Privacy Policy

A single policy covering Client users and Artisan users of the DailyPay NG application

Effective date: 01.07.2026

Last updated: 08.08.2026

Data controller: Dekon Industries Limited, Uyo, Akwa Ibom, Nigeria

1. Who we are and how to read this policy

APPLIES TO: ALL USERS (CLIENTS AND ARTISANS)

This Privacy Policy is issued by Dekon Industries Limited, a company incorporated in Nigeria, with its registered office in Uyo, Akwa Ibom, Nigeria (“Dekon Industries,” “DailyPay NG,” “we,” “us,” or “our”). Dekon Industries Limited is the data controller responsible for the personal data described in this policy, in respect of the DailyPay NG mobile application and related services (the “Platform”).

The Platform connects two categories of user: Clients, who request and pay for services, and Artisans, who offer skilled trade services. This policy is written as a single document covering both, because a meaningful proportion of our processing — account security, payments, messaging, and general platform operation — is identical for both groups. Where an obligation, data category, or right applies to only one group, the relevant section is clearly marked with a coloured tag, as shown above. Sections without a tag, or marked “All users,” apply equally to both Clients and Artisans.

This policy should be read together with our Terms of Service. If there is a direct conflict between the two on a data protection matter, this Privacy Policy prevails.

2. The laws that apply to this policy

APPLIES TO: ALL USERS (CLIENTS AND ARTISANS)

Because Dekon Industries Limited is established in Nigeria, and the Platform is principally used by individuals located in Nigeria, two data protection regimes apply concurrently, and neither displaces the other:

The UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018, because Dekon Industries Limited is established in the UK and determines the purposes and means of processing.

The Nigeria Data Protection Act 2023 (“NDPA”), because the NDPA applies on an extraterritorial basis to the processing of personal data of data subjects located in Nigeria, regardless of where the controller is incorporated or where the processing technically occurs.

Where this policy describes a right, safeguard, or obligation that derives from one regime specifically, we say so. Where a protection is offered under both regimes, we describe the higher or more protective standard and apply it to all users, irrespective of which specific law would otherwise have applied to them.

3. Personal data we collect from all users

APPLIES TO: ALL USERS (CLIENTS AND ARTISANS)

The categories below are collected from every user of the Platform, whether registered as a Client or an Artisan.

3.1 Account and identity data

Full name, phone number, email address, and date of birth (collected to confirm you meet our minimum age requirement, described in Section 11).

State and Local Government Area (LGA) of residence in Nigeria, or equivalent locality information.

Account password, stored only as a salted cryptographic hash; we do not store or have access to your password in plain, readable form.

Biometric authentication tokens generated by your device if you enable Face ID, fingerprint, or device passkey sign-in. These tokens are created and held by your device’s own operating system and are not transmitted to or stored on our servers. This is distinct from the identity-verification biometric data described in Section 4, which applies to Artisans only.

3.2 Communications and content data

Messages exchanged with other users through in-app chat.

Job request content, including any text typed or audio recorded by a Client describing a job, and any quotes, notes, or attachments exchanged in connection with a job.

Photographs you choose to upload, including reference images and, for Artisans, portfolio images.

Ratings, written reviews, and feedback submitted about a completed job.

Records of correspondence with our customer support team.

3.3 Payment data

Payment references, transaction status, and transaction amount associated with deposits, balance payments, and payouts processed through our licensed payment processing partner, Paystack Payments Limited.

We do not directly collect, transmit, or store your full card number, card verification value (CVV), or banking personal identification number (PIN). These are entered directly into, and processed by, Paystack’s own systems, which operate under the Payment Card Industry Data Security Standard (PCI-DSS). We retain only the truncated card reference (such as the last four digits, where applicable) and the transaction outcome supplied to us by Paystack.

3.4 Device, location, and usage data

Device model, operating system and version, unique device identifiers, IP address, mobile network information, and application version.

With your permission, precise or approximate location data, used as described in Sections 3.5 (Clients) and 5 (Artisans).

Usage data, including screens viewed, features used, search queries, session duration, and crash or performance diagnostics.

3.5 Location data — client-specific use

APPLIES TO: CLIENTS ONLY

As a Client, we collect your precise device location, with your permission, at two points: when you post a job request, to identify nearby Artisans for matching purposes, and during active job tracking, to display an Artisan’s live position and estimated arrival time to you. You may decline location permissions; doing so will materially limit your ability to use the job-matching feature, since geographic proximity is a required input to the matching process.

4. Identity verification and biometric data (Artisans only)

APPLIES TO: ARTISANS ONLY

This section applies only to users registered as Artisans. It does not apply to Clients, and Clients are not asked to provide any of the data described in this section.

Registering as an Artisan requires you to complete identity verification. It is a condition of holding an Artisan account, not an optional step, and an Artisan account is not created without it. We require it to protect Clients, who admit Artisans into their homes and businesses, and to meet our own obligations to prevent fraud and impersonation. The data collected is classified as sensitive personal data under both the NDPA and the UK GDPR, and is treated with corresponding additional safeguards.

4.1 What we collect

One government-issued identity document of your choosing, from those we accept at the time you register. These currently comprise the National Identification Number (NIN) slip, an International Passport, a Driver’s Licence, or a Voter’s Card (PVC). Certain crafts may be restricted to a narrower set of documents, in which case the app will show you only the documents you may use.

A photograph of that document, captured live through your device camera. For a Driver’s Licence, both sides are photographed. You cannot upload an existing image from your photo library; the capture must be taken at the time.

The document number, which you type yourself.

The expiry date, where the document you have chosen carries one.

A live selfie photograph, captured during registration.

The verification outcome and the review status of your document (for example: pending, approved, or rejected).

4.2 Reading text from your document, including your address

We may run automated text recognition over the photograph of your document in order to read the printed text from it. Where the document carries a residential address — as a NIN slip and a Driver’s Licence ordinarily do — that address is extracted and stored, and is made available to our verification reviewers, without being displayed to you or separately requested from you during registration. We draw this to your attention specifically because it is not obvious from the act of photographing a card. Where the document carries no address, as with an International Passport, none is extracted, and this is a normal outcome rather than a failure.

We also retain the raw text read from the document, so that a reviewer can check the number you typed against what is actually printed on the card rather than taking it on trust.

We use this address to confirm that you are where you say you are, to assess service coverage, and to assist in tracing an Artisan in the event of a serious dispute, a safety incident, or a lawful request from an authority. Your address is never shown to Clients.

The text recognition runs on our own servers by default, and in that configuration your document image is not sent to any third party. We may alternatively enable Google Cloud Vision, operated by Google LLC, to perform the same text extraction more accurately; where that setting is enabled, the document image is transmitted to Google acting as our processor. Section 9 describes the transfer safeguards that apply.

4.3 Comparing your face against your document

We compare the photograph printed on your identity document against the live selfie you provide, to check that the document belongs to the person presenting it. This comparison is performed entirely on our own servers. Your face is not sent to any third-party facial recognition service, and we do not use any such service.

The comparison produces a numerical similarity score between 0 and 100. We store only that score. We do not store, and do not create any durable record of, the underlying facial template or biometric vector — it exists only in memory for the moment the comparison takes place and is discarded immediately afterwards. This matters because a facial template is biometric data with a long life and real legal weight, whereas a similarity score tells a reviewer what they need to know and is of little value to anyone who should not have it.

We are candid about the limits of this comparison. It compares a live photograph against a photograph of a printed photograph, which may be laminated, worn, poorly lit, or many years old. It is unreliable in those conditions, and facial recognition is documented to perform less accurately on darker-skinned subjects. We have designed the process around that fact rather than in spite of it: an uncertain result is always referred to a human reviewer, never treated as an accusation.

4.4 Automated decision-making, and your right to a human decision

You should know exactly how much a machine decides here.

A sufficiently high similarity score may cause your document to be approved without a person examining it. Every other outcome is referred to a member of our team, who examines the document and the selfie and decides.

A score low enough to indicate no meaningful resemblance at all may cause your submission to be refused automatically. This threshold is deliberately set far below the level at which the system is merely uncertain, so that an old or degraded photograph of the correct person is referred for human review rather than refused. A refusal is never issued where the system failed to locate a face, where the comparison could not be performed, or where the detection was weak.

Where this constitutes a decision based solely on automated processing producing legal or similarly significant effects, you have the right to obtain human intervention, to express your point of view, and to contest the decision, under Article 22 of the UK GDPR and the corresponding provisions of the NDPA. In practice: every automated refusal is recorded and visible to our team, may be overturned by them, and you may request that a person review it by writing to support@dailypayng.com. You may also simply submit the document again. We do not treat an automated refusal as a finding of dishonesty.

4.5 Limits on disclosure

Your document number, your document images, your selfie, your extracted address, and your similarity score are never disclosed to Clients or to other Artisans, under any circumstances. Within our organisation they are accessible only to staff performing identity review, and each review action is recorded against the individual member of staff who took it.

5. Continuous location tracking (Artisans only)

APPLIES TO: ARTISANS ONLY

Artisans are subject to more frequent and continuous location collection than Clients, because live location is the mechanism by which the Platform matches Artisans to nearby job requests and informs Clients of an Artisan’s progress toward a job site. Specifically:

While you have toggled yourself “available” within the job pool, we periodically collect your device’s GPS coordinates so that open job requests can be ranked by proximity to you.

While you are en route to, or actively working on, an assigned job, we collect more frequent location updates, at approximately [10–30]-second intervals, so that the Client engaging you can view your live position and an estimated time of arrival.

Location collection stops, other than retention of your last known general area for matching freshness, once you toggle yourself unavailable or are not engaged in an active job.

You may decline location permissions; doing so will prevent you from being matched to job requests, since proximity is a required input to the matching algorithm, but will not otherwise affect your ability to maintain a profile or view past job history.

6. Wallet, earnings, and payout data (Artisans only)

APPLIES TO: ARTISANS ONLY

Bank account number, account name, and bank code, provided when you request a withdrawal of your earnings.

Wallet balance, earnings history, and a record of completed jobs and associated payment amounts.

Withdrawal requests and their processing status, transmitted to and fulfilled through Paystack’s transfer infrastructure.

We do not collect or store your online banking login credentials or banking PIN. Payout transfers are initiated through Paystack under its own applicable regulatory licences and arrangements with Nigerian deposit money banks.

7. Why we process your data, and our legal basis

APPLIES TO: ALL USERS (CLIENTS AND ARTISANS)

Under both the UK GDPR and the NDPA, we are required to identify a specific lawful basis for each purpose of processing. The table below sets these out. Several entries marked “Artisans only” reflect the additional processing described in Sections 4–6.

Purpose

Examples

Legal basis (UK GDPR / NDPA)

Account creation and authentication

Verifying identity at signup; enabling device biometric sign-in

Performance of a contract; consent (for device biometric login)

Identity verification (Artisans only)

Capturing a government-issued identity document and recording its number and expiry

Explicit consent (sensitive personal data); legal obligation related to fraud and financial-crime prevention; legitimate interest in platform trust and safety

Face comparison (Artisans only)

Comparing the photograph on the identity document against the live selfie, on our own servers, and storing only the resulting similarity score

Explicit consent (biometric data processed for the purpose of uniquely identifying a person); legitimate interest in preventing impersonation. Consent is obtained at the point of capture, and this processing is a condition of holding an Artisan account.

Address extraction (Artisans only)

Reading the residential address printed on an identity document, where the document carries one, and making it available to our reviewers

Legitimate interest in verifying an Artisan’s stated locality, in tracing an Artisan in the event of a safety incident or serious dispute, and in assessing service coverage; legal obligation where an authority lawfully requires it

Automated approval and refusal (Artisans only)

Approving a document without human review where the similarity score is high, and refusing one where the score shows no meaningful resemblance

Necessary for entering into a contract, and carried out with explicit consent, as permitted by Article 22(2) UK GDPR; subject at all times to the right to human intervention described in Section 4.4

Job matching

Ranking Artisans by category fit, rating, and proximity to a Client’s job request

Performance of a contract

Live job tracking

Showing a Client an Artisan’s live location and ETA during an active job

Performance of a contract; consent

Payments, escrow, and payouts

Processing deposits, holding funds in escrow, releasing payment, processing Artisan withdrawals

Performance of a contract; compliance with legal obligations (including financial record-keeping)

Trust, safety, and fraud prevention

Investigating disputes, detecting fraudulent accounts or job claims, calculating Trust Scores

Legitimate interest; legal obligation

Customer support

Responding to enquiries and complaints

Performance of a contract; legitimate interest

Service improvement

Analysing usage patterns, fixing defects, improving matching accuracy

Legitimate interest

Legal and regulatory compliance

Responding to lawful requests from courts or regulators; tax and AML record-keeping

Legal obligation

Marketing communications

Sending product updates or promotional offers

Consent (opt-in; withdrawable at any time, see Section 12)

Where we rely on legitimate interest, we have considered, and are prepared to demonstrate on request, that the relevant processing is necessary for that interest and that it is not overridden by your interests or fundamental rights and freedoms. Where we rely on consent for sensitive personal data, that consent is sought explicitly and separately from general acceptance of our Terms of Service, and may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.

8. How we share personal data

APPLIES TO: ALL USERS (CLIENTS AND ARTISANS)

We do not sell personal data, to anyone, for any purpose. We disclose personal data only in the following circumstances, and, where a recipient acts as our processor, only under a written data processing agreement consistent with the requirements of the UK GDPR and the NDPA:

Between Clients and Artisans: when a Client selects a specific Artisan for a job, that Artisan receives the Client’s first name, job request details, and general address; the Client receives the Artisan’s profile information, ratings, and reviews, and, once a job is mutually accepted, the Artisan’s live location for tracking purposes. Full phone numbers are shared between the two parties only once a job is mutually accepted.

