Privacy Policy
MetroReach Internet Services
Full Fibre Broadband · Open Access FTTH · Retail & Wholesale
Effective Date: 15 August 2025MetroReach is a leading Internet broadband provider in Nigeria, delivering high-speed retail and wholesale connectivity over an open-access Full Fibre to the Home (FTTH) infrastructure. We operate as a licensed Internet Access Service Provider (IASP) regulated by the Nigerian Communications Commission (NCC) and are committed to protecting the privacy and security of all data we process.
This Privacy Policy explains how MetroReach collects, uses, discloses, and protects your personal data when you use our services, including full fibre broadband subscriptions, wholesale capacity services, websites, apps, and all other interactions with MetroReach.
We process personal data in compliance with the Nigeria Data Protection Act 2023 (NDPA), the Nigerian Communications Act 2003, the Cybercrimes (Prohibition, Prevention, etc.) Act 2015 (as amended), guidelines from the NCC and the National Information Technology Development Agency (NITDA), and all other applicable Nigerian laws and regulations.
By using our services, you consent to the practices described in this Policy. If you do not agree, please do not use our services.
1. Our Role as Data Controller
MetroReach acts as a Data Controller under the NDPA for all personal data we process in connection with the delivery of retail and wholesale internet services over our open-access full fibre network.
Registered Details
Registered Office: Plot 1265 / 54A Adeola Odeku Street, Victoria Island, Lagos
Data Protection Officer (DPO): privacy@metroreach.ng
Website: www.metroreach.ng
As a data controller of major importance, processing significant volumes of personal data relevant to Nigeria's economy and digital infrastructure, MetroReach is registered with the Nigeria Data Protection Commission (NDPC) and fully complies with all registration and reporting obligations under the NDPA.
2. Information We Collect
We collect the following categories of personal data depending on your interaction with us and the nature of the service you subscribe to.
a. Personal Identification Information
Name, email address, phone number, and postal address.
Government-issued identification details such as NIN or passport provided during subscription, registration, or identity verification.
Business registration details for corporate and wholesale customers.
b. Payment and Financial Information
Billing address, bank account details, or payment card information for processing subscriptions and wholesale invoices.
Transaction records, invoice history, and payment status.
c. Usage and Technical Data
Internet usage logs including IP addresses, timestamps, data volumes, and session records for network management, fault resolution, and lawful interception compliance.
Device information such as MAC address, device type, operating system, and browser details.
Network performance metrics collected through our FTTH and open-access infrastructure.
Approximate location data based on point-of-presence or IP address for location-based services or regulatory compliance.
d. Wholesale & Carrier Data
Business contact information, technical configuration details, and capacity requirements for wholesale and carrier customers.
Network interconnection data, routing information, and traffic volumes as required for service delivery.
e. Sensitive Personal Data
We do not ordinarily collect sensitive personal data such as racial or ethnic origin, political opinions, religious beliefs, health data, or biometric data. Where this is strictly required, for example for accessibility services, we obtain explicit consent and process it only to the minimum extent necessary in accordance with NDPA Section 30.
f. Children's Data
Our services are not directed at children under 13. We do not knowingly collect personal data from children under 13 without verifiable parental or guardian consent. For users under 18, guardian approval may be required for certain services.
g. Other Data
Customer support interactions, feedback submissions, and survey responses.
Marketing preferences and opt-in or opt-out records.
Cookies and tracking data from our website and customer portal as described in Section 9.
We collect data directly from you, automatically through our network infrastructure, or from authorised third parties such as payment processors and identity verification services.
3. How We Use Your Information
We process personal data based on lawful grounds under NDPA Section 24, including consent, contract performance, legal obligations, legitimate interests, vital interests, and public tasks. Our processing purposes include:
- Provisioning and maintaining retail broadband and wholesale fibre services over our open-access FTTH infrastructure.
- Billing, payment processing, invoice management, and account administration.
- Network optimisation, fault diagnosis, performance monitoring, and capacity planning.
- Security operations and fraud detection, including detecting malware, DDoS activity, or unauthorised access.
- Legal and regulatory compliance, including retaining traffic data for 2 years under the Cybercrimes Act and disclosing data to authorities upon receipt of a lawful request from the NCC, NDPC, or law enforcement.
- Marketing and service communications with your consent, with opt-out available at any time.
- Service improvement through analytics, anonymised and aggregated where possible.
- Onboarding and managing wholesale carrier and ISP partners.
We conduct Data Protection Impact Assessments (DPIAs) for high-risk processing activities and apply data minimisation principles across all operations.
4. Sharing and Disclosure of Your Information
We may share your personal data with the following categories of recipients:
- Affiliates and group companies for internal operational and administrative purposes.
- Service providers such as cloud hosting partners, payment gateways, and CRM platforms bound by data processing agreements that impose equivalent data protection obligations.
- Open-access infrastructure partners and wholesale customers to the extent necessary for service delivery and network management.
- Regulatory and law enforcement authorities such as the NCC, NDPC, Nigeria Police Force, and Economic and Financial Crimes Commission as required by applicable law.
