shield Legal

Privacy Policy

calendar_today Last updated: June 28, 2025
corporate_fare ITIODE Conglomerate Ltd.
verified_user NDPR Compliant
Your privacy matters to us. This policy explains what personal information ITIODE collects, why we collect it, how we use and protect it, and the rights you have over your data. We comply with Nigeria's Nigeria Data Protection Regulation (NDPR) and applicable international data protection standards.

Contents

1

Overview

ITIODE Conglomerate Ltd. ("ITIODE", "we", "us") is committed to protecting your personal information. This Privacy Policy describes how we collect, use, store, and disclose data when you interact with our services — Offkrent, Hive Academy, and Dellla Logistics — and our websites and mobile applications.

This Policy applies to all users worldwide. For users in Nigeria, it is also our NDPR Privacy Notice. For users in the European Economic Area, it constitutes our GDPR-compliant privacy notice where applicable.

If you have questions about this policy or wish to exercise your data rights, contact our Data Protection Officer at dpo@itiode.com.
2

Information We Collect

2.1 Information You Provide

  • Account data: Name, email address, phone number, date of birth, and password when you register.
  • Identity verification: Government-issued ID, NIN, or BVN where required for Offkrent tenancy or financial services.
  • Payment data: Card details (tokenised — we never store raw card numbers), bank account numbers for withdrawals.
  • Housing data (Offkrent): Emergency contacts, next-of-kin, occupancy preferences, and maintenance requests.
  • Educational data (Hive Academy): Course progress, quiz responses, assignment submissions, and certificates earned.
  • Logistics data (Dellla): Delivery addresses, package descriptions, and recipient contact details.
  • Communications: Messages you send to our support team, feedback, and survey responses.

2.2 Information We Collect Automatically

  • Device & usage data: IP address, browser type, operating system, device identifiers, pages visited, and actions taken.
  • Location data: Approximate location derived from IP; precise GPS location for Dellla delivery tracking (with your consent).
  • Cookies & similar technologies: See Section 5 for full details.

2.3 Information from Third Parties

  • Social login providers (Google, Apple) when you choose to sign in via those services.
  • Payment processors (Paystack, Flutterwave) for transaction status and fraud signals.
  • Referral data from other ITIODE users who referred you.
3

How We Use Your Information

PurposeLegal Basis (NDPR / GDPR)
Create and manage your ITIODE accountContractual necessity
Process payments and prevent fraudContractual necessity / Legitimate interests
Provide, maintain, and improve our ServicesContractual necessity
Send transactional emails and SMS notificationsContractual necessity
Send marketing communicationsConsent (you may withdraw at any time)
Personalise your experience and recommendationsLegitimate interests
Comply with legal obligationsLegal obligation
Safety, security, and fraud detectionLegitimate interests / Legal obligation
Analytics to understand platform usageLegitimate interests
Run our referral and rewards programmeContractual necessity / Consent

We will never sell your personal data to third parties for their own marketing purposes.

4

Sharing Your Information

We may share your personal data with:

  • Service providers: Payment processors, cloud infrastructure (AWS, Google Cloud), SMS/email delivery providers, and analytics tools — all bound by data processing agreements.
  • Dellla delivery partners: Riders and logistics partners receive only the information necessary to complete a delivery (recipient name, address, phone).
  • Hive Academy instructors: Tutors can view your enrolled course progress to facilitate mentorship. They may not download or export your data.
  • Offkrent property managers: Limited to your name, emergency contact, and tenancy status for on-site management purposes.
  • Law enforcement: We may disclose information when required by law, court order, or to protect the safety of our users or the public.
  • Business transfers: If ITIODE is involved in a merger, acquisition, or asset sale, your data may be transferred. We will notify you before this occurs.
All third-party service providers are contractually required to process your data only on our instructions and to maintain appropriate technical and organisational security measures.
5

Cookies & Tracking

We use cookies and similar technologies (local storage, pixels) to operate and improve our Services. Here is a summary of what we use:

TypePurposeCan opt out?
EssentialSession management, authentication, securityNo — required for the platform to function
FunctionalRemember your preferences (language, theme)Yes, via cookie settings
AnalyticsUnderstand how users interact with the platform (Google Analytics)Yes, via cookie settings
MarketingServe relevant advertisements on third-party platformsYes, via cookie settings or ad opt-out tools

You can manage your cookie preferences at any time via the cookie banner on our website or through your browser settings. Note that disabling essential cookies will prevent you from using key platform features.

6

Data Retention

We retain your personal data for as long as necessary to fulfil the purposes outlined in this Policy, unless a longer retention period is required by law.

  • Active accounts: Data retained for the lifetime of your account plus 12 months following closure to resolve disputes.
  • Financial records: Retained for 7 years in compliance with Nigerian tax and financial regulations.
  • Hive Academy certificates: Permanently retained on our records so graduates can verify credentials at any time.
  • Marketing data: Deleted within 30 days of consent withdrawal or account closure.
  • Delivery data (Dellla): Retained for 2 years for dispute resolution and customer service purposes.

When data is no longer needed, we delete it securely or anonymise it so it can no longer be linked to you.

7

Data Security

We implement industry-standard technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:

  • TLS/SSL encryption for all data in transit.
  • AES-256 encryption for sensitive data at rest.
  • Multi-factor authentication for staff accessing customer data.
  • Regular penetration testing and security audits by independent third parties.
  • Role-based access controls ensuring staff only access data necessary for their role.
  • Incident response plan with mandatory breach notification within 72 hours where required by law.
Despite these measures, no method of transmission over the internet is 100% secure. If you suspect your account has been compromised, please contact us immediately at security@itiode.com.
8

Your Rights

Under the NDPR and applicable law, you have the following rights regarding your personal data. To exercise any of these rights, email dpo@itiode.com. We will respond within 30 days.

RightWhat It Means
AccessRequest a copy of all personal data we hold about you.
RectificationAsk us to correct inaccurate or incomplete data.
ErasureRequest deletion of your data where there is no legitimate reason to retain it.
RestrictionAsk us to suspend processing of your data in certain circumstances.
PortabilityReceive your data in a structured, machine-readable format.
ObjectionObject to processing based on legitimate interests or for direct marketing.
Withdraw consentWithdraw consent at any time where processing is based on consent.
Lodge a complaintFile a complaint with Nigeria's National Information Technology Development Agency (NITDA).
9

Children's Privacy

ITIODE Services are not directed at children under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a person under 18, we will delete it promptly.

If you believe we may have collected data about a child, please contact us immediately at dpo@itiode.com.

10

International Transfers

Your personal data is primarily stored and processed in Nigeria. However, some of our service providers (such as cloud infrastructure and analytics partners) may process data in other countries, including the United States and the European Union.

Whenever we transfer data internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs), adequacy decisions, or other legally recognised transfer mechanisms.

11

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Notify you by email at least 14 days before the changes take effect.
  • Display a prominent notice within the ITIODE platform.
  • Update the "Last updated" date at the top of this page.

We encourage you to review this Policy periodically. Your continued use of our Services after the effective date of any changes signifies your acceptance of the updated Policy.

12

Contact Us

For privacy-related queries, data subject requests, or to reach our Data Protection Officer:

shield

Data Protection Officer

dpo@itiode.com

mail

General Privacy

privacy@itiode.com

location_on

Registered Address

Lagos, Nigeria

verified_user

NDPR Regulator

NITDA — nitda.gov.ng

© 2025 ITIODE Conglomerate Ltd. All rights reserved.

Terms of ServicePrivacy PolicyContact