Security Protocol File

Privacy Policy Document

JAMAZAVI PETROLEUM & ENERGY TRADING • Effective Date: May 21, 2026

01 // Introduction

JAMAZAVI LIMITED ("Company," "we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website www.jamazavi-petroleum-energy.com (the "Website") or engage our petroleum trading, buyer-sourcing, and mandate representation services (collectively, the "Services").

This Privacy Policy complies with:
The Nigeria Data Protection Regulation (NDPR) 2019
The General Data Protection Regulation (GDPR) (EU) 2016/679 (where applicable)
The African Union Convention on Cyber Security and Personal Data Protection
Applicable petroleum industry data protection standards.

02 // Information We Collect

We may collect the following categories of personal information across our standard workflows:

[A] Identity & Contact

• Full name, title, and job position
• Company name, registration number, and business address
• Email address, telephone number, and WhatsApp contact
• Nationality and country of residence

[B] Business & Professional

• Petroleum import/export license numbers and expiry dates
• Company financial statements and bank references
• Tax identification numbers and VAT/GST registration details
• Business banking details for transaction processing
• Trade references and commercial history

[C] Transactional Parameters

• Purchase orders, Letters of Intent (LOIs), and supply agreements
• Product preferences, volume requirements, and delivery specifications
• Pricing negotiations and contract terms
• Payment records, invoice details, and commission calculations
• Shipping and logistics documentation

[D] Technical & Usage

• Purchase orders, Letters of Intent (LOIs), and supply agreements
• Product preferences, volume requirements, and delivery specifications • Pricing negotiations and contract terms
• Payment records, invoice details, and commission calculations
• Shipping and logistics documentation

[E] COMMUNICATION DATA

• Email correspondence and chat transcripts
• Meeting notes and call recordings (with prior consent)
• Feedback, complaints, and survey responses

[!] Sensitive Personal Data:We generally do not collect sensitive personal data (e.g., racial or ethnic origin, political opinions, religious beliefs, health information, biometric data). If such data is voluntarily provided, we will process it only with your explicit consent and in accordance with applicable law.

03 // HOW WE COLLECT YOUR INFORMATION

  • Direct Interaction:
    • Website contact forms, registration forms, and LOI submissions
    • Email, telephone, WhatsApp, and video conference communications
    • In-person meetings and trade show interactions
    • Signed contracts, agreements, and official correspondence
  • Automated Technologies:
    • Cookies, web beacons, and server logs
    • Google Analytics and similar analytics tools
    • Security monitoring and fraud detection systems
  • Third-Party Sources:
    • Business directories and industry databases
    • Credit reference agencies and financial institutions
    • Regulatory bodies and licensing authorities
    • Publicly available corporate records and LinkedIn profiles
    • Mutual business introductions and referrals

04 // Legal Basis For Data Processing

We process your personal data based on the following clear legal grounds defined under regulatory guidelines:

Contractual Necessity (Article 6(1)(b) GDPR / NDPR Section 2.1(a))

Processing is necessary to perform our contract with you or to take essential steps at your request before entering into a contract (e.g., preparing supply proposals, evaluating LOIs, and executing mandate agreements).

Legal Obligation (Article 6(1)(c) GDPR / NDPR Section 2.1(b))

Processing is mandatory to comply with statutory legal frameworks, including Anti-Money Laundering (AML) checks, Know-Your-Customer (KYC) compliance, refinery regulations, tax record keeping, and court investigations.

Legitimate Interests (Article 6(1)(f) GDPR / NDPR Section 2.1(d))

Processing necessary for our legitimate business interests, provided your interests and fundamental rights do not override those interests, including:
• Business development and buyer-sourcing activities
• Fraud prevention and security
• Network and information systems security
• Marketing and relationship management

Consent (Article 6(1)(a) GDPR / NDPR Section 2.1(e))

Where you have given explicit consent, such as for:
• Marketing communications and newsletters
• Sharing data with specific third-party partners
• Processing sensitive personal data
• Call recordings and video conferencing storage

