GDPR
Last updated: 27 July 2026
Obana.Africa is operated from Nigeria by ICON Tech & Ecom Services Ltd and is governed primarily by the Nigeria Data Protection Act 2023. Where we offer goods or services to people in the European Economic Area or the United Kingdom, or monitor their behaviour there, the EU General Data Protection Regulation and the UK GDPR also apply. This notice explains how we meet them.
Read it alongside our Privacy Policy, our NDPA compliance statement and our Cookie Policy.
When the GDPR applies to you
The GDPR applies to our processing of your personal data if you are in the EEA or the UK and you:
- submit a contact enquiry, quote request or shipment booking to us;
- subscribe to our newsletter;
- apply to sell, supply or partner with us through one of our platforms; or
- are named on a shipment we arrange — as a sender or receiver — where that shipment touches the EEA or UK.
Where the GDPR and the NDPA both apply, we meet the higher standard rather than treating them as alternatives.
Our role: controller and processor
For data collected through obana.africa we are the controller — we decide why and how it is processed. Where we handle personal data on the documented instructions of a vendor, supplier or partner, we act as a processor for them under a written agreement meeting Article 28.
Legal bases (Article 6)
- Article 6(1)(b) — contract: quoting, sourcing, arranging shipment, invoicing and supporting an order.
- Article 6(1)(a) — consent: newsletters and marketing to people who are not existing business contacts. Withdrawable at any time.
- Article 6(1)(f) — legitimate interests: securing our platform, preventing fraud, maintaining business records, and B2B relationship management. We balance these against your rights and can share our assessment on request.
- Article 6(1)(c) — legal obligation: tax, customs, export control and accounting requirements.
We do not process special category data (Article 9) through this website, and we carry out no automated decision-making producing legal or similarly significant effects (Article 22).
Your rights (Articles 15–22)
- Access (Art. 15) — confirmation of whether we process your data, and a copy of it.
- Rectification (Art. 16) — correction of inaccurate or incomplete data.
- Erasure (Art. 17) — deletion where we no longer have a lawful basis to keep it.
- Restriction (Art. 18) — limiting processing while accuracy or an objection is resolved.
- Portability (Art. 20) — data you gave us, in a structured, commonly used, machine-readable format, where processing is based on consent or contract and is automated.
- Objection (Art. 21) — to processing based on legitimate interests, and an absolute right to object to direct marketing.
- Withdraw consent (Art. 7(3)) — at any time, without affecting prior processing.
Send requests to contact@obana.africa with “GDPR request” in the subject line. We respond within one month, extendable by up to two further months for complex requests — we will tell you within the first month if we need that extension. Requests are free unless manifestly unfounded or excessive.
International transfers (Chapter V)
Personal data you send us is processed in Nigeria and in the countries where our service providers and supply chain partners operate. Nigeria is not currently the subject of an EU or UK adequacy decision.
Where we receive personal data from the EEA or UK, we rely on appropriate safeguards under Article 46 — principally the Standard Contractual Clauses (with the UK Addendum or IDTA where relevant) — supported by a transfer risk assessment and supplementary measures such as encryption in transit and access control. In limited cases we rely on the Article 49 derogation for transfers necessary to perform a contract with you.
You can request a copy of the safeguards applying to a specific transfer from contact@obana.africa.
Processors and sub-processors (Article 28)
We engage processors to run our services, including Zoho (CRM, business email and campaigns), Google (Sheets, reCAPTCHA), Cloudinary (file and image storage) and our hosting provider. Each is bound by a written agreement requiring them to:
- process only on our documented instructions;
- ensure staff with access are under a duty of confidentiality;
- implement Article 32 security measures appropriate to the risk;
- obtain our authorisation before appointing a sub-processor, and flow these terms down;
- assist with data subject requests, breach notification and impact assessments; and
- delete or return personal data at the end of the engagement, subject to legal retention.
Retention and minimisation
We keep personal data only as long as the purpose requires it. Enquiries and quotes that do not convert are typically kept for up to 24 months; transaction, customs and accounting records are kept for the period required by law. The detail is set out in our Privacy Policy.
Security and breach notification
We apply technical and organisational measures under Article 32, including encryption in transit, role-based access control and bot protection on public forms. Where a personal data breach is likely to result in a risk to your rights and freedoms, we notify the competent supervisory authority within 72 hours of becoming aware of it (Article 33), and notify affected individuals without undue delay where the risk is high (Article 34).
EU/UK representative and Data Protection Officer
Where Article 27 requires us to designate a representative in the EU or UK, details are available on request from contact@obana.africa. Until then, please direct all data protection enquiries to our Data Protection Officer below.
Data Protection Officer — contact@obana.africa, ICON Tech & Ecom Services Ltd, 77 Opebi Road, Ikeja, Lagos, Nigeria.
Complaints
Please raise any concern with us first at contact@obana.africa. You also have the right to lodge a complaint with the supervisory authority in your country of residence, place of work or the place of the alleged infringement — in the UK, the Information Commissioner’s Office — or with the Nigeria Data Protection Commission.