I. Aim of the Data Protection Policy
Urhere Solutions Ltd, the operator of Asanya, is committed to compliance with applicable data protection laws and internationally recognised data protection principles.
This Data Protection Policy applies to Urhere Solutions Ltd in relation to Asanya and is based on generally accepted principles governing the lawful and responsible processing of personal data.
Ensuring appropriate data protection is fundamental to trustworthy relationships between Asanya, Businesses, Partners, users and other stakeholders.
The Data Protection Policy is intended to support the level of data protection required under applicable Nigerian data protection laws and other applicable legal requirements.
II. Scope and Amendment of the Data Protection Policy
This Data Protection Policy applies to Urhere Solutions Ltd and its employees, officers, authorised personnel and relevant operations relating to Asanya.
The Policy applies to the processing of personal data in connection with Asanya, including personal data relating to:
-
Business users;
-
Partners;
-
prospective users;
-
customers or participants where relevant;
-
employees and applicants;
-
persons represented within attribution or programme activity;
-
authorised users;
-
website visitors; and
-
other data subjects whose information is lawfully processed through Asanya.
Anonymised data, including data used for statistical evaluations, research or aggregated reporting where individuals cannot reasonably be identified, is not personal data for purposes of this Policy.
This Data Protection Policy may be amended in coordination with the Data Protection Officer and the Chief Executive Officer under the applicable internal procedure for amending policies.
Material amendments shall be documented and communicated through the applicable policy-management process.
III. Application of National Laws
This Data Protection Policy incorporates internationally recognised data protection principles without replacing applicable national laws. It supplements applicable Nigerian data protection laws.
Where applicable law conflicts with this Policy or imposes stricter requirements, the applicable law shall prevail.
The principles contained in this Policy should also guide Urhere’s processing activities where no specific legal provision directly addresses the relevant matter.
Applicable requirements concerning registration, reporting, notification, cross-border transfer and other regulated processing activities must be observed.
Urhere Solutions Ltd is responsible for compliance with this Policy and its applicable legal obligations.
Where there is reason to believe that a legal requirement conflicts with this Policy, the Data Protection Officer should be informed so that an appropriate and lawful solution can be determined.
IV. Principles for Processing Personal Data
a. Fairness and Lawfulness
When processing personal data, the rights and interests of data subjects must be respected. Personal data must be collected and processed fairly, lawfully and in a transparent manner.
b. Purpose Limitation
Personal data should be processed only for identified and legitimate purposes. A subsequent change in purpose must be lawful, reasonably compatible with the original purpose where required, and properly documented.
c. Transparency
Data subjects should be given appropriate information about how their personal data is handled. Where reasonably practicable and appropriate, personal data should be obtained directly from the individual concerned or through another lawful source.
d. Data Minimisation
Before processing personal data, Urhere should determine whether and to what extent the processing is necessary for the relevant purpose. Personal data should not be collected merely because it may become useful in the future unless such collection is lawful and reasonably necessary.
This principle applies particularly to Asanya’s Partner visibility and relationship-management functionality. Where a status, confirmation or aggregate information is sufficient, underlying personal or confidential information should not be unnecessarily disclosed.
e. Storage Limitation
Personal data should be retained only for as long as reasonably necessary for the applicable purpose or required by law, contract, audit, regulatory, dispute-resolution or legitimate business requirements.
Data that is no longer required should be deleted, anonymised or securely archived in accordance with applicable retention rules.
f. Accuracy
Personal data must, where appropriate, be accurate, complete and kept reasonably up to date. Appropriate measures should be available for inaccurate or incomplete personal data to be corrected, supplemented, updated or otherwise appropriately addressed.
g. Confidentiality and Integrity of Data
Personal data must be protected through appropriate organisational and technical measures against:
h. Lawfulness
Personal data may be processed only where an appropriate lawful basis exists. A lawful basis is also required where the purpose of processing is materially changed.
Where required, the data subject should be informed of:
-
the identity of the relevant Data Controller;
-
the purpose of the processing;
-
applicable categories of personal data;
-
relevant recipients or categories of recipients; and
-
other information required under applicable law.
V. Reliability of Data Processing
Collecting, processing and using personal data is permitted only where an appropriate lawful basis exists.
1. Business, Partner and User Data
1.1 Data Processing for a Contractual Relationship
Personal data relating to Businesses, Partners, prospective users and other relevant users may be processed where necessary to establish, perform, administer or terminate a contractual relationship.
