Privacy Policy
Last updated: 4 May 2026
BiyaLink is a technology product of DenoSys LTD. BiyaLink does not accept deposits or hold customer funds. Financial accounts, transfers, cards, payments, and related regulated services are provided by licensed financial institution and payment service partners. This Policy explains how DenoSys handles personal data through BiyaLink.
1. About This Privacy Policy
This Privacy Policy applies when you visit the BiyaLink website, join our waitlist, create or use a BiyaLink account, contact customer support, or use any BiyaLink application or related service.
BiyaLink is operated by DenoSys LTD, a company incorporated in Nigeria. In this Policy, "BiyaLink," "DenoSys," "we," "us," and "our" refer to DenoSys LTD. "You" and "your" refer to the person whose personal data we process.
DenoSys acts as a data controller for personal data used to operate BiyaLink, manage customer relationships, provide support, protect the platform, and meet our legal obligations. A financial institution or other service partner may act as a separate data controller for the regulated service it provides. Its privacy notice may also apply to you.
2. Personal Data We Collect
Identity and contact data
- Full name, date of birth, gender, and nationality where required
- Phone number, email address, and residential address
- Bank Verification Number, National Identification Number, and other identifiers
- Government-issued identity documents and document details
- Occupation, employer, source of funds, income range, and transaction purpose
Identity verification and biometric data
Our identity verification providers may collect a facial photograph, selfie, liveness recording, identity document image, and related biometric measurements to confirm your identity and prevent impersonation. We may receive the verification result, risk indicators, document details, and evidence needed to support a review. The provider may retain source materials under its own legal and contractual obligations.
Account and financial data
- BiyaLink account profile, customer number, verification status, and limits
- Bank account names, account numbers, virtual account details, and beneficiaries
- Balances and account information received from licensed financial partners
- Masked or tokenised card details, card status, and card transaction information
- Funding, transfer, payment, bill payment, refund, reversal, and dispute records
- Currency, exchange rate, amount, merchant, biller, recipient, and transaction purpose
DenoSys does not store your complete card security code. Full card credentials may be stored and processed by the licensed card issuer or payment processor responsible for the card service.
Device, usage, and security data
- IP address, device type, operating system, app version, and browser type
- Device identifiers, device fingerprint, mobile network, and language settings
- Login history, session information, authentication events, and audit logs
- App interactions, feature usage, error reports, and performance information
- Approximate or precise location where you permit access or where it is needed for fraud prevention and regulatory controls
Communications and support data
- Support requests, complaints, correspondence, and call or chat records
- Files, screenshots, receipts, and other evidence you submit
- Marketing preferences, survey responses, and promotion participation
3. How We Obtain Personal Data
We obtain personal data:
- Directly from you when you register, verify your identity, transact, or contact us
- Automatically from your device when you use our website or application
- From identity verification, fraud prevention, sanctions screening, and compliance providers
- From banks, card issuers, payment processors, billers, merchants, and other service partners
- From lawful public records, regulators, law enforcement agencies, and watchlist sources where permitted
- From another person where they send money to you, name you as a beneficiary, or contact us about a transaction
4. Why We Process Personal Data
We process personal data to:
- Review applications, create accounts, and manage customer profiles
- Verify identity, age, residency, and account ownership
- Provide access to accounts, transfers, cards, payments, and bill payment services
- Authenticate instructions and process, reconcile, reverse, or investigate transactions
- Apply transaction limits, security controls, and account restrictions
- Detect and prevent fraud, identity theft, account takeover, money laundering, and other abuse
- Conduct sanctions, watchlist, and politically exposed person screening
- Respond to enquiries, complaints, disputes, and support requests
- Send receipts, statements, alerts, service notices, and security messages
- Maintain records, audit activity, and meet legal and regulatory obligations
- Monitor reliability, correct errors, secure our systems, and improve BiyaLink
- Measure campaigns and send marketing where permitted
- Establish, exercise, or defend legal claims
5. Lawful Bases for Processing
Depending on the purpose, we rely on one or more of the following lawful bases:
- Contract: Processing needed to register you, provide requested services, and perform our agreement with you
- Legal obligation: Processing needed to satisfy identity verification, financial crime prevention, recordkeeping, reporting, consumer protection, and other legal duties
- Legitimate interests: Processing needed to protect customers, prevent fraud, secure the platform, improve services, enforce our terms, and operate our business where those interests do not override your rights
- Consent: Processing based on a clear choice, such as optional marketing, device permissions, or biometric processing where consent is the appropriate basis
- Public interest or vital interests: Processing needed in limited circumstances to protect a person or support a lawful public interest function
Where we rely on consent, you may withdraw it at any time. Withdrawal does not make earlier processing unlawful. We may continue processing where another lawful basis applies.
6. Identity Verification and Financial Crime Prevention
We and our partners use identity, transaction, device, behavioural, and risk data to verify customers, screen against relevant watchlists, monitor transactions, and identify suspicious or prohibited activity. These checks may occur during registration and throughout the customer relationship.
We may request more information, repeat verification, delay a transaction, restrict a service, or refer an account for manual review. We may share information with the relevant financial institution, regulator, or law enforcement agency where required or permitted by law. We may be unable to disclose details that would compromise a security control, investigation, or confidential regulatory report.
7. Automated Checks and Decision-Making
We may use automated rules, device analysis, transaction monitoring, identity matching, and risk scoring to detect fraud, assess account activity, apply limits, or identify transactions that require review. An automated alert may result in a temporary delay or restriction while we or a partner investigate.
Where a decision is based solely on automated processing and produces a legal or similarly significant effect, you may request human review, express your point of view, and contest the decision, subject to applicable legal exceptions.
