01Regulatory Framework
Our operations are governed by, and aligned with, the following Nigerian laws and standards:
- Nigeria Data Protection Act 2023 (NDPA);
- Nigeria Data Protection Regulation 2019 (NDPR);
- NDPC General Application and Implementation Directive (GAID) 2025;
- Money Laundering (Prevention and Prohibition) Act 2022;
- The regulatory framework of the Central Bank of Nigeria (CBN), via our licensed banking and open-banking partners.
02Registrations & Licences
Corporate Registration
Raavon Limited is registered with the Corporate Affairs Commission of Nigeria under RC-9537604.
SCUML / Anti-Money Laundering
Raavon Limited is registered with the Special Control Unit Against Money Laundering (SCUML), under the Economic and Financial Crimes Commission (EFCC), in accordance with Section 17(2)(a) of the Money Laundering (Prevention and Prohibition) Act 2022.
- SCUML Registration Number: SC 251523895;
- Date of issue: 8 June 2026.
03Data Protection
We process personal data lawfully, fairly and transparently under the NDPA 2023, and we have appointed a Data Protection Officer responsible for compliance, the Record of Processing Activities, regulator liaison and breach coordination.
- Data Protection Officer: privacy@raavon.com;
- Data subjects can access, correct, port, restrict, object to and erase their data, and withdraw consent at any time;
- Personal data breaches that pose a risk are notified to the NDPC within 72 hours.
Read our full Data Protection Policy
04Information Security
We maintain an Information Security Policy aligned with recognised hardening standards (NIST, ISO 27001 / CIS Benchmarks). Core controls include:
- Encryption of data in transit (TLS 1.2 or higher) and at rest;
- Role-based access control and least privilege, with unique user IDs;
- Multi-factor authentication on critical systems, cloud consoles, code repositories and production environments;
- Centralised logging, monitoring and alerting, with audit logs retained;
- A formal change-control process, with protected repositories and mandatory review before merge;
- Secure application development aligned with the OWASP Top 10, and periodic penetration testing;
- Secure data retention and disposal.
Klario is not a bank and does not store your bank login credentials. Financial data is accessed on a read-only basis through licensed open-banking partners.
05Anti-Fraud
We operate a zero-tolerance Anti-Fraud, Bribery & Corruption policy across the company and all of its ventures, with mandatory reporting, confidential whistleblowing and thorough investigation of every reported incident.
Read our full Anti-Fraud Policy
06Records & Policies
We maintain a Record of Processing Activities (RoPA) documenting every processing activity, its lawful basis, recipients, transfers and retention, reviewed at least annually. Our full policy set includes:
- Data Protection Policy (RAAVON/DPP/2026);
- Information Security Policy (RAAVON/ISP/2026);
- Anti-Fraud, Bribery & Corruption Policy;
- Record of Processing Activities (RAAVON/ROPA/2026).
The Information Security Policy and Record of Processing Activities are internal compliance documents; summaries are provided above and full copies are available to regulators and partners on request.
07Contact
Raavon Limited (RC-9537604)
Compliance & data protection: privacy@raavon.com
General: contact@raavon.com
Parent Company: www.raavon.com