Before a contract is concluded, personal data may also be processed where necessary to respond to enquiries, facilitate onboarding, provide information or take other steps requested in connection with a prospective relationship.
1.2 Data Processing for Asanya Business and Partner Relationships
Personal data may be processed where reasonably necessary to provide Asanya functionality, including:
-
creating Business or Partner accounts;
-
administering Business and Partner relationships;
-
providing Partner Codes or other identifiers;
-
recording attribution;
-
recording milestones;
-
recording Qualifying Outcomes;
-
facilitating Partner visibility and relationship management;
-
calculating or recording commission or other supported rewards;
-
maintaining settlement records;
-
supporting dispute resolution;
-
maintaining audit and activity histories;
-
administering Partner visibility, availability and discoverability;
-
enabling supported integrations; and
-
providing other functionality made available on Asanya.
The extent of the personal data processed must remain proportionate to the relevant purpose.
1.3 Data Processing for Advertising and Marketing Purposes
Where a data subject contacts Asanya to request information about its services, personal data may be processed to respond to that request.
Personal data may also be processed for lawful marketing, advertising, market research or opinion research where an appropriate legal basis exists and the processing is compatible with the purpose for which the information was collected.
Where a data subject validly objects to or withdraws consent for relevant direct marketing, the personal data should no longer be used for that purpose except as permitted by law.
1.4 Consent to Data Processing
Personal data may be processed where valid consent has been obtained and consent is the appropriate lawful basis.
Before providing consent, the data subject should receive appropriate information concerning the proposed processing.
Consent should be capable of being demonstrated and may be obtained electronically or in another lawful manner.
1.5 Legal Obligation
Personal data may be processed where applicable legislation requires, authorises or permits the processing.
The nature and extent of the processing should be necessary and proportionate to the relevant legal requirement.
1.6 Performance of Contract
Personal data may be processed where necessary to perform a contract between Urhere Solutions Ltd and a Business, Partner or other user.
Where Asanya processes personal data on behalf of another entity in circumstances requiring contractual data-processing arrangements, an appropriate Data Processing Agreement or Data Processing Schedule should apply.
1.7 Legitimate Interest
Personal data may be processed where necessary for a legitimate interest of Urhere Solutions Ltd or another relevant party, provided that the interests, rights and freedoms of the data subject do not override that interest.
Before materially relying on legitimate interest for processing where appropriate, Urhere should assess and document:
-
the legitimate interest being pursued;
-
the necessity of the processing; and
-
the impact on the data subject.
A Legitimate Interest Assessment may be conducted where appropriate.
1.8 Processing of Sensitive Personal Data
Sensitive personal data may be processed only where an appropriate lawful basis and any additional condition required by law are satisfied. Where Asanya or another Urhere operation proposes material processing of sensitive personal data, the Data Protection Officer should be consulted in advance.
Asanya should not collect or expose underlying sensitive information merely because a Business-defined milestone or programme status relates to it.
Example: Where status-level information such as “KYC Submitted — Pending Business Review” is sufficient for Partner relationship management, underlying identity or KYC documentation should not be disclosed unnecessarily.
1.9 Automated Individual Decisions
Where personal data is processed automatically to assess individuals, such processing should not be used as the sole basis for a decision producing significant adverse legal or similarly significant effects except where permitted by applicable law and appropriate safeguards are in place.
Where required, affected persons should be informed of relevant automated decision-making and provided with applicable rights.
1.10 User Data, Websites and Applications
Where personal data is processed through the Asanya website, application or related digital services, data subjects should be provided with an appropriate Privacy Notice.
Where cookies or similar technologies are used, appropriate information and controls should be provided in accordance with applicable requirements.
2. Employee Data
2.1 Data Processing for the Employment Relationship
In employment relationships, personal data may be processed where necessary to initiate, administer and terminate the employment relationship.
Where a person applies for employment with Urhere, applicant data may be processed for recruitment and selection purposes.
Where an applicant is unsuccessful, the information should be deleted or retained only in accordance with the applicable retention period or with an appropriate lawful basis.
2.2 Legal Obligation
Employee personal data may be processed where applicable legislation requires, authorises or permits such processing.
The extent of the processing must remain necessary for the relevant lawful purpose.
2.3 Collective Agreements on Data Processing
Where applicable, processing that goes beyond ordinary contractual requirements may be authorised through a valid collective agreement or similar arrangement where recognised by applicable law.
