Effective Date: August 2026
Last Updated: August 2026
Version: 1.0
Controller: SabiWell Technologies Ltd
Website: www.sabiwell.com
Privacy Contact: privacy@sabiwell.com / support@sabiwell.com
1. Introduction
SabiWell ("SabiWell", "we", "us" or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, store, transfer, protect and otherwise process personal data when you access or use our website, mobile application, marketplace, communication tools, customer-support channels and related services (together, the "Platform").
This Privacy Policy has been prepared to comply with the Constitution of the Federal Republic of Nigeria 1999, the Nigeria Data Protection Act 2023 ("NDPA" or "NDP Act"), the Nigeria Data Protection Act General Application and Implementation Directive 2025 ("NDP Act-GAID"), and other applicable Nigerian data protection and privacy laws, regulations, directives and guidelines.
This Privacy Policy is intended to inform you about our processing activities. Where Nigerian law requires your consent for a specific processing activity, we will request that consent separately, clearly and affirmatively. Your continued use of the Platform means that you acknowledge that you have read and understood this Privacy Policy; it does not remove any right you have under applicable law.
2. About SabiWell and Our Role
SabiWell is an online platform that connects customers with independent artisans and tradespeople across Nigeria. We help users discover skilled professionals, communicate through the Platform, manage bookings, and review completed services. SabiWell does not employ artisans and does not control the independent services rendered by artisans to customers outside the Platform.
For personal data processed in connection with operating the Platform, SabiWell acts as a data controller because we determine the purposes and means of that processing. Artisans may also act as independent data controllers for personal data they receive from customers in order to provide their own services, issue quotations, visit service locations, communicate outside the Platform, or comply with their own legal obligations.
- Legal name: SabiWell Technologies Ltd
- CAC/RC number: 8599324
- Registered office: Craig Close, Challenge, Ibadan, Oyo State, Nigeria
- DPO / privacy contact: privacy@sabiwell.com
- Email: privacy@sabiwell.com / support@sabiwell.com
- Website: www.sabiwell.com
3. Key Definitions
- Personal data: any information relating to an identified or identifiable natural person.
- Processing: any operation performed on personal data, including collection, recording, organisation, storage, use, disclosure, transmission, restriction, erasure or destruction.
- Data subject: the individual to whom personal data relates, including a customer, artisan, visitor, applicant, complainant or other Platform user.
- Data controller: a person or organisation that determines the purposes and means of processing personal data.
- Data processor: a person or organisation that processes personal data on behalf of a data controller.
- Sensitive personal data: special categories of personal data under Nigerian law, including health data, biometric data used for identification, racial or ethnic origin, religious or similar beliefs, political opinions, trade union membership, and other data prescribed as sensitive by the Nigeria Data Protection Commission ("NDPC").
4. Personal Data We Collect
The personal data we collect depends on how you use the Platform, whether you are a customer, artisan, website visitor, complainant, business contact or prospective partner. We only seek to collect personal data that is adequate, relevant and limited to what is necessary for the purposes stated in this Policy.
- Account and contact data: Full name, email address, mobile telephone number, username, password or authentication credentials, one-time password records, account status and communication preferences.
- Profile data: Profile photograph, public display name, customer or artisan profile details, service areas, language preferences and user biography.
- Artisan/business data: Business name, trade category, skills, experience, qualifications or certifications, service descriptions, portfolio photographs, availability, ratings, reviews and service coverage areas.
- Verification data: Identity verification documents, selfie/profile image, document type, document number, verification status, fraud-screening flags and related audit records where required.
- Booking and service data: Job requests, service location, booking dates and times, quotations, booking status, booking history, complaint records, cancellation records and service notes.
- Messages and user-generated content: Messages exchanged through the Platform, reviews, ratings, photographs, comments, complaints, support tickets and other content submitted by users.
- Payment and transaction data: Transaction reference, payment status, amount paid, invoice or receipt information, subscription or service-fee records. SabiWell does not store debit card, credit card or bank login credentials.
- Location data: Approximate location, service location, and, where you permit it, precise device location to help connect customers with nearby artisans or improve Platform search results.
- Technical and device data: IP address, device identifiers, browser type, operating system, mobile network, app version, access times, crash logs, security logs and diagnostic information.
- Cookie and analytics data: Cookie identifiers, pages viewed, referral links, session duration, feature use and marketing or analytics preferences.
- Support and complaint data: Correspondence with us, call or chat records where enabled, complaint details, evidence submitted, investigation notes and outcome records.
- Marketing data: Newsletter or promotional consent status, campaign interactions, opt-out records and preferences for email, SMS, push notification or in-app marketing.
5. How We Collect Personal Data
- Directly from you when you create an account, update your profile, submit a booking request, message another user, post a review, contact support, complete verification, or subscribe to communications;
- From other Platform users, for example where a customer submits a booking involving an artisan or an artisan responds to a customer request;
- Automatically from your device through server logs, cookies, analytics tools, app diagnostics and security technologies;
- From third-party service providers, such as payment processors, identity verification providers, hosting providers, fraud-prevention services or analytics providers; and
- From publicly available sources or lawful business sources where necessary for verification, fraud prevention, safety, legal compliance or dispute resolution.
6. Sensitive Personal Data and Identity Documents
We do not seek to collect sensitive personal data unless it is necessary for a specific lawful purpose and permitted under applicable law. Where we process sensitive personal data, we will rely on an appropriate legal basis, such as explicit consent, legal obligation, vital interest, establishment or defence of legal claims, substantial public interest, or another lawful basis recognised under Nigerian law.
Where identity verification is required for artisans or other users, we may collