6membership6membershipA 6clement Joshua service™Legal & Trust Center
Privacy · Legal document

Privacy and Data Protection Notice

Detailed terms governing applications, membership relationships, payment review, benefits, conduct, verification and status.

Version 0.9-draftUpdated 6 August 202620 sections116 detailed clauses
Statusdraft
Effective dateNot yet effective
Change typeinitial publication
ReacceptanceNot required yet
Before you continue

Understanding this document

This Privacy and Data Protection Notice explains how 6membership collects, receives, creates, uses, stores, verifies, shares, protects, retains and deletes personal information.

6membership is a membership service operated by 6clement Joshua under the laws of the Federal Republic of Nigeria, with mandatory local consumer and privacy rights preserved where they apply.

This Notice applies to visitors, applicants, parents and guardians, household representatives, entity representatives, payers, approved members, associated persons, persons using public membership verification and persons communicating with 6membership.

Flutterwave is the selected production payment integration. Flutterwave and participating banks, card networks, mobile-money operators or other financial institutions may process payment information under their own legal and operational responsibilities in addition to the information processed by 6membership.

This Notice must be read with the Membership Terms and Conditions and the additional policies referenced throughout this document.

The Country-Specific Privacy Rights Addendum explains additional rights that may apply because of a person’s country, state, province, territory or other jurisdiction.

Applicant photographs and identity information

A clear and recent applicant photograph is ordinarily required for application review, identity matching, card production and impersonation prevention. The photograph is not permission for advertising, unrelated facial recognition or public promotion.

Scope

Who these Terms apply to

01

Visitors using the 6membership website and Legal & Trust Center.

02

Individuals comparing tiers or beginning an application.

03

Applicants submitting personal, household, business or organisational information.

04

Parents and guardians acting for a permitted younger applicant.

05

Primary representatives acting for a household, business, organisation or another approved entity.

06

Persons whose information is included in an application by an authorised representative.

07

Payers whose identity or transaction information differs from the applicant.

08

Approved, expired, suspended, restricted, cancelled or former members.

09

Persons using a Membership ID, digital card, certificate or public verification service.

10

Persons submitting privacy, security, complaint, appeal, legal or regulatory requests.

Jump toDocument sections
1

Operator, responsibility and scope

Who controls the information and when this Notice applies.

1.1

Service operator and data controller

For most processing described in this Notice, 6membership, operated by 6clement Joshua, determines why and how personal information is processed and therefore acts as the relevant data controller or equivalent responsible organisation.

Some third parties, including Flutterwave, participating banks, card networks, mobile-money operators, identity-verification providers or public authorities, may independently determine how they process information under their own legal responsibilities.

Where a service provider processes information only on documented instructions from 6membership, that provider ordinarily acts as a processor or service provider for the relevant activity.

Related documents
Third-Party Service Providers List
1.2

Processing covered by this Notice

This Notice covers information processed through the website, application forms, payment flows, email communications, membership administration, identity review, document uploads, membership cards, certificates, public verification, complaints, appeals and support channels.

It also covers records created for security, fraud prevention, compliance reviews, audit history, renewal administration, policy acceptance and legal obligations.

1.3

External websites and independent services

This Notice does not control an independent website, Flutterwave-hosted payment page, bank, card network, mobile-money service, social platform or other third-party service that determines its own processing purposes.

A link or redirect from 6membership to Flutterwave or another service does not mean that 6membership controls every activity performed by that service.

Applicants should review the privacy information presented by Flutterwave, a participating bank or another independent third party before supplying information directly to it.

1.4

Mandatory privacy rights remain preserved

Nothing in this Notice removes a privacy right, remedy or protection that applicable law makes mandatory.

Where a jurisdiction grants additional rights, those rights apply only to the extent that its law applies to the relevant person and processing activity.

Related documents
Country-Specific Privacy Rights Addendum
2

Privacy principles

Standards used when deciding how personal information should be handled.

2.1

Lawfulness, fairness and transparency

6membership aims to process personal information lawfully, fairly and transparently.

Information should not be collected or used through deceptive descriptions, hidden purposes or misleading application questions.

Material processing purposes will be explained through this Notice, the relevant form, a just-in-time notice or another appropriate communication.

2.2

Purpose limitation

Personal information is collected for specified and legitimate purposes connected with membership applications, administration, payments, verification, communications, security, compliance and legal responsibilities.

Information will not be repurposed for an unrelated and incompatible activity without an appropriate legal basis and any notice or permission required by applicable law.

2.3

Data minimisation

6membership will seek information that is reasonably relevant to the selected tier, applicant category, payment value, verification requirement and identified risk.

A higher tier, unusual payment, entity application or compliance concern may require more information than an ordinary Starter application.

An applicant should not upload unrelated documents or disclose unnecessary private information.

