1. Overview and Scope
This Privacy Policy ("Policy") sets out how RIF Africa, operating as Subpadi, collects, uses, stores, shares, and protects your personal data when you access or use the Subpadi platform including its website, mobile applications, APIs, and all associated services (collectively, the "Platform").
We are committed to protecting your personal data and handling it responsibly, transparently, and in full compliance with applicable data protection laws and regulations including those in force in Nigeria and in other jurisdictions where our services operate.
This Policy applies to:
- All registered users of the Platform including Guardian-Managed Account holders and Minor Beneficiary Users.
- Visitors to the Platform who have not registered.
- Merchants and business users who access the Platform through the API.
- Job applicants and prospective employees.
- Any other person whose personal data is processed by us in connection with the Platform.
By using the Platform, you acknowledge that you have read and understood this Policy and you consent to the collection and processing of your personal data as described herein. If you do not agree with any part of this Policy, you must cease using the Platform.
This Policy should be read alongside our Terms of Service, which are incorporated by reference.
2. Who We Are
The data controller responsible for your personal data collected through the Subpadi Platform is:
RIF Africa (RIF African Business Enterprise)
CAC Registration Number: RC 2709434
Operating as: Subpadi
Website: www.subpadi.com
General Contact: [email protected]
Data Protection Contact: [email protected]
3. Eligibility and Minor Users
The Platform is accessible to users aged 11 and above, subject to the Guardian-Managed Account structure described in the Terms of Service. All KYC verification for accounts used by persons under 18 is conducted by and in the name of the Adult Guardian who is the account holder of record. We do not directly contract with or collect personal data directly from minors. Personal data of minor beneficiary users is collected by the Adult Guardian and provided to us as part of the account setup.
Children under the age of 11 may only access the Platform under direct adult supervision as described in the Terms of Service.
4. Consent
By registering for an Account, using the Platform, or providing your personal data to us, you consent to the collection, storage, use, and disclosure of your personal data in accordance with this Policy.
Where we rely on consent as our lawful basis for processing, you have the right to withdraw that consent at any time as described in Section 19. Withdrawal of consent for one purpose does not affect processing conducted under a different lawful basis or for a different purpose.
Where we seek your consent for a specific use of your personal data, we will make the purpose clear at the time of collection and will not use your data for any materially different purpose without obtaining fresh consent or identifying another lawful basis.
5. Lawful Basis for Processing Personal Data
We process your personal data only where we have a lawful basis for doing so under applicable data protection law. The lawful bases on which we rely are:
5.1 Consent
Where you have given us clear, freely given, specific, informed, and unambiguous consent to process your personal data for one or more specific purposes. We rely on consent for marketing communications and for the processing of biometric data collected during identity verification.
5.2 Performance of a Contract
Where processing is necessary to fulfil a contract we have with you or to take steps at your request before entering into a contract. We rely on this basis to create and manage your Account, to verify your identity as part of onboarding, and to process transactions you initiate.
5.3 Legal Obligation
Where processing is necessary to comply with a legal obligation to which we are subject. We rely on this basis to meet our anti-money laundering and counter-financing of terrorism obligations, for regulatory reporting, and for financial record-keeping requirements.
5.4 Legitimate Interests
Where processing is necessary for our legitimate business interests or those of a third party, provided those interests are not overridden by your fundamental rights and freedoms. We rely on this basis for fraud prevention, security monitoring, and improving the Platform. Where we rely on legitimate interests, we have conducted a balancing test to ensure our interests do not override your rights.
5.5 Vital Interests
Where processing is necessary to protect the vital interests of you or another person. We may rely on this basis in emergency situations involving financial fraud or security threats.
5.6 Public Interest
Where processing is necessary for the performance of a task in the public interest, including cooperation with law enforcement agencies and regulatory authorities investigating financial crime.
6. Categories of Personal Data We Collect
6.1 Identity Data
- Full legal name as it appears on official identification documents.
- Date of birth.
- Gender.
- Nationality and country of residence.
- Copies or images of government-issued identification documents including National ID Card, International Passport, Driver's Licence, and Permanent Voter's Card.
6.2 Contact Data
- Email address.
- Phone number including mobile network information.
- Residential and business address.
- Alternative contact details where provided.
