VTUAgent Logo
Section01 · Our approach

VTUAgent holds a wallet balance and the identity details Nigerian financial rules require us to verify. This page explains how that information is protected at each point it exists.

It sits alongside our Privacy Policy, which sets out what we collect and how long we keep it, and our Terms of Service.

01

Our approach

The strongest protection is not holding the data in the first place.

We collect only what is needed to open your account, verify you where the law requires it, deliver the products you pay for, and keep your money safe. Data we never collect cannot be leaked, subpoenaed or sold.

Data minimisation in practice
We do not collect your location, contacts, photos, camera, microphone or advertising identifiers. We do not ask for card numbers, card CVVs, bank login credentials, or photographs of government ID — the app has no card-entry screen. We use no advertising or analytics SDKs.

The full inventory is in the Privacy Policy. Data that is no longer needed is deleted or irreversibly anonymised at the end of its retention period.

02

On your device

Some things never reach us at all.

App-unlock PIN
Converted on your device into a salted, stretched hash (PBKDF2-HMAC-SHA256) and stored in the iOS Keychain or Android Keystore. Neither the PIN nor the hash is ever transmitted to us.
Biometric data
Your fingerprint or face data is held by Apple or Google in the device’s secure hardware. VTUAgent never sees it and cannot store it — the operating system only reports “unlocked” or “not unlocked”.
Session tokens
Kept in the Keychain or Keystore rather than ordinary app storage. The short-lived access token is held in memory only. Both are erased when you sign out or delete the app.
03

In transit

Every request between the app and our servers travels over HTTPS with TLS encryption. This covers sign-in, wallet funding, purchases, and the identity details submitted during verification.

Bank transfers that fund your wallet move over Nigerian banking rails and are handled by our licensed payment service provider, not by us — we receive notification that a transfer arrived, not your banking credentials.

04

On our servers

Secrets are stored so that they cannot be read back — including by us.

Passwords
Stored only as salted hashes. There is no process, and no member of staff, that can recover your password in readable form.
Transaction PIN
Verified server-side and never displayed back to you. It is required for every purchase.
Session integrity
If we detect that a session token has been reused or stolen, we end that session automatically.
If you suspect unauthorised access
Sign out the affected device immediately from Profile → Signed-in devices, change your password, and email [email protected].
05

Who can access your data

Access is limited to what a specific task requires.

Our staff
Access to customer data is restricted to personnel who need it to provide support, investigate a disputed transaction, or meet a legal obligation. Passwords and PINs are not visible to anyone, including staff.
Product providers
Mobile networks, broadcasters and electricity distribution companies receive only the recipient detail needed to deliver what you bought — the phone, meter or smartcard number, and the amount.
Infrastructure providers
Hosting, database and email-delivery services act on our instructions under contract and may not use your data for their own purposes.
Regulators and law enforcement
Only where we are legally required to disclose, or where disclosure is necessary to investigate fraud or protect our users.

We never sell your personal information, and we never share it with advertisers or data brokers.

06

What you control

Security measures you can operate yourself, from inside the app.

Signed-in devices
Review every device signed in to your account and sign any of them out remotely, from Profile → Signed-in devices.
Transaction PIN
Required on every purchase. Keep it separate from your device unlock code.
App lock
Optionally lock the app itself with Face ID, Touch ID or a local PIN. Declining costs you no functionality.
Account deletion
Close your account and revoke every session at any time, from Profile → Delete account.
What we cannot protect you from
Anyone who has your password or transaction PIN can spend your wallet balance. Transactions authorised with your PIN are treated as authorised by you. Keep your credentials and your device secure, and never share your PIN.
07

Regulatory compliance

VTUAgent is a Nigerian service, regulated under Nigerian law.

Nigeria Data Protection Act 2023
The primary law governing how we handle your personal data, overseen by the Nigeria Data Protection Commission (NDPC).
Anti-money-laundering rules
Require us to verify customer identity (KYC) and to retain transaction and identity records for a minimum of five years.
GDPR
Applied where it applies to you. The rights set out in our Privacy Policy — access, correction, deletion, portability, objection and withdrawal of consent — are honoured on request.

Where an infrastructure provider stores or processes data outside Nigeria, we rely on contractual safeguards requiring protection consistent with the NDPA 2023 and, where applicable, standard contractual clauses.

08

Breach response

No system is perfectly secure. If personal data is affected by a breach, our response is to contain it, assess what was exposed, notify those affected and the Nigeria Data Protection Commission as the NDPA 2023 requires, and correct the weakness that allowed it.

  • Contain the incident and stop further exposure.
  • Establish what data was affected and whose.
  • Notify the Nigeria Data Protection Commission within the period the law requires.
  • Notify affected users directly, with what happened and what to do.
  • Revoke sessions and force credential resets where accounts may be compromised.
  • Fix the underlying cause and review what allowed it.
09

Reporting a problem

If you have found a security issue, we want to hear about it.

Email [email protected] with enough detail to reproduce the issue. Please report it to us privately and give us a reasonable opportunity to fix it before disclosing it publicly. We do not take legal action against people who report vulnerabilities in good faith and do not access, alter or destroy other users’ data.

For questions about your own data — what we hold, correcting it, or deleting it — see Delete your account or email us. We respond within 30 days. You may also complain to the Nigeria Data Protection Commission.

VTUAgent

Published by XTRAHOLA CONCEPT

Security reports and data protection enquiries. We respond within 30 days.

[email protected]