1. Who we are and what this policy covers
KlaroTax is a deterministic-plus-AI financial intelligence tool that helps Nigerian individuals, freelancers, and sole proprietors organise their financial evidence and understand their tax position under the 2026 tax regime (Nigeria Tax Act 2025 and Nigeria Tax Administration Act 2025). This policy explains what personal data we collect when you use the KlaroTax app or website, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It applies to app.klarotax.net, the KlaroTax mobile app, and klarotax.net.
Krexant Platforms Ltd, the company that operates KlaroTax, is the data controller for every category of personal data described below — we decide why and how your data is processed, even where a third-party processor (see Section 5) handles storage or infrastructure on our behalf.
Krexant Platforms Ltd's registered business address is 4 OAU Street, 900107, Abuja, Nigeria.
2. Data we collect
| Category | Examples | Source |
|---|---|---|
| Sign-in data | Your name, email address, and password | You, at sign-up. Your password is handled by Clerk, our authentication provider, and stored by Clerk in encrypted (hashed) form — KlaroTax never sees or stores it. |
| Profile data | Phone number, and the profile details you complete during onboarding | You, directly into KlaroTax. We do not send your phone number to our sign-in provider, and our sign-in provider is configured so that it cannot store one. |
| Financial documents | Bank statements (PDF/image), receipts you upload | You, via document upload |
| Transaction data | Amounts, dates, narrations, categories extracted from your documents | Extracted by KlaroTax's AI layer from your uploaded documents |
| Payment data | Your email address as sent to our payment provider, the plan and amount you bought, the date, a payment reference, how you paid (for example card or bank transfer), the fee Paystack charged, whether the card was issued outside Nigeria, and Paystack's transaction number | You, at checkout. Your card or bank details are entered on Paystack's page and are never sent to or stored by KlaroTax. |
| Tax computation data | Income, expense, deduction, gains, and PIT computation results | Generated by KlaroTax's deterministic tax engine from your transaction data |
| Sensitive personal data | If you choose to claim National Health Insurance Scheme (NHIS) premium relief, a receipt or statement showing that you paid an NHIS premium. We do not ask for, and you should not upload, medical records, test results, diagnoses, or treatment or claims details; if your statement shows any of these, please hide or crop them before you upload. A premium receipt can still show that you are enrolled in a health-insurance scheme, so we treat it as sensitive personal data to be safe, and give it additional handling care. | You, via document upload. Uploading is optional: you can record a relief claim without uploading evidence. Whether the tax authority accepts a relief claim without evidence is for the authority, and it may ask you for proof, so keep your receipt. |
| Direct identifiers | BVN, NIN, TIN, bank account numbers — where a document or a future bank-linking integration surfaces them | You, or (for future account-linking) a licensed open-banking partner |
| Usage data | App interactions, screens viewed, feature usage — anonymised where possible | Automatically, as you use the app |
| Device data | Device type, OS version, IP address (for security and fraud prevention) | Automatically |
We do not collect this data through any external AI/LLM API call. KlaroTax's document extraction and tax computation run on infrastructure we control: our OCR uses Tesseract, and our classification uses rule-based and machine-learning models we operate ourselves, not a hosted large-language-model API (see Section 5 for hosting).
3. Why we process your data (lawful basis)
Under the Nigeria Data Protection Act 2023 and the General Application and Implementation Directive (GAID) 2025, we rely on the following lawful bases:
- Performance of a contract (NDPA s.25) — processing your financial documents, transactions, and computing your tax position is the core service you signed up for; we cannot deliver KlaroTax without it.
- Consent (NDPA s.25) — any optional processing, such as product-improvement analytics, is based on your consent. Health-insurance premium receipts: a premium receipt can show that you have health insurance, which is information about your health. When you attach an NHIS premium receipt to your relief claim in the app, we ask you to tick a box, each time, confirming that you understand this and that attaching it is your choice. The box is never ticked for you, and if we cannot save your tick, nothing is uploaded. We keep a record of each tick (the date, your account ID and the version of the wording you saw) so we can show you agreed. The record says you ticked the box for a health-insurance receipt; it never contains the receipt or what it shows (see Section 6). We use the receipt only to support your own NHIS relief claim and for nothing else. Attaching it is optional. Receipts attached before this step was introduced were handled under the earlier version of this policy; you can delete them at any time (Settings → Privacy & Data → Delete My Data).
