About this Privacy Policy
This Privacy Policy explains how CitiBIM Nigeria Limited (“CitiBIM”, “we”, “us” or “our”) collects, uses, stores, protects and shares personal data when you use CITIShield (“CITIShield”, “the Platform” or “the Service”).
CITIShield is intended to help individuals and communities communicate, share information and respond to safety-related situations. Depending on the features you use, CITIShield may process information such as your telephone number, display name, location, device information, account information, messages, reports, and other information that you choose to provide.
We understand that information about your identity, location and safety can be sensitive. We therefore aim to collect only information that we reasonably need, use it for clear purposes, keep it secure and retain it only for as long as necessary.
This Privacy Policy is intended to comply with the Nigeria Data Protection Act 2023 (“NDPA”), applicable regulations and guidance issued by the Nigeria Data Protection Commission (“NDPC”), including the NDP Act General Application and Implementation Directive 2025 (“GAID”), as applicable.
Where another applicable privacy or data-protection law gives you greater protection, we will comply with that law where it applies to our processing.
Who is responsible for your personal data?
The organisation responsible for the processing of your personal data is:
2nd Floor, Turbo Energy Building,
Sector Centre D,
1121 Oladipo Diya Street,
Gudu District, Abuja, Nigeria.
Email: contact@citibim.com
For questions, requests or complaints concerning your personal data, you may contact us using the details above.
CitiBIM Nigeria Limited is the data controller for personal data processed through CITIShield. This means that CitiBIM determines the purposes for which, and the manner in which, your personal data is processed.
Where CitiBIM provides CITIShield to an organisation and processes personal data on that organisation's instructions, CitiBIM may act as a data processor for that specific processing.
What information do we collect?
The information we collect depends on how you use CITIShield.
We do not necessarily collect every type of information listed below. We collect information only where it is required for a particular feature, service, legal obligation or other lawful purpose.
3.1 Information you provide to us
This may include:
- username or display name;
- telephone number;
- virtual NIN (vNIN) token, where you choose to verify your identity;
- identity verification status;
- authentication information;
- account information;
- address or general area;
- information you provide when contacting customer support;
- information contained in reports, complaints or safety alerts;
- information you provide when creating or responding to a safety incident;
- information you provide when participating in community activities;
- information you voluntarily provide in your profile or other parts of the Platform.
Account creation. You create a CITIShield account using your telephone number. We send a one-time verification code to that number by SMS to confirm that the number belongs to you. Account authentication is provided through a third-party authentication service.
We do not ask you for your first name, last name, email address or a profile photograph when you create an account. You choose a display name.
Providing your vNIN token is required only to obtain a fully verified account.
3.2 Identity verification and your virtual NIN (vNIN) token
CITIShield exists to give communities information they can trust. Reports on the Platform are only as reliable as the people making them. Verifying that account holders are real, identifiable individuals is therefore central to the Service: it supports the quality and credibility of the information shared on CITIShield, and it discourages false, duplicate and malicious reporting.
3.2.1 Verification is optional, but it unlocks full access
You may use CITIShield without providing your vNIN token. If you do not provide it, you will hold a basic account with access to a reduced set of features.
If you choose to verify your identity, you will hold a verified account with access to the full set of features.
3.2.2 What we collect for verification
- your vNIN token;
- the outcome of the verification check;
- the date and time of the check and a reference number for it;
- the information returned to us by the verification service.
3.2.3 How verification works
When you submit your vNIN token, we transmit it, together with the details required for matching, to our identity-verification partner, a verification aggregator licensed by the National Identity Management Commission (“NIMC”). Our partner submits the check to NIMC. NIMC checks the vNIN token against the National Identity Database and returns a verification result to us through that partner.
The response we receive may include identity details held by NIMC about the holder of that vNIN token, which may include name, date of birth, gender, registered telephone number, registered address and photograph.
