Cool Microfinance Bank Limited is a fully licensed microfinance institution operating under the regulatory framework of the Central Bank of Nigeria. We are committed to delivering innovative and customer-centric banking solutions to a diverse client base, including individuals, small and medium enterprises (SMEs), and non-governmental organizations.
Our banking services are designed to meet the evolving needs of our customers, providing seamless access through our physical head office and advanced digital platforms. These platforms include secure internet banking and a user-friendly mobile application, enabling customers to perform transactions conveniently from anywhere. Whether through in-person interactions or digital channels, we are dedicated to offering reliable, efficient, and accessible financial solutions to empower our customers and foster sustainable growth. Customers and potential customers can access our services through these channels including our website mycoolbank.com
When you open an account at any of our branches, use our electronic channels (e-channels), or subscribe to any of our products and services including online banking, instant banking, and ATM card services, you provide personally identifiable information. This Privacy Policy explains how we collect, use, store, disclose, and, when necessary, destroy the personal data you share with us. We are committed to safeguarding your information in compliance with applicable data protection laws.
You can access the complete Privacy Policy on our website at mycoolbank.com or by visiting our head office. We encourage you to read the policy carefully. By engaging with any of our products or services, you consent to the collection and processing of your personal data as described in this policy. Unless otherwise specified, all terms used in this Privacy Policy align with the definitions provided in our Terms and Conditions, which are also available on our website.
“Consent” of the Data Subject means any freely given, specific, informed, and unambiguous authorization for the processing of their Personal Data. Such consent must be expressed through a clear affirmative action or an explicit statement, through a statement or a clear affirmative action signifies agreement to the processing of Personal Data relating to him or her;
“Data” means Any form of information, including characters, symbols, or binary code, that is processed digitally. This data can be stored, transmitted, or retrieved through electronic means and may exist in diverse formats across various storage devices.;
“Data Protection Officer or DPO” he designated officer appointed under Data Protection Laws to ensure Cool Microfinance Bank’s compliance with regulatory frameworks. The DPO advises the Bank and its personnel on data protection responsibilities, monitors adherence to legal requirements, and oversees data handling practices under the Data Protection Laws, for monitoring compliance with Data Protection Law;
“Data Subject”Any natural person who can be identified directly or indirectly through unique identifiers (such as a name, identification number) or other distinguishing factors related to their physical, mental, economic, cultural, or social characteristics;
"NDPR"means the Nigeria Data Protection Regulation, 2019; An abbreviation for the Nigeria Data Protection Regulation, 2019, which governs the collection, storage, and processing of personal data within Nigeria;
"NDPA"means the Nigeria Data Protection Act, 2023; An abbreviation for the Nigeria Data Protection Act, 2023, which establishes legal frameworks and standards for data protection and privacy in Nigeria;
“Our Services”Refers to the digital banking services offered by the Bank to its customers, including but not limited to online/mobile banking and instant banking;
“Personal Data” Any information related to an identified or identifiable natural person ("Data Subject"), who can be recognized directly or indirectly through identifiers such as a name, identification number, location data, online identifiers, or other factors related to their physical, physiological, genetic, mental, economic, cultural, or social identity. This includes, but is not limited to, names, addresses, photographs, email addresses, bank information, social media posts, medical records, and technical identifiers such as MAC addresses, IP addresses, IMEI numbers, IMSI numbers, SIM information, and other forms of Personal Identifiable Information (PII).
“Personal Identifiable Information (PII)”Information that, alone or combined with other data, can be used to identify, contact, or locate a specific individual, or to identify a person in a particular context;
We collect several different types of information for various purposes to provide and improve our services to you.
As part of delivering our services, we may collect and process certain personally identifiable information ("Personal Data") to identify or communicate with you. This data may include, but is not limited to your full name (first, middle, and last), email address, phone number, home address, signature, date of birth, and government-issued identification (such as a driver’s license, international passport, or national identity card). We may also collect your bank verification number (BVN) for identity verification purposes.
When you subscribe to our services, especially e-channel services like online and mobile banking, you may need to provide specific authentication information. This may include your User ID, PIN, token-generated responses, password hints, and similar security credentials. Where applicable, you may choose or be required to provide biometric data for account access and transaction verification. To safeguard your information, we use advanced security protocols, including data encryption and secure storage, to protect your credentials and ensure the integrity of your transactions.
