Summary
We collect the data needed to run your account, process payments, and transfer prizes. We do not sell your data. We use industry-standard encryption and comply fully with the Nigeria Data Protection Act 2023. You can request access to, correction of, or deletion of your data at any time by emailing dpo@winbig9ja.com.
1. Data Controller
- Winbig9ja Limited (RC No. 1234567), 12 Adeola Odeku Street, Victoria Island, Lagos State, Nigeria, is the data controller responsible for your personal data.
- Our Data Protection Officer (DPO) can be contacted at dpo@winbig9ja.com.
- This Policy applies to all personal data collected through the Platform, our email communications, and any offline interactions with our team.
2. Data We Collect
- Identity data: full name, date of birth, nationality, a copy of a government-issued ID (where required for prize verification).
- Contact data: email address, phone number, and residential address.
- Financial data: payment method details (card type and last four digits only — full card details are processed by our PCI-DSS compliant payment processor and are never stored by Winbig9ja), bank account details for refunds.
- Transaction data: details of entries purchased, draw participation history, and refund records.
- Technical data: IP address, browser type and version, device identifiers, time zone, cookies, and page interaction data.
- Marketing data: your preferences for receiving marketing communications from us.
- We do not collect any special category data (such as health, religion, or political affiliation) unless you voluntarily provide it for a specific purpose.
3. How We Collect Data
- Directly from you when you create an account, purchase entries, contact our support team, or complete surveys.
- Automatically via cookies and analytics tools when you use the Platform (see Section 8 — Cookies).
- From third-party payment processors (e.g. Paystack, Flutterwave) who confirm transaction status.
- From identity verification providers where required to verify prize eligibility.
4. Lawful Basis for Processing
- Contract performance: processing your entries, confirming payments, communicating draw results, and transferring prizes.
- Legal obligation: complying with anti-money laundering regulations, tax obligations, and instructions from the NLRC.
- Legitimate interests: fraud prevention, platform security, and improving our service — where these do not override your rights.
- Consent: sending marketing communications. You may withdraw consent at any time by clicking "Unsubscribe" in any email or contacting us at dpo@winbig9ja.com.
5. How We Use Your Data
- To register and maintain your account on the Platform.
- To process entry purchases, allocate Entry Reference Numbers, and record draw participation.
- To notify you of draw results, prize collection processes, and refunds.
- To comply with our regulatory obligations under the NLRC licence and the Nigeria Data Protection Act 2023.
- To detect and prevent fraud, money laundering, and other criminal activity.
- To send you service communications (account updates, draw reminders) and, with your consent, marketing communications.
- To analyse platform usage and improve the user experience.
7. Retention
- Account data is retained for as long as your account is active and for 7 years thereafter, in compliance with Nigerian financial record-keeping requirements.
- Transaction data (including entry records) is retained for 7 years from the date of the relevant Draw, as required by NLRC regulations.
- Marketing data is retained until you withdraw consent.
- Technical/log data is retained for 12 months.
- You may request deletion of your account and personal data at any time subject to our retention obligations above.
9. Your Rights
- Right of access: you may request a copy of all personal data we hold about you.
- Right to rectification: you may ask us to correct inaccurate or incomplete data.
- Right to erasure: you may ask us to delete your data where we have no overriding legal obligation to retain it.
- Right to restrict processing: you may ask us to pause processing while a complaint is being resolved.
- Right to data portability: you may request your data in a structured, machine-readable format.
- Right to object: you may object to processing based on legitimate interests or for direct marketing.
- To exercise any right, email dpo@winbig9ja.com. We will respond within 21 days.
- You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpb.gov.ng.
10. Security
- All data is transmitted over TLS 1.2 or higher. Sensitive data at rest is encrypted using AES-256.
- We perform regular penetration testing and vulnerability assessments of the Platform.
- Access to personal data within Winbig9ja is restricted to employees who need it to perform their role.
- We maintain an incident response plan. In the event of a personal data breach that poses a risk to your rights, we will notify you and the NDPC within 72 hours.
11. Changes to This Policy
- We may update this Policy from time to time. We will notify you of material changes by email and by a notice on the Platform at least 14 days before the change takes effect.
- The date of the most recent revision is always shown at the top of this page.
Data Protection Enquiries
Contact our DPO at dpo@winbig9ja.com. You may also write to Winbig9ja Limited, 12 Adeola Odeku Street, Victoria Island, Lagos State.
Read our Terms of Service