Privacy Policy

A single policy covering Client users and Artisan users of the DailyPay NG application

Effective date: 01.07.2026

Last updated: 01.07.2026

Data controller: Dekon Industries Limited, Uyo, Akwa Ibom, Nigeria

1. Who we are and how to read this policy

APPLIES TO: ALL USERS (CLIENTS AND ARTISANS)

This Privacy Policy is issued by Dekon Industries Limited, a company incorporated in Nigeria, with its registered office in Uyo, Akwa Ibom, Nigeria (“Dekon Industries,” “DailyPay NG,” “we,” “us,” or “our”). Dekon Industries Limited is the data controller responsible for the personal data described in this policy, in respect of the DailyPay NG mobile application and related services (the “Platform”).

The Platform connects two categories of user: Clients, who request and pay for services, and Artisans, who offer skilled trade services. This policy is written as a single document covering both, because a meaningful proportion of our processing — account security, payments, messaging, and general platform operation — is identical for both groups. Where an obligation, data category, or right applies to only one group, the relevant section is clearly marked with a coloured tag, as shown above. Sections without a tag, or marked “All users,” apply equally to both Clients and Artisans.

This policy should be read together with our Terms of Service. If there is a direct conflict between the two on a data protection matter, this Privacy Policy prevails.

2. The laws that apply to this policy

APPLIES TO: ALL USERS (CLIENTS AND ARTISANS)

Because Dekon Industries Limited is established in Nigeria, and the Platform is principally used by individuals located in Nigeria, two data protection regimes apply concurrently, and neither displaces the other:

The UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018, because Dekon Industries Limited is established in the UK and determines the purposes and means of processing.

The Nigeria Data Protection Act 2023 (“NDPA”), because the NDPA applies on an extraterritorial basis to the processing of personal data of data subjects located in Nigeria, regardless of where the controller is incorporated or where the processing technically occurs.

Where this policy describes a right, safeguard, or obligation that derives from one regime specifically, we say so. Where a protection is offered under both regimes, we describe the higher or more protective standard and apply it to all users, irrespective of which specific law would otherwise have applied to them.

3. Personal data we collect from all users

APPLIES TO: ALL USERS (CLIENTS AND ARTISANS)

The categories below are collected from every user of the Platform, whether registered as a Client or an Artisan.

3.1 Account and identity data

Full name, phone number, email address, and date of birth (collected to confirm you meet our minimum age requirement, described in Section 11).

State and Local Government Area (LGA) of residence in Nigeria, or equivalent locality information.

Account password, stored only as a salted cryptographic hash; we do not store or have access to your password in plain, readable form.

Biometric authentication tokens generated by your device if you enable Face ID, fingerprint, or device passkey sign-in. These tokens are created and held by your device’s own operating system and are not transmitted to or stored on our servers. This is distinct from the identity-verification biometric data described in Section 4, which applies to Artisans only.

3.2 Communications and content data

Messages exchanged with other users through in-app chat.

Job request content, including any text typed or audio recorded by a Client describing a job, and any quotes, notes, or attachments exchanged in connection with a job.

Photographs you choose to upload, including reference images and, for Artisans, portfolio images.

Ratings, written reviews, and feedback submitted about a completed job.

Records of correspondence with our customer support team.

3.3 Payment data

Payment references, transaction status, and transaction amount associated with deposits, balance payments, and payouts processed through our licensed payment processing partner, Paystack Payments Limited.

We do not directly collect, transmit, or store your full card number, card verification value (CVV), or banking personal identification number (PIN). These are entered directly into, and processed by, Paystack’s own systems, which operate under the Payment Card Industry Data Security Standard (PCI-DSS). We retain only the truncated card reference (such as the last four digits, where applicable) and the transaction outcome supplied to us by Paystack.

3.4 Device, location, and usage data

Device model, operating system and version, unique device identifiers, IP address, mobile network information, and application version.

With your permission, precise or approximate location data, used as described in Sections 3.5 (Clients) and 5 (Artisans).

Usage data, including screens viewed, features used, search queries, session duration, and crash or performance diagnostics.

3.5 Location data — client-specific use

APPLIES TO: CLIENTS ONLY

As a Client, we collect your precise device location, with your permission, at two points: when you post a job request, to identify nearby Artisans for matching purposes, and during active job tracking, to display an Artisan’s live position and estimated arrival time to you. You may decline location permissions; doing so will materially limit your ability to use the job-matching feature, since geographic proximity is a required input to the matching process.

4. Identity verification and biometric data (Artisans only)

APPLIES TO: ARTISANS ONLY

This section applies only to users registered as Artisans. It does not apply to Clients, and Clients are not asked to provide any of the data described in this section.

