Privacy Policy for Farath Holdings
1. Introduction
https://farathholdings.com/ is provided by Farath Holdings L.L.C-FZ (“Farath”).
At Farath, we value your privacy, and we are committed to safeguarding your personal information. All personal data that you provide us will be protected and kept confidential among our affiliates, representatives, and privies. This Privacy Policy does not apply to financial institutions, other data providers, other partners, or any other entities that are not affiliates of Farath. This Privacy Policy also does not apply to what any of them may do with any of your information that we provide to them (or any other information they may collect about you separately from Farath). We encourage you to review the notices of those third parties for information about their practices.
Throughout the website, the terms “we”, “us” and “our” refer to Farath.
This Privacy Policy explains how we collect, use, share and protect your personal data in connection with your use of our services. This Policy also sets out your rights and who you may contact for further information.
You agree to this Privacy Policy by visiting our website and when you use our services.
Your use of our services, and any dispute over privacy is subject to this Policy and our Terms of Service, including its applicable limitations on damages and the resolution of disputes. Our Terms of Service are incorporated by reference into this Policy.
Our website and services are not directed at you if we are prohibited by any law of any jurisdiction from making the information on our website available to you and is not intended for any use that would be contrary to local law or regulation.
2. Definitions
“consent” |
means the consent of the data subject which must be a freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which they (by a statement or by a clear affirmative action) signify their agreement to the processing of personal data relating to them; |
“data controller” |
means the natural or legal person or organisation which, alone or jointly with others, determines the purposes and means of the processing of personal data. For the purposes of this Policy, Farath is the data controller of all personal data relating to data subjects; |
“data processor” |
means a person or organisation which processes personal data on behalf of a data controller. This includes Farath, its employees and third-party service providers; |
“Data Protection Legislation” |
means all applicable data protection and privacy laws including, but not limited to the Nigeria Data Protection Act 2023, the Nigeria Data Protection Regulation 2019 (NDPR), the Personal Data Protection Law, Federal Decree Law No. 45 of 2021 (UAE) regarding the Protection of Personal Data and the United Kingdom General Data Protection Regulation (UK GDPR); |
“data subject” |
means a living, identified, or identifiable individual about whom Farath holds personal data; |
“personal data” |
means any information relating to a data subject who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that data subject; |
“personal data breach” |
means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed; |
“processing” |
means any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. |
3. Consent
3.1. Where processing of your personal data is based on consent, we shall obtain the requisite consent at the time of collection of the personal information. In this regard, you consent to the processing of your personal information when you access our website, or use our services, content, features, technologies or functions offered on our website or other digital platforms. You can withdraw your consent at any time but such withdrawal will not affect the lawfulness of the processing of your data based on consent given before its withdrawal.
3.2. Where your personal data is to be processed for a different purpose that is incompatible with the purpose or purposes for which that personal data was originally collected that was not disclosed to you when you first provided your consent, we will obtain your consent to the new purpose or purposes.
4.Age Restriction
You affirm that you are over 18 years old and have the right to contract in your own name, and that you have read the above authorisation and fully understand its contents.
5.Data Protection Principles
We, our employees, agents, contractors and third-party service providers comply with the following principles when collecting or processing your personal data. All personal data must be:
5.1. processed lawfully, fairly, and in a transparent manner in relation to the data subject;
5.2. collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes. Further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered to be incompatible with the initial purposes;
5.3. adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed;
5.4. accurate and, where necessary, kept up to date. Every reasonable step must be taken to ensure that personal data that is inaccurate, having regard to the purposes for which it is processed, is erased, or rectified without delay;
5.5. kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data is processed. Personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, subject to implementation of the appropriate technical and organisational measures in accordance with relevant data protection laws, in order to safeguard the rights and freedoms of the data subject;
5.6. processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organisational measures.
6. Information We Collect
In providing our services to you, we collect certain non-personal and personal data about you. Our policy is to keep this information confidential and strictly safeguarded, and to use or disclose it only as needed to provide services to you, or as permitted or required by the relevant data protection laws.
