Cookie Policy
Last updated: September 28, 2026
MASTER PRIVACY POLICY
Effective Date: 28 September 2026
Version: 1.0
Last Reviewed: 28 September 2026
Next Review Date: 28 September 2027
1.Purpose and commitment
Fuelventa Technologies Limited (” Fuelventa”, “Company”, “we”, “us or “our”) is a technology company established to develop, own, commercialise and operate technology-enabled products, platforms, software and services relating to the digitisation of filling-station, depots and refineries, operations, including inventory sponsorship and businesses within the energy and mobility ecosystem.
Fuelventa recognises that personal data is an important business asset that must be handled responsibly, securely and transparently.
We are committed to protecting the privacy and confidentiality of personal data entrusted to us and to embedding privacy and data protection principles into the design, development and operation of our technology products and services.
This Privacy Policy sets out the principles governing Fuelventa’s collection, use, storage, disclosure, transfer, protection, and deletion of personal data. It has the following policy documents as schedules:
a.Cookie policy and cookie management notice
b.Personal data breach response and notification procedure
c.Data subject access request and data rights procedure
2.Regulatory framework
This Policy is principally designed to comply with the:
a.Nigeria Data Protection Act, 2023 (”NDPA”);
b.applicable regulations, directives, guidelines and codes issued by the Nigeria Data Protection Commission (”NDPC”);
c.applicable cybersecurity, electronic communications and consumer-protection requirements; and
d.other applicable data-protection laws in jurisdictions in which Fuelventa operates.
Where a foreign data-protection law applies to a particular processing activity, Fuelventa shall implement additional measures where reasonably necessary to comply with that law.
3.Scope
This Policy applies to personal data processed through or in connection with:
a.Fuelventa’s websites;
b.Mobile applications;
c.Desktop application;
d.APIs;
e.Cloud infrastructure;
f.customer-management systems;
g.analytics and reporting systems;
h.payment integrations;
i.customer-support systems;
j.marketing systems;
k.enterprise integrations; and
l.other current or future Fuelventa technology products and services.
4.Fuelventa as controller and processor
4.1Fuelventa as data controller
Fuelventa acts as a data controller when it determines the purposes and means of processing personal data. Examples may include personal data relating to:
a.Fuelventa customers;
b.prospective customers;
c.website visitors;
d.employees;
e.contractors;
f.suppliers;
g.investors;
h.business contacts;
i.platform administrators; and
j.marketing recipients.
4.2Fuelventa as Data Processor
Fuelventa will act as a data processor where it processes personal data on behalf of a filling-station, depot, logistic or refinery operator, corporate customer, inventory sponsor or other organisation pursuant to that organisation’s documented instructions. Examples may include personal data relating to:
a.filling-station or depot attendants;
b.station or refinery employees;
c.customers of the filling station, depot or refinery;
d.transaction users;
e.customer accounts;
f.operational personnel; and
g.other persons whose information is uploaded into a customer’s Fuelventa environment.
Where Fuelventa acts as processor, the customer’s Data Processing Agreement with Fuelventa shall govern the processing relationship.
5.Categories of personal data
Depending on the service involved, Fuelventa may process:
a.Identity Data - Names, photographs, identification information and usernames.
b.Contact Data - Telephone numbers, email addresses, physical addresses and business contact details.
c.Employment and Workforce Data - Job titles, employee identifiers, shift information, attendance records, refinery, report or station assignments and other employment-related information.
d.Account Data - Usernames, account identifiers, authentication information, permissions and access records.
e.Transaction Data - Transaction references, dates, times, amounts, products purchased, transaction status and related operational information.
f.Location Data - Filling-station, refinery or depot locations, device locations and other location information where necessary for the relevant service.
g.Device and Technical Data - IP addresses, device identifiers, browser information, operating systems, application versions, logs and technical metadata.
h.Communications Data - Customer-service communications, enquiries, complaints, feedback and correspondence.
i.Usage Data - Information concerning interaction with Fuelventa’s platforms, features and services.
6.Principles of processing
Fuelventa shall process personal data in accordance with the following principles:
a.lawfulness, fairness and transparency;
b.purpose limitation;
c.data minimisation;
d.accuracy;
e.storage limitation;
f.integrity and confidentiality;
g.accountability;
h.privacy by design and default; and
i.respect for data-subject rights.
