Legal
Gbanjo Data Retention Schedule
This Data Retention Schedule explains how long Griid Network LTD, trading as Gbanjo ("Gbanjo", "we", "us", or "our"), keeps each category of personal data and what happens when the period ends. It supplements the Gbanjo Privacy Policy. Where this Schedule gives a more specific period than the Privacy Policy, this Schedule governs from its effective date.
This Schedule applies to the Gbanjo mobile applications, public website, marketplace, support channels, and related services.
1. Governing framework
This Schedule is based primarily on the Nigeria Data Protection Act 2023 and the Nigeria Data Protection Commission General Application and Implementation Directive 2025.
The Nigeria Data Protection Commission (NDPC) is Nigeria's data-protection regulator. References to the Nigeria Data Protection Regulation 2019 (NDPR) are read subject to the NDP Act 2023 and current NDPC guidance; the NDPR is not the sole authority for this Schedule.
Other laws may require particular commercial records to be kept for a defined period. Those requirements apply only to the records they govern and do not permit Gbanjo to retain an entire user profile indefinitely.
2. Retention principles
Gbanjo will:
- collect and retain only the personal data needed for a stated lawful purpose;
- assign a retention trigger and period to each data category;
- restrict retained records to authorized personnel and approved processors;
- delete personal data or irreversibly de-identify it when its purpose and lawful basis end;
- keep aggregated information only where it can no longer identify a person;
- document every legal hold, its scope, owner, reason, review date, and release date;
- prevent retained legal or security records from being reused for marketing or unrelated profiling.
"Deletion" means removal from active systems and instruction to relevant processors to delete the data where Gbanjo controls that processing. "De-identification" means an irreversible process that prevents the data from being linked back to a person using reasonably available means.
3. Retention schedule
| Data category | Retention period or trigger | Action at the end of the period |
|---|---|---|
| Account and profile data, including name, username, email, phone, and avatar | While the account is active. After a verified deletion request, normally no later than 30 days unless a documented exception applies | Delete direct identifiers and public profile content, or irreversibly de-identify records that must remain linked to retained transactions |
| Authentication credentials, sessions, passkeys, linked sign-in identities, device registrations, and push tokens | While needed to secure an active account; revoke when account deletion is completed or access is closed | Revoke and delete from active authentication systems |
| Draft listings and unpublished uploads | 90 days after the draft or upload is abandoned, or on completed account deletion if earlier | Delete the draft content and associated media |
| Closed listings that did not result in a transaction | 12 months after closure, unless attached to a fraud, moderation, or legal case | Remove public seller identity and delete media that is no longer required |
| Auctions, bids, orders, deposits, payments, refunds, payouts, invoices, fees, and settlement records | The later of six years from record creation or six years after the relevant tax assessment period, where applicable; longer only under a documented legal hold | Retain the minimum accounting and transaction record with a pseudonymous account reference; remove unrelated profile data |
| Transaction chat | 24 months after transaction completion. Selected messages may be retained longer only when necessary for an active dispute, fraud investigation, or legal claim | Delete ordinary conversation content; retain only case-relevant extracts under the applicable case hold |
| Disputes, chargebacks, fraud, shill-bidding, safety reports, and enforcement evidence | Until final resolution, then only for the applicable legal-claim or statutory record period | Delete or de-identify when the case and any documented hold expire |
| Identity-verification metadata held by Gbanjo | While verification remains relevant and ordinarily up to 24 months after account closure. If an applicable anti-money-laundering obligation requires a longer period, retain only the required record for that period | Delete verification metadata and keyed identifiers. Gbanjo does not retain raw identity documents or selfies received through the hosted verification provider |
| Ordinary customer-support records | 24 months after the case closes | Delete or de-identify unless the record forms part of a transaction, dispute, security incident, or legal hold |
| Ordinary application and operational logs | 90 days | Automatically delete or aggregate without user identifiers |
