Privacy

Privacy Policy

Last updated: March 1, 2025This policy explains how TaxWise collects, uses, and protects your data.

1. Information We Collect

We collect information to provide and improve the TaxWise service:

Account Information: Full name, email address, phone number, and password when you create an account.

Tax Profile Data: Employment status, income sources, salary range, TIN, state of residence, and employer details you provide during onboarding.

Financial Data: Bank statements you upload (CSV, Excel, or PDF files), transaction data extracted from those statements, and AI-generated classifications.

Usage Data: How you interact with the app, feature usage, session duration, and device information for analytics and improvement purposes.

2. How We Use Your Data

Your data is used exclusively to provide the TaxWise service:

  • Parse and extract transactions from your bank statements
  • Classify transactions using AI for tax categorization
  • Calculate your tax liability based on Nigerian PITA regulations
  • Generate tax filing exports (Form A Annual Returns)
  • Provide AI-powered tax guidance through the assistant
  • Send important account and filing notifications
  • Improve our classification accuracy and service quality

We never use your financial data for advertising, marketing to third parties, or any purpose unrelated to your tax filing.

3. Data Storage & Security

We take the security of your financial data extremely seriously:

  • AES-256 Encryption: All data is encrypted at rest and in transit using industry-standard AES-256 encryption
  • Secure Infrastructure: Our servers are hosted on SOC 2 compliant cloud infrastructure with automatic backups and DDoS protection
  • Access Controls: Strict role-based access controls ensure only authorized systems process your data
  • Statement Processing: Bank statements are processed in isolated, encrypted environments and raw files are not permanently stored after extraction
  • Password Security: Passwords are hashed using bcrypt and never stored in plain text
  • Regular Audits: We conduct regular security audits and penetration testing

4. Third-Party Sharing

We do not sell, rent, or trade your personal or financial data. We only share data with:

  • AI Processing Partners: OpenAI (GPT-4o) processes transaction descriptions for classification. Only transaction narrations are sent — never account numbers, balances, or personal identifiers.
  • Payment Processors: Paystack/Flutterwave process subscription payments. We never store your card details.
  • Analytics: Anonymous, aggregated usage data for service improvement.
  • Legal Requirements: We may disclose data if required by Nigerian law or valid legal process.

5. Your Rights

Under the Nigeria Data Protection Regulation (NDPR), you have the right to:

  • Access: Request a copy of all personal data we hold about you
  • Rectification: Correct inaccurate or incomplete personal data
  • Deletion: Request permanent deletion of your account and all associated data
  • Portability: Export your data in a machine-readable format
  • Objection: Object to processing of your data for specific purposes
  • Withdraw Consent: Withdraw consent for data processing at any time

To exercise any of these rights, contact us at privacy@taxwise.ng. We will respond within 30 days.

6. Cookies & Analytics

The TaxWise web application uses minimal cookies:

  • Essential Cookies: Required for authentication and session management. These cannot be disabled.
  • Analytics Cookies: We use privacy-focused analytics (Plausible) that do not use cookies or collect personal data. We track aggregate page views and feature usage only.

The TaxWise mobile app does not use cookies. We use anonymous telemetry to understand feature adoption and improve the product.

7. Data Retention & Deletion

We retain your data only as long as necessary to provide the Service:

  • Active Accounts: Data is retained while your account is active
  • Deleted Accounts: All personal data is permanently deleted within 30 days of account deletion
  • Bank Statements: Raw uploaded files are deleted after transaction extraction is complete
  • Transaction Data: Retained until you delete the filing or your account
  • Backups: Encrypted backups are retained for 90 days for disaster recovery, then purged

You can delete individual filings, statements, or your entire account at any time through the app settings.

Questions about this policy?

Contact us at privacy@taxwise.ng or write to TaxWise Technologies Ltd., Lagos, Nigeria.