kourair-icon

PRIVACY POLICY

Effective Date: April 1, 2026 | Last Updated: April 1, 2026

Introduction

THE DATASEED COMPANY CANADA LIMITED (KOURIAR) - PRIVACY POLICY

This Privacy Policy applies to all services offered by The Dataseed Company Canada Limited (Owners and Developers of the Product ‘Kouriar’), our international money remittance service (Canada to Nigeria). Please read it carefully. By accessing or using any Kouriar service, you acknowledge that you have read and understood this Policy.

1. WHO WE ARE

1.1 Company Information

The Dataseed Company Canada Ltd. (“Kouriar,” “we,” “us,” or “our”) is a federally incorporated Canadian company providing International Money Remittance i.e. enabling individuals in Canada to send funds to recipients in Nigeria (in Naira equivalent from the initiation currency) through its Product known as ‘Kouriar’.

As a Money Services Business (MSB), Kouriar is registered with the Financial Transactions and Reports Analysis Centre of Canada (FINTRAC) and operates in compliance with the Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA).

1.2 Contact Details

Kouriar's registered address is:

3302, Carding Mill Trail, Oakville, Canada, L6M1S1

General contact: help@kouriar.com

2. SCOPE AND APPLICATION OF THIS POLICY

2.1 Applicable Laws

This Privacy Policy is designed to comply with:

  • Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), S.C. 2000, c. 5, and its 10 Fair Information Principles;
  • The Breach of Security Safeguards Regulations, SOR/2018-64 (mandatory breach notification under PIPEDA, in force since November 1, 2018);
  • Nigeria's Data Protection Act, 2023 (NDPA), and the Nigeria Data Protection Commission's General Application and Implementation Directive (GAID), effective September 19, 2025;
  • The Proceeds of Crime (Money Laundering) and Terrorist Financing Act (PCMLTFA) and associated FINTRAC regulations;
  • The Financial Consumer Agency of Canada Act (FCAC Act) and applicable FCAC guidelines on consumer protection in financial services.

Where provincial privacy legislation has been deemed “substantially similar” to PIPEDA (Alberta, British Columbia, and Quebec), we comply with the applicable provincial law with respect to activities occurring entirely within that province. For all interprovincial and international activities, PIPEDA applies.

2.2 Who This Policy Applies To

This Policy applies to:

  • Canadian residents who use Kouriar to send money to Nigeria;
  • Recipients in Nigeria who receive funds through our remittance service;
  • Visitors to our website (www.kouriar.com) and mobile application; and
  • Any individual whose personal information we handle in the course of our commercial activities.

2.3 What Is Not Covered

This Policy does not apply to:

  • Third-party websites, apps, or services linked from our platform. We encourage you to review their privacy policies independently;
  • Anonymized or aggregated information that cannot be used to identify you; or
  • Business contact information used solely for communicating with you in your professional capacity.

3. PERSONAL INFORMATION WE COLLECT

We collect only the personal information that is necessary to provide our services, meet our legal obligations, and manage our business. “Personal information” means any information about an identifiable individual, as defined under PIPEDA.

3.1 Identity and Account Information

  • Full legal name
  • Date of birth
  • Government-issued photo identification (e.g., passport, provincial driver's licence, permanent resident card, or national identity card)
  • Nationality and country of residence
  • Social Insurance Number (SIN), where required by law for tax reporting purposes
  • Photograph or selfie, where required for identity verification

3.2 Contact Information

  • Email address
  • Mobile phone number
  • Residential address (street, city, province, postal code)

3.3 Financial and Income Information

  • Bank account or debit/credit card information used to fund transfers
  • Transaction history and records
  • Source of funds declarations (where required for AML compliance)
  • Beneficiary information: recipient's full name, Nigerian bank account number, bank name, and contact details

Note on banking credentials: Consistent with the guidance of the Office of the Privacy Commissioner of Canada, Kouriar does not collect, request, or store online banking passwords, usernames, or security questions. Income and account verification is conducted through direct document submission only.