6.3 Verification and Biometric Data
- Bank Verification Number (BVN), cross-referenced against applicable verification databases.
- National Identification Number (NIN), cross-referenced against applicable identity registers.
- Facial biometric data collected during liveness verification, including the selfie or video captured and the biometric template derived from it.
- Results of identity verification checks conducted by our authorised verification partners.
6.4 Financial Data
- Bank account details including account number, bank name, and account name.
- Payment card details, which are processed and tokenised by our licensed payment partners and are not stored in raw form by us.
- Transaction history including dates, amounts, service types, and counterparty information.
- Account balance information where applicable.
- Source of funds information provided during enhanced verification.
6.5 Business and Corporate Data
For corporate users and merchants:
- Business name and trading name.
- Company registration number and Certificate of Incorporation.
- Memorandum and Articles of Association.
- Tax Identification Number.
- Details of directors, beneficial owners, and authorised signatories.
- Business address and registered office.
- Business bank account details.
- Business activity description and sector.
- KYB verification results.
6.6 Technical Data
- Internet Protocol (IP) address.
- Device identifiers including device ID and advertising ID.
- Browser type and version.
- Operating system and version.
- Device model and manufacturer.
- Screen resolution and display settings.
- Time zone and language settings.
- Mobile network information.
6.7 Usage Data
- Pages, screens, and features accessed on the Platform.
- Time and duration of Platform sessions.
- Search queries and navigation patterns.
- Transaction patterns and service usage frequency.
- Error logs and crash reports.
- Customer support interactions and communications.
6.8 Location Data
- Approximate location derived from your IP address.
- Precise location data from your mobile device where you have granted permission for location access.
6.9 Communication Data
- The content of your communications with our customer support team including emails and chat transcripts.
- Survey responses and feedback you provide.
- Communications sent through Platform messaging features where available.
6.10 Compliance and Risk Data
- Results of sanctions screening checks.
- PEP status and related disclosures.
- Fraud risk scores and indicators generated by our risk assessment systems.
- Investigation records where applicable.
- Records of your responses to our compliance enquiries.
7. How We Collect Your Personal Data
7.1 Direct Collection
You provide personal data directly when you:
- Register for an Account.
- Complete identity verification or enhanced KYC.
- Initiate or confirm a transaction.
- Contact our customer support team.
- Fill in forms on the Platform.
- Subscribe to our communications.
- Provide feedback or participate in surveys.
- Apply for a merchant or API account.
7.2 Automated Collection
We automatically collect technical and usage data when you access or use the Platform through:
- Server logs recording your IP address, browser type, pages visited, and access times.
- Cookies and similar tracking technologies as described in Section 16.
- Mobile application analytics tools recording usage patterns and performance data.
- Security monitoring tools logging access attempts and unusual activity.
7.3 Collection from Third Parties
We receive personal data from the following third-party sources:
- Identity verification partners: verification results, document verification results, and liveness check results.
- Payment partners: transaction data, payment status, and fraud indicators.
- Sanctions screening providers: sanctions and PEP screening results.
- Other Platform users: where another user provides your details in connection with a transaction, such as a merchant providing beneficiary information for a payout.
7.4 Incomplete Form Data
Where you partially complete a registration or onboarding form and do not finish the process, we may retain information provided up to that point and use it to contact you to assist you in completing the process.
8. Special Categories of Personal Data
Certain categories of personal data require enhanced protection because of their particularly sensitive nature. We may collect and process the following special categories in connection with the Platform:
8.1 Biometric Data
We collect facial biometric data as part of the Enhanced KYC verification process. See Section 17 for full details of how we handle biometric data.
8.2 Criminal History Data
In connection with our financial crime prevention obligations, we may process information about criminal convictions, offences, or allegations that are relevant to your use of the Platform, where we receive such information from authorities in the course of their investigations. We process this data on the basis of legal obligation and public interest.
8.3 Other Sensitive Data
We do not intentionally collect personal data relating to racial or ethnic origin, political opinions, religious beliefs, trade union membership, health, sexual orientation, or genetic data as part of our standard operations. If such data comes to our attention incidentally, we will handle it with the highest level of care and process it only where we have a specific legal basis.
9. How We Use Your Personal Data
9.1 Account Management
- To create, activate, and manage your Account.
