Skip to main content

Privacy Policy

Version 1.0-NG (draft) · Effective 16 July 2026

This policy applies to SafeGuard Workers Nigeria ("we", "us", "our"). We are the data controller for all personal data described here, and we comply with the Nigeria Data Protection Act 2023 (NDPA) and the regulations and directives issued under it by the Nigeria Data Protection Commission (NDPC).

This policy is undergoing legal review

Details of our registered Nigerian entity and our NDPC registration status will be published here once confirmed. Your data is protected as described below in the meantime, and you can reach our privacy team at any time at support@safeguardworkers.com.ng.

1. Data Controller

Controller: SafeGuard Workers Nigeria

Registered address: to be published following completion of legal review

Privacy enquiries: support@safeguardworkers.com.ng

General support: support@safeguardworkers.com.ng

The NDPA requires data controllers of major importance to register with the NDPC and designate a Data Protection Officer. We are currently assessing whether we meet that designation; this section will be updated with our registration details and DPO contact once that assessment is complete. Until then, all data protection enquiries are handled by our privacy contact at the address above.

2. What Personal Data We Collect

2.1 Account Registration

  • Full name, email address, password (stored as bcrypt hash — never in plaintext)
  • Phone number (optional)
  • Job role and employer sector
  • Nationality / work permit status (optional — you may select "prefer not to say")
  • Trade union membership and union name (optional)
  • Consent timestamp and policy version

2.2 Incident Reports

  • Workplace name, specific location, date and time of incident
  • Free-text description of what happened
  • Name and role of any person involved (employer, manager, colleague, customer)
  • Witness names and contact information (if provided)
  • Injury details, medical attention sought, days off work
  • Retaliation events, timeline, and description
  • Police or NAPTIP involvement and any case reference number
  • Details of document confiscation (NIN, passport, ID card) or coercion by an employer

2.3 Evidence Files

  • File contents (photos, PDFs, documents) stored in encrypted object storage
  • File metadata: name, type, size, SHA-256 hash, upload timestamp
  • EXIF metadata extracted automatically: GPS coordinates, device make/model, original capture timestamp — you are notified of this at upload
  • Masked IP address and browser user-agent at upload time

2.4 Legal Claims

  • Case type, status, notes, and linked incident report
  • Legal representative contact details (name, firm, email, phone)
  • Retaliation event log
  • Legal deadlines (National Industrial Court filing dates, limitation dates)

2.5 Technical & Usage Data

  • Masked IP address — the last octet of your IPv4 address (or last 4 groups of IPv6) are zeroed before storage. We never store your full IP.
  • Browser user-agent string (for device compatibility diagnostics)
  • Audit log entries: action type, resource accessed, timestamp (no report content)
  • Session authentication cookies (HTTP-only, Secure, SameSite=Lax)

2.6 Anonymous Submissions

If you use our anonymous submission option, no account or email is required. We store: incident type, workplace sector, state (Nigerian state, not precise location), retaliation flag, injury flag, and work-permit flag. We also generate a UUID token you can use to claim the report later.

Important: anonymous does not mean unidentifiable

The combination of fields you submit (sector + state + incident type + date) may be sufficient to identify you in a small workplace. We cannot guarantee anonymity. If you are at serious risk, consider using a public computer or a device your employer cannot access.

3. Sensitive Personal Data (Section 30 NDPA)

We process sensitive personal data

The nature of workplace incident reporting means we handle sensitive personal data as defined by section 30 of the NDPA. This data receives the highest level of protection we can provide.

Sensitive CategoryWhere It AppearsCondition We Rely On
Health dataInjury description, medical attention, days off workProtection of vital interests; establishment or defence of legal claims
Ethnic origin / nationality (proxy)Nationality, work permit status, document confiscation by employerSubstantial public interest; establishment or defence of legal claims
Trade union membershipUnion member flag, union name (NLC / TUC / sector union)Your explicit consent
Data relating to criminal allegationsPolice or NAPTIP case reference, retaliation descriptionsEstablishment or defence of legal claims; substantial public interest

4. Lawful Basis for Each Processing Activity

Section 25 of the NDPA requires a lawful basis for every processing activity, and section 30 imposes additional conditions for sensitive personal data. The table below sets out our basis for each activity.

