PrivacyPolicy.
inSmartio is committed to protecting your personal data. This policy explains how we collect, use, and safeguard your information in full compliance with Nigerian law.
Effective Date
April 1, 2026
Last Updated
March 2026
Version
1.0
Quick Reference Summary
What We Collect
- Identity & Contact info
- Verification data (NIN, BVN)
- Financial & Transaction records
- Communications & Job details
- TAS recruitment data
How We Protect You
- Encryption for all sensitive data
- Strict access controls
- Regular audits & staff training
- Breach notification within 72 hours
Your Rights
- Access your data (DSAR)
- Correct inaccurate data
- Request deletion
- Withdraw consent
- Lodge complaint with NDPC
Introduction & Commitment
At inSmartio ("we", "us", "our"), we are committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use our platform, whether as a Client, Expert, or Talent Acquisition Specialist (TAS).
We process your personal data in compliance with the Nigeria Data Protection Act 2023 (NDPA), General Application and Implementation Directive (GAID) 2025, Section 37 of the Constitution of the Federal Republic of Nigeria 1999 (as amended), and other applicable data protection regulations.
"We treat your privacy as a fundamental right. This policy is designed to be transparent, simple to understand, and to give you control over your information."
Definitions
| Term | Meaning |
|---|---|
| Personal Data | Any information relating to an identified or identifiable natural person ("Data Subject") |
| Data Subject | You – the individual whose personal data is being processed |
| Data Controller | inSmartio – the entity that determines the purposes and means of processing your data |
| Data Processor | Third parties who process data on our behalf (e.g., payment processors, cloud storage) |
| Processing | Any operation performed on personal data (collection, storage, use, sharing, deletion) |
| Consent | Freely given, specific, informed, and unambiguous agreement to process your data |
| DPO | Data Protection Officer – our designated privacy expert |
| NDPC | Nigeria Data Protection Commission – the regulatory authority |
| GAID | General Application and Implementation Directive 2025 |
| Client | A user seeking services on inSmartio |
| Expert | A verified service provider on inSmartio |
| TAS | Talent Acquisition Specialist – a recruiter of experts |
Who We Are (Data Controller Information)
Our Guiding Principles
In processing your personal data, we adhere strictly to the principles of data protection as required by the NDPA and GAID. We ensure that personal data shall be:
| Principle | Our Commitment |
|---|---|
| Lawfulness, Fairness & Transparency | Processed lawfully, fairly, and in a transparent manner |
| Purpose Limitation | Collected for specified, explicit, and legitimate purposes only |
| Data Minimization | Adequate, relevant, and limited to what is necessary |
| Accuracy | Accurate and kept up to date; inaccurate data corrected or erased |
| Storage Limitation | Kept only as long as necessary for the purpose |
| Integrity & Confidentiality | Secured against unauthorized access, loss, or damage |
| Accountability | We demonstrate compliance with all principles |
What Personal Data We Collect
Depending on your interaction with us (as Client, Expert, TAS, or visitor), we may collect the following categories of personal data:
How We Collect Your Data
| Collection Method | Description |
|---|---|
| Direct Registration | When you fill registration forms (paper or digital) |
| App/Website Usage | When you use our platform, post jobs, place bids, or communicate |
| Verification Process | When you submit NIN, BVN, and other verification documents |
| Communications | When you contact us via phone, email, WhatsApp, or chat |
| Third-Party Sources | Verification partners (NIMC, credit bureaus, guarantors) |
| Public Sources | Public records and databases (for verification purposes only) |
| Automated Technologies | Cookies, log files, and analytics tools |
| TAS Referral | When you register using a TAS referral link or code |
Purpose of Collection & Lawful Basis
We process your personal data for specific purposes and rely on lawful bases as required by the NDPA and GAID:
| Purpose of Processing | Categories of Data | Lawful Basis |
|---|---|---|
| Account Registration & Management | Identity, Contact | Performance of a contract; Consent |
| Service Provision (matching Clients & Experts) | Identity, Contact, Service, Location | Performance of a contract |
| Verification & Trust (NIN/BVN checks) | Verification, Identity | Legal obligation; Legitimate interest |
| TAS Program Administration | TAS-specific, Bank details | Performance of a contract; Legitimate interest |
| Commission Calculation & Payment | Financial, Identity, TAS-specific | Performance of a contract |
| Payment Processing | Financial, Identity | Performance of a contract |
| Communication about Jobs | Contact, Communications | Performance of a contract; Legitimate interest |
| Customer Support | All relevant categories | Legitimate interest; Legal obligation |
| Dispute Resolution | All relevant categories | Legal obligation; Legitimate interest |
| Fraud Prevention & Platform Security | All relevant categories | Legal obligation; Legitimate interest |
| Marketing & Promotions | Contact, Usage | Consent (opt-in required) |
| Analytics & Platform Improvement | Usage, Technical | Legitimate interest; Consent (where required) |
| Legal Compliance | All relevant categories | Legal obligation |
| Safety & Emergency Protocols | Location, Identity | Vital interest; Consent |
Sensitive Personal Data
The NDPA classifies certain data as "sensitive personal data" requiring extra protection. This includes: health information, genetic/biometric data, political opinions, religious/philosophical beliefs, trade union membership, sexual orientation, and criminal records.