- To authenticate your identity when you log in.
- To communicate with you about your Account.
- To process your requests to update Account information.
- To manage Account security.
9.2 Service Delivery
- To process and execute your transactions.
- To send you transaction confirmations, receipts, and status updates.
- To resolve failed transactions and process refunds where applicable.
- To communicate with third-party service providers to fulfil your service requests.
9.3 Identity Verification and Compliance
- To verify your identity as required by our compliance obligations and the requirements of our licensed partners.
- To screen your identity against applicable sanctions lists.
- To assess and monitor your risk profile on an ongoing basis.
- To conduct enhanced due diligence where required.
- To maintain records required by applicable law.
9.4 Fraud Prevention and Security
- To detect, investigate, and prevent fraudulent transactions and financial crime.
- To monitor transactions and account activity for suspicious patterns.
- To protect the security and integrity of the Platform.
- To investigate security breaches and incidents.
- To share relevant information with our licensed partners and law enforcement where required.
9.5 Customer Support
- To respond to your enquiries and complaints.
- To investigate and resolve disputes.
- To process your requests for account changes or refunds.
9.6 Legal and Regulatory Compliance
- To comply with our obligations under applicable anti-money laundering, counter-terrorism financing, and financial services laws.
- To report suspicious transactions to relevant financial intelligence authorities as required.
- To respond to lawful requests for information from regulatory and law enforcement authorities.
- To comply with court orders and other legal process.
- To enforce our Terms of Service and other policies.
9.7 Platform Improvement and Analytics
- To analyse usage patterns to understand how users interact with the Platform.
- To identify and fix technical issues.
- To develop new features and improve existing ones.
Analytics data used for this purpose is aggregated and anonymised where possible.
9.8 Marketing and Communications
- To send you service-related communications that you cannot opt out of, such as transaction confirmations, security alerts, and policy updates.
- To send you marketing communications about our products and services where you have consented.
- To personalise your Platform experience based on usage patterns and preferences.
You may opt out of marketing communications at any time by following the unsubscribe link in our emails or by contacting us at [email protected].
10. Fraud Prevention and Financial Crime Detection
We process your personal data for fraud prevention purposes based on our legitimate interest and our legal obligations under applicable financial crime law. Our fraud prevention activities include:
- Screening all users and transactions against sanctions lists and fraud databases.
- Monitoring transactions for patterns consistent with money laundering, terrorist financing, or other financial crime.
- Analysing transaction patterns to identify anomalies or suspicious activity.
- Sharing relevant information with our licensed payment partners who operate their own fraud detection systems.
- Reporting suspicious transactions to relevant financial intelligence authorities as required by law.
- Cooperating fully with investigations by relevant law enforcement and regulatory authorities.
Where we detect or suspect fraud or financial crime, we may immediately suspend or restrict your Account, hold pending transactions pending investigation, disclose relevant information to law enforcement and regulatory authorities, and retain relevant data for longer than standard retention periods.
We will not tip you off if we have filed a suspicious transaction report, as doing so may be unlawful.
11. Data Analytics and Platform Improvement
We use aggregated and anonymised data for analytics and benchmarking purposes including analysing which features and services are most used, identifying usage patterns at an aggregate level, and generating statistical reports for internal purposes.
Where analytics data relates to individual users, we ensure it is processed on a pseudonymised basis wherever possible and that individual users cannot be identified from the analytics output.
12. Marketing Communications
We may send you marketing communications about our products, services, and promotions where you have given consent. You can opt out at any time by clicking the unsubscribe link in any marketing email, updating your communication preferences in Account settings, or contacting us at [email protected].
Opting out of marketing communications will not affect your receipt of transactional and service communications necessary for the operation of your Account.
We do not sell your personal data to third parties for marketing purposes and do not share it with third parties for their own marketing purposes without your explicit consent.
13. Data Sharing and Disclosure
We do not sell your personal data to any third party. We may share your personal data with the following categories of recipients:
13.1 Licensed Service Partners
We share personal data with our licensed service partners who process it on our behalf or jointly with us as necessary to provide Platform services. These include partners for payment processing, identity verification, virtual asset services, and cross-border payments. All service partners are bound by contractual data processing obligations requiring them to process your data only for authorised purposes, maintain appropriate security, and comply with applicable data protection law.