We collect a variety of information from our users and visitors to our website. As described below, some information is automatically collected when you visit our website, some you provide to us when filling out a form or communicating with us, and some are provided to us by third-party integration Application Programming Interface (API).
6.1. Information Collected Automatically: Whenever you use our services or visit our website, we may, as permitted by law collect certain information automatically from your browser or device. Specifically, the information we collect automatically may include information like your IP address, device type, browser type, broad geographic location (e.g. country, state, or city-level location) and other technical information. We may also collect information about how your device has interacted with our website, including the pages accessed and links clicked, and assign your set of interactions with a unique identification number. Collecting this information enables us to better understand the visitors who come to our websites, where they come from, and what content on our websites is of interest to them. We use this information for our internal analytics purposes and to improve the quality and relevance of our websites to visitors like you. Some of this information may be collected using cookies and similar tracking technology which includes information on how you can adjust your preferences and opt out at any time.
6.2. Information You Provide Us: We collect personal information that you provide voluntarily through our web pages and our websites. We collect the following personal information:
6.2.1. name, phone number, e-mail address;
6.2.2. username and password;
6.2.3. contact information;
6.2.4. identity information (e.g., photo ID, passport information, National ID card and nationality etc.);
6.2.5. financial information where you make any payment for our services; and
6.2.6. any other information you provide to us.
If we ask you to provide any other personal information not described above, the information that you are asked to provide, and the reasons why you are asked to provide it, will be made clear to you at the point that you are asked to provide your information.
Other information which may be automatically collected from you when you visit our website include domain name of your internet service provider, the internet protocol address used to connect the computer to the internet, the average time spent on our website, pages viewed, information searched for, access times, your geographical location, operating system, referral source, and other relevant statistics.
7. Using Your Personal Data
7.1. We primarily collect your personal data to ensure that we provide the most efficient service to you, monitor the use and improve our website and other legitimate interests. Your information will solely be used and disclosed for the following purposes:
7.1.1. to help us verify your identity;
7.1.2. to carry out our obligations ensuing from any contracts entered into between you and us;
7.1.3. to provide you with the products, services and information you request from us;
7.1.4. to assist you with enquiries and improve our customer service;
7.1.5. to assist us in carrying out marketing analysis and customer profiling (including transactional information), conduct research, including creating statistical and testing information;
7.1.6. to allow us to communicate with you in any way (including e-mail, telephone, visit, and text or multimedia messages);
7.1.7. for our billing and account purposes;
7.1.8. to help prevent and detect fraud or loss;
7.1.9. to update our records;
7.1.10. to make recommendations and suggestions to you about services offered by us unless you have previously asked us not to do so;
7.1.11. to send you service or support messages, such as updates, security alerts, email notifications and /or newsletters;
7.1.12. to conduct investigations and risk assessments; and
7.1.13. for compliance with legal and regulatory obligations.
7.2. Employees, agents, contractors, or other parties working on behalf of Farath shall collect your personal data only to the extent required for the performance of their job duties and only in accordance with this Policy. Excessive personal data must not be collected.
7.3. Employees, agents, contractors, or other parties working on behalf of Farath shall process your personal data only when the performance of their job duties requires it. Your personal data held by Farath cannot be processed for any unrelated reasons.
8. Data Accuracy
Your personal data must be accurate and kept up to date. In this regard, Farath shall ensure that any data it collects and/or processes is accurate and not misleading in a way that could be harmful to you; make efforts to keep your personal data updated where reasonable and applicable; and make timely efforts to correct or erase your personal data when inaccuracies are discovered.
9. Data Retention
We will retain your information for as long as your account is active or as needed to provide you with our services, comply with our legal and statutory obligations or verify your information with a financial institution.
Farath is statutory obligated to retain the data you provide us with in order to process transactions, ensure settlements, make refunds, identify fraud and in compliance with laws and regulatory guidelines applicable to us, our banking providers. Therefore, even after closing your account with Farath, we will retain certain data in order to comply with these obligations.
Farath shall not keep personal data for any longer than is necessary in light of the purpose or purposes for which that personal data was originally collected, held, and processed. In the case of your financial data, the purpose for which the data was collected is to provide you with our services. Unless Farath is statutorily bound to retain for a longer period of time or receives a valid request to erase your data, the data is retained for 12 months after you actively stop using our services or products. This allows your record to be maintained.