Identity verification (Artisans only): identity documents are not shared with any third-party verification bureau, and the comparison of your face against your document is performed on our own servers. The single exception is that, where we have enabled the optional Google Cloud Vision text-recognition setting described in Section 4.2, the document image is transmitted to Google LLC acting as our processor for the sole purpose of reading the printed text from it.

With Paystack Payments Limited: payment and payout data are shared to process transactions described in Sections 3.3 and 6.

With cloud hosting, database, and infrastructure providers, who store and process personal data on our behalf, as described in Section 9.

With professional advisers, including lawyers, auditors, and insurers, under confidentiality obligations, where reasonably necessary to obtain advice or services.

With regulators, courts, or law enforcement authorities, in the United Kingdom, Nigeria, or elsewhere, where required by valid legal process, or to protect the rights, property, or safety of Dekon Industries Limited, our users, or the public.

In connection with a corporate transaction, such as a merger, acquisition, financing, or sale of assets involving Dekon Industries Limited, personal data may be transferred as part of that transaction, subject to confidentiality commitments and, where required by law, prior notice to affected users.

9. International data transfers

APPLIES TO: ALL USERS (CLIENTS AND ARTISANS)

Personal data collected through the Platform is collected from users principally located in Nigeria, by a controller established in the United Kingdom, and is stored using internationally hosted cloud infrastructure. As a result, your personal data will, in the ordinary course, be transferred across at least the following paths, each of which is governed by a different transfer regime:

From Nigeria to the United Kingdom or to third countries where our infrastructure providers operate: this transfer is a transfer of personal data of Nigerian data subjects out of Nigeria, and is governed by the NDPA’s cross-border transfer provisions, which generally require that the receiving country or organisation offer an adequate level of protection, or that an alternative safeguard recognised by the NDPA apply.

Receipt and onward processing within the United Kingdom or in third countries by our sub-processors: this is governed by the UK GDPR’s own restricted-transfer regime, which generally requires an adequacy regulation, appropriate safeguards such as the UK’s International Data Transfer Agreement (IDTA) or the EU Standard Contractual Clauses as modified by the UK Addendum, or an applicable derogation.

We seek to ensure that, irrespective of which specific regime applies to a given transfer, an adequate and broadly equivalent level of protection is maintained throughout, by relying on one or more of the following:

Adequacy assessments recognised by the relevant authority (the NDPC or the UK authorities, as applicable) in respect of the receiving country;

Standard contractual clauses, the UK International Data Transfer Agreement, or substantively equivalent contractual safeguards with our processors and sub-processors; or

Your explicit, informed consent to a specific transfer, where no other safeguard is available and consent is the appropriate basis.

10. Data retention

APPLIES TO: ALL USERS (CLIENTS AND ARTISANS)

We retain personal data only for as long as reasonably necessary for the purposes described in this policy, including to satisfy legal, accounting, tax, and regulatory record-keeping obligations in both the United Kingdom and Nigeria. As a general guide, and subject to confirmation by legal counsel against current statutory requirements in both jurisdictions:

Account and profile data: retained for the duration of your account, and for [SUGGEST: 24 months] following account closure, to address residual disputes or legal claims.

Identity verification records (Artisans only): retained for [SUGGEST: 5 years] following account closure, consistent with typical know-your-customer and anti-money-laundering record-keeping expectations, subject to confirmation against any sector-specific requirement applicable to this Platform.

Face-comparison data (Artisans only): the facial template used to compare your document photograph with your selfie is never written to storage at all. It exists only in memory for the moment the comparison runs and is discarded immediately afterwards. We retain only the resulting similarity score, the outcome, and the date of the comparison, for the identity-verification retention period described above.

Identity document images and extracted address (Artisans only): retained for the identity-verification period described above. A replacement submission overwrites the previous one, so we hold your most recent document rather than a history of attempts.

Transaction and payment records: retained for a minimum of [SUGGEST: 6 years], reflecting standard financial record-keeping practice; to be confirmed against specific UK and Nigerian statutory minimums applicable to this business.

Job request content and in-app messages: retained for [SUGGEST: 24 months] following job completion, or longer where the subject of an active dispute or legal claim.

Location history (Artisans only): granular location pings collected during active job tracking are retained for [SUGGEST: 90 days] following job completion, principally to resolve disputes about timing or service area, then securely deleted or anonymised.

On expiry of the applicable retention period, we securely delete or irreversibly anonymise the relevant personal data, except to the extent continued retention is required by law or is necessary to establish, exercise, or defend legal claims.

