Legal

Privacy Policy

Updated September 2026

01Who controls your data

Where Maxella operates an agent for a financial institution, that institution is the data controller and Maxella acts as processor on its written instructions. Customer data belongs to the institution. For visitors to this website, Maxella AI is the controller.

02What we collect

  • What you give us directly: name, work email, organisation, and what you tell us in a demo request.
  • Technical information from your visit, used to understand how the site performs.
  • On behalf of client institutions: the customer records and interaction signals that institution instructs us to process.

03Consent

Consent is purpose-specific and captured per institution at the moment of value. It is versioned, auditable and revocable, and enforced on every read. Where a customer withdraws consent, processing for that purpose stops.

04Lawful basis

We process personal data in line with the Nigeria Data Protection Act. Agent configuration is tailored to the relevant regulator, including CBN, NAICOM, PenCom and SEC, and each client subsidiary runs in an isolated environment.

05Retention

Enquiry data is kept only as long as needed to respond and maintain our records. Client data is retained on the institution’s instructions and its own policy, and is exported in full or deleted on exit.

06Your rights

You may request access, correction, deletion or restriction of your personal data. Where the data concerns a service delivered for an institution, we refer your request to that institution as controller.

Full data processing agreement, audit summary and NDPA documentation are available to client institutions on request.

07Contact