2.4

Accuracy

Reasonable steps may be taken to keep material membership information accurate and current.

Applicants and members must promptly report significant errors or changes affecting their identity, contact details, representative authority, eligibility, payment ownership or membership record.

2.5

Retention, security and accountability

Information should not be kept in identifiable form for longer than reasonably necessary for the relevant purpose, subject to legal, payment, fraud-prevention and record-preservation requirements.

6membership will maintain proportionate organisational and technical controls and retain evidence supporting material privacy decisions, policy acceptance, access and administrative actions.

3

Information we may collect

The principal categories of applicant, member and visitor information.

3.1

Identity and profile information

Identity information may include first name, middle name, last name, display name, date of birth, age range, gender where relevant and lawful, nationality, country of residence and applicant type.

It may also include a recent applicant photograph, signature, Membership ID, Application Reference and information used to distinguish the applicant from another person.

3.2

Contact and location information

Contact information may include email address, telephone number, residential or business address, city, state or region, country and preferred communication details.

Approximate country or region may also be inferred from technical or payment information for security, payment-routing, tax or jurisdictional purposes.

6membership does not describe this processing as continuous location tracking.

3.3

Photographs and verification documents

Verification information may include an applicant photograph, government-issued identity document, proof of address, age evidence, guardian documentation, authority documents, business registration records or other evidence requested for the applicable review.

Documents may reveal information beyond the fields required for verification. Access to uploaded documents should therefore remain limited to authorised personnel and systems.

Do not upload unnecessary information

Where a document contains unrelated identifiers or information that may lawfully be obscured, the applicant should follow the upload instructions rather than sending an unrestricted copy through an unofficial channel.

Related documents
Application, Identity and Photograph Policy
3.4

Household, dependant and guardian information

A Family or other household application may include the names, relationships, dates of birth and limited contact details of associated persons.

A permitted younger applicant may require parent or guardian name, contact details, relationship, authority evidence and consent records.

The primary representative must have an appropriate basis to provide information about another person.

3.5

Business and organisation information

An entity application may include legal name, registration details, operating address, representative information, ownership or controlling-person information and evidence of authority.

For higher-risk or higher-value relationships, information may include directors, beneficial owners, authorised signatories, business activities, funding sources and relevant public records.

3.6

Application and eligibility information

Application information includes selected tier, billing period, applicant category, eligibility answers, intended relationship, declarations, consent choices and supporting explanations.

Higher-tier applications may include preceding Membership IDs and records used to confirm an active Silver, Black, Platinum or Elite membership.

Private consideration requests may contain strategic, investment, partnership or business relationship information.

3.7

Payment and transaction information

Payment information may include Flutterwave as provider, the 6membership checkout or application reference, Flutterwave transaction reference, provider transaction ID, amount, currency, payment status, payer or customer name, payer or customer email, telephone number where supplied, payment method category, transaction time, provider verification response, settlement information, refund status, chargeback or dispute information and relevant risk signals.

6membership must not store a complete payment-card number, card security code, card PIN, online-banking password, payment OTP or another secret authentication credential as an ordinary application, membership or payment field.

Flutterwave, participating banks, card networks, mobile-money operators and other financial institutions may independently process additional payment credentials, financial information, device information and transaction-security data required to authorise, process, settle, refund or dispute a payment.

3.8

Fraud, compliance and source-of-funds information

Where reasonably necessary, information may include an explanation of the payment purpose, payment ownership, source of funds, beneficial ownership, sanctions or watchlist results, fraud indicators and investigation records.

A compliance record may include internal risk assessments and information that cannot be fully disclosed where disclosure would undermine security, reveal another person’s information or violate law.

Related documents
Anti-Fraud, Anti-Money-Laundering, Sanctions and Source-of-Funds Policy
3.9

Communications and support records

6membership may retain emails, support requests, complaints, appeals, privacy requests, security reports and other official correspondence.

Records may include message content, attachments, participants, delivery status, timestamps and actions taken.

3.10

Device, network and technical information

Technical information may include Internet Protocol address, browser type, device type, operating system, user agent, referring page, source URL, request time, language, cookie or local-storage identifiers and security events.

This information may support website delivery, session continuity, fraud prevention, diagnostics, consent records and security investigations.

3.11

Membership and verification records

Membership records may include holder name, tier, billing period, coverage, issue date, start date, expiry date, card version and current status.

Status may include pending, active, expiring soon, expired, suspended, restricted, reported stolen, invalid, revoked or cancelled.

Verification logs may record the Membership ID entered, result returned, request time and limited technical information.

4

Sources of information

How personal information reaches 6membership.

4.1

Information supplied directly

Most information is supplied directly by a visitor, applicant, member, payer, parent, guardian, representative or person contacting 6membership.

Information may be entered into a form, uploaded as a document, sent through an official email channel or provided during an authorised review.

