1. Who we are
Servixus Limited (“Servixus”, “we”, “us”) operates a digital marketplace in Nigeria that connects customers with independently verified artisans. For most processing described in this Policy we are the data controller: we decide why and how personal data is processed. Payment partners, KYC vendors, SMS/email providers and cloud hosts act as processors or, in some cases, independent controllers. Their roles are described in Section 8.
This Policy applies to personal data of Customers, Artisans, Admin users, visitors and people whose data appears in job media or reviews. It covers the Flutter mobile app, APIs, admin console and related websites.
The NDPA applies because we operate in Nigeria and we process personal data of data subjects in Nigeria. If we later process data of persons outside Nigeria, we will apply this Policy plus any extra rules that then apply.
2. Scope and definitions
“Personal data” means any information relating to an identified or identifiable natural person. “Sensitive personal data” under the NDPA includes biometric data and other specified categories. BVN and NIN are identity numbers that link to biometric templates held by CBN/NIBSS and NIMC; we treat them, and any biometric match result we receive, as highly protected data and, where the statutory definition is met, as sensitive personal data requiring a valid condition for processing.
“Processing” includes collection, storage, use, disclosure, restriction, erasure and other operations, whether automated or not.
3. Data we collect
3.1 Data you provide
- Identity and contact: name, phone number, email address, gender (if provided), profile photo.
- Customer profile: saved addresses and locations, job descriptions, preferred date/time.
- Artisan profile: trade categories, service areas, bio, portfolio photographs and videos.
- KYC: BVN, NIN, government ID images, proof of address, supporting trade documents, and any liveness or face-match image required by the KYC provider.
- Job media: photographs and videos of premises, faults, parts and completed work.
- Quotes and contracts: itemised prices, Work Type, parts lists, acceptance records.
- Communications: in-app chat, support tickets, dispute narratives and evidence uploads.
- Reviews: ratings, text and optional photographs; Artisan responses.
- Optional completion questionnaire: whether an extra off-platform payment was made, optional reason and amount.
- Payout details: Nigerian bank name, account number and account name.
3.2 Data collected automatically
- Device and session data: device identifiers, app version, approximate network type, coarse location if you grant permission, IP address, log-in timestamps.
- Usage data: pages or screens viewed, quote and job status changes, upload retries.
- Security logs: OTP events, failed logins, rate-limit hits, webhook receipts.
3.3 Data from third parties
- KYC match results and status (match / no-match / manual review) from the approved verification provider.
- Payment status, charge identifiers and transfer references from Paystack.
- SMS delivery receipts from Termii, Twilio or a successor gateway.
We do not require access to your phone contact list, photos beyond those you choose to upload, or SMS inbox. We will not harvest contacts for marketing or debt collection.
4. Purposes and lawful bases
Under section 25 of the NDPA, we process personal data only where a lawful basis applies. Consent is not used as a bundled substitute for every purpose. Where consent is required (including certain KYC and optional questionnaires), it is requested separately from acceptance of the Terms of Use, can be withdrawn, and is recorded.
| Purpose | Main data | Lawful basis (NDPA) |
|---|---|---|
| Create and secure accounts; OTP login; RBAC | Phone, email, tokens, device/session | Contract; legitimate interests (security) |
| Customer job posting, media, matching | Profile, address, job media | Contract |
| Artisan profile, portfolio, badges | Profile, ratings, KYC status | Contract; legitimate interests (trust) |
| BVN/NIN verification and admin KYC review | BVN, NIN, ID docs, match result | Consent; contract (Artisan onboarding); legal obligation where AML/CFT or identity rules apply to us or our payment partner |
| Quotes, snapshot, chat, completion | Job and message content | Contract |
| Payments, commission, weekly payouts, ledger | Paystack refs, bank account | Contract; legal obligation (tax, payment-partner rules) |
| Disputes, refunds, audit logs | Evidence, decision records | Contract; legitimate interests; legal obligation |
| Verified reviews | Rating, review text/photos | Contract; legitimate interests |
| Optional off-platform payment survey | Survey answers | Consent (skippable) |
| SMS/email transactional notices | Phone, email, event type | Contract |
| Fraud, leakage and trust-and-safety | Logs, survey, chargebacks | Legitimate interests; legal obligation |
| Analytics of marketplace health (aggregated where possible) | Pseudonymous usage metrics | Legitimate interests |
| NDPC/FCCPC/CBN/police requests; litigation hold | Relevant account records | Legal obligation; establishment of legal claims |
| Marketing (if introduced later) | Contact + preference | Consent — not used for MVP unless you opt in |
Legitimate interests are used only where they are not overridden by your rights and where you would reasonably expect the processing (for example, preventing off-platform fraud after you use a paid marketplace). You may object under Section 10.