7.Purposes of processing
Fuelventa may process personal data to:
a.digitise filling-station, depot or refinery operations;
b.Manage pumps telemetry data
c.process and reconcile transactions and cash handovers;
d.manage inventory and operational data;
e.administer customer accounts;
f.provide analytics and reporting;
g.authenticate users;
h.maintain platform security;
i.prevent fraud and misuse;
j.provide customer support;
k.communicate with customers;
l.develop and improve products;
m.conduct business administration;
n.comply with legal obligations;
o.establish or defend legal claims; and
p.perform other lawful purposes communicated to the relevant data subject.
8.Lawful basis
8.1Fuelventa shall identify and document an appropriate lawful basis before processing personal data. Depending on the circumstances, this may include:
a.consent;
b.performance of a contract;
c.compliance with a legal obligation;
d.protection of vital interests;
e.public interest; or
f.legitimate interests, subject to applicable legal requirements.
8.2Fuelventa shall not use consent where another lawful basis is more appropriate merely as a matter of convenience.
9.Privacy by design
9.1Privacy and data protection shall be incorporated into the design and development lifecycle of Fuelventa products.
9.2Where appropriate, product-development teams shall consider:
a.data minimisation;
b.access controls;
c.encryption;
d.retention periods;
e.pseudonymisation;
f.anonymisation;
g.user permissions;
h.audit trails;
i.privacy notices;
j.consent mechanisms;
k.data-subject rights; and
l.deletion functionality.
9.3Where processing is likely to present significant privacy risks, Fuelventa shall undertake an appropriate Data Protection Impact Assessment (”DPIA”).
10.Data security
10.1Fuelventa shall maintain technical and organisational measures appropriate to the nature and risk of the processing. These may include:
a.encryption in transit and at rest;
b.role-based access controls;
c.multi-factor authentication;
d.secure credential management;
e.network security;
f.vulnerability management;
g.security monitoring;
h.logging;
i.backup and disaster recovery;
j.secure software development;
k.penetration testing;
l.employee confidentiality obligations;
m.security training; and
n.incident-response procedures.
10.2Access to personal data shall be based on the principle of least privilege.
11.Data retention
11.1Personal data shall not be retained indefinitely.
11.2The following retention period shall apply to the listed categories:
| S/n | Data type | Retention period |
| 1 | Customer account data | 5 years after termination |
| 2 | Transaction data | 5 years after transaction |
| 3 | Support tickets | 24 months |
| 4 | Marketing records | until consent withdrawal or 24 months of inactivity |
| 5 | Security logs | 12 months |
11.3Upon expiry of the applicable retention period, personal data shall be:
a.securely deleted;
b.securely destroyed;
c.anonymised; or
d.retained only where required or permitted by applicable law.
12.Third-party processors
12.1Fuelventa may engage carefully selected third-party service providers. Examples include:
a.cloud-hosting providers;
b.payment processors;
c.communications providers;
d.cybersecurity providers;
e.analytics providers;
f.customer-support providers;
g.authentication providers; and
h.other technology infrastructure providers.
12.2Fuelventa shall undertake reasonable due diligence before appointing material processors.
12.3Where required, processors shall be bound by written agreements containing appropriate data-protection obligations which may include to:
a.Maintain appropriate security controls.
b.Report breaches promptly.
c.Permit audits where appropriate.
d.Assist with data-subject requests.
13.International data transfers
Where personal data is transferred outside Nigeria, Fuelventa shall implement appropriate safeguards required by applicable law. Relevant safeguards may include:
a.contractual safeguards;
b.transfer assessments;
c.appropriate technical measures;
d.security controls;
e.adequacy mechanisms where applicable; and
f.other safeguards recognised under applicable law.
14.Data-subject rights
14.1 Subject to applicable law, individuals may have rights including:
a.right to be informed;
b.right of access;
c.right to rectification;
d.right to object;
e.right to restriction;
f.right to erasure;
g.right to data portability;
h.right to withdraw consent;
i.right concerning automated decision-making; and
j.right to lodge a complaint.
