Legal & Compliance

Privacy Notice

Effective Date: February 6, 2026Last Updated: February 5, 2026

1. Introduction

BertAndre Group Limited (“we”, “us”, “our”, or “BertAndre”) is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Notice explains how we collect, use, disclose, retain, and protect personal data when you interact with our Estate Management Product (the “Product”), our website, and related services.

This Privacy Notice is issued in compliance with the Nigeria Data Protection Act 2023 (“NDPA”), the Nigeria Data Protection Commission's General Application and Implementation Directive (“GAID”), and other applicable data protection laws and regulations.

By using our Product, website, or services, you acknowledge that you have read and understood this Privacy Notice. If you do not agree with the practices described herein, please discontinue use of our services.

2. Data Controller Information

For the purposes of this Privacy Notice, BertAndre acts as the Data Controller responsible for processing your personal data.

Registered Entity

BertAndre Consulting

Registered Address

20 Awudu Ephekha Boulevard, Lekki Phase 1, Lagos

Phone Number

09138667927

Data Protection Officer (DPO)

Name: Oluwadunsin Babatunde
Email: dunsin.babatunde@bertandregroup.com

3. Categories of Data Subjects

We process personal data belonging to the underlisted categories of individuals. For clarity, this privacy notice applies to you if you are:

  • Website Visitors: An individual visiting our official website (www.bertandregroup.com) to learn about our services, access resources, or contact us.
  • Property Owners & Administrators: A Property owner, estate manager, and/or administrator who creates accounts on the Product to manage properties and tenancies. This includes:
    • Super-Administrators: Primary account holders with full administrative privileges.
    • Administrators: Designated users with property management capabilities.
    • Authorized Users: Staff members or agents granted limited access by administrators.
  • Tenants: An individual whose tenancy information is recorded on the Product by property owners or managers, including those subject to identity verification processes.
  • Visitors: An individual who visits properties managed through the Product and whose visit details are logged by property managers or residents.
  • Payees & Payers: An individual who makes or receives payments through the Product's integrated payment and wallet services.

4. Categories of Personal Data Collected

We may collect and process the following categories of personal data based on your interaction with our services:

Personal Identification Information

Full name (first name, middle name, surname), date of birth, gender, photograph/profile picture, National Identification Number (NIN), or other government-issued identification documents.

Contact Information

Phone number(s), email address, residential address, emergency contact details.

Sensitive Data

Biometric Data

Facial recognition data (for identity verification purposes), fingerprint data (where applicable for access control).

Note: Biometric data is classified as sensitive personal data under the NDPA 2023. We implement enhanced security measures and process this data only with explicit consent or where required by law.

Financial and Transaction Data

Bank account details (for payment processing), payment card information (processed via licensed third-party payment providers- we do not directly collect or retain your card data), transaction history, wallet balance, and rental payment records.

Property and Tenancy Information

Property address and description, tenancy agreement details, rent amount, payment schedule, move-in/move-out dates, and occupancy status.

Technical and Usage Data

IP address, device information (type, operating system, browser), login timestamps, session data, geolocation data (where enabled), cookies, and similar tracking technologies.

Visitor Log Data

Visitor's full name, phone number, purpose of visit, date and time of visit, vehicle registration number (if applicable), check-in and check-out times.

5. Purposes of Processing

We process your personal data for the following essential business purposes:

  • Service Delivery, Complaint Resolution & Account Management: To create and manage your user account, resolve complaints, provide access to features, enable property/tenancy management, process visitor logging, and facilitate communications.
  • Identity Verification & Compliance: To verify tenant identity using National Identification Number (NIN) and biometric data, comply with the Nigerian Mandatory Use of National Identification Number Regulations, fulfill AML/CFT obligations, and prevent fraud.
  • Payment Processing: To process rental payments and transactions, manage wallet services, issue receipts, and process refunds.
  • Security & Fraud Prevention: To maintain audit logs of activities, detect and prevent unauthorized access, investigate security incidents, and comply with law enforcement requests.
  • Communication: To send service notifications, respond to enquiries, and send marketing communications (with your consent).
  • Legal Management & Regulatory Compliance: To comply with applicable laws, regulations, and respond to requests from authorities.

