Privacy Policy
Privacy Policy
GOSAR is a global fintech infrastructure platform. We take your privacy seriously across every market we operate in. This policy explains how we collect, use, and protect your personal information β wherever you are.
01 Who We Are
GOSAR (operated by GOSAR PRIME TECHNOLOGY and its affiliated entities, collectively "GOSAR," "we," "our," or "us") provides fintech infrastructure services including business incorporation, regulatory licensing, compliance management, and Merchant of Record (MoR) solutions across Africa and other international markets.
GOSAR acts as the data controller in respect of personal information collected through our website (gosar.co), our platform, and in the course of providing services to clients, merchants, and their customers. Where we process personal data on behalf of our clients, we act as a data processor, and our data processing agreements govern that relationship.
Registered Entity
GOSAR PRIME TECHNOLOGY (trading as GOSAR)
Website: www.gosar.co | Email: privacy@gosar.co
Offices: Nigeria (Abuja) Β· Canada Β· Cameroon
02 What We Collect
Identity & Contact Information
- Full name, email address, phone number, mailing address
- Government-issued ID, passport, or BVN/NIN (for regulatory KYC/AML purposes)
- Company registration details, director information, and beneficial ownership data
- Date of birth where required for identity verification
Financial & Transaction Information
- Payment card details (tokenised; we do not store raw card numbers)
- Bank account details, IBAN, or mobile money wallet references
- Transaction records, billing history, and settlement data
- Merchant revenue data and payout records where GOSAR acts as Merchant of Record
Business & Licensing Information
- Incorporation documents, share structures, business plans
- Regulatory application data submitted for licensing on your behalf
- Compliance documentation including AML/CFT records
Technical & Usage Data
- IP address, browser type, device identifiers
- Platform usage logs, API call metadata, session data
- Cookies and similar tracking technologies (see Section 10)
Communications Data
- Emails, support tickets, and onboarding call notes
- Feedback, survey responses, and testimonials
Special Categories: Where we collect sensitive data such as biometric information or politically exposed person (PEP) status, we do so solely to meet our regulatory obligations under applicable financial services laws. We apply enhanced safeguards to such data.
03 How We Use Your Information
Service Delivery
- Providing incorporation, licensing, and compliance services
- Operating our Merchant of Record infrastructure on your behalf
- Processing payments and managing settlements
- Communicating with regulators on your behalf during licensing processes
Regulatory & Legal Obligations
- Conducting Know Your Customer (KYC) and Know Your Business (KYB) checks
- Anti-Money Laundering (AML) and Counter-Financing of Terrorism (CFT) screening
- Filing required reports with applicable regulators (CBN, FINTRAC, FCA, etc.)
- Maintaining records as required under financial services and data protection laws
Platform Operations & Security
- Account management, authentication, and access control
- Fraud detection, risk monitoring, and security incident response
- Platform maintenance, debugging, and performance optimisation
Business Communications & Marketing
- Service notifications, policy updates, and billing communications
- Marketing communications about GOSAR services where you have consented or where permitted by law
- Client success outreach and account management
04 Legal Bases for Processing
We process your personal information under one or more of the following legal bases, depending on the applicable jurisdiction and purpose:
06 International Data Transfers
As a multi-jurisdiction platform, GOSAR processes and stores personal data across Canada, Nigeria, Cameroon, and other countries where we operate. Where we transfer personal data across borders, we put in place appropriate safeguards:
- Standard Contractual Clauses (SCCs) or equivalent approved mechanisms for transfers from the EU/UK
- Data Processing Agreements with all cross-border sub-processors meeting applicable adequacy standards
- Transfers to Canada from EU/UK benefit from Canada's adequacy status under GDPR
- For transfers involving Nigeria, we comply with the cross-border transfer provisions under the Nigeria Data Protection Act 2023 (Section 43)
- For transfers involving Cameroon, we apply contractual safeguards consistent with applicable CEMAC and national data protection standards
You may request details of the specific safeguards applied to any cross-border transfer by contacting us at privacy@gosar.co.
07 Data Retention
We retain your personal information for as long as necessary to fulfil the purposes set out in this policy and to comply with our legal, regulatory, and contractual obligations. Our primary retention periods are:
- Client account data: Duration of the client relationship plus 7 years, aligned with financial regulatory record-keeping requirements across applicable jurisdictions
- KYC/AML records: Minimum 5 years after the end of the business relationship, or 10 years where required under applicable AML regulations
- Transaction records: 7 years from the date of transaction, or as required by the applicable regulator
- Marketing data: Until you withdraw consent or opt out, plus 12 months for audit purposes
- Website analytics: 26 months from collection
- Support communications: 3 years from closure of the matter
When personal data is no longer required, we securely delete or anonymise it in accordance with our data destruction procedures.
08 Your Privacy Rights
Subject to applicable law, you have the following rights in respect of your personal information:
To exercise any of these rights, submit a request to privacy@gosar.co. We will respond within 30 days (or sooner where required by law). We may need to verify your identity before processing your request.
09 Security
GOSAR implements technical and organisational measures appropriate to the sensitivity of the personal data we process, including:
- AES-256 encryption for data at rest; TLS 1.2+ for data in transit
- Access controls based on the principle of least privilege
- Multi-factor authentication for platform access
- Regular security audits, penetration testing, and vulnerability management
- Incident response procedures with mandatory breach notification protocols
- Staff training on data protection and information security
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (or the period required by applicable law) and affected individuals without undue delay.
11 Children's Privacy
GOSAR's services are intended for businesses and adults aged 18 years and older. We do not knowingly collect personal information from individuals under 18. If we become aware that we have inadvertently collected personal data from a minor, we will delete such information promptly. Contact us at privacy@gosar.co if you believe we may have received information from a child.