10. Other Information We Collect
We may also collect information from you using cookies and other analytical tools especially when you use our products and services. More details are provided in our section on Cookies.
We may collect information about you or others from our affiliates or from third-party sources. For example, we may, in our sole discretion, ask for and collect supplemental information from non-affiliated parties, such as information to verify your identity or information for other fraud or safety protection purposes, to the extent permitted by law. We may combine information collected from you through the Services with information obtained from third parties and information derived from other products or services we offer.
11. Data Confidentiality
Your information is regarded as confidential and will not be divulged to any third party, except under legal and/or regulatory conditions. You have the right to request copies of any and all information we keep on you, if such requests are made in compliance with applicable laws and other relevant enactments. While we are responsible for safeguarding the information entrusted to us, your role in fulfilling confidentiality duties includes, but is not limited to, adopting and enforcing appropriate security measures such as non-sharing of passwords and other platform login details, adherence with physical security protocols on our premises, dealing with only authorized officers of Farath.
12. Disclosures
12.1. We will not sell, publish, or disclose to third parties your personal data collected on our website, through our servers or otherwise obtained by us, other than to provide our services and as set forth in this Policy. We may share generic aggregated demographic information not linked to any personally identifiable information regarding visitors and users with our business partners, trusted affiliates, professional advisers and advertisers for the purposes outlined above. We may share your information with these third parties for those limited purposes if you have given us your permission and in compliance with the Data Protection Legislation.
12.2. We may request and provide personal data about you from and to third parties to provide our services. We may share personal data with service providers, affiliates, partners, and other third parties where it is necessary to provide the products and services, or for any other purposes described in this Privacy Policy.
12.3. Your personal data may be provided as necessary to the following categories of recipients: security, insurance, professional advisory (including legal, accounting and auditing advice), banking, payment processing, data storage, information processing, marketing, online communications technology services, and other trusted third parties with whom we have an agreement for the protection of your information, or government/regulatory/law enforcement agencies pursuant to legally binding order.
12.4. We will notify you as soon as we become aware of a harmful data breach which may result in a risk of your rights and freedom.
12.5. You have the right to request an erasure of your data at any time.
12.6. We will notify you if we are transferring your data.
12.7. You may request at any time that we halt further dissemination of your data or cease to use your data.
12.8. If you submit content in a public forum or a social media post, or use a similar feature on our website, that content is publicly visible.
12.9. We may disclose Personally Identifiable Information if required to do so by law or in the good faith belief that such action is necessary to (a) conform with the requirements of the law or comply with legal process served on us, or (b) act in urgent circumstances to protect the personal safety of users of our service or members of the public.
12.10. To the extent practicable and legally permitted, we will attempt to advise you prior to any such disclosure, so that you may seek a protective order or other relief limiting such disclosure.
13. Transfer of Personal Data
13.1. Third Party Processor
We may engage the services of third parties in order to process your personal data. The processing by such third parties shall be governed by a written contract with Farath to ensure adequate protection and security measures are put in place by the third party for the protection of your personal data in accordance with the terms of this policy and the Data Protection Regulation.
13.2. International Transfers
To operate our business and provide you with our services, we may send your personal information to our other offices and outside of your country. Your personal information may be subject to the laws of the countries where we send it. When we send your information to other countries not covered by this Policy, we shall ensure your personal information is protected, and only send your information to countries that have strong data protection laws.
13.3. Transfer of Personal Data of Nigerian Citizens to a Foreign Country
13.3.1. Where your personal data is to be transferred to a country outside Nigeria, we shall put adequate measures in place to ensure the security of such data. In particular, we shall, among other things, conduct a detailed assessment of whether the said country is on the Nigerian Data Protection Bureau (NDPB) Whitelist of Countries with adequate data protection laws.
