Privacy Policy
Last Updated: May 29, 2026
Xavorian ("we", "us", or "our") is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, store, and share your personal data when you use the Xavorian real estate marketplace platform, in strict compliance with the Nigeria Data Protection Regulation (NDPR), the Nigeria Data Protection Act (NDPA) 2023, and other applicable data protection laws in Nigeria.
1. Important Information & Who We Are
Data Controller
Xavorian is the data controller responsible for your personal data. We have appointed a Data Protection Officer (DPO) who is responsible for overseeing questions in relation to this privacy policy. If you have any questions, including any requests to exercise your legal rights under the NDPR, please contact our DPO:
- Email Address: dpo@xavorian.xyz
- Registered Address: Xavorian Technologies Ltd, Benin City, Edo State, Nigeria.
2. The Data We Collect About You
Personal data means any information about an individual from which that person can be identified. We may collect, use, store, and transfer different kinds of personal data about you, categorized as follows:
- Identity Data: First name, last name, username, date of birth, gender, national identity documents (NIN, International Passport, or Driver's License), and live selfie biometrics.
- Contact Data: Billing address, physical address, email address, and telephone numbers.
- Financial Data: Bank account details, escrow account references, payment card tokens, and BVN (where required strictly for high-value escrow transaction AML compliance).
- Transaction Data: Details about payments into and out of escrow accounts, property purchases, lease agreements, and service fees paid on our platform.
- Technical Data: Internet protocol (IP) address, login data, browser type and version, time zone setting, location data, and platform usage metrics.
- Profile & Communications Data: Your username and password, listings created, transaction disputes raised, interests, preferences, feedback, and customer support communications.
3. Lawful Basis for Processing
Under the NDPR, we are required to identify a lawful basis for every processing activity involving your personal data. We rely on the following bases:
- Consent: Where you have given explicit consent to process your data (e.g., subscribing to newsletters, placing optional cookies). You can withdraw this consent at any time.
- Performance of a Contract: Where processing is necessary to execute the contract you are entering into with us (e.g., executing the Escrow Agreement, creating an account, or listing properties).
- Legal Obligation: Where processing is necessary to comply with Nigerian laws, including anti-money laundering (AML) guidelines, taxation laws, and court orders.
- Legitimate Interests: Where it is necessary for our legitimate business interests (or those of a third party) and your fundamental rights do not override those interests (e.g., platform security, fraud prevention, and system maintenance).
4. Your Rights Under the NDPR
As a Nigerian data subject, you have several powerful rights under the Nigeria Data Protection Regulation (NDPR) in relation to your personal data:
- Right to be Informed: The right to clear, transparent information about how we collect and process your personal data.
- Right of Access: The right to request a copy of the personal data we hold about you (commonly known as a "data subject access request").
- Right to Rectification: The right to request that we correct any incomplete or inaccurate data we hold about you.
- Right to Erasure (Right to Be Forgotten): The right to ask us to delete or remove personal data where there is no good reason for us continuing to process it, subject to statutory retention periods.
- Right to Restrict Processing: The right to ask us to suspend the processing of your personal data in certain scenarios, such as verifying data accuracy.
- Right to Data Portability: The right to request the transfer of your personal data to you or to a third-party service provider in a structured, machine-readable format.
- Right to Object: The right to object to the processing of your personal data where we are relying on a legitimate interest or direct marketing.
To exercise any of these rights, please submit a written request to our DPO at dpo@xavorian.xyz. We will respond to all legitimate requests within 30 calendar days.
5. Data Security & Retention
Data Security
We have put in place robust security measures to prevent your personal data from being accidentally lost, used, accessed in an unauthorized way, altered, or disclosed. All transaction and financial data is transmitted using secure socket layer (SSL/TLS) encryption. Access to your personal data is restricted to authorized employees, contractors, and partners who have a strict business "need to know" and are bound by legal confidentiality obligations.
Data Retention
We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including satisfying any legal, accounting, tax, or reporting requirements. Under Nigerian anti-money laundering (AML) guidelines and tax laws, we are legally required to retain basic customer identity, transaction, and financial data for a minimum of 7 years after they cease to be active users.
6. International Data Transfers
Your personal data may be stored and processed on cloud servers located outside the Federal Republic of Nigeria. In all such cases, we ensure that the transfer of your data is done in compliance with the NDPR's requirements on international transfers, ensuring adequate safeguards are implemented (such as Standard Contractual Clauses approved by the Nigeria Data Protection Commission - NDPC).