Privacy Policy
Last updated: July 17, 2026
This Privacy Policy explains how HANDI Limited ("HANDI", "we", "our", "us") — registered in Nigeria under the Companies and Allied Matters Act 2020 (RC 9684059) — collects, uses, shares, stores, and protects your personal data when you access or use our platform at handiapp.com.ng and related mobile applications. We are committed to handling your personal data lawfully, fairly, and transparently in accordance with the Nigeria Data Protection Act 2023 (NDPA) and the General Application and Implementation Directive (GAID) 2025. Please read this policy carefully before using our services.
1. Who We Are and How to Contact Us
HANDI Limited is the data controller responsible for your personal data processed through this platform.
- Company Registration No. (RC): 9684059
- General enquiries: legal@handiapp.com.ng
- Data Protection Officer (DPO) contact: privacy@handiapp.com.ng
- Platform: handiapp.com.ng
You may contact our Data Protection Officer directly at privacy@handiapp.com.ng for any question about how we use your personal data, to exercise your rights under the NDPA 2023, or to lodge a concern. We aim to respond within 30 days.
2. Personal Data We Collect
2.1 Data you provide directly
- Identity data: full name, email address, phone number, profile photograph
- Account credentials: password (stored in hashed, encrypted form only — we never store plaintext passwords)
- Service provider profile data: business name, service descriptions, professional licences and certifications, portfolio photographs
- Payment and billing information: bank account details or card information — processed and stored by our licensed payment service provider, not directly by HANDI
- Background-check data: for service providers, data collected to verify identity, professional credentials, references, and (for certain service categories) police character certificates, as part of our tiered verification process
- Location data: your address or service delivery location as provided when making or receiving a booking. Service provider registration and service bookings are currently only available within our published service area (Rivers State as at the date of this policy); we use this data in part to confirm eligibility. Product purchases from vendors are unaffected by this restriction.
- Communications: messages exchanged with service providers or our support team through the in-app messaging feature
- Reviews and ratings: feedback you submit after a completed service
- Support correspondence: emails, chat messages, or in-app reports submitted to HANDI customer support
2.2 Data we collect automatically when you use our platform
- Device and technical data: IP address, browser type and version, operating system, device type, device identifiers
- Usage data: pages and features accessed, search queries, booking history, session duration, clicks and navigation paths
- Transaction data: booking amounts, payment status, dispute history
- Cookie and tracking data: as described in Section 9
2.3 Data we receive from third parties
- Identity verification data: from government identity databases (e.g. NIMC) where we verify a service provider's identity
- Professional credential data: from professional bodies (e.g. COREN, CORBON, NIA) where we verify licences
- Background-check data: from police character certificate providers and references you supply, where applicable to your service category under our tiered verification process
- Payment confirmation data: from our licensed payment service provider confirming transaction outcomes
3. How and Why We Use Your Personal Data
We only process your personal data where we have a lawful basis to do so under the NDPA 2023, including:
- Creating and managing your account — performance of contract (s.25(1)(b))
- Processing bookings and connecting you with service providers — performance of contract (s.25(1)(b))
- Processing and facilitating payments — performance of contract and legal obligation (s.25(1)(b) & (c))
- Verifying service provider identity and credentials — legitimate interests in platform safety and consumer trust (s.25(1)(e))
- Detecting, investigating and preventing fraud and abuse — legitimate interests in fraud prevention and platform security (s.25(1)(e))
- Sending transactional communications (booking confirmations, receipts, OTPs) — performance of contract (s.25(1)(b))
- Sending promotional communications, offers and newsletters — your consent (s.25(1)(a)), which you may withdraw at any time
- Monitoring platform usage and improving our services — legitimate interests in service improvement (s.25(1)(e))
- Responding to your support requests and complaints — performance of contract and legitimate interests (s.25(1)(b) & (e))
- Complying with legal and regulatory obligations (tax, AML, court orders, regulator requests) — legal obligation (s.25(1)(c))
- Enforcing our Terms of Service and protecting HANDI's legal rights — legitimate interests in legal defence (s.25(1)(e))
Where we rely on legitimate interests as our lawful basis, we have assessed that our interests are not outweighed by your rights and freedoms. You may request details of this assessment from our DPO.
4. How We Share Your Personal Data
We do not sell your personal data to any third party. We share your data only in the following circumstances:
4.1 Service providers (to fulfil your bookings)
We share your name, contact information, and booking details with the specific service provider you select, strictly to the extent necessary to complete the booked service.
