFT records are maintained properly and kept for no less than five ( 5 ) years before they are sent to the archives.
7. Sharing collected information
In order for services to be provided, we may share some necessary details about you with the Business Partners, and according to our business dynamics and the continued provision of efficient services to you, we may, from time to time, transfer such details to other Business Partners as we deem fit. However, under any circumstance, we will take steps to ensure that your privacy rights continue to be protected.
We may transfer your personal information to any other third party as part of a sale of some or all of our business and assets to any third party or as part of any business restructuring or reorganisation, but we will take steps with the aim of ensuring that your privacy rights continue to be protected.
In addition, we may pass your information on to one of our carefully selected business partners or to other carefully selected third parties to enable them to send you information which may be of interest to you but only if you have given us permission to do so. You can stop receiving such mail whenever you choose by unsubscribing via the link to be provided.
Other than as set out above, we will not disclose any of your personal information without your permission unless we are required by law to do so (for example, if required to do so by a court order or for the purposes of prevention of fraud or other crime).
8. Information automatically collected from your computer
- Log files/IP addresses: When you visit the Site, our web server automatically records your IP address. This IP address is not linked to any of your personal information. We use IP addresses to help us administer the Site and to collect demographic information for aggregation purposes.
- Other technologies including pixel tags, web beacons, and clear gifs: These may be used in connection with some Site pages, downloadable mobile applications and HTML-formatted email messages to measure the effectiveness of our communications, the success of our marketing campaigns, to compile statistics about usage and response rates, to personalise/tailor your experience while engaging with us online and offline, for fraud detection and prevention, for security purposes, for advertising, and to assist us in resolving account holders' questions regarding the use of our Site.
- Aggregated and de-identified data: Aggregated and De-identified Data is data that we may create or compile from various sources, including but not limited to accounts and transactions. This information, which does not identify individual account holders, may be used for our business purposes, which may include offering products or services, research, marketing or analysing market trends, and other purposes consistent with applicable laws.
- Through your browser or device: Certain information is collected by most browsers and/or through your devices, such as your Media Access Control (MAC) address, device type, screen resolution, operating system version and internet browser type and version. We use this information to ensure Sites function properly, for fraud detection and prevention, and security purposes.
9. Cookies
- so that you will not have to re-enter your details each time you visit the Site to track how our Site is used and to improve and update our content
- store your preferences
- customise elements of the layout and/or content of the site for you
- collect statistical information about how you use the site so that we can improve the site
10. Advertisement and information about other products and services
Brass advertises online (e.g., pages within our Sites and mobile apps, through the Company's managed social media presence, and on other sites and mobile apps not affiliated with Brass) and offline (e.g. in banking centres, through call centres, and direct marketing). In order to understand how our advertising performs, we may collect certain information on our Sites and other sites and mobile apps through our advertising service providers using cookies, IP addresses, and other technologies. The collected information may include the number of page visits, pages viewed on our Sites, search engine referrals, browsing activities over time and across other sites following your visit to one of our Sites or Apps, and responses to advertisements and promotions on the Sites and on sites and apps where we advertise.
Brass uses the information described in this Policy to help advertise our products and services. We use such information to:
- Present tailored ads to you, including; Banner ads and splash ads that appear as you sign on or off of your online accounts on our Sites, within mobile banking and other mobility applications;
- E-mail, postal mail, and telemarketing;
- On other sites and mobile apps not affiliated with Brass;
- Analyse the effectiveness of our ads; and
- Determine whether you might be interested in new products or services
Advertising on third party sites and mobile apps: Brass contracts with advertising companies to advertise our products and services on sites and mobile apps not affiliated with us. We may use Aggregated and De-identified Data and information provided by you to these third-party sites and mobile apps to select which of our advertisements or offers may appeal to you, display them to you and monitor your responses. Third-Party Sites and mobile apps are not subject to Brass Privacy Policy. Please visit the individual sites and mobile apps for additional information on their data and privacy practices and opt-out policies.
11. Changes to your details
12. Use of forums or chat rooms
13. Security
- Secure server software (SSL) encryption for financial data transmission;
- Strict access controls and authentication measures;
- Regular security assessments and monitoring of our IT systems;
- Oversight of third-party service providers to ensure they maintain adequate data protection measures.
14. Linking to third-party websites and other aggregation website
We cannot be responsible for the privacy policies and practices of other sites even if you access them using links from our Site and recommend that you check the policy of each site you visit and contact its owner or operator if you have any concerns or questions.
Using Other Aggregation Websites: Other companies offer aggregation websites and services that allow you to consolidate your financial account information from different sources (such as your accounts with us or with other financial institutions) so that you can view all your account information at one online location. To do this, an aggregation provider may request access to personal information, such as financial information, usernames and passwords. You should use caution and ensure that the aggregator company has appropriate policies and practices to protect the privacy and security of any information you provide or to which they are gaining access. We are not responsible for the use or disclosure of any personal information accessed by any company or person to whom you provide your Site username and password.
If you provide your Site username, password or other information about your accounts with us to an aggregation website, we will consider that you have authorized all transactions or actions initiated by an aggregation website using access information you provide, whether or not you were aware of a specific transaction or action. If you decide to revoke the authority you have given to an aggregation website, we strongly recommend that you change your password for the Site to ensure that the aggregation website cannot continue to access your account.