Privacy notice
How personal data is handled in FieldCRM.
This notice explains the principal processing carried out through FieldCRM by Mainstreet Microfinance Bank in accordance with the Nigeria Data Protection Act 2023 and applicable banking obligations.
- Effective
- 2 September 2026
- Applies to
- Staff, applicants, customers, guarantors and related persons
1. Data controller and scope
Mainstreet Microfinance Bank Limited is the controller for personal data processed through FieldCRM for loan origination, assessment, approval, servicing, collections, compliance, security and audit. Approved service providers may act as processors under Mainstreet’s instructions.
2. Personal data we process
Depending on the relationship and product, FieldCRM may process identity and contact details; BVN, NIN and other identifiers; photographs and signatures; employment and business details; addresses and GPS/visit evidence; income, expenditure, account and transaction information; loan, repayment and arrears data; documents; guarantor, collateral and credit-bureau information; communications; device, session, IP, security and audit records.
Some information may constitute sensitive personal data or create significant risk if misused. Access is restricted according to responsibility and business need.
3. Purposes and lawful bases
We process data to take steps at an applicant’s request and perform contracts; comply with legal and regulatory duties, including customer identification, credit, prudential, reporting, fraud-prevention and recordkeeping obligations; protect legitimate interests in secure and efficient credit operations; establish, exercise or defend legal claims; protect vital or public interests where applicable; and rely on consent where law requires it and consent is appropriate.
Providing required application and verification information may be necessary to assess or service a facility. Where information is not provided, Mainstreet may be unable to proceed, subject to applicable law and fair-treatment duties.
5. Retention and accuracy
Records are retained for the period required by banking, tax, anti-money-laundering, limitation, audit, litigation and other applicable obligations, and no longer than necessary for the stated purposes. Some workflow, approval and audit records are maintained as immutable evidence. Inaccurate source data should be reported through official channels; corrections may be recorded without erasing required historical evidence.
6. Data-subject rights
Subject to lawful restrictions and identity verification, individuals may request information about processing and access to their data; correction; erasure where retention is not legally required; restriction; objection; portability where applicable; withdrawal of consent without affecting earlier lawful processing; and review of a significant decision based solely on automated processing. FieldCRM supports staff decision-making and does not authorise a solely automated final credit decision unless separately approved and lawfully implemented.
7. Security and incidents
Mainstreet applies organisational and technical safeguards including role and tenant controls, session protection, encryption for designated sensitive data, secure document access, validation, logging, monitoring and recovery controls. No system is risk-free. Suspected loss, unauthorised access or disclosure must be reported immediately through the official Mainstreet security or support channel.
8. Requests, complaints and updates
Submit privacy requests or complaints through Mainstreet’s officially published branch, support or Data Protection Officer channel. Mainstreet may verify identity before acting. An individual may also complain to the Nigeria Data Protection Commission. This notice may be updated to reflect legal, regulatory or operational changes; material changes will be communicated through appropriate channels.
Primary reference: Nigeria Data Protection Act 2023.