3.4 Compliance and Regulatory Information

  • Politically Exposed Person (PEP) and Head of International Organization (HIO) status assessments
  • Sanctions screening data (against Canadian, UN, and other applicable sanctions lists)
  • Records required under PCMLTFA, including large cash transaction reports and suspicious transaction reports, where applicable
  • Beneficial ownership information

3.5 Technical and Usage Information

  • IP address and approximate geographic location
  • Device type, operating system, and browser information
  • Login and session activity logs
  • Cookies and similar tracking technologies (see Section 13)

3.6 Customer Communications

  • Records of customer support interactions (phone, email, in-app chat)
  • Complaints and dispute records
  • Feedback, survey responses, and reviews
  • Records of consent provided or withdrawn

4. HOW WE COLLECT YOUR PERSONAL INFORMATION

4.1 Direct Collection

Directly From You:

  • When you register an account or complete an onboarding process
  • When you submit a money transfer application or request
  • When you upload identity documents or proof of income
  • When you contact our customer support team
  • When you respond to surveys or provide feedback
  • When you grant or withdraw consent for specific uses

4.2 Automated Collection

Automatically Through Our Platform:

  • Through our website and mobile application using cookies, web beacons, and similar technologies (see Section 13)
  • Through server logs and analytics tools that record usage activity

4.3 Third-Party Collection

From Third Parties:

  • Identity verification and know-your-customer (KYC) providers who help us confirm your identity and assess document authenticity
  • Sanctions screening and fraud detection service providers
  • Correspondent banks and payment partners in Nigeria (for remittance beneficiary verification)
  • FINTRAC and other regulatory bodies, where we are required to receive or act on information by law
  • Debt collection agencies, where applicable in loan recovery scenarios

5. PURPOSES FOR WHICH WE USE YOUR PERSONAL INFORMATION

We use your personal information only for the purposes for which it was collected or for purposes consistent with those purposes, or as required or permitted by law.

5.1 Remittance Service Purposes

  • Processing and completing money transfers from Canada to Nigeria;
  • Verifying your identity and the identity of your designated beneficiary;
  • Detecting and preventing fraud, money laundering, and terrorist financing;
  • Conducting sanctions screening as required by PCMLTFA and applicable law;
  • Generating and retaining FINTRAC-required transaction records and reports;
  • Notifying you of the status of your transfers;
  • Managing your account, including password reset and account recovery; and
  • Resolving disputes relating to remittance transactions.

5.2 General Business Purposes

  • Maintaining and improving our platform, products, and services;
  • Conducting internal audits, risk management, and fraud analysis;
  • Complying with all applicable Canadian federal and provincial laws and regulations, and applicable Nigerian law;
  • Fulfilling tax reporting obligations to the Canada Revenue Agency (CRA);
  • Communicating administrative and service-related notices to you;
  • Sending marketing communications, but only with your express opt-in consent, and subject to Canada's Anti-Spam Legislation (CASL); and
  • Defending or asserting legal claims.

5.3 Legal Bases Under PIPEDA

Under PIPEDA, we process your personal information on the basis of:

  • Your express or implied consent (for most data collection and use);
  • Our legal obligations under PCMLTFA, provincial payday lending legislation, the Criminal Code, and other applicable law; and
  • Our legitimate business interests, where they do not override your privacy rights.

5.4 Legal Bases Under Nigeria's NDPA 2023

For personal information relating to recipients of remittances in Nigeria, we process personal data on the basis of:

  • Performance of a contract (completing the remittance transaction);
  • Legal obligations under Nigerian law, including CBN regulations; and
  • Your consent, where required under the NDPA 2023.

6. DISCLOSURE OF YOUR PERSONAL INFORMATION

Kouriar does not sell, rent, or trade your personal information to third parties for their own marketing purposes. We disclose your personal information only in the following circumstances.

