Compliant with NDPR & GDPR • Last updated: September 2026
At Globconnects, we are committed to safeguarding your personal data and upholding the highest standards of financial privacy and information security. This Privacy Policy details how we collect, process, encrypt, store, and protect your information.
We collect and process only the minimal personal data required to deliver VTU top-ups, issue virtual accounts/cards, provide customer support, and meet statutory regulatory obligations:
2.1. Encryption at Rest: All sensitive identity documents and KYC numbers are encrypted using AES-256-GCM prior to database persistence. Plaintext BVN numbers are never stored in the clear.
2.2. Blind Indexing: To detect multi-account identity theft and duplicate farming without exposing cleartext data, we compute deterministic keyed HMAC-SHA256 blind hashes.
2.3. Passwords: All account credentials and PINs are hashed using irreversible bcrypt with high work factors.
We use session cookies strictly for authentication and CSRF protection. In production environments:
Secure flag (transmitted exclusively over TLS/HTTPS).HttpOnly to prevent client-side JavaScript access and XSS theft.SameSite=Lax is enforced to mitigate Cross-Site Request Forgery (CSRF).We never sell, monetize, or rent your personal information. We share data only with:
Under the Nigeria Data Protection Act (NDPA) and international privacy frameworks, you have the right to request access to your transaction records, update your profile details, or request account closure. In compliance with financial regulatory recordkeeping statutes, financial ledger records are retained for statutory minimum retention periods.
For data inquiries, rights requests, or security notices, reach our Data Protection team at privacy@globconnects.net.