Products
Home/Legal/Data Protection

Data Protection Policy

Organisational commitments, governance, and controls for protecting personal and business data across WaZoBia-Books — for customers, regulators, and partners.

Last updated: (2026-08-10)

Purpose & commitment

WaZoBia Smartech LTD (“WaZoBia-Books”) processes personal data and sensitive business information on behalf of Nigerian and international customers. This Data Protection Policy sets out our organisational approach — how we govern privacy, assign accountability, and embed protection into our products and operations.

We commit to:

  • Processing data lawfully, fairly, and transparently
  • Collecting only what we need and keeping it no longer than necessary
  • Implementing appropriate technical and organisational security measures
  • Honouring data subject rights without undue delay
  • Not selling personal data or using it for unrelated third-party marketing
  • Working with vetted subprocessors under written data protection terms

This policy complements our Privacy Policy (transparency notice to individuals), Data Retention Policy, and Security & Compliance page.

Regulatory framework

We design our programme to meet or exceed obligations under applicable laws. The frameworks below guide our controls; not every provision applies to every customer or processing activity.

Nigeria Data Protection Act 2023 (NDPA)

  • Lawful, fair, and transparent processing
  • Storage limitation (s.24) — see our Data Retention Policy
  • Data subject rights (ss. 34–38) and breach notification (s.40)
  • Registration and compliance obligations with the NDPC where applicable

Nigeria Data Protection Regulation (NDPR) 2019

  • Continues to inform practice for organisations transitioning to NDPA
  • Privacy policies, consent, and security safeguards for Nigerian data subjects

EU General Data Protection Regulation (GDPR)

  • Articles 5–6 lawful bases; Arts. 13–14 transparency
  • Arts. 15–22 data subject rights; Art. 32 security; Art. 33–34 breach notification
  • Chapter V international transfers (SCCs / adequacy)

US state privacy laws (CCPA / CPRA and equivalents)

  • No sale of personal information; opt-out of sale/share honoured
  • Global Privacy Control (GPC) signal support
  • Dedicated Do Not Sell page and privacy opt-out API

ISO/IEC 27001 alignment (information security)

  • Risk-based ISMS controls documented on our Security page
  • Access control, logging, encryption, and supplier management

Governance & roles

RoleResponsibilityContact
Data controllerWaZoBia Smartech LTD — determines purposes and means for website and Service dataWaZoBia Smartech LTD, Kano, Lagos, and Abuja, Nigeria
Privacy leadDSAR handling, policy maintenance, NDPC/regulator liaison, privacy enquiriesadmin@wazobia-books.ng
Security leadSecurity architecture, incident response, vulnerability disclosureadmin@wazobia-books.ng
Data Protection Officer (DPO)Not currently mandatory for our scale under GDPR Art. 37; privacy lead fulfils governance duties. Appointment will be updated here if required.
Customer (Account Owner)Controller for employee, customer, and vendor PII entered into their workspaceYour organisation

Platforms covered: wazobiabooks.com and alias wazobia-books.ng (redirects to canonical site), plus the WaZoBia-Books cloud application.

Data protection principles

Lawfulness, fairness, transparency

We tell individuals what we collect and why; we do not mislead or hide processing.

Purpose limitation

Data is used for stated purposes — service delivery, support, security, billing, compliance.

Data minimisation

Forms and APIs collect only fields required for the function.

Accuracy

Customers can update records in-app; we correct inaccuracies on verified request.

Storage limitation

Documented retention schedule; see Data Retention Policy.

Integrity & confidentiality

Encryption, access controls, monitoring, and staff confidentiality obligations.

Accountability

Policies published, requests logged, subprocessors contracted, incidents documented.

Data classification

We classify information to apply proportionate controls. Business accounting data is treated as Restricted by default.