4.2

Information supplied by representatives

A household, guardian or entity representative may provide information about another person where appropriately authorised.

6membership may contact the affected person or request authority evidence where necessary to confirm that the information was lawfully supplied.

4.3

Payment and service providers

Flutterwave may return transaction, payer or customer, verification, settlement, refund, chargeback, dispute and risk information connected with the payment flow.

Infrastructure, email, security and other providers may generate delivery, access, error, event and audit records while performing their services.

4.4

Existing membership and internal records

Information may be obtained from an earlier application, existing Membership ID, payment record, complaint, appeal, verification request, renewal or administrative history.

Existing records may be used to confirm predecessor-tier eligibility, prevent duplicate applications and preserve status history.

4.5

Lawful public and third-party sources

For higher-risk, higher-value, business, investor or strategic relationships, 6membership may review lawful public records and reputable sources relevant to identity, authority, sanctions, fraud, adverse legal findings or business registration.

A public source will not automatically be treated as accurate. Relevant information may require confirmation or an opportunity for the affected person to respond.

5

Why information is processed

The operational, contractual, security and legal purposes for processing.

5.1

Creating and administering applications

Information is processed to create an application record, generate an Application Reference, confirm the selected tier and billing period, preserve submitted answers and communicate application status.

It is also used to identify incomplete information, request clarification and maintain an accurate application history.

5.2

Assessing eligibility and suitability

Information is used to determine whether the applicant satisfies tier, age, guardian, household, representative and predecessor-membership requirements.

It may also be used to assess whether the requested relationship creates unacceptable fraud, safety, legal, compliance or integrity risk.

5.3

Verifying identity and preventing impersonation

Information is used to determine whether the application appears to relate to the person or entity represented.

Photographs and documents may be compared manually with submitted information and existing records.

Duplicate, altered, stolen or mismatched information may be investigated to protect applicants, members and the brand.

5.4

Processing and verifying payments

Transaction information is used to initialise payment through Flutterwave, associate the checkout with the correct application, verify the payment independently on the server, issue accurate payment records, process eligible refunds and address chargebacks or other disputes.

Before a payment is recognised as successful, 6membership should verify through Flutterwave that the transaction status, amount, currency, transaction reference and relevant customer or application relationship match the expected internal record.

Authenticated Flutterwave webhook events may update payment or refund records, but critical outcomes should be checked against Flutterwave’s verification service rather than accepted solely from a redirect, screenshot, debit alert or unverified payload.

Payment, webhook, refund and dispute events may be processed idempotently so that duplicate provider notifications do not create repeated membership activation, receipts, refunds or administrative actions.

Payment records may also be used for accounting, tax, fraud prevention, reconciliation, security and legal compliance.

5.5

Issuing and managing membership

Approved information is used to create the membership record, issue a Membership ID, generate a digital card or certificate and administer status, coverage, renewal, expiry, restriction and reissuance.

Information may be used to determine whether a person qualifies for an applicable event, communication route, invitation or membership opportunity.

5.6

Providing public verification

Limited approved information may be displayed to help a third party verify whether a presented Membership ID is recognised and current.

The public result is designed to reduce fake memberships, altered cards and unauthorised representation.

5.7

Delivering official communications

Contact information is used to send email OTPs, application confirmations, payment records, information requests, decisions, security notices, policy updates, renewal reminders and expiry notices.

Communication records may be retained to establish what was sent, when it was sent and whether delivery succeeded or failed.

5.8

Security, abuse prevention and investigations

Technical, account, identity, payment and communication information may be processed to prevent unauthorised access, fraud, scraping, impersonation, fake cards, malicious submissions and misuse of membership benefits.

Information may be preserved while a security, payment, conduct or compliance incident is investigated.

5.9

Legal, regulatory and compliance responsibilities

Information may be processed to comply with tax, accounting, consumer-protection, privacy, payment, sanctions, court, regulatory and other lawful obligations.

It may also be used to establish, exercise or defend legal claims and to respond to valid authority requests.

5.10

Improving reliability and user experience

Limited usage, diagnostic and feedback information may be used to identify broken flows, improve accessibility, measure performance and understand how visitors use the service.

Non-essential analytics or tracking technologies will be handled according to the Cookie and Tracking Technologies Policy and applicable consent requirements.

6

Lawful bases for processing

The legal grounds relied upon for different processing activities.

6.1

Application, contract and pre-contract steps

Information may be processed where necessary to take steps requested by an applicant before entering a membership relationship or to perform an approved membership arrangement.

This basis may cover application creation, payment association, review administration, membership issuance, renewal and delivery of requested services.

6.2

Legal obligation

Information may be processed where necessary to comply with an applicable legal, tax, accounting, consumer, privacy, payment, court or regulatory obligation.