13.2 Regulatory and Law Enforcement Authorities
We may disclose your personal data to regulatory and law enforcement authorities where required by law or where disclosure is necessary to comply with our financial crime obligations, respond to lawful requests, comply with court orders, or assist competent authorities in investigations.
13.3 Professional Advisors
We may share personal data with legal advisors, auditors, accountants, and other professional advisors where necessary, subject to appropriate confidentiality obligations.
13.4 Business Transfers
If we are involved in a merger, acquisition, restructuring, or sale of all or part of our business, your personal data may be transferred to the acquiring entity. We will notify you of any such transfer.
13.5 With Your Consent
We may share your personal data with third parties for purposes not described in this Policy where you have given explicit consent.
13.6 Protection of Rights
We may disclose your personal data where we believe disclosure is necessary to protect the rights, property, or safety of RIF Africa, our users, or the public.
14. Third-Party Data Processors
We engage third-party data processors who process personal data on our behalf. We ensure all processors are bound by appropriate data processing agreements requiring them to process data only on our instructions and for authorised purposes, implement appropriate security measures, not engage sub-processors without prior authorisation, assist us in meeting data subject obligations, and comply with applicable data protection law.
Our processors include providers in the categories of identity verification, payment processing, virtual asset services, cross-border payments, cloud hosting and infrastructure, analytics, customer support, and security monitoring. We do not name individual processors in this Policy as our processor relationships may change from time to time. You may request a current list of our processors by contacting [email protected].
15. Data Transfers Outside Nigeria
We primarily process and store personal data within Nigeria wherever possible. However, in some circumstances your personal data may be transferred to, stored, or processed outside Nigeria, including in connection with cloud infrastructure hosted in other jurisdictions, the services of international data processors, and cross-border payment services.
Where we transfer personal data outside Nigeria, we ensure such transfers comply with applicable data protection law and that one of the following safeguards applies:
- We have entered into data transfer agreements with the recipient that incorporate appropriate contractual protections.
- The transfer is necessary for the performance of a contract with you or for pre-contractual measures at your request.
- The transfer is necessary for the establishment, exercise, or defence of legal claims.
- You have given explicit consent to the transfer after being informed of the applicable risks.
We use hosting infrastructure located in the United States and Germany among other locations. Transfers to these jurisdictions are protected through contractual safeguards in our hosting and service agreements. By using the Platform, you acknowledge and consent to your personal data being transferred to these jurisdictions subject to the safeguards described above.
16. Cookies and Tracking Technologies
16.1 What Are Cookies
Cookies are small text files placed on your device when you visit a website or use an application. They allow the Platform to recognise your device and remember certain information about your visit.
16.2 Types of Cookies We Use
Strictly Necessary Cookies
Essential for the operation of the Platform. They enable core functions such as page navigation, access to secure areas, and session management. You cannot opt out of these cookies as the Platform cannot function without them.
Functional Cookies
Allow the Platform to remember your preferences and settings such as language preference and login status. Disabling these cookies may affect your experience.
Analytics Cookies
Used to understand how users interact with the Platform including which pages are most visited and how long users spend on the Platform. This data is used to improve the Platform. We deploy analytics cookies only with your explicit consent.
Security Cookies
Support our security functions including fraud detection and prevention of unauthorised access. These form part of our security infrastructure and cannot be disabled.
16.3 Cookie Consent
When you first visit the Platform, you will be presented with a cookie consent notice. You can choose to accept or decline non-essential cookies. You can change your cookie preferences at any time through your browser settings.
16.4 Managing Cookies
Most web browsers allow you to control cookies through their settings. Disabling certain cookies may affect Platform functionality. For more information about cookies, please visit www.aboutcookies.org.
16.5 Mobile Application Tracking
Our mobile applications may use mobile analytics tools and device identifiers to collect usage data. You can limit tracking through your device privacy settings.
17. Biometric Data
17.1 Collection
Facial biometric data is collected through the liveness verification step of the Enhanced KYC process. You will be asked to take a selfie or short video which is used to verify that you are the person in the identification document you upload and that you are a live person.
17.2 Processing
Biometric data is processed by our authorised identity verification partners using automated facial recognition technology. The verification result is returned to us and recorded on your Account.