2.4 Consent to Data Processing
Employee personal data may be processed on the basis of consent only where the consent is valid, informed and genuinely voluntary.
Consent must not be obtained through improper pressure or circumstances that materially undermine free choice.
2.5 Legitimate Interest
Employee personal data may also be processed where necessary for a legitimate interest, provided the employee’s interests, rights and freedoms do not override that interest.
The relevant legitimate interest and impact on the employee should be identified and documented where appropriate.
2.6 Processing of Sensitive Data
Sensitive employee personal data may be processed only where an appropriate legal basis and any additional lawful conditions are satisfied.
Where significant sensitive-data processing is proposed, the Data Protection Officer should be consulted.
2.7 Automated Decisions
Automated processing of employee personal data should not be the sole basis for decisions producing significant adverse consequences for an employee except where lawfully permitted and appropriate safeguards are available.
2.8 Telecommunications and Internet
Telephone systems, email, internet access and other technology provided by Urhere are primarily intended for authorised work purposes.
There should be no indiscriminate monitoring of employee communications.
Where appropriate, use of systems may be logged for security, operational or investigation purposes in accordance with applicable law and legitimate business requirements.
VI. Transmission of Personal Data
Transmission of personal data to recipients inside or outside Urhere must comply with the applicable requirements governing lawful processing. A recipient should use personal data only for lawful and defined purposes.
This applies to disclosures between Asanya participants, including Businesses and Partners.
Asanya should not disclose underlying customer, KYC, identity, financial or other confidential personal data to a Partner merely because the Partner has an interest in the progress of an attributed relationship where status-level information is sufficient.
Where personal data is transferred outside Nigeria, Urhere must comply with applicable legal requirements governing international transfers.
Appropriate safeguards should be applied where required.
VII. Contract Data Processing
Where Urhere appoints an external provider to process personal data on its behalf, an appropriate data-processing arrangement must be established where required.
The following requirements should be considered:
-
the provider should be selected having regard to its ability to implement appropriate technical and organisational safeguards;
-
processing instructions and responsibilities should be appropriately documented;
-
relevant contractual data-protection standards should be used;
-
appropriate due diligence should be undertaken before material processing begins;
-
compliance may be evidenced through audits, certifications, questionnaires or other reasonable assurance mechanisms; and
-
international or cross-border processing must comply with applicable transfer requirements.
The respective role of Urhere, a Business, Partner or other party may differ depending on the specific processing activity.
Urhere should therefore not automatically be characterised as a processor or controller for all Asanya processing without considering the particular activity.
VIII. Rights of the Data Subject
Subject to applicable law, data subjects may exercise applicable rights in relation to personal data concerning them.
These may include the right to:
-
request information concerning personal data held about them;
-
request access to applicable personal data;
-
ask how the information was obtained and the purposes for which it is processed;
-
request information regarding recipients or categories of recipients;
-
request correction of inaccurate or incomplete information;
-
withdraw consent where consent is the lawful basis;
-
object to certain processing;
-
request restriction of processing in applicable circumstances;
-
request deletion where there is no continuing lawful basis for processing;
-
object to direct marketing;
-
request applicable data portability; and
-
exercise other rights available under applicable data-protection law.
The exercise of a right should not result in unfair disadvantage to a data subject.
However, some information may need to be retained despite a request for deletion where retention is necessary for:
Requests should be handled promptly through the responsible unit and the Data Protection Officer.
IX. Confidentiality of Processing
Unauthorised collection, processing, disclosure or use of personal data by employees or other authorised personnel is prohibited.
The need-to-know and least-access principles should apply. Employees and authorised personnel may access personal information only to the extent reasonably required for their roles.
They must not:
-
use personal information for unauthorised private or commercial purposes;
-
disclose it to unauthorised persons;
-
permit unauthorised access; or
-
use it in a manner inconsistent with the relevant lawful purpose.
Appropriate confidentiality obligations should remain effective after employment or engagement ends.
X. Processing Security
Personal data must be protected against:
This applies to personal data processed electronically or in physical form.
Before introducing new material processing activities, systems or technology, appropriate technical and organisational safeguards should be considered and implemented.
The measures should have regard to:
-
the state of available technology;
-
implementation costs where appropriate;
-
the nature and scope of the processing;
-
the risks presented by the processing; and
-
the rights and interests of affected data subjects.
Privacy and data protection considerations should be incorporated into material Asanya product development and changes.