We do not knowingly collect sensitive personal data unless voluntarily provided. If you provide such data, you explicitly consent to its processing.
Criminal records (Police Clearance) are collected only for Tier 3 Experts under strict safeguards and legal obligation. Biometric data (photographs, NIN/BVN) is collected for verification purposes only.
For sensitive data processing, we conduct a Data Protection Impact Assessment (DPIA) as mandated by GAID.
8.2 Automated Decision-Making & Profiling
We do not use automated decision-making or profiling that produces legal effects or significantly affects you. However, we use automated systems for:
| Activity | Description | Your Rights |
|---|---|---|
| Job Matching | Algorithm matches jobs with relevant experts based on category, location, and rating | You can request human review |
| Fraud Detection | Automated systems flag suspicious activity for human review | You can appeal decisions |
| TAS Tier Calculation | Automated calculation based on active expert count | You can request manual review |
To request human review, contact dpo@insmartio.io.
Consent and Your Rights
Consent is your freely given, specific, informed, and unambiguous agreement to process your personal data. It is the entry point for most processing activities.
How We Obtain Consent: Explicit consent via checkboxes, signature on forms, or click-to-accept buttons. Constructive consent by using our platform. Consent can be withdrawn at any time.
Special Situations: Marketing communications require explicit opt-in consent. Location tracking is enabled only with your permission. Sensitive data requires explicit consent.
Detailed Rights of Data Subjects
Under the NDPA and GAID, you have the following rights regarding your personal data:
Right to be Informed
To know what data we collect, why, and how we use it (this policy fulfills this right)
Right of Access (DSAR)
To request a copy of your personal data we hold
Right to Rectification
To correct inaccurate or incomplete data
Right to Erasure
To request deletion of your data, subject to legal obligations
Right to Restrict Processing
To limit how we use your data in certain circumstances
Right to Data Portability
To receive your data in a structured, commonly used format and transfer it to another controller
Right to Object
To object to processing based on legitimate interests or direct marketing
Right to Withdraw Consent
To withdraw consent at any time (without affecting prior lawful processing)
Right to Lodge a Complaint
To complain to the Nigeria Data Protection Commission (NDPC)
Rights are not absolute and may be limited by legal obligations. We will respond to requests within one month, free of charge. Manifestly unfounded or excessive requests may incur a reasonable fee.
How to Exercise Your Rights (DSAR Process)
To exercise any of your rights, please follow this process:
Complete a DSAR Form
Available at our office or request via email at dpo@insmartio.io
Submit to Our DPO
Via email: dpo@insmartio.io | WhatsApp: +234 800 INSMARTIO | In-person: Admiralty Way, Lekki Phase 1, Lagos
Provide Identification
Two forms of ID (one photo ID, one address verification) to confirm your identity
Acknowledgment
Our DPO will acknowledge receipt within 5 working days
Full Response
We will respond fully within one month of receiving your request
Cross-Border Data Transfers
As a Nigerian platform, we primarily store data within Nigeria. However, some service providers may be located outside Nigeria (cloud infrastructure, payment processors, analytics tools).
Before transferring personal data outside Nigeria, we ensure one of the following safeguards:
Adequacy Decision
The recipient country has adequate data protection laws (as determined by NDPC)
Appropriate Safeguards
Binding Corporate Rules, Standard Contractual Clauses (approved by NDPC), or other approved transfer instruments
Derogations
Specific situations such as your consent, contract performance, or legal claims
Data Security Measures
Technical Measures
- End-to-end encryption for chat communications
- SSL/TLS encryption for all data in transit
- AES-256 encryption for sensitive data at rest
- Firewalls and intrusion detection systems
- Regular security patches and updates
- Multi-factor authentication for admin access
Organizational Measures
- Strict access controls (role-based access)
- Regular staff training on data protection
- Data protection by design and by default
- Annual compliance audits (as required by GAID)
- Data Protection Impact Assessments (DPIAs) for high-risk processing
Verification Document Storage
| Security Measure | Implementation |
|---|---|
| Encryption at rest | AES-256 |
| Encryption in transit | TLS 1.3 |
| Access control | Admin only, with audit logging |
| Retention | Account duration + 2 years |
| Deletion | Anonymized after retention period |
| Third-party access | Verification partners only (NIMC, etc.) |
Data Retention Period
| Data Category | Retention Period | Reason |
|---|---|---|
| Financial Records (transactions, payouts) | 7 years | Regulatory compliance (tax, audit) |
| Verification Documents (NIN, BVN) | Duration of account + 2 years | Platform integrity, fraud prevention |
| Job Postings & Bids | 2 years post-completion | Dispute resolution, platform improvement |
| Chat Logs & Communications | 2 years | Dispute resolution, quality monitoring |
| User Profile Data | Until account deletion + 24 months inactivity | Service provision |
| TAS Recruitment Records | Duration of TAS status + 2 years | Commission tracking, dispute resolution |
| Usage Analytics | Anonymized after 36 months | Business intelligence |
| Marketing Preferences | Until consent withdrawn | Marketing compliance |
Account Deletion: When you delete your account, your profile becomes inaccessible and personal data is anonymized or deleted (subject to legal holds). Reviews and ratings may remain anonymized to preserve platform integrity. Financial records are retained for 7 years per legal requirement.
