Effective Date: June 1, 2026
Version: 2.0
Last Reviewed: May 18, 2026.

A. INTRODUCTION

SIFAX Group is a diversified business group with interests in maritime, aviation, logistics, oil and gas, financial services and hospitality.

In the course of our businesses, we collect and process personal data relating to our customers, employees, passengers, guests, suppliers, contractors, business partners, visitors, beneficiaries and other individuals who interact with us.

This Privacy Notice explains how SIFAX Group and the relevant companies within the Group collect, use, disclose, retain and protect personal data.

Because SIFAX Group operates through separate companies and businesses, the company responsible for providing a particular service may be the data controller for the personal data processed in connection with that service. The applicable company and its role depend on the nature of the relationship and the processing activity.

Some businesses may also provide additional privacy information where the nature of their services, regulatory requirements or processing activities requires more detail.

This Notice applies to personal data processed through our websites, digital platforms, business operations, premises, services and other channels through which we interact with individuals.

B. PERSONAL DATA WE COLLECT

The personal data we collect depends on the nature of our relationship with you and the service or activity
involved.

This may include:

a. name, address, telephone number, email address and other contact details;
b. identification and verification information;
c. employment, professional and business information;
d. customer, supplier and contractor information;
e. financial, payment, account and transaction information;
f. KYC and KYB information;
g. travel, passenger, booking and reservation information;
h. hotel and hospitality information;
i. vehicle, driver, visitor and access-control information;
j. photographs, CCTV images, video and other security information;
k. website, device, log, IP address and cookie information;
l. health or medical information where there is a lawful and specific reason to process it;
m. biometric information where lawfully collected and used;
n. information relating to beneficiaries of approved community, social-impact or health programmes;
o. information contained in complaints, investigations or whistleblowing reports; and
p. other information reasonably required for a lawful and identified business, contractual or regulatory purpose.

We collect personal data that is relevant to the purpose for which it is required and do not seek to collect
information that is unnecessary for that purpose.

C. HOW WE COLLECT PERSONAL DATA

We may collect personal data directly from you or, where permitted by law, from other persons or organisations.

Personal data may be collected when you:

a. visit or use our websites, applications or digital platforms;
b. make an enquiry, reservation, booking or application;
c. purchase or use our products or services;
d. enter into a contractual or business relationship with us;
e. apply for employment or provide services to a SIFAX company;
f. visit or access our premises;
g. participate in a customer, supplier, community or health programme;
h. communicate with us by email, telephone, social media or other channels;
i. submit a complaint, request or whistleblowing report; or
j. interact with systems and service providers used in connection with our operations.

Where personal data is obtained from another organisation, we expect the information to have been collected and disclosed on a lawful basis.

D. PURPOSES FOR WHICH WE USE PERSONAL DATA

We process personal data for legitimate business, operational, contractual and regulatory purposes, including providing our services, managing business relationships, processing transactions, administering employment and recruitment, meeting legal and regulatory obligations, maintaining security, managing risks, resolving complaints and improving our services. Personal data is processed only for identified and lawful purposes and is not used in ways incompatible with those purposes.

We do not use personal data for an unrelated purpose without a lawful basis for doing so.

E. LAWFUL BASIS FOR PROCESSING

We process personal data only where a lawful basis exists under applicable data-protection law.

Depending on the circumstances, the lawful basis may be:

a. your consent;
b. performance of a contract or steps taken at your request before entering into a contract;
c. compliance with a legal or regulatory obligation;
d. protection of vital interests;
e. performance of a task carried out in the public interest or under applicable law; or
f. our legitimate interests, where permitted by law and where those interests do not override your rights and freedoms.

Where consent is required, we obtain it in a clear and appropriate manner. Consent may be withdrawn where consent is the lawful basis for the processing.

Withdrawal of consent does not affect processing that was lawfully carried out before the withdrawal.

F. SENSITIVE PERSONAL DATA

Certain personal data requires additional protection because of the nature of the information and the potential harm that could result from its misuse or unauthorised disclosure.

This may include health information, medical information, biometric information used for identification and other categories recognised as sensitive under applicable law.

Where we process such information, access is restricted to authorised persons with a legitimate need to use it.

The relevant SIFAX business applies appropriate measures relating to collection, access, use, disclosure, security, retention and disposal.

Medical fitness information, health information relating to beneficiaries and qualifying biometric information are not used for unrelated purposes merely because the information is available to us.

Where the nature or risk of the processing requires it, appropriate privacy and risk assessments are undertaken before or during the processing.

G. AVIATION, FINANCIAL SERVICES, MARITIME, LOGISTICS AND HOSPITALITY

The nature of personal data processing differs across our businesses.