8. How We Share Personal Data
We share personal data only where needed for a lawful purpose. Recipients may include:
- Licensed banks and financial institutions that hold funds or provide accounts
- Card issuers, card networks, payment processors, and transaction switches
- Identity verification, sanctions screening, and fraud prevention providers
- Billers, airtime providers, merchants, banks, and transaction recipients
- Cloud hosting, database, cybersecurity, analytics, and software service providers
- Email, SMS, push notification, and customer support providers
- Auditors, insurers, lawyers, accountants, and other professional advisers
- Regulators, courts, law enforcement agencies, and public authorities
- A purchaser, investor, lender, or successor involved in a proposed or completed financing, restructuring, merger, acquisition, or sale, subject to confidentiality and legal safeguards
Service providers may process personal data only for agreed purposes and under appropriate contractual, confidentiality, and security obligations. Some financial partners process data under their own legal duties and privacy notices.
We do not sell personal data or disclose it to third parties for their independent direct marketing without your permission.
9. International Data Transfers
Some service providers may process or store personal data outside Nigeria. Where personal data is transferred internationally, we use a lawful transfer basis and safeguards designed to provide an adequate level of protection. These may include contractual protections, binding corporate rules, an approved certification or code of conduct, consent where legally appropriate, or another basis permitted by law.
We assess the destination, recipient, type of data, purpose of transfer, available rights, and security controls before relying on a transfer arrangement. You may contact us for information about the safeguards relevant to your data.
10. Data Security
We use technical and organisational safeguards designed to protect personal data against accidental or unlawful loss, alteration, misuse, disclosure, or access. These measures include encryption in transit and at rest, access controls, strong authentication, logging, monitoring, secure development practices, backups, and restricted production access.
No system is completely secure. You are responsible for protecting your password, PIN, one-time passwords, device, email account, and mobile number. Contact us immediately if you believe your BiyaLink account or personal data has been compromised.
If a personal data breach creates a risk to your rights and requires notification, we will notify the Nigeria Data Protection Commission and affected persons in line with applicable law. A notice may describe the incident, likely consequences, protective steps, and our response.
11. Data Retention
We retain personal data only for as long as needed for the purpose for which it was collected and for applicable legal, regulatory, contractual, security, fraud prevention, accounting, dispute, and recordkeeping requirements.
Retention periods depend on the type of information, service, transaction, legal duty, partner requirement, and whether a complaint, investigation, chargeback, or legal claim is active. Closing your account does not require immediate deletion of records that we or our partners must retain. When information is no longer needed, we delete it, anonymise it, or securely isolate it until deletion is possible.
12. Your Data Protection Rights
Subject to applicable law and relevant exceptions, you may:
- Ask whether we process your personal data and request access to it
- Request correction of inaccurate, incomplete, outdated, or misleading data
- Request deletion where the data is no longer needed or no lawful basis applies
- Request restriction of processing in appropriate circumstances
- Object to processing based on legitimate interests or direct marketing
- Withdraw consent where processing relies on consent
- Request eligible data in a structured, commonly used, machine-readable format
- Request human review of an eligible automated decision
- Complain to us or the Nigeria Data Protection Commission
A request may be limited where complying would violate another person's rights, reveal confidential security or financial crime controls, conflict with a legal obligation, or interfere with a legal claim or investigation.
13. Exercising Your Rights
Submit a privacy request through the in-app support channel or email hello@biyalink.com. State the right you wish to exercise and provide enough information for us to locate your records.
We may verify your identity before acting on a request. Where an authorized person submits a request for you, we may ask for proof of authority and may still verify your identity. We will respond within the period required by applicable law and notify you if more time or information is reasonably needed.
14. Marketing Communications
We may send product news, promotions, referral offers, and surveys where you have consented or where another lawful basis permits it. You may unsubscribe through the message, adjust available preferences, or contact support.
Opting out of marketing does not stop essential messages concerning transactions, security, account status, legal notices, or service changes.
15. Cookies and Similar Technologies
Our website and application may use cookies, local storage, software development kits, pixels, and similar technologies to keep you signed in, remember preferences, measure performance, understand usage, prevent fraud, and improve our services.
Essential technologies are required for security and core functions. Where consent is required for analytics or advertising technologies, we will provide an appropriate choice. You can also manage some settings through your browser or device, although disabling essential storage may affect service operation.
16. Children
BiyaLink accounts are available only to persons aged 18 or older. We do not knowingly offer accounts to children. If we learn that a child provided personal data for an account, we may close the account and delete or restrict the data, subject to any legal obligation to retain relevant records.
17. Third-Party Websites and Services
BiyaLink may link to websites, applications, merchants, or services that DenoSys does not control. Their privacy practices are governed by their own notices. Review those notices before providing personal data directly to them.
18. Changes to This Privacy Policy
We may update this Policy to reflect changes in our services, partners, technology, legal obligations, or processing practices. We will publish the revised Policy and update the date shown above. We will provide additional notice where a change is material or where consent is required.
19. Complaints and Regulatory Contact
Contact us first if you have a privacy concern so that we can investigate and try to resolve it. You also have the right to lodge a complaint with the Nigeria Data Protection Commission.
Information about privacy complaints and the Commission's contact channels is available on the Nigeria Data Protection Commission website.
20. Contact Us
For privacy questions, requests, or complaints, contact DenoSys LTD through the in-app support channel or email hello@biyalink.com. Please use the subject line Privacy Request where your message concerns a data protection right.
Your use of BiyaLink is also governed by our Terms of Service and Electronic Signature and Consent Agreement.