15.Data breaches
Fuelventa shall maintain an internal Personal Data Breach Response Procedure. Where a breach occurs, Fuelventa shall:
a.identify and contain the incident;
b.assess the nature and scope of the breach;
c.preserve evidence;
d.assess the risk to affected individuals;
e.notify relevant customers where Fuelventa acts as processor;
f.notify the NDPC where legally required;
g.notify affected data subjects where legally required;
h.remediate the vulnerability; and
i.document the incident and lessons learned.
16.Sensitive personal data
Fuelventa does not intentionally process sensitive personal data except where required by law, expressly authorised by the data subject, or necessary for employment, security or regulatory purposes.
17.Children
Fuelventa’s services are primarily intended for businesses and adult users. Fuelventa shall not knowingly collect children’s personal data except where lawful and appropriate safeguards are in place.
18.Automated decision-making
18.1Where Fuelventa implements automated decision-making that may produce legal or similarly significant effects on individuals, it shall assess the applicable legal requirements and implement appropriate safeguards.
18.2Individuals shall have the right to request human intervention, express their views, and contest decisions where automated processing produces legal or similarly significant effects.
19.Anonymised data
19.1Fuelventa may use properly anonymised and aggregated information for:
a.analytics;
b.product development;
c.operational intelligence;
d.benchmarking;
e.research;
f.business planning; and
g.service improvement.
19.2Anonymised information shall not be treated as personal data where it has been irreversibly anonymised in accordance with applicable law.
20.Confidentiality
Personnel and contractors authorised to access personal data shall be subject to appropriate confidentiality obligations.
Unauthorised disclosure, use, copying or extraction of personal data constitutes a serious compliance matter and may result in disciplinary or contractual action.
21.Data governance
Fuelventa shall maintain, as appropriate:
a.records of processing activities;
b.data inventories;
c.data-flow maps;
d.processor registers;
e.sub-processor registers;
f.retention schedules;
g.DPIAs;
h.incident registers;
i.data-subject request registers;
j.security policies; and
k.relevant privacy training records.
22.Privacy contact
Fuelventa has appointed a Privacy Lead who is responsible for overseeing compliance with applicable data protection laws and coordinating responses to privacy-related enquiries and requests.
Email: privacy@fuelventa.com
23.Changes
Fuelventa may amend this Policy from time to time. Material changes shall be communicated through appropriate channels.
Schedule 1
Cookie policy and cookie management notice
Fuelventa Technologies Limited
Effective Date: [1 October 2026]
1.Purpose
Fuelventa uses cookies and similar technologies on its websites, applications and digital platforms.
This Cookie Policy explains what cookies are, the categories of cookies we may use, why we use them and how users may manage their preferences.
The NDPC’s current implementation materials specifically contemplate privacy and cookie notices on websites and an opportunity for users to accept or decline applicable cookies.
2.What are cookies?
Cookies are small text files or similar technologies stored on or associated with a user’s device when the user accesses a website or application.
They may enable a website or application to recognise a device, maintain a session, remember preferences or understand how services are used.
3.Categories of cookies
3.1Strictly necessary cookies
These are required for essential functions, including:
a.authentication;
b.security;
c.session management;
d.account access; and
e.core platform functionality.
These cookies cannot ordinarily be disabled without affecting the operation of the service.
3.2Functional cookies
These remember preferences and settings, such as:
a.language;
b.user preferences;
c.interface configuration; and
d.other functionality.
3.3Analytics cookies
These help us understand:
a.website traffic;
b.feature usage;
c.performance;
d.navigation patterns; and
e.technical errors.
Where required by law, Fuelventa will obtain appropriate consent before using non-essential analytics cookies.
3.4Marketing cookies
Where applicable, these may be used to understand interaction with marketing communications or deliver relevant advertising.
Fuelventa will not deploy non-essential marketing cookies without an appropriate lawful basis.
4.Third-party cookies
Some cookies may be placed by third-party service providers, including analytics, security, payment or other technology providers.
Fuelventa does not control the privacy practices of third parties, and users should consult the relevant third-party privacy notices.
5.Cookie preferences
5.1Where required, users shall be provided with an appropriate cookie preference mechanism.
