Privacy Policy
Version 1.0-NG (draft) · Effective 16 July 2026
This policy applies to SafeGuard Workers Nigeria ("we", "us", "our"). We are the data controller for all personal data described here, and we comply with the Nigeria Data Protection Act 2023 (NDPA) and the regulations and directives issued under it by the Nigeria Data Protection Commission (NDPC).
This policy is undergoing legal review
Details of our registered Nigerian entity and our NDPC registration status will be published here once confirmed. Your data is protected as described below in the meantime, and you can reach our privacy team at any time at support@safeguardworkers.com.ng.
1. Data Controller
Controller: SafeGuard Workers Nigeria
Registered address: to be published following completion of legal review
Privacy enquiries: support@safeguardworkers.com.ng
General support: support@safeguardworkers.com.ng
The NDPA requires data controllers of major importance to register with the NDPC and designate a Data Protection Officer. We are currently assessing whether we meet that designation; this section will be updated with our registration details and DPO contact once that assessment is complete. Until then, all data protection enquiries are handled by our privacy contact at the address above.
2. What Personal Data We Collect
2.1 Account Registration
- Full name, email address, password (stored as bcrypt hash — never in plaintext)
- Phone number (optional)
- Job role and employer sector
- Nationality / work permit status (optional — you may select "prefer not to say")
- Trade union membership and union name (optional)
- Consent timestamp and policy version
2.2 Incident Reports
- Workplace name, specific location, date and time of incident
- Free-text description of what happened
- Name and role of any person involved (employer, manager, colleague, customer)
- Witness names and contact information (if provided)
- Injury details, medical attention sought, days off work
- Retaliation events, timeline, and description
- Police or NAPTIP involvement and any case reference number
- Details of document confiscation (NIN, passport, ID card) or coercion by an employer
2.3 Evidence Files
- File contents (photos, PDFs, documents) stored in encrypted object storage
- File metadata: name, type, size, SHA-256 hash, upload timestamp
- EXIF metadata extracted automatically: GPS coordinates, device make/model, original capture timestamp — you are notified of this at upload
- Masked IP address and browser user-agent at upload time
2.4 Legal Claims
- Case type, status, notes, and linked incident report
- Legal representative contact details (name, firm, email, phone)
- Retaliation event log
- Legal deadlines (National Industrial Court filing dates, limitation dates)
2.5 Technical & Usage Data
- Masked IP address — the last octet of your IPv4 address (or last 4 groups of IPv6) are zeroed before storage. We never store your full IP.
- Browser user-agent string (for device compatibility diagnostics)
- Audit log entries: action type, resource accessed, timestamp (no report content)
- Session authentication cookies (HTTP-only, Secure, SameSite=Lax)
2.6 Anonymous Submissions
If you use our anonymous submission option, no account or email is required. We store: incident type, workplace sector, state (Nigerian state, not precise location), retaliation flag, injury flag, and work-permit flag. We also generate a UUID token you can use to claim the report later.
Important: anonymous does not mean unidentifiable
The combination of fields you submit (sector + state + incident type + date) may be sufficient to identify you in a small workplace. We cannot guarantee anonymity. If you are at serious risk, consider using a public computer or a device your employer cannot access.
3. Sensitive Personal Data (Section 30 NDPA)
We process sensitive personal data
The nature of workplace incident reporting means we handle sensitive personal data as defined by section 30 of the NDPA. This data receives the highest level of protection we can provide.
| Sensitive Category | Where It Appears | Condition We Rely On |
|---|---|---|
| Health data | Injury description, medical attention, days off work | Protection of vital interests; establishment or defence of legal claims |
| Ethnic origin / nationality (proxy) | Nationality, work permit status, document confiscation by employer | Substantial public interest; establishment or defence of legal claims |
| Trade union membership | Union member flag, union name (NLC / TUC / sector union) | Your explicit consent |
| Data relating to criminal allegations | Police or NAPTIP case reference, retaliation descriptions | Establishment or defence of legal claims; substantial public interest |
4. Lawful Basis for Each Processing Activity
Section 25 of the NDPA requires a lawful basis for every processing activity, and section 30 imposes additional conditions for sensitive personal data. The table below sets out our basis for each activity.
| Processing Activity | Lawful Basis (s.25) | Sensitive Data Condition (s.30) |
|---|---|---|
| Account registration | Contract + Consent | Substantial public interest |
| Incident report storage | Contract + Consent | Vital interests + Legal claims |
| Anonymous submissions | Legitimate interests | Minimised — pseudonymous data |
| Evidence file storage | Contract | Legal claims |
| Legal claims management | Contract | Legal claims |
| Near-miss logging | Contract + Legitimate interests | N/A |
| Sharing with lawyers / organisations | Consent (worker-initiated) | Explicit consent |
| Transactional emails | Contract | N/A (reference IDs only) |
| Error monitoring (Sentry) | Legitimate interests | N/A (body stripped) |
| Session replay (Sentry) | Consent | N/A |
| Product analytics (PostHog) | Consent | N/A (usage events only) |
| Audit logging | Legal obligation + Legitimate interests | N/A |
| Data subject rights responses | Legal obligation | N/A |
| Police / NAPTIP report assistance | Contract | Legal claims |
5. How We Use Your Data
- Providing the service — storing and displaying your reports, evidence, and legal cases
- Authentication — verifying your identity on each request
- Communications — confirmation emails, legal deadline reminders, organisation invites
- AI incident classification — automatically categorising your report to assist you in understanding its urgency and type. This runs entirely on our platform; no data is sent to external AI APIs without your knowledge.