LevelExamplesControls
PublicMarketing content, published pricing, open documentationIntegrity monitoring; no special confidentiality requirement
InternalRoadmaps, internal runbooks, aggregated analyticsStaff authentication; need-to-know access
ConfidentialAccount profiles, contact enquiries, support ticketsEncryption, RBAC, audit logging, retention limits
RestrictedCredentials, payroll, financial ledgers, tax IDs, bank detailsStrong encryption, MFA, least privilege, enhanced monitoring

Lawful processing

We process personal data only where a lawful basis exists. A detailed purpose-and-basis matrix appears in our Privacy Policy — purposes & lawful bases. In summary:

  • Contract — operating accounts, delivering accounting features, processing subscriptions
  • Legal obligation — tax, audit, regulatory requests, breach notification
  • Legitimate interests — security, fraud prevention, product reliability (balanced against individual rights)
  • Consent — optional marketing, non-essential analytics where we request it

Privacy by design & default

  • Role-based access control (RBAC) with least-privilege defaults for new users
  • Encryption in transit (TLS 1.2+) for all client and API traffic
  • Encryption at rest for databases and sensitive object storage
  • Optional two-factor authentication (2FA) for account holders
  • Audit trails for financial and permission-changing actions
  • Data export tools so customers can port or back up their records
  • Cookie consent banner with essential vs optional categories and GPC honouring
  • Security headers (CSP, HSTS, frame denial) on the marketing site

Risk assessment & DPIA

We conduct privacy risk reviews when launching material new features, onboarding subprocessors that access personal data, or changing international transfer routes. Where GDPR Art. 35 requires a Data Protection Impact Assessment (DPIA), we document:

  1. Description of processing and purposes
  2. Necessity and proportionality assessment
  3. Risks to individuals and mitigations
  4. Consultation with privacy lead and, where appropriate, the NDPC or EU supervisory authority

Vendors & subprocessors

Third parties that process personal data on our behalf are subject to due diligence, contractual data protection clauses, and periodic review. Current named subprocessors are listed in the Privacy Policy — subprocessors. We require:

  • Processing only on documented instructions
  • Confidentiality commitments from personnel
  • Appropriate security measures (encryption, access control)
  • Assistance with data subject requests and breach notification
  • Deletion or return of data at contract end

Data subject rights

We maintain a documented procedure to receive, verify, and respond to requests within statutory timelines (typically 30 days, extendable where permitted). Channels:

Full rights descriptions: Privacy Policy — data subject rights

International transfers

Personal data may be processed in Nigeria, the United States, the EEA, the UK, and other locations where our subprocessors operate. We implement transfer mechanisms described in our Privacy Policy — international transfers (adequacy decisions, Standard Contractual Clauses, NDPC guidance). Enterprise customers may request a copy of relevant safeguards.

Security measures

Technical and organisational measures include encryption, MFA, logging, secure SDLC practices, vulnerability management, and incident response. Detailed control mapping is published on our Security & Compliance page. Responsible disclosure: security.txt

Incidents & personal data breaches

We maintain an incident response plan covering detection, containment, eradication, recovery, and post-incident review. Personal data breaches are assessed for risk to individuals. Where NDPA s.40 or GDPR Arts. 33–34 apply, we notify the NDPC and/or EU supervisory authority within required timelines and communicate to affected users when high risk exists.

Process details: Privacy Policy — breach notification

Training & awareness

Staff and contractors with access to personal data receive onboarding privacy and security guidance and are bound by confidentiality obligations. Engineering and support teams receive additional training on secure handling of customer accounts, DSAR workflows, and phishing awareness.

Audit & compliance monitoring

  • Periodic review of policies, retention schedule, and subprocessor list
  • Logging and monitoring of authentication and administrative actions
  • Rate limiting and abuse detection on public privacy APIs
  • Management review of open DSARs, incidents, and regulator correspondence
  • Readiness for NDPC registration and ISO 27001 certification pathways as we scale

Review

This Data Protection Policy is reviewed at least annually and after significant regulatory or product changes. Material updates are published on this page with a new “Last updated” date.

Contact

Privacy lead: admin@wazobia-books.ng

Security: admin@wazobia-books.ng

WaZoBia Smartech LTD · WaZoBia Smartech LTD, Kano, Lagos, and Abuja, Nigeria