05 //HOW WE USE YOUR INFORMATION

We use your personal data for the following specific business and technical operations:

[5.1] Service Delivery

• Processing buyer registrations, LOIs, and supply proposals
• Facilitating petroleum product transactions and mandate agreements
• Coordinating logistics, shipping, and delivery arrangements
• Managing commission calculations and payments
• Providing customer support and account management

[5.2] Compliance & Risk Management

• Conducting due diligence, KYC, and AML verification
• Verifying import licenses and regulatory compliance
• Assessing creditworthiness and financial capacity
• Detecting and preventing fraud, bribery, and corruption
• Maintaining audit trails and regulatory records

[5.3] Business Development

• Identifying and qualifying potential buyers and partners
• Analyzing market trends and buyer preferences
• Developing new products and service offerings
• Conducting market research and competitive analysis

[5.4] Communications

• Responding to inquiries and providing transaction updates
• Sending contractual notices, invoices, and payment reminders
• Distributing industry insights, market reports, and newsletters
• Inviting to events, webinars, and trade shows

[5.5] Website Improvement & Security

• Analyzing user behavior and website performance
• Troubleshooting technical issues and optimizing functionality
• Personalizing user experience and content recommendations
• Ensuring website security and preventing cyber threats

06 // Information Disclosure Safeguards

We do not sell data logs to generic marketing aggregators. We may share your personal data with the following categories of recipients:

6.1 Refinery Partners & Suppliers

  • • Dangote Petroleum Refinery & Petrochemicals FZE
  • • Other petroleum refineries and production facilities
  • • Product inspection agencies (SGS, Intertek, Bureau Veritas)
  • • Shipping lines, vessel operators, and port authorities

6.2 Financial & Professional

  • • Banks and financial institutions for transaction processing
  • • Insurance providers for cargo and credit risk coverage
  • • Legal advisors and dispute resolution services
  • • Accounting and audit firms
  • • Credit reference agencies

6.3 Regulatory & Governmental

  • • Nigerian National Petroleum Corporation (NNPC) and regulatory bodies
  • • Petroleum regulatory authorities in buyer jurisdictions
  • • Tax authorities and customs departments
  • • Law enforcement and anti-corruption agencies (where legally required)
  • • Courts and tribunals in connection with legal proceedings

6.4 Business Partners & Affiliates

  • • Joint venture partners and co-brokers (with contractual safeguards)
  • • Affiliated companies within the JAMAZAVI group
  • • Professional associations and industry bodies (anonymized where possible)

6.5 Technology & Service Providers

• Website hosting and cloud storage providers
• Customer relationship management (CRM) platforms
• Email and communication service providers
• Cybersecurity and fraud prevention services
• Data analytics and business intelligence tools

6.6 Corporate Transactions: In the event of a merger, acquisition, asset sale, or business restructuring, we may transfer your personal data to the relevant third party, subject to confidentiality obligations.

07 // International Data Transfers

As a petroleum trading company operating across Africa and international markets, your personal data may be transferred to and processed in countries outside your country of residence, including:

  • Nigeria (our primary operating jurisdiction)
  • Other African countries where buyers and partners are located
  • European Union, United Kingdom, United States, and Middle East
  • Countries where refineries, shipping operators, and financial institutions are headquartered

We ensure appropriate safeguards for international transfers through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission.
  • Adequacy decisions by the European Commission or Nigerian Data Protection Bureau.
  • Binding corporate rules for intra-group transfers[cite: 20].
  • Contractual commitments from third-party processors[cite: 20].

08 // Cookies & Tracking Protocols

8.1 What Are Cookies?

Cookies are small text files placed on your device when you visit our Website. They help us recognize your device, remember your preferences, and improve your experience.

8.2 Types of Cookies We Use

[A] Strictly Necessary Cookies

Essential for Website functionality. Cannot be disabled. Examples include session management, security authentication, and load balancing.

[B] Performance Cookies

Collect anonymous data on Website usage to help us improve performance. Examples include Google Analytics and page load time monitoring.

[C] Functionality Cookies

Remember your preferences and settings for an enhanced experience. Examples include language selection, form auto-fill, and display preferences.