11. How we protect your data

APPLIES TO: ALL USERS (CLIENTS AND ARTISANS)

We apply technical and organisational measures designed to protect personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage, including:

Encryption of data in transit using TLS, and encryption of sensitive data at rest.

Password storage using industry-standard salted hashing (bcrypt); we do not store passwords in plain, readable text.

Role-based access controls limiting employee and contractor access to personal data on a need-to-know basis, with additional restrictions on access to identity verification and biometric records described in Section 4.

Network-level protections, including rate limiting, intended to detect and resist automated abuse.

Periodic review of our security practices as the Platform and its user base grow.

No system of transmission or storage can be guaranteed to be 100% secure. If we become aware of a personal data breach that is likely to result in a risk to the rights and freedoms of affected individuals, we will, as applicable and within the timescales required by law, notify the UK Information Commissioner’s Office, the Nigeria Data Protection Commission, and affected users.

12. Your rights

APPLIES TO: ALL USERS (CLIENTS AND ARTISANS)

Whether the UK GDPR, the NDPA, or both apply to a specific instance of processing concerning you, we extend the following set of rights to all users of the Platform, applying whichever version of a right is more protective where the two regimes differ in detail:

Right of access: to obtain confirmation of whether we process your personal data, and a copy of that data.

Right to rectification: to have inaccurate or incomplete personal data corrected.

Right to erasure: to request deletion of your personal data, subject to the retention obligations described in Section 10 and any other applicable legal exception.

Right to restriction of processing: to request that we limit how we use your data in specified circumstances, for example while a dispute about its accuracy is resolved.

Right to data portability: to receive certain personal data you have provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible.

Right to object: to object to processing based on legitimate interest, including direct marketing, at any time.

Rights related to automated decision-making: our job-matching algorithm produces a ranked recommendation, but a Client always makes the final decision to select an Artisan, and no purely automated decision with legal or similarly significant effect is made about you without the opportunity for human review.

Right to withdraw consent: where processing is based on consent, including biometric verification consent and marketing consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

Right to lodge a complaint: with a supervisory authority. Because two regimes apply, you may lodge a complaint with either or both of: the UK Information Commissioner’s Office (ico.org.uk), and the Nigeria Data Protection Commission (ndpc.gov.ng).

To exercise any of these rights, contact us using the details in Section 14. We will respond within the timeframe required by applicable law (generally one month under the UK GDPR, subject to extension in complex cases), and may need to verify your identity before fulfilling certain requests.

13. Other important information

APPLIES TO: ALL USERS (CLIENTS AND ARTISANS)

13.1 Minimum age

The Platform is intended for use by individuals who are at least 18 years old. We do not knowingly collect personal data from individuals under 18. If we become aware that we have inadvertently collected personal data from a person under 18, we will take prompt steps to delete that data, save to the extent we are legally required to retain it.

13.2 Cookies and similar technologies

If the Platform is accessed through a website or web-based portal, we may use cookies and similar tracking technologies to recognise your device, remember preferences, and analyse usage. Cookie preferences can generally be controlled through browser settings. A full cookie schedule will be published prior to any web-based launch of the Platform.

13.3 Marketing communications

With your consent, we may send promotional messages about new features, offers, or recommendations by push notification, SMS, or email. You may withdraw this consent at any time by adjusting in-app notification settings, replying STOP to SMS messages, or using the unsubscribe link in marketing emails. Opting out of marketing communications does not affect transactional messages necessary for the operation of your account or an active job.

13.4 Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, the law, or other relevant factors. We will notify you of material changes through the app or by email, and will update the “Last updated” date at the top of this policy. Continued use of the Platform after such changes take effect constitutes your acceptance of the revised policy.

14. Contact us

APPLIES TO: ALL USERS (CLIENTS AND ARTISANS)

Questions, concerns, or requests regarding this Privacy Policy, or the exercise of any right described in Section 12, may be directed to:

Data Protection Contact: Emma Assam

Email: operations.control@chrismgroup.com

Postal address: Dekon Industries Limited, 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

You may also lodge a complaint directly with either supervisory authority:

UK Information Commissioner’s Office — ico.org.uk

Nigeria Data Protection Commission — ndpc.gov.ng

END OF DRAFT. This policy requires sign-off from a lawyer qualified in the United Kingdom and, given the NDPA’s extraterritorial application and the Nigerian user base, from Nigerian counsel as well, before publication. Particular attention should be given to the callouts in Sections 2, 4, and 9, and to confirming all bracketed retention periods in Section 10 against current statutory minimums in both jurisdictions.