- Legal obligation (NDPA s.25) — retaining tax-computation records for the period described in Section 6.
- Legitimate interest (NDPA s.25) — security monitoring, fraud prevention, and service reliability, balanced against your rights and never overriding them for sensitive categories.
4. How your data is used
- To extract, classify, and compute your tax position (deterministic engine — see the Explainability note below).
- To show you readiness scores, deadlines, and compliance guidance.
- To respond to your support requests.
- To improve KlaroTax's extraction and classification accuracy (using de-identified or aggregated data wherever feasible, and never health-insurance receipts).
- To meet our own legal and regulatory obligations (tax record-keeping, audit cooperation).
Every number KlaroTax shows you is explainable — you can always see what rule or calculation produced it. AI never overrides KlaroTax's deterministic tax logic; AI is additive only (document extraction, classification suggestions, advisory insights).
5. Who we share your data with (processors and sub-processors)
We use the following third parties to operate KlaroTax. Except where we say otherwise (Paystack, below), each processes your data only on our instructions, under a data processing agreement, and only to the extent needed to provide their service to us:
| Processor | Role | Data involved |
|---|---|---|
| Clerk | Authentication — sign-up, sign-in, and keeping you signed in | Your name, email address, and password (which Clerk stores in encrypted form — we never see it), your authentication tokens, and technical information Clerk records automatically when you sign in (IP address, device and browser identifiers, sign-in activity). We do not send Clerk your phone number — our sign-in provider is configured so that it cannot store one — and we do not send it your bank or financial data, your uploaded documents, or any tax information: those never leave our own database and document storage. |
| Supabase | Database and document storage infrastructure | All categories in Section 2, encrypted at rest for direct identifiers (see Section 8) |
| DigitalOcean | Server hosting — our backend and web app run on a DigitalOcean droplet (Ubuntu), served by Nginx | All categories in Section 2, as processed/served by our application |
| GitHub (a Microsoft company) | Storage of our encrypted daily database backup, and the automated job that creates it | An encrypted copy of our database, so in principle all categories in Section 2. The copy is encrypted with a key that GitHub does not hold, so GitHub cannot read it once it is stored; it is deleted automatically after 14 days. We do not put your data anywhere else on GitHub, and we do not store it in our source code. |
| Paystack (Paystack Payments Limited) | Payment processing when you buy a paid plan | Your email address, to start and confirm the payment. Card or bank details are collected by Paystack on its own page; KlaroTax never receives or stores them. We keep the payment reference and the outcome (paid or not). |
| Sentry | Application error monitoring for our mobile app only — helps us detect and fix bugs. Our backend does not currently send any data to Sentry. | Crash reports and technical diagnostics only: error messages and stack traces, device and operating-system information, a sample of performance timings (which screen, how long, not what was on it), and your IP address. Our mobile app is not configured to send your name, your email address, your KlaroTax user ID, your financial documents, your transactions, or your tax position to Sentry. We do not yet run an automated filter that would strip this information if it were ever accidentally included in an error message — we are building one — so treat this as what we deliberately send today, not as a guarantee that nothing else ever could be. |
Paystack (a Stripe company) takes payment for Paid plans. For the payment itself, Paystack generally acts on our behalf as a service provider (a data processor). Paystack is also responsible in its own right for some uses of payment data, namely fraud prevention and meeting its own legal and record-keeping duties, and for those it decides the purpose itself and is an independent controller. We send Paystack your email address; Paystack's secure page collects your card details, and KlaroTax never sees or stores them. We keep only a reference to the transaction. Paystack's own privacy policy is at paystack.com/terms.
We deliberately keep the sign-in provider's copy of your data as small as possible. Adding any new category of personal data to it is treated as a change to this policy, not as a routine product update. While the database backup is being created, the data is briefly processed on GitHub's systems before it is encrypted and the temporary workspace is discarded.
