Data Protection Overview
Last Updated: August 2026 — Statutory Framework: NDPA 2023 & NDPC GAID 2025
1. Introduction & Regulatory Governance
Nura Mustapha Technologies Limited (“SwiftPOS”) is committed to protecting the confidentiality, integrity, and security of all personal and enterprise records processed across our Point of Sale platforms, cloud servers, and mobile applications. Our data protection program operates under the Nigeria Data Protection Act 2023 (NDPA) and the Nigeria Data Protection Commission (NDPC) General Application and Implementation Directive 2025 (GAID).
2. Data Controller vs. Data Processor Delineation
In accordance with the NDPA 2023:
- Merchant as Data Controller: Merchants determine the purpose for collecting customer debt records, shopper phone numbers, and cashier accounts stored in their tenant environment.
- SwiftPOS as Data Processor: SwiftPOS processes merchant-entered data solely upon documented merchant instructions to provide cloud POS, inventory tracking, and reporting services under our Data Processing Agreement (DPA).
- SwiftPOS as Data Controller: We act as Data Controller for direct merchant account registration, subscription billing, and marketing website telemetry.
3. Encryption & Storage Security
We deploy defense-in-depth technical and organizational controls:
- In Transit: End-to-end TLS 1.3 / TLS 1.2 encryption with enforced HSTS headers across all endpoints.
- At Rest: AES-256 encryption applied to database storage volumes and automated system backups.
- Tenant Isolation: Logical database-level separation guaranteeing that no merchant can access or view another store's inventory, sales, or customer data.
- Credential Hashing: Passwords and cashier authorization PINs are stored exclusively as salted cryptographic hashes.
4. Merchant Rights & Data Portability
Merchants retain 100% ownership over their operational data. Through the SwiftPOS Export Center, you may download complete CSV exports of your product catalogs, sales orders, customer debts, and audit trails at any time. Upon subscription cancellation, your data is retained in read-only mode for up to 90 days as described in our Terms of Service, after which inactive tenant data may be permanently removed from active systems.
5. Related Compliance Documentation
For complete details on our data handling practices and contractual terms, please review:
- Privacy Policy — Full transparency on data collection, legal bases, sub-processors, and NDPA rights.
- Data Processing Agreement (DPA) — Binding processor terms, breach notification protocols (72h), and sub-processor schedules.
- Terms of Service — Platform usage, subscriptions, and commercial terms.
6. Contact Our Data Protection Officer
For data protection inquiries or to exercise your NDPA rights, email our Compliance Officer at compliance@swiftpos.ng.