NGO As A Service
Legal

Privacy Policy

Effective date: 1 July 2025 ·  Last updated: 1 July 2025

This policy explains what data we collect, why we collect it, and your rights.

Nigeria Data Protection Act 2023 (NDPA): This policy is designed to comply with the Nigeria Data Protection Act 2023 and the Nigeria Data Protection Regulation (NDPR). We are committed to protecting the personal data of all our users and processing it only in accordance with applicable law.

1.

Who We Are

NGO As A Service (“we,” “us,” or “our”) operates theNGO As A Service platform — a trust infrastructure service for NGOs, foundations, and their corporate partners in Nigeria. For the purposes of data protection law, we are the “data controller” of the personal data described in this Policy.

Company: NGO As A Service

Email: privacy@ngoasaservice.com

Address: Lagos, Nigeria

DPO Email: dpo@ngoasaservice.com

2.

Scope of This Policy

This Privacy Policy applies to all personal data collected, processed, or stored byNGO As A Service in connection with:

(a)

Use of our web and mobile platform at ngoasaservice.com;

(b)

Registration and account management for NGO, company, or individual users;

(c)

Verification submissions, outreach reports, CSR activity records, and any other data submitted through Platform features;

(d)

Communications with us by email, contact forms, or any other channel.

This Policy does not apply to third-party websites or services linked from the Platform. We encourage you to review the privacy policies of those third parties independently.

3.

Data We Collect

We collect the following categories of personal and organisational data:

Account & Registration Data

(a)

For all users: email address, hashed password, account type (NGO or Company), and registration timestamp.

(b)

For NGO accounts: foundation/organisation name, contact person name, phone number, contact address, and optionally a custom profile slug (URL).

(c)

For Company accounts: company name, industry, contact person name, phone number, website URL, and contact address.

Verification & Document Data (NGOs)

(d)

Legal section: CAC registration number, year of incorporation, about / mission statement, board member names and contact details, uploaded legal documents (CAC certificate, constitution, board resolutions).

(e)

Financial section: funding sources, income and expense summaries, uploaded financial documents (audited accounts, bank statements).

(f)

Impact section: description of past interventions, uploaded evidence documents and images.

(g)

Digital section: website URL, social media handles and links.

Outreach Report Data (NGOs)

(h)

Report content including title, intervention type, location, dates, number of beneficiaries, cost breakdowns, beneficiary testimonies (names, contacts, and statements), uploaded photos, and Cloudflare Stream video content.

Report Access Request Data

(i)

When a company submits a report access request: company name, industry, purpose, optional message, and timestamps. This data is shared with the relevant NGO to enable an informed consent decision.

CSR Activity Data

(j)

Activity titles, descriptions, partner NGO references, start and end dates, budget amounts, disbursement records (amount, date, description), and activity status.

Technical & Usage Data

(k)

IP address, browser type and version, device type, pages visited, timestamps, and referring URLs — collected automatically when you use the Platform.

4.

How We Use Your Data

We use the data we collect for the following purposes:

(a)

Account provision and authentication: to create and manage your account, authenticate your identity, and maintain account security.

(b)

Verification processing: to review submitted documents, assess verification status, and generate Readiness Scores for NGO profiles.

(c)

Public profile display: to display summary NGO information, Readiness Scores, and outreach data on public-facing profile pages accessible to all visitors without an account.

(d)

Report access facilitation: to enable companies to submit access requests and to share company profile information with NGOs so they can make an informed consent decision.

(e)

CSR activity management: to enable companies to create, track, and report on CSR activities linked to NGO partners.

(f)

Communications: to send transactional emails (account verification, password resets, request notifications, verification status updates). We do not send marketing emails without your explicit consent.

(g)

Platform improvement: to analyse usage patterns, troubleshoot issues, and improve the Platform's functionality and user experience.

(h)

Legal and compliance: to comply with applicable Nigerian law, respond to lawful requests from regulatory or law enforcement authorities, and enforce our Terms of Service.

