1. Who we are and what this policy covers

KlaroTax is a deterministic-plus-AI financial intelligence tool that helps Nigerian individuals, freelancers, and sole proprietors organise their financial evidence and understand their tax position under the 2026 tax regime (Nigeria Tax Act 2025 and Nigeria Tax Administration Act 2025). This policy explains what personal data we collect when you use the KlaroTax app or website, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It applies to app.klarotax.net, the KlaroTax mobile app, and klarotax.net.

Krexant Platforms Ltd, the company that operates KlaroTax, is the data controller for every category of personal data described below — we decide why and how your data is processed, even where a third-party processor (see Section 5) handles storage or infrastructure on our behalf.

Krexant Platforms Ltd's registered business address is 4 OAU Street, 900107, Abuja, Nigeria.

2. Data we collect

CategoryExamplesSource
Sign-in dataYour name, email address, and passwordYou, at sign-up. Your password is handled by Clerk, our authentication provider, and stored by Clerk in encrypted (hashed) form — KlaroTax never sees or stores it.
Profile dataPhone number, and the profile details you complete during onboardingYou, directly into KlaroTax. We do not send your phone number to our sign-in provider, and our sign-in provider is configured so that it cannot store one.
Financial documentsBank statements (PDF/image), receipts you uploadYou, via document upload
Transaction dataAmounts, dates, narrations, categories extracted from your documentsExtracted by KlaroTax's AI layer from your uploaded documents
Payment dataYour email address as sent to our payment provider, the plan and amount you bought, the date, a payment reference, how you paid (for example card or bank transfer), the fee Paystack charged, whether the card was issued outside Nigeria, and Paystack's transaction numberYou, at checkout. Your card or bank details are entered on Paystack's page and are never sent to or stored by KlaroTax.
Tax computation dataIncome, expense, deduction, gains, and PIT computation resultsGenerated by KlaroTax's deterministic tax engine from your transaction data
Sensitive personal dataIf you choose to claim National Health Insurance Scheme (NHIS) premium relief, a receipt or statement showing that you paid an NHIS premium. We do not ask for, and you should not upload, medical records, test results, diagnoses, or treatment or claims details; if your statement shows any of these, please hide or crop them before you upload. A premium receipt can still show that you are enrolled in a health-insurance scheme, so we treat it as sensitive personal data to be safe, and give it additional handling care.You, via document upload. Uploading is optional: you can record a relief claim without uploading evidence. Whether the tax authority accepts a relief claim without evidence is for the authority, and it may ask you for proof, so keep your receipt.
Direct identifiersBVN, NIN, TIN, bank account numbers — where a document or a future bank-linking integration surfaces themYou, or (for future account-linking) a licensed open-banking partner
Usage dataApp interactions, screens viewed, feature usage — anonymised where possibleAutomatically, as you use the app
Device dataDevice type, OS version, IP address (for security and fraud prevention)Automatically

We do not collect this data through any external AI/LLM API call. KlaroTax's document extraction and tax computation run on infrastructure we control: our OCR uses Tesseract, and our classification uses rule-based and machine-learning models we operate ourselves, not a hosted large-language-model API (see Section 5 for hosting).

3. Why we process your data (lawful basis)

Under the Nigeria Data Protection Act 2023 and the General Application and Implementation Directive (GAID) 2025, we rely on the following lawful bases:

4. How your data is used

Every number KlaroTax shows you is explainable — you can always see what rule or calculation produced it. AI never overrides KlaroTax's deterministic tax logic; AI is additive only (document extraction, classification suggestions, advisory insights).

5. Who we share your data with (processors and sub-processors)

We use the following third parties to operate KlaroTax. Except where we say otherwise (Paystack, below), each processes your data only on our instructions, under a data processing agreement, and only to the extent needed to provide their service to us:

ProcessorRoleData involved
ClerkAuthentication — sign-up, sign-in, and keeping you signed inYour name, email address, and password (which Clerk stores in encrypted form — we never see it), your authentication tokens, and technical information Clerk records automatically when you sign in (IP address, device and browser identifiers, sign-in activity). We do not send Clerk your phone number — our sign-in provider is configured so that it cannot store one — and we do not send it your bank or financial data, your uploaded documents, or any tax information: those never leave our own database and document storage.
SupabaseDatabase and document storage infrastructureAll categories in Section 2, encrypted at rest for direct identifiers (see Section 8)
DigitalOceanServer hosting — our backend and web app run on a DigitalOcean droplet (Ubuntu), served by NginxAll categories in Section 2, as processed/served by our application
GitHub (a Microsoft company)Storage of our encrypted daily database backup, and the automated job that creates itAn encrypted copy of our database, so in principle all categories in Section 2. The copy is encrypted with a key that GitHub does not hold, so GitHub cannot read it once it is stored; it is deleted automatically after 14 days. We do not put your data anywhere else on GitHub, and we do not store it in our source code.
Paystack (Paystack Payments Limited)Payment processing when you buy a paid planYour email address, to start and confirm the payment. Card or bank details are collected by Paystack on its own page; KlaroTax never receives or stores them. We keep the payment reference and the outcome (paid or not).
SentryApplication error monitoring for our mobile app only — helps us detect and fix bugs. Our backend does not currently send any data to Sentry.Crash reports and technical diagnostics only: error messages and stack traces, device and operating-system information, a sample of performance timings (which screen, how long, not what was on it), and your IP address. Our mobile app is not configured to send your name, your email address, your KlaroTax user ID, your financial documents, your transactions, or your tax position to Sentry. We do not yet run an automated filter that would strip this information if it were ever accidentally included in an error message — we are building one — so treat this as what we deliberately send today, not as a guarantee that nothing else ever could be.