Jurisdiction-Specific Notices
The following supplements apply to residents of specific jurisdictions. Where there is a conflict between a supplement and the general policy above, the supplement governs for residents of that jurisdiction.
GOSAR is registered as a Money Services Business (MSB) applicant with FINTRAC and processes Canadian personal information in compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.
Accountability & Consent
GOSAR has designated a Privacy Officer accountable for our PIPEDA compliance. We obtain meaningful consent before collecting, using, or disclosing personal information, except where law permits us to do so without consent (e.g. mandatory AML/CFT reporting to FINTRAC).
Quebec Supplement β Law 25
For residents of Quebec, we comply with Quebec's Act respecting the protection of personal information in the private sector as amended by Law 25, including privacy impact assessments for high-risk uses, availability of this policy in French upon written request, and honouring the right to data portability and the right to be forgotten. Contact privacy@gosar.co to request a French-language version.
FINTRAC Reporting
As a regulated MSB, GOSAR is required under the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) to collect and retain certain personal information and to report specified transactions to FINTRAC. This processing is mandatory and cannot be restricted or consented out of.
Access & Correction
Canadian residents may request access to their personal information and correction of inaccuracies by contacting our Privacy Officer at privacy@gosar.co. We will respond within 30 days.
Complaints
If you are dissatisfied with our response, you may contact the Office of the Privacy Commissioner of Canada at priv.gc.ca or, for Quebec residents, the Commission d'accès à l'information du Québec.
GOSAR operates in Nigeria through its affiliated Nigerian entity and processes personal data in compliance with the Nigeria Data Protection Act 2023 (NDPA) administered by the Nigeria Data Protection Commission (NDPC).
Data Controller Registration
GOSAR is registered as a Data Controller with the NDPC. Our registration details are available upon request.
Lawful Bases Under the NDPA
We process personal data of Nigerian residents on the bases of: consent, contractual necessity, legal obligation (including CBN, SEC, and NDPC requirements), legitimate interests, and vital interests as defined under the NDPA 2023.
Rights of Nigerian Data Subjects
- Right to be informed of processing activities
- Right to access, rectify, and delete personal data
- Right to object to processing and withdraw consent
- Right to data portability
- Right to lodge a complaint with the NDPC
Cross-Border Transfers
Transfers of personal data of Nigerian residents outside Nigeria are conducted in accordance with Section 43 of the NDPA, which requires that the recipient country affords adequate data protection or that appropriate contractual safeguards are in place.
CBN Financial Data
Personal and transaction data processed in connection with CBN-regulated activities is subject to the CBN Consumer Protection Framework and applicable CBN Circulars governing data management by payment service providers.
Complaints
Nigerian residents may direct complaints to the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.
GOSAR serves clients in Cameroon and processes related personal data in compliance with Cameroon's applicable data protection and cybersecurity legal framework, including Law No. 2010/012 on cybersecurity and cybercriminality, and COBAC payment operator requirements within the CEMAC zone.
Data Handling Principles
Personal data of Cameroonian individuals is collected only for specified, legitimate purposes, stored securely, and not transferred to third parties except as required for service delivery or by law. GOSAR applies safeguards consistent with OHADA financial services standards and applicable COBAC directives.
Bilingual Service
In recognition of Cameroon's bilingual status, this policy and key service communications are available in French upon written request to privacy@gosar.co.
Rights & Enquiries
Cameroonian data subjects may exercise rights of access, rectification, and objection by contacting us at privacy@gosar.co. As Cameroon's dedicated data protection regulatory framework continues to mature, GOSAR commits to updating its compliance posture accordingly and will notify affected clients of material changes.
To the extent GOSAR processes personal data of individuals located in the EU or UK β for example EU-based clients or in connection with our FCA licensing activities β we do so in compliance with the EU General Data Protection Regulation (GDPR) and the UK GDPR.
Lawful Bases
We rely on Article 6 GDPR bases: contract performance (Art. 6(1)(b)), legal obligation (Art. 6(1)(c)), legitimate interests (Art. 6(1)(f)), and consent (Art. 6(1)(a)). For special category data, we rely on Article 9(2)(b) and Article 9(2)(g) where applicable.
EU/UK Data Subject Rights
- Right to access (Art. 15 GDPR)
- Right to rectification (Art. 16)
- Right to erasure β right to be forgotten (Art. 17)
- Right to restriction of processing (Art. 18)
- Right to data portability (Art. 20)
- Right to object (Art. 21)
- Rights related to automated decision-making (Art. 22)
International Transfers
Where we transfer personal data from the EU/UK to third countries, we rely on the applicable adequacy decision (Canada holds a GDPR adequacy decision) or Standard Contractual Clauses (SCCs) as the transfer mechanism. For transfers to Nigeria and Cameroon, SCCs and appropriate contractual safeguards apply.
UK Representative
GOSAR is in the process of engaging a UK GDPR Article 27 representative for UK data subjects. Details will be published here upon confirmation.
Supervisory Authorities
EU residents may lodge complaints with their national supervisory authority. UK residents may contact the Information Commissioner's Office (ICO) at ico.org.uk.
12 Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, data practices, or applicable law. We will notify you of material changes by posting the updated policy with a revised effective date, emailing registered users, and displaying in-platform notifications for active clients. Your continued use of GOSAR's services after the effective date constitutes acceptance of the updated policy.
The current version is effective as of 1 June 2025.
13 Contact Us & Data Protection Officer
For any questions, concerns, or data subject requests relating to this Privacy Policy, contact us through the following channels:
Data Subject Requests: Email privacy@gosar.co with the subject line "Data Subject Request β [Your Country]". We acknowledge within 48 hours and respond fully within the timeframe required by your applicable law.