3.2.4 What we retain
Once verification is complete, we retain your verification status, the date of the check and a reference identifier. We retain only a one-way cryptographic hash of your vNIN token, never the token itself.
We do not add the identity details returned by NIMC to your CITIShield profile. Your display name remains the name other users see.
3.2.5 Confidentiality of your vNIN token
Your vNIN token is never displayed to other CITIShield users, is never included in a safety report, alert or message, and is not made visible to organisations using CITIShield.
Where verification status is relevant to other users, only the fact that an account is verified is displayed. The underlying identity information is not.
3.2.6 If verification is unsuccessful
If NIMC is unable to verify your vNIN token, or the details submitted do not match, we will be unable to upgrade your account to a verified account. You may correct the information submitted and try again, or contact us for assistance.
Where the information held about you by NIMC is itself inaccurate, that record can only be corrected by NIMC. You should contact NIMC directly.
3.2.7 Your obligations
You must submit only your own vNIN token. Submitting another person's vNIN token, or a vNIN token that has not been issued to you, may be unlawful and may result in suspension or closure of your account and referral to the appropriate authorities.
Location information
Because CITIShield provides location-based safety and community information services, the Platform processes location information.
Depending on the features you use, this may include:
- precise GPS location;
- approximate location;
- location associated with a safety report;
- location at the time an alert is created;
- location shared with another CITIShield user;
- location information generated from your device;
- the ShieldCode associated with a location.
Precise location is required for core CITIShield features, including the local status view, the map view, the near-you feed, and the creation and community verification of reports.
CITIShield does not collect location information in the background. We do not collect or maintain a continuous record of your movements. Location is collected while you are actively using the Platform.
4.1 ShieldCode
CITIShield uses ShieldCode, a precise location identifier for places that do not have a formal address.
Because a ShieldCode can identify a specific dwelling or premises, we treat ShieldCodes as personal data where they are associated with an identifiable individual, and protect them accordingly.
4.2 Your controls
We will request permission before accessing location information where required by your device or applicable law.
You may be able to disable location access through your device settings. However, disabling location access will prevent most CITIShield features from working, as the Platform is built around your immediate area.
4.3 Location visible to others
Where you submit a report, the location of that report is displayed to other users in the vicinity. This is necessary for the Service to function.
The location of a report is not the same as your own location. However, where a report is submitted at or near your home, other users may be able to infer where you live. You should take this into account when submitting a report.
Device and technical information
When you use CITIShield, we may automatically receive certain technical information from your device.
This may include:
- device type;
- operating system;
- application version;
- unique device or application identifiers;
- IP address;
- mobile network information;
- language and time-zone settings;
- crash reports;
- diagnostic information;
- login information;
- security information;
- date and time of access;
- information about how you interact with the Platform.
We use this information to operate, secure, maintain and improve CITIShield.
Usage and behavioural information
We may collect information about how you use CITIShield.
This may include:
- features you use;
- pages or screens you access;
- searches;
- interactions with alerts;
- reports you create, view or verify;
- approximate usage times;
- actions taken within the application;
- error and performance information.
We may use this information to understand how CITIShield is used, improve the Platform, detect abuse and protect users.
Where information is used for analytics, we will seek to use information in a form that does not unnecessarily identify you.
Safety reports and user-generated content
CITIShield allows users to create safety reports, alerts or other content.
Reports submitted through CITIShield consist of a report category, a description and a location. CITIShield does not allow users to attach photographs, video, audio recordings or other media files to a report.
Such information may contain personal data about:
- you;
- other individuals;
- witnesses;
- suspected offenders;
- victims;
- emergency situations;
- locations;
- vehicles;
- other information contained in the report.
You should not provide another person's personal information unless you have a lawful reason to do so.
You should also avoid including unnecessary sensitive personal information in a report.
For example, do not include someone's medical information, identity document number, National Identification Number, financial information or other highly sensitive information.
