Overview
ITIODE Conglomerate Ltd. ("ITIODE", "we", "us") is committed to protecting your personal information. This Privacy Policy describes how we collect, use, store, and disclose data when you interact with our services — Offkrent, Hive Academy, and Dellla Logistics — and our websites and mobile applications.
This Policy applies to all users worldwide. For users in Nigeria, it is also our NDPR Privacy Notice. For users in the European Economic Area, it constitutes our GDPR-compliant privacy notice where applicable.
Information We Collect
2.1 Information You Provide
- Account data: Name, email address, phone number, date of birth, and password when you register.
- Identity verification: Government-issued ID, NIN, or BVN where required for Offkrent tenancy or financial services.
- Payment data: Card details (tokenised — we never store raw card numbers), bank account numbers for withdrawals.
- Housing data (Offkrent): Emergency contacts, next-of-kin, occupancy preferences, and maintenance requests.
- Educational data (Hive Academy): Course progress, quiz responses, assignment submissions, and certificates earned.
- Logistics data (Dellla): Delivery addresses, package descriptions, and recipient contact details.
- Communications: Messages you send to our support team, feedback, and survey responses.
2.2 Information We Collect Automatically
- Device & usage data: IP address, browser type, operating system, device identifiers, pages visited, and actions taken.
- Location data: Approximate location derived from IP; precise GPS location for Dellla delivery tracking (with your consent).
- Cookies & similar technologies: See Section 5 for full details.
2.3 Information from Third Parties
- Social login providers (Google, Apple) when you choose to sign in via those services.
- Payment processors (Paystack, Flutterwave) for transaction status and fraud signals.
- Referral data from other ITIODE users who referred you.
How We Use Your Information
| Purpose | Legal Basis (NDPR / GDPR) |
|---|---|
| Create and manage your ITIODE account | Contractual necessity |
| Process payments and prevent fraud | Contractual necessity / Legitimate interests |
| Provide, maintain, and improve our Services | Contractual necessity |
| Send transactional emails and SMS notifications | Contractual necessity |
| Send marketing communications | Consent (you may withdraw at any time) |
| Personalise your experience and recommendations | Legitimate interests |
| Comply with legal obligations | Legal obligation |
| Safety, security, and fraud detection | Legitimate interests / Legal obligation |
| Analytics to understand platform usage | Legitimate interests |
| Run our referral and rewards programme | Contractual necessity / Consent |
We will never sell your personal data to third parties for their own marketing purposes.
Data Retention
We retain your personal data for as long as necessary to fulfil the purposes outlined in this Policy, unless a longer retention period is required by law.
- Active accounts: Data retained for the lifetime of your account plus 12 months following closure to resolve disputes.
- Financial records: Retained for 7 years in compliance with Nigerian tax and financial regulations.
- Hive Academy certificates: Permanently retained on our records so graduates can verify credentials at any time.
- Marketing data: Deleted within 30 days of consent withdrawal or account closure.
- Delivery data (Dellla): Retained for 2 years for dispute resolution and customer service purposes.
When data is no longer needed, we delete it securely or anonymise it so it can no longer be linked to you.
Data Security
We implement industry-standard technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- TLS/SSL encryption for all data in transit.
- AES-256 encryption for sensitive data at rest.
- Multi-factor authentication for staff accessing customer data.
- Regular penetration testing and security audits by independent third parties.
- Role-based access controls ensuring staff only access data necessary for their role.
- Incident response plan with mandatory breach notification within 72 hours where required by law.
Your Rights
Under the NDPR and applicable law, you have the following rights regarding your personal data. To exercise any of these rights, email dpo@itiode.com. We will respond within 30 days.
| Right | What It Means |
|---|---|
| Access | Request a copy of all personal data we hold about you. |
| Rectification | Ask us to correct inaccurate or incomplete data. |
| Erasure | Request deletion of your data where there is no legitimate reason to retain it. |
| Restriction | Ask us to suspend processing of your data in certain circumstances. |
| Portability | Receive your data in a structured, machine-readable format. |
| Objection | Object to processing based on legitimate interests or for direct marketing. |
| Withdraw consent | Withdraw consent at any time where processing is based on consent. |
| Lodge a complaint | File a complaint with Nigeria's National Information Technology Development Agency (NITDA). |
Children's Privacy
ITIODE Services are not directed at children under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected data from a person under 18, we will delete it promptly.
If you believe we may have collected data about a child, please contact us immediately at dpo@itiode.com.
International Transfers
Your personal data is primarily stored and processed in Nigeria. However, some of our service providers (such as cloud infrastructure and analytics partners) may process data in other countries, including the United States and the European Union.
Whenever we transfer data internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs), adequacy decisions, or other legally recognised transfer mechanisms.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
- Notify you by email at least 14 days before the changes take effect.
- Display a prominent notice within the ITIODE platform.
- Update the "Last updated" date at the top of this page.
We encourage you to review this Policy periodically. Your continued use of our Services after the effective date of any changes signifies your acceptance of the updated Policy.
Contact Us
For privacy-related queries, data subject requests, or to reach our Data Protection Officer:
Data Protection Officer
dpo@itiode.com
General Privacy
privacy@itiode.com
Registered Address
Lagos, Nigeria
NDPR Regulator
NITDA — nitda.gov.ng