NDPR Compliant

Privacy Policy

We value your trust. This policy explains how Trifix collects, uses, and protects your personal data.

Last Updated: January 1, 2026

Data Security

Your data is encrypted using industry-standard SSL/TLS technology. We do not sell your personal data to third parties.

Location Privacy

We only track location during active jobs to ensure safety and artisan arrival. Tracking stops when the job ends.

Payment Data

We do not store your full card details. All payments are processed by licensed partners (Paystack, Monnify).

1 Introduction & Scope

TRIFIX ARTISAN NETWORK LTD ("Trifix," "we," "us," or "our") is a company duly incorporated under the laws of the Federal Republic of Nigeria with registration number [CAC Registration Number]. We are committed to protecting and respecting your privacy.

This Privacy Policy ("Policy") explains how we collect, use, disclose, transfer, store, and protect your personal data when you access or use the Trifix website, mobile application, USSD service, or any related features (collectively, the "Platform").

This Policy is drafted in strict compliance with the Nigeria Data Protection Regulation (NDPR) 2019, the NDPR Implementation Framework 2021, and all other applicable data protection laws of Nigeria. It should be read in conjunction with our Terms of Service.

BY USING THE PLATFORM, YOU CONSENT TO THE COLLECTION, USE, AND DISCLOSURE OF YOUR PERSONAL DATA AS DESCRIBED IN THIS POLICY.

2 Data Controller & Contact Details

For the purposes of the NDPR, the data controller responsible for your personal data is:

TRIFIX ARTISAN NETWORK LTD

RC:

140 Atiku Abubakar Way, Uyo

Akwa Ibom State, Nigeria

Data Protection Officer (DPO): privacy@trifix.ng

General Inquiries: support@trifix.ng

Our Data Protection Officer is responsible for overseeing questions in relation to this Policy. If you have any questions, including any requests to exercise your legal rights, please contact the DPO using the details above.

3 Categories of Personal Data We Collect

Personal data means any information relating to an identified or identifiable natural person. We may collect, use, store, and transfer different kinds of personal data about you, which we have grouped as follows:

Category Examples
Identity Data Full name, username, profile photograph, government-issued ID (NIN, Driver's Licence, International Passport), date of birth, gender.
Contact Data Phone number, email address, residential/service address, billing address.
Location Data Real-time GPS coordinates (only during active job sessions), IP-derived approximate location.
Transaction Data Payment history, job amounts, dates, service types, partial payment card details (last 4 digits, expiry) processed via our payment partners.
Technical & Usage Data IP address, device type, operating system, browser type, app version, access times, pages viewed, features used, crash logs.
Communications Data In-app chat messages, call logs (metadata only), email correspondence, support tickets, dispute evidence (photos/videos).
Verification & Background Data Results of identity verification checks, skills assessments, and background screening (with your explicit consent).
Marketing & Preferences Data Your marketing preferences, survey responses, and feedback.

We also collect, use, and share Aggregated Data such as statistical or demographic data for any purpose. Aggregated Data does not directly or indirectly reveal your identity and is not considered personal data under NDPR.

4 How We Collect Your Data

We use different methods to collect data from and about you, including:

  • Direct Interactions: You provide data when you register an account, create a profile, book a service, upload documents for verification, contact support, or complete surveys.
  • Automated Technologies: As you interact with our Platform, we automatically collect Technical and Usage Data via cookies, server logs, and similar technologies (see Section 13: Cookies & Tracking).
  • Third Parties: We may receive data from payment processors (Paystack, Monnify), identity verification services, background check providers, and other users (e.g., reviews).
  • Public Sources: We may verify identity information against publicly available government databases where permitted by law.

5 Legal Basis & Purposes for Processing

Under NDPR, we rely on the following lawful bases for processing your personal data:

Purpose Categories of Data Lawful Basis
Account creation & management Identity, Contact Performance of a contract
Artisan vetting & verification Identity, Verification, Background Consent; Legitimate interest (fraud prevention)
Job matching & service delivery Identity, Contact, Location Performance of a contract
Payment processing & Escrow Transaction, Contact Performance of a contract
Customer support & dispute resolution Communications, Transaction Legitimate interest; Legal claims
Safety, security & fraud prevention Technical, Location, Identity Legitimate interest; Legal obligation
Compliance with legal obligations All relevant categories Legal obligation (KYC/AML, Tax, CBN directives)
Platform improvement & analytics Technical, Usage Legitimate interest
Marketing communications Contact, Marketing Consent

Where we rely on legitimate interests, we have balanced your rights and freedoms against our interests and determined that our interests are not overridden by the impact on you. You may object to processing based on legitimate interests by contacting our DPO.

