Data Protection Policy
How Termii safeguards the data of customers, stakeholders and partners, with care, transparency and respect for individual rights.
- Last updated
- 31 August 2026
- Frameworks
- NDPA · GDPR
This Data Protection Policy, together with our Privacy Policy, sets out Termii’s commitment to treating personal data of customers, stakeholders, partners, and other interested parties with the utmost care and confidentiality, in accordance with the Nigeria Data Protection Act (NDPA) 2023, the General Data Protection Regulation (GDPR), and other applicable laws.
We acknowledge that we gather, store, and handle data fairly, transparently, and with respect for individual rights. This policy also covers the processing of personal data in connection with our AI Services (including AYLA).
1. Scope
As part of Termii’s operation, we often obtain and process information which includes names, addresses, phone numbers, email addresses, and more. We collect this information securely and transparently and only with your full cooperation and knowledge.
To ensure the protection of this information, we apply the following rules:
- Use for lawful purposes only.
- Protect against any unauthorized and illegal access.
- Only share with third parties to provide services.
To exercise the provisions of data protection regulations and show our commitment to compliance, we:
- Restrict and monitor access to sensitive data.
- Develop transparent data collection procedures.
- Train employees in online privacy and security measures.
- Build secure networks to protect online data from cyberattacks.
- Establish clear procedures for reporting privacy breaches or data misuse.
- Establish data protection practices (document shredding, secure locks, data encryption, frequent backups, access authorization, etc.).
2. How we obtain your personal data
We obtain your personal data when you use our service through the registration process. In the process of signing up, we request data such as name, phone number, address, email, company name, designation, and country.
Through a third-party source, in the process of funding your wallet, you will be directed to our payment institution platform where you will be required to input your card details for such funding. Termii does not store credit card details. Payment processing is handled by our payment partners. For details on how your payment data is handled, please review their privacy policies.
Likewise, while using our services, you may be required to fill in your details and/or your customer’s details during the use of our Phone book, Teams, Group, or Direct SMS services. In addition, when interacting with our customer service, you may be required to provide us with more personal data to provide quality services to you.
AI-specific collection: When you use AI Services, you may provide additional data as Customer Inputs (e.g. message content, customer lists, routing preferences). We may also generate AI Outputs that contain or reference personal data (e.g. summarised customer interactions, fraud alerts). This data is obtained with your knowledge and consent as part of your use of the AI features.
3. Personal data usage
Ways in which we use the personal data provided to us include processing or delivering our services, notifying you of the status of the services, and sending marketing or campaign material to which you opt-in.
AI-specific usage:
- To provide AI-assisted communication, messaging workflows, fraud detection, routing, analytics, and automation.
- To improve the accuracy, performance, and security of our AI models using aggregated and de-identified data.
- To support customer support and troubleshooting related to AI Services.
- We do not use Customer Inputs for training publicly available foundation models unless we have a separate agreement with you.
4. Sharing your personal data
Notwithstanding the provision of this clause, Termii does not sell nor trade customer personal data to anyone. We only use it to render our services to you.
We may share your data with our partners or suppliers to provide services to you. Such data may include your name, phone number, and email address. We may also share your data with companies or organizations that we engage to provide services to us for the furtherance of your transaction or direct you to a third-party website that may provide services for you directly and/or on our behalf.
The privacy policies of these third-party sites may be different from our Data Protection and Privacy Policy and will govern any transactions and services performed on that site. Termii and such companies are each independent data controllers and not joint data controllers. You are advised to read and consent to such third-party site data protection and privacy policy.
AI-specific sharing: We may share Customer Inputs and AI Outputs with third-party AI service providers, telecommunications partners, and cloud infrastructure providers strictly for the purpose of delivering the AI Services. Such third parties act as data processors and are bound by contractual obligations to process data only on our instructions and in compliance with data protection laws. We require all processors to implement appropriate technical and organisational measures to protect personal data.
4.1 As an organization that offers our services in different regions, we may need to transfer your personal data to our service providers, affiliates, or contractors in various jurisdictions to provide our services to you. In such cases, we ensure adequate safeguards and measures are put in place for your data to remain protected.
5. Securing customer personal data
We secure your data by using a database with limited access and a secure server that encrypts all the data we collect, hence protecting it from unauthorized third parties. We also use a firewall to prevent access to information on our system.
AI-specific security:
- We implement access controls and audit logs to monitor interactions with AI systems.
- We apply encryption to data in transit and at rest, including AI training datasets.
- We conduct regular vulnerability assessments and penetration testing on AI components.
6. Customer compliance
It is the responsibility of you as a Termii customer to ensure that you comply and continue to comply with applicable data protection laws and regulations in your use of our services and in processing personal data. In addition, you will be responsible for the right to transfer, share and receive the consent of data subjects that you share with us to provide our service. By using our service, you hereby agree as follows:
- You are complying and will continue to comply with applicable data protection laws and regulations that you process through your use of our service.
- You hereby indemnify Termii of any and/or all liabilities, claims, legal actions, losses, and damages as a result of data violation and/or your breaching any data protection laws and regulations.
- You will not intentionally collect or process any special categories of personal data unless Termii includes such types of data in the content submitted to you.
- Taking into account the nature of processing and the information available to you, you shall provide Termii, insofar as this is possible and at Termii’s written request, with all information required for Termii to comply with statutory obligations under applicable data protection law (in particular, the obligations necessary to ensure Termii’s compliance with security of processing, personal data breach notification, data protection impact assessment, and prior consultations with supervisory authorities).