6.3

Legitimate interests or equivalent lawful interests

Where permitted by applicable law, information may be processed for legitimate interests such as preventing fraud, protecting the service, maintaining records, enforcing policies, improving reliability and defending legal claims.

Before relying on this basis, the relevant interest should be assessed against the individual’s rights, expectations and potential impact.

This basis will not be used where the individual’s rights and interests override the proposed processing.

6.4

Consent

Consent may be used where processing is genuinely optional and consent is an appropriate legal basis.

Examples may include optional marketing, certain non-essential cookies, an optional public profile image or a use of information outside the ordinary membership purpose.

Consent must not be bundled with an unrelated mandatory activity where the individual should have a genuine choice.

Consent is not used for everything

Some records must be processed to review an application, verify payment, prevent fraud or comply with law. Those activities may rely on another lawful basis instead of consent.

6.5

Vital interests or public-interest grounds

In limited circumstances, information may be processed to protect a person’s life or physical safety, or for another public-interest ground recognised by applicable law.

These grounds will not be used as a routine substitute for an ordinary application or contractual basis.

6.6

Withdrawing consent

Where processing relies on consent, the individual may withdraw that consent through the applicable privacy or preference channel.

Withdrawal does not invalidate processing that was lawful before withdrawal.

Withdrawal may prevent an optional feature from continuing, but it does not automatically require deletion of records retained under another lawful basis.

7

Photographs, identity documents and biometric information

Special protections for the applicant image and identity-verification materials.

7.1

Required applicant photograph

A clear, recent and recognisable photograph of the applicant is ordinarily required.

The photograph supports human review, identity matching, card production, duplicate detection and impersonation prevention.

The photograph should show the correct applicant and must not be materially altered to misrepresent identity.

7.2

Permitted photograph uses

The photograph may be reviewed by authorised personnel, stored with the application, displayed on an approved membership card and used to investigate suspected impersonation or card misuse.

A limited version may appear in a verification result only where the display is reasonably necessary, proportionate and properly disclosed.

7.3

No automatic promotional permission

Submitting a photograph does not authorise 6membership to use it in advertising, social-media campaigns, testimonials, promotional materials or unrelated public announcements.

A separate permission or another valid legal basis is required for an unrelated promotional use.

7.4

When a photograph becomes biometric data

A normal photograph is not automatically described by 6membership as biometric recognition data merely because it depicts a face.

If technology is introduced that extracts facial geometry, biometric templates or similar identifiers for automated recognition, 6membership will provide an additional notice, assess the legal basis and obtain consent where required before using that technology.

No undisclosed facial-recognition system

The current membership design does not authorise hidden facial recognition or unrelated biometric profiling.

7.5

Private storage and controlled access

Application photographs and identity documents should be stored in private systems rather than unrestricted public storage.

Access should be limited to authorised review, verification, security, compliance and administrative purposes.

Where temporary signed links are used, they should expire and must not be treated as permanent public addresses.

7.6

Document redaction and minimisation

Upload instructions may permit an applicant to obscure information that is not required for the relevant check.

An applicant must not alter a document in a manner that falsifies identity, validity, ownership, authority or another material fact.

7.7

Detailed identity rules

Detailed image quality, document integrity, impersonation and duplicate-application rules are contained in the dedicated identity policy.

Related documents
Application, Identity and Photograph PolicyData Retention, Deletion and Records Policy
8

Children, younger applicants and guardians

How age information and guardian involvement are handled.

8.1

Applicants under 13

A child under 13 must not independently submit a membership application.

Where 6membership becomes aware that information was submitted directly by a child under 13 without an authorised process, the application may be blocked, restricted or deleted subject to legal preservation requirements.

8.2

Applicants aged 13 to 17

Where a tier permits a person aged 13 to 17 to participate, verified parent or guardian involvement may be required before the application proceeds.

Age, relationship, authority and consent information may be processed to protect the younger applicant and verify the guardian’s role.

8.3

Guardian information

Guardian information may include name, contact details, relationship, evidence of authority, approval status and communications concerning the younger applicant.

The guardian must provide accurate information and must not use a child’s identity to obtain an adult-only membership or evade eligibility requirements.

8.4

Protection and proportionality

Processing involving a younger applicant should be limited to what is reasonably required for eligibility, consent, safety, administration and legal obligations.

Optional marketing or unrelated public use of a younger applicant’s photograph requires separate consideration and appropriate permission.

8.5

Detailed age policy

Age eligibility, guardian confirmation, cancellation and communication requirements are explained in the dedicated policy.

Related documents
Eligibility, Age and Guardian Consent Policy
9

Payments, fraud and compliance information

Privacy rules applying to transaction verification and unusual-payment review.

9.1

Information sent to and received from Flutterwave

6membership may send Flutterwave the amount, currency, application or checkout reference, payer or customer name, email address, telephone number where required, transaction description and other information reasonably necessary to initialise, process and verify a transaction.