7.1 Community verification of reports
CITIShield allows other users in the vicinity of a report to confirm or dispute it. This helps the community distinguish accurate reports from inaccurate ones.
Community verification is not a finding of fact. A report that has been confirmed by other users remains a report. It is not proof that an event occurred or that any person has committed an offence.
7.2 Content moderation
We operate content moderation and abuse reporting. We may review, restrict, remove or withhold content that breaches our terms, is inaccurate, is abusive, or places any person at risk.
Information about other people
You may sometimes provide information about another person, for example when reporting a safety incident or requesting assistance.
If you provide information about another person, you should ensure that you have a lawful basis for providing that information.
We may process the information for the purpose for which it was submitted, including safety, security, investigation, emergency response, dispute resolution or compliance with the law.
We may also remove, restrict or anonymise information where necessary to protect individuals' privacy or comply with applicable law.
Sensitive personal data
Some information may be particularly sensitive.
Depending on the circumstances, this may include information relating to:
- health;
- disability;
- criminal allegations or offences;
- precise location;
- information concerning vulnerable persons;
- information revealing other sensitive characteristics.
CITIShield will not deliberately collect sensitive personal data unless there is a clear and lawful reason to do so.
Where sensitive personal data is processed, we will apply additional safeguards required by applicable law.
Biometric data. CITIShield does not process biometric data. We do not collect or process fingerprints, facial recognition templates or other biometric identifiers, and we do not perform any facial comparison between a user-submitted image and the photograph held by NIMC.
Criminal-allegation data. Safety reports submitted through CITIShield may contain allegations relating to criminal conduct. We treat such information as sensitive, apply moderation and access controls to it, and remind users that a report is not proof of an offence.
Information we receive from third parties
Where necessary for providing CITIShield, we may receive information from third parties.
This may include:
- the National Identity Management Commission (NIMC), which returns identity verification results;
- authentication providers;
- telecommunications providers;
- mapping or location service providers;
- hosting providers;
- analytics and crash-reporting providers;
- security providers;
- payment providers;
- emergency or public authorities;
- business customers or organisations using CITIShield;
- other service providers acting on our behalf.
We will only receive or use such information where there is a lawful basis for doing so.
Why do we use your personal data?
We may use your personal data for the following purposes:
11.1 Providing CITIShield
We use your information to:
- create and manage your account;
- authenticate you;
- provide requested features;
- provide location-based services;
- deliver alerts;
- process safety reports;
- enable community verification of reports;
- process donations to community projects;
- provide customer support;
- maintain the Platform.
11.2 Verifying identity and maintaining information quality
We use your vNIN token and the information returned by NIMC to:
- confirm that you are a real, identifiable person;
- confirm that the identity you have claimed belongs to you;
- prevent the creation of fake, duplicate or impersonating accounts;
- support the reliability and credibility of information shared on the Platform;
- reduce false, malicious or anonymous reporting;
- confirm age where required.
11.3 Safety and security
We may use information to:
- identify and respond to safety incidents;
- investigate misuse;
- prevent fraud;
- detect suspicious activity;
- protect users;
- protect our systems;
- investigate security incidents;
- enforce our terms and policies.
11.4 Improving CITIShield
We may use information to:
- understand how users use the Platform;
- identify technical problems;
- test new features;
- improve reliability;
- improve safety features;
- develop reports and statistics.
Where reasonably possible, information used for these purposes will be aggregated or anonymised.
11.5 Communication
We may use your contact information to:
- send service messages;
- send security alerts;
- respond to enquiries;
- notify you about important changes;
- provide support.
Where marketing communications require consent, we will obtain consent as required by law.
11.6 Legal and regulatory purposes
We may process personal data where necessary to:
- comply with applicable law;
- comply with a court order;
- respond to a lawful request from a government authority;
- establish, exercise or defend legal rights;
- investigate suspected unlawful activity;
- protect the rights, safety or property of CitiBIM, CITIShield users or others.
