Legal
Last updated: June 2025
Owoye Institutional Systems ("Owoye", "we", "our", "us") is committed to protecting your personal information. This Privacy Policy explains how we collect, use, store, and protect information about you when you use our financial management platform, in compliance with the Nigeria Data Protection Regulation (NDPR) and applicable Central Bank of Nigeria (CBN) guidelines.
We collect information you provide directly to us, including your name, email address, phone number, and business details when you register for an account or update your profile.
When you connect your bank accounts via Mono open banking, we access read-only transaction data, account balances, and institution details. We do not store your online banking credentials.
We also collect usage data such as log files, IP addresses, device identifiers, browser type, and pages visited to improve our services and ensure platform security.
We use your information to provide, maintain, and improve the Owoye platform — including aggregating transactions, generating financial insights, processing invoices, and powering the Kara AI assistant.
We use your email address to send transactional notifications, security alerts, and product updates. You may opt out of marketing communications at any time.
We may use anonymised, aggregated data to improve our AI models and platform features. This data cannot be used to identify individual users.
Owoye uses Mono (mono.co) to facilitate bank account connections. By connecting your accounts, you authorise Mono to retrieve your transaction history and account information on our behalf under the terms of Mono's own privacy policy.
We store your transaction data in encrypted form on our servers. This data is used solely to provide your Owoye dashboard and will not be sold or shared with third parties for marketing purposes.
You can disconnect any linked bank account at any time from Settings → Connected Accounts.
We implement industry-standard security measures, including TLS encryption in transit, AES-256 encryption at rest, and JSON Web Token (JWT) authentication with session versioning — which ensures only one active session per account at any time.
Sensitive operations such as password changes and 2FA modifications trigger immediate session invalidation across all devices.
Despite these measures, no system is completely immune to security risks. We encourage you to use a strong, unique password and enable Two-Factor Authentication.
We retain your account and transaction data for as long as your account is active or as required by applicable Nigerian law, including the Central Bank of Nigeria (CBN) regulations and the Nigeria Data Protection Regulation (NDPR).
If you delete your account, we will remove your personal data within 30 days, except where retention is required by law or for legitimate business purposes such as fraud prevention.
Under the Nigeria Data Protection Regulation (NDPR), you have the right to access, correct, or request deletion of your personal data. You also have the right to restrict or object to processing, and the right to data portability.
To exercise any of these rights, contact us at support@owoye.com. We will respond to all verified requests within 30 days.
Owoye uses only essential session cookies required for authentication. We do not use tracking, advertising, or analytics cookies. No cookie consent banner is presented because no non-essential cookies are set.
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or an in-app notice at least 14 days before the changes take effect. Continued use of Owoye after the effective date constitutes your acceptance of the updated policy.
If you have questions about this Privacy Policy or our data practices, please contact our Data Protection Officer at:
Email: support@owoye.com Phone: +234 (0) 800 OWOYE 1 Address: Owoye Institutional Systems, Lagos, Nigeria