Legal
Privacy Notice
How Dannon Group Petroleum handles personal data
Scope and Who We Are
This Privacy Notice applies to personal data processed through www.dannongroup.net and in connection with Dannon Group Petroleum's enquiries, supplier and customer onboarding, due diligence, commercial discussions, events, recruitment and business relationships. The specific Dannon entity identified in the relevant form, correspondence or contract will ordinarily be the data controller for that activity.
Personal Data We May Collect
- Identity and contact data, including name, title, organisation, address, email address, telephone number and authorised-representative details.
- Corporate due-diligence data, including incorporation records, licences, ownership and beneficial-ownership information, directorships, signatures and authority documents.
- Identity-verification and compliance data, which may include government-issued identification details, screening results, source-of-funds or source-of-wealth information, bank confirmation details and risk assessments where legally required and proportionate.
- Commercial and transaction data, including product requirements, specifications, volumes, delivery locations, contractual correspondence, invoices, payment status and logistics information.
- Website and technical data, including IP address, device and browser information, access logs, cookie identifiers and security events.
- Communications, complaints, survey responses, meeting records and information voluntarily supplied to us.
How We Obtain Personal Data
We obtain personal data directly from individuals and organisations, from authorised representatives and counterparties, through our website and communications, and from lawful public, regulatory, professional, sanctions-screening, credit-reference and verification sources. We do not seek unnecessary personal data.
Purposes and Lawful Bases
- To respond to enquiries, prepare proposals, conduct negotiations, enter into and perform contracts, and administer business relationships.
- To verify identity, authority, ownership, licensing, financial standing and counterparty suitability; prevent fraud; conduct sanctions and politically exposed person screening; and meet legal or regulatory obligations.
- To operate, secure, improve and measure our website, systems and services, and to investigate suspected misuse or cybersecurity incidents.
- To manage payments, records, audits, disputes, insurance, professional advice and legal claims.
- To send relevant corporate or commercial communications where permitted by law and subject to applicable choices.
Depending on the activity, processing may be based on consent, steps requested before entering a contract, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a task in the public interest where applicable, or our legitimate interests balanced against the rights of the individual.
Sharing and International Transfers
We may share personal data on a need-to-know basis with Dannon affiliates, professional advisers, banks and payment providers, information-technology and hosting providers, logistics and inspection providers, insurers, auditors, screening and verification providers, authorised commercial partners, regulators, law-enforcement bodies and courts. We do not sell personal data.
Where personal data is transferred across borders, we apply the safeguards required by applicable law, which may include an adequacy basis, approved contractual safeguards, consent where appropriate, or another lawful transfer mechanism. We also assess confidentiality, security and access controls appropriate to the transfer.
Retention and Security
We retain personal data only for as long as reasonably necessary for the stated purpose and to satisfy contractual, tax, audit, regulatory, anti-money laundering, dispute and records-management requirements. Retention periods vary by record type and jurisdiction. We use proportionate organisational and technical safeguards, including role-based access, confidentiality controls, secure transmission and storage, logging, backups, vendor oversight and incident-response procedures. No system is completely secure, and users should protect their own devices and credentials.
Your Rights
Subject to applicable law and lawful limitations, an individual may request access to, correction or deletion of personal data; object to or restrict processing; request data portability; withdraw consent without affecting prior lawful processing; and lodge a complaint with the Nigeria Data Protection Commission or another competent supervisory authority. Identity verification may be required before a request is fulfilled.
Children, Automated Decisions and Third-Party Sites
Our business website and services are not directed to children, and we do not knowingly collect children's data without an appropriate lawful basis and safeguards. We do not intend to make decisions producing legal or similarly significant effects solely by automated means unless appropriate notice and safeguards are provided. Third-party websites linked from our site operate under their own notices and controls.
Updates and Contact
We may update this Notice to reflect legal, operational or technology changes. The effective date will be revised when material updates are published. Privacy enquiries and rights requests may be submitted through the Contact page or delivered to either corporate address shown there.