TaxStreem Privacy Policy

Last updated: December 2025 | Archived versions | Download PDF

Country version: Nigeria

Introduction

Welcome to TaxStreem. We are committed to safeguarding your privacy and ensuring the security of your personal data. Hence, this privacy policy explains what personal information we collect, why we collect it, how we use and disclose it, your choices, any rights you may have, and how you can contact us about our privacy practices. This privacy policy does not apply to third-party websites, products, or services, even if we provide links to them or they link to us.

The privacy policy is issued in line with the Nigeria Data Protection Act (NDPA) 2023 and the NDPA- General Application and Implementation Directives (GAID) 2025 and other relevant data protection laws and regulations in Nigeria.


Legal Bases for Processing

We rely on different lawful bases for processing personal data, depending on the purpose of processing, including contractual necessity, legal obligation, legitimate interest, and consent, in accordance with the Nigeria Data Protection Act (NDPA) 2023

Consent

Where required, consent is appropriate at sign-up or in the account settings. In this case, consent is freely given, specific, informed, unambiguous, and obtained through a clear affirmative action (an unticked checkbox the user chooses to tick), and users are able to withdraw it at any time. Withdrawing consent will not affect the lawfulness of any processing carried out before the withdrawal, but it may affect our ability to provide you with certain optional features or services that rely on that consent

Performance of a Contract

We process your personal data where this is necessary to enter into and perform a contract with you, or to take steps at your request. In particular, we use your information to:

  • create and manage your user account;
  • provide our tax calculation, preparation and filing services, including collecting the information required to complete your tax returns and submitting them to the relevant tax authorities on your instructions;
  • provide customer support, respond to your enquiries, and communicate with you about your use of our services; and
  • process payments, issue invoices and manage subscriptions or service plans.

If you do not provide the personal data that we need for these purposes, we may be unable to provide some or all of our services to you.

What Personal Information We May Collect About You

In the bid to serve you better, your personal information disclosed by you on our webapp will be collected.

Information You Provided Directly
  • When you create an account with us, we collect your full name, email address, phone number, and business information where applicable.
  • For tax-related purposes, we collect comprehensive information, including your TIN, your income details such as salary, business income, and investments. We also collect invoices, receipts, and expense records, financial statements, tax returns, and supporting documents.
  • When you integrate your bank account with our Platform, we collect bank account numbers, account holder names, financial statements, and banking credentials necessary for account linking.
Information We Collect Automatically
  • When you link your email to your account, we collect email metadata, including sender, recipient, date, and subject lines. We also extract invoice attachments and financial documents, tax-related correspondence, and email authentication tokens necessary to maintain the connection from your email.
  • Our Platform automatically collects technical information, including your IP address, device type and operating system, browser type and version, platform usage patterns, and log files and analytics data.
  • We use cookies and similar tracking technologies to enhance your experience. You can manage cookie preferences through your browser settings.
Information from Third Parties

We may receive information about you from financial institutions such as banks, from FIRS and other tax authorities, where applicable and from payment processors.

How Do We Collect Your Data

The personal information we have about you is directly made available to us when you:

  • Sign up on our web app;
  • Use any of our services;
  • Contact our customer support team;
  • Fill out our online forms;
  • Contact us.

The lawful basis we rely on for processing your personal information are:

  • Your consent: Where you agree to us collecting your personal information by using our Services.
  • We have a contractual obligation: Without your personal information, we cannot provide our Services to you.

How We May Use Your Personal Information

Primary Purposes
  • We use your information to calculate your tax liabilities accurately, generate tax reports and summaries, prepare and file tax returns with FIRS, track filing status and refunds, and maintain tax compliance records.
  • Our AI-powered platform analyzes financial documents using artificial intelligence, extracts invoice data from emails automatically, and identifies tax deductions and credits.
  • For account management purposes, we use your information to create and maintain your user account, authenticate your identity, provide customer support, send service-related notifications, and process payments for our services.
  • We communicate with you to respond to your inquiries and requests, send tax deadline reminders, provide platform updates and announcements, and share important changes to our services or policies.
Secondary Purposes
  • We analyze your information to improve our services by studying platform usage and performance, developing new features and functionality, conducting research and analytics, and improving AI model training and accuracy.
  • We use your data to detect and monitor security threats, protect against unauthorized access, and verify user identities.
  • To ensure legal compliance, we process your information to comply with tax laws and regulations, respond to regulatory requests, and maintain records as required by law.

Data Security and Retention

The security of your personal information is important to us. We are committed to protecting the information we collect. We maintain administrative, technical and physical controls designed to protect the personal information you provide, or we collect against loss or theft, as well as against any unauthorized access, risk of loss, disclosure, copying, misuse or modification.

We employ industry-standard encryption measures, including Advanced Encryption Standard (AES-256) for data at rest and Transport Layer Security (TLS) for data in transit. We maintain advanced firewall protection systems and implement role-based access controls to restrict data access. Multi-factor authentication is required for all sensitive operations. Regular encrypted backups are performed with comprehensive disaster recovery procedures in place.

Where you use a password for any of your accounts, please ensure you do not share this with anyone, and the password is kept confidential at all times.

Where it is necessary to access third-party platforms, including tax authority portals or financial institutions, TaxStreem does not require or encourage users to share permanent login credentials where secure alternatives are available. Access is obtained through secure authorization mechanisms such as user-initiated login flows, authorization tokens, or other industry-accepted secure access methods.