- Prospective buyers or investors in the context of a business transfer, merger, or acquisition, with appropriate notice provided to you.
We do not sell your personal data to third parties. We may share anonymised, aggregated usage data with partners for network analytics and planning purposes.
Cross-Border Data Transfers
If personal data is transferred outside Nigeria, for example to cloud infrastructure hosted internationally, we ensure that such transfers are protected by adequacy decisions, standard contractual clauses, or other NDPA-approved safeguards under Section 42. We maintain records of the legal basis for all cross-border transfers.
5. Data Security
We implement robust technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These include:
- End-to-end encryption for data in transit (HTTPS, TLS) and encryption for sensitive data at rest.
- Firewalls, intrusion detection systems, and access controls on all network and IT systems.
- Role-based access management to limit data access to authorised personnel only.
- Regular risk assessments, vulnerability testing, security audits, and penetration testing.
- Employee training and awareness programmes on data protection obligations.
- Incident response procedures aligned with NDPA and NCC requirements.
6. Data Breach Notification
In the event of a personal data breach, MetroReach will:
- Notify the NDPC within 72 hours of becoming aware of the breach where the breach is likely to result in a risk to the rights and freedoms of individuals.
- Notify affected data subjects without undue delay if the breach poses a high risk to their rights and freedoms.
- Notify the NCC and affected customers within 48 hours in accordance with the NCC Internet Code of Practice where the breach relates to Internet Access Service provision.
All breaches, including those not requiring notification, are logged internally. We maintain a breach register in accordance with our obligations as a data controller of major importance.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our standard retention periods are:
- Subscriber identity and account information: duration of the contract plus 2 years.
- Traffic and usage data (broadband and FTTH): 2 years in compliance with the Cybercrimes (Prohibition, Prevention, etc.) Act 2015.
- Wholesale carrier and ISP records: duration of the commercial relationship plus 3 years.
- Financial and billing records: 7 years in accordance with Nigerian tax and financial regulations.
- Customer support records: 2 years after case closure.
Upon expiry of applicable retention periods, data is securely deleted or irreversibly anonymised. We conduct periodic data audits to ensure compliance with this schedule.
8. Your Rights as a Data Subject
Under the Nigeria Data Protection Act 2023 (Sections 34-38), you have the following rights in relation to your personal data:
- Right to Access: request a copy of the personal data we hold about you.
- Right to Rectification: request correction of inaccurate or incomplete data.
- Right to Erasure: request deletion of your data in certain circumstances.
- Right to Restrict Processing: request that we limit how we use your data.
- Right to Object: object to processing based on legitimate interests, including direct marketing.
- Right to Data Portability: receive your data in a structured, machine-readable format where technically feasible.
- Right to Withdraw Consent: withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
- Right to Lodge a Complaint: submit a complaint to the Nigeria Data Protection Commission (NDPC).
To exercise any of these rights, contact our Data Protection Officer at privacy@metroreach.ng. We will respond within one calendar month, extendable by a further two months where the request is complex or numerous. We may require proof of identity before processing your request.
Parents and legal guardians may exercise data subject rights on behalf of children under 18.
9. Cookies and Tracking Technologies
Our website (www.metroreach.ng) and customer portal use cookies and similar tracking technologies. We deploy the following categories of cookies:
- Essential Cookies: required for the website and portal to function and cannot be disabled.
- Performance & Analytics Cookies: help us understand how users interact with our site using anonymised data.
- Functional Cookies: remember your preferences and settings.
- Targeting & Advertising Cookies: serve relevant marketing content only with your consent.
You can manage or withdraw your cookie preferences at any time via your browser settings or our cookie preference centre on the website. Disabling essential cookies may affect the functionality of our services.
10. Children's Privacy
Our services are not directed at or intended for children under the age of 13. We do not knowingly collect personal data from children under 13 without verifiable parental or guardian consent in compliance with the NDPA and the Child Rights Act 2003. If we become aware that personal data of a child under 13 has been collected without appropriate consent, we will delete it promptly. If you believe a child's data has been collected improperly, please contact us at privacy@metroreach.ng.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, our services, or operational practices. Any changes will be published on our website (www.metroreach.ng) with the updated effective date. Your continued use of our services following such publication constitutes acceptance of the revised Policy. Where changes are material, we will provide prominent notice via email or an in-portal notification.
12. Contact Us
For questions, complaints, or to exercise your data subject rights, please contact:
- MetroReach Data Protection Officer
- Email: privacy@metroreach.ng
- Phone: 0908 799 1042 | 0908 799 1156 | 0908 799 0824
- Address: Plot 1265 / 54A Adeola Odeku Street, Victoria Island, Lagos, Nigeria
- Website: www.metroreach.ng
- Nigeria Data Protection Commission (NDPC)
- Address: No. 12 Dr. Clement Isong Street, Asokoro, Abuja, Nigeria
- Email: info@ndpc.gov.ng
- Phone: +234 (0) 916 061 5551
- Website: ndpc.gov.ng
Thank you for trusting MetroReach. We are committed to safeguarding your privacy and delivering connectivity you can rely on.