Paystack (a Stripe company) takes payment for Paid plans. For the payment itself, Paystack generally acts on our behalf as a service provider (a data processor). Paystack is also responsible in its own right for some uses of payment data, namely fraud prevention and meeting its own legal and record-keeping duties, and for those it decides the purpose itself and is an independent controller. We send Paystack your email address; Paystack's secure page collects your card details, and KlaroTax never sees or stores them. We keep only a reference to the transaction. Paystack's own privacy policy is at paystack.com/terms.

We deliberately keep the sign-in provider's copy of your data as small as possible. Adding any new category of personal data to it is treated as a change to this policy, not as a routine product update. While the database backup is being created, the data is briefly processed on GitHub's systems before it is encrypted and the temporary workspace is discarded.

We do not currently use a content-delivery network (CDN) — the app is served directly from our DigitalOcean server. We plan to add Cloudflare (for CDN/DDoS protection) as a processor; it would sit at the network edge in front of our server. This table will be updated, and you will be notified of material changes, before it goes live in production.

We are not currently engaged with any savings, investment, or "Reserve"-style referral partner. If we introduce such a feature, this table will be updated — and you will be notified of the change — before it goes live, naming the specific partner and what data, if any, would be shared with them.

We do not sell your personal data to anyone. We do not share it with advertisers.

6. How long we keep your data

Data categoryRetention periodWhy
Computation audit events & archives7 years from the end of the assessment yearNigerian tax law requires records sufficient to verify a return to be kept for a minimum number of years after the end of the year of assessment; we keep them for 7, one year longer than we currently understand the minimum to be, so a record is never lost at the boundary
Document vault (uploaded statements, receipts)7 years from the end of the assessment yearSame — supporting documents for a filed return, kept for one year longer than we currently understand the law to require
Account/role dataDuration of your active account, plus 1 year after closureData-minimisation principle; no statutory minimum applies
Payment records (plan, amount, date, reference)7 years from the date of paymentFinancial and tax record-keeping. If you ask us to delete your account, we keep a payment record with your account link removed for this period.
Consent records (your consent to storage outside Nigeria, and each tick for an NHIS receipt)8 years from the date you gave consentTo prove that you agreed, and to defend legal claims. A consent record holds the date, your account ID, the wording version and, for the cross-border consent, a keyed fingerprint of your email. For a health-insurance receipt the record says you ticked the box; it never contains the receipt or what it shows. Delete My Data does not remove it.
Application logs90 daysOperational; logs carry a trace ID only, not your document content
BackupsTwo kinds, kept separately. (1) Application server: weekly backups of our application server, each kept for 168 days (24 weeks) and then deleted. (2) Database: a daily copy of our database, encrypted so that only we can open it, stored with GitHub (see Sections 5 and 7) and automatically deleted after 14 days. Our database provider does not currently keep backups for us under our plan, so this daily copy is our database backup.Operational recovery (disaster recovery only)

If you have an active tax audit or dispute with the Nigeria Revenue Service, we may need to hold your records past the normal deletion point until that matter is formally closed — we will tell you if this applies to you.

Our policy is to delete, not to keep. We retain your document vault and computation records for the period set out above and no longer. We do not offer indefinite or open-ended retention, and KlaroTax is not a permanent archive for your records.

We are honest with you about how that is enforced today: deletion at the end of the retention period is currently carried out by our team as an operational process, and we are building automated expiry so that it happens without anyone having to run it. Until that automation is live, treat the period above as our commitment to you rather than as something a machine guarantees. You can delete your data yourself at any time, immediately, from Settings → Privacy & Data — that route is automated today and does not wait for any retention period.

Please keep your own copies of the documents you upload. Your own backup is the only copy that remains available to you once our retention window closes. That is your responsibility, not something KlaroTax manages for you beyond the period stated above.

7. Where your data is stored — cross-border transfers

Some of our infrastructure providers host data outside Nigeria:

ProviderWhat it doesWhere your data sits
SupabaseOur database and document storageUnited Kingdom
KlaroTax serversThe computers our app and API run onUnited Kingdom
ClerkSign-in, and keeping you signed inUnited States
SentryError monitoring, so we can find and fix bugsGermany
GitHubStorage of our encrypted daily database backup (kept 14 days)United States (GitHub is owned by Microsoft)
PaystackTaking your paymentNigeria and other countries where Paystack and its providers operate, including Ireland (its cloud servers). Paystack is a Stripe company.