| Security-incident evidence | For the duration of the investigation and up to 24 months after closure, unless legal proceedings or a lawful request require longer | Delete or de-identify when the incident hold expires |
| Traffic or subscriber information specifically covered by section 38 of the Cybercrimes Act | Two years only where that statutory category and service-provider obligation applies | Delete when the statutory period expires unless subject to a valid legal hold |
| User-level analytics and crash diagnostics | No longer than 14 months, subject to available provider controls and user consent where required | Delete, expire, or irreversibly aggregate; do not include passwords, payment credentials, message contents, or raw identity documents |
| Marketing consent and preference records | While the preference remains current; evidence of consent or withdrawal may be retained for six years where needed to demonstrate compliance | Keep only the minimum suppression or consent record needed to honor the user's choice |
| Account-deletion request audit record | Six years after completion | Retain only the request identifier, timestamps, outcome, and documented legal basis for any exception; do not retain the deleted profile as proof |
| Cookies and similar browser storage | For the lifetime disclosed in Gbanjo's cookie controls, and only after consent for non-essential categories | Expire or delete the cookie and associated user-level data |
| Backup copies, if introduced | A documented rotation period not exceeding 90 days | Expire the backup securely; deleted data must not be restored to active use and must be removed again after any authorized restoration |
"Transaction completion" means the latest applicable completion point for the order, refund, chargeback, payout, dispute, or enforcement review.
4. Account deletion
After Gbanjo verifies an account-deletion request, we will identify the data connected to that account and separate data that can be deleted from records that must lawfully remain.
We will normally complete the request within 30 days. Completion includes:
- closing access to the account;
- revoking active sessions, passkeys, linked sign-in identities, and push registrations;
- removing public profile identifiers;
- deleting drafts and other data that no longer has a lawful purpose;
- replacing the account identity in retained commercial records with a restricted pseudonymous reference where feasible;
- recording a minimal audit receipt showing that the request was completed.
If an open payment, refund, payout, delivery, dispute, investigation, legal obligation, or legal hold prevents deletion of a specific record, Gbanjo will retain only the affected record and will explain the reason where legally permitted. The exception does not authorize blanket retention of unrelated account data.
5. Legal holds
A legal hold pauses deletion only for the specific records needed for:
- a legal or regulatory obligation;
- a valid request from an authorized public body;
- an active dispute, chargeback, fraud, security, or marketplace-integrity investigation;
- the establishment, exercise, or defence of a legal claim.
Every hold must identify the affected data, lawful basis, responsible owner, start date, review date, and release condition. Holds are reviewed periodically and released when the reason ends. Indefinite or account-wide holds without a documented basis are not permitted.
6. Service providers and international processing
Where a service provider processes personal data for Gbanjo, Gbanjo will use contractual and technical controls appropriate to that processing. Gbanjo will send deletion or restriction instructions to processors where Gbanjo controls the relevant data and the retention period has ended.
An independent provider may have its own legal retention duties. Where that applies, the provider is responsible for explaining its independent processing in its privacy information.
7. Your rights
You may ask Gbanjo to access, correct, delete, restrict, or provide information about your personal data, subject to applicable law.
To submit a request, email privacy@gbanjo.auction or use the account-deletion option in the Gbanjo app. We may verify account ownership before acting on a request.
If you are dissatisfied with Gbanjo's response, you may complain to the Nigeria Data Protection Commission.
8. Authorities and source legislation
- Nigeria Data Protection Commission
- Nigeria Data Protection Act 2023
- NDPC General Application and Implementation Directive 2025
- Nigeria Tax Administration Act 2025
- Companies and Allied Matters Act 2020
- Cybercrimes Act 2024
- SCUML Regulations 2022
The Cybercrimes Act and anti-money-laundering periods apply only where Gbanjo and the relevant record fall within their scope.
9. Contact
Griid Network LTD 7 Ibiyinka Olorunbe, Victoria Island, Lagos Privacy: privacy@gbanjo.auction Support: support@gbanjo.auction