4.2 Payment service provider
We share necessary payment information with Paystack, a payment service provider licensed by the Central Bank of Nigeria (CBN). This provider processes your payment data under its own privacy policy and CBN regulatory obligations. HANDI does not store your full card number or bank account details on our servers. For online bookings, HANDI holds payment data associated with your transaction in escrow until the service is confirmed complete or the dispute window has elapsed. Where a service provider accepts cash payment for a booking, only the transaction record and associated platform commission are processed by HANDI — the cash payment itself is exchanged directly between customer and provider and is not processed by HANDI or Paystack.
4.3 SMS, OTP and notification providers
We use Termii and Brevo to deliver booking confirmations, OTP codes, and service alerts to your phone number and email address. These providers process your contact details only for this delivery purpose.
4.4 Cloud hosting provider
Our platform is hosted on Vercel's cloud infrastructure. Where those servers are located outside Nigeria, we have put in place appropriate transfer safeguards as described in Section 5.
4.5 Analytics and monitoring providers
We use Vercel Analytics to understand, in aggregate, how users interact with our platform, and Sentry to monitor errors and application performance so we can diagnose and fix technical faults. We configure these tools to pseudonymise or aggregate data where possible. You can opt out of non-essential analytics tracking through our cookie settings (Section 9).
4.6 Professional verification bodies
Where verifying a service provider's professional credentials, we may share the provider's name and licence number with relevant Nigerian professional bodies (e.g. COREN, CORBON, NIA) to confirm registration status.
4.7 Legal and regulatory disclosures
We may disclose personal data to:
- Nigerian courts, law enforcement agencies, or regulatory authorities (including the NDPC, FCCPC, or CBN) where required by law, court order, or valid regulatory directive;
- Our professional advisers (lawyers, auditors, insurers) bound by professional confidentiality obligations; and
- A buyer or successor entity in connection with a merger, acquisition, or sale of all or substantially all of HANDI's assets, provided the recipient agrees to protect your data consistently with this policy.
4.8 With your explicit consent
We may share your data with other parties where we have first obtained your express, specific, and informed consent.
5. International Transfers of Personal Data
Some of our third-party service providers — including our cloud hosting provider, payment processor, SMS provider, and analytics tools — are based outside Nigeria or operate servers outside Nigeria. Any transfer of your personal data outside Nigeria is subject to the requirements of the NDPA 2023 and GAID 2025.
We ensure that transfers are protected by at least one of the following safeguards:
- Standard contractual clauses (SCCs) approved or recognised by the NDPC, incorporated into our contracts with those third-party providers;
- A determination by the NDPC that the destination country provides an adequate level of protection; or
- Your explicit consent, where required and where no other safeguard is available.
A list of the countries to which we transfer personal data and the specific safeguard in place for each transfer is available on request from our DPO at privacy@handiapp.com.ng.
6. How Long We Keep Your Personal Data
We keep personal data only for as long as necessary for the purpose for which it was collected, or as required by Nigerian law. The retention periods below apply:
- Account data (active accounts): duration of your account, plus 2 years after account closure
- Booking and transaction records: 6 years from transaction date (FIRS / CAMA financial record requirements)
- Payment data: minimum 5 years as required by CBN regulations
- In-app messages and communications: 2 years from the date of communication
- Reviews and ratings: duration of the platform, or until you request deletion
- Fraud investigation records: duration of investigation plus 2 years thereafter
- Marketing consent records: until consent is withdrawn, plus 2 years
- Technical and usage logs: 12 months on a rolling basis
- Support correspondence: 3 years from date of resolution
- Data subject rights requests and responses: 5 years from date of response
Where retention beyond these periods is required by law (for example, by a court order or regulatory instruction), we will retain only the data required and for the period specified. After the applicable retention period, data is securely deleted or irreversibly anonymised.
7. Your Rights Under the NDPA 2023
The NDPA 2023 gives you the following rights over your personal data. These rights are not absolute and are subject to exceptions under the Act, but we will always respond to your request and explain our reasoning if we are unable to fulfil it.
- Right of access — Request a copy of the personal data we hold about you, and information about how we use it.
- Right to rectification — Ask us to correct personal data that is inaccurate or incomplete.
- Right to erasure — Ask us to delete your personal data where it is no longer needed for its original purpose, you withdraw consent and no other lawful basis applies, you have objected and we have no overriding legitimate grounds, or the data was unlawfully processed.
- Right to data portability — Receive your personal data in a structured, commonly used, machine-readable format (e.g. JSON or CSV) and transfer it to another service provider.
- Right to restriction — Ask us to pause processing of your personal data, for example while we verify the accuracy of data you have disputed.