Sensitive personal data and biometric-linked identifiers are processed only where a condition in section 30 of the NDPA is met — typically your explicit consent for KYC, or a legal obligation that specifically requires identity verification. We do not use KYC data for marketing.
5. Children
The Platform is for persons aged 18 and above. We do not knowingly process children’s personal data. Job media should not focus on identifiable children. If a child is incidentally visible, we may blur or delete the file on request or on review. Parental consent rules under section 31 of the NDPA therefore should not be engaged in ordinary use.
6. How we use job media and chat
Job photographs and videos are shown to Artisans who receive the request, to Admin for support and disputes, and as needed to operate matching. Chat is job-scoped. Contact details remain masked until a deposit is paid. We may scan media and chat with automated tools for malware, spam and obvious policy violations; significant decisions (ban, KYC reject, dispute outcome) are not based solely on automated processing that produces legal or similarly significant effects, consistent with section 37 of the NDPA.
7. Sharing and processors
We do not sell personal data. We share data only as follows:
- Other users, as needed to perform a job (limited profile, verification badge, ratings, job media, chat after the relevant trigger).
- Paystack — payments, transfers, webhooks, settlement. Paystack is a licensed payment institution and processes payment data under its own privacy notice and CBN rules.
- Current KYC provider — Dojah (or a successor licensed provider) for BVN/NIN verification, document checks and optional liveness. The provider returns a result to us; source records remain with NIMC, NIBSS or the provider as applicable.
- Current SMS gateway — Termii (Twilio as a fallback if contracted) and email provider (Amazon SES, SendGrid or Mailgun as contracted) — OTPs and transactional notices.
- S3-compatible object storage and CDN — hosting of images and videos.
- Cloud infrastructure for NestJS APIs, PostgreSQL and Redis — hosting and caching.
- Professional advisers, insurers and auditors bound by confidentiality.
- Regulators and law enforcement when required by a valid legal demand (NDPC, FCCPC, CBN, NIMC, EFCC, Nigeria Police Force, courts).
- A buyer of our business, under a contract that continues this standard of protection.
We execute written processor terms requiring confidentiality, security, deletion or return of data, and assistance with data-subject rights and breach notification. Where a vendor is an independent controller (typically Paystack or NIMC), their notice also applies.
8. Cross-border transfers
Some vendors (for example global clouds, Twilio or Stripe-group entities connected to Paystack) may process data outside Nigeria. Sections 41–43 of the NDPA restrict transfers unless there is an adequacy decision, appropriate safeguards (such as contractual clauses approved or recognised by the NDPC), or another permitted basis including your consent where required.
We will not transfer personal data outside Nigeria unless a lawful transfer mechanism is in place. We will list current transfer destinations and safeguards in an annex or in-app notice as vendors are contracted. Payment transaction data generated in Nigeria will be stored in accordance with applicable CBN localisation directions (including the requirement, as published, for in-country storage of Nigerian payment-transaction data from 1 January 2027).
9. Retention
We keep personal data only as long as needed for the purpose collected, and thereafter as required to meet legal, tax, dispute and security obligations (storage limitation, NDPA section 24). Illustrative periods:
| Record type | Typical retention |
|---|---|
| Account profile while active | Life of account |
| Closed account contact identifiers | Up to 12 months, then suppression/anonymisation unless a hold applies |
| KYC pack and verification decision | At least 5 years after last payout or account closure (fraud / payment-partner / possible AML alignment) |
| Job, quote, chat, completion and dispute files | 6 years after job close (limitation-aligned commercial records) |
| Payment ledger, webhooks, payout batches | 6 years (tax and financial audit) |
| Optional leakage questionnaire | 24 months in identifiable form, then aggregate |
| OTP and raw access logs | 90–180 days unless needed for an investigation |
| Review content on a public profile | Until removed under policy or account deletion rules |
When a period ends we delete or irreversibly anonymise the data, unless a litigation or regulatory hold applies.