[D] Targeting/Advertising Cookies

Used to deliver relevant advertisements and measure campaign effectiveness. Examples include LinkedIn Insight Tag and Google Ads conversion tracking.

8.3 Cookie Consent

Upon first visiting our Website, you will see a cookie consent banner. You may choose to:

  • • Accept all cookies
  • • Reject non-essential cookies
  • • Customize preferences by category

You can modify your cookie preferences at any time through the "Cookie Settings" link in our Website footer.

8.4 Third-Party Cookies

Our Website may include content and features from third parties (e.g., social media plugins, embedded videos, payment gateways) that set their own cookies. We do not control these cookies. Please review the privacy policies of these third parties.

09 // Data Encryption & Structural Defense

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:

  • Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256).
  • Role-based access controls and multi-factor authentication.
  • Regular security assessments and penetration testing.
  • Employee training on data protection and confidentiality.
  • Incident response and breach notification procedures.
  • Secure disposal of data when no longer required.

Despite these measures, no internet transmission or electronic storage is completely secure. We cannot guarantee absolute security but commit to promptly notifying you and relevant authorities of any data breach affecting your personal data, as required by law.

10 // Data Retention Policies

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:

  • Duration of our business relationship plus applicable statute of limitations.
  • Regulatory record-keeping requirements (typically 5-7 years for petroleum trading and financial transactions).
  • Legal proceedings or investigations that may require retention.
  • Tax and accounting obligations.

When data is no longer required, we securely delete or anonymize it in accordance with our data retention schedule.

11 // User Control Rights & Protections

Depending on your jurisdiction, you may have the following rights regarding your personal data:

A. Right to Access (NDPR Section 3.1(1)(a) / GDPR Article 15) Request a copy of the personal data we hold about you.
B. Right to Rectification (NDPR Section 3.1(1)(b) / GDPR Article 16) Request correction of inaccurate or incomplete data.
C. Right to Erasure ("Right to be Forgotten") (NDPR Section 3.1(1)(c) / GDPR Article 17) Request deletion of your personal data, subject to legal retention obligations.
D. Right to Restrict Processing (NDPR Section 3.1(1)(d) / GDPR Article 18) Request limitation on how we use your data.
E. Right to Data Portability (GDPR Article 20) Receive your data in a structured, machine-readable format and transmit it to another controller.
F. Right to Object (NDPR Section 3.1(1)(e) / GDPR Article 21) Object to processing based on legitimate interests or direct marketing.
G. Right to Withdraw Consent Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
H. Right to Lodge a Complaint File a complaint with the Nigerian Data Protection Bureau (NDPB) or your local data protection authority.

To exercise your rights, please contact us using the details in Section 15. We will respond within 30 days of receiving your request, or within the applicable legal timeframe.

12 // Children's Privacy

Our Website and Services are directed exclusively to business professionals and corporations engaged in the petroleum and energy trading sectors. We do not knowingly market to or collect personal data from individuals under the age of 18.

If we discover that an individual under 18 has provided personal data to us, we will delete that data from our systems immediately. If you believe we have accidentally collected data from a minor, please contact us at info@jamazavi-petroleum-energy.com.

13 // Third-Party Links

Our Website may contain links to third-party websites, plugins, and applications. Clicking these links may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices. We encourage you to review the privacy policy of every website you visit.

14 // Document Update Registers

We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or business operations. The updated version will be indicated by an updated "Effective Date" at the top of this page. We encourage you to review this Privacy Policy regularly.

For material changes, we will notify you through:

  • Prominent notice on our Website homepage
  • Email notification to registered users
  • Direct communication for active business partners

15 // Secure Contact Office

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact our Data Protection Officer:

Contact Info

JAMAZAVI LIMITED

Data Protection Officer

Email: info@jamazavi-petroleum-energy.com

Phone: +234 906 817 1039

Address: Orchid Road, Lekki

For formal complaints, you may also contact:

Nigerian Data Protection Bureau (NDPB)

[Address and contact details as applicable]