Privacy Policy

What we collect, the legal bases we rely on, who we share it with, how long we keep it, and the rights you can exercise over it.

Effective 1 June 2026 · Version 1.0

Introduction

XODOS Technologies Limited ("XODOS", "we", "us", "our") is committed to protecting the privacy and personal data of all individuals who use the XODOS Platform. This Privacy Policy explains who we are, what personal data we collect, why we collect it, how we use and share it, how long we retain it, and what rights you have in respect of your data.

This Policy applies to all users of the XODOS mobile application, web portal, APIs, and associated services (collectively, the "Platform"), including diaspora investors in the United Kingdom, United States, and Canada, as well as users in Nigeria.

This Privacy Policy is incorporated into and forms part of XODOS's Terms of Service. Capitalised terms not defined here have the meanings given to them in the Terms of Service. By using the Platform, you consent to the collection and processing of your personal data as described in this Policy.

XODOS is the Data Controller in respect of personal data collected and processed through the Platform. Our registered address is House 1, Plot 15, Ihuntayi Road, Oniru, Lagos, Nigeria. For all privacy enquiries and data subject requests, contact privacy@x-o-dos.com.

2. Data controller identity and contact

Data Controller

XODOS Technologies Limited, House 1, Plot 15, Ihuntayi Road, Oniru, Lagos, Nigeria. RC Number: 9539993.

Data Protection Officer

XODOS has designated a Data Protection Officer, who can be contacted at privacy@x-o-dos.com, or by post at: Data Protection Officer, XODOS Technologies Limited, House 1, Plot 15, Ihuntayi Road, Oniru, Lagos, Nigeria.

3. Personal data we collect

We collect the following categories of personal data from you, or about you from third parties:

3.1 Identity and verification data

  • Full legal name;
  • Date of birth;
  • Nationality and country of residence;
  • Government-issued photo identification (passport, national ID, driving licence);
  • Bank Verification Number (BVN) and/or National Identification Number (NIN), where applicable;
  • Selfie or liveness check images used for biometric identity verification;
  • Signature, where required for regulatory documentation.

3.2 Contact data

  • Email address;
  • Mobile phone number;
  • Residential address and proof of address (utility bill, bank statement).

3.3 Financial and transaction data

  • Bank account details, for withdrawal processing;
  • Source of funds declarations;
  • Deposit history, withdrawal history, and transaction records;
  • Portfolio holdings, trade history, and settlement records;
  • cNGN wallet balances and transaction logs;
  • FX conversion history.

3.4 KYC/AML compliance data

  • AML screening results, including PEP (Politically Exposed Person) and sanctions screening outcomes;
  • Enhanced due diligence documentation where applicable;
  • Beneficial ownership declarations;
  • Ongoing transaction monitoring data.

3.5 Technical and usage data

  • IP address and device identifiers;
  • Browser type, operating system, and device type;
  • Login timestamps, session data, and activity logs;
  • App usage data, feature interactions, and clickstream data;
  • Push notification preferences and interaction history;
  • Error logs and crash reports.

3.6 Communications data

  • Records of correspondence with XODOS's customer support team;
  • Complaint records and dispute resolution communications;
  • In-app messages and service request logs.

3.7 Marketing and preference data

  • Marketing communication preferences;
  • Referral data, where you have participated in a referral programme;
  • Survey responses and feedback.

3.8 Data from third parties

We receive personal data from the following third-party sources in the course of onboarding and operating the Platform:

  • Identity verification vendors (Prembly, Usesense, or equivalent) — identity verification outcomes and document authentication results;
  • ARM Securities Limited — trade confirmations, KYC status, and account information;
  • Wema Bank — settlement wallet transaction data and bank statements;
  • RMB — custodian services;
  • CSCS — securities custody and settlement records;
  • NGX — trade execution confirmations and market data;
  • Stablecoin settlement partner (Juicyway or equivalent) — cNGN conversion and wallet records;
  • Payment gateway providers (Flutterwave or equivalent) — fiat deposit and withdrawal confirmation data.

We do not purchase personal data from data brokers or third-party list providers.

5. How we share your personal data

XODOS does not sell your personal data to third parties. We share personal data only in the following circumstances and only to the extent necessary.

5.1 Regulated capital markets partners

  • ARM Securities Limited — for client onboarding, KYC/AML compliance, trade routing, and order execution on NGX;
  • Wema Bank — for settlement wallet provisioning, cash inflow and outflow processing, and account reconciliation;
  • RMB — for custodian services;
  • CSCS — for securities custody registration, settlement confirmation, and portfolio reconciliation;
  • NGX — for trade execution, market data, and regulatory reporting.