Aviation

Aviation-related businesses may process passenger, employee, contractor, identification, access-control, travel and, where lawfully required, medical fitness information.

Medical or health information is handled on a restricted-access basis and used only for a defined and lawful purpose.

Financial Services

Financial-services businesses may process identification, KYC/KYB, account, payment, transaction, risk, compliance and regulatory information.

This information may be used for customer onboarding, regulatory compliance, fraud prevention, transaction monitoring, risk management, and related lawful purposes.

Where a KYC process involves biometric or other information that qualifies for enhanced protection, the relevant safeguards for such information apply.

Maritime and Logistics
Our maritime and logistics operations may involve personal data relating to customers, shippers, consignees, drivers, vessel personnel, contractors, visitors and other persons involved in cargo handling, transportation and related services.

This may include identification, contact, vehicle, access-control, operational, and security information.

Hospitality

Our hospitality businesses may process guest identity, contact, reservation, accommodation, payment, preference, loyalty, security and service information.

Where a hotel uses a global reservation, loyalty or technology platform, personal data may also be processed by the relevant platform provider or other participating organisations under the applicable contractual and privacy arrangements.

Community and Health Programmes

Where a SIFAX company or Group-supported foundation participates in a health, insurance or community programme, personal data is collected and used for the purposes of administering the programme and supporting its stated objectives.

Health information received or generated in connection with such programmes is handled in accordance with the additional safeguards applicable to sensitive personal data.

H. SHARING OF PERSONAL DATA
Personal data may be shared with relevant SIFAX Group companies, regulators, professional advisers, service providers, business partners and other parties where necessary for legitimate business, contractual or legal purposes. Where another organisation processes personal data on our behalf, appropriate contractual, confidentiality, security and data-protection requirements apply. Information may also be disclosed where required by law, regulatory authority or lawful process.

I. SIFAX GROUP COMPANIES AND DATA CONTROLLER RESPONSIBILITY

SIFAX Group comprises separate companies and businesses with different operational responsibilities.

The SIFAX company providing a particular product or service may therefore act as the data controller for the personal data processed in connection with that activity.

A SIFAX company may also process personal data on behalf of another Group company. In that situation, the applicable responsibilities are determined by the actual processing arrangement.

An external service provider may act as a data processor where it processes personal data on behalf of a SIFAX company.

Another organisation may act as an independent controller where it determines its own purposes and means of processing.

In some circumstances, two or more organisations may jointly determine the purposes and means of processing.

The relationship between the parties is determined by the actual processing activity and not simply by corporate ownership or the use of the SIFAX name.

Where appropriate, the relevant parties enter into data-processing, data-sharing or other contractual arrangements setting out their respective responsibilities.

J. DATA PROCESSORS

SIFAX companies may engage third-party service providers to process personal data on their behalf. Such processors are selected and managed in accordance with applicable data-protection requirements and are subject to appropriate contractual obligations covering confidentiality, security, processing instructions, data retention, incident management and other relevant compliance requirements. Where appropriate, processor performance and compliance are reviewed throughout the engagement.

K. INTERNATIONAL DATA TRANSFERS

Some of our businesses, systems, service providers and business partners operate internationally.

Personal data may therefore be accessed, hosted, transferred or otherwise processed outside Nigeria.

Where this occurs, the relevant SIFAX business applies a lawful transfer mechanism recognised under applicable Nigerian data-protection law.

Depending on the circumstances, this may include an adequacy decision, an approved cross-border datatransfer instrument or another lawful mechanism available under the Nigeria Data Protection Act and applicable regulatory requirements.

International transfers are assessed according to the nature and risk of the processing, and appropriate contractual, technical and organisational safeguards are applied.

Where an international service provider is involved, its contractual and privacy arrangements are reviewed to establish the applicable responsibilities and safeguards.

L. DATA SECURITY

We maintain appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, loss, misuse or destruction. These measures include access controls, confidentiality requirements, information-security controls, secure systems and other safeguards appropriate to the nature and risk of the processing. Access to personal data is restricted to authorised persons with a legitimate business need.

M. DATA RETENTION

We retain personal data for as long as reasonably necessary for the purpose for which it was collected or for other legitimate legal, regulatory, contractual or business requirements.

Retention periods differ according to the type of information, the purpose of processing and the requirements applicable to the relevant SIFAX business.

Information that is no longer required is securely deleted, destroyed, anonymised or otherwise disposed of in accordance with applicable retention requirements.