We do not currently use a content-delivery network (CDN) — the app is served directly from our DigitalOcean server. We plan to add Cloudflare (for CDN/DDoS protection) as a processor; it would sit at the network edge in front of our server. This table will be updated, and you will be notified of material changes, before it goes live in production.
We are not currently engaged with any savings, investment, or "Reserve"-style referral partner. If we introduce such a feature, this table will be updated — and you will be notified of the change — before it goes live, naming the specific partner and what data, if any, would be shared with them.
We do not sell your personal data to anyone. We do not share it with advertisers.
6. How long we keep your data
| Data category | Retention period | Why |
|---|---|---|
| Computation audit events & archives | 7 years from the end of the assessment year | Nigerian tax law requires records sufficient to verify a return to be kept for a minimum number of years after the end of the year of assessment; we keep them for 7, one year longer than we currently understand the minimum to be, so a record is never lost at the boundary |
| Document vault (uploaded statements, receipts) | 7 years from the end of the assessment year | Same — supporting documents for a filed return, kept for one year longer than we currently understand the law to require |
| Account/role data | Duration of your active account, plus 1 year after closure | Data-minimisation principle; no statutory minimum applies |
| Payment records (plan, amount, date, reference) | 7 years from the date of payment | Financial and tax record-keeping. If you ask us to delete your account, we keep a payment record with your account link removed for this period. |
| Consent records (your consent to storage outside Nigeria, and each tick for an NHIS receipt) | 8 years from the date you gave consent | To prove that you agreed, and to defend legal claims. A consent record holds the date, your account ID, the wording version and, for the cross-border consent, a keyed fingerprint of your email. For a health-insurance receipt the record says you ticked the box; it never contains the receipt or what it shows. Delete My Data does not remove it. |
| Application logs | 90 days | Operational; logs carry a trace ID only, not your document content |
| Backups | Two kinds, kept separately. (1) Application server: weekly backups of our application server, each kept for 168 days (24 weeks) and then deleted. (2) Database: a daily copy of our database, encrypted so that only we can open it, stored with GitHub (see Sections 5 and 7) and automatically deleted after 14 days. Our database provider does not currently keep backups for us under our plan, so this daily copy is our database backup. | Operational recovery (disaster recovery only) |
If you have an active tax audit or dispute with the Nigeria Revenue Service, we may need to hold your records past the normal deletion point until that matter is formally closed — we will tell you if this applies to you.
Our policy is to delete, not to keep. We retain your document vault and computation records for the period set out above and no longer. We do not offer indefinite or open-ended retention, and KlaroTax is not a permanent archive for your records.
We are honest with you about how that is enforced today: deletion at the end of the retention period is currently carried out by our team as an operational process, and we are building automated expiry so that it happens without anyone having to run it. Until that automation is live, treat the period above as our commitment to you rather than as something a machine guarantees. You can delete your data yourself at any time, immediately, from Settings → Privacy & Data — that route is automated today and does not wait for any retention period.
Please keep your own copies of the documents you upload. Your own backup is the only copy that remains available to you once our retention window closes. That is your responsibility, not something KlaroTax manages for you beyond the period stated above.
7. Where your data is stored — cross-border transfers
Some of our infrastructure providers host data outside Nigeria:
| Provider | What it does | Where your data sits |
|---|---|---|
| Supabase | Our database and document storage | United Kingdom |
| KlaroTax servers | The computers our app and API run on | United Kingdom |
| Clerk | Sign-in, and keeping you signed in | United States |
| Sentry | Error monitoring, so we can find and fix bugs | Germany |
| GitHub | Storage of our encrypted daily database backup (kept 14 days) | United States (GitHub is owned by Microsoft) |
| Paystack | Taking your payment | Nigeria and other countries where Paystack and its providers operate, including Ireland (its cloud servers). Paystack is a Stripe company. |
For the backup copy held by GitHub, we add technical safeguards on top of the contractual ones described below: the copy is encrypted with a key that is kept offline by us and is never given to GitHub, so GitHub cannot read it; and it expires and is deleted automatically after 14 days.