6.1 Service Providers and Processors

We engage trusted third-party service providers who process personal information on our behalf under written contracts that require them to maintain confidentiality and data protection standards equivalent to our own. These include:

  • Identity verification and KYC providers
  • Payment processors and banking partners (Canadian and Nigerian)
  • Cloud infrastructure and data hosting providers
  • Customer support and communications platforms
  • Fraud detection, cybersecurity, and sanctions screening services
  • Legal, accounting, and audit professionals

6.2 Nigerian Correspondent Banks and Payment Partners

To complete remittance transactions, we share the minimum necessary recipient information (full name, bank account number, bank name, and where required, contact details) with our Nigerian correspondent banks and payment partners. These entities are subject to the NDPA 2023, Central Bank of Nigeria (CBN) consumer data protection directives, and the contractual data protection obligations we impose.

6.3 Regulatory and Law Enforcement Authorities

We are required to disclose certain personal information to:

  • FINTRAC, in accordance with mandatory reporting obligations under PCMLTFA (including large cash transaction reports, suspicious transaction reports, and terrorist property reports);
  • The Canada Revenue Agency (CRA), for applicable tax reporting obligations;
  • Provincial consumer protection, where required by our licensing obligations (e.g., the Financial Services Regulatory Authority of Ontario, or equivalent in other provinces);
  • The Financial Consumer Agency of Canada (FCAC), where applicable;
  • Law enforcement agencies, courts, or other governmental authorities, when required by a valid court order, subpoena, or applicable law; and
  • The Nigeria Data Protection Commission (NDPC) and other Nigerian regulatory authorities, where required in connection with remittance transactions.

6.4 Business Transfers

In the event of a proposed or completed merger, acquisition, sale of assets, or restructuring involving Kouriar, your personal information may be reviewed by and transferred to the acquiring or successor entity as part of that transaction. Where practicable, we will notify you of such a change prior to its completion, and your personal information will remain subject to this Privacy Policy or a policy offering equivalent protections.

6.5 With Your Consent

We may disclose your personal information to third parties not described above, but only with your express prior consent, which you may withdraw at any time.

6.6 Intra-Group Transfers

Where Kouriar establishes subsidiaries or affiliated entities, personal information may be shared within the Kouriar corporate group for the purposes described in this Policy, subject to equivalent data protection standards.

7. INTERNATIONAL DATA TRANSFERS (CANADA TO NIGERIA)

Kouriar's remittance service necessarily involves the transfer of personal data from Canada to Nigeria. We approach these transfers with care and transparency.

7.1 Transfers from Canada Under PIPEDA

PIPEDA does not prohibit cross-border transfers of personal information but requires that organizations use contractual or other means to provide a comparable level of protection to personal information transferred internationally. When personal information is transferred from Canada to our service providers or partners outside Canada (including in Nigeria), we:

  • Enter into written data processing agreements that impose privacy and security obligations at least equivalent to PIPEDA requirements;
  • Limit transfers to the minimum personal information necessary to complete the relevant transaction or service; and
  • Conduct due diligence on the data protection practices of our international partners before engaging them.

You acknowledge that personal information disclosed to us may be transferred to and processed in Nigeria and potentially other countries, and that applicable laws in those countries may differ from Canadian law.

7.2 Transfers to Nigeria Under the NDPA 2023

Under Section 41 of the NDPA 2023, transfers of personal data outside Nigeria are prohibited by default, subject to certain exceptions. Conversely, as a data controller that transfers personal data into Nigeria (as a destination for remittance recipients' data), we ensure that our Nigerian partners who receive this data comply with the NDPA 2023.

Where data originates in Nigeria (for example, recipient data initially provided by Nigerian residents or financial institutions), any further transfer outside Nigeria is handled through:

  • Contractual clauses that provide an adequate level of protection equivalent to the NDPA 2023, consistent with Section 41(1) of the Act; and
  • Ensuring recipients are bound by binding corporate rules, codes of conduct, or certification mechanisms approved by the Nigeria Data Protection Commission (NDPC), where applicable.