Our lawful bases for processing
Under the NDPA, personal data should be processed on a recognised lawful basis.
Depending on the circumstances, CitiBIM may rely on:
- Consent – where you have freely given permission for a particular processing activity;
- Contract – where processing is necessary to provide a service or perform a contract with you;
- Legal obligation – where the law requires us to process information;
- Vital interests – where processing is necessary to protect someone's life or another vital interest in circumstances recognised by law;
- Public interest or official authority, where applicable;
- Legitimate interests, where applicable and where those interests do not override your rights and freedoms.
We will not rely on consent where another lawful basis is more appropriate.
Where we rely on consent, you may withdraw your consent where permitted by law. Withdrawal of consent will not affect processing that took place before the withdrawal.
Emergency and safety processing
CITIShield is designed to support safety-related activities.
In an emergency, we may process or disclose information where necessary to protect a person's life, health or safety, or where permitted or required by law.
For example, information may be shared with an appropriate emergency service or competent authority where there is a lawful basis to do so.
However, CITIShield is not a replacement for emergency services. CITIShield does not automatically contact the police, fire service, ambulance service or any other emergency responder on your behalf.
Users should contact the appropriate emergency service directly where immediate emergency assistance is required.
Sharing personal data
We do not sell your personal data for money.
We may share personal data where necessary for legitimate and lawful purposes.
This may include sharing with:
14.1 Service providers
We may use trusted companies to provide services such as:
- cloud hosting;
- databases;
- cybersecurity;
- software infrastructure;
- mapping;
- communications;
- email and SMS delivery;
- push notifications;
- crash reporting and analytics;
- customer support;
- authentication;
- payment processing.
These providers should only process personal data according to our instructions and applicable law where they act as our processors.
14.2 NIMC
We disclose your vNIN token and the associated matching details to our identity-verification partner (a NIMC-licensed aggregator), which submits the check to NIMC, for the sole purpose of verifying your identity. This disclosure is limited to what is necessary to complete the verification check.
14.3 Other CITIShield users
Some CITIShield features allow information to be displayed to other users.
For example, a safety alert may contain information about an incident or its location, and users in the vicinity may be able to view and verify that report.
Your NIN, your telephone number, the identity details returned by NIMC and your verification records are not visible to other users.
We will provide appropriate controls and notices where users are given choices about what information they share.
14.4 Organisations using CITIShield
Where CITIShield is provided through a business, community organisation, estate, school, security organisation or other institution, that organisation may receive certain information.
The organisation's role and access should be clearly explained to users before or when their information is collected.
Organisations do not receive your NIN.
14.5 Government authorities and law enforcement
We may disclose information where required or permitted by law, including in response to:
- lawful government requests;
- regulatory requirements;
- investigations;
- serious safety concerns.
We do not provide information merely because a person asks for it.
International data transfers
Some of our service providers or technology infrastructure may be located outside Nigeria. This may include authentication, cloud hosting, crash reporting and analytics services.
Where personal data is transferred outside Nigeria, we will take reasonable steps to ensure that the transfer complies with applicable Nigerian data-protection requirements.
This may include using appropriate contractual, technical or organisational safeguards and other mechanisms recognised by applicable law.
SDKs and similar technologies
CITIShield may use software development kits (“SDKs”), local storage, device identifiers and similar technologies within the application.
These technologies may be used to:
- keep the Platform functioning;
- remember settings;
- maintain security;
- understand how the Platform is used;
- measure performance;
- improve our services;
- provide analytics.
Where required by law, we will request your consent before using non-essential analytics or similar technologies.
You may be able to control some of these through your device settings.
Children's privacy
CITIShield is not intended to collect personal data from children in circumstances where such processing would be unlawful.
The minimum age for using CITIShield is 18 years.
Where a CITIShield service is intended for children or is likely to be used by children, we will apply appropriate safeguards required by applicable law.