5.2Users may:
a.accept all cookies;
b.reject non-essential cookies; or
c.customise their preferences.
5.3Cookie preferences may be changed where the relevant platform permits.
5.4Users may withdraw cookie consent at any time through the cookie preference centre available on Fuelventa's website.
6.Contact
Questions regarding cookies may be directed to:
Schedule 2
Personal data breach response and notification procedure
1.Purpose
This Procedure establishes Fuelventa’s internal process for detecting, assessing, containing, investigating, reporting and remediating personal data breaches.
It applies to all Fuelventa personnel, contractors and relevant service providers.
2.What constitutes a data breach?
A Personal Data Breach includes an incident involving:
a.unauthorised access;
b.unauthorised disclosure;
c.accidental disclosure;
d.loss of personal data;
e.destruction;
f.corruption;
g.alteration;
h.ransomware;
i.credential compromise;
j.hacking;
k.malware;
l.stolen devices;
m.misdirected emails; or
n.any other event compromising the confidentiality, integrity or availability of personal data.
3.Immediate reporting
Any employee or contractor who suspects a breach shall immediately report it to:
Privacy/Data Protection Lead: Kemjika Igwe, Esq.
Email: privacy@fuelventa.com
Emergency Contact: 08138063507
Employees shall not delay reporting while attempting to investigate the matter independently.
4.Incident classification
The Data Protection/Incident Response Team shall classify incidents as:
a.Level 1 – Low
No material personal-data exposure or significant risk identified.
b.Level 2 – Moderate
Limited personal-data exposure with manageable risk.
c.Level 3 – High
Significant personal-data exposure, sensitive information, large numbers of affected individuals or significant risk.
d.Level 4 – Critical
Major compromise involving substantial data, systemic security failure, significant financial or operational consequences, or serious risk to data subjects.
5.Incident response team
The response team should ordinarily include:
a.Chief Executive Officer or designated executive;
b.Data Protection Officer/Privacy Lead;
c.Chief Technology Officer/Technology Lead;
d.Information Security Lead;
e.Legal Counsel;
f.Communications representative; and
g.relevant business-unit representative.
External cybersecurity, forensic or legal specialists may be engaged where necessary.
6.Containment
Immediate measures may include:
a.disabling compromised accounts;
b.isolating affected systems;
c.revoking credentials;
d.blocking unauthorised access;
e.preserving logs;
f.securing affected devices;
g.terminating malicious sessions; and
h.deploying security patches.
7.Investigation
The response team shall determine:
a.what happened;
b.when it occurred;
c.when it was discovered;
d.which systems were affected;
e.what personal data was involved;
f.how many individuals may be affected;
g.whether the data was encrypted or otherwise protected;
h.the likely consequences;
i.whether third parties are involved; and
j.what remediation is required.
8.Customer notification
Where Fuelventa acts as processor and Customer personal data is affected, Fuelventa shall notify the Customer without undue delay and, where reasonably practicable, within 24 hours of becoming aware of the breach.
The notification shall be updated as further information becomes available.
9.Regulatory notification
Fuelventa shall assess whether notification to the NDPC is required.
Under section 40 of the NDPA, where a breach is likely to result in a risk to individuals’ rights and freedoms, a controller must notify the Commission within 72 hours of becoming aware of the breach.
Where the breach is likely to result in a high risk to the rights and freedoms of a data subject, appropriate communication to the affected data subject shall also be considered and made where legally required.
10.Content of notification
Where applicable, notification should include:
a.nature of breach;
b.date/time of occurrence;
c.date/time discovered;
d.categories of affected data;
e.approximate number of affected individuals;
f.likely consequences;
g.measures already taken;
h.proposed remedial measures; and
i.contact details of the relevant privacy representative.
11.Data-subject communication
Communications to affected individuals shall:
a.be clear;
b.avoid unnecessary technical language;
c.explain what happened;
d.explain likely consequences;
e.identify protective measures;
f.provide appropriate contact information; and
g.explain any steps the individual should take.
12.Post-incident review
Following a material incident, Fuelventa shall conduct a post-incident review addressing:
a.root cause;
b.control failures;
c.remediation;
d.security improvements;
e.employee training;
f.vendor management;
g.policy changes; and
h.whether a DPIA or security assessment should be revisited.
