Where Maxella operates an agent for a financial institution, that institution is the data controller and Maxella acts as processor on its written instructions. Customer data belongs to the institution. For visitors to this website, Maxella AI is the controller.
Consent is purpose-specific and captured per institution at the moment of value. It is versioned, auditable and revocable, and enforced on every read. Where a customer withdraws consent, processing for that purpose stops.
We process personal data in line with the Nigeria Data Protection Act. Agent configuration is tailored to the relevant regulator, including CBN, NAICOM, PenCom and SEC, and each client subsidiary runs in an isolated environment.
Enquiry data is kept only as long as needed to respond and maintain our records. Client data is retained on the institution’s instructions and its own policy, and is exported in full or deleted on exit.
You may request access, correction, deletion or restriction of your personal data. Where the data concerns a service delivered for an institution, we refer your request to that institution as controller.
Full data processing agreement, audit summary and NDPA documentation are available to client institutions on request.
Write to hello@maxella.ai.