Purpose & commitment
WaZoBia Smartech LTD (“WaZoBia-Books”) processes personal data and sensitive business information on behalf of Nigerian and international customers. This Data Protection Policy sets out our organisational approach — how we govern privacy, assign accountability, and embed protection into our products and operations.
We commit to:
- Processing data lawfully, fairly, and transparently
- Collecting only what we need and keeping it no longer than necessary
- Implementing appropriate technical and organisational security measures
- Honouring data subject rights without undue delay
- Not selling personal data or using it for unrelated third-party marketing
- Working with vetted subprocessors under written data protection terms
This policy complements our Privacy Policy (transparency notice to individuals), Data Retention Policy, and Security & Compliance page.
Regulatory framework
We design our programme to meet or exceed obligations under applicable laws. The frameworks below guide our controls; not every provision applies to every customer or processing activity.
Nigeria Data Protection Act 2023 (NDPA)
- Lawful, fair, and transparent processing
- Storage limitation (s.24) — see our Data Retention Policy
- Data subject rights (ss. 34–38) and breach notification (s.40)
- Registration and compliance obligations with the NDPC where applicable
Nigeria Data Protection Regulation (NDPR) 2019
- Continues to inform practice for organisations transitioning to NDPA
- Privacy policies, consent, and security safeguards for Nigerian data subjects
EU General Data Protection Regulation (GDPR)
- Articles 5–6 lawful bases; Arts. 13–14 transparency
- Arts. 15–22 data subject rights; Art. 32 security; Art. 33–34 breach notification
- Chapter V international transfers (SCCs / adequacy)
US state privacy laws (CCPA / CPRA and equivalents)
- No sale of personal information; opt-out of sale/share honoured
- Global Privacy Control (GPC) signal support
- Dedicated Do Not Sell page and privacy opt-out API
ISO/IEC 27001 alignment (information security)
- Risk-based ISMS controls documented on our Security page
- Access control, logging, encryption, and supplier management
Governance & roles
| Role | Responsibility | Contact |
|---|---|---|
| Data controller | WaZoBia Smartech LTD — determines purposes and means for website and Service data | WaZoBia Smartech LTD, Kano, Lagos, and Abuja, Nigeria |
| Privacy lead | DSAR handling, policy maintenance, NDPC/regulator liaison, privacy enquiries | admin@wazobia-books.ng |
| Security lead | Security architecture, incident response, vulnerability disclosure | admin@wazobia-books.ng |
| Data Protection Officer (DPO) | Not currently mandatory for our scale under GDPR Art. 37; privacy lead fulfils governance duties. Appointment will be updated here if required. | — |
| Customer (Account Owner) | Controller for employee, customer, and vendor PII entered into their workspace | Your organisation |
Platforms covered: wazobiabooks.com and alias wazobia-books.ng (redirects to canonical site), plus the WaZoBia-Books cloud application.
Data protection principles
Lawfulness, fairness, transparency
We tell individuals what we collect and why; we do not mislead or hide processing.
Purpose limitation
Data is used for stated purposes — service delivery, support, security, billing, compliance.
Data minimisation
Forms and APIs collect only fields required for the function.
Accuracy
Customers can update records in-app; we correct inaccuracies on verified request.
Storage limitation
Documented retention schedule; see Data Retention Policy.
Integrity & confidentiality
Encryption, access controls, monitoring, and staff confidentiality obligations.
Accountability
Policies published, requests logged, subprocessors contracted, incidents documented.
