IMATA Logistics Nigeria Limited ("IMATA", "we", "us") is committed to operating in full compliance with applicable laws and regulatory standards within the Federal Republic of Nigeria. This statement outlines the legal frameworks guiding our operations and what they mean for users of our platform.
1. Regulatory Framework
Our operations are aligned with the following Nigerian laws and regulatory guidelines:
1.1 Data Protection & Privacy
- Nigeria Data Protection Act 2023
- Nigeria Data Protection Regulation
We collect, process, and store personal data in accordance with national data protection standards and regulatory oversight by NITDA.
1.2 Consumer Protection
- Federal Competition and Consumer Protection Act (FCCPA)
We maintain fair pricing, transparent policies, and dispute resolution mechanisms that protect consumer rights.
1.3 Corporate Governance
- Companies and Allied Matters Act 2020 (CAMA)
IMATA operates as a duly registered and compliant corporate entity in Nigeria.
1.4 Payments & Financial Compliance
Central Bank of Nigeria Guidelines. All payment processing, reconciliation, and financial controls align with applicable CBN standards, including Know Your Customer (KYC) requirements where necessary.
1.5 Cybersecurity & Fraud Prevention
- Cybercrimes (Prohibition, Prevention, etc.) Act
We implement safeguards to prevent unauthorised access, fraud, and system abuse.
1.6 Digital & Telecommunications Compliance
Nigerian Communications Commission Consumer Protection Guidelines. We align our digital platform operations with applicable telecom and service delivery standards.
2. Data Protection Commitments
We are committed to responsible data handling:
- Personal data is collected only for legitimate operational purposes, including shipment processing, tracking, communication, and payment verification
- We do not sell or commercially distribute personal data
- Data access is restricted to authorised personnel and systems
- Security controls are implemented to prevent unauthorised access, loss, or misuse
3. User Rights
In line with Nigerian data protection laws, you have the right to:
- Access your personal data
- Request correction of inaccurate information
- Request deletion of your data, subject to legal and operational requirements
- Withdraw consent where applicable
Requests may be submitted through our official support channels.
4. Compliance Enforcement
To ensure adherence:
- Internal controls and audit mechanisms are maintained
- Transactions and system activities are logged and monitored
- Fraud detection and risk management processes are implemented
- Non-compliance or abuse may result in account restriction, suspension, or reporting to relevant authorities
5. Complaints & Regulatory Escalation
If you believe your rights have been violated:
- Contact IMATA support for internal resolution
- If unresolved, complaints may be escalated to the National Information Technology Development Agency (NITDA)
6. Acknowledgement
By using the IMATA platform, you acknowledge that:
- Our services operate within the above regulatory frameworks
- Your data is processed in accordance with applicable Nigerian laws
- You understand your rights and responsibilities under these frameworks
7. IMATA Account Deletion and Data Retention Policy
- Policy title
- IMATA Account Deletion and Data Retention Policy
- Version
- 1.1
- Effective date
- 27 August 2026
- Last reviewed
- 27 August 2026
- Policy owner
- Customer Trust Operations / Data Protection
- Approved by
- Founder / CEO
Customers may delete their IMATA account from their authenticated profile. Account deletion immediately disables the account and stops normal account processing. Closing an account is not the same as deleting IMATA's business, delivery, financial, compliance or evidentiary records. IMATA may retain those records in a restricted archive where required or permitted by applicable law, including for financial, tax, regulatory, security, fraud prevention, dispute resolution or legal purposes. Where information is retained, IMATA will restrict its use, will not present it as an active customer profile, and will retain only what is necessary. Eligible customer profile information follows a three-month restricted deletion archive. Retained business records follow a separate retention cycle, with a twelve calendar-month operational baseline unless a longer lawful duty applies. Customers may register a new IMATA account in the future, subject to the registration and verification requirements applicable at that time.
How deletion is requested
Customers confirm the request by entering the phrase delete my account. The confirmation is designed to prevent accidental deletion. Rider and enterprise accounts use Customer Trust Operations rather than this self-service path.
Effect of deletion
- Account access is disabled and active sessions are terminated
- Normal account processing and marketing communication stop
- The account is placed into restricted deletion processing
The deletion request does not automatically erase records that IMATA is legally required or otherwise lawfully permitted to retain.
Customer profile retention
IMATA's standard account deletion archive period for customer profile data is three months. During this period, archived account information is restricted, inaccessible through normal customer features, excluded from active customer processing, and not used for marketing. At the end of that period, eligible profile information — including customer profile photographs and similar account-profile images — is permanently deleted or irreversibly anonymised, unless a legal hold or other lawful exception applies.
Business, operational and compliance records
Account deletion does not erase IMATA's legitimate business records. The following categories remain in restricted archive and are not destroyed as part of the three-month customer profile purge:
- Parcel and delivery evidence, including proof of delivery and related operational photographs
- Receipts and invoices
- Payment, ledger and other financial evidence required for accounting or tax
- Know-your-customer and identity-verification documents
- Operational rider photographs used for delivery identification and safety
- Audit, security, fraud-investigation and dispute records required to establish operational history
The operational archive baseline for these retained records is twelve calendar months from the applicable record date, which may be document creation, invoice date, delivery completion or another authoritative event for that category. This twelve-month baseline is IMATA operational policy. It is not a claim that Nigerian law or the GDPR requires destruction after exactly twelve months, and it is not a maximum. Where a longer lawful retention duty applies — including tax, accounting, KYC, audit or legal-claim preservation — IMATA retains the record for that longer period. A legal hold, active dispute, fraud investigation or regulatory requirement prevents destruction until the hold or requirement is released.
Retained records remain access-controlled. They are not made public, are not shown as an active customer profile after deletion, and are available only to authorised IMATA roles for legitimate business, legal, compliance, financial or operational purposes.
Legal exceptions
IMATA may retain limited information beyond the profile or operational archive periods where required or permitted by applicable law, including financial records, tax obligations, regulatory requirements, fraud prevention, security investigations, dispute resolution, legal claims, law enforcement requests, and contractual obligations. Only the minimum necessary information should be retained. Evidence that must be kept is not altered merely to make an account appear deleted.
This policy recognises the Nigeria Data Protection Act 2023 and applicable Nigeria Data Protection Commission requirements: transparency, purpose limitation, data minimisation, storage limitation, security, and accountability. Where GDPR applies to an IMATA processing activity or data subject, IMATA supports the right to erasure subject to the conditions and exceptions in Article 17. The three-month profile archive and the twelve-month business-record baseline are operational policies. They are not a claim that GDPR or Nigerian law requires every record to be permanently destroyed after those periods.
