Skip to content
Mainstreet Microfinance BankFieldCRM
HomePlatformWorkflowMobileControlsHelp
Staff login ↗

Privacy notice

How personal data is handled in FieldCRM.

This notice explains the principal processing carried out through FieldCRM by Mainstreet Microfinance Bank in accordance with the Nigeria Data Protection Act 2023 and applicable banking obligations.

Effective
2 September 2026
Applies to
Staff, applicants, customers, guarantors and related persons
1. Controller2. Data collected3. Purposes and lawful bases4. Sharing5. Retention6. Your rights7. Security8. Contact and complaints

1. Data controller and scope

Mainstreet Microfinance Bank Limited is the controller for personal data processed through FieldCRM for loan origination, assessment, approval, servicing, collections, compliance, security and audit. Approved service providers may act as processors under Mainstreet’s instructions.

2. Personal data we process

Depending on the relationship and product, FieldCRM may process identity and contact details; BVN, NIN and other identifiers; photographs and signatures; employment and business details; addresses and GPS/visit evidence; income, expenditure, account and transaction information; loan, repayment and arrears data; documents; guarantor, collateral and credit-bureau information; communications; device, session, IP, security and audit records.

Some information may constitute sensitive personal data or create significant risk if misused. Access is restricted according to responsibility and business need.

3. Purposes and lawful bases

We process data to take steps at an applicant’s request and perform contracts; comply with legal and regulatory duties, including customer identification, credit, prudential, reporting, fraud-prevention and recordkeeping obligations; protect legitimate interests in secure and efficient credit operations; establish, exercise or defend legal claims; protect vital or public interests where applicable; and rely on consent where law requires it and consent is appropriate.

Providing required application and verification information may be necessary to assess or service a facility. Where information is not provided, Mainstreet may be unable to proceed, subject to applicable law and fair-treatment duties.

4. Sources and permitted sharing

Data may come from the individual, authorised Mainstreet personnel, prior Mainstreet records, referees or guarantors, identity and credit providers, core-banking systems, public or legally accessible sources, and approved service providers. It may be shared on a need-to-know basis with Mainstreet personnel, regulators, credit bureaux, identity-verification providers, professional advisers, auditors, courts, law-enforcement bodies acting lawfully, technology processors, and parties involved in enforcing or restructuring a facility.

Cross-border transfers, if any, must use a lawful transfer mechanism and safeguards required by the Nigeria Data Protection Act. Mainstreet does not authorise staff to export personal data to personal accounts or unapproved services.

5. Retention and accuracy

Records are retained for the period required by banking, tax, anti-money-laundering, limitation, audit, litigation and other applicable obligations, and no longer than necessary for the stated purposes. Some workflow, approval and audit records are maintained as immutable evidence. Inaccurate source data should be reported through official channels; corrections may be recorded without erasing required historical evidence.

6. Data-subject rights

Subject to lawful restrictions and identity verification, individuals may request information about processing and access to their data; correction; erasure where retention is not legally required; restriction; objection; portability where applicable; withdrawal of consent without affecting earlier lawful processing; and review of a significant decision based solely on automated processing. FieldCRM supports staff decision-making and does not authorise a solely automated final credit decision unless separately approved and lawfully implemented.

7. Security and incidents

Mainstreet applies organisational and technical safeguards including role and tenant controls, session protection, encryption for designated sensitive data, secure document access, validation, logging, monitoring and recovery controls. No system is risk-free. Suspected loss, unauthorised access or disclosure must be reported immediately through the official Mainstreet security or support channel.

8. Requests, complaints and updates

Submit privacy requests or complaints through Mainstreet’s officially published branch, support or Data Protection Officer channel. Mainstreet may verify identity before acting. An individual may also complain to the Nigeria Data Protection Commission. This notice may be updated to reflect legal, regulatory or operational changes; material changes will be communicated through appropriate channels.

Primary reference: Nigeria Data Protection Act 2023.

Mainstreet Microfinance Bank

© 2026 Mainstreet Microfinance Bank Limited. All rights reserved.

HomePlatformControlsPrivacyTermsStaff login