5.

Legal Basis for Processing

Under the Nigeria Data Protection Act 2023, we process personal data on the following legal bases:

(a)

Contract performance: processing necessary to provide the Services you have registered for — including account management, verification review, and platform features.

(b)

Legitimate interests: processing for Platform security, fraud prevention, abuse detection, and service improvement, where such interests are not overridden by your rights.

(c)

Consent: where we rely on consent (e.g. for marketing communications or optional features), you may withdraw that consent at any time without affecting the lawfulness of prior processing.

(d)

Legal obligation: processing required to comply with applicable Nigerian law or a lawful order of a competent authority.

Where you have provided sensitive data (such as images of individuals or beneficiary testimony), we rely on your explicit consent, which you provide by submitting such data through the Platform.

6.

Data Sharing & Disclosure

We do not sell, rent, or trade your personal data. We share your data only in the following circumstances:

(a)

Public profile data: Summary NGO information, Readiness Scores, beneficiary statistics, published outreach report summaries, and section verification statuses are publicly visible to anyone accessing the Platform, including non-registered visitors. You control what you submit to each section.

(b)

Report access (company-granted): When an NGO grants a company's access request, full NGO documentation, financial records, board contacts, and outreach report details become accessible to that specific company's account. NGOs remain in full control of whether to grant or decline each request.

(c)

Company profile sharing: When a company submits an access request, the requesting company's profile data is shared with the target NGO to enable an informed consent decision.

(d)

Service providers: We share data with third-party service providers who process data on our behalf solely to provide the Platform. These include Firebase (Google LLC) for authentication, database, and hosting, and Cloudflare for file storage and video streaming. All service providers are bound by data processing agreements.

(e)

Legal requirements: We may disclose your data if required to do so by law, court order, or a lawful request from a government or regulatory authority in Nigeria.

(f)

Business transfers: In the event of a merger, acquisition, or sale of all or a substantial part of our assets, user data may be transferred to the acquiring entity, subject to equivalent privacy protections.

7.

International Data Transfers

Our infrastructure providers (Google Firebase and Cloudflare) may process and store data in data centres located outside Nigeria, including in the United States and the European Union.

Where data is transferred outside Nigeria, we take steps to ensure that adequate protections are in place, including reliance on providers who comply with internationally recognised data protection standards and who are subject to binding data processing agreements with appropriate safeguards.

8.

Data Retention

We retain your data for as long as your account is active or as necessary to provide the Services. Specifically:

(a)

Active accounts: All account data, verification records, outreach reports, and CSR activity data are retained for the duration of your account.

(b)

Deleted accounts: Upon account deletion, we will delete or anonymise your personal data within 90 days, except where retention is required by law or legitimate business necessity (e.g. financial records for tax compliance, data subject to an active legal dispute).

(c)

Published outreach reports: If an NGO has published outreach reports that are linked to CSR activity records held by a company user, we may retain anonymised impact data following NGO account deletion to maintain the integrity of the company's records.

(d)

Legal and compliance records: Certain records may be retained for up to 7 years as required by Nigerian financial, tax, and corporate law.

We review retention periods periodically and will delete data that is no longer necessary.

9.

Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:

(a)

Encryption of data in transit using TLS/HTTPS for all Platform communications.

(b)

Secure credential storage — passwords are hashed using industry-standard algorithms via Firebase Authentication and are never stored in plain text.

(c)

Role-based access controls — NGO data is accessible only to the relevant account holder and to companies with explicitly granted access.

(d)

Firestore security rules enforcing that users can only access data they are authorised to view.

(e)

Cloudflare R2 and Stream presigned URL mechanisms ensuring uploaded documents and videos are not publicly accessible without authorisation.

Despite these measures, no data transmission or storage system can be guaranteed 100% secure. If you become aware of any security vulnerability or breach, please notify us immediately at privacy@ngoasaservice.com.

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify the Nigeria Data Protection Commission (NDPC) and affected users in accordance with our obligations under the NDPA 2023.