5.2 Technology and service providers

We share personal data with service providers who process data on our behalf as data processors, subject to strict contractual data protection obligations:

  • Identity verification vendors (Prembly, Usesense, or equivalent) — for KYC/AML screening;
  • Stablecoin settlement partner (Juicyway or equivalent) — for cNGN issuance, conversion, and on-chain settlement;
  • Payment gateway providers (Flutterwave or equivalent) — for fiat deposit and withdrawal processing;
  • Cloud infrastructure providers — for Platform hosting and data storage;
  • Customer support software providers — for support ticketing and communications management;
  • Analytics providers — for Platform usage analytics, using anonymised or pseudonymised data where possible.

5.3 Regulatory and law enforcement authorities

We disclose personal data to competent authorities where required by law, including:

  • The Securities and Exchange Commission Nigeria (SEC Nigeria);
  • The Nigerian Financial Intelligence Unit (NFIU), for AML/CFT reporting obligations;
  • The Central Bank of Nigeria (CBN);
  • The Nigeria Data Protection Commission (NDPC);
  • The Financial Conduct Authority (FCA), for UK-resident Clients where applicable;
  • FinCEN, OFAC, and other US regulatory bodies, for US-resident Clients where applicable;
  • Law enforcement authorities, courts, or other public bodies, upon valid legal request.

5.4 Corporate transactions

In the event of a merger, acquisition, restructuring, or sale of all or part of XODOS's business, your personal data may be transferred to a successor entity, subject to equivalent data protection obligations. You will be notified of any such transfer and your rights under applicable data protection law.

5.5 With your consent

We may share your personal data with other third parties where you have given your explicit prior consent for such sharing.

6. International data transfers

XODOS operates across Nigeria, the United Kingdom, the United States, and Canada. In providing the Platform, your personal data may be transferred to and processed in countries other than your country of residence.

For transfers of personal data from the UK or the European Economic Area to Nigeria or other third countries, XODOS relies on:

  • Standard Contractual Clauses approved by the UK ICO or European Commission, as applicable;
  • Adequacy decisions, where applicable; or
  • Other appropriate safeguards as permitted under UK GDPR Article 46 or NDPA Part VI.

A copy of the relevant safeguards for international transfers is available on written request to privacy@x-o-dos.com.

7. Data retention

XODOS retains personal data for as long as necessary to fulfil the purposes for which it was collected and to comply with our legal and regulatory obligations. The following minimum retention periods apply:

  • Identity and KYC/AML records — a minimum of 5 years from account closure, or longer if required by applicable AML/CFT law.
  • Transaction and financial records — a minimum of 7 years from the date of the transaction, in accordance with Nigerian tax law, FIRS requirements, and applicable UK/US/Canadian record-keeping obligations.
  • Trade confirmations and settlement records — a minimum of 5 years from the date of the trade, in accordance with SEC Nigeria and NGX requirements.
  • Customer support and complaints records — a minimum of 3 years from resolution of the complaint.
  • Technical and usage data (logs) — up to 24 months from collection, unless longer retention is required for security, fraud investigation, or legal proceedings.
  • Marketing preferences — until you withdraw consent, plus a short period to process the withdrawal.

Following expiry of the applicable retention period, personal data is securely deleted or anonymised in accordance with XODOS's data destruction policy.

8. Cookies and tracking technologies

XODOS uses cookies and similar tracking technologies (web beacons, pixels, local storage) on its website and mobile application:

  • Strictly necessary cookies — required for the operation of the Platform, including session management, authentication, and security. These cannot be disabled.
  • Functional cookies — enable enhanced functionality and personalisation, such as remembering your language preferences and display settings.
  • Analytics cookies — help us understand how users interact with the Platform, identify usage patterns, and improve performance.
  • Marketing cookies — used to serve relevant marketing communications where you have consented to receive them.

You may manage your cookie preferences at any time through the cookie settings in the Platform or your device or browser settings. Disabling non-essential cookies will not affect your ability to use the core trading and portfolio features of the Platform.

9. Data security

XODOS implements a comprehensive information security programme designed to protect your personal data against unauthorised access, disclosure, alteration, or destruction. Our security measures include:

  • AES-256 encryption of personal data at rest and TLS 1.2+ encryption in transit;
  • Multi-factor authentication enforced for all Client accounts and internal staff access;
  • Role-based access controls limiting internal staff access to personal data on a strict need-to-know basis;
  • Segregation of duties across onboarding, trading, and settlement functions;
  • Regular penetration testing and vulnerability assessments conducted by independent third-party security firms;
  • Intrusion detection and continuous security monitoring of the Platform infrastructure;
  • Secure API design with tokenised authentication between XODOS, ARM Securities, Wema Bank, CSCS, and NGX;
  • Incident response plan and data breach notification procedures in compliance with NDPA, UK GDPR, and applicable state laws;
  • Regular staff training on data protection and information security obligations.

Notwithstanding these measures, no system is entirely secure. If you believe your XODOS Account has been compromised, contact security@x-o-dos.com immediately.

9.1 Personal data breach notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, XODOS will notify the relevant supervisory authority (NDPC, and the ICO where applicable) within 72 hours of becoming aware of the breach, and will notify affected individuals without undue delay, as required by applicable law.