XI. Data Protection Control
Compliance with this Data Protection Policy and applicable data-protection laws should be reviewed periodically through appropriate:
-
audits;
-
assessments;
-
reviews;
-
monitoring;
-
compliance checks; and
-
other controls.
Responsibility for these controls may rest with the Data Protection Officer, relevant Urhere functions, external advisers or independent auditors where appropriate.
Material findings should be communicated to the relevant management or governing body.
Where required by law, relevant information should be provided to the Nigeria Data Protection Commission or another competent authority.
XII. Data Protection Incidents
Employees and authorised personnel must promptly notify the appropriate internal contact or the Data Protection Officer of any suspected or confirmed breach of this Policy or another data-protection requirement.
This includes circumstances involving:
-
improper transmission of personal data;
-
unauthorised third-party access;
-
accidental or unlawful disclosure;
-
loss of personal data;
-
unauthorised alteration;
-
security compromise; or
-
another suspected personal-data breach.
Applicable internal incident-management procedures should be activated promptly to enable appropriate containment, investigation, documentation, remediation and regulatory or data-subject notification where required.
Refer to the applicable Data Breach / Security Incident Management Procedure.
XIII. Responsibilities and Sanctions
Urhere Solutions Ltd is responsible for ensuring that appropriate organisational, human and technical measures are implemented for lawful processing of personal data.
Management is responsible for promoting compliance with this Policy within relevant areas of responsibility.
The Data Protection Officer should be informed in good time about significant new or materially changed processing activities where appropriate.
Relevant personnel should receive appropriate data-protection awareness or training.
Improper processing of personal data may result in:
-
disciplinary action;
-
contractual consequences;
-
regulatory action;
-
civil liability;
-
compensation claims;
-
criminal consequences where applicable; or
-
other sanctions available under applicable law.
XIV. Data Protection Officer
Urhere Solutions Ltd designates a Data Protection Officer or responsible privacy contact to support compliance with applicable data-protection requirements.
The Data Protection Officer should have appropriate independence in performing the privacy and compliance function and should promptly raise material data-protection risks with management.
Data subjects may contact the Data Protection Officer to:
-
raise concerns;
-
request information;
-
exercise applicable rights;
-
make privacy complaints; or
-
raise data-security concerns.
Where appropriate, concerns and complaints should be handled confidentially and promptly.
Regulatory or supervisory-authority enquiries relating to personal data should be promptly referred to the Data Protection Officer.
Data Protection Officer
Urhere Solutions Ltd
100A Apapa-Oshodi Expressway, Lagos, Nigeria
XV. Definitions
For purposes of this Policy:
| Term |
Definition |
| Anonymised Data |
Data processed in such a way that an individual is no longer reasonably identifiable. |
| Asanya |
The relationship-led growth infrastructure operated by Urhere Solutions Ltd. |
| Business |
An organisation, enterprise, professional practice or other entity using Asanya to manage Partners, attribution or related programme activity. |
| Consent |
A voluntary, informed and legally valid indication of agreement to processing where consent is relied upon as the lawful basis. |
| Data Controller |
A person or organisation that determines the purposes and means of processing personal data, as recognised under applicable law. |
| Data Protection Incident |
An event involving a suspected or confirmed unlawful or unauthorised collection, access, use, alteration, copying, disclosure, transmission, loss or other compromise of personal data. |
| Data Subject |
An identifiable natural person whose personal data is processed. |
| Partner |
An individual or organisation participating in Asanya as a Partner in connection with one or more Business relationships or through independent onboarding. |
| Personal Data |
Information relating to an identified or identifiable natural person. |
| Processing |
Any operation or set of operations performed on personal data, including collection, recording, organisation, storage, alteration, retrieval, consultation, use, disclosure, transmission, dissemination, restriction, deletion or destruction. |
| Sensitive Personal Data |
Personal data that is subject to enhanced protection under applicable data-protection law because of its nature or the risks associated with its processing. |
| Third Party |
A person or organisation other than the data subject, relevant controller, processor or person authorised to process the personal data. |
| Transmission |
The disclosure or transfer of personal data from one authorised person or system to another. |
| Qualifying Outcome |
The Business-defined event establishing that the relevant commercial value or programme result required under a Business programme has occurred. |
| Attribution |
The process through which a relevant customer, opportunity, activity, subject or commercial outcome is associated with a Partner. |
Questions about data protection?
Contact our Data Protection Officer for any inquiries, privacy concerns, or data rights requests.
Urhere Solutions Ltd
100A Apapa-Oshodi Expressway
Lagos, Nigeria