Data Protection
Our commitments under the Nigeria Data Protection Act and international standards.
Last updated 6 October 2026
1. Our framework
TravelBuxx processes personal data in line with the Nigeria Data Protection Act 2023 (NDPA), and follows GDPR principles where applicants or agencies are in other jurisdictions.
2. Principles
Lawful, fair and transparent processing; collecting only what is necessary; accuracy; limited retention; integrity and confidentiality; and accountability.
3. Tenant isolation
Every case, document, message and payment is scoped to a single agency. TravelBuxx platform operators monitor service health without reading client files.
4. Security measures
Encryption in transit, private document storage, role-based access, two-factor authentication, automatic sign-out after inactivity, and an audit trail of every status, document and message event.
5. International transfers
Where data is transferred outside Nigeria (for example to embassies or hosting providers), we rely on appropriate safeguards as required by the NDPA.
6. Breach response
We will notify affected agencies, and where required the Nigeria Data Protection Commission, without undue delay if a personal data breach occurs.
7. Data subject requests
Applicants can export their data directly from their profile. For other requests contact your agency or legal@thetravelbuxx.com.
