Privacy Policy
Contents
This Privacy Policy explains how Icon Stockbrokers Limited ("Icon", "we", "our") collects, uses, and protects the personal information of users of the Icon e-Trade mobile application ("the App"). By using the App you agree to the practices described here.
1. Who We Are
Icon Stockbrokers Limited is a licensed Dealing Member of the Nigerian Exchange Group (NGX) and is regulated by the Securities and Exchange Commission of Nigeria (SEC). We provide online securities trading services through the Icon e-Trade mobile application.
Data Controller: Icon Stockbrokers Limited
Address: 24 Campbell Street, Lagos Island, Lagos, Nigeria
Email: privacy@icon-securities.ng
2. Information We Collect
2.1 Identity & Account Information
- Full legal name, date of birth, nationality
- Email address and phone number
- Residential address
- Means of identification (government-issued ID, passport, driver's licence)
- Bank Verification Number (BVN) and National Identification Number (NIN) — used exclusively for regulatory KYC verification
- Passport photograph / selfie for biometric liveness check
2.2 Financial Information
- Bank account details linked for deposit and withdrawal
- Portfolio holdings, trade history, and order records
- Deposit and withdrawal transaction history
2.3 Device & Technical Information
- Device identifiers (for security and fraud prevention)
- IP address, operating system, and app version
- Camera and photo library access — only when you actively capture or upload KYC documents
- Face ID / biometric token — stored locally on your device; we never receive raw biometric data
2.4 Usage Data
- App interactions (screens visited, features used) for product improvement
- Crash reports and performance data (via on-device diagnostics)
- Customer support correspondence
3. How We Use Your Information
- Account creation & KYC verification — to satisfy SEC/NGX regulatory requirements
- Trade execution & settlement — to process orders on the NGX on your behalf
- Payments processing — to handle deposits and withdrawals via our payment partners
- Market intelligence & research — to deliver personalised CIE research aligned to your portfolio (with your consent where required)
- Push notifications — order confirmations, price alerts, and new research editions (you may opt out at any time)
- Fraud prevention & security — to protect your account and comply with anti-money laundering (AML) obligations
- Regulatory compliance — maintaining audit trails as required by the SEC, NGX, and CSCS rules
- Customer support — to respond to your enquiries and resolve disputes
- Service improvement — aggregate, anonymised analytics to improve App performance and features
4. Legal Basis for Processing
We process your personal data under the Nigeria Data Protection Act 2023 (NDPA) on the following bases:
- Contract performance — processing necessary to provide the trading services you have requested
- Legal obligation — SEC, NGX, and CSCS regulations requiring KYC, AML checks, and audit trails
- Legitimate interests — fraud prevention, security monitoring, and service improvement
- Consent — marketing communications and optional research personalisation (you may withdraw consent at any time)
5. Sharing Your Information
We do not sell your personal data. We may share data with:
- Central Securities Clearing System (CSCS) — for share settlement and registration
- Nigerian Exchange Group (NGX) — for trade execution and reporting
- Cellion Platforms Nigeria Limited — our KYC and Capital Intelligence Engine partner, under a binding Data Processing Agreement
- Paystack (a Stripe company) — our payment gateway, for processing deposits and withdrawals
- Regulatory authorities — the SEC, Central Bank of Nigeria (CBN), or EFCC when required by law
- Professional advisers — lawyers and auditors under confidentiality obligations
All third-party processors are contractually required to handle your data in accordance with applicable Nigerian data protection law.
6. Data Retention
We retain personal data for as long as your account is active and for a minimum of seven (7) years after account closure, as required by SEC and CBN regulations for financial records. Anonymised or aggregated data may be retained indefinitely for analytics purposes.
7. Security
We implement industry-standard security measures including:
- TLS 1.2+ encryption for all data in transit
- Encrypted storage for sensitive credentials (passwords are hashed using bcrypt)
- JWT-based session authentication with short-lived tokens
- Role-based access controls limiting staff access to client data
- Full audit logging of all administrative actions
No method of transmission over the internet or electronic storage is 100% secure. If you suspect unauthorised access to your account, please contact us immediately at security@icon-securities.ng.
8. Your Rights
Under the Nigeria Data Protection Act 2023 you have the right to:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate or incomplete data
- Erasure — request deletion of your data (subject to our legal retention obligations)
- Restriction — request that we limit the processing of your data in certain circumstances
- Portability — receive your data in a structured, machine-readable format
- Object — object to processing based on legitimate interests or for direct marketing
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior lawful processing
To exercise any of these rights, please email privacy@icon-securities.ng. We will respond within 30 days.
If you are dissatisfied with our response, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.
9. Children's Privacy
The Icon e-Trade App is intended for users aged 18 and above. We do not knowingly collect personal information from persons under 18. If you believe a minor has created an account, please contact us and we will delete the account and associated data promptly.
10. International Users
Icon e-Trade is designed for Nigerian residents and citizens. If you access the App from outside Nigeria, please be aware that your data will be processed in Nigeria and any other country where our service providers operate. By using the App you consent to such transfer.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via in-app notification and update the "Last Updated" date at the top of this page. Your continued use of the App after the effective date constitutes acceptance of the revised policy.
12. Contact Us
For any privacy-related questions, requests, or concerns:
- Email: privacy@icon-securities.ng
- Post: Data Privacy Officer, Icon Stockbrokers Limited, 24 Campbell Street, Lagos Island, Lagos, Nigeria
- Regulatory body: Nigeria Data Protection Commission — ndpc.gov.ng