← Security & Trust

Data Protection Policy

Fueling Agile Nigeria · Effective 1 January 2026 · Next review 18 January 2027
Owner: David Owolabi · Contact: fuelingagilenigeria@gmail.com

1. Purpose

Explain what personal and business data we process in AgileFlex / FANMS, why we process it, how we protect it, and how we handle requests and retention — in line with the Nigeria Data Protection Act (NDPA).

2. Roles

RoleMeaning for us
Data ControllerFueling Agile for platform admin accounts, product telemetry we decide to collect, and our own business records
Data ProcessorFueling Agile when we process fleet/company data on behalf of a customer organisation
Data SubjectIndividuals whose personal data appears in the system (for example drivers, company contacts, staff)

Customer organisations remain responsible for the lawfulness of data they upload or instruct us to process.

3. Categories of data we process

CategoryExamplesWhy
Account & contactEmail, phone, company address, admin namesProvide the service, support, alerts
Fleet & operationsVehicles, cards, balances, limits, subsidiariesCore fuel-card management
Financial / bank-importFuel debit/credit transactions, bank log importsReconcile and manage fuel spend
TelematicsLocation, trips, tank readings (where enabled)Fraud / misuse detection and fleet visibility
Security logsLogin times, IP, user agent, approximate geo, audit eventsSecure the service and investigate incidents
SupportEmails and ticketsCustomer support

4. Why we process it

  1. Deliver the contracted fuel-management service
  2. Detect suspicious fuel activity and protect customers from abuse
  3. Send operational alerts the customer configures
  4. Secure accounts and investigate incidents
  5. Meet legal and accounting obligations

We do not sell personal data.

5. Security of processing

We do not currently claim application-level encryption of every field at rest. See the Encryption Policy.

6. Processors

We use trusted providers needed to run the product (hosting, email, telematics, bank/fuel-card sources, maps, source control and CI). A current subprocessor list is available on request.

7. Retention

Active customer operational data is kept for the life of the contract plus a reasonable wind-down. Security logs are kept long enough to investigate incidents. After contract end we delete or anonymise on request or per contract, except where law requires retention.

8. Data subject / customer requests

Requests can be submitted in the company app under Privacy & data rights, or by email to fuelingagilenigeria@gmail.com. We verify identity and authority and respond within a reasonable time consistent with NDPA expectations.

9. Breach notification

Suspected personal-data breaches are handled under the Incident Response Policy. Where required we notify affected customers and, if applicable, the relevant authority without undue delay.

Reviewed with the Information Security Policy.