We may take reasonable steps to verify age where required.
If you believe that a child has provided personal data to us unlawfully, please contact us at contact@citibim.com.
We will investigate the matter and take appropriate action.
Automated decision-making and profiling
CITIShield may use automated systems for purposes such as:
- detecting spam;
- identifying suspicious activity;
- identifying potentially fraudulent accounts;
- prioritising technical or safety alerts;
- improving system performance;
- calculating user reliability scores.
Reliability scoring. CITIShield maintains a reliability score for user accounts. The score reflects the accuracy of a user's previous reports, including whether those reports were confirmed or disputed by other users and whether any content was removed through moderation.
The score is used to help assess the weight and priority given to a report. A persistently low score may result in restrictions being applied to an account.
We will not make significant decisions about you solely through automated processing where doing so would unlawfully affect your rights or interests. Where a restriction is applied to your account, a person will review the matter.
Where applicable law gives you a right to human intervention, explanation or review, we will provide that right. You may ask us to explain your reliability score and to review any decision made in reliance on it.
Data accuracy
We aim to keep personal data accurate and up to date.
You should provide accurate information and tell us if information in your account is incorrect.
You may request correction of inaccurate or incomplete personal data.
We are unable to correct the information held about you in the National Identity Database. That record is maintained by NIMC and corrections must be requested from NIMC directly.
How we protect your information
We use reasonable technical and organisational measures to protect personal data.
These may include:
- access controls;
- authentication controls;
- encryption where appropriate;
- secure software development practices;
- monitoring;
- security testing;
- backups;
- staff confidentiality obligations;
- access restrictions;
- logging of access to identity information;
- masking of identifiers in internal and support interfaces;
- incident response procedures.
No internet service can be guaranteed to be completely secure.
You should protect your account credentials and notify us if you believe that your account has been compromised.
Data breaches
If a personal data breach occurs, we will assess the incident and take appropriate steps in accordance with applicable law.
Where notification to the NDPC or affected individuals is legally required, we will make the required notification within the applicable legal timeframe.
We will also take reasonable steps to contain the breach, reduce potential harm and prevent recurrence.
How long do we keep your information?
We do not keep personal data forever.
We retain personal data only for as long as reasonably necessary for:
- the purpose for which it was collected;
- providing CITIShield;
- legitimate business purposes;
- legal obligations;
- dispute resolution;
- fraud and security investigations;
- establishing or defending legal claims.
When personal data is no longer required, we will delete it, anonymise it or securely dispose of it, subject to applicable legal or regulatory requirements.
Different categories of information may have different retention periods.
Identity verification status is retained for as long as your account remains open.
Your rights
Subject to applicable law and certain lawful exceptions, you may have rights relating to your personal data.
These may include the right to:
- know how we process your personal data;
- request access to personal data we hold about you;
- request correction of inaccurate data;
- request deletion of your personal data;
- object to certain processing;
- request restriction of certain processing;
- withdraw consent where consent is our lawful basis;
- request portability of certain personal data;
- object to certain automated decision-making;
- request human intervention where applicable;
- lodge a complaint about our processing.
Some rights are not absolute.
For example, we may need to retain certain information where the law requires us to do so or where it is necessary to establish, exercise or defend legal claims.
Two further limits apply specifically to identity information. We cannot correct the record held about you by NIMC. And where you request deletion of your verification data, we may be required to close your verified account.
How to exercise your rights
To exercise your rights, contact:
Sector Centre D,
1121 Oladipo Diya Street,
Gudu District, Abuja, Nigeria.
Email: contact@citibim.com
Please provide enough information for us to understand your request and verify your identity where reasonably necessary.
We may ask for additional information to prevent someone else from accessing your personal data.
We will respond to valid requests within the timeframe required by applicable law.
Your right to complain
If you believe that CitiBIM has processed your personal data unlawfully or has not adequately addressed your privacy request, please contact us first at contact@citibim.com.