Before an Artisan may accept paid jobs on the Platform, they must complete an identity verification process. This is a condition of using the Artisan side of the Platform, undertaken to protect Clients and to meet our own obligations to prevent fraud and impersonation. The verification process involves the collection of the following data, which is classified as sensitive personal data under both the NDPA and the UK GDPR, and is treated with corresponding additional safeguards:

National Identification Number (NIN), or, where a NIN is unavailable, an International Passport number or Driver’s Licence number.

A photograph or scan of the corresponding government-issued identity document.

A live selfie photograph or short video clip, captured at the point of onboarding, used solely to perform an automated liveness check and to match your face against the photograph on your identity document.

The verification outcome returned to us (for example, matched, not matched, verified, pending, or rejected).

We engage Smile Identity, a licensed identity verification provider operating across Africa, to perform NIN verification against the National Identity Management Commission (NIMC) database and to conduct the biometric liveness and face-match check on our behalf. Smile Identity acts as our data processor for this purpose. We do not ourselves retain the raw biometric facial scan or template beyond what is technically necessary to receive and record the verification outcome; the underlying biometric data is processed and retained by Smile Identity in accordance with its own data retention practices, which we have reviewed at a summary level and consider broadly consistent with the standards expected under the NDPA, subject to the legal confirmation requested below.

Your full NIN, your raw identity document images, and your biometric scan are never disclosed to Clients or to other Artisans, under any circumstances.

5. Continuous location tracking (Artisans only)

APPLIES TO: ARTISANS ONLY

Artisans are subject to more frequent and continuous location collection than Clients, because live location is the mechanism by which the Platform matches Artisans to nearby job requests and informs Clients of an Artisan’s progress toward a job site. Specifically:

While you have toggled yourself “available” within the job pool, we periodically collect your device’s GPS coordinates so that open job requests can be ranked by proximity to you.

While you are en route to, or actively working on, an assigned job, we collect more frequent location updates, at approximately [10–30]-second intervals, so that the Client engaging you can view your live position and an estimated time of arrival.

Location collection stops, other than retention of your last known general area for matching freshness, once you toggle yourself unavailable or are not engaged in an active job.

You may decline location permissions; doing so will prevent you from being matched to job requests, since proximity is a required input to the matching algorithm, but will not otherwise affect your ability to maintain a profile or view past job history.

6. Wallet, earnings, and payout data (Artisans only)

APPLIES TO: ARTISANS ONLY

Bank account number, account name, and bank code, provided when you request a withdrawal of your earnings.

Wallet balance, earnings history, and a record of completed jobs and associated payment amounts.

Withdrawal requests and their processing status, transmitted to and fulfilled through Paystack’s transfer infrastructure.

We do not collect or store your online banking login credentials or banking PIN. Payout transfers are initiated through Paystack under its own applicable regulatory licences and arrangements with Nigerian deposit money banks.

7. Why we process your data, and our legal basis

APPLIES TO: ALL USERS (CLIENTS AND ARTISANS)

Under both the UK GDPR and the NDPA, we are required to identify a specific lawful basis for each purpose of processing. The table below sets these out. Several entries marked “Artisans only” reflect the additional processing described in Sections 4–6.

Purpose

Examples

Legal basis (UK GDPR / NDPA)

Account creation and authentication

Verifying identity at signup; enabling device biometric sign-in

Performance of a contract; consent (for device biometric login)

Identity verification (Artisans only)

NIN check against NIMC; biometric liveness and face-match check

Explicit consent (sensitive personal data); legal obligation related to fraud and financial-crime prevention; legitimate interest in platform trust and safety

Job matching

Ranking Artisans by category fit, rating, and proximity to a Client’s job request

Performance of a contract

Live job tracking

Showing a Client an Artisan’s live location and ETA during an active job

Performance of a contract; consent

Payments, escrow, and payouts

Processing deposits, holding funds in escrow, releasing payment, processing Artisan withdrawals

Performance of a contract; compliance with legal obligations (including financial record-keeping)

Trust, safety, and fraud prevention

Investigating disputes, detecting fraudulent accounts or job claims, calculating Trust Scores

Legitimate interest; legal obligation

Customer support

Responding to enquiries and complaints

Performance of a contract; legitimate interest

Service improvement

Analysing usage patterns, fixing defects, improving matching accuracy

Legitimate interest

Legal and regulatory compliance

Responding to lawful requests from courts or regulators; tax and AML record-keeping

Legal obligation

Marketing communications

Sending product updates or promotional offers

Consent (opt-in; withdrawable at any time, see Section 12)

Where we rely on legitimate interest, we have considered, and are prepared to demonstrate on request, that the relevant processing is necessary for that interest and that it is not overridden by your interests or fundamental rights and freedoms. Where we rely on consent for sensitive personal data, that consent is sought explicitly and separately from general acceptance of our Terms of Service, and may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.

