BPRIME ASSETS LIMITED

Operator of the BPrime Projects Platform (x.bprimeassets.com)

Security & Data Protection Statement

BPrime Projects — a platform of BPrime Assets Limited

Legal EntityBPrime Assets Limited (“BPrime”, “the Company”, “we”, “us”, or “our”)
PlatformBPrime Projects — x.bprimeassets.com
Corporate Sitebprimeassets.com
JurisdictionFederal Republic of Nigeria
Effective Date6 July 2026
VersionVersion 1.0
Contactlegal@bprimeassets.com

Table of Contents

1. Introduction

This Security & Data Protection Statement (“Statement”) describes the technical, organisational, and procedural measures that BPrime Assets Limited (“BPrime”, “we”, “us”, or “our”) has implemented to protect the confidentiality, integrity, and availability of Personal Data and other information processed through the BPrime Projects platform (projects.bprimeassets.com) (the “Platform”), including Project data, payment information, and contracts generated using the Contract Tools.

This Statement supplements, and should be read together with, our Privacy Policy. For security reasons, certain specific technical configurations are not disclosed publicly; this Statement describes our practices at a level appropriate for general assurance without compromising the effectiveness of our controls.

2. Governance and Organisational Measures

2.1 Data Protection Officer

In accordance with the NDPA, BPrime has designated a Data Protection Officer (DPO) responsible for overseeing our data protection compliance programme. The DPO may be contacted at legal@bprimeassets.com.

2.2 Policies and Training

We maintain internal information security and data protection policies applicable to all personnel and contractors with access to Platform systems, Project data, or Personal Data. Personnel undergo periodic training on data protection, security awareness, and incident reporting.

2.3 Access Governance

Access to systems processing Personal Data, Project records, and Generated Contracts is governed by the principle of least privilege. Access rights are reviewed periodically and revoked promptly upon a change of role or termination of engagement.

2.4 Vendor and Processor Oversight

Where we engage third-party service providers, including our Payment Processor (Paystack) and any e-signature or document infrastructure providers, we conduct due diligence on their security practices and require contractual commitments consistent with the NDPA and this Statement, including confidentiality, security, and breach notification obligations.

3. Technical Security Measures

3.1 Encryption

  • Transport Layer Security (TLS) encryption for data transmitted between User devices and the Platform;
  • Encryption of sensitive data at rest, including Project records, contract content, and payment metadata, within our production databases and backup systems;
  • Secure handling of authentication credentials, which are never stored in plain text.

3.2 Authentication and Access Control

  • Secure session management with defined session expiry and re-authentication requirements;
  • Support for strong password requirements and, where enabled, multi-factor authentication (MFA);
  • Monitoring of login attempts and contract-execution requests to detect suspicious or anomalous activity;
  • Rate-limiting and account lock-out mechanisms to mitigate brute-force attacks.

3.3 Network and Infrastructure Security

  • Firewalls, network segmentation, and intrusion detection/prevention systems;
  • Regular vulnerability scanning and periodic penetration testing of Platform infrastructure and applications;
  • Hardened server configurations and timely application of security patches;
  • Continuous monitoring and logging of system activity to support security incident detection and forensic investigation.

3.4 Payment Security

Payment transactions are processed through Paystack Payments Limited, a licensed payment service provider maintaining Payment Card Industry Data Security Standard (PCI DSS) compliance. BPrime does not store full payment card details on its own systems.

3.5 Contract Document Security

Generated Contracts, including any Personal Data of Contract Counterparties they contain, are stored using the same encryption-at-rest and access-control standards applied to other sensitive Platform data. Where the Contract Tools support electronic signature, we maintain an audit trail for each Generated Contract, including timestamps, IP addresses, and signatory metadata, to support the integrity and evidentiary value of the executed document. Access to a Generated Contract is restricted to the User who created it and, where applicable, the Contract Counterparty named in it.

3.6 Application Security

We follow secure software development practices, including code review, dependency vulnerability scanning, and security testing prior to deployment of new features, including updates to the Contract Tools and Project Management Tools.

4. Data Minimisation and Segregation

We collect and retain only the Personal Data reasonably necessary to provide the Services, consistent with the data minimisation principle under the NDPA. Where feasible, Personal Data is pseudonymised or aggregated for analytical purposes to reduce identifiability.

5. Business Continuity and Backup

We maintain backup procedures designed to enable recovery of critical systems and data, including Project records and Generated Contracts, in the event of a system failure, and maintain a business continuity and disaster recovery framework intended to minimise disruption and protect data integrity in the event of an incident.

6. Incident Detection and Response

We maintain a security incident response process designed to detect, assess, contain, and remediate security incidents in a timely manner. Where a Personal Data breach occurs that is likely to result in a risk to the rights and freedoms of affected Data Subjects, we will:

  • Promptly investigate and take steps to contain and remediate the incident;
  • Notify the Nigeria Data Protection Commission (NDPC) within the timeframe prescribed under the NDPA;
  • Notify affected Users and, where reasonably identifiable and appropriate, affected Contract Counterparties, without undue delay where the breach is likely to result in a high risk to their rights and freedoms;
  • Document the incident, including its nature, effects, and remedial action taken, in accordance with our internal incident register.

7. User Responsibilities

While we implement robust security measures, security is a shared responsibility. We encourage Users to:

  • Use a strong, unique password for their BPrime SSO credentials and enable multi-factor authentication where available;
  • Avoid sharing Account credentials or one-time passcodes (OTPs) with any third party, including individuals purporting to represent BPrime;
  • Verify that any communication purportedly from BPrime originates from an official bprimeassets.com or projects.bprimeassets.com channel before acting on it;
  • Exercise care when inviting a Contract Counterparty to review or execute a Generated Contract, including verifying the counterparty’s contact details before sending;
  • Promptly report any suspected security incident, unauthorised access, or phishing attempt to legal@bprimeassets.com;
  • Keep their devices and browsers updated with current security patches.

8. International Processing and Sub-Processors

Certain infrastructure and processing activities, including e-signature and payment infrastructure, may be carried out by service providers located outside Nigeria. Any such cross-border processing is conducted in accordance with the safeguards described in Section 7 of our Privacy Policy.

9. Continuous Improvement

We periodically review and update our security controls to reflect evolving threats, technologies, and regulatory requirements, including guidance issued by the NDPC. This Statement will be reviewed at least annually, or sooner where a material change to our security posture or the regulatory environment occurs.

10. Reporting a Vulnerability or Concern

If you believe you have discovered a security vulnerability affecting the Platform, or have any concern regarding the security of your Personal Data or Generated Contracts, please contact us immediately at legal@bprimeassets.com. We ask that you report such matters responsibly and refrain from exploiting, disclosing, or testing any vulnerability beyond what is reasonably necessary to demonstrate its existence.

11. Contact Us

BPrime Assets Limited — Legal & Compliance Department

Email: legal@bprimeassets.com

Platform: projects.bprimeassets.com