By subscribing to our ATM card services, you will receive an ATM card containing unique security identifiers:
To ensure the security of your card, you must keep these details confidential and prevent unauthorized access. If we issue a default PIN, you are required to change it immediately to activate and use your card. These identifiers may be requested during card-related transactions or online service enrollments for verification purposes.
When you make payments or transfers, we collect the necessary information, including your card number and security code. All payment-related data is handled in strict adherence to PCI DSS standards, ensuring secure processing, transmission, and storage
When you access our services via a web browser or mobile device, we may collect data to enhance your experience and ensure the functionality of our services. This data includes:
We use cookies and similar tracking technologies to monitor how you interact with our services. These small data files help us collect anonymous information for analysis and service enhancement. If you prefer not to accept cookies, you may adjust your browser settings. However, please note that some service features may be restricted if cookies are disabled.
We may use third-party Service Providers to monitor and analyze the use of our Service. Such service includes but is not limited to:
We collect personally identifiable information to provide you with the banking services you have subscribed to and to facilitate seamless transaction processing. Additionally, your data may be used beyond these purposes when necessary to comply with legal, regulatory, and contractual obligations, as well as other legitimate business interests. Specifically, your data may be used for the following purposes, including but not limited to:
Your information helps us enhance your banking experience while complying with legal and business requirements.
We may use your information to develop and display content and advertising (and work with third parties who do so) tailored to your interests and or location and to measure its effectiveness.
The modern banking ecosystem is highly interconnected, involving multiple parties in the processing of transactions, such as personalization companies, switching firms, processors, acquirers, merchants, and card schemes. During these transactions, certain personal data may be shared among these entities.
Cool Microfinance is committed to safeguarding your personal data and will only share it as necessary for banking services, legal and regulatory compliance, contractual obligations, or other relevant purposes. If data sharing is required, stringent security measures will be in place to prevent unauthorized access. All collected data will be stored within Cool Microfinance’s systems in Nigeria, and any use of cloud services will adhere to strict governance policies.
We ensure that all reasonable steps are taken to protect your personal information. No transfer of data will occur to another organization or country without adequate security controls in place.
Cool Microfinance is committed to ensuring the security of personal data when it is transferred outside Nigeria. In line with this commitment, the Bank will undertake a comprehensive assessment to verify whether the destination country is included on the NITDA White List of Countries with adequate data protection frameworks.
Any cross-border transfer of personal data will comply strictly with the Nigeria Data Protection Regulation (NDPR) 2019 and will only be conducted under the following legal grounds:
In every case, the Bank will ensure that the Data Subject is fully informed of potential risks associated with transferring data to a third-party country. This provision does not apply if the transfer is necessary for ongoing civil or criminal proceedings involving the Data Subject in the third-party country. If the destination country is not recognized on the White List and no qualifying conditions are met, the Bank will seek prior authorization from NITDA and the Office of the Honourable Attorney General of the Federation (HAGF) before facilitating the transfer.
The Bank is committed to maintaining the security of all data during transfer and will provide full details of protective measures upon request by the Data Subject.
We only share and disclose your information in the following situations:
We value the security of your personal information and have adopted appropriate technical and organizational measures to protect the data we collect and process. These measures are designed to ensure the confidentiality, integrity, and security of your information against unauthorized access, loss, or misuse.
Despite our commitment to protecting your data, no digital or internet-based system can be entirely secure. We cannot guarantee absolute security for information transmitted to and from our services. For your safety, we advise accessing our services only through secure networks and environments. We will continue to enhance our security measures to safeguard your personal information to the best of our ability
Cool Microfinance is fully committed to complying with the Nigeria Data Protection Regulation (NDPR) in all aspects of Personal Data processing. This commitment underscores our dedication to fostering a privacy-centric environment and ensuring that all personal information is handled with the utmost care and responsibility.
To uphold these standards, the Bank strictly adheres to the following fundamental principle:
The Bank is committed to ensuring the accuracy and currency of Personal Data. To this end:
The collection and processing of Personal Data will be limited to the purposes specified in the Bank’s Privacy Notice and to which the Data Subject has provided explicit consent. Personal Data will not be repurposed for any other use without obtaining fresh consent, except as permitted by law.
