Legal
Privacy Policy
Version 1.1 · Effective date: 1 January 2026. Last updated: 4 July 2026.
1. Introduction
Reciiva ("Reciiva", "we", "our", or "us") operates the Reciiva Liquidity Marketplace at app.reciiva.com and www.reciiva.com (the "Platform"). We are committed to protecting the personal information of all individuals who use our Platform. This Privacy Policy describes how we collect, use, store, share, and protect your personal data in accordance with the Nigeria Data Protection Regulation 2019 ("NDPR"), the Nigeria Data Protection Act 2023 ("NDPA"), and other applicable laws.
By accessing or using the Platform, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Platform.
2. Who we are
Reciiva is a data controller registered in Nigeria. Our designated Data Protection Officer ("DPO") can be reached at privacy@reciiva.com.
3. Data we collect
3.1 Identity and registration data
- Full legal name, email address, phone number, and password hash.
- Business information: RC number, TIN, industry sector, company address.
- Identity verification: BVN, NIN, date of birth, and occupation (individual investors only).
- Director passport photograph and government-issued ID documents.
3.2 Financial and transactional data
- Invoice details: amounts, due dates, debtor identities, tenor.
- Local Purchase Order (LPO) details submitted for financing: amounts, buyer identity, payment terms, and supporting documents.
- Bank statements submitted for credit assessment (PDFs/images), whether uploaded manually or fetched via open banking (Mono).
- Bank account details (bank name, account number, account name) used for disbursement of advance proceeds.
- Funding offer terms, rates, settlement dates.
- Repayment records and portfolio performance data.
3.3 Usage and technical data
- IP address, browser type, device type, and operating system.
- Pages visited, time spent, click paths, and session duration.
- Authentication events (login times, token refresh events).
- API request logs retained for security and compliance purposes.
- Browser localStorage data used to enforce the public AI assistant question limit (stores a question count and a 24-hour expiry timestamp; contains no personal data).
3.4 Communications and AI interaction data
- Content of messages sent through the Platform's per-invoice private message threads (between suppliers and lenders).
- Questions and answers exchanged with our AI Copilot (Karl), including the text of each question, Karl's response, and associated token usage metrics. These are logged to our
copilot_sessionstable and associated with your user account. - Email correspondence with our support and compliance teams.
- Procurement contact email addresses provided for off-platform buyer validation. These individuals may not be registered Platform users; they receive a validation email and their address is retained only for the purpose of that transaction.
4. Lawful basis for processing
We process your personal data under one or more of the following lawful bases:
- Contract performance — processing necessary to operate your account and facilitate transactions.
- Legitimate interest — fraud detection, platform security, credit risk assessment, adverse news screening, and aggregate analytics.
- Legal obligation — AML/KYC compliance, CBN regulatory reporting, NDPA obligations.
- Consent — marketing communications and open banking data access via Mono. You may withdraw consent at any time.
5. How we use your data
- Create and manage your account and verify your identity.
- Process invoice and LPO submissions, funding offers, and repayments.
- Run AI-powered credit scoring, credit underwriting analysis, and fraud detection.
- Screen your company name against public adverse news sources (litigation, fraud, insolvency, regulatory sanctions) as part of credit underwriting.
- Verify identities via CAC, BVN, and TIN APIs.
- Fetch and analyse bank transaction data via open banking (Mono) where you have granted consent, to generate cashflow assessments for credit underwriting.
- Process advance disbursements and lender repayments via Paystack.
- Power the Karl AI Copilot to answer your questions about the Platform using your role-scoped account data as context.
- Send transactional emails (offer notifications, funding confirmations, repayment requests, PO and invoice validation requests to buyers).
- Send in-app notifications and (where consented) WhatsApp notifications.
- Comply with regulatory reporting requirements.
- Improve the Platform through aggregated, anonymised usage analytics.
6. AI and automated decision-making
The Platform uses AI models (Anthropic Claude) and automated systems for the following purposes:
- Invoice credit memos — bank statement content, invoice details, and supplier profile data are passed to Anthropic Claude to generate a structured credit analysis per invoice. Results are stored and reviewed by Reciiva administrators.
- Credit Underwriting Agent — for supplier-level risk assessments, we pass your company name to a third-party news search service (Serper) to identify adverse public information (litigation, fraud allegations, regulatory sanctions). Your company name and sector are also submitted to the Nigerian CAC API to verify registration status. Bank statements may be passed to Anthropic Claude for cashflow analysis. Results are stored in our credit risk records and reviewed by Reciiva administrators.
- Karl AI Copilot — your questions and role-scoped account context (invoice pipeline, outstanding obligations, portfolio data) are passed to Anthropic Claude to generate responses. These interactions are logged. Karl's responses are informational only and do not constitute financial, legal, or investment advice.
- Invoice fraud detection — every invoice submission is screened by automated rules (duplicate detection, amount anomalies, velocity checks, OCR comparison). Flags are reviewed by Reciiva's compliance team; no adverse action is taken without human review.
AI outputs assist human decision-makers and do not constitute fully automated decisions that produce legal effects without human review. You have the right to request human review of any AI-assisted credit decision by contacting us at privacy@reciiva.com.
