SW SmartWorks360

Data Protection & Privacy Policy

Last updated: 22 August 2026 · Aligned with the Nigeria Data Protection Act, 2023 (NDPA 2023) and the NDPC General Application and Implementation Directive, 2025 (GAID 2025).

This Policy explains how SmartWorks360 (“we”, “us”, “our”) collects, uses, secures, retains, and shares personal data — including data obtained through third-party identity and corporate registry lookups — when you use our mobile app, employer dashboard, and related services (the “Services”). We process personal data as a data processor where we process employee personal data on behalf of our corporate clients, and as a data controller for our own operations.

1. Who we are and our data protection roles

2. Legal framework

We process personal data in accordance with:

We apply the NDPA data-processing principles: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; and integrity, confidentiality and accountability.

3. Personal data we process

4. Registry & identity lookup data — how it is managed

To verify organisations and applicants, we retrieve data from licensed lookup providers, including Mono (corporate registry / CAC lookups) and Monnify (BVN identity match). This section describes the full lifecycle of that lookup data, as required for our onboarding with those providers.

4.1 What is retrieved

4.2 Purpose (purpose limitation)

Lookup data is retrieved and used solely to verify the identity and legitimacy of an organisation and its authorised representatives, and of individual applicants, for Know-Your-Customer (KYC), anti-fraud, and regulatory-compliance purposes. It is not used for marketing, profiling unrelated to verification, automated decision-making with legal effect without human review, or any purpose incompatible with verification.

4.3 Lawful basis for lookups

We perform lookups on the basis of (a) the necessity of processing for entering into and performing our contract with the organisation/applicant; (b) compliance with our legal and regulatory KYC/AML obligations; and (c) our legitimate interest in preventing fraud. Where a director’s or third party’s personal data is returned by a registry, we rely on the legal obligation and legitimate-interest bases and limit use strictly to verification. The person initiating verification confirms they are authorised to submit the organisation’s details.

4.4 Storage, minimisation & security of lookup data

4.5 Retention & deletion of lookup data

We retain verification and lookup data only for as long as necessary to fulfil the verification purpose and to meet legal, tax, and regulatory record-keeping obligations (including AML record-retention requirements). When it is no longer required, we delete or irreversibly anonymise it. An organisation or data subject may request deletion, which we honour subject to overriding legal-retention requirements.

4.6 Sharing of lookup data

Lookup data is not sold and is not shared for any purpose other than verification. It is accessible to the relevant employer organisation only insofar as it concerns that organisation’s own registration, and may be disclosed to regulators or law enforcement where legally required.

5. Biometric data — face verification

Salary-advance applicants complete a face scan (liveness check) as part of first-time identity verification. Because a facial template derived for the purpose of uniquely identifying a person is sensitive personal data under the NDPA 2023, this section sets out that processing separately and in full.

5.1 What is processed

5.2 Purpose (purpose limitation)

The face scan is used solely to establish that a real, live person is present and that this person is the individual shown on the submitted identity document, for KYC, anti-fraud, and AML compliance. It is not used for marketing, advertising, profiling, emotion or demographic inference, surveillance, or model training. We operate no face collection or biometric search index: every comparison is one-to-one against the applicant’s own document, never a one-to-many search.

5.3 Lawful basis

We rely on the explicit consent of the data subject, obtained in-app immediately before the scan begins, together with our legal obligation to conduct KYC/AML identity verification. Consent is freely given: an employee who declines retains full access to the remainder of the Services and forgoes only the salary-advance facility, for which verified identity is a precondition of lending. Consent may be withdrawn at any time, and withdrawal triggers erasure of the biometric records subject to overriding AML retention obligations.

5.4 Processor, storage, and cross-border transfer

5.5 Retention & erasure

Biometric verification records form part of the KYC file we are required to retain under AML record-keeping rules, and are held for the statutory period following the end of the customer relationship, after which they are deleted or irreversibly anonymised. A data subject may request erasure at any time; we honour such requests except where retention is legally mandated, and we inform the data subject where that exception applies.

5.6 Sharing

Biometric data is never sold and is not disclosed to the employer organisation, which receives only the binary outcome of verification. It may be disclosed to regulators or law enforcement where legally required. Given the sensitivity of this processing, it is treated as high-risk and subject to a Data Protection Impact Assessment under GAID 2025.

6. Lawful basis of processing

Under NDPA 2023, we rely on one or more of the following bases:

7. Use & data minimisation

We collect and process only the personal data necessary for the stated purposes, retain it only as long as needed, and design our verification flows to request the minimum data required. High-risk processing is subject to a Data Protection Impact Assessment (DPIA) as contemplated by GAID 2025.

8. Processors & cross-border transfers

We engage vetted service providers as data processors under written agreements requiring NDPA-consistent safeguards, including:

Where any processing or storage occurs outside Nigeria, we ensure an adequate level of protection and appropriate safeguards consistent with the NDPA 2023 and GAID 2025 cross-border transfer requirements. Specifically, identity documents and biometric face-scan data are stored and processed in AWS’s Europe (Ireland) region; that transfer is made on the basis of the data subject’s explicit consent and a data processing agreement imposing NDPA-consistent obligations on the processor.

9. How we protect data

We apply technical and organisational measures including encryption of sensitive data at rest (e.g. BVN, bank account numbers) and TLS in transit, role-based access controls, audit logging of administrative actions, and continuous monitoring. No system is perfectly secure, but we work to protect personal data and to respond promptly to incidents.

10. Data retention

We retain personal data for as long as an account is active and as long as necessary to provide the Services and to meet legal, tax, and regulatory obligations, resolve disputes, and enforce our agreements. Financial and verification records may be retained for statutory periods. Thereafter we delete or anonymise the data.

11. Your rights

Subject to applicable law, you may:

To exercise these rights, contact our DPO (below). We respond within the timelines required by the NDPA 2023 and GAID 2025. You also have the right to lodge a complaint with the NDPC.

12. Breach notification

In the event of a personal-data breach likely to result in risk to data subjects, we will notify the NDPC and, where required, affected individuals in accordance with the timelines and requirements of the NDPA 2023 and GAID 2025 (including notification to the Commission within 72 hours of becoming aware, where applicable).

13. Children

The Services are intended for employed adults (18+) and are not directed at children. We do not knowingly collect data from anyone under 18.

14. Changes to this Policy

We may update this Policy from time to time. We will post the updated version here with a new “Last updated” date and, where appropriate, notify you in the app.

15. Contact us

For any privacy question, request, or complaint, contact our Data Protection Officer at privacy@smartworks360.com. You may also contact the Nigeria Data Protection Commission (NDPC) as the supervisory authority.