Privacy Policy
- Home
- Privacy Policy
Privacy Policy
OmniAfric Trust Bank (“the Bank”) is committed to protecting the privacy and security of the personal information entrusted to us by our customers, representatives, and other individuals. This Privacy Policy explains how we collect, use, store, share, and safeguard personal data when establishing or maintaining a banking relationship, whether through our branches, website, digital channels, or other banking services. We process all personal information in accordance with applicable laws, regulations, and industry best practices.
1. Collection of Personal Data
As part of establishing and maintaining a banking relationship, the Bank may collect personal information relating to customers, legal representatives, directors, authorized signatories, beneficial owners, and other associated individuals. The information we collect may include:
- Identification and civil status information
- Copies of valid official identification documents
- Contact details
- Employment, professional, and financial information
- Details relating to authorized representatives and signatories
To comply with applicable legal and regulatory obligations — including anti-money laundering (AML), counter-terrorism financing (CTF), fraud prevention, sanctions screening, risk management, and transaction monitoring — the Bank may also collect information relating to:
- Individuals associated with the customer or account
- Beneficial owners, beneficiaries, recipients, and intermediaries involved in transactions
- Parties connected with customer-related financial activities and business relationships
Data may be obtained directly from clients when opening accounts, subscribing to products, performing transactions, or providing instructions, or indirectly from authorized third-party sources such as public databases, commercial registers, or other legally recognized sources.
2. Purposes of Processing
Personal data is collected and processed by the Bank for specific, legitimate, and transparent purposes, including:
2.1 Account and Product Management
The Bank processes personal data to:
- Open, administer, and maintain customer accounts, products, and banking services
- Process, execute, and record transactions, requests, and instructions
- Fulfill contractual and service-related obligations
2.2 Relationship Management and Marketing
The Bank may process personal data to:
- Manage customer relationships and enhance the quality of our services
- Provide information about products, services, and relevant financial solutions
- Organize customer engagements, events, and communications
- Conduct statistical, analytical, and behavioral assessments for internal business improvement purposes
2.3 Regulatory and Compliance Requirements
The Bank processes personal data to:
- Verify identity, legal capacity, and customer information
- Monitor transactions and assess operational, financial, and compliance risks
- Prevent fraud, financial crime, money laundering, terrorist financing, and conflicts of interest
- Meet regulatory requirements, reporting obligations, and supervisory standards
The Bank may also record and retain electronic communications, including telephone calls, emails, and digital messages, where permitted by law, for regulatory compliance, security monitoring, dispute resolution, and service quality assurance purposes.
3. Sharing Personal Data with Third Parties
The Bank may share personal data only where necessary to provide banking services, comply with legal and regulatory obligations, or support its legitimate business operations. Appropriate safeguards are applied to ensure that all personal information remains secure and confidential.
3.1 Within OmniAfric Trust Bank
Personal data may be shared within OmniAfric Trust Bank and its affiliated entities where necessary to:
- Manage customer relationships and banking activities
- Deliver banking products and services
- Process and execute transactions
- Support centralized accounting, reporting, compliance, risk management, and operational functions
3.2 Service Providers and Business Partners
The Bank may share personal data with carefully selected third-party service providers that support our operations, including information technology, payment processing, document management, customer support, cloud services, and other outsourced business functions.
All service providers are subject to contractual obligations requiring them to maintain the confidentiality, integrity, and security of personal information and to process such data only for authorized purposes. The Bank implements appropriate technical, organizational, and physical safeguards to protect personal data throughout its lifecycle.
4. International Data Transfers
To support our banking operations and the delivery of services, personal data may be transferred to, stored in, or accessed from jurisdictions outside the African Economic Area (AEA) where applicable. Where such transfers occur, the Bank implements appropriate safeguards to ensure that personal data remains protected in accordance with applicable data protection laws.
International data transfers are conducted using legally recognized safeguards, which may include:
- Binding contractual arrangements, including standard contractual clauses or other approved transfer mechanisms
- Authorizations or approvals from relevant data protection or regulatory authorities, where required by applicable law
- Other legally recognized safeguards that provide an adequate level of protection for personal data
The Bank may also disclose personal data to regulatory, judicial, law enforcement, or other competent authorities — within or outside the African Economic Area — where required to comply with applicable laws, including anti-money laundering (AML), counter-terrorism financing (CTF), sanctions, fraud prevention, tax, or other legal and regulatory obligations.
5. Security Measures
The Bank is committed to protecting personal data through robust organizational, physical, and technical security measures designed to safeguard information throughout its lifecycle.
Our security controls are intended to:
- Protect personal data against unauthorized access, misuse, loss, alteration, or destruction
- Maintain the confidentiality, integrity, and availability of information
- Prevent unauthorized disclosure, modification, or processing of personal data
- Ensure the resilience and security of our systems, networks, and digital services
The Bank regularly reviews and enhances its security practices to address evolving cyber threats, technological developments, and applicable legal and regulatory requirements, ensuring that personal information remains protected in accordance with industry best practices.
6. Your Privacy Rights
Subject to applicable data protection laws, individuals whose personal data is processed by the Bank may exercise the following rights
- Right of Access – Request confirmation of whether your personal data is being processed and obtain a copy of the information we hold
- Right to Rectification – Request the correction or updating of inaccurate, incomplete, or outdated personal data
- Right to Erasure – Request the deletion of your personal data where permitted by applicable law and subject to the Bank's legal and regulatory obligations
- Right to Object – Object to the processing of your personal data on legitimate grounds, where applicable. Please note that exercising this right may affect the Bank's ability to provide certain products or services
- Right to Restrict Processing – Request that the processing of your personal data be limited under specific circumstances provided by law
- Right to Object to Direct Marketing – Request that your personal data not be used or shared for direct marketing or other commercial communications
To exercise any of these rights, please contact your Relationship Manager or your designated Customer Service Representative. The Bank will respond to all valid requests in accordance with applicable legal and regulatory requirements.