7. Data sharing
We share personal data only as described below:
- Platform participants — invoice details are shared with the relevant anchor buyer and, upon offer, with the relevant lender. Private message threads on invoices are visible only to the participating lender and the relevant supplier; Reciiva administrators have oversight access for compliance purposes. We share the minimum necessary.
- Identity verification providers — BVN, RC, and TIN data is passed to licensed Nigerian verification APIs for identity confirmation only.
- Open banking provider (Mono) — where you grant consent, Mono fetches your bank transaction data on our behalf. Mono operates under its own privacy terms and applicable CBN open banking guidelines.
- Payment processor (Paystack) — bank account details are shared with Paystack to process advance disbursements and repayments. Paystack operates under its own privacy terms and applicable CBN regulations.
- Cloud infrastructure providers — Neon (database), Vercel (hosting and Blob storage), Resend (email delivery). Each operates under appropriate data-processing agreements.
- WhatsApp notification provider (Termii) — your phone number and notification content (e.g. invoice funded, offer received) are passed to Termii to deliver WhatsApp messages where you have opted in. Termii operates under its own privacy terms and applicable Nigerian telecoms regulations.
- AI service providers — bank statement content, invoice data, supplier profile information, and copilot question context are passed to Anthropic (Claude API) solely for generating credit assessments and AI Copilot responses. Anthropic processes this data under strict enterprise data-use controls and does not use it to train its models.
- Adverse news search (Serper) — your company name is submitted as a search query to Serper's web search API to identify public adverse information during credit underwriting. No personal financial data is included in this query.
- Off-platform buyers — procurement email addresses you provide are used to send invoice or LPO validation requests. The buyer's email address and the relevant transaction details are shared solely for the purpose of completing that validation.
- White-label tenant operators — if you access the Platform through a white-label tenant deployment, the tenant operator may have access to transaction and account data within their tenant scope, governed by a data processing agreement with Reciiva.
- Regulatory authorities — we will disclose data to the CBN, EFCC, FIRS, or other competent authorities when required by law.
- Successors — in the event of a merger or acquisition, data may transfer to the successor entity, subject to the same privacy protections.
We do not sell personal data to third parties.
8. International data transfers
Some infrastructure and AI service providers (including Anthropic, Vercel, and Resend) operate servers outside Nigeria. Where data is transferred internationally, we rely on Standard Contractual Clauses or equivalent safeguards recognised under the NDPA to protect your data.
9. Data retention
- Account and KYC data — retained for the duration of your account plus 7 years after closure, in compliance with AML regulations.
- Transaction records — retained for 7 years from the date of the last transaction.
- Credit memos and AI assessments — retained for the duration of the relevant invoice's lifecycle plus 5 years.
- Copilot session logs — retained for 12 months, then anonymised.
- Private message thread content — retained for the duration of the relevant invoice's lifecycle plus 5 years.
- Off-platform buyer emails and validation tokens — retained for 90 days after the validation event, then deleted.
- Server logs — retained for 90 days.
- Marketing consent records — retained until consent is withdrawn plus 2 years.
10. Your rights
Under the NDPA, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate data.
- Erasure — request deletion, where no legal obligation requires retention.
- Restriction — limit how we use your data while a dispute is resolved.
- Portability — receive your data in a structured, machine-readable format.
- Object — object to processing based on legitimate interest, including profiling and adverse news screening.
- Withdraw consent — at any time for consent-based processing (open banking, marketing).
- Human review — request that any AI-assisted credit or risk assessment be reviewed by a human administrator.
To exercise any right, email privacy@reciiva.com. We will respond within 30 days. Identity verification may be required before we act on your request.
If you believe your rights have been violated, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.
11. Security
We implement industry-standard safeguards including: TLS 1.3 encryption in transit; AES-256 encryption at rest; token-based authentication with session management and refresh token rotation; rate limiting on all authentication endpoints; AI-powered fraud detection on all invoice submissions; role-based access controls with full audit trails; and account lockout after repeated failed login attempts. While we are committed to maintaining robust protections, the nature of digital systems means we cannot warrant that unauthorised access, disclosure, or loss of data will never occur.
12. Cookies and local storage
The Platform uses strictly necessary session cookies to maintain your authenticated session. We do not use third-party advertising or tracking cookies. Our public AI assistant widget stores a question count and a 24-hour expiry timestamp in your browser's localStorage to enforce usage limits; this data is not transmitted to our servers and contains no personal information. You can clear this data at any time by clearing your browser's local storage.
13. Children's data
The Platform is intended for business use only. We do not knowingly collect personal data from individuals under 18 years of age. If you believe a minor has registered, contact us immediately.
14. Changes to this policy
We may update this Privacy Policy from time to time. We will notify registered users by email at least 14 days before material changes take effect. Continued use of the Platform after the effective date constitutes acceptance of the updated policy.
15. Contact
For privacy-related questions or to exercise your rights, contact our DPO:
Email: privacy@reciiva.com
Postal: Data Protection Officer, Reciiva, Yaba, Lagos, Nigeria.