Data Protection & Privacy Policy
Last updated: 24 July 2026 · Aligned with the Nigeria Data Protection Act, 2023 (NDPA 2023) and the NDPC General Application and Implementation Directive, 2025 (GAID 2025).
This Policy explains how SmartWorks360 (“we”, “us”, “our”) collects, uses, secures, retains, and shares personal data — including data obtained through third-party identity and corporate registry lookups — when you use our mobile app, employer dashboard, and related services (the “Services”). We process personal data as a data processor where we process employee personal data on behalf of our corporate clients, and as a data controller for our own operations.
1. Who we are and our data protection roles
- Entity: SmartWorks360.
- As data processor: where we process the personal data of our corporate clients’ employees — names, employment records, salary details, bank account details, and identity data (BVN and government-issued identity documents) — we do so on behalf of and on the instructions of the client organisation, which remains the data controller of that data.
- As data controller: we are the controller for our own operations, including the personal data of our own employees and of our business contacts at client organisations.
- Data Protection Officer (DPO): reachable at privacy@smartworks360.com.
- Supervisory authority: the Nigeria Data Protection Commission (NDPC).
2. Legal framework
We process personal data in accordance with:
- the Nigeria Data Protection Act, 2023 (NDPA 2023) — the principal data protection law, which builds on and supersedes the earlier NDPR framework;
- the NDPC General Application and Implementation Directive, 2025 (GAID 2025), which operationalises the NDPA; and
- any other applicable Nigerian law and the contractual and regulatory requirements of our licensed data-source partners.
We apply the NDPA data-processing principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; and integrity, confidentiality and accountability.
3. Personal data we process
- Identity & contact: name, email address, phone number, date of birth.
- Employment data: employer, role, staff ID, salary details (provided by the employer).
- Financial data: bank account details; and, for salary-advance applicants, Bank Verification Number (BVN).
- Verification media: a photo of a government ID and a selfie/liveness capture.
- Registry & lookup data: corporate and identity information retrieved from licensed providers — see the next section.
- Device & usage data: device type, app version, and diagnostic logs.
4. Registry & identity lookup data — how it is managed
To verify organisations and applicants, we retrieve data from licensed lookup providers, including Mono (corporate registry / CAC lookups) and Monnify (BVN identity match). This section describes the full lifecycle of that lookup data, as required for our onboarding with those providers.
4.1 What is retrieved
- Corporate registry (CAC) lookup via Mono, keyed by the company’s RC number: company name, RC number, registration date, registered/head-office address, and the particulars of the company’s directors — each director’s name, designation, date of birth, nationality, and address.
- BVN identity match via Monnify, for individual salary-advance applicants: a match result comparing the applicant-supplied name, date of birth, and phone against the BVN record. We receive match outcomes; we do not retrieve or store the full BVN record.
4.2 Purpose (purpose limitation)
Lookup data is retrieved and used solely to verify the identity and legitimacy of an organisation and its authorised representatives, and of individual applicants, for Know-Your-Customer (KYC), anti-fraud, and regulatory-compliance purposes. It is not used for marketing, profiling unrelated to verification, automated decision-making with legal effect without human review, or any purpose incompatible with verification.
4.3 Lawful basis for lookups
We perform lookups on the basis of (a) the necessity of processing for entering into and performing our contract with the organisation/applicant; (b) compliance with our legal and regulatory KYC/AML obligations; and (c) our legitimate interest in preventing fraud. Where a director’s or third party’s personal data is returned by a registry, we rely on the legal obligation and legitimate-interest bases and limit use strictly to verification. The person initiating verification confirms they are authorised to submit the organisation’s details.
4.4 Storage, minimisation & security of lookup data
- We store only the fields necessary for verification (company name, RC number, business address, and director particulars needed to complete director verification). We do not retain provider payloads beyond what is required.
- Lookup results are stored in access-controlled databases; sensitive identifiers (e.g. BVN) are encrypted at rest and are never displayed in full.
- Access is restricted to authorised personnel and internal compliance staff on a need-to-know basis, and administrative access is audit-logged.
- Data in transit is protected with TLS encryption.
4.5 Retention & deletion of lookup data
We retain verification and lookup data only for as long as necessary to fulfil the verification purpose and to meet legal, tax, and regulatory record-keeping obligations (including AML record-retention requirements). When it is no longer required, we delete or irreversibly anonymise it. An organisation or data subject may request deletion, which we honour subject to overriding legal-retention requirements.
4.6 Sharing of lookup data
Lookup data is not sold and is not shared for any purpose other than verification. It is accessible to the relevant employer organisation only insofar as it concerns that organisation’s own registration, and may be disclosed to regulators or law enforcement where legally required.
5. Lawful basis of processing
Under NDPA 2023, we rely on one or more of the following bases:
- Contract — to provide the Services you or your employer request.
- Legal obligation — KYC/AML, tax, and regulatory compliance.
- Legitimate interest — fraud prevention and securing the Services.
- Consent — where required (e.g. certain verification steps); consent may be withdrawn at any time.
6. Use & data minimisation
We collect and process only the personal data necessary for the stated purposes, retain it only as long as needed, and design our verification flows to request the minimum data required. High-risk processing is subject to a Data Protection Impact Assessment (DPIA) as contemplated by GAID 2025.
7. Processors & cross-border transfers
We engage vetted service providers as data processors under written agreements requiring NDPA-consistent safeguards, including:
- Mono — corporate registry (CAC) lookups.
- Monnify — payments, wallet funding, card processing, and BVN identity match.
- Cloud hosting, storage, and email providers supporting our operations.
Where any processing or storage occurs outside Nigeria, we ensure an adequate level of protection and appropriate safeguards consistent with the NDPA 2023 and GAID 2025 cross-border transfer requirements.
8. How we protect data
We apply technical and organisational measures including encryption of sensitive data at rest (e.g. BVN, bank account numbers) and TLS in transit, role-based access controls, audit logging of administrative actions, and continuous monitoring. No system is perfectly secure, but we work to protect personal data and to respond promptly to incidents.
9. Data retention
We retain personal data for as long as an account is active and as long as necessary to provide the Services and to meet legal, tax, and regulatory obligations, resolve disputes, and enforce our agreements. Financial and verification records may be retained for statutory periods. Thereafter we delete or anonymise the data.
10. Your rights
Subject to applicable law, you may:
- access the personal data we hold about you and request a copy;
- request correction of inaccurate or incomplete data;
- request erasure, subject to legal-retention requirements;
- object to or restrict certain processing, and withdraw consent where processing relies on consent;
- request portability of data you provided, where applicable.
To exercise these rights, contact our DPO (below). We respond within the timelines required by the NDPA 2023 and GAID 2025. You also have the right to lodge a complaint with the NDPC.
11. Breach notification
In the event of a personal-data breach likely to result in risk to data subjects, we will notify the NDPC and, where required, affected individuals in accordance with the timelines and requirements of the NDPA 2023 and GAID 2025 (including notification to the Commission within 72 hours of becoming aware, where applicable).
12. Children
The Services are intended for employed adults (18+) and are not directed at children. We do not knowingly collect data from anyone under 18.
13. Changes to this Policy
We may update this Policy from time to time. We will post the updated version here with a new “Last updated” date and, where appropriate, notify you in the app.
14. Contact us
For any privacy question, request, or complaint, contact our Data Protection Officer at privacy@smartworks360.com. You may also contact the Nigeria Data Protection Commission (NDPC) as the supervisory authority.