Processing ActivityLawful Basis (s.25)Sensitive Data Condition (s.30)
Account registrationContract + ConsentSubstantial public interest
Incident report storageContract + ConsentVital interests + Legal claims
Anonymous submissionsLegitimate interestsMinimised — pseudonymous data
Evidence file storageContractLegal claims
Legal claims managementContractLegal claims
Near-miss loggingContract + Legitimate interestsN/A
Sharing with lawyers / organisationsConsent (worker-initiated)Explicit consent
Transactional emailsContractN/A (reference IDs only)
Error monitoring (Sentry)Legitimate interestsN/A (body stripped)
Session replay (Sentry)ConsentN/A
Product analytics (PostHog)ConsentN/A (usage events only)
Audit loggingLegal obligation + Legitimate interestsN/A
Data subject rights responsesLegal obligationN/A
Police / NAPTIP report assistanceContractLegal claims

5. How We Use Your Data

  • Providing the service — storing and displaying your reports, evidence, and legal cases
  • Authentication — verifying your identity on each request
  • Communications — confirmation emails, legal deadline reminders, organisation invites
  • AI incident classification — automatically categorising your report to assist you in understanding its urgency and type. This runs entirely on our platform; no data is sent to external AI APIs without your knowledge.
  • Evidence integrity — computing SHA-256 hashes and optional blockchain timestamps to create tamper-evident records for legal proceedings
  • Security and fraud prevention — rate limiting, audit logging, and abuse detection
  • Platform stability — error monitoring via Sentry (body stripped; see §10)
  • Legal compliance — responding to lawful requests from courts or regulators

We do not sell, rent, or broker your data to any third party.

We do not use your data for advertising, profiling, or automated decision-making that produces legal or significant effects.

6. Data Sharing & Sub-processors

We share your data only with the sub-processors listed below, each subject to a written data processing agreement as the NDPA requires for engagements between controllers and processors.

ProcessorPurposeData SentLocation
SupabaseDatabase & authAll user dataEU / US
ResendTransactional emailName, email, report reference IDUS
SentryError monitoringError traces, masked user ID, masked emailUS
PostHogProduct analytics (opt-in only)Usage events; profile linked only after consentUS
VercelHosting & computeRequest logs (IP, URL) ≤30 daysEU / US

Payment processing (Stripe) is not currently active on the Nigerian service — no paid plans are offered in Nigeria at this time.

Sharing with Lawyers, Unions & Organisations

If you request help from a lawyer or NGO through our directory, or link your account to a union or organisation, you may choose to share specific incident reports or legal cases with them. This sharing is always worker-initiated and explicit — we never share your data with an organisation without your action. You can revoke any share at any time from your reports page.

Legal Disclosure

We may disclose data if required by a court order, statutory authority (such as the NDPC, the Police, or NAPTIP acting under lawful powers), or applicable law. Where permitted by law, we will notify you before disclosing.

7. Where Your Data Is Stored (Cross-Border Transfers)

Your data is stored outside Nigeria

Our infrastructure providers store data in European Union and United States data centres. There is currently no Nigerian data-centre option for our stack.

The NDPA permits transfers of personal data outside Nigeria where the recipient is subject to a law, contract, or binding scheme that provides an adequate level of protection. All our sub-processors are bound by written data processing agreements incorporating standard contractual protections (including GDPR-grade Standard Contractual Clauses), which we rely on as the safeguard for these transfers. Copies of the relevant clauses are available on request.

8. Data Retention Periods

We keep data only as long as necessary for the purpose it was collected, or as required by law. The table below sets out our retention periods.

Data CategoryRetention PeriodReason
User profile (active account)Account life + 30 daysContract
User profile (after deletion request)30 days (anonymised), then hard-deletedRight to erasure
Incident reports7 years from submissionLegal claims window — state limitation laws (typically 5–6 years) plus margin
Witness recordsDeleted immediately on account deletion requestThird-party PII
Evidence files (no legal hold)7 yearsLegal claims
Evidence files (under legal hold)Until hold released, then 7 yearsLegal obligation
Legal case data7 years after case closureLegal claims window
Near-miss logs7 yearsEmployees’ Compensation Act 2010 / NSITF claims
Audit logs2 yearsLegitimate interests (security)
API token usage logs90 daysLegitimate interests (security)
Anonymous submissions3 yearsLegitimate interests
Sentry error logs90 days (Sentry-managed)Legitimate interests

Hard-deletion after account closure

When you request account deletion, your profile is immediately pseudonymised (name replaced with "Deleted User"; contact fields nulled; work-permit/union data cleared). All incident report PII fields (descriptions, names, locations, medical details) are anonymised within the same request. Witness records are hard-deleted immediately. The remaining structural data is permanently deleted within 30 days.