Personal Data collection will be restricted to what is directly relevant, adequate, and essential for the specified processing purpose. When feasible, the Bank will anonymize data to minimize the identification of Data Subjects while fulfilling processing objectives
The Bank enforces rigorous controls to protect Personal Data from unauthorized access, modification, and disclosure, whether stored digitally or physically. Measures are in place to prevent unauthorized access or changes to Personal Data, ensuring its continued accuracy and trustworthiness.
All Personal Data collected, stored, and processed by the Bank shall be retained and disposed of in line with regulatory and legislative requirements. The Bank will conduct periodic reviews of the Personal Data in its possession to assess its accuracy, relevance, purpose, and the continued need for retention. The retention period for Personal Data is determined based on the following factors, subject to applicable laws and the Bank’s Document Retention Policy:
The Bank will promptly delete or securely dispose of Personal Data that is no longer required, in accordance with its Document Retention Policy, unless there is a legal or regulatory obligation to retain such data.
At Cool Microfinance, we uphold our commitment to data privacy by maintaining robust accountability measures in line with the Nigeria Data Protection Regulation (NDPR). This section outlines our approach to ensuring compliance, managing breaches, and enforcing internal accountability.
The Bank is dedicated to demonstrating ongoing compliance with the NDPR by regularly monitoring, reviewing, and improving its data privacy practices. This commitment ensures that the Bank remains aligned with regulatory requirements and industry best practices.
Any employee, contractor, or third party who violates this Privacy Policy will be subject to disciplinary action, which may include:
In the event of a potential or actual breach of Personal Data, the Bank will initiate a structured investigation process to identify and address the issue promptly and effectively:
We are committed to retaining your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is mandated or permitted by law (such as for tax, accounting, or other legal obligations).
Upon receiving a request for account closure:
In some regions (like the European Economic Area), you have certain rights under applicable data protection laws. These may include the right.
In certain circumstances as stated in section 2.8 of the Nigeria Data Protection Regulation, you may also object to the processing of your personal information. To make such a request, please use the contact details provided below. We will consider and act upon any request in accordance with applicable data protection laws.
If we are relying on your consent to process your personal information, you have the right to withdraw your consent at any time. Please note however that this will not affect the lawfulness of the processing before its withdrawal.
If you are resident in the European Economic Area and you believe we are unlawfully processing your personal information, you also have the right to complain to your local data protection supervisory authority. You can find their contact details here:
European Data Protection Board
If you wish to review, modify, or terminate your account, you may contact us using the details provided in this Privacy Policy.
The Bank is committed to ensuring that all employees involved in the collection, access, and processing of Personal Data receive comprehensive training on data privacy and protection. This training is designed to equip employees with the knowledge, skills, and competencies required to manage the compliance framework under this Privacy Policy and the Nigeria Data Protection Regulation (NDPR). The Bank shall develop and implement an annual capacity-building plan to enhance employees' understanding of data privacy and protection in accordance with the NDPR.
The Bank shall appoint a Data Protection Officer (DPO) responsible for overseeing the Bank’s data protection strategy and ensuring compliance with the Nigeria Data Protection Regulation (NDPR). The DPO shall possess expert knowledge of data privacy and protection principles and maintain a thorough understanding of the NDPR’s provisions.
The Bank is committed to ensuring regulatory compliance through an annual data protection audit conducted by a licensed Data Protection Compliance Organization (DPCO).
The audit shall assess the Bank’s adherence to the NDPR and other applicable data protection laws. Upon completion, the DPCO will certify the audit report and submit it to the National Information Technology Development Agency (NITDA) as mandated by law.
This Privacy Policy may be updated from time to time to reflect regulatory changes, business practices, or other operational adjustments. Any modifications will be published on this page and made accessible at our branches.
We recommend that you periodically review this Privacy Policy to remain informed about how we manage and protect your personal data. All updates will take effect from the date of publication unless otherwise stated.
If you have any questions or comments about this policy, you may contact our Data Protection Officer (DPO) by email at: management@coolbank.ng or by post to:
Data Protection Officer.
Cool Microfinance Bank Limited C96-C101, Road 2,
Ikota Shopping Complex,
Lekki-Ajah Expressway, Lagos
Nigeria
If you have any further questions or comments about us or our policies,
email us at info@coolbank.ng or by post to:
Cool Microfinance Bank Limited C96-C101, Road 2,
Ikota Shopping Complex,
Lekki-Ajah Expressway, Lagos
Nigeria.