Canada has a recognized data protection framework. We assess the adequacy of protection using criteria consistent with Section 42 of the NDPA 2023.

7.3 Beneficiary Data

When you initiate a transfer, we share the minimum required information about your beneficiary with Nigerian banking partners. Beneficiaries in Nigeria have privacy rights under the NDPA 2023 and may contact us to exercise those rights as set out in Section 9 of this Policy.

8. DATA RETENTION

Retention Schedule

We retain personal information for as long as necessary to fulfill the purposes described in this Policy, or as required by applicable law. The following minimum retention periods apply:

Record TypeMinimum Retention Period
AML/CTF records (PCMLTFA compliance)5 years from date of transaction or report
KYC and identity verification records (both services)5 years from the date the business relationship ends or last transaction
Records supporting FINTRAC reports5 years (PCMLTFA)
Customer account dataDuration of account + 5 years following closure
Security and access logs2 years
Marketing consent recordsUntil consent withdrawn + 1 year
Customer support and complaint records5 years
Breach and incident recordsMinimum 24 months (PIPEDA Breach Regulations)

Where personal information is no longer required and is not subject to a legal retention obligation, we will destroy, delete, or anonymize it in a secure manner.

9. YOUR PRIVACY RIGHTS

9.1 Rights Under PIPEDA (Canadian Users)

  • Right of Access: You have the right to request access to the personal information we hold about you and to receive information about how it is being used and disclosed. We will respond within 30 calendar days, or advise you of any extension where permitted by law.
  • Right to Correction: If you believe that personal information we hold about you is inaccurate or incomplete, you may request that we correct it. Where we disagree with your correction request, we will note your disagreement in your file.
  • Right to Withdraw Consent: Where we rely on your consent to process your personal information, you may withdraw that consent at any time, subject to legal or contractual limitations. Withdrawal of consent may affect our ability to provide you with certain services.
  • Right to Make a Complaint: If you believe we have not complied with PIPEDA, you may file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at www.priv.gc.ca or 1-800-282-1376.

9.2 Rights Under the NDPA 2023 (Nigerian Recipients)

Individuals whose personal data is processed under Nigerian law have the following rights under the NDPA 2023:

  • Right of Access: To obtain confirmation of whether we process your personal data, and to receive a copy of that data.
  • Right to Rectification: To have inaccurate or incomplete personal data corrected without undue delay.
  • Right to Erasure: To request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, or where you withdraw consent, subject to our legal retention obligations.
  • Right to Object: To object to the processing of your personal data in certain circumstances, including processing based on legitimate interests.
  • Right to Data Portability: To receive your personal data in a structured, commonly used, and machine-readable format, and to request that we transmit that data to another controller where technically feasible.
  • Right to Restriction: To request that we limit the processing of your personal data in certain circumstances.
  • Right against Solely Automated Decision-Making: Not to be subject to a decision that produces legal or similarly significant effects on you, where that decision is based solely on automated processing (including profiling), without human review.
  • Right to Make a Complaint: To lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.

9.3 How to Exercise Your Rights

To exercise any of the rights described in this Section, please contact our Privacy Officer at:

Email: help@kouriar.com

We will respond to all rights requests within 30 calendar days. Where a request is complex or numerous, we may extend this period by up to an additional 30 days and will notify you accordingly. We will not charge a fee for access requests unless the request is manifestly unfounded or excessive.

We may require you to verify your identity before responding to a rights request, to protect your personal information from unauthorized access.

10. CONSENT

10.1 Obtaining Consent

Under PIPEDA, we obtain your consent before or at the time we collect personal information, except where the law permits or requires us to collect it without consent. Consent may be:

  • Express: provided explicitly in writing or verbally (required for sensitive information such as credit bureau checks, marketing communications, and certain disclosures to third parties); or
  • Implied: reasonably inferred from your conduct (for example, providing your bank account details for the purpose of receiving a loan disbursement constitutes implied consent to use those details for that purpose).