10.

Your Rights

Under the Nigeria Data Protection Act 2023, you have the following rights with respect to your personal data:

(a)

Right of access: You may request a copy of the personal data we hold about you.

(b)

Right to rectification: You may request that we correct inaccurate or incomplete personal data about you.

(c)

Right to erasure (“right to be forgotten”): You may request that we delete your personal data in certain circumstances, including where it is no longer necessary for the purpose it was collected.

(d)

Right to restrict processing: You may request that we restrict the processing of your data in certain circumstances.

(e)

Right to data portability: Where processing is based on consent or contract and is carried out by automated means, you may request a copy of your data in a structured, machine-readable format.

(f)

Right to object: You may object to processing based on legitimate interests or for direct marketing purposes.

(g)

Right to withdraw consent: Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

To exercise any of these rights, please contact our Data Protection Officer at dpo@ngoasaservice.com. We will respond to your request within 30 days. We may ask you to verify your identity before processing your request.

You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpb.gov.ng if you believe we have violated your data protection rights.

11.

Cookies & Tracking

The Platform uses cookies and similar tracking technologies to operate correctly and improve your experience. We use the following types of cookies:

(a)

Strictly necessary cookies: Required for authentication and session management (including Firebase Authentication session tokens). These cannot be disabled without preventing core Platform functionality.

(b)

Functional cookies: Used to remember your preferences (such as filter settings) during a session.

(c)

Analytics cookies: We may use anonymous analytics tools to understand how users interact with the Platform. Where used, no personally identifiable information is collected through analytics cookies without your consent.

You can control cookies through your browser settings. Note that disabling strictly necessary cookies will affect Platform functionality, including your ability to log in.

12.

Children's Privacy

The Platform is not directed at children under the age of 18. We do not knowingly collect personal data from anyone under 18. If we become aware that we have inadvertently collected personal data from a person under 18 without appropriate consent, we will delete that data promptly.

If you believe we may have collected data from or about a child under 18, please contact us immediately at privacy@ngoasaservice.com.

Where beneficiary testimony or imagery submitted by NGOs includes data relating to minors, the submitting NGO is responsible for ensuring that appropriate consent has been obtained from the minor's parent or legal guardian in accordance with applicable law.

13.

Third-Party Services

The Platform integrates with the following third-party services that may process your personal data:

(a)

Google Firebase (Google LLC): Authentication, real-time database (Firestore), and cloud infrastructure. Governed by Google's Privacy Policy and Data Processing Terms. Data may be processed in the United States and other jurisdictions where Google operates.

(b)

Cloudflare, Inc.: File storage (Cloudflare R2) for uploaded documents and images, and video streaming (Cloudflare Stream) for uploaded video content. Governed by Cloudflare's Privacy Policy.

We encourage you to review the privacy policies of these providers. We are not responsible for the data practices of third-party services beyond the scope of our data processing agreements with them.

14.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the Services, or applicable law. When we make material changes, we will notify you by posting a notice on the Platform and, where practicable, by sending an email to your registered address at least 14 days before the changes take effect.

The updated Policy will be identified by a revised effective date at the top of this page. We encourage you to review this Policy periodically. Your continued use of the Platform after the effective date of any revision constitutes your acceptance of the updated Policy.

15.

Contact & Data Protection Officer

For all privacy-related queries, data subject requests, or to report a suspected data breach, please contact our Data Protection Officer:

Data Protection Officer

Organisation: NGO As A Service

Email: dpo@ngoasaservice.com

General enquiries: privacy@ngoasaservice.com

Address: Lagos, Nigeria

We aim to respond to all data protection enquiries within 30 calendar days. Where a request is complex or you have made multiple requests, this period may be extended by a further two months, in which case we will notify you of the extension and the reasons for it within the initial 30-day period.

You may also contact the Nigeria Data Protection Commission (NDPC) directly if you are unsatisfied with our response: ndpb.gov.ng

© 2026 NGO As A Service. All rights reserved.