10. Your rights

Subject to applicable law and regulation, you have the following rights in respect of your personal data. To exercise any of these rights, contact privacy@x-o-dos.com with your name, Account identifier, and a description of your request. We will respond within 30 days, or a shorter period where required by applicable law.

10.1 Rights available to all users

  • Right to be informed — to receive clear information about how your data is processed, fulfilled by this Policy.
  • Right of access — to obtain a copy of the personal data XODOS holds about you.
  • Right to rectification — to have inaccurate or incomplete personal data corrected.
  • Right to erasure — to request deletion of your personal data where it is no longer necessary, subject to our legal retention obligations.
  • Right to restrict processing — to request that we limit the processing of your data in certain circumstances.
  • Right to data portability — to receive your personal data in a structured, machine-readable format and transmit it to another controller.
  • Right to object — to object to processing based on legitimate interests or for direct marketing purposes.
  • Right to withdraw consent — where processing is based on consent, to withdraw it at any time without affecting the lawfulness of prior processing.
  • Right to lodge a complaint — with the Nigeria Data Protection Commission at www.ndpc.gov.ng.

10.2 Additional UK rights (UK GDPR)

UK-resident users additionally have the right to lodge a complaint with the Information Commissioner's Office at www.ico.org.uk, and the right to compensation for material or non-material damage caused by a breach of UK GDPR.

10.3 Additional Canadian rights (PIPEDA / Quebec Law 25)

Canadian-resident users may contact XODOS's Privacy Officer at privacy@x-o-dos.com to exercise rights under PIPEDA, including the right of access and correction. Quebec residents have additional rights under Law 25, including the right to data portability and the right to be de-indexed. Complaints may be submitted to the Office of the Privacy Commissioner of Canada at www.priv.gc.ca.

10.4 California residents (CCPA/CPRA)

California residents have the following additional rights:

  • The right to know what categories of personal information we collect and the purposes for which it is used;
  • The right to delete personal information collected from you, subject to certain exceptions;
  • The right to opt out of the sale or sharing of personal information — XODOS does not sell or share your personal information for cross-context behavioural advertising;
  • The right to correct inaccurate personal information;
  • The right to limit use of sensitive personal information;
  • The right not to receive discriminatory treatment for exercising your CCPA rights.

To submit a CCPA request, contact privacy@x-o-dos.com. XODOS will respond within 45 days of receiving a verifiable request.

10.5 Identity verification for data subject requests

To protect your personal data, XODOS will verify your identity before processing any data subject request. Verification will typically require confirmation of your Account email address and at least one additional piece of information linked to your Account. We may decline requests we are unable to verify.

10.6 Limitations on rights

Some rights are not absolute. We may decline a request, wholly or in part, where:

  • Compliance would conflict with a legal or regulatory obligation, such as AML/CFT record-keeping requirements;
  • The data is necessary for the establishment, exercise, or defence of legal claims; or
  • The request is manifestly unfounded or excessive.

Where we decline a request, we will explain the reason in writing.

11. Children's privacy

The XODOS Platform is not directed at or intended for use by individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If you are a parent or guardian and believe your child has provided personal data to XODOS, contact privacy@x-o-dos.com immediately. We will promptly delete such data upon verification.

12. Automated decision-making and profiling

XODOS uses automated processes in certain aspects of its operations:

  • Automated AML screening and sanctions checking during onboarding and on an ongoing basis, using rule-based systems and third-party screening databases;
  • Automated pre-trade compliance checks (balance validation, order size limits) before trade routing.

Where a fully automated decision produces a legal or similarly significant effect on you — for example, an automated rejection of your account application based solely on AML screening — you have the right to request human review of the decision, express your point of view, and contest the decision.

To request human review of an automated decision, contact privacy@x-o-dos.com within 30 days of the decision.

14. Changes to this Privacy Policy

XODOS may update this Privacy Policy from time to time to reflect changes in law, regulation, or our data processing practices. Material changes will be notified to you by email and in-app notification at least 14 days before taking effect. We will update the "Effective Date" at the top of this Policy when changes are made. Your continued use of the Platform after the effective date of any update constitutes your acceptance of the revised Policy.

Previous versions of this Policy are available on request from privacy@x-o-dos.com.

15. How to contact us

For all privacy-related enquiries, data subject requests, or complaints, contact the Data Protection Officer at privacy@x-o-dos.com, or by post at: Data Protection Officer, XODOS Technologies Limited, House 1, Plot 15, Ihuntayi Road, Oniru, Lagos, Nigeria.

You also have the right to lodge a complaint directly with a supervisory authority:

  • Nigeria — Nigeria Data Protection Commission (NDPC), www.ndpc.gov.ng
  • United Kingdom — Information Commissioner's Office (ICO), www.ico.org.uk
  • Canada — Office of the Privacy Commissioner of Canada, www.priv.gc.ca
  • United States (California) — California Privacy Protection Agency, www.cppa.ca.gov

ODOS