BPRIME ASSETS LIMITED

Operator of the BPrime X Platform (x.bprimeassets.com)

Security & Data Protection Statement

BPrime X — a platform of BPrime Assets Limited

Legal EntityBPrime Assets Limited (“BPrime”, “the Company”, “we”, “us”, or “our”)
PlatformBPrime X — x.bprimeassets.com
Corporate Sitebprimeassets.com
JurisdictionFederal Republic of Nigeria
Effective Date6 July 2026
VersionVersion 1.0
Contactlegal@bprimeassets.com

Table of Contents

1. Introduction

This Security & Data Protection Statement (“Statement”) describes the technical, organisational, and procedural measures that BPrime Assets Limited (“BPrime”, “we”, “us”, or “our”) has implemented to protect the confidentiality, integrity, and availability of Personal Data and other information processed through the BPrime X platform (x.bprimeassets.com) (the “Platform”).

This Statement is intended to give Users a transparent overview of our security posture. It supplements, and should be read together with, our Privacy Policy. For security reasons, certain specific technical configurations and control details are not disclosed publicly; this Statement describes our practices at a level appropriate for general assurance without compromising the effectiveness of our controls.

2. Governance and Organisational Measures

2.1 Data Protection Officer

In accordance with the NDPA, BPrime has designated a Data Protection Officer (DPO) responsible for overseeing our data protection compliance programme, including monitoring adherence to this Statement and our Privacy Policy. The DPO may be contacted at legal@bprimeassets.com.

2.2 Policies and Training

We maintain internal information security and data protection policies applicable to all personnel and contractors with access to Platform systems or Personal Data. Personnel undergo periodic training on data protection obligations, security awareness, phishing recognition, and incident reporting procedures.

2.3 Access Governance

Access to systems processing Personal Data is governed by the principle of least privilege — personnel are granted access only to the extent necessary to perform their role. Access rights are reviewed periodically and revoked promptly upon a change of role or termination of engagement.

2.4 Vendor and Processor Oversight

Where we engage third-party service providers, including our Payment Processor (Paystack) and infrastructure providers, to process Personal Data on our behalf, we conduct due diligence on their security practices and require contractual commitments consistent with the NDPA and this Statement, including obligations relating to confidentiality, security, and breach notification.

3. Technical Security Measures

3.1 Encryption

We apply industry-standard encryption to protect data both in transit and at rest, including:

  • Transport Layer Security (TLS) encryption for data transmitted between User devices and the Platform;
  • Encryption of sensitive data at rest within our production databases and backup systems;
  • Secure handling of authentication credentials, which are never stored in plain text.

3.2 Authentication and Access Control

The Platform’s Single Sign-On (SSO) framework is designed with security as a core principle, including:

  • Secure session management with defined session expiry and re-authentication requirements;
  • Support for strong password requirements and, where enabled, multi-factor authentication (MFA);
  • Monitoring of login attempts to detect and respond to suspicious or anomalous access patterns;
  • Rate-limiting and account lock-out mechanisms to mitigate brute-force attacks.

3.3 Network and Infrastructure Security

  • Use of firewalls, network segmentation, and intrusion detection/prevention systems to protect our infrastructure;
  • Regular vulnerability scanning and periodic penetration testing of Platform infrastructure and applications;
  • Hardened server configurations and timely application of security patches;
  • Continuous monitoring and logging of system activity to support security incident detection and forensic investigation where necessary.

3.4 Payment Security

Payment transactions are processed through Paystack Payments Limited, a licensed payment service provider that maintains Payment Card Industry Data Security Standard (PCI DSS) compliance. BPrime does not store full payment card details on its own systems; such data is handled directly by Paystack in accordance with applicable card network security requirements.

3.5 Application Security

We follow secure software development practices, including code review, dependency vulnerability scanning, and security testing prior to the deployment of new features, in order to reduce the risk of vulnerabilities such as injection attacks, cross-site scripting, and other common application security risks.

4. Data Minimisation and Segregation

We collect and retain only the Personal Data reasonably necessary to provide the Services and meet our legal and regulatory obligations, consistent with the data minimisation principle under the NDPA. Where feasible, Personal Data is pseudonymised or aggregated for analytical purposes to reduce identifiability.

5. Business Continuity and Backup

We maintain backup procedures designed to enable recovery of critical systems and data in the event of a system failure, and maintain a business continuity and disaster recovery framework intended to minimise disruption to the Services and protect the integrity of Personal Data in the event of an incident.

6. Incident Detection and Response

We maintain a security incident response process designed to detect, assess, contain, and remediate security incidents in a timely manner. Where a Personal Data breach occurs that is likely to result in a risk to the rights and freedoms of affected Data Subjects, we will:

  • Promptly investigate and take steps to contain and remediate the incident;
  • Notify the Nigeria Data Protection Commission (NDPC) within the timeframe prescribed under the NDPA;
  • Notify affected Users without undue delay where the breach is likely to result in a high risk to their rights and freedoms, together with guidance on protective steps they may take;
  • Document the incident, including its nature, effects, and remedial action taken, in accordance with our internal incident register.

7. User Responsibilities

While we implement robust security measures, security is a shared responsibility. We encourage Users to:

  • Use a strong, unique password for their BPrime SSO credentials and enable multi-factor authentication where available;
  • Avoid sharing Account credentials or one-time passcodes (OTPs) with any third party, including individuals purporting to represent BPrime;
  • Verify that any communication purportedly from BPrime originates from an official bprimeassets.com or x.bprimeassets.com channel before acting on it;
  • Promptly report any suspected security incident, unauthorised access, or phishing attempt to legal@bprimeassets.com;
  • Keep their devices and browsers updated with current security patches.

8. International Processing and Sub-Processors

Certain infrastructure and processing activities may be carried out by service providers located outside Nigeria. Any such cross-border processing is conducted in accordance with the safeguards described in Section 8 of our Privacy Policy, including the use of appropriate contractual protections consistent with the NDPA.

9. Continuous Improvement

We periodically review and update our security controls to reflect evolving threats, technologies, and regulatory requirements, including guidance issued by the NDPC. This Statement will be reviewed at least annually, or sooner where a material change to our security posture or the regulatory environment occurs.

10. Reporting a Vulnerability or Concern

If you believe you have discovered a security vulnerability affecting the Platform, or have any concern regarding the security of your Personal Data, please contact us immediately at legal@bprimeassets.com. We ask that you report such matters responsibly and refrain from exploiting, disclosing, or testing any vulnerability beyond what is reasonably necessary to demonstrate its existence.

11. Contact Us

For questions regarding this Statement or our security practices, please contact:

BPrime Assets Limited — Legal & Compliance Department

Email: legal@bprimeassets.com

Platform: x.bprimeassets.com