10.2 Consent for Marketing

We will only send you promotional or marketing communications with your prior express opt-in consent, in compliance with Canada's Anti-Spam Legislation (CASL), S.C. 2010, c. 23. Every marketing communication we send will include a clear and easy mechanism for you to unsubscribe. Unsubscribing from marketing communications will not affect your receipt of transactional or service-related communications.

10.3 Withdrawing Consent

You may withdraw your consent to non-essential uses of your personal information at any time by contacting us at help@kouriar.com or by using in-app preference settings. Please note that withdrawing consent may limit or prevent us from continuing to provide certain services to you.

11. DATA SECURITY

Security Framework

Kouriar implements appropriate technical and organizational safeguards to protect your personal information against unauthorized access, loss, alteration, disclosure, or destruction. Our measures include:

  • AES-256 encryption for personal data at rest;
  • TLS 1.2 or higher encryption for all data transmitted over public networks;
  • Multi-factor authentication (MFA) for all user accounts and internal systems;
  • Role-based access controls, limiting access to personal information to personnel with a legitimate business need;
  • Regular security audits, penetration testing, and vulnerability assessments;
  • Employee training on privacy and data security obligations;
  • Formal information security policies and incident response procedures;
  • Contractual security obligations imposed on all third-party service providers; and
  • Physical access controls for any premises where personal information is processed.

Despite these measures, no system is completely secure. If you believe your Kouriar account has been compromised, or if you become aware of any unauthorized use of your information, please contact us immediately at: help@kouriar.com

12. DATA BREACH NOTIFICATION

In the event of a breach of our security safeguards involving your personal information, we will act in accordance with our legal obligations under PIPEDA and, where applicable, the NDPA 2023.

12.1 Under PIPEDA (Canadian Users)

Where a breach creates a “real risk of significant harm” to individuals (which includes financial loss, identity theft, damage to reputation, humiliation, physical harm, or loss of employment), we will:

  • Report the breach to the Office of the Privacy Commissioner of Canada (OPC) as soon as feasible after determining that the breach has occurred;
  • Notify affected individuals directly and as soon as feasible, with sufficient information to allow them to take steps to protect themselves; and
  • Notify any other organizations that may be able to reduce the risk of harm to affected individuals.

We maintain records of all security breaches for a minimum of 24 months, regardless of whether the breach triggers mandatory notification, in compliance with the Breach of Security Safeguards Regulations.

12.2 Under the NDPA 2023 (Nigerian Data Subjects)

Where a breach affects personal data relating to Nigerian data subjects, we will notify the Nigeria Data Protection Commission (NDPC) and affected individuals as required by the NDPA 2023 and applicable NDPC directives.

12.3 What We Will Tell You

In a breach notification, we will include:

  • A description of what happened and the type of personal information involved;
  • The steps we have taken or are taking to address the breach;
  • Steps you can take to protect yourself; and
  • Contact information for further inquiry or to make a complaint.

13. COOKIES AND TRACKING TECHNOLOGIES

Our website and mobile application use cookies and similar technologies to support core functionality, enhance your experience, and analyze usage patterns.

13.1 Types of Cookies We Use

  • Strictly Necessary Cookies: These are essential for the platform to function securely, including session management, authentication, and fraud prevention. These cookies cannot be disabled.
  • Analytics Cookies: These help us understand how users navigate and use our platform, which pages are visited, and where issues arise. These cookies collect aggregated, non-identifying data. They are enabled only with your consent.
  • Functional Cookies: These remember your preferences and settings to improve your experience (e.g., language preferences). They are enabled only with your consent.
  • Marketing and Communications Cookies: These support our ability to deliver relevant communications and measure the effectiveness of campaigns. They are enabled only with your express opt-in consent.

