Draw #13 Open — Only 90 entries remaining. Enter today.

Legal

Privacy Policy

Your privacy matters to us. This policy explains exactly what personal data we collect, why we collect it, and how we keep it safe — in plain language.

Last updated: 1 June 2025 ·  Compliant with the Nigeria Data Protection Act 2023

Summary

We collect the data needed to run your account, process payments, and transfer prizes. We do not sell your data. We use industry-standard encryption and comply fully with the Nigeria Data Protection Act 2023. You can request access to, correction of, or deletion of your data at any time by emailing dpo@winbig9ja.com.

1. Data Controller

  • Winbig9ja Limited (RC No. 1234567), 12 Adeola Odeku Street, Victoria Island, Lagos State, Nigeria, is the data controller responsible for your personal data.
  • Our Data Protection Officer (DPO) can be contacted at dpo@winbig9ja.com.
  • This Policy applies to all personal data collected through the Platform, our email communications, and any offline interactions with our team.

2. Data We Collect

  • Identity data: full name, date of birth, nationality, a copy of a government-issued ID (where required for prize verification).
  • Contact data: email address, phone number, and residential address.
  • Financial data: payment method details (card type and last four digits only — full card details are processed by our PCI-DSS compliant payment processor and are never stored by Winbig9ja), bank account details for refunds.
  • Transaction data: details of entries purchased, draw participation history, and refund records.
  • Technical data: IP address, browser type and version, device identifiers, time zone, cookies, and page interaction data.
  • Marketing data: your preferences for receiving marketing communications from us.
  • We do not collect any special category data (such as health, religion, or political affiliation) unless you voluntarily provide it for a specific purpose.

3. How We Collect Data

  • Directly from you when you create an account, purchase entries, contact our support team, or complete surveys.
  • Automatically via cookies and analytics tools when you use the Platform (see Section 8 — Cookies).
  • From third-party payment processors (e.g. Paystack, Flutterwave) who confirm transaction status.
  • From identity verification providers where required to verify prize eligibility.

4. Lawful Basis for Processing

  • Contract performance: processing your entries, confirming payments, communicating draw results, and transferring prizes.
  • Legal obligation: complying with anti-money laundering regulations, tax obligations, and instructions from the NLRC.
  • Legitimate interests: fraud prevention, platform security, and improving our service — where these do not override your rights.
  • Consent: sending marketing communications. You may withdraw consent at any time by clicking "Unsubscribe" in any email or contacting us at dpo@winbig9ja.com.

5. How We Use Your Data

  • To register and maintain your account on the Platform.
  • To process entry purchases, allocate Entry Reference Numbers, and record draw participation.
  • To notify you of draw results, prize collection processes, and refunds.
  • To comply with our regulatory obligations under the NLRC licence and the Nigeria Data Protection Act 2023.
  • To detect and prevent fraud, money laundering, and other criminal activity.
  • To send you service communications (account updates, draw reminders) and, with your consent, marketing communications.
  • To analyse platform usage and improve the user experience.

6. Sharing Your Data

  • We do not sell your personal data to third parties.
  • We share data with our payment processors (Paystack / Flutterwave) strictly to complete your transactions.
  • We share data with our independent auditor and notary public solely for the purpose of conducting a specific Draw.
  • We share data with our legal advisers for the purposes of prize title transfer.
  • We may share data with law enforcement or regulatory bodies where required by law.
  • All third parties we engage are contractually bound to process your data only for the specified purpose and in compliance with the Nigeria Data Protection Act 2023.

7. Retention

  • Account data is retained for as long as your account is active and for 7 years thereafter, in compliance with Nigerian financial record-keeping requirements.
  • Transaction data (including entry records) is retained for 7 years from the date of the relevant Draw, as required by NLRC regulations.
  • Marketing data is retained until you withdraw consent.
  • Technical/log data is retained for 12 months.
  • You may request deletion of your account and personal data at any time subject to our retention obligations above.

8. Cookies

  • We use strictly necessary cookies to operate the Platform (session management, CSRF protection).
  • We use analytics cookies (Google Analytics 4) to understand how Participants use the Platform. These can be declined via our cookie banner.
  • We use preference cookies to remember your settings and language choices.
  • We do not use advertising or tracking cookies.
  • You can manage cookie preferences at any time through your browser settings.

9. Your Rights

  • Right of access: you may request a copy of all personal data we hold about you.
  • Right to rectification: you may ask us to correct inaccurate or incomplete data.
  • Right to erasure: you may ask us to delete your data where we have no overriding legal obligation to retain it.
  • Right to restrict processing: you may ask us to pause processing while a complaint is being resolved.
  • Right to data portability: you may request your data in a structured, machine-readable format.
  • Right to object: you may object to processing based on legitimate interests or for direct marketing.
  • To exercise any right, email dpo@winbig9ja.com. We will respond within 21 days.
  • You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpb.gov.ng.

10. Security

  • All data is transmitted over TLS 1.2 or higher. Sensitive data at rest is encrypted using AES-256.
  • We perform regular penetration testing and vulnerability assessments of the Platform.
  • Access to personal data within Winbig9ja is restricted to employees who need it to perform their role.
  • We maintain an incident response plan. In the event of a personal data breach that poses a risk to your rights, we will notify you and the NDPC within 72 hours.

11. Changes to This Policy

  • We may update this Policy from time to time. We will notify you of material changes by email and by a notice on the Platform at least 14 days before the change takes effect.
  • The date of the most recent revision is always shown at the top of this page.

Data Protection Enquiries

Contact our DPO at dpo@winbig9ja.com. You may also write to Winbig9ja Limited, 12 Adeola Odeku Street, Victoria Island, Lagos State.

Read our Terms of Service