AI-specific customer obligations:
- You must ensure that any Customer Inputs you provide to the AI Services are lawful and that you have obtained all necessary permissions, notices, and consents from data subjects (e.g. end-users whose data you submit for AI processing).
- You are responsible for reviewing AI Outputs before use and ensuring they are accurate, appropriate, and compliant with applicable laws.
- You must maintain appropriate human oversight over decisions informed by AI Outputs, especially in high-risk areas (e.g. credit, employment, healthcare).
- You agree to indemnify Termii against claims arising from your misuse of AI Services or failure to comply with data protection obligations.
7. Your choices and rights
You have the reserved right to decline the request to provide your personal data when requested by Termii or Termii’s authorized representatives. You also have the right to withdraw consent given to our data protection policy and privacy policy. Please contact us at dataprotection@termii.com if you wish to exercise any of your rights. It is however noteworthy to mention that certain services or all services may be unavailable to you as a result.
AI-specific rights:
- You may request an explanation of how your personal data is used in AI processing (logic, significance, and envisaged consequences).
- You may object to processing of your data for AI model improvement where it is based on legitimate interests, unless we demonstrate compelling grounds.
- You have the right to request that we restrict processing of your data for AI purposes while we verify its accuracy or lawfulness.
- You may ask us to delete personal data that was collected as Customer Inputs, provided it is no longer necessary for the AI Services you have purchased.
To exercise these rights, contact dataprotection@termii.com. Some services may be unavailable if you withdraw consent for essential AI processing.
8. Data Protection Impact Assessment procedure
Termii shall conduct a Data Protection Impact Assessment (DPIA) for any processing activity that is likely to result in a high risk to the rights and freedoms of data subjects, in accordance with the NDPA. The DPIA shall be carried out before initiating such processing and shall include the following steps:
- Termii shall assess the processing activity by identifying and documenting the nature, scope, context, and purpose of the processing. This assessment shall determine whether the processing involves special categories of data, large-scale processing, automated decision-making, or profiling.
- Identify and evaluate potential risks associated with the processing. This includes assessing the possible impact on data subjects, such as risks to privacy, security, and fundamental rights, and identifying potential threats, including data breaches, unauthorised access, or misuse of personal data.
- Termii shall evaluate whether the processing is essential to achieve its intended purpose and ensure that it aligns with data protection principles such as data minimization, purpose limitation, and security safeguards.
- To mitigate identified risks, Termii shall implement appropriate technical and organizational measures. These may include encryption, pseudonymization, access controls, and the establishment of data retention policies to enhance security and compliance.
- All findings, decisions, and risk mitigation strategies shall be documented, and a detailed record of the DPIA shall be maintained. Where required, the DPIA indicates that the processing of the data would result in a high risk to the rights and freedoms of data subjects; Termii shall submit the DPIA to the Nigeria Data Protection Commission (NDPC) for review.
- The DPIA shall be subject to periodic review and monitoring, particularly when there are changes in processing activities or regulatory requirements. Any necessary updates to risk mitigation measures shall be implemented to maintain compliance with data protection laws.
- The DPO shall oversee the entire DPIA process, ensuring that high-risk processing activities are conducted in full compliance with the NDPA.
9. AI Governance commitment
Termii is committed to responsible AI development and operation. We maintain:
- Ethical Principles – fairness, transparency, accountability, and privacy by design.
- Governance Framework – policies and procedures for AI development, deployment, and monitoring.
- Risk Management – continuous assessment of AI-related risks, including bias, security, and compliance.
- Human Oversight – appropriate human review of AI Outputs for high-impact decisions.
- Incident Response – procedures to address AI-related errors, breaches, or complaints.
Nothing in this section constitutes a guarantee that AI Outputs will always be error-free, but we strive to minimise risks through diligent governance.
International standard privacy compliance
Termii is a company established and with offices in more than one jurisdiction. We recognize that we have customers and provide our services to customers in different jurisdictions. Hence our approach to data policies is the international standard that covers specific data protection requirements from regions. Therefore, regardless of where you are located, we are committed to abiding by all applicable data protection regulations.
- EEA & UK: if you are from a region such as Europe or the UK where there is a requirement of the legal basis for processing your personal data, the basis for collecting and using your personal data is as explicitly stipulated above. However, in certain circumstances, we may also have a legal obligation to collect certain personal data from you when required or mandated by a government or regulatory enforcement agency. Should you require more information and/or clarification, do not hesitate to contact us at dataprotection@termii.com.
- United States: we recognize the California Consumer Access and Deletion Rights. You can contact us at any time to request any information regarding your personal data and as well for your personal data to be deleted. Once we have verified that you are authorized to make the request, we will inform you of any limitation of service it may bring to you and ensure your request is carried out as swiftly as possible.
- Other regions: our policy is broad and extensive enough to cover and safeguard your interest regardless of where you are or reside. We offer high standards of privacy and data protection to all our customers and respect individual citizenship data protection regulation requirements.
Changes to our policies
We reserve the right to change these policies at any time subject to our discretion. If we choose to change any of our policies, we will post those changes here and in any other places we deem appropriate so that you are aware. If we make material changes to any of these policies, we will notify you here, by email, or using a notice on our home page.