Any access granted to TaxStreem is limited to the minimum scope necessary to perform the requested services and may be revoked at any time through your account settings or by contacting us.

Where temporary credentials are provided, they are encrypted, access-restricted, and used solely for the specific transaction authorized by you.

We are committed to conducting our business in accordance with these principles in order to ensure that the confidentiality of your personal information is protected and maintained. Transmitting information online is not entirely secure. As such, we cannot guarantee that all information provided online is secure. We would take all reasonable steps to ensure that your personal information is secured and well-protected.

We will only retain personal information on our servers for as long as is reasonably necessary to provide services to you. Where required by law, tax records and related information may be retained for up to six (6) years, after which the data is securely deleted or anonymized unless further retention is required by law.

Marketing

We may process your personal information in order to contact you or send you marketing content and communication about our products, services, or surveys. You may exercise your right to object to such contact from us or opt out of the marketing content. Please note, however, that if you opt out of marketing content, we may still send you messages relating to transactions and our services related to our ongoing business relationship.

We may ask you for permission to send notifications to you. Our services will still work if you do not grant us consent to send you notifications.

Your Data Protection Rights and Choices

Based on the applicable laws, below are the rights you have as a user in relation to the processing of your personal information:

  • Right to be informed;
  • Right to request access to the personal information we hold about you;
  • Right to request that TaxStreem erase your personal information. Please note that this is a limited right which applies where the data is no longer required, or the processing has no legal justification. The exceptions to this right are where the applicable law requires TaxStreem to retain a historical archive or where we retain a core set of your personal information to ensure we do not inadvertently contact you in the future where you object to your data being used for marketing purposes.
  • Right to correct or rectify any personal information that you provide which may be incorrect, out of date, or inaccurate. You also have the right to ask us to complete information you think is incomplete.
  • Right to object to the processing of your personal information for marketing purposes. You have a right to ask us not to contact you for marketing purposes by opting out via the unsubscribe link in marketing emails we send you.
  • You have the right to object to the processing of your Personal Information in certain circumstances. Please note that where you object to us processing your personal information, we might be unable to provide services to you.
  • You have the right to withdraw consent at any time, though this may affect service availability.
  • Where technically feasible, you also have the right to request that we transmit your personal data directly to another data controller.
  • Finally, you have the right to complain and may file a complaint with the Nigeria Data Protection Commission where there is a breach of privacy. (complaints@ndpc.gov.ng)
  • To exercise these rights, please contact us using the details of our DPO in the last section of this Privacy Policy.

We aim to respond to all privacy-related requests and complaints within a reasonable timeframe, typically within thirty (30) days

Cookies

Cookies are small text files stored on your device that help us provide and improve our services.

We use essential cookies that are required for platform functionality. Performance cookies help us understand how users interact with our platform. Functional cookies remember your preferences and settings. Analytics cookies provide insights into platform usage patterns.

You may control cookies through your browser settings. However, disabling certain cookies may affect platform functionality and your user experience.

Automated Processing

The platform has integrated AI for automated processing to support certain operational, security, and analytical functions. Certain classification models that affect transaction information are enabled by default where such processing is necessary for the performance, security, and integrity of transactions conducted on the platform.

Other classification models that do not affect transaction information are not enabled by default and are applied only where a user has expressly opted in or otherwise accepted such processing. TaxStreem does not make decisions based solely on automated processing that produces legal or similarly significant effects on users without appropriate human involvement, except where such processing is strictly necessary for the performance of a contract or compliance with legal obligations.

All tax calculations, classifications, and filing outputs generated by automated systems are subject to user review and, where applicable, human oversight before submission to tax authorities.

You have the right to request human intervention, express your point of view, or contest the outcome of automated processing by contacting us through the details provided in this Privacy Policy.

Minors

This website and applications are not directed at persons under the age of eighteen (18), and we do not collect any personal information knowingly or directly from minors who fall within this category.

Where you believe that TaxStreem has mistakenly or unknowingly collected information from a minor, please contact us immediately so we can investigate and restrict such data.

International Data Transfers

Currently, your data is stored and processed within Nigeria. If we transfer data outside Nigeria in the future, we will ensure adequate data protection safeguards, obtain your explicit consent, comply with NDPA requirements for cross-border transfers, and notify you of such transfers.

Third-Party Data Sharing

We do not sell, disclose personal data to third parties except as strictly necessary to fulfill our legal and regulatory obligations. In particular, personal data collected through the platform may be shared with the relevant tax authority solely for the purpose of preparing, submitting, and filing tax returns or tax-related information on the tax authority's official website, in accordance with applicable tax laws.

Such disclosure is limited to the minimum personal data required to complete the tax filing process and is carried out securely.

Updates to our privacy policy

From time to time, we may change, amend, or review this privacy policy periodically to reflect new services or changes in our privacy policy and place any updates on this page. All changes made will be posted on this page, and where changes will materially affect you, we will notify you of this change by placing a notice online or via mail. If you keep using our services, you consent to all amendments of this privacy policy.

Contact Us

All access requests, questions, comments, complaints, and other requests regarding data privacy and this policy should be sent to dpo@taxstreem.com

We may request additional details from you regarding your complaints and keep records of your requests and their resolution.

This Privacy Policy was last updated in December 2025