VTUAgent holds a wallet balance and the identity details Nigerian financial rules require us to verify. This page explains how that information is protected at each point it exists.
It sits alongside our Privacy Policy, which sets out what we collect and how long we keep it, and our Terms of Service.
Our approach
The strongest protection is not holding the data in the first place.
We collect only what is needed to open your account, verify you where the law requires it, deliver the products you pay for, and keep your money safe. Data we never collect cannot be leaked, subpoenaed or sold.
The full inventory is in the Privacy Policy. Data that is no longer needed is deleted or irreversibly anonymised at the end of its retention period.
On your device
Some things never reach us at all.
- App-unlock PIN
- Converted on your device into a salted, stretched hash (PBKDF2-HMAC-SHA256) and stored in the iOS Keychain or Android Keystore. Neither the PIN nor the hash is ever transmitted to us.
- Biometric data
- Your fingerprint or face data is held by Apple or Google in the device’s secure hardware. VTUAgent never sees it and cannot store it — the operating system only reports “unlocked” or “not unlocked”.
- Session tokens
- Kept in the Keychain or Keystore rather than ordinary app storage. The short-lived access token is held in memory only. Both are erased when you sign out or delete the app.
In transit
Every request between the app and our servers travels over HTTPS with TLS encryption. This covers sign-in, wallet funding, purchases, and the identity details submitted during verification.
Bank transfers that fund your wallet move over Nigerian banking rails and are handled by our licensed payment service provider, not by us — we receive notification that a transfer arrived, not your banking credentials.
On our servers
Secrets are stored so that they cannot be read back — including by us.
- Passwords
- Stored only as salted hashes. There is no process, and no member of staff, that can recover your password in readable form.
- Transaction PIN
- Verified server-side and never displayed back to you. It is required for every purchase.
- Session integrity
- If we detect that a session token has been reused or stolen, we end that session automatically.
Who can access your data
Access is limited to what a specific task requires.
- Our staff
- Access to customer data is restricted to personnel who need it to provide support, investigate a disputed transaction, or meet a legal obligation. Passwords and PINs are not visible to anyone, including staff.
- Product providers
- Mobile networks, broadcasters and electricity distribution companies receive only the recipient detail needed to deliver what you bought — the phone, meter or smartcard number, and the amount.
- Infrastructure providers
- Hosting, database and email-delivery services act on our instructions under contract and may not use your data for their own purposes.
- Regulators and law enforcement
- Only where we are legally required to disclose, or where disclosure is necessary to investigate fraud or protect our users.
We never sell your personal information, and we never share it with advertisers or data brokers.
What you control
Security measures you can operate yourself, from inside the app.
- Signed-in devices
- Review every device signed in to your account and sign any of them out remotely, from Profile → Signed-in devices.
- Transaction PIN
- Required on every purchase. Keep it separate from your device unlock code.
- App lock
- Optionally lock the app itself with Face ID, Touch ID or a local PIN. Declining costs you no functionality.
- Account deletion
- Close your account and revoke every session at any time, from Profile → Delete account.
Regulatory compliance
VTUAgent is a Nigerian service, regulated under Nigerian law.
- Nigeria Data Protection Act 2023
- The primary law governing how we handle your personal data, overseen by the Nigeria Data Protection Commission (NDPC).
- Anti-money-laundering rules
- Require us to verify customer identity (KYC) and to retain transaction and identity records for a minimum of five years.
- GDPR
- Applied where it applies to you. The rights set out in our Privacy Policy — access, correction, deletion, portability, objection and withdrawal of consent — are honoured on request.
Where an infrastructure provider stores or processes data outside Nigeria, we rely on contractual safeguards requiring protection consistent with the NDPA 2023 and, where applicable, standard contractual clauses.
Breach response
No system is perfectly secure. If personal data is affected by a breach, our response is to contain it, assess what was exposed, notify those affected and the Nigeria Data Protection Commission as the NDPA 2023 requires, and correct the weakness that allowed it.
- Contain the incident and stop further exposure.
- Establish what data was affected and whose.
- Notify the Nigeria Data Protection Commission within the period the law requires.
- Notify affected users directly, with what happened and what to do.
- Revoke sessions and force credential resets where accounts may be compromised.
- Fix the underlying cause and review what allowed it.
Reporting a problem
If you have found a security issue, we want to hear about it.
Email [email protected] with enough detail to reproduce the issue. Please report it to us privately and give us a reasonable opportunity to fix it before disclosing it publicly. We do not take legal action against people who report vulnerabilities in good faith and do not access, alter or destroy other users’ data.
For questions about your own data — what we hold, correcting it, or deleting it — see Delete your account or email us. We respond within 30 days. You may also complain to the Nigeria Data Protection Commission.
VTUAgent
Published by XTRAHOLA CONCEPT
Security reports and data protection enquiries. We respond within 30 days.
[email protected]