Flutterwave may return a transaction reference, provider transaction ID, amount, currency, status, payment method category, payer or customer information, transaction time, settlement information, refund status, chargeback or dispute information and relevant risk or authentication signals.

The exact information depends on the selected payment method, country, participating financial institution and Flutterwave product configuration.

9.2

Payment credentials and independent provider processing

Complete card details, card security codes, card PINs, banking passwords and payment OTPs should be entered only into Flutterwave’s or the participating financial institution’s authorised interface.

6membership does not require an applicant to email or message a complete card number, card security code, banking password, payment PIN or OTP.

Flutterwave and participating financial institutions may independently process payment-card, bank-account, device, network, authentication and fraud-prevention information under their own privacy notices and legal responsibilities.

Do not send payment secrets to 6membership

A legitimate 6membership administrator will not request a complete card number, CVV, card PIN, banking password or payment OTP by email, social media or messaging service.

9.3

High-value and unusual payments

A high-value, unusual, mismatched or suspicious transaction may require enhanced review.

Information requested may include payer identity, payment authority, source of funds, beneficial ownership, business purpose and supporting documentation.

The existence of a review does not by itself mean that the applicant has committed wrongdoing.

9.4

Server verification, webhooks and duplicate-event controls

A browser redirect, screenshot, debit alert or applicant statement does not by itself establish that a payment succeeded.

6membership should verify critical payment information through Flutterwave’s server-side verification service, including the status, amount, currency, transaction reference and connection to the expected application or customer.

Incoming Flutterwave webhook requests should be authenticated using the configured signature or secret mechanism before their contents are trusted.

Payment and refund events may arrive more than once. 6membership may retain provider event identifiers, transaction references and prior processing results to apply idempotent duplicate-event controls.

Flutterwave API keys, webhook secrets, encryption material and other privileged payment credentials must remain server-side and must not be exposed in browser code, public repositories, policy pages or ordinary support messages.

9.5

Investigations and restricted disclosure

Certain fraud, sanctions, security, Flutterwave risk and investigation information may be restricted where disclosure would reveal confidential controls, prejudice an investigation, expose another person’s information or violate law.

Where permitted, an affected person may still request correction of materially inaccurate information.

9.6

Refund, chargeback and dispute records

Refund records may include the reason, amount, internal approval, Flutterwave submission or acceptance time, processing status, completion time, failure details, provider refund reference and original payment destination.

An internal refund approval is not the same as submission to Flutterwave, provider processing or final completion. Communications should describe the verified stage accurately.

Chargeback and dispute records may include the reason code, evidence supplied, response deadlines, provider or financial-institution outcome and any related membership restriction.

These records may be retained to resolve the claim, prevent duplicate reimbursement, reconcile financial records and comply with Flutterwave, financial-institution or legal requirements.

Related documents
Payments, Taxes, Refunds, Chargebacks and Renewals PolicyAnti-Fraud, Anti-Money-Laundering, Sanctions and Source-of-Funds PolicyThird-Party Service Providers List
10

Membership cards and public verification

What may be displayed when another person checks a Membership ID.

10.1

Purpose of public verification

Public verification helps determine whether a presented Membership ID is recognised and whether its status appears current.

It is intended to reduce fake cards, altered certificates, expired claims and unauthorised representation.

10.2

Information that may be displayed

A verification result may display the approved holder or entity name, Membership ID, tier, current status, coverage, issue date, expiry date and last status update.

A limited approved image may be displayed only where reasonably necessary and properly disclosed.

10.3

Information not ordinarily displayed

Public verification will not ordinarily reveal the registered email address, telephone number, date of birth, residential address, payment record, private application answers, identity documents, guardian evidence or internal review notes.

10.4

Verification logs

A verification request may generate a limited log containing the Membership ID entered, result, timestamp, request source and technical security information.

Logs may be used to investigate systematic scraping, fraudulent checking, harassment or misuse of the verification service.

10.5

Detailed card and verification rules

Card display, replacement, stolen-card status, reissuance and verification limitations are explained in the dedicated policy.

Related documents
Membership Card, Certificate and Public Verification Policy
11

Cookies, local storage and technical processing

How website technologies support essential and optional functions.

11.1

Strictly necessary technologies

Strictly necessary cookies or local-storage technologies may support security, session continuity, request routing, fraud prevention, consent storage and accessibility.

Disabling a strictly necessary technology may prevent an application, security or preference function from working correctly.

11.2

Optional technologies

Preference, analytics or marketing technologies will be classified separately from strictly necessary technologies.

Where applicable law requires consent, an optional technology will not be activated until the appropriate consent is received.

11.3

Consent records

Cookie choices may be recorded with a visitor identifier, consent version, selected categories, timestamp, source page and limited technical information.