13.2 Managing Cookie Preferences

You may manage your cookie preferences through our Cookie Preference Centre, accessible on our website. You may also adjust your browser settings to block or delete cookies. Note that disabling strictly necessary cookies may impair your ability to use our services.

Opting out of analytics or marketing cookies will not affect your ability to use Kouriar's core remittance or payday loan services.

14. ANTI-MONEY LAUNDERING AND COUNTER-TERRORIST FINANCING (AML/CTF)

Compliance Mandate

Kouriar is a Money Services Business regulated by FINTRAC under the PCMLTFA. Our AML/CTF obligations require us to:

  • Verify the identity of clients before providing certain services;
  • Keep records of transactions and identification documents for a minimum of five years;
  • Report certain transactions to FINTRAC, including Large Cash Transactions, Electronic Funds Transfer Reports, Suspicious Transaction Reports, and Terrorist Property Reports, where required by law;
  • Screen clients and transactions against applicable sanctions lists; and
  • Assess and manage the risk of money laundering and terrorist financing associated with our business activities.

These activities are conducted pursuant to our legal obligations and are not subject to your consent. Where we are required by law to make a report to FINTRAC or another authority, we may not be able to disclose to you that such a report has been made, as tipping off a subject of a suspicious transaction report may itself be an offence under Canadian law.

15. CHILDREN'S PRIVACY

Age Restrictions

Kouriar's services are not directed to or intended for individuals under the age of 18. We do not knowingly collect personal information from minors. You must be at least 18 years of age, and meet applicable provincial minimum age requirements for payday lending, to use our services.

If you believe that we have inadvertently collected personal information from a person under 18, please notify us immediately at help@kouriar.com and we will take prompt steps to delete that information, except to the extent we are required to retain it by law.

16. CHANGES TO THIS PRIVACY POLICY

Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, regulatory developments, or privacy best practices. When we make material changes, we will:

  • Post the updated Policy on our website at www.kouriar.ca with a revised Effective Date prominently displayed;
  • Notify registered users via email or in-app notification; and
  • Where required by applicable law (including PIPEDA or the NDPA 2023), seek your renewed consent before applying material changes to our processing of your personal information.

Your continued use of Kouriar's services after the effective date of any update constitutes your acknowledgment of the revised Policy. If you do not agree with the changes, you should discontinue use of our services and contact us to close your account.

We encourage you to review this Policy periodically. Prior versions of this Policy are available on request.

17. GOVERNING LAW AND JURISDICTION

Legal Framework

This Privacy Policy is governed by and construed in accordance with the laws of Canada, including PIPEDA and applicable provincial privacy legislation.

To the extent that Nigerian law applies to the processing of personal data of Nigerian residents or the transfer of personal data to Nigeria, the Nigeria Data Protection Act 2023 and applicable NDPC directives shall govern those processing activities.

Nothing in this Policy limits Kouriar's obligations under applicable federal or provincial law, including PCMLTFA and provincial payday lending legislation.

18. HOW TO CONTACT US

Contact Framework

For all privacy-related inquiries, rights requests, complaints, or consent withdrawals, please contact:

  • Email: help@kouriar.com
  • General: help@kouriar.com
  • Security: help@kouriar.com (for suspected account compromise or data breaches)
  • Website: www.kouriar.com

We will acknowledge all privacy inquiries within five (5) business days and aim to resolve them fully within thirty (30) calendar days.

External Regulators

Office of the Privacy Commissioner of Canada (OPC)

Website: www.priv.gc.ca | Phone: 1-800-282-1376

Address: 30 Victoria Street, Gatineau, Quebec K1A 1H3

Nigeria Data Protection Commission (NDPC)

Website: ndpc.gov.ng

Financial Consumer Agency of Canada (FCAC)

Website: www.canada.ca/en/financial-consumer-agency | Phone: 1-866-461-3222

FINTRAC

Website: www.fintrac-canafe.gc.ca