10. Your rights
Subject to the conditions in the NDPA, you may:
- be informed about processing (this Policy and in-app notices);
- access a copy of personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase data where the basis no longer applies and no exemption requires retention;
- restrict processing in the cases the Act provides;
- object to processing based on legitimate interests;
- withdraw consent without affecting processing already lawfully done;
- receive data you provided in a structured, commonly used, machine-readable format and transmit it where technically feasible (portability); and
- not be subject to a solely automated decision with legal or similarly significant effects.
To exercise rights, email privacy@servixus.com or dpo@servixus.com from your registered address or phone-linked email, or use the in-app request form when available. We will respond without undue delay and within the period required by the NDPA and NDPC guidance. We may need to verify your identity. We will not charge a fee unless a request is manifestly unfounded or excessive.
You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) at https://ndpc.gov.ng or any successor URL, and to seek judicial remedy.
11. Security
We implement technical and organisational measures appropriate to risk, including:
- TLS in transit; encrypted secrets; secure token storage on devices as the OS allows;
- role-based access control on APIs; admin audit logs for KYC, disputes and financial state changes;
- Paystack webhook signature verification and idempotent event handling;
- rate limiting, Redis-backed queues and retry policies;
- S3 access controls and CDN delivery for media;
- automated PostgreSQL backups; and
- least-privilege staff access to KYC and payout data.
No method of transmission or storage is perfectly secure. You must also protect your OTP-capable phone.
12. Personal data breaches
We maintain a breach register. If a personal data breach occurs, we will notify the NDPC within seventy-two (72) hours of becoming aware of it where the Act requires notification. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify affected data subjects without undue delay, describing the nature of the breach and the steps you can take. Processors must notify us without undue delay so we can meet the 72-hour clock.
13. Data Protection Officer, DPIA and registration
Servixus will appoint a Data Protection Officer with expert knowledge of Nigerian data protection practice. Contact: dpo@servixus.com. The DPO monitors compliance, advises staff and is the point of contact for the NDPC and for you.
Because KYC involves identity numbers linked to biometrics, and because the Platform systematically matches jobs and monitors leakage and fraud, we will conduct a Data Privacy Impact Assessment before or at the start of that processing and consult the NDPC if residual high risk remains, as required by section 28 of the NDPA.
If we meet the NDPC thresholds for a Data Controller or Data Processor of Major Importance (including processing personal data of 200 or more data subjects in six months, providing commercial ICT services that store others’ data, or operating in a designated sector such as e-commerce or financial services), we will register with the NDPC in the applicable tier and pay the prescribed fee. We will also complete any required audit through an NDPC-recognised Data Protection Compliance Organisation.
14. Cookies and similar technologies
The mobile app uses local storage and device identifiers required for login, session security and upload resume. Any later marketing website will present a cookie notice and will not set non-essential cookies before consent. Analytics on MVP will be configured to minimise identifiers.
15. Automated decision-making
Routing of job requests uses admin-configurable rules (category, service area). Quote ranking improvements and fraud rules are on the post-launch roadmap. We will not make a solely automated decision that legally rejects KYC, bans an account or determines a dispute outcome without meaningful human involvement.
16. Changes to this Policy
We will post the new version with a new effective date and notify you of material changes through the app, SMS or email. If a change requires fresh consent (for example a new KYC vendor that re-processes NIN), we will ask for that consent separately.
17. How to contact us
Website — https://www.servixus.com
Privacy Policy — https://www.servixus.com/privacy
Short Privacy Notice — https://www.servixus.com/privacy-notice
Account deletion — https://www.servixus.com/delete-account
Data subject rights requests — https://www.servixus.com/privacy-requests or privacy@servixus.com
Data Protection Officer — dpo@servixus.com
General support — support@servixus.com
Postal: Data Protection Officer, Servixus Limited, [Insert CAC registered office], Nigeria.
Nigeria Data Protection Commission — Independent complaints authority. See ndpc.gov.ng for current filing channels.
By creating an account you acknowledge that you have been provided with this information under section 27 of the NDPA. Where we rely on consent, we will ask you to give it through a clear affirmative act that is separate from ticking the Terms of Use.