17.3 Storage
We do not store raw biometric templates in our own systems. The biometric template generated during verification is processed by our verification partners in accordance with their security standards. Verification results and images captured during verification may be retained by us for the period described in Section 20.
17.4 Legal Basis
We process biometric data on the basis of your explicit consent, which you provide when you choose to complete Enhanced KYC verification. You may withdraw this consent by closing your Account, but this will prevent you from accessing services that require biometric verification.
17.5 Security
Biometric data is subject to the highest level of security controls available to us, including encryption at rest and in transit and access controls limiting access to authorised personnel only.
18. Children and Minor Users
18.1 Guardian-Managed Accounts
The Platform is accessible to users aged 11 and above through the Guardian-Managed Account structure described in the Terms of Service. In this structure, the Adult Guardian is the account holder and provides all personal data required for account registration and verification. The Minor Beneficiary User is not a direct contracting party and we do not collect personal data directly from them.
18.2 Children Under 11
The Platform is not directed at children under 11. We do not knowingly collect personal data from children under 11 other than as provided by an Adult Guardian in connection with supervised use of the Platform as described in the Terms of Service.
18.3 Inadvertent Collection
If you believe we have inadvertently collected personal data from a child under 11 without appropriate adult supervision and consent, please contact us immediately at [email protected] and we will take steps to address the situation promptly.
19. Your Rights as a Data Subject
You have the following rights in relation to your personal data. We will respond to all rights requests within 30 days of receipt, though complex requests may take longer, in which case we will notify you.
19.1 Right to Be Informed
You have the right to be informed about how we collect and use your personal data. This Policy is our primary mechanism for fulfilling this obligation.
19.2 Right of Access
You have the right to request a copy of the personal data we hold about you and information about how it is being processed. Submit a request by contacting [email protected]. We may require proof of your identity before processing your request.
19.3 Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data. You can update some information directly through your Account settings. For other information, contact [email protected].
19.4 Right to Erasure
You have the right to request deletion of your personal data in certain circumstances. This right does not apply where we are required to retain your data to comply with a legal obligation including our financial crime record-keeping requirements, or where the data is needed for legal claims.
19.5 Right to Restrict Processing
You have the right to request restriction of the processing of your personal data in certain circumstances, including where you contest the accuracy of the data or where the processing is unlawful.
19.6 Right to Data Portability
You have the right to receive a copy of the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to request that we transmit that data to another controller where technically feasible.
19.7 Right to Object
You have the right to object to processing where we rely on legitimate interests as our lawful basis, and where processing is for direct marketing purposes. Where you object to direct marketing processing, we will cease processing for that purpose immediately.
19.8 Rights Related to Automated Decision Making
You have the right not to be subject to decisions made solely on the basis of automated processing that produce legal or similarly significant effects on you. Where we make such decisions, you have the right to request human review, express your point of view, and contest the decision.
19.9 Right to Withdraw Consent
Where we process your personal data on the basis of your consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
19.10 How to Exercise Your Rights
To exercise any of the rights described above, contact our Data Protection contact at [email protected]. Please provide sufficient information to identify you and understand the nature of your request. We may require proof of identity before processing your request.
We will not charge a fee for processing rights requests in ordinary circumstances. Where requests are manifestly unfounded or excessive, we reserve the right to charge a reasonable administrative fee.
19.11 Right to Complain
If you are not satisfied with how we have handled your personal data or responded to your rights request, you have the right to lodge a complaint with the relevant data protection authority in your jurisdiction. We would appreciate the opportunity to address your concerns before you approach any authority and encourage you to contact us in the first instance at [email protected].
20. Retention of Your Personal Data
We retain your personal data only for as long as is necessary for the purposes for which it was collected or as required by applicable law.
| Data Category | Retention Period | Basis |
|---|---|---|
| KYC and identity verification records | 5 years after account closure | Legal obligation |
| Biometric verification results and images | 5 years after account closure | Legal obligation |
| Transaction records | 5 years after the transaction date | Legal obligation |
| Account information | Duration of account plus 5 years after closure | Legal obligation and legitimate interest |
| Suspicious transaction and investigation records | 10 years | Legal obligation |
| Customer support records | 3 years after the support interaction | Legitimate interest |
| Security and access logs | 1 year | Legitimate interest |
| Marketing preferences and opt-out records | Until withdrawn plus 1 year | Legal compliance |
| Fraud and compliance risk records | 7 years | Legal obligation and legitimate interest |
| Job applicant data | 1 year after the recruitment decision | Legitimate interest |
When personal data is no longer required, we securely delete, anonymise, or destroy it using processes appropriate to the format in which it is held.