A visitor may update or withdraw optional choices through the available cookie settings.

11.4

Detailed cookie information

The Cookie and Tracking Technologies Policy will identify relevant categories, purposes, durations and available controls.

Related documents
Cookie and Tracking Technologies Policy
12

How information may be shared

The limited circumstances in which information may be disclosed.

12.1

No sale of applicant information

6membership does not intend to sell applicant or member personal information for money.

The service is not designed to exchange application photographs, identity documents or private membership records for advertising revenue.

Where a jurisdiction defines sale or sharing more broadly, any applicable rights are explained in the Country-Specific Privacy Rights Addendum.

12.2

Operational service providers

Information may be disclosed to providers supporting hosting, databases, private storage, email delivery, payments, security, fraud prevention, analytics, document generation and customer support.

For production payments, relevant transaction and payer information may be disclosed to Flutterwave and may also be processed by participating banks, card networks, mobile-money operators and other financial institutions required to complete or investigate the transaction.

The information disclosed should be limited to what is reasonably necessary for the provider’s assigned function.

Providers may be required through contract, technical controls or law to protect information and restrict unauthorised use.

Related documents
Third-Party Service Providers List
12.3

Affiliated organisations and authorised personnel

Limited information may be shared with an affiliated organisation or authorised personnel where necessary to administer an approved membership opportunity, invitation, verification or relationship.

Membership information must not be treated as permission to distribute the full application to every affiliated organisation.

12.4

Professional advisers

Information may be disclosed to lawyers, accountants, auditors, insurers, investigators or other professional advisers where reasonably necessary for advice, compliance, claims or risk management.

12.5

Courts, regulators and lawful authorities

Information may be disclosed where required by a valid legal obligation, court order, regulatory demand or other lawful authority request.

6membership may review the validity, scope and proportionality of a request and may challenge or narrow an excessive request where lawful and appropriate.

12.6

Protection of people and the service

Information may be disclosed where reasonably necessary to investigate fraud, prevent serious harm, protect rights, secure the service or address unlawful conduct.

Any disclosure should be proportionate to the identified risk and applicable law.

12.7

Business reorganisation or transfer

Information may be reviewed or transferred as part of a genuine merger, acquisition, restructuring, financing, asset transfer or similar transaction.

The recipient must respect applicable privacy obligations and any materially different future use may require additional notice or choice.

13

International processing and transfers

How information may be processed outside the applicant’s country.

13.1

Global infrastructure

6membership may use providers, servers, support personnel or payment systems located outside the applicant’s country.

Flutterwave may process payment and related information through its applicable corporate entity, affiliates, participating financial institutions, infrastructure providers and service providers in Nigeria, the United States or other jurisdictions described in its current privacy information and service arrangements.

Information may therefore be stored, accessed, transmitted or otherwise processed in Nigeria, the provider’s operating region or another permitted location.

13.2

Transfer protections

Where applicable law restricts international transfers, 6membership will use an available legal mechanism appropriate to the transfer.

Mechanisms may include an adequacy decision, contractual protections, binding rules, certification, explicit consent in limited circumstances or another legally recognised safeguard.

13.3

Risk and provider assessment

Relevant factors may include the destination, type of information, provider security, legal protections, government-access risk and contractual remedies.

Additional technical or organisational safeguards may be used where reasonably necessary.

13.4

Requesting transfer information

Where applicable law grants the right, an individual may request information about relevant transfer safeguards through the privacy contact channel.

Related documents
Country-Specific Privacy Rights AddendumThird-Party Service Providers List
14

Retention and deletion

How long different records may remain available.

14.1

Retention criteria

Retention depends on the type of record, application outcome, membership status, payment period, legal obligations, limitation periods, dispute risk, security needs and fraud-prevention value.

A single retention period will not necessarily apply to every category of information.

14.2

Incomplete and abandoned applications

An incomplete application may be retained temporarily to allow completion, prevent duplicate abuse and support technical troubleshooting.

After the applicable period, unnecessary draft information may be deleted or anonymised unless another lawful reason requires retention.

14.3

Denied and cancelled applications

A denied or cancelled application may be retained for refund administration, complaint handling, fraud prevention, audit history, legal claims and prevention of repeated evasion.

Highly sensitive documents may have a shorter active-access period than the core decision record where continued document storage is unnecessary.

14.4

Approved and former memberships

Core membership, payment, acceptance and status history may be retained throughout the relationship and for an appropriate period after expiry, cancellation or revocation.

Historical records may remain necessary to verify that an old card is expired, revoked, stolen or otherwise invalid.

14.5

Legal holds and investigations

Deletion may be paused where information is relevant to a dispute, chargeback, fraud review, regulatory request, court order, security incident or other legal-preservation obligation.