8. How we share personal data

APPLIES TO: ALL USERS (CLIENTS AND ARTISANS)

We do not sell personal data, to anyone, for any purpose. We disclose personal data only in the following circumstances, and, where a recipient acts as our processor, only under a written data processing agreement consistent with the requirements of the UK GDPR and the NDPA:

Between Clients and Artisans: when a Client selects a specific Artisan for a job, that Artisan receives the Client’s first name, job request details, and general address; the Client receives the Artisan’s profile information, ratings, and reviews, and, once a job is mutually accepted, the Artisan’s live location for tracking purposes. Full phone numbers are shared between the two parties only once a job is mutually accepted.

With Smile Identity (Artisans only): identity documents and biometric data are shared solely for the verification purpose described in Section 4.

With Paystack Payments Limited: payment and payout data are shared to process transactions described in Sections 3.3 and 6.

With cloud hosting, database, and infrastructure providers, who store and process personal data on our behalf, as described in Section 9.

With professional advisers, including lawyers, auditors, and insurers, under confidentiality obligations, where reasonably necessary to obtain advice or services.

With regulators, courts, or law enforcement authorities, in the United Kingdom, Nigeria, or elsewhere, where required by valid legal process, or to protect the rights, property, or safety of Dekon Industries Limited, our users, or the public.

In connection with a corporate transaction, such as a merger, acquisition, financing, or sale of assets involving Dekon Industries Limited, personal data may be transferred as part of that transaction, subject to confidentiality commitments and, where required by law, prior notice to affected users.

9. International data transfers

APPLIES TO: ALL USERS (CLIENTS AND ARTISANS)

Personal data collected through the Platform is collected from users principally located in Nigeria, by a controller established in the United Kingdom, and is stored using internationally hosted cloud infrastructure. As a result, your personal data will, in the ordinary course, be transferred across at least the following paths, each of which is governed by a different transfer regime:

From Nigeria to the United Kingdom or to third countries where our infrastructure providers operate: this transfer is a transfer of personal data of Nigerian data subjects out of Nigeria, and is governed by the NDPA’s cross-border transfer provisions, which generally require that the receiving country or organisation offer an adequate level of protection, or that an alternative safeguard recognised by the NDPA apply.

Receipt and onward processing within the United Kingdom or in third countries by our sub-processors: this is governed by the UK GDPR’s own restricted-transfer regime, which generally requires an adequacy regulation, appropriate safeguards such as the UK’s International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses as modified by the UK Addendum, or an applicable derogation.

We seek to ensure that, irrespective of which specific regime applies to a given transfer, an adequate and broadly equivalent level of protection is maintained throughout, by relying on one or more of the following:

Adequacy assessments recognised by the relevant authority (the NDPC or the UK authorities, as applicable) in respect of the receiving country;

Standard contractual clauses, the UK International Data Transfer Agreement, or substantively equivalent contractual safeguards with our processors and sub-processors; or

Your explicit, informed consent to a specific transfer, where no other safeguard is available and consent is the appropriate basis.

10. Data retention

APPLIES TO: ALL USERS (CLIENTS AND ARTISANS)

We retain personal data only for as long as reasonably necessary for the purposes described in this policy, including to satisfy legal, accounting, tax, and regulatory record-keeping obligations in both the United Kingdom and Nigeria. As a general guide, and subject to confirmation by legal counsel against current statutory requirements in both jurisdictions:

Account and profile data: retained for the duration of your account, and for [SUGGEST: 24 months] following account closure, to address residual disputes or legal claims.

Identity verification records (Artisans only): retained for [SUGGEST: 5 years] following account closure, consistent with typical know-your-customer and anti-money-laundering record-keeping expectations, subject to confirmation against any sector-specific requirement applicable to this Platform.

Biometric liveness data (Artisans only): the underlying biometric scan is processed and retained by Smile Identity in accordance with its own retention schedule, referenced in Section 4; we retain only the verification outcome, not the underlying scan, for the period described above.

Transaction and payment records: retained for a minimum of [SUGGEST: 6 years], reflecting standard financial record-keeping practice; to be confirmed against specific UK and Nigerian statutory minimums applicable to this business.

Job request content and in-app messages: retained for [SUGGEST: 24 months] following job completion, or longer where the subject of an active dispute or legal claim.

Location history (Artisans only): granular location pings collected during active job tracking are retained for [SUGGEST: 90 days] following job completion, principally to resolve disputes about timing or service area, then securely deleted or anonymised.