6 Sharing & Disclosure of Your Data

We do not sell, rent, or trade your personal data. We share data only in the following limited circumstances:

  • Between Users: When a job is confirmed, we share the Client's name, address, and contact number with the assigned Artisan. We share the Artisan's name, profile photo, and verification status with the Client. This sharing is essential for service delivery.
  • Payment Processors: We transmit Transaction Data to our licensed payment partners—Paystack and Monnify—to process payments, manage Escrow, and handle payouts. These partners are independent data controllers for payment data and have their own privacy policies, which we encourage you to review.
  • Identity Verification & Background Check Providers: With your explicit consent, we share Identity Data with third-party verification services to confirm your identity and conduct background screening.
  • Service Providers & Sub-processors: We engage trusted third parties to support Platform operations (e.g., cloud hosting—AWS/Google Cloud, SMS/Email delivery, customer support tools). These providers are contractually bound to process data only on our instructions and with appropriate security measures.
  • Legal & Regulatory Disclosures: We may disclose data where required by law, court order, or governmental regulation (e.g., EFCC, NITDA, CBN, Police). We will notify you of such disclosure unless prohibited by law.
  • Business Transfers: In the event of a merger, acquisition, or asset sale, your data may be transferred to the successor entity, subject to this Policy.
  • With Your Consent: We may share data for other purposes with your explicit consent.
Important Note on User-to-User Sharing: You acknowledge and agree that once personal data (e.g., address, phone number) is shared with another User for job fulfillment, Trifix has no control over how that User handles such data. You should not share sensitive information beyond what is necessary for the job. Any misuse of shared data by a User is a violation of our Terms and should be reported immediately.

7 International Data Transfers

Trifix is based in Nigeria, and your data is primarily stored on servers located within Nigeria. However, some of our third-party service providers (e.g., cloud hosting, analytics) may be located outside Nigeria, including in jurisdictions that may not have data protection laws equivalent to the NDPR.

In such cases, we ensure that appropriate safeguards are in place to protect your data in accordance with NDPR requirements. These safeguards include:

  • Entering into data processing agreements that incorporate NDPR-compliant clauses (e.g., Standard Contractual Clauses approved by NITDA).
  • Ensuring that the recipient jurisdiction has been deemed to provide an adequate level of protection by NITDA.
  • Obtaining your explicit consent for the transfer where required.

By using the Platform, you consent to the transfer of your data to such third parties and locations as described in this Policy.

8 Data Security

We implement and maintain appropriate technical, administrative, and physical security measures designed to protect your personal data from accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include:

  • Encryption of data in transit using TLS 1.3 and at rest using AES-256.
  • Multi-factor authentication for internal administrative access.
  • Regular vulnerability scanning and penetration testing.
  • Strict access controls and role-based permissions.
  • Regular security awareness training for all personnel.

However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee its absolute security.

9 Data Breach Notification

In compliance with Article 4.2 of the NDPR, Trifix maintains a personal data breach management policy. In the unlikely event of a data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the National Information Technology Development Agency (NITDA) within 72 hours of becoming aware of the breach.
  • Notify affected individuals without undue delay, describing the nature of the breach, the likely consequences, and the measures taken to address it.
  • Provide contact details for our DPO for further information.

We will not notify you if the data was encrypted and the encryption key was not compromised, or if we have taken subsequent measures to ensure the high risk no longer materializes.

10 Data Retention

We will retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements.

Our retention periods are as follows:

  • Transaction & Financial Records: Minimum of 5 years from the date of transaction (in compliance with CBN regulations and tax laws).
  • Account & Identity Data: For the duration of your active account plus a period of 3 years after account closure for legal and dispute resolution purposes.
  • Communications & Chat Logs: Retained for 2 years to support dispute resolution, unless subject to legal hold.
  • Location Data: Detailed GPS history is deleted within 7 days of job completion. Anonymized location patterns may be retained longer for analytics.
  • Marketing Preferences: Retained indefinitely unless you withdraw consent.

