Zeravest Privacy Policy
Effective date: 1 January 2026
Last updated: 23 February 2026
- Zeravest (“we”, “us”, “our”) is an education-first web application that provides news, data, and interactive tools about the Nigerian capital market. This Privacy Policy explains how we collect, use, disclose, and protect information when you:
- Visit or use the Zeravest website, mobile web, or any associated service (collectively, the “Service”).
- Interact with our AI-powered chatbot (“Zera”) for learning purposes.
- By accessing the Service you agree to the terms below. If you do not agree, please discontinue use.
- Definitions “Personal Data” means any information that can identify an individual, directly or indirectly, in line with the Nigeria Data Protection Regulation (NDPR) 2019 and the EU General Data Protection Regulation (GDPR) where applicable. “Process/Processing” means any operation performed on data, whether automated or not. “User”, “you”, “your” means any person who accesses or uses the Service.
- Information We Collect
- Information you provide voluntarily
- Account credentials (name, email, password hash).
- Optional profile data (phone number, city, state, investor category, bio).
- Chatbot conversations you initiate (text, attachments, feedback).
- Support tickets or survey responses.
- Information collected automatically
- Device identifiers (IP address, browser user-agent, OS, language).
- Usage analytics (pages viewed, time spent, buttons clicked, scroll depth)
- Log files (error reports, feature usage).
- Cookies and similar technologies (see Section 9).
- Information from third parties
- Social-media profile data when you choose “Sign in with Google or other third party auth provider”.
- Publicly available regulatory filings or company announcements that you request the Chatbot to retrieve and summarise.
- Information We Collect
- Legal Bases for Processing (GDPR/NDPR)
- Consent: optional newsletters, cookies (non-essential), Chatbot storage.
- Contract: account creation, delivering purchased features.
- Legitimate interests: fraud detection, service improvement, network security.
- Legal obligation: retaining transaction records under Securities & Exchange Commission (SEC) Nigeria rules and the Companies & Allied Matters Act.
- Purpose of Processing
- Provide, personalise, and improve the Service.
- Answer your capital-market questions via the Chatbot.
- Send market alerts or educational content you opt into.
- Detect and prevent abuse, spam, or market-manipulation attempts.
- Generate aggregated insights for research or public reports (non-identifiable).
- Comply with regulatory audits or lawful requests.
- Data Sharing & Disclosure We never sell your Personal Data. We only share:
- With service providers (hosting, analytics, email delivery) under written data-processing agreements.
- With regulators or law-enforcement when legally compelled. • With your consent (e.g., sharing a portfolio summary you generate with a friend via a shareable link).
- In business transfers (merger, acquisition, asset sale) with notice to you.
- Aggregated or anonymised statistics with research partners or advertisers (cannot identify you).
- International Transfers Our primary servers are in AWS eu-west-1 (Ireland). Where we transfer data outside Nigeria we:
- Execute Standard Contractual Clauses (SCCs) approved by the European Commission.
- Verify adequate protection under NDPR guidelines. Maintain encryption in transit (TLS 1.3) and at rest (AES-256).
- Cookies & Similar Technologies Essential cookies keep you logged in. Analytics cookies help us understand traffic (Google Analytics 4, self-hosted Plausible). Marketing cookies are off by default; you may opt in. You can manage preferences via the “Cookie Settings” link in the footer. Do-Not-Track signals are honoured.
- Security Measures
- ISO 27001-aligned information-security management system.
- End-to-end encryption for Chatbot sessions (TLS 1.3 + 256-bit AES at rest).
- Multi-factor authentication for staff; least-privilege access; quarterly penetration tests.
- Continuous vulnerability scanning; 24-hour incident-response team. Despite best efforts, no internet transmission is 100 % secure; you should use strong passwords and keep them confidential.
- Your Rights: You may, at no cost:
- Access, rectify, or erase your Personal Data.
- Restrict or object to processing.
- Receive your data in a portable format.
- Withdraw consent at any time (does not affect prior lawful processing).
- Lodge a complaint with the Nigeria Data Protection Bureau (NDPB) or your EU supervisory authority. To exercise rights, email privacy@zeravest.ng or use our contact form. We respond within 30 days.
- Children’s Privacy The Service is intended for users aged 16+. We do not knowingly collect data from children under 16. If you believe we have such data, contact us; we will promptly delete it.
- Chatbot Specifics
- The Chatbot is for educational purposes only; its responses do not constitute investment advice.
- We log questions and answers to improve accuracy. You may delete individual threads or your entire history in Settings.
- Do not enter sensitive personal data (e.g., bank OTPs, passport numbers) into the Chatbot. If you accidentally do, notify us immediately so we can purge the data.
- AI models are hosted by Zeravest; no third-party AI provider retains your data beyond temporary processing.
- Third-Party Links: The Service may link to stockbrokers, regulators, or news sites. This Policy does not cover external sites; review their policies before submitting data.
- Changes to This Policy We will post material changes on this page with a “Last updated” date and, where feasible, send you email notice. Continued use after changes constitutes acceptance.
- Consent Statement By clicking “Sign Up” or by continuing to interact with the Service, you acknowledge that you have read, understood, and agree to this Privacy Policy and our Terms of Service.