- Right to object — Object to processing based on legitimate interests. We must stop unless we demonstrate compelling legitimate grounds that override your interests.
- Right to withdraw consent — Where processing relies on your consent, withdraw it at any time without affecting the lawfulness of prior processing.
- Right regarding automated decisions — Not be subject to a decision with significant legal or similar effects that is based solely on automated processing, without the opportunity for human review.
To exercise any right, email our DPO at privacy@handiapp.com.ng stating your full name, account email address, and the right you wish to exercise. We will respond within 30 calendar days. We will not charge a fee for reasonable requests.
If you are not satisfied with how we handle your personal data or your rights request, you have the right to file a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng. You may do this at any time.
8. Data Security
We implement appropriate technical and organisational security measures proportionate to the risks involved in our processing. These include:
- Encryption of all data in transit using TLS/SSL protocols
- Encryption of sensitive data at rest (including payment tokens and identity documents)
- Role-based access controls limiting staff access to personal data on a strict need-to-know basis
- Multi-factor authentication for staff access to production systems
- Regular vulnerability assessments and penetration testing of our platform
- Secure server environments managed by our cloud hosting provider under a shared responsibility model
- Internal data protection training for staff who handle personal data
- A documented incident response procedure
8.1 Data breach notification
In the event of a personal data breach that is likely to pose a risk to the rights and freedoms of affected individuals, we will:
- Notify the NDPC within 72 hours of becoming aware of the breach, as required by the NDPA 2023 and GAID 2025;
- Notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms; and
- Maintain a record of all breaches, including those that do not require notification, in our internal breach register.
No security system is impenetrable. If you believe your account has been compromised, contact us immediately at privacy@handiapp.com.ng.
9. Cookies and Tracking Technologies
9.1 What we use and why
We use cookies and similar tracking technologies (pixels, local storage) to operate and improve our platform:
- Strictly necessary (no consent required) — Session authentication, security tokens, load balancing, fraud detection. Without these the platform cannot function.
- Functional (consent required) — Remembering your language preference, display settings, and saved searches.
- Analytics (consent required) — Understanding how users navigate the platform, measuring feature usage, identifying error pages. Providers: Vercel Analytics, Sentry.
- Marketing (consent required) — Delivering relevant promotions and advertisements, measuring campaign effectiveness.
9.2 Your cookie choices
When you first visit our platform, a cookie consent banner will appear. You may: (a) accept all cookies; (b) accept strictly necessary cookies only; or (c) customise your preferences by category. You may change your preferences at any time through the Cookie Settings link in the website footer or app settings menu.
Withdrawing consent for non-essential cookies will not affect the core functionality of the platform (booking, payment, messaging). If you clear your browser cookies, you will be asked for your preferences again on your next visit.
10. Children's Privacy
Our platform is intended for adults aged 18 and over. We do not knowingly collect personal data from anyone under the age of 18. If you are under 18, you must not create an account, submit a booking, or otherwise provide personal data through our platform.
If a parent or guardian believes their child under 18 has provided personal data to HANDI, please contact our DPO at privacy@handiapp.com.ng immediately. We will verify the report and, where confirmed, delete the relevant data promptly.
Where a parent or guardian wishes to register a minor for a permissible service offered through a verified service provider, they must contact us directly. We will only proceed where valid, verifiable parental consent is obtained in writing.
11. Third-Party Links and Services
Our platform may contain links to third-party websites, payment interfaces, or services that operate independently of HANDI. We are not responsible for the privacy practices or content of those third-party services. We recommend you read the privacy notice of any third-party service before providing your personal data to them.
12. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our services, legal obligations, or data processing practices. Where we make a material change — meaning a change that affects your rights or our obligations in a meaningful way — we will:
- Send a notification to the email address registered on your HANDI account at least 14 days before the change takes effect; and
- Post a prominent notice on the HANDI platform and app.
The updated policy will display a revised "Last updated" date at the top of this page. Your continued use of HANDI after the effective date of any material change constitutes acceptance of the revised policy. If you do not agree to the revised policy, you should close your account before the effective date.
13. Governing Law and Regulator
This Privacy Policy is governed by and construed in accordance with the laws of the Federal Republic of Nigeria, including the Nigeria Data Protection Act 2023, the General Application and Implementation Directive 2025, and all other applicable Nigerian data protection legislation.
The Nigeria Data Protection Commission (NDPC) is the supervisory authority for data protection in Nigeria. You may contact the NDPC at ndpc.gov.ng, or file a complaint through the Data Subject Rights tab on that site.
14. Contact Us
If you have questions about this Privacy Policy, please contact us at privacy@handiapp.com.ng.