9. Security Measures

Encryption in transit

All data transmitted over TLS 1.3. HTTP requests are rejected.

Encryption at rest

All database rows and file storage encrypted at rest by Supabase.

Row Level Security

Database RLS policies enforce data isolation — you can only access your own records.

IP address masking

We zero the last octet of your IP before any storage. Full IPs are never persisted.

Input sanitisation

All user inputs are sanitised before storage to prevent XSS and injection.

Rate limiting

All API endpoints are rate limited per user or IP using persistent Supabase counters.

Despite these measures, no system is completely secure. If you discover a security vulnerability, please report it responsibly to support@safeguardworkers.com.ng.

10. Cookies & Analytics

Cookie / TechnologyPurposeLawful BasisOpt-out?
sb-*-auth-tokenSupabase session authentication (HTTP-only, Secure)Strictly necessary — contractNo (required to use the service)
localeStores your preferred languageStrictly necessary — contractNo
gdpr_consent_v1Records your cookie consent choiceStrictly necessary — legal obligationNo
Sentry error trackingCaptures JavaScript errors to help us fix bugsLegitimate interestsYes — via Account Settings
Sentry session replayRecords anonymised screen interactions when errors occurConsentYes — opt-in only via Account Settings
PostHog analytics (ph_*)Product usage analytics — disabled until you accept the consent bannerConsentYes — decline or ignore the consent banner

We use no advertising cookies, no cross-site tracking, and no fingerprinting. The Sentry session replay feature is disabled by default and only enabled with your explicit consent. Text and media are masked even when replay is enabled.

11. Your Rights Under the NDPA 2023 (Part VI)

You have the following rights. Most can be exercised directly in your Account Settings. We will respond within 30 days.

Right of Access

Request confirmation of what personal data we hold about you and a copy of it.

How: Account Settings → Download my data

Right to Data Portability

Receive your data in a structured, machine-readable JSON format.

How: Account Settings → Download my data

Right to Correction

Correct inaccurate personal data. You can update your profile directly.

How: Account Settings → Personal Details, or email us

Right to Erasure

Request deletion of your data. Profile PII and report PII are anonymised immediately; full deletion within 30 days. Some data may be retained where a legal hold applies or where we have a legal obligation.

How: Account Settings → Delete account

Right to Restrict Processing

Pause all non-essential processing of your data while a dispute is resolved.

How: Account Settings → Your Privacy Rights → Restrict processing

Right to Object

Object to processing based on legitimate interests. We will cease non-essential processing immediately.

How: Account Settings → Your Privacy Rights → Object to processing

Right to Withdraw Consent

Withdraw the consent you gave at registration, as easily as you gave it. Some features may become unavailable if consent is withdrawn.

How: Account Settings → Your Privacy Rights → Withdraw consent

To exercise rights not available in Account Settings (correction, portability, complex erasure), email support@safeguardworkers.com.ng with "Privacy Rights Request" in the subject line. We may ask you to verify your identity.

12. Age Requirements

Our Nigerian service is intended for workers aged 18 and over. The NDPA requires verifiable parental or guardian consent before processing the personal data of a child (under 18), and we do not have a mechanism to obtain it. If you believe we have collected data from anyone under 18, please contact us immediately at support@safeguardworkers.com.ng and we will delete the data without delay.

If you are under 18 and experiencing forced labour or workplace abuse, you can still get help without creating an account: call NAPTIP on 627 (toll-free, 24 hours) or the NHRC on 6472.

13. Changes to This Privacy Policy

We will update this policy when our processing activities change. For material changes (new sensitive-data processing, new sub-processors, changes to retention) we will notify registered users by email and require re-consent where the lawful basis is consent. Minor clarifications will be noted in the version history.

The current version is 1.0-NG (draft), effective 16 July 2026. Older versions are available on request.

14. Contact & Complaints

Right to complain to the NDPC

If you are not satisfied with how we handle your personal data or respond to your rights request, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC), the supervisory authority under the NDPA:

Website: https://ndpc.gov.ng

We ask that you contact us first — we will do our best to resolve your concern within 30 days.

Privacy Policy | SafeGuard Workers Nigeria