7. Third-Party Data Sharing and Disclosure

We may share your personal data with the following categories of recipients:

  • Payment Service Providers: We use licensed third-party providers (specifically Flutterwave) to process payments and manage wallets. We do not directly retain payment card details.
  • Identity Verification Providers: Contractually bound third parties that assist in verifying NIN and biometric data safely.
  • Cloud Infrastructure Providers: Reputable hosting providers with strict physical and digital security controls.
  • Property Owners & Managers: If you are a tenant/visitor, details are shared with the managers of the property you visit/occupy.
  • Regulatory & Law Enforcement: Including the NDPC, CBN, NFIU, or law enforcement in response to lawful warrants.
  • Professional Advisors: Attorneys, auditors, and IT consultants who support our compliance and operations.

All third-party service providers are bound by Data Processing Agreements (DPAs) requiring them to process data strictly under our instructions and maintain robust safety measures.

8. Data Retention

We retain data only as long as required by law or to satisfy the purposes of processing. Our retention schedule is detailed below:

Data CategoryRetention PeriodRegulatory Basis
Account InformationDuration of account + 5 yearsContractual requirements & compliance
KYC & Identity Data5 years post-account terminationMoney Laundering Act 2022
Transaction RecordsMinimum 5 years post-transactionAML compliance; CBN regulations
Tenancy RecordsDuration of tenancy + 3 yearsContractual and legal record protection
Visitor Log DataMaximum 12 monthsProperty security & check-in management
Audit Logs5 yearsSecurity, diagnostics & fraud checks
Technical Usage DataMaximum 24 monthsAnalytics & system maintenance

9. Your Rights as a Data Subject

Under the NDPA 2023, you hold key rights regarding your personal information:

Right of Access

Request confirmation of processing and obtain a copy of the personal data we hold about you.

Right to Rectification

Request updates or corrections to any incomplete or inaccurate data.

Right to Erasure (“To be Forgotten”)

Request deletion of data when it is no longer necessary or consent is withdrawn.

Right to Restrict & Object

Object to processing based on legitimate interests or request restrictions under certain conditions.

To exercise these rights, please email us at info@bertandregroup.com. We will respond within thirty (30) days of receiving your request.

10. Data Security

We implement robust technical and organizational security controls to shield data from unauthorized access or alteration. These measures include:

  • SSL/TLS encryption of data in transit and AES-256 encryption at rest.
  • Secure cryptographic password hashing.
  • Multi-factor authentication (MFA) for internal staff access.
  • Strict Role-Based Access Controls (RBAC) and network security parameters.
  • Regular automated penetration testing and threat audits.

11. International Data Transfers

Some service providers may host data outside Nigeria. If transfer occurs, we enforce safeguards like Standard Contractual Clauses (SCCs) and verify that destination countries hold adequate data protection laws under NDPA 2023 regulations.

12. Children's Privacy

Our services and Product are not intended for or directed toward individuals under the age of 18. We do not knowingly collect children's data. If we discover children's data was inadvertently stored without parental consent, we will delete it immediately.

13. Updates to This Notice

We update this notice periodically. When updates occur, we will post the changes here, adjust the “Last Updated” date at the top, and notify users via email or within the Product interface.

14. Complaints

If you believe your data has been handled in violation of NDPA rules, you have the right to file a complaint. You can contact our DPO first or write to the regulatory body:

Authority: Nigeria Data Protection Commission (NDPC)

Website: https://ndpc.gov.ng

Address: 12, Dr. Clement Isong Street, Asokoro, FCT, Abuja.

15. Contact Us

If you have any questions or require support regarding your personal data, please reach out to us at: