Data Protection

Our commitments under the Nigeria Data Protection Act and international standards.

Last updated 6 October 2026

1. Our framework

TravelBuxx processes personal data in line with the Nigeria Data Protection Act 2023 (NDPA), and follows GDPR principles where applicants or agencies are in other jurisdictions.

2. Principles

Lawful, fair and transparent processing; collecting only what is necessary; accuracy; limited retention; integrity and confidentiality; and accountability.

3. Tenant isolation

Every case, document, message and payment is scoped to a single agency. TravelBuxx platform operators monitor service health without reading client files.

4. Security measures

Encryption in transit, private document storage, role-based access, two-factor authentication, automatic sign-out after inactivity, and an audit trail of every status, document and message event.

5. International transfers

Where data is transferred outside Nigeria (for example to embassies or hosting providers), we rely on appropriate safeguards as required by the NDPA.

6. Breach response

We will notify affected agencies, and where required the Nigeria Data Protection Commission, without undue delay if a personal data breach occurs.

7. Data subject requests

Applicants can export their data directly from their profile. For other requests contact your agency or legal@thetravelbuxx.com.