To request account deletion, contact dpo@insmartio.io.
Data Protection Officer (DPO) Contact
Appointed DPO
Eugene LOKO
The DPO monitors compliance with data protection laws, advises on DPIAs, cooperates with the NDPC, and handles all data subject requests and complaints.
Complaint Handling & Remediation
If you believe your data protection rights have been violated, follow this internal process:
Contact Our DPO
Submit your complaint in writing to dpo@insmartio.io with your full name, contact details, description of the issue, relevant dates and evidence, and desired resolution.
Acknowledgment
We will acknowledge receipt within 48 hours.
Investigation
Our DPO will investigate thoroughly, involving relevant departments.
Response
We will respond with our findings and proposed resolution within 7 working days.
Escalation
If unsatisfied, you may escalate within inSmartio for senior review.
External Remedies
If your complaint is not resolved internally, you have the right to lodge a complaint with:
Nigeria Data Protection Commission (NDPC)
Website: www.ndpc.gov.ng
Email: info@ndpc.gov.ng
You also have the right to seek judicial remedy in a court of competent jurisdiction.
Changes to This Policy
We may update this Privacy Policy to reflect changes in data protection laws (NDPA/GAID updates), changes in our data processing activities, new features or services, or regulatory guidance.
Notification: Material changes will be notified via email, SMS, or in-app notification. The "Last Updated" date at the top will be revised. We encourage you to review this policy periodically.
If you continue to use inSmartio after changes take effect, you signify acceptance of the updated policy. If you do not agree, you may close your account.
Acceptance of Policy
By registering on inSmartio, using our platform, or submitting your personal data to us, you acknowledge that you have read, understood, and agree to this Privacy Policy.
For Clients
This policy applies to your use of Client Mode.
For Experts
This policy applies to your use of Expert Mode and the verification process.
For TAS
This policy applies to your use of TAS Mode, the application process, and commission tracking.
For Visitors
This policy applies to your browsing of our website/app.
Children's Data
Our platform is not intended for children under 18 years of age. We do not knowingly collect personal data from children under 18.
If you are a parent or guardian and believe your child under 18 has provided personal data to us, please contact us immediately at dpo@insmartio.io. We will take steps to delete such information.
For users under 18: You must have parental consent to use our platform.
Marketing Communications & Opt-Out
We may send you marketing communications only with your explicit consent. You can opt out at any time via:
- Click "Unsubscribe" in any marketing email
- Toggle off "Marketing Communications" in app settings
- Reply "STOP" to any marketing SMS
- Email dpo@insmartio.io with subject "Unsubscribe"
What you will still receive after opt-out
- Transactional emails (payment confirmations, job updates)
- Security alerts
- Legal notices
- Account-related communications
Third-Party Links Disclaimer
Our platform may contain links to third-party websites or services (e.g., payment gateways, social media). This Privacy Policy does not apply to those third parties. We are not responsible for the privacy practices of third-party sites. We encourage you to read their privacy policies before providing any personal data.
TAS Data Retention (Specific)
For TAS agents, in addition to Section 15:
| TAS Data Category | Retention Period | Reason |
|---|---|---|
| TAS application records | Duration of TAS status + 3 years | Audit, dispute resolution |
| Referral link click data | 2 years | Analytics, commission verification |
| Sub-TAS relationships | Duration of relationship + 3 years | Override commission verification |
| Recruitment network data | Anonymized after 2 years inactive | Business intelligence |
27. Sub-TAS Data Sharing Disclosure
If you are a Tier 3+ TAS recruiting sub-TAS agents, the following data is shared:
| Data Shared | With Whom | Purpose |
|---|---|---|
| Sub-TAS name and TAS ID | Master TAS | Team management |
| Sub-TAS recruitment numbers | Master TAS | Override commission calculation |
| Sub-TAS performance metrics | Master TAS | Team performance tracking |
Sub-TAS agents consent to this sharing when they agree to join a master TAS's team.
Glossary of Terms
| Term | Definition |
|---|---|
| NDPA | Nigeria Data Protection Act 2023 |
| GAID | General Application and Implementation Directive 2025 |
| NDPC | Nigeria Data Protection Commission |
| DPO | Data Protection Officer |
| DSAR | Data Subject Access Request |
| DPIA | Data Protection Impact Assessment |
| LIA | Legitimate Interest Assessment |
| NIN | National Identification Number |
| BVN | Bank Verification Number |
| TAS | Talent Acquisition Specialist |
Document Control
Version 1.0 — Initial release by inSmartio Legal, March 2026
inSmartio: Trusted Services,
Verified Professionals.