21. Security of Your Personal Data
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, disclosure, or destruction.
21.1 Technical Measures
- Encryption of personal data in transit and at rest using industry-standard protocols.
- Secure network infrastructure including firewalls and intrusion detection systems.
- Regular security assessments of Platform infrastructure.
- Secure development practices including code review and security testing.
- Secure API authentication and authorisation mechanisms.
21.2 Organisational Measures
- Access controls limiting data access to authorised personnel.
- Regular training of personnel on data protection and security obligations.
- Documented procedures for detecting, reporting, and managing security incidents.
- Non-disclosure agreements with all personnel and contractors who access personal data.
21.3 Limitations
No method of electronic transmission or storage is completely secure. We cannot guarantee the absolute security of personal data transmitted over the internet. You are responsible for protecting your own login credentials and the security of your devices.
22. Automated Decision Making and Profiling
We use automated systems to make certain decisions in connection with your use of the Platform including decisions on identity verification approval, fraud risk scoring of transactions, determination of transaction limits, and sanctions screening. Where automated decisions have a significant effect on you, you have the right to request human review of that decision. Contact us at [email protected] to exercise this right.
We engage in profiling for fraud prevention purposes, analysing transaction patterns to identify anomalies that may indicate fraudulent activity. This profiling is conducted on the basis of our legitimate interest in preventing financial crime.
23. Accuracy of Your Personal Data
It is important that the personal data we hold about you is accurate and current. You are responsible for notifying us promptly of any change to your personal data. You can update certain information through your Account settings and for other changes please contact us at [email protected].
We are not responsible for any failure to deliver services or communications arising from inaccurate personal data on your Account.
24. Data Breach Notification
In the event of a personal data breach that is likely to result in significant risk to your rights and freedoms, we will notify you of the breach as soon as practicable after we become aware of it. The notification will include a description of the breach, the categories and approximate number of individuals affected, the likely consequences, the measures we have taken or propose to take, and contact details for further information.
We will also notify relevant data protection and regulatory authorities of reportable breaches within the timeframes required by applicable law.
25. Confidentiality
We treat your personal data as confidential information and will not disclose it to any third party other than as described in this Policy. All personnel and contractors with access to your personal data are bound by confidentiality obligations.
Where we are required by law to disclose your personal data to a third party, we will notify you where we are legally permitted to do so.
26. Job Applicants
If you apply for a position with RIF Africa, you will provide personal data including your name, contact details, educational history, professional experience, and other relevant information. We use this solely to assess your application and candidacy. We may share your data with third-party recruitment service providers and background check providers as relevant to the process.
We retain job applicant data for one year after the recruitment decision. To request deletion, contact [email protected].
27. Changes to This Policy
We reserve the right to update, modify, or replace this Policy at any time. We will communicate material changes through Platform notifications, our social media channels, community groups, and other available announcement channels. We do not guarantee advance notice of every change and we are not obligated to notify every user by email ahead of changes.
You are responsible for reviewing this Policy periodically. We recommend reviewing it at least monthly. The date of the most recent update is displayed at the top of this Policy. Your continued use of the Platform after the effective date of any update constitutes your acceptance of the changes.
28. Contact and Complaints
For any questions, concerns, or requests relating to this Policy or our data protection practices:
Company: RIF African Business Enterprise (RC 2709434)
Trading As: Subpadi
Website: www.subpadi.com
Data Protection: [email protected]
Support Email: [email protected]
Legal Notices: [email protected]
Registered Office: 1, Omitoogun Chamber, Abeokuta, FRN, Nigeria
To complain about our data protection practices, you may contact the relevant data protection authority in your jurisdiction. We would appreciate the opportunity to address your concerns first and encourage you to contact our Data Protection team in the first instance at [email protected].
This Privacy Policy was last updated in July 2026. Subpadi is a product of RIF African Business Enterprise. Future updates will reflect any transition to Rif Pay Limited as the operating entity.