N. DATA SUBJECT RIGHTS

Data subjects have rights available under applicable data-protection law, including the right to request access to their personal data, correction of inaccurate information, restriction or objection to certain processing, deletion where applicable, data portability where applicable, and withdrawal of consent where processing is based on consent. Requests may be submitted through the Group’s designated data protection contact, subject to applicable legal requirements and necessary verification.

These versions remove the more elaborate explanatory language while retaining the legal, operational and control substance needed for a public-facing Group Privacy Notice.

O. EXERCISING YOUR DATA PROTECTION RIGHTS

Requests concerning your personal data should be directed to the Data Protection Officer using the contact details provided in this Notice.

We may request sufficient information to verify your identity before responding to a request. This is intended to protect your personal data from being disclosed to someone who is not authorised to receive it.

Requests are handled within the applicable statutory and regulatory timelines.

Where a request cannot be fully granted, we will provide an explanation to the extent permitted by law.

P. WHISTLEBLOWING AND CONFIDENTIAL REPORTING

Information submitted through SIFAX whistleblowing channels is treated as confidential and is handled on a restricted-access basis.

Access is limited to persons authorised to receive, assess, investigate or otherwise lawfully handle the report.

The identity of a whistleblower is not unnecessarily disclosed.

Confidentiality does not amount to an absolute guarantee of anonymity. Information may be disclosed where required by law, regulatory obligation, court order or where disclosure is necessary for the proper investigation or protection of persons.

Whistleblowing information is retained only for as long as reasonably required for the investigation or other legitimate legal, regulatory or governance purpose.

Q. CHILDREN’S PERSONAL DATA

Our services are generally intended for adults and business users.

Where a SIFAX business processes personal data relating to a child, appropriate safeguards are applied in accordance with applicable law, including any consent or parental or guardian requirements that may apply.

R. COOKIES AND SIMILAR TECHNOLOGIES
Our websites and digital platforms may use cookies and similar technologies.

Some cookies are necessary for the operation, security, and basic functionality of the website. Other cookies may be used for analytics, preferences, performance, or related purposes.

Where consent is required, non-essential cookies are used in accordance with the applicable consent mechanism.

Further information about the cookies used on a particular SIFAX website and the choices available to users is provided in the relevant Cookie Policy.

S. DIRECT MARKETING

Where we send marketing communications, we do so in accordance with applicable law.

Where consent is required, the appropriate consent is obtained before sending the communication.

You may opt out of marketing communications by using the unsubscribe facility provided in the communication or by contacting us through the details provided in this Notice.

T. AUTOMATED DECISION-MAKING

Some of our businesses may use automated tools to support activities such as screening, verification, fraud detection, risk assessment or other business processes.

Where a decision is made solely through automated processing and produces legal or similarly significant effects on an individual, the applicable safeguards under data-protection law will apply.

Where required, individuals will receive appropriate information about the processing and the rights available to them.

U. COMPLAINTS AND PRIVACY CONCERNS

If you have a concern about how your personal data has been handled, we encourage you to contact the Data Protection Officer first so that the matter can be reviewed and addressed.

Privacy complaints are handled with the relevant SIFAX business or function responsible for the processing.

Nothing in this Notice prevents a data subject from exercising the right to lodge a complaint with the Nigeria Data Protection Commission or another competent authority where applicable.

V. DATA PROTECTION OFFICER

The SIFAX Group Data Protection Officer is responsible for coordinating data protection and privacy matters across the Group and may liaise with the relevant SIFAX company or business where a request concerns a specific processing activity.

For privacy enquiries, data-subject requests and other data-protection concerns, please contact:

Data Protection Officer
SIFAX Group
Email: babatundeawo@sifaxgroup.com
Telephone: +234 706 340 3739

W. DATA PROTECTION COMPLIANCE

SIFAX Group maintains data-protection governance arrangements designed to protect personal data and support compliance with applicable Nigerian data-protection requirements.

These arrangements cover, as applicable, personal-data inventories, records of processing activities, privacy reviews, contractual controls, data-processing agreements, Data Protection Impact Assessments, security measures, retention requirements, staff wareness, incident management and periodic compliance reviews.

Where registration, audit filing or other regulatory requirements apply to a SIFAX entity, the relevant entity maintains the applicable registration and compliance records.

X. UPDATES TO THIS PRIVACY NOTICE

Our businesses, services, systems and use of personal data may change from time to time.

We may update this Privacy Notice to reflect changes in our operations, processing activities, applicable law, regulatory requirements or privacy practices.

Where a change is material, reasonable steps will be taken to bring the change to your attention.

The current version of this Privacy Notice will be made available through SIFAX website

Effective Date: June 1, 2026
Version: 2.0
Last Reviewed: May 18, 2026