BREAKING Afri Invoice secures NRS accreditation as a System Integrator for Nigeria's mandatory e-Invoicing platform. Read the mandate timeline

Privacy Policy

Afri Invoice — NRS-Accredited E-Invoicing Platform (Systems Integrator & Access Point Provider)

Last Updated
1 January 2025
Effective
1 January 2025

This Privacy Policy explains how Afri Invoice Nigeria Limited (RC 7570323) ("Afri Invoice", "Company", "we", "us", or "our") collects, uses, discloses, and protects personal data when you use the Afri Invoice platform, website, mobile application, and APIs (together, the "Platform"). Afri Invoice is accredited by the Nigeria Revenue Service (NRS) as a Systems Integrator (SI) and an Access Point Provider (APP) under the NRS Merchant Buyer Solution (MBS) e-invoicing framework. This Policy should be read together with our Terms & Conditions and our Cookie Policy.

We process personal data in accordance with the Nigeria Data Protection Act 2023 (NDPA), the Nigeria Data Protection Regulation 2019 (NDPR), and, where applicable to users in the United Kingdom or the European Union, the UK GDPR and the EU General Data Protection Regulation (GDPR).

01

Who We Are (Data Controller)

For personal data processed in connection with your account and use of the Platform, the data controller is Afri Invoice Nigeria Limited, 10 Gbolagade Street, Ikotun, Lagos, Nigeria. Our Data Protection Officer (DPO) can be contacted at support@afrinvoice.com.

An important distinction: when we validate, digitally sign, and transmit your electronic invoices to the NRS MBS platform as your Access Point Provider, or integrate your ERP or accounting systems as your Systems Integrator, we act on your instructions and on the mandate of applicable tax law. In respect of the personal data contained within your invoice and transaction records (for example, the names and contact details of your customers and suppliers), you are the data controller and Afri Invoice acts as a data processor, except to the extent that the law requires otherwise.

02

Personal Data We Collect

2.1 Account and Identity Data

Name, business name, email address, telephone number, job title, login credentials, and, for business verification (KYC/KYB), Corporate Affairs Commission (CAC) registration details, Tax Identification Number (TIN), Bank Verification Number (BVN), directors' and signatories' identification documents, and evidence of authority.

2.2 Invoice and Transaction Data

Data contained in electronic invoices, credit notes, and debit notes created on or transmitted through the Platform, including buyer and seller identities and TINs, addresses, line items, values, tax computations (VAT, WHT), payment terms and status, and the validation identifiers (such as the Invoice Reference Number and QR code) returned by the MBS platform.

2.3 Financial and Billing Data

Credit purchases and top-ups, Credit balance and consumption records, billing history, and payment details. Card payments are processed by licensed payment gateways; we do not store full card numbers on our systems.

2.4 Technical and Usage Data

IP address, device and browser type, operating system, log data, API usage records, audit trails, and cookie data as described in our Cookie Policy.

2.5 Communications Data

Support tickets, emails, and other correspondence with our customer care and compliance teams.

03

Lawful Bases for Processing

Under the NDPA, we rely on the following lawful bases:

  • Performance of a contract: to create and administer your account, provide SI and APP services, and process billing;
  • Legal obligation: to validate, digitally sign, and transmit e-invoice data to the NRS in accordance with the national e-invoicing mandate; to conduct KYC/KYB and anti-money laundering checks; to retain fiscal records for statutory periods; and to respond to lawful requests from competent authorities;
  • Legitimate interests: to secure the Platform, prevent fraud and abuse, improve our services, and manage our business, provided such interests are not overridden by your rights;
  • Consent: for optional cookies, marketing communications, and any other processing for which we ask your permission. You may withdraw consent at any time without affecting the lawfulness of prior processing.
04

How We Use Personal Data

  • To provide, operate, and maintain the Platform and its e-invoicing services;
  • To onboard your business to the NRS MBS platform and manage your taxpayer profile as your Access Point Provider;
  • To integrate your ERP, accounting, POS, or billing systems as your Systems Integrator;
  • To validate invoice data against NRS schema rules, digitally sign e-invoices, transmit them to the MBS platform, and retrieve clearance status and validation identifiers;
  • To verify your identity and business and meet compliance obligations (KYC/KYB, AML/CFT);
  • To process Credit purchases, top-ups, payments, re-credits, and refunds;
  • To provide customer support and manage complaints;
  • To monitor, secure, and audit the Platform, including maintaining cryptographic audit trails of every e-invoice processed;
  • To send service notices and, with your consent, marketing communications;
  • To comply with legal and regulatory obligations and to establish, exercise, or defend legal claims.
05