Data classification
We classify information to apply proportionate controls. Business accounting data is treated as Restricted by default.
| Level | Examples | Controls |
|---|---|---|
| Public | Marketing content, published pricing, open documentation | Integrity monitoring; no special confidentiality requirement |
| Internal | Roadmaps, internal runbooks, aggregated analytics | Staff authentication; need-to-know access |
| Confidential | Account profiles, contact enquiries, support tickets | Encryption, RBAC, audit logging, retention limits |
| Restricted | Credentials, payroll, financial ledgers, tax IDs, bank details | Strong encryption, MFA, least privilege, enhanced monitoring |
Lawful processing
We process personal data only where a lawful basis exists. A detailed purpose-and-basis matrix appears in our Privacy Policy — purposes & lawful bases. In summary:
- Contract — operating accounts, delivering accounting features, processing subscriptions
- Legal obligation — tax, audit, regulatory requests, breach notification
- Legitimate interests — security, fraud prevention, product reliability (balanced against individual rights)
- Consent — optional marketing, non-essential analytics where we request it
Privacy by design & default
- Role-based access control (RBAC) with least-privilege defaults for new users
- Encryption in transit (TLS 1.2+) for all client and API traffic
- Encryption at rest for databases and sensitive object storage
- Optional two-factor authentication (2FA) for account holders
- Audit trails for financial and permission-changing actions
- Data export tools so customers can port or back up their records
- Cookie consent banner with essential vs optional categories and GPC honouring
- Security headers (CSP, HSTS, frame denial) on the marketing site
Risk assessment & DPIA
We conduct privacy risk reviews when launching material new features, onboarding subprocessors that access personal data, or changing international transfer routes. Where GDPR Art. 35 requires a Data Protection Impact Assessment (DPIA), we document:
- Description of processing and purposes
- Necessity and proportionality assessment
- Risks to individuals and mitigations
- Consultation with privacy lead and, where appropriate, the NDPC or EU supervisory authority
Vendors & subprocessors
Third parties that process personal data on our behalf are subject to due diligence, contractual data protection clauses, and periodic review. Current named subprocessors are listed in the Privacy Policy — subprocessors. We require:
- Processing only on documented instructions
- Confidentiality commitments from personnel
- Appropriate security measures (encryption, access control)
- Assistance with data subject requests and breach notification
- Deletion or return of data at contract end
Data subject rights
We maintain a documented procedure to receive, verify, and respond to requests within statutory timelines (typically 30 days, extendable where permitted). Channels:
- Online DSAR form
- Email: admin@wazobia-books.ng
- US opt-out: Do Not Sell or Share
Full rights descriptions: Privacy Policy — data subject rights
International transfers
Personal data may be processed in Nigeria, the United States, the EEA, the UK, and other locations where our subprocessors operate. We implement transfer mechanisms described in our Privacy Policy — international transfers (adequacy decisions, Standard Contractual Clauses, NDPC guidance). Enterprise customers may request a copy of relevant safeguards.
Security measures
Technical and organisational measures include encryption, MFA, logging, secure SDLC practices, vulnerability management, and incident response. Detailed control mapping is published on our Security & Compliance page. Responsible disclosure: security.txt
Incidents & personal data breaches
We maintain an incident response plan covering detection, containment, eradication, recovery, and post-incident review. Personal data breaches are assessed for risk to individuals. Where NDPA s.40 or GDPR Arts. 33–34 apply, we notify the NDPC and/or EU supervisory authority within required timelines and communicate to affected users when high risk exists.
Process details: Privacy Policy — breach notification
Training & awareness
Staff and contractors with access to personal data receive onboarding privacy and security guidance and are bound by confidentiality obligations. Engineering and support teams receive additional training on secure handling of customer accounts, DSAR workflows, and phishing awareness.
Audit & compliance monitoring
- Periodic review of policies, retention schedule, and subprocessor list
- Logging and monitoring of authentication and administrative actions
- Rate limiting and abuse detection on public privacy APIs
- Management review of open DSARs, incidents, and regulator correspondence
- Readiness for NDPC registration and ISO 27001 certification pathways as we scale
Review
This Data Protection Policy is reviewed at least annually and after significant regulatory or product changes. Material updates are published on this page with a new “Last updated” date.
Contact
Privacy lead: admin@wazobia-books.ng
Security: admin@wazobia-books.ng
WaZoBia Smartech LTD · WaZoBia Smartech LTD, Kano, Lagos, and Abuja, Nigeria