SW SmartWorks360

Data Protection & Privacy Policy

Last updated: 24 July 2026 · Aligned with the Nigeria Data Protection Act, 2023 (NDPA 2023) and the NDPC General Application and Implementation Directive, 2025 (GAID 2025).

This Policy explains how SmartWorks360 (“we”, “us”, “our”) collects, uses, secures, retains, and shares personal data — including data obtained through third-party identity and corporate registry lookups — when you use our mobile app, employer dashboard, and related services (the “Services”). We process personal data as a data processor where we process employee personal data on behalf of our corporate clients, and as a data controller for our own operations.

1. Who we are and our data protection roles

2. Legal framework

We process personal data in accordance with:

We apply the NDPA data-processing principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; and integrity, confidentiality and accountability.

3. Personal data we process

4. Registry & identity lookup data — how it is managed

To verify organisations and applicants, we retrieve data from licensed lookup providers, including Mono (corporate registry / CAC lookups) and Monnify (BVN identity match). This section describes the full lifecycle of that lookup data, as required for our onboarding with those providers.

4.1 What is retrieved

4.2 Purpose (purpose limitation)

Lookup data is retrieved and used solely to verify the identity and legitimacy of an organisation and its authorised representatives, and of individual applicants, for Know-Your-Customer (KYC), anti-fraud, and regulatory-compliance purposes. It is not used for marketing, profiling unrelated to verification, automated decision-making with legal effect without human review, or any purpose incompatible with verification.

4.3 Lawful basis for lookups

We perform lookups on the basis of (a) the necessity of processing for entering into and performing our contract with the organisation/applicant; (b) compliance with our legal and regulatory KYC/AML obligations; and (c) our legitimate interest in preventing fraud. Where a director’s or third party’s personal data is returned by a registry, we rely on the legal obligation and legitimate-interest bases and limit use strictly to verification. The person initiating verification confirms they are authorised to submit the organisation’s details.

4.4 Storage, minimisation & security of lookup data

4.5 Retention & deletion of lookup data

We retain verification and lookup data only for as long as necessary to fulfil the verification purpose and to meet legal, tax, and regulatory record-keeping obligations (including AML record-retention requirements). When it is no longer required, we delete or irreversibly anonymise it. An organisation or data subject may request deletion, which we honour subject to overriding legal-retention requirements.

4.6 Sharing of lookup data

Lookup data is not sold and is not shared for any purpose other than verification. It is accessible to the relevant employer organisation only insofar as it concerns that organisation’s own registration, and may be disclosed to regulators or law enforcement where legally required.

5. Lawful basis of processing

Under NDPA 2023, we rely on one or more of the following bases:

6. Use & data minimisation

We collect and process only the personal data necessary for the stated purposes, retain it only as long as needed, and design our verification flows to request the minimum data required. High-risk processing is subject to a Data Protection Impact Assessment (DPIA) as contemplated by GAID 2025.

7. Processors & cross-border transfers

We engage vetted service providers as data processors under written agreements requiring NDPA-consistent safeguards, including:

Where any processing or storage occurs outside Nigeria, we ensure an adequate level of protection and appropriate safeguards consistent with the NDPA 2023 and GAID 2025 cross-border transfer requirements.

8. How we protect data

We apply technical and organisational measures including encryption of sensitive data at rest (e.g. BVN, bank account numbers) and TLS in transit, role-based access controls, audit logging of administrative actions, and continuous monitoring. No system is perfectly secure, but we work to protect personal data and to respond promptly to incidents.

9. Data retention

We retain personal data for as long as an account is active and as long as necessary to provide the Services and to meet legal, tax, and regulatory obligations, resolve disputes, and enforce our agreements. Financial and verification records may be retained for statutory periods. Thereafter we delete or anonymise the data.

10. Your rights

Subject to applicable law, you may:

To exercise these rights, contact our DPO (below). We respond within the timelines required by the NDPA 2023 and GAID 2025. You also have the right to lodge a complaint with the NDPC.

11. Breach notification

In the event of a personal-data breach likely to result in risk to data subjects, we will notify the NDPC and, where required, affected individuals in accordance with the timelines and requirements of the NDPA 2023 and GAID 2025 (including notification to the Commission within 72 hours of becoming aware, where applicable).

12. Children

The Services are intended for employed adults (18+) and are not directed at children. We do not knowingly collect data from anyone under 18.

13. Changes to this Policy

We may update this Policy from time to time. We will post the updated version here with a new “Last updated” date and, where appropriate, notify you in the app.

14. Contact us

For any privacy question, request, or complaint, contact our Data Protection Officer at privacy@smartworks360.com. You may also contact the Nigeria Data Protection Commission (NDPC) as the supervisory authority.