Data Protection Policy
1. Purpose
Explain what personal and business data we process in AgileFlex / FANMS, why we process it, how we protect it, and how we handle requests and retention — in line with the Nigeria Data Protection Act (NDPA).
2. Roles
| Role | Meaning for us |
|---|---|
| Data Controller | Fueling Agile for platform admin accounts, product telemetry we decide to collect, and our own business records |
| Data Processor | Fueling Agile when we process fleet/company data on behalf of a customer organisation |
| Data Subject | Individuals whose personal data appears in the system (for example drivers, company contacts, staff) |
Customer organisations remain responsible for the lawfulness of data they upload or instruct us to process.
3. Categories of data we process
| Category | Examples | Why |
|---|---|---|
| Account & contact | Email, phone, company address, admin names | Provide the service, support, alerts |
| Fleet & operations | Vehicles, cards, balances, limits, subsidiaries | Core fuel-card management |
| Financial / bank-import | Fuel debit/credit transactions, bank log imports | Reconcile and manage fuel spend |
| Telematics | Location, trips, tank readings (where enabled) | Fraud / misuse detection and fleet visibility |
| Security logs | Login times, IP, user agent, approximate geo, audit events | Secure the service and investigate incidents |
| Support | Emails and tickets | Customer support |
4. Why we process it
- Deliver the contracted fuel-management service
- Detect suspicious fuel activity and protect customers from abuse
- Send operational alerts the customer configures
- Secure accounts and investigate incidents
- Meet legal and accounting obligations
We do not sell personal data.
5. Security of processing
- Encryption in transit via HTTPS at the public edge
- Access control and company scoping
- Password hashing; revocable sessions
- Secrets excluded from source control
- Separate test and production environments
- Audit logging of sensitive admin activity
We do not currently claim application-level encryption of every field at rest. See the Encryption Policy.
6. Processors
We use trusted providers needed to run the product (hosting, email, telematics, bank/fuel-card sources, maps, source control and CI). A current subprocessor list is available on request.
7. Retention
Active customer operational data is kept for the life of the contract plus a reasonable wind-down. Security logs are kept long enough to investigate incidents. After contract end we delete or anonymise on request or per contract, except where law requires retention.
8. Data subject / customer requests
Requests can be submitted in the company app under Privacy & data rights, or by email to fuelingagilenigeria@gmail.com. We verify identity and authority and respond within a reasonable time consistent with NDPA expectations.
9. Breach notification
Suspected personal-data breaches are handled under the Incident Response Policy. Where required we notify affected customers and, if applicable, the relevant authority without undue delay.