Data Protection Policy
Effective: 19 September 2026
This public policy states the minimum data-protection rules applied by Invicast Group and its member companies. It supports compliance with the Nigeria Data Protection Act 2023, the GAID 2025 and applicable sector requirements. The Privacy Policy explains how individuals’ personal data is handled.
1. Purpose and application
This Policy applies to Invicast Platforms Limited, Invicast Telecom Limited and Invicast Academy Limited, and to personnel, contractors and processors handling personal data on their behalf. It covers personal data in electronic and physical form throughout its lifecycle, including collection, access, use, disclosure, storage, transfer, archiving and deletion.
2. Governance and accountability
- Each member company is accountable for processing within its business area and must identify whether it acts as controller, joint controller or processor.
- The Data Protection Officer coordinates compliance, rights requests, incident response, records and engagement with the Nigeria Data Protection Commission, reports to senior management, is protected from conflicting instructions, and is given appropriate independence and resources.
- The Data Protection Officer’s contact is published and notified to the Commission as required. The DPO maintains the Record of Processing Activities and prepares the GAID semi-annual compliance report covering lawful bases, notices, rights, complaints, DPIAs, legitimate-interest assessments, safeguards, transfers and breaches.
- Processing activities, lawful bases, recipients, retention periods, transfers and safeguards must be documented at a level proportionate to risk.
- Each member company will assess whether it is a Data Controller or Processor of Major Importance and its applicable tier, complete required Commission registration, file compliance audit returns through a licensed Data Protection Compliance Organisation where required, and retain supporting evidence within applicable regulatory periods.
3. Mandatory processing principles
Personal data must be processed lawfully, fairly and transparently; collected for specified, explicit and legitimate purposes; adequate, relevant and limited to what is necessary; accurate and kept up to date; retained no longer than necessary; and secured against unauthorised or unlawful processing, loss, destruction or damage. The responsible member company must be able to demonstrate compliance.
4. Lawful basis and transparency
Before processing begins, the responsible team must identify and record an NDPA lawful basis and provide a clear notice where required. Consent will be used only when freely given, specific, informed, unambiguous and capable of withdrawal. Service access must not be made conditional on consent to unnecessary processing. Where legitimate interests are relied upon, necessity and the effect on individuals must be assessed and documented.
5. Data minimisation and purpose control
- Forms, systems and workflows must collect only the fields required for a defined purpose.
- Personal data must not be reused for an incompatible purpose without a valid legal basis and any required notice.
- Sensitive personal data and children’s data require enhanced necessity, authorisation and safeguards.
- Test, development and analytics environments should use anonymised, synthetic or appropriately pseudonymised data wherever practicable.
6. Privacy by design and impact assessment
New products, integrations, vendors and material processing changes must consider privacy from design through retirement. A data-protection impact assessment must be completed before processing likely to create high risk, including systematic monitoring, large-scale sensitive-data processing, significant automated decisions or new technology with material effects on individuals. High residual risk must be escalated and, where legally required, referred to the Commission before processing.
KYC/KYB onboarding must apply data minimisation, purpose limitation and role-based access. Government identifiers, document images, liveness or biometric results, beneficial-ownership data, company-representative identity and authority, and screening results may be requested only through an approved secure workflow. Each invitation must record whether third-party verification is enabled. The verification supplier must be assessed as a processor or independent controller as applicable, covered by appropriate terms, restricted from unrelated use, and configured to return only the evidence necessary for an accountable compliance decision. Third-party verification never automatically activates an account: an authorised Compliance Officer must approve or reject the case and record a proportionate rationale.
Onboarding systems must keep compulsory email verification separate from any phone verification authorised for a particular invitation. Structured names and addresses must be collected only to the granularity needed for identification, contracting, billing, fraud prevention or legal compliance. SMS and WhatsApp processors must be subject to due diligence, access controls, transmission security, purpose restrictions, retention controls and transfer safeguards. WhatsApp notification eligibility requires a channel-specific proof-of-control event; an SMS-verified phone number alone is insufficient.
Onboarding cannot proceed until the user separately accepts every required current agreement. The system must preserve tamper-evident evidence of the email, timestamp, agreement code and version, encrypted IP address, hashed device signals, device class, declared location and limited onboarding identification context. Raw device identifiers must not be used for advertising. Access is restricted to authorised legal, privacy, compliance and audit functions. Publication of a new agreement version must preserve the old version record and trigger an auditable email notice to verified account holders.
7. Information security
Safeguards must reflect the likelihood and severity of harm and may include:
- role-based access, least privilege, strong authentication and prompt access revocation;
- encryption in transit and at rest where appropriate, secure key and secret management, and prohibition of credentials in source-control repositories;
- secure development, configuration, patching, vulnerability management and change control;
- logging, monitoring, backups, recovery testing and resilience measures;
- physical security, confidentiality commitments, training and disciplinary controls;
- regular assessment of safeguards and remediation of identified weaknesses.
8. Processors, suppliers and partners
Processors must be selected through proportionate due diligence and bound by a written agreement covering subject matter, duration, nature, purpose, data types, categories of individuals, confidentiality, security, sub-processing, rights assistance, breach notification, audits, transfer restrictions and deletion or return. Processors may act only on documented lawful instructions unless otherwise required by law.
9. International transfers
Personal data may be transferred outside Nigeria only after the responsible team documents an adequacy basis, permitted safeguard or statutory exception under the NDPA and GAID. Transfer assessments must consider the destination, recipient, enforceable rights, onward transfers and supplementary safeguards. Repeated or structural transfers must be periodically reviewed.
10. Retention and secure disposal
Business owners must apply documented retention periods based on purpose, contract, legal obligation, risk and limitation periods. Data subject to a legal hold must be preserved. When retention ends, personal data must be securely deleted, anonymised or destroyed across active systems and managed backups according to a controlled schedule.
11. Individual rights
Requests for access, correction, erasure, restriction, objection, portability, consent withdrawal or review of qualifying automated decisions must be sent immediately to the data-protection contact. Identity and authority must be verified proportionately. Requests, decisions, searches, disclosures, extensions and refusals must be documented and completed within the legal period.
12. Incident and breach management
- Suspected loss, unauthorised access, disclosure, alteration or destruction must be reported internally without delay.
- The response team will contain the incident, preserve evidence, assess affected data and individuals, reduce harm and document the decision.
- A processor must notify the relevant Invicast controller promptly and provide the information needed for compliance.
- Where a breach is likely to result in risk, the controller will notify the Commission within 72 hours of awareness as required by the NDPA. Where high risk is likely, affected individuals will be informed promptly in clear language, subject to lawful exceptions.
13. Direct marketing and communications
Marketing must use a lawful basis, respect channel-specific rules and provide a simple opt-out. Suppression records may be retained to honour objections. Purchased or partner-supplied lists may not be used without documented provenance, lawful collection and transparency.
14. Training, monitoring and enforcement
Personnel with access to personal data must receive role-appropriate training. Compliance is monitored through reviews, access checks, vendor oversight, incident lessons and audits. Deliberate or negligent violations may result in access restriction, disciplinary action, contract termination, regulatory reporting or legal action.
15. Contact and review
This Policy is reviewed at least annually and after material legal, service or risk changes. Privacy questions or concerns should be sent to the Data Protection Officer at dpo@invicast.com with the subject “Data Protection Request”. This address is reserved for privacy and data-protection matters. Individuals may also complain to the Nigeria Data Protection Commission.