Restricted retention does not mean that information remains available for ordinary operational use.

14.6

Deletion and anonymisation

When retention is no longer justified, information may be deleted, securely destroyed, irreversibly anonymised or aggregated so that it is no longer reasonably linked to an identifiable person.

Deletion from active systems may not immediately remove every encrypted backup copy. Backup copies may expire according to controlled backup cycles and remain unavailable for ordinary use.

Related documents
Data Retention, Deletion and Records Policy
15

Security and incident response

Measures intended to reduce unauthorised access, loss and misuse.

15.1

Organisational and technical safeguards

6membership will use safeguards proportionate to the nature, volume, sensitivity and risk of the information processed.

Measures may include access restrictions, private storage, encryption in transit, secret management, server-side privileged operations, Row Level Security, audit logs, short-lived links, backups, authenticated Flutterwave webhook handling, transaction re-verification, idempotency controls and incident procedures.

15.2

Access limitation

Access to application photographs, identity documents, payment reviews, internal notes and administrative records should be limited according to role and operational need.

Verification administrators should not automatically receive unrestricted authority to approve, refund, revoke or alter protected records.

15.3

Applicant and member responsibilities

Applicants and members must protect access to their registered email address, devices, OTPs, Membership ID and official communications.

A person must not disclose an OTP to an unauthorised individual or submit private documents through an unverified social account or personal payment channel.

15.4

No absolute security guarantee

No internet service, payment network, email system or storage platform can guarantee that every risk will be eliminated.

6membership will respond to identified incidents according to the circumstances, applicable law and available evidence.

15.5

Personal-data incidents

A suspected personal-data breach may be investigated to determine the affected information, people, systems, cause, likely consequences and containment measures.

Affected individuals and regulators will be notified where applicable law requires notification.

A notification may be delayed or limited where law enforcement, security containment or another lawful restriction applies.

Related documents
Security, Account Access and Incident Response Policy
16

Privacy rights and requests

How individuals may exercise applicable rights over their information.

16.1

Rights that may apply

Depending on applicable law, an individual may have rights to receive information, obtain access, request correction, request deletion, restrict processing, object, withdraw consent, obtain portability or request review of certain automated decisions.

A person may also have the right to complain to an applicable privacy regulator.

16.2

Rights are not always absolute

A request may be limited or denied where the requested action would reveal another person’s information, undermine fraud controls, interfere with legal obligations, prejudice an investigation or require deletion of records that must lawfully be retained.

Where appropriate and permitted, the response will explain the relevant limitation.

16.3

Submitting a request

A privacy request should identify the requester, the right being exercised and the application or membership record concerned where available.

Requests should be sent through the official privacy channel rather than an unauthorised social account.

A unique privacy-request reference may be issued for tracking.

16.4

Identity verification

Before disclosing, changing or deleting protected information, 6membership may take proportionate steps to confirm the requester’s identity and authority.

The verification process should not require materially more information than reasonably necessary for the request.

An authorised representative may be required to provide evidence of authority.

16.5

Response and timing

6membership will acknowledge and respond to a valid request within the period required by applicable law.

Additional time may be used where law permits an extension because of complexity, volume or identity-verification issues.

The requester will be informed where an extension or additional information is required.

16.6

Fees and excessive requests

Ordinary privacy requests will not be charged where applicable law requires them to be free.

Where legally permitted, a reasonable fee or refusal may apply to a manifestly unfounded, excessive or repeatedly duplicative request.

16.7

No unlawful retaliation

6membership will not unlawfully discriminate against a person for exercising an applicable privacy right.

A service feature may nevertheless become unavailable where the requested deletion or objection makes that feature impossible to provide and no other lawful basis supports the processing.

16.8

Jurisdiction-specific rights

Additional information concerning Nigeria, the European Union and European Economic Area, the United Kingdom, California, South Africa and other relevant jurisdictions will be maintained in the Country-Specific Privacy Rights Addendum.

Related documents
Country-Specific Privacy Rights AddendumComplaints, Appeals and Dispute Resolution Policy
17

Automated tools and human review

How technical screening may support, but not secretly replace, material decisions.

17.1

Technical screening

Automated tools may help identify duplicate submissions, invalid formats, unusual transaction patterns, security events, blocked devices, Flutterwave or financial-institution risk signals, or information requiring manual review.

A technical or provider flag does not necessarily prove fraud or wrongdoing.

17.2

Decisions with significant effects

6membership does not intend to make a final approval, denial, suspension or revocation decision solely through undisclosed automated processing where applicable law requires meaningful human involvement.

Relevant flags may be reviewed together with application information, provider records and any explanation supplied by the affected person.

17.3

Requesting review

Where applicable law provides the right, an individual may request human review, express their position and challenge materially inaccurate information used in an automated or substantially automated decision.