For the backup copy held by GitHub, we add technical safeguards on top of the contractual ones described below: the copy is encrypted with a key that is kept offline by us and is never given to GitHub, so GitHub cannot read it; and it expires and is deleted automatically after 14 days.

Because the Nigeria Data Protection Commission (NDPC) has not formally designated the United Kingdom, the United States, or Germany as offering an automatic "adequate" level of data protection, we do not rely on an adequacy finding alone. Our approach is to secure these transfers using Cross-Border Data Transfer Instruments (CBDTIs) as contemplated under the Nigeria Data Protection Act — in practice, Data Processing Agreements (DPAs) with our infrastructure providers, which we require to include Standard Contractual Clauses (SCCs) or an equivalent contractual safeguard obligating each provider to protect your data to a standard materially equivalent to Nigerian law.

Paystack is a Nigerian-licensed payment company and sets its own transfer safeguards, which differ from the agreements above. Paystack states that it transfers personal data outside Nigeria to other Paystack entities and service providers, relying on the Nigeria Data Protection Act and its General Application and Implementation Directive, and on Binding Corporate Rules for transfers within its group. We have not separately confirmed the cross-border text of Paystack's data processing terms with us, and we rely on Paystack's published statements for the rest. Where we find a gap we will close it or tell you.

We are honest with you about where that stands today: we have not yet independently confirmed, provider by provider, that each of these agreements currently contains executed SCC-equivalent text — that confirmation exercise is under way. Where we find a gap, we will close it or tell you, rather than leave it undisclosed.

To complement these contractual safeguards, we also implement strict technical protections, including:

8. How we protect your data

9. Your rights

Under the NDPA, you have the right to:

Document vault files follow within the timelines in Section 6. We target same-day automated deletion of the live copy of your data. Copies held in our backups are not deleted on the same day: they remain until those backups expire. For our database backups that is up to 14 days after you delete your data. For our application-server backups it can be up to 168 days (24 weeks). Backups exist only so that we can recover from a serious outage; we do not use them for any other purpose. This means that, for backup copies only, complete removal can take longer than 30 days. Some records may be exempt from immediate deletion if you have an active tax audit or legal proceeding (see Section 6).

How withdrawal works today. When you withdraw your consent in the app (Settings → Privacy & Data), the app records your withdrawal, then deletes your KlaroTax data and signs you out, as one continuous process; you do not need to wait for us. If anything interrupts that process (for example, you lose your connection part-way), the app tells you, and you should email privacy@krexant.com: we will complete the deletion ourselves and confirm to you in writing within 30 days. Two things are handled separately and are described elsewhere: your sign-in record with Clerk (next paragraph), and copies of your data that remain in our backups for a limited period (Section 6 and above).

We want to be precise about one thing rather than leave you to assume it: your sign-in record with Clerk, our authentication provider (your name, email address and encrypted password, and nothing else), is not deleted by the in-app deletion. Today we delete it by hand. To have it erased, email privacy@krexant.com from the address you signed up with; we will verify it is you, delete the record, and confirm to you in writing within 30 days. Until you do, Clerk keeps that record and your email address will still be recognised if you try to sign in again. We are building automatic deletion of this record into the in-app process and will update this policy when it is live.

To exercise any of these rights beyond the in-app tools, contact our Data Protection Officer (see Section 13).

Payments and deleting your account. When you ask us to delete your account we delete your account data and your plan. We keep a record of each payment (amount, plan, date and payment reference, with your account link removed) for 7 years, because tax and accounting rules require it. Our security log also keeps a payment event under your sign-in ID; that ID identifies you only while your sign-in record exists, and deleting your sign-in record is part of how we handle an account-deletion request. Deleting your data in the app does not delete what Paystack holds about your payment. Nigerian law requires Paystack to keep transaction records for at least 5 years after the transaction, and identification records for 7 years after the relationship ends, so it cannot erase them earlier on request. Ask Paystack directly about its copy (see its privacy policy).

10. Children's data

KlaroTax is not directed at or intended for use by minors. Our services are intended for individuals of legal working/taxpaying age in Nigeria. We do not knowingly collect personal data from children. If we learn we have inadvertently collected data from a minor, we will delete it promptly.

11. What happens if there's a data breach

If a breach occurs that is likely to compromise the confidentiality, integrity, or availability of your personal data, we will assess it under our internal Incident Response Playbook and, where required, notify the Nigeria Data Protection Commission and affected users without undue delay, consistent with NDPA notification timelines.

12. Changes to this policy

We will update this policy as our practices, the law, or our processors change, and will post the effective date at the top. Material changes will be flagged in-app.

13. Contact us / Data Protection Officer

Krexant Platforms Ltd's designated Data Protection Officer for KlaroTax is Emmanuel Olatinwo. For any privacy question, data-rights request, or complaint:

You may also lodge a complaint directly with the Nigeria Data Protection Commission (NDPC) if you believe we have not handled your data lawfully.

Krexant Platforms Ltd has assessed itself as a data controller of major importance under the Nigeria Data Protection Act 2023 and is in the process of registering with the Nigeria Data Protection Commission. We will update this policy once that registration is completed.