GLOBALNET API SERVICES LTD · RC 9757658
Privacy Policy
This Privacy Policy explains how GLOBALNET API SERVICES LTD (RC 9757658), trading as GlobalNetApi ("we", "us" or "our"), handles personal data when you use our website, mobile application, wallet, developer API, support channels and related virtual top-up and bill-payment services. We act as a data controller for the processing described here and apply the Nigeria Data Protection Act 2023 (NDPA) and the NDPA General Application and Implementation Directive 2025 (GAID).
Last updated: 4 October 2026
1. Who this policy applies to
This policy applies to customers, prospective customers, website and app visitors, developer/API users, beneficiaries, support correspondents and authorised representatives. It does not replace a privacy notice issued by a bank, payment service provider, telecommunications network, utility, cable company, examination body or other independent service provider.
2. Personal data we collect
Account and identity data: name, username, email address, phone number, address, password hash, transaction-PIN hash, verification status and, where submitted for identity verification, BVN or NIN information stored using encryption and masked references. Wallet and transaction data: balances, virtual-account details, funding records, purchase amounts, service type, recipient number, network, meter number, smart-card or IUC number, selected plan, voucher fulfilment records, references, timestamps, reversals and dispute history. Device and technical data: IP address, device or browser type, operating system, session and security events, request identifiers, API usage, error records and logs needed for authentication, fraud prevention, availability and troubleshooting. Communications: support tickets, messages, complaints, feedback, notification preferences and account-deletion requests. Referral and developer data: referral relationships, rewards, API credentials and API request metadata. We do not store plaintext passwords, transaction PINs or full reusable API tokens after their secure creation flow.
3. Phone contacts and device permissions
If you grant contacts permission in the mobile app, the app reads phone numbers so you can choose a recipient from your phonebook. The permission is optional. Your phonebook is displayed for selection and is not bulk-uploaded to our servers. Only a number you actively select may be transmitted to complete a purchase or saved as a recipient when you ask us to save it. You can deny or revoke contacts permission in device settings and type a number manually. Biometric templates remain under the control of your device operating system; we receive only a success or failure result and do not receive or store your fingerprint or facial template.
4. How we obtain data
We obtain data directly from you when you register, verify an account, fund a wallet, make a purchase, contact support, use the API or request deletion; automatically from your use of our services and security systems; and from providers that process funding, identity verification, bill payment or digital service delivery. We may also receive lawful fraud, chargeback or compliance information from payment partners and authorities.
5. Purposes and lawful bases
We process data to create and authenticate accounts; perform contracts and requested transactions; provide wallet, funding, receipt, referral, support and API functions; verify identity where required; prevent fraud and abuse; protect users and infrastructure; reconcile transactions; resolve complaints; comply with tax, accounting, anti-fraud, court, law-enforcement and regulatory duties; improve reliability; and communicate essential service information. Depending on the activity, our lawful basis is performance of a contract or steps requested before a contract, compliance with a legal obligation, your consent, protection of vital interests in exceptional cases, or our legitimate interests in secure, reliable and accountable service delivery where those interests do not override your rights. You may withdraw consent at any time, but withdrawal does not affect earlier lawful processing or processing supported by another lawful basis.
6. Sharing and service providers
We share only what is reasonably necessary with payment processors, banks and payment service banks, virtual-account providers, identity-verification providers, telecommunications and data vendors, cable and utility providers, examination and voucher providers, cloud hosting and security vendors, email or notification providers, professional advisers, auditors and customer-support processors. We may disclose information to courts, regulators, law-enforcement agencies or other authorities where lawfully required, and during a genuine corporate restructuring subject to appropriate safeguards. Providers may act as our processors or as independent controllers under their own notices. We do not sell personal data or phonebook contacts.
7. International transfers
Some technology providers may process information outside Nigeria. Where personal data is transferred across borders, we use a transfer mechanism permitted by the NDPA and GAID, assess the destination and recipient, and apply contractual, organisational and technical safeguards appropriate to the risk.
8. Security
We use measures designed to protect confidentiality, integrity and availability, including access controls, least-privilege administration, encryption for selected sensitive fields, hashing for passwords and transaction PINs, secure session handling, audit trails, rate limiting, monitoring, backups and provider-access controls. No internet service can promise absolute security. You must protect your password, PIN, API token and device and report suspected compromise promptly. We will assess and notify affected persons and the Nigeria Data Protection Commission of a qualifying personal-data breach as required by law.
9. Retention
We keep personal data only for as long as necessary for the stated purpose and applicable legal, accounting, reconciliation, anti-fraud, complaint and dispute requirements. Account profile and authentication data is generally retained while the account is active and through deletion review. Transaction, wallet, payment, audit and complaint records may be retained after account deletion where Nigerian law or the establishment, exercise or defence of legal claims requires it. Provider-response logs are kept for a short operational period where configured; backups expire on controlled schedules. When retention is no longer justified, data is securely deleted or irreversibly anonymised.
10. Your rights
Subject to lawful limits and identity verification, you may ask to be informed about processing; access your personal data; correct inaccurate or incomplete data; withdraw consent; object to or restrict certain processing; receive portable data where applicable; and request deletion. You may submit an account-deletion request in the app or at https://globalnetapi.com/account-deletion. You may also complain to us or lodge a complaint with the Nigeria Data Protection Commission. We will not retaliate against you for exercising a right. Some information cannot be deleted immediately where retention is required by law or necessary for an unresolved transaction, fraud investigation, dispute or legal claim.
11. Automated processing
We may use automated rules for network identification, transaction routing, service limits, duplicate prevention, security monitoring and fraud signals. We do not intentionally make a solely automated decision that produces a legal or similarly significant effect without a lawful basis and the safeguards required by the NDPA. You may contact support to request human review of an eligible decision.
12. Children
The service is intended for persons aged 18 or older. We do not knowingly create accounts for children. If you believe a child provided personal data without appropriate authority, contact us so we can investigate and take appropriate action.
13. Cookies and local storage
The website uses strictly necessary cookies and similar storage for authentication, cross-site request forgery protection, preferences and security. The app uses secure device storage and local storage for sessions, theme preferences and device-specific settings. We do not use these technologies to sell personal profiles. Any future non-essential analytics or advertising technology will be subject to an appropriate notice and consent choice where required.
14. Changes and contact
We may update this policy when services, providers or legal requirements change. Material changes will be communicated through the website, app or registered contact details where appropriate. Privacy and data-subject requests can be sent to support@globalnetapi.com. We may ask for information needed to verify identity and protect the account before disclosing, correcting or deleting data.
15. Nigerian legal framework
This policy is designed with reference to the Nigeria Data Protection Act 2023, the NDPA General Application and Implementation Directive 2025, the Federal Competition and Consumer Protection Act 2018 and applicable Central Bank of Nigeria payment and consumer-protection rules where our activities or regulated partners fall within their scope.
Questions? Contact support@globalnetapi.com.