On expiry of the applicable retention period, we securely delete or irreversibly anonymise the relevant personal data, except to the extent continued retention is required by law or is necessary to establish, exercise, or defend legal claims.

11. How we protect your data

APPLIES TO: ALL USERS (CLIENTS AND ARTISANS)

We apply technical and organisational measures designed to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage, including:

Encryption of data in transit using TLS, and encryption of sensitive data at rest.

Password storage using industry-standard salted hashing (bcrypt); we do not store passwords in plain, readable text.

Role-based access controls limiting employee and contractor access to personal data on a need-to-know basis, with additional restrictions on access to identity verification and biometric records described in Section 4.

Network-level protections, including rate limiting, intended to detect and resist automated abuse.

Periodic review of our security practices as the Platform and its user base grow.

No system of transmission or storage can be guaranteed to be 100% secure. If we become aware of a personal data breach that is likely to result in a risk to the rights and freedoms of affected individuals, we will, as applicable and within the timescales required by law, notify the UK Information Commissioner’s Office, the Nigeria Data Protection Commission, and affected users.

12. Your rights

APPLIES TO: ALL USERS (CLIENTS AND ARTISANS)

Whether the UK GDPR, the NDPA, or both apply to a specific instance of processing concerning you, we extend the following set of rights to all users of the Platform, applying whichever version of a right is more protective where the two regimes differ in detail:

Right of access: to obtain confirmation of whether we process your personal data, and a copy of that data.

Right to rectification: to have inaccurate or incomplete personal data corrected.

Right to erasure: to request deletion of your personal data, subject to the retention obligations described in Section 10 and any other applicable legal exception.

Right to restriction of processing: to request that we limit how we use your data in specified circumstances, for example while a dispute about its accuracy is resolved.

Right to data portability: to receive certain personal data you have provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.

Right to object: to object to processing based on legitimate interest, including direct marketing, at any time.

Rights related to automated decision-making: our job-matching algorithm produces a ranked recommendation, but a Client always makes the final decision to select an Artisan, and no purely automated decision with legal or similarly significant effect is made about you without the opportunity for human review.

Right to withdraw consent: where processing is based on consent, including biometric verification consent and marketing consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

Right to lodge a complaint: with a supervisory authority. Because two regimes apply, you may lodge a complaint with either or both of: the UK Information Commissioner’s Office (ico.org.uk), and the Nigeria Data Protection Commission (ndpc.gov.ng).

To exercise any of these rights, contact us using the details in Section 14. We will respond within the timeframe required by applicable law (generally one month under the UK GDPR, subject to extension in complex cases), and may need to verify your identity before fulfilling certain requests.

13. Other important information

APPLIES TO: ALL USERS (CLIENTS AND ARTISANS)

13.1 Minimum age

The Platform is intended for use by individuals who are at least 18 years old. We do not knowingly collect personal data from individuals under 18. If we become aware that we have inadvertently collected personal data from a person under 18, we will take prompt steps to delete that data, save to the extent we are legally required to retain it.

13.2 Cookies and similar technologies

If the Platform is accessed through a website or web-based portal, we may use cookies and similar tracking technologies to recognise your device, remember preferences, and analyse usage. Cookie preferences can generally be controlled through browser settings. A full cookie schedule will be published prior to any web-based launch of the Platform.

13.3 Marketing communications

With your consent, we may send promotional messages about new features, offers, or recommendations by push notification, SMS, or email. You may withdraw this consent at any time by adjusting in-app notification settings, replying STOP to SMS messages, or using the unsubscribe link in marketing emails. Opting out of marketing communications does not affect transactional messages necessary for the operation of your account or an active job.

13.4 Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the law, or other relevant factors. We will notify you of material changes through the app or by email, and will update the “Last updated” date at the top of this policy. Continued use of the Platform after such changes take effect constitutes your acceptance of the revised policy.

14. Contact us

APPLIES TO: ALL USERS (CLIENTS AND ARTISANS)

Questions, concerns, or requests regarding this Privacy Policy, or the exercise of any right described in Section 12, may be directed to:

Data Protection Contact: Emma Assam

Email: operations.control@chrismgroup.com

Postal address: Dekon Industries Limited, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

You may also lodge a complaint directly with either supervisory authority:

UK Information Commissioner’s Office — ico.org.uk

Nigeria Data Protection Commission — ndpc.gov.ng

END OF DRAFT. This policy requires sign-off from a lawyer qualified in the United Kingdom and, given the NDPA’s extraterritorial application and the Nigerian user base, from Nigerian counsel as well, before publication. Particular attention should be given to the callouts in Sections 2, 4, and 9, and to confirming all bracketed retention periods in Section 10 against current statutory minimums in both jurisdictions.