Skip to content
Legal

ePoynt Data Protection & Processing

NDPR-aligned. Covers every ePoynt product, in sandbox and production.

Last updated: 28 Aug 2026 Provider: ePoynt Technologies Ltd (RC 9009902), Abuja, Nigeria Scope: Processing of customer data across every ePoynt product — TaxPoynt (SI, AP and Hybrid e-invoicing) and FleetPoynt (the vehicle register) — in sandbox and production.

Read this together with the ePoynt Privacy Policy and, for a fleet register, the FleetPoynt Privacy Notice. Those state what we hold and why. This document states the terms on which we process it for you.

1. Roles

  • You are the data controller for your organisation's data. ePoynt Technologies Ltd is the processor. In limited cases we are a controller where the law requires it, such as fraud and abuse prevention.
  • Our products hold personal data about people who never sign in: a driver, a custodian, a buyer named on an invoice. You remain the controller for those people. Send us a request from one of them and we will support you in answering it, but the answer is yours to give.

2. Processing purposes

Every product. Reliability, security and support: monitoring, alerting, and incident response. Our own staff access is least-privilege, and is used only for support and incident response.

TaxPoynt. Deliver e-invoicing: ingest canonical invoices, generate the IRN and QR, validate with FIRS, archive and audit, and deliver callbacks. Meet the legal and regulatory duties that attach to that work, including FIRS retention and validation.

FleetPoynt. Deliver the vehicle register: keep the register, derive expiry and service-due warnings, send alerts and the weekly digest, send a custodian a reminder about their own vehicle over WhatsApp where they have agreed to it, produce log books and the monthly management report, and export your data when you ask for it.

We do not use your records for advertising. We do not sell them. We do not use one organisation's data to serve another.

3. Data handling controls

  • Transport. TLS 1.2 or later on every public endpoint, with managed certificates and automated renewal. HSTS and hardened response headers on the API.
  • At rest. Managed PostgreSQL with provider-level disk encryption. Object storage encrypted at rest by the storage provider.
  • Sign-in. Multi-factor sign-in with an authenticator app, plus single-use backup codes. Passwords are hashed with bcrypt. Sessions ride httpOnly cookies that page scripts cannot read.
  • Secrets. Secrets and keys are never shown in the interface. API keys are stored as one-way hashes, shown once at issuance, and held per organisation and per environment.
  • Tenant isolation. Every read is scoped to your organisation. Sandbox and production are isolated from each other. Access inside your organisation is role-based. Where a product narrows access further — a FleetPoynt custodian sees only the vehicle they hold — that boundary is enforced in code and checked automatically on every change we ship.
  • Logging and audit. Logs are redacted and carry no secrets. Audit rows record the actor, the timestamp, and the old and new value. Audit rows are never updated and never deleted.
  • Documents. Uploaded documents are held in private storage with no public address. They are read through short-lived signed links, issued one request at a time to someone who already has access.
  • Minimal payloads. Where a product sends a callback, it carries only the fields the receiver needs.

4. Subprocessors

  • Limited to infrastructure, email, messaging and observability providers, each vetted for security posture.
  • A current list, naming each provider and the region it operates in, is provided in your agreement or on request.
  • We tell you before a new subprocessor begins processing your data.

5. Cross-border transfer

Our infrastructure is outside Nigeria, so processing your data is a cross-border transfer under the NDPR. These terms govern that transfer and impose contractual safeguards on every subprocessor.

Where each store is held is stated once, in the ePoynt Privacy Policy section 6 and in the FleetPoynt Privacy Notice section 9. This document does not repeat those regions. A residency claim held in several places drifts, and ours has been corrected twice for exactly that reason. Exact regions are available on request for your due-diligence file.

6. Retention and deletion

  • Retention follows your contract and the law that applies to the record.
  • On termination, or on written request where permitted, we delete or return your data, subject to legal holds.

⚠️ In an append-only product, deletion means something specific, and we would rather state it than have you discover it.

A FleetPoynt register cancels a mistaken entry rather than erasing it. The entry leaves the working register and stops affecting any figure, but it stays in history so the audit trail is not broken. A vehicle is never hard-deleted; a disposal is a recorded status change carrying its own approval trail. Deactivating a driver keeps the record, because trip history points at it.

So a deletion request may be answered by cancellation and restriction rather than erasure, where the record belongs to an audit trail your organisation must keep. Where erasure is lawful and possible, we do it. Where it is not, we name the duty that prevents it and say what we can do instead. The FleetPoynt Privacy Notice section 7 states this in full.

7. Return and portability

  • A FleetPoynt register exports to CSV from inside the product, on every plan, with no export fee: vehicles, maintenance, insurance, statutory papers, drivers, movements, fuel and disposals. Log books and the monthly management report print as PDF.
  • Where a product has no self-service export, we return your data on written request in a structured, commonly used format.
  • Your records are an institutional record that must outlive any one supplier, including us.

8. Breach notification

  • We notify you of a security incident with material impact without undue delay, following your contract and the law.
  • The notification says what happened, which data was affected, what we have done, and what we recommend you do.

9. Data subject rights (NDPR)

  • We support access, correction, deletion where legally permissible, restriction, and portability.
  • Where the request concerns somebody who does not hold a sign-in — a driver, a custodian, a buyer named on an invoice — your organisation is the controller. Send the request to them. We support them in answering it.
  • To raise a request with us: info@epoynt.com.

10. Contact

For data-processing questions, our subprocessor list, or a signed DPA for your due-diligence file: info@epoynt.com.

ePoynt Technologies Ltd (RC 9009902), Abuja, Nigeria.