17.4

Future automated-decision technology

Before introducing a materially different automated-decision or biometric system, 6membership will assess the privacy impact, update the relevant notice and obtain consent or provide rights where required.

18

Electronic communications and marketing choices

The difference between necessary service notices and optional promotion.

18.1

Necessary service communications

Applicants and members may receive communications necessary to administer the relationship, including OTPs, application confirmations, payment notices, information requests, decisions, status changes, security alerts, policy notices, renewal reminders and expiry notices.

These communications are not treated as optional marketing merely because they are delivered by email.

18.2

Optional marketing

Promotional communications unrelated to the necessary administration of the membership will use an appropriate legal basis and provide an opt-out where required.

Withdrawing from optional marketing does not prevent delivery of essential application, payment, security or legal notices.

18.3

Delivery and email records

Email delivery records may include provider message ID, recipient, sender, subject, status, sent time, delivery time, bounce time and failure reason.

These records support troubleshooting, evidence of notice, security and communication reliability.

18.4

Electronic records and consent

The legal effect of electronic notices, records, policy acceptance and communication preferences is explained in the Electronic Communications Consent.

Related documents
Electronic Communications Consent
19

Law-enforcement, regulatory and legal requests

How protected information may be preserved or disclosed to authorities.

19.1

Validation of requests

6membership may examine whether an authority request appears authentic, lawful, properly issued, sufficiently specific and within the requesting authority’s powers.

Additional information or formal legal process may be requested where appropriate.

19.2

Proportional disclosure

Where disclosure is required, 6membership will seek to disclose only information reasonably responsive to the lawful request.

An excessive, unclear or invalid request may be challenged, narrowed or rejected where lawful.

19.3

Preservation

Relevant records may be preserved where required by a valid preservation notice, court process, regulatory duty, dispute or credible investigation.

Preservation may temporarily override an ordinary deletion schedule.

19.4

Notification of affected persons

Where lawful and appropriate, 6membership may notify an affected person before or after disclosure.

Notification may be delayed or prohibited where a valid legal restriction applies, where notice would create serious risk or where it would prejudice an investigation.

19.5

Emergency requests

A narrowly tailored disclosure may be considered where there is a credible and urgent risk of death or serious physical harm and applicable law permits disclosure.

Emergency requests may require identity, authority and urgency verification.

Related documents
Law-Enforcement, Regulatory and Government Requests Policy
20

Changes, complaints and privacy contacts

How this Notice will be updated and how privacy concerns can be raised.

20.1

Policy versions

Each published version of this Notice will display a version number, last-updated date, effective date and summary of material changes.

Historical application records may remain connected to the exact policy version accepted or presented at the relevant time.

20.2

Material privacy changes

Where a material change affects how existing information is used, 6membership may provide notice through the website, application flow, membership portal or registered email address.

Renewed consent or acceptance will be obtained where applicable law requires it.

20.3

Privacy questions and complaints

Privacy questions, rights requests and complaints should be sent through the official privacy channel.

The request should provide enough information to identify the relevant application, membership or processing activity without including unnecessary sensitive information.

20.4

Regulatory complaints

An individual may contact an applicable privacy regulator where the law provides that right.

Using the internal privacy channel first may help resolve an issue, but it does not remove a mandatory right to approach a regulator.

20.5

Policy-update framework

Detailed publication, notification, effective-date and reacceptance rules are contained in the Policy Updates, Effective Dates and Change Log.

Related documents
Policy Updates, Effective Dates and Change Log
Cross-reference

Related policies

Membership Terms and Conditions

The contractual framework for applications and memberships.

Country-Specific Privacy Rights Addendum

Additional rights that apply in particular jurisdictions.

Application, Identity and Photograph Policy

Detailed rules for photographs, documents and identity checks.

Cookie and Tracking Technologies Policy

Website storage, analytics, consent and preference controls.

Data Retention, Deletion and Records Policy

Record-specific retention, deletion and legal holds.

Third-Party Service Providers List

Providers supporting hosting, databases, email and Flutterwave payment processing.

Security, Account Access and Incident Response Policy

Account safeguards and incident-management procedures.

Law-Enforcement, Regulatory and Government Requests Policy

Validation, preservation and disclosure rules.

Electronic Communications Consent

Electronic notices, records, policy acceptance and OTP delivery.

Official channels

Contact points

Privacy requestsprivacy@6membership.com

Access, correction, deletion, objection, portability, restriction and consent-withdrawal requests.

Security reportssecurity@6membership.com

Suspected account compromise, exposed information or security incidents.

General administrationadmin@6membership.com

General application and membership administration that does not require a formal privacy request.

Legal and regulatory correspondencelegal@6membership.com

Formal notices from authorised legal representatives, regulators and public authorities.

6membershipA 6clement Joshua service™

© 2026 6clement Joshua. All rights reserved.