Exercising Your Data Subject Rights at Paystack
At Paystack, we believe privacy is a fundamental right. As a merchant on our platform, you and your customers have specific legal rights over how personal data is collected and used. This article explains those rights and how to exercise them.
Your rights as a merchant
Under data protection laws such as the Nigeria Data Protection Act (NDPA), South Africa's Protection of Personal Information Act (POPIA), and Ghana's Data Protection Act (DPA), you're entitled to the following rights:
Right to information: Receive clear details about how we collect, process, and store your personal data. Our privacy policy covers this, but you can request further clarification at any time.
Right of access: Request a copy of the personal data Paystack holds about you.
Right to data portability: Request that your personal data be transferred to another data controller in a structured, commonly used electronic format.
Right to rectification: Correct any inaccurate or incomplete information we hold about you.
Right to erasure (also known as the "right to be forgotten"): Request that we delete your data, unless we're legally required to keep it (for example, to meet financial regulations).
Right to object to processing: Object to your data being used for purposes like direct marketing at any time.
Right to withdraw consent: Withdraw any consent you've previously given us to process your personal data.
Right to restrict processing: Limit how we process your personal data.
Right to object to automated decision-making: Object to decisions that affect you and are made through automated systems, including artificial intelligence.
Right to issue a Standard Notice to Address Grievance (SNAG): If you're a merchant or customer in Nigeria, you can issue a SNAG if you believe we've violated your right to privacy.
Right to lodge a complaint: File a complaint with the data protection authority in your country.
Supporting your customers' rights
When your customers exercise their rights with you, we're here to help you stay compliant. If a customer asks you to correct or delete data that's been shared with Paystack, we'll work with you to make sure those changes are reflected in our systems.
How to make a request
To exercise any of these rights, email our Data Protection Officer at dpo@paystack.com or contact our support team at support@paystack.com.
We'll acknowledge your request within two working days and aim to provide a full response within 20 days.