Disclosure of Personal Data

5.1 Disclosure to the Nigeria Revenue Service

As an NRS-accredited Access Point Provider, we transmit the invoice and transaction data you submit for clearance to the NRS Merchant Buyer Solution platform in real time, as required by the national e-invoicing framework. This disclosure is a legal requirement of the e-invoicing mandate: without it, your e-invoices cannot be validated or cleared. The NRS processes such data as a public authority under its own legal mandate.

5.2 Other Disclosures

  • Service providers and sub-processors: hosting, infrastructure, communications, and analytics providers acting under contract and confidentiality obligations;
  • Payment gateways: licensed providers who process payments made through the Platform;
  • Group entities: our affiliated offices in the United Kingdom and France, where necessary for support, operations, and administration, subject to the safeguards in Section 6;
  • Regulators and authorities: the NRS, the Nigeria Data Protection Commission (NDPC), law enforcement, courts, and other competent bodies where disclosure is required by law;
  • Professional advisers: auditors, insurers, and legal advisers under confidentiality obligations;
  • Business transfers: in connection with a merger, acquisition, or restructuring, subject to appropriate protections.

We do not sell personal data to third parties.

06

International Transfers

Personal data is primarily hosted and processed in secure clouds serving our Nigerian operations. Where personal data is transferred outside Nigeria, for example, to our offices in the United Kingdom and France or to international service providers, we implement the safeguards required by the NDPA and the NDPC, such as transfers to jurisdictions providing an adequate level of protection, contractual safeguards, or your explicit consent where applicable. For users subject to the UK GDPR or EU GDPR, transfers are protected by appropriate mechanisms such as adequacy decisions or standard contractual clauses.

07

Data Security

We operate an Information Security Management System certified to ISO/IEC 27001:2022. Security measures include TLS encryption for data in transit, AES-256 encryption for data at rest, OAuth 2.0 secured APIs, two-factor authentication, role-based access controls, network monitoring, penetration testing, and regular internal and external audits. Every e-invoice processed through the Platform is cryptographically signed and fully traceable. No system is completely immune to breaches; in the event of a personal data breach likely to result in a risk to your rights, we will notify the NDPC and affected individuals within 72 hours of becoming aware, in line with the NDPA.

08

Data Retention

After the applicable retention period, data is securely deleted or irreversibly anonymised.

09

Your Rights

Subject to the conditions and exemptions in the NDPA, you have the right to:

  • Access: obtain confirmation of processing and a copy of your personal data;
  • Rectification: have inaccurate or incomplete data corrected;
  • Erasure: request deletion of data, save where retention is required by law (for example, fiscal records transmitted to the NRS);
  • Restriction and objection: restrict or object to certain processing, including direct marketing;
  • Data portability: receive your data in a structured, commonly used, machine-readable format;
  • Withdraw consent: at any time, where processing is based on consent;
  • Complain: lodge a complaint with the Nigeria Data Protection Commission (NDPC) or, for UK and EU users, with your local supervisory authority.

To exercise any of these rights, contact our DPO at compliance@afrinvoice.com. We will respond within the timelines prescribed by the NDPA. Please note that statutory e-invoicing records already transmitted to the NRS are held by the NRS under its own legal mandate, and requests concerning those records may need to be directed to the NRS.

10

Children

The Platform is a business service and is not directed at children. We do not knowingly collect personal data from anyone under 18 years of age. If you believe a minor has provided us with personal data, please contact us and we will delete it.

11

Cookies

We use cookies and similar technologies as described in our Cookie Policy, which forms part of this Privacy Policy.

12

Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated to registered users via email or in-Platform notice before taking effect. The "Last Updated" date at the top of this Policy indicates the most recent revision.

13

Contact Us

Afri Invoice Nigeria Limited
Registered in Nigeria · RC 7570323
Address
10 Gbolagade Street, Ikotun, Lagos, Nigeria