Because the Nigeria Data Protection Commission (NDPC) has not formally designated the United Kingdom, the United States, or Germany as offering an automatic "adequate" level of data protection, we do not rely on an adequacy finding alone. Our approach is to secure these transfers using Cross-Border Data Transfer Instruments (CBDTIs) as contemplated under the Nigeria Data Protection Act — in practice, Data Processing Agreements (DPAs) with our infrastructure providers, which we require to include Standard Contractual Clauses (SCCs) or an equivalent contractual safeguard obligating each provider to protect your data to a standard materially equivalent to Nigerian law.
Paystack is a Nigerian-licensed payment company and sets its own transfer safeguards, which differ from the agreements above. Paystack states that it transfers personal data outside Nigeria to other Paystack entities and service providers, relying on the Nigeria Data Protection Act and its General Application and Implementation Directive, and on Binding Corporate Rules for transfers within its group. We have not separately confirmed the cross-border text of Paystack's data processing terms with us, and we rely on Paystack's published statements for the rest. Where we find a gap we will close it or tell you.
We are honest with you about where that stands today: we have not yet independently confirmed, provider by provider, that each of these agreements currently contains executed SCC-equivalent text — that confirmation exercise is under way. Where we find a gap, we will close it or tell you, rather than leave it undisclosed.
To complement these contractual safeguards, we also implement strict technical protections, including:
- Data minimisation & encryption — we encrypt direct identifiers and personal data both while resting on foreign servers and while travelling across networks (in transit).
- Access control — we enforce strict access management so that foreign infrastructure teams cannot access your raw personal information without authorisation.
- Impact assessments before high-risk processing — where we begin a new type of processing that the NDPA classifies as high-risk, such as open-banking account linking, we carry out a Data Protection Impact Assessment before that processing begins, as we did for our open-banking integration. We do not yet run these on a fixed recurring calendar; each is triggered by the processing activity that requires it.
8. How we protect your data
- Documents you upload — bank statements, receipts, and any other financial document — are encrypted at rest using AES-256-GCM as a whole file, from the moment they reach our storage. Where a document contains a BVN, NIN, TIN, bank account number, or your name, that information is protected as part of the encrypted document; KlaroTax does not currently extract and separately store these as structured identifier fields outside that encrypted file. If that changes, this section will be updated to describe the additional protection applied to those fields.
- Role-based access control and tenant isolation mean KlaroTax staff cannot browse your data outside of a legitimate support or audit-cooperation need.
- All connections to KlaroTax are encrypted in transit (HTTPS/TLS).
- We maintain an incident response process; if a breach affecting your personal data occurs, we will notify the Nigeria Data Protection Commission and affected users in line with the NDPA's breach-notification timelines (see Section 11).
9. Your rights
Under the NDPA, you have the right to:
- Access — see what personal data we hold about you.
- Correction — fix inaccurate data (for example, re-categorise a transaction our AI extracted incorrectly).
- Erasure ("right to be forgotten") — request deletion of your personal data. KlaroTax provides a self-service in-app deletion (Settings → Privacy & Data → Delete My Data), which: 1. Verifies it's really you (your authenticated session). 2. Logs the deletion request itself, before deleting anything. 3. Deletes your data from our audit, computation, and role tables. 4. Confirms which stores were cleared. Some records are kept as described in Section 6: payment records with your account link removed, and the record that you gave consent (date, account ID, wording version), which never contains a receipt or what it shows.
Document vault files follow within the timelines in Section 6. We target same-day automated deletion of the live copy of your data. Copies held in our backups are not deleted on the same day: they remain until those backups expire. For our database backups that is up to 14 days after you delete your data. For our application-server backups it can be up to 168 days (24 weeks). Backups exist only so that we can recover from a serious outage; we do not use them for any other purpose. This means that, for backup copies only, complete removal can take longer than 30 days. Some records may be exempt from immediate deletion if you have an active tax audit or legal proceeding (see Section 6).
- Objection / restriction — object to processing based on legitimate interest, or ask us to restrict processing while a dispute is resolved.
- Portability — you can ask for a copy of the personal data you have given us in a commonly used, machine-readable format. An in-app export is not yet available. Email privacy@krexant.com and within 30 days we will tell you how and when we can provide it; we are building a proper export.