After the applicable retention period, your data will be securely deleted, anonymized, or archived in a way that prevents further processing.

11 Your Rights Under the NDPR

As a data subject under the NDPR, you have the following rights regarding your personal data:

Right to be Informed

You have the right to be provided with clear, transparent, and easily understandable information about how we use your data (which this Policy fulfills).

Right of Access

You may request a copy of the personal data we hold about you, free of charge (except for manifestly unfounded or excessive requests).

Right to Rectification

You may request that we correct any inaccurate or incomplete personal data.

Right to Erasure ("Right to be Forgotten")

You may request deletion of your data where there is no compelling lawful basis for its continued retention. This right is subject to legal retention obligations (e.g., financial records).

Right to Restrict Processing

You may request that we limit processing of your data in certain circumstances (e.g., while verifying accuracy).

Right to Data Portability

You may request a copy of your data in a structured, commonly used, machine-readable format to transmit to another controller.

Right to Object

You may object to processing based on legitimate interests or for direct marketing purposes at any time.

Right to Withdraw Consent

Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing prior to withdrawal.

Right to Lodge a Complaint

You have the right to lodge a complaint with NITDA if you believe your data protection rights have been violated.

To exercise any of these rights, please contact our DPO at privacy@trifix.ng. We will respond within one (1) month of receipt, which may be extended by up to two (2) additional months for complex requests. We may require proof of identity before processing your request.

NITDA Contact Details: National Information Technology Development Agency (NITDA), No. 28, Port Harcourt Crescent, Off Gimbiya Street, Area 11, Garki, Abuja. Website: nitda.gov.ng.

12 Children's Privacy

The Platform is not intended for individuals under the age of 18. We do not knowingly collect or solicit personal data from anyone under 18. If we become aware that we have inadvertently collected personal data from a child under 18 without verified parental consent, we will take prompt steps to delete such data from our records. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at privacy@trifix.ng.

13 Cookies & Tracking Technologies

We use cookies and similar tracking technologies (e.g., pixels, tags, local storage) to collect Technical and Usage Data, enhance user experience, and analyze Platform performance.

We use the following categories of cookies:

  • Strictly Necessary Cookies: Essential for Platform functionality, such as maintaining your session and processing payments. These cannot be disabled.
  • Performance/Analytics Cookies: Help us understand how visitors interact with the Platform (e.g., pages visited, time spent). We use Google Analytics and similar tools. Data is aggregated and anonymized.
  • Functional Cookies: Remember your preferences and choices (e.g., language, region).
  • Targeting/Advertising Cookies: We may use these to deliver relevant advertisements (with your consent). We do not currently run third-party ad networks on the Platform.

You can control cookies through your browser settings. Most browsers allow you to refuse or delete cookies. However, disabling strictly necessary cookies may impact Platform functionality.

14 Third-Party Links

The Platform may contain links to third-party websites, plug-ins, or applications (e.g., payment gateways, social media). Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy practices. We encourage you to read the privacy policy of every website you visit.

15 Changes to This Policy

We reserve the right to update or modify this Policy at any time to reflect changes in our practices, legal requirements, or operational needs. If we make material changes, we will provide notice through the Platform, via email, or by other means prior to the change becoming effective. The "Last Updated" date at the top of this Policy indicates the most recent version. Your continued use of the Platform after any changes constitutes acceptance of the revised Policy.

16 Contact & Complaints

If you have any questions, concerns, or complaints regarding this Privacy Policy or our data practices, please contact our Data Protection Officer:

Trifix Data Protection Office

Data Protection Officer: [DPO Name]

Email: privacy@trifix.ng

Phone: +234 708 760 5126

Address: TRIFIX ARTISAN NETWORK LTD, 140 Atiku Abubakar Way, Uyo, Akwa Ibom State, Nigeria.

If you are not satisfied with our response, you have the right to lodge a complaint with the Nigeria Data Protection Bureau (NDPB) — formerly NITDA — via their official channels.