13.3.2. Transfer of your personal data out of Nigeria would be in accordance with the provisions of the Nigeria Data Protection Act 2023. We will therefore only transfer your personal data out of Nigeria on one of the following conditions:
a. your explicit consent has been obtained;
b. the transfer is necessary for the performance of a contract between you and Farath;
c. the transfer is necessary to conclude a contract between Farath and a third party in your interest;
d. the transfer is necessary for reason of public interest;
e. the transfer is for the establishment, exercise or defense of legal claims;
f. the transfer is necessary in order to protect your vital interests or the interests of other persons, where you are physically or legally incapable of giving consent.
13.3.3. Provided, in all circumstances, that you have been manifestly made to understand through clear warnings of the specific principle(s) of data protection that are likely to be violated in the event of transfer to a third country, this provision shall not apply to any instance where you are answerable in duly established legal action for any civil or criminal claim in another country.
13.3.4. We will take all necessary steps to ensure that your personal data is transmitted in a safe and secure manner. Details of the protection given to your information when it is transferred outside Nigeria shall be provided to you upon request.
14. Your Rights
Subject to certain limitations and exceptions, you are entitled to the following principal rights under the Data Protection Legislation:
14.1. you have the right to be notified if we are transferring your personal information;
14.2. you have the right to object to the processing of your personal data;
14.3. you have the right to file a complaint against a data processor with the relevant
authority;
14.4. you have the right to request an erasure of your personal data at any time;
14.5. you have the right to request that we rectify inaccurate personal information;
14.6. you may request at any time that we halt further dissemination of your data or cease to use your personal information; and
14.7. you have the right to request for copies of your personal information.
15. Website Security
We are committed to ensuring that your information is secure. In order to prevent unauthorised access or disclosure, we have put in place suitable physical, electronic and managerial procedures such as secure sockets layer (SSL) to safeguard and secure the information we collect online. We use encryption tools when accepting and transmitting delicate visitor information through our website. Some of the other safeguards we use are firewalls and physical access controls to our data centres, and information access authorization controls.
16. Training
We shall ensure that employees who collect, access and process your personal data receive adequate data privacy and protection training in order to develop the necessary knowledge, skills and competence required to effectively manage the compliance framework under this policy and relevant data protection laws with regard to the protection of personal data. On an annual basis, we shall develop a capacity building plan for our employees on data privacy and protection in accordance with relevant data protection laws.
17. Use of Cookies
We use cookies to identify you as a user and make your user experience easier, customise our services, content and advertising; help you ensure that your account security is not compromised, mitigate risk and prevent fraud; and to promote trust and safety on our website. Cookies allow our servers to remember your account log-in information when you visit our website, IP addresses, date and time of visits, monitor web traffic and prevent fraudulent activities. If your browser or browser add-on permits, you have the choice to disable cookies on our website; however, this may limit your ability to use our website.
18. Data Breach Management Procedure
18.1. In the event where there is any accidental or unlawful destruction, processing, loss, alteration, unauthorized disclosure of, or access to your personal data, we shall:
18.1.1. notify you within 24 hours of the occurrence of the data breach;
18.1.2. properly investigate the breach and take the necessary steps to mitigate such breach;
18.1.3. identify remediation requirements and track the resolution of such breach; and
18.1.4. notify the relevant regulatory authority, where necessary.
19. Links to Third Party Websites
19.1. Our website may contain links to third-party websites or services that are not owned or controlled by us.
19.2. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party websites or services. You further acknowledge and agree that we shall not be responsible or liable, directly or indirectly, for any damage or loss caused or alleged to be caused by or in connection with use of or reliance on any such content, goods or services available on or through any such websites or services.
19.3. We strongly advise you to read the terms and conditions and privacy policies of any third-party websites or services that you visit.
20. Limitation of Liability
We exercise reasonable efforts to safeguard the security and confidentiality of your personal data; however, we will not be liable for unauthorised disclosure of personal data that occurs through no fault of ours.
21. Changes to this Privacy Policy
Changes may be made to this Privacy Policy from time to time. Whenever such changes are made, we will notify you. These changes will take effect immediately after you have been notified.
22. Contact Us
If you would like more information or you have any comments or questions on our Privacy Policy, please contact us at admin@farathholdings.com.
This policy is effective as of April 22, 2024.
Last updated: April 22, 2024.