- Withdraw consent — where processing relies on your consent, you can withdraw it at any time, without affecting the lawfulness of processing before withdrawal. For your consent to storage outside Nigeria (Section 7), use Settings → Privacy & Data. Because KlaroTax cannot sign you in or store your records without using providers located outside Nigeria, withdrawing that consent means we can no longer provide the service to you; we tell you this before you confirm. On withdrawal we sign you out and delete your KlaroTax data — your documents, transactions, computations and profile — from our database and document storage, subject only to the retention exceptions in Section 6. For NHIS premium receipts, withdrawing your consent means deleting the receipt. You can delete your NHIS receipt by using Delete My Data in Settings. This removes all your KlaroTax data, including the receipt, and cannot be undone. We intend to add a way to remove a single receipt on its own. If you cannot use the app, email privacy@krexant.com and we will verify it is you and help you delete your data. There is no separate in-app button to withdraw only this consent. We keep the record that you gave consent, as described in Section 6.
How withdrawal works today. When you withdraw your consent in the app (Settings → Privacy & Data), the app records your withdrawal, then deletes your KlaroTax data and signs you out, as one continuous process; you do not need to wait for us. If anything interrupts that process (for example, you lose your connection part-way), the app tells you, and you should email privacy@krexant.com: we will complete the deletion ourselves and confirm to you in writing within 30 days. Two things are handled separately and are described elsewhere: your sign-in record with Clerk (next paragraph), and copies of your data that remain in our backups for a limited period (Section 6 and above).
We want to be precise about one thing rather than leave you to assume it: your sign-in record with Clerk, our authentication provider (your name, email address and encrypted password, and nothing else), is not deleted by the in-app deletion. Today we delete it by hand. To have it erased, email privacy@krexant.com from the address you signed up with; we will verify it is you, delete the record, and confirm to you in writing within 30 days. Until you do, Clerk keeps that record and your email address will still be recognised if you try to sign in again. We are building automatic deletion of this record into the in-app process and will update this policy when it is live.
To exercise any of these rights beyond the in-app tools, contact our Data Protection Officer (see Section 13).
Payments and deleting your account. When you ask us to delete your account we delete your account data and your plan. We keep a record of each payment (amount, plan, date and payment reference, with your account link removed) for 7 years, because tax and accounting rules require it. Our security log also keeps a payment event under your sign-in ID; that ID identifies you only while your sign-in record exists, and deleting your sign-in record is part of how we handle an account-deletion request. Deleting your data in the app does not delete what Paystack holds about your payment. Nigerian law requires Paystack to keep transaction records for at least 5 years after the transaction, and identification records for 7 years after the relationship ends, so it cannot erase them earlier on request. Ask Paystack directly about its copy (see its privacy policy).
10. Children's data
KlaroTax is not directed at or intended for use by minors. Our services are intended for individuals of legal working/taxpaying age in Nigeria. We do not knowingly collect personal data from children. If we learn we have inadvertently collected data from a minor, we will delete it promptly.
11. What happens if there's a data breach
If a breach occurs that is likely to compromise the confidentiality, integrity, or availability of your personal data, we will assess it under our internal Incident Response Playbook and, where required, notify the Nigeria Data Protection Commission and affected users without undue delay, consistent with NDPA notification timelines.
12. Changes to this policy
We will update this policy as our practices, the law, or our processors change, and will post the effective date at the top. Material changes will be flagged in-app.
13. Contact us / Data Protection Officer
Krexant Platforms Ltd's designated Data Protection Officer for KlaroTax is Emmanuel Olatinwo. For any privacy question, data-rights request, or complaint:
- In-app: Settings → Privacy & Data
- Email: privacy@krexant.com
- Post: Krexant Platforms Ltd, 4 OAU Street, 900107, Abuja, Nigeria
You may also lodge a complaint directly with the Nigeria Data Protection Commission (NDPC) if you believe we have not handled your data lawfully.
Krexant Platforms Ltd has assessed itself as a data controller of major importance under the Nigeria Data Protection Act 2023 and is in the process of registering with the Nigeria Data Protection Commission. We will update this policy once that registration is completed.