You may also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).
The NDPC is Nigeria's data protection regulator. Its official website provides information about privacy rights, regulatory requirements and complaints.
Data protection impact assessments
Because CITIShield processes precise location information, identity information, safety reports and other information that could create risks to individuals, CitiBIM will assess whether a Data Protection Impact Assessment (“DPIA”) is required before or during relevant processing activities.
Where a DPIA is required, we will identify privacy risks and implement reasonable measures to reduce those risks.
The NDPC's guidance recognises circumstances in which DPIAs are required, particularly for higher-risk processing activities.
Privacy by design
We aim to build privacy protections into CITIShield from the beginning.
This includes, where appropriate:
- collecting only necessary information;
- allowing use of the Platform without identity verification, at a reduced feature level;
- not retaining the NIN once verification is complete;
- not collecting photographs, video or audio recordings;
- not collecting location in the background;
- limiting access to personal data;
- giving users meaningful privacy choices;
- protecting location information;
- limiting retention periods;
- using anonymisation or pseudonymisation where appropriate;
- reviewing third-party services;
- conducting privacy and security assessments.
Public safety reports and false reports
CITIShield may allow users to submit safety-related reports.
Users must not knowingly submit false, malicious, threatening, defamatory or misleading reports.
Where appropriate and lawful, CitiBIM may investigate reports, restrict accounts, remove content or provide relevant information to competent authorities.
We do not guarantee that every report submitted through CITIShield is true or accurate.
Users should exercise appropriate caution and should not treat information on CITIShield as proof that a person has committed an offence.
Third-party websites and services
CITIShield may contain links to websites, applications or services operated by third parties.
Those third parties may have their own privacy policies.
We are not responsible for the privacy practices of third-party services that we do not control.
You should read the privacy policy of any third-party service before providing personal data to it.
Third-party software and SDKs
CITIShield may use third-party software development kits, application programming interfaces (“APIs”) and technology services.
These technologies may process certain technical or personal information on our behalf.
Business transfers
If CitiBIM undergoes a merger, acquisition, restructuring, sale of assets or similar transaction, personal data may be transferred as part of that transaction where legally permitted.
Any successor organisation will be expected to respect applicable privacy obligations.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
When we make significant changes, we will take reasonable steps to notify users where required by law.
The date at the top of this Privacy Policy shows when it was last updated.
Your continued use of CITIShield after an effective update means that you acknowledge the updated policy, subject to any consent requirements imposed by applicable law.
Contact us
If you have a question, request or complaint concerning privacy or your personal data, contact:
2nd Floor, Turbo Energy Building,
Sector Centre D,
1121 Oladipo Diya Street,
Gudu District, Abuja, Nigeria.
Email: contact@citibim.com
Telephone: +234 916 675 5544
Important information about this policy
This Privacy Policy describes our intended approach to personal data protection.
It does not create rights or obligations beyond those provided by applicable law.
Where a provision of this Privacy Policy conflicts with a mandatory requirement of applicable data-protection law, the mandatory legal requirement will apply.
Summary for users
In simple terms:
information needed to provide and secure CITIShield. You sign up with your telephone number and a display name only. We do not ask for your real name, your email address or a photograph of you. We also collect your location, device information and whatever you submit through the Platform.
you sign up with your telephone number. Providing your NIN is optional, but it unlocks full access. We check it with NIMC so that information on CITIShield comes from real, identifiable people. We do not keep the number itself, and it is never shown to other users.
provide CITIShield, support safety features, verify identity and information quality, communicate with you, protect users, improve the Platform and comply with the law.
only where necessary and where we have a lawful basis, including with service providers, NIMC for verification, authorised organisations and authorities where legally permitted or required.
using reasonable security measures.
only for as long as reasonably necessary or as required by law.
including rights to access, correct, delete, object to or otherwise control certain uses of your personal data.
Contact us at contact@citibim.com.