- Evidence integrity — computing SHA-256 hashes and optional blockchain timestamps to create tamper-evident records for legal proceedings
- Security and fraud prevention — rate limiting, audit logging, and abuse detection
- Platform stability — error monitoring via Sentry (body stripped; see §10)
- Legal compliance — responding to lawful requests from courts or regulators
We do not sell, rent, or broker your data to any third party.
We do not use your data for advertising, profiling, or automated decision-making that produces legal or significant effects.
7. Where Your Data Is Stored (Cross-Border Transfers)
Your data is stored outside Nigeria
Our infrastructure providers store data in European Union and United States data centres. There is currently no Nigerian data-centre option for our stack.
The NDPA permits transfers of personal data outside Nigeria where the recipient is subject to a law, contract, or binding scheme that provides an adequate level of protection. All our sub-processors are bound by written data processing agreements incorporating standard contractual protections (including GDPR-grade Standard Contractual Clauses), which we rely on as the safeguard for these transfers. Copies of the relevant clauses are available on request.
8. Data Retention Periods
We keep data only as long as necessary for the purpose it was collected, or as required by law. The table below sets out our retention periods.
| Data Category | Retention Period | Reason |
|---|---|---|
| User profile (active account) | Account life + 30 days | Contract |
| User profile (after deletion request) | 30 days (anonymised), then hard-deleted | Right to erasure |
| Incident reports | 7 years from submission | Legal claims window — state limitation laws (typically 5–6 years) plus margin |
| Witness records | Deleted immediately on account deletion request | Third-party PII |
| Evidence files (no legal hold) | 7 years | Legal claims |
| Evidence files (under legal hold) | Until hold released, then 7 years | Legal obligation |
| Legal case data | 7 years after case closure | Legal claims window |
| Near-miss logs | 7 years | Employees’ Compensation Act 2010 / NSITF claims |
| Audit logs | 2 years | Legitimate interests (security) |
| API token usage logs | 90 days | Legitimate interests (security) |
| Anonymous submissions | 3 years | Legitimate interests |
| Sentry error logs | 90 days (Sentry-managed) | Legitimate interests |
Hard-deletion after account closure
When you request account deletion, your profile is immediately pseudonymised (name replaced with "Deleted User"; contact fields nulled; work-permit/union data cleared). All incident report PII fields (descriptions, names, locations, medical details) are anonymised within the same request. Witness records are hard-deleted immediately. The remaining structural data is permanently deleted within 30 days.
9. Security Measures
Encryption in transit
All data transmitted over TLS 1.3. HTTP requests are rejected.
Encryption at rest
All database rows and file storage encrypted at rest by Supabase.
Row Level Security
Database RLS policies enforce data isolation — you can only access your own records.
IP address masking
We zero the last octet of your IP before any storage. Full IPs are never persisted.
Input sanitisation
All user inputs are sanitised before storage to prevent XSS and injection.
Rate limiting
All API endpoints are rate limited per user or IP using persistent Supabase counters.
Despite these measures, no system is completely secure. If you discover a security vulnerability, please report it responsibly to support@safeguardworkers.com.ng.
11. Your Rights Under the NDPA 2023 (Part VI)
You have the following rights. Most can be exercised directly in your Account Settings. We will respond within 30 days.
Right of Access
Request confirmation of what personal data we hold about you and a copy of it.
How: Account Settings → Download my data
Right to Data Portability
Receive your data in a structured, machine-readable JSON format.
How: Account Settings → Download my data
Right to Correction
Correct inaccurate personal data. You can update your profile directly.
How: Account Settings → Personal Details, or email us
Right to Erasure
Request deletion of your data. Profile PII and report PII are anonymised immediately; full deletion within 30 days. Some data may be retained where a legal hold applies or where we have a legal obligation.
How: Account Settings → Delete account
Right to Restrict Processing
Pause all non-essential processing of your data while a dispute is resolved.
How: Account Settings → Your Privacy Rights → Restrict processing
Right to Object
Object to processing based on legitimate interests. We will cease non-essential processing immediately.
How: Account Settings → Your Privacy Rights → Object to processing
Right to Withdraw Consent
Withdraw the consent you gave at registration, as easily as you gave it. Some features may become unavailable if consent is withdrawn.
How: Account Settings → Your Privacy Rights → Withdraw consent
To exercise rights not available in Account Settings (correction, portability, complex erasure), email support@safeguardworkers.com.ng with "Privacy Rights Request" in the subject line. We may ask you to verify your identity.
12. Age Requirements
Our Nigerian service is intended for workers aged 18 and over. The NDPA requires verifiable parental or guardian consent before processing the personal data of a child (under 18), and we do not have a mechanism to obtain it. If you believe we have collected data from anyone under 18, please contact us immediately at support@safeguardworkers.com.ng and we will delete the data without delay.
If you are under 18 and experiencing forced labour or workplace abuse, you can still get help without creating an account: call NAPTIP on 627 (toll-free, 24 hours) or the NHRC on 6472.
13. Changes to This Privacy Policy
We will update this policy when our processing activities change. For material changes (new sensitive-data processing, new sub-processors, changes to retention) we will notify registered users by email and require re-consent where the lawful basis is consent. Minor clarifications will be noted in the version history.
The current version is 1.0-NG (draft), effective 16 July 2026. Older versions are available on request.
14. Contact & Complaints
Privacy enquiries: support@safeguardworkers.com.ng
General support: support@safeguardworkers.com.ng
Right to complain to the NDPC
If you are not satisfied with how we handle your personal data or respond to your rights request, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC), the supervisory authority under the NDPA:
Website: https://ndpc.gov.ng
We ask that you contact us first — we will do our best to resolve your concern within 30 days.