13.Record keeping
Fuelventa shall maintain an incident register recording material data breaches and relevant decisions, including incidents where notification was considered unnecessary.
Schedule 3
Data subject access request and data rights procedure
1.Purpose
This Procedure establishes the process by which individuals may exercise their rights regarding personal data processed by Fuelventa.
2.Request channel
2.1Requests may be submitted to:
Email: xx@fuelventa.com
Name: [xx]
2.2Requests may be made in writing or through an approved electronic mechanism.
3.Information to be provided
A requester should provide:
a.full name;
b.contact information;
c.nature of request;
d.relevant account or customer information;
e.description of the data requested;
f.relevant dates or transaction references, where known; and
g.any other information reasonably necessary to locate the data.
4.Identity verification
4.1Fuelventa may request reasonable information necessary to verify the identity of the requester
4.2Verification shall be proportionate
4.3Fuelventa shall not request unnecessary identification information
5.Request logging
Each request shall be recorded in a DSAR Register containing:
a.request date;
b.requester;
c.request type;
d.verification status;
e.responsible officer;
f.response deadline;
g.action taken;
h.response date; and
i.reason for any refusal or restriction.
6.Search and collection
The Privacy Lead shall coordinate with relevant departments, including:
a.Technology;
b.Customer Support;
c.Finance;
d.Human Resources;
e.Legal;
f.Information Security; and
g.relevant business units.
Searches should cover relevant systems reasonably likely to contain responsive personal data.
7.Types of request
Fuelventa may receive requests for:
a.access;
b.rectification;
c.erasure;
d.restriction;
e.objection;
f.portability;
g.withdrawal of consent; or
h.information concerning automated decision-making.
8.Access response
Where access is granted, Fuelventa should provide:
a.the relevant personal data;
b.purposes of processing;
c.categories of personal data;
d.relevant recipients;
e.retention information;
f.source of data where appropriate;
g.applicable rights; and
h.other information required by law.
9.Third-party data
Where responding to a request would disclose another person’s personal data, Fuelventa shall assess whether disclosure is lawful and whether appropriate measures should be taken to protect that third party.
10.Refusal or restriction
10.1Fuelventa may refuse or restrict a request where permitted by law.
10.2Where a request is refused, Fuelventa shall, where legally permissible:
a.explain the reason;
b.identify the relevant legal basis;
c.explain any available review or complaint mechanism; and
d.advise the requester of their right to approach the NDPC where applicable.
11.Deadlines
11.1Fuelventa will endeavour to respond to valid requests within thirty (30) days, unless a longer period is permitted by applicable law.
11.2Where additional information is reasonably required to verify identity or clarify the request, the processing timeline shall be managed in accordance with applicable law.
12.Processor requests
12.1Where Fuelventa receives a request concerning personal data for which one of its customers is the controller, Fuelventa shall promptly refer the request to the relevant customer and provide reasonable assistance.
12.2Fuelventa shall not independently determine the customer’s response unless:
a.the customer authorises it; or
b.applicable law requires Fuelventa to respond directly.
13.Data portability
13.1Where applicable, Fuelventa shall provide personal data in a structured, commonly used and machine-readable format.
13.2Where technically feasible and legally required, Fuelventa may transmit the information directly to another controller at the request of the Data Subject.
14.Erasure
14.1Where a valid erasure request is granted, Fuelventa shall take reasonable steps to delete the relevant personal data from active systems.
14.2Where deletion from backups is not immediately technically feasible, the data shall be placed beyond ordinary use and deleted in accordance with the applicable backup retention cycle.
15.Rectification
Where inaccurate personal data is identified, Fuelventa shall correct or update the information within a reasonable period and, where required, communicate the correction to relevant recipients.
16.Complaints
Where an individual is dissatisfied with Fuelventa’s handling of a request, the individual may contact:
Fuelventa Privacy/Data Protection Office
privacy@fuelventa.com
The individual may also exercise applicable rights to lodge a complaint with the Nigeria Data Protection Commission.
17.Governance
The Privacy Lead shall conduct periodic reviews of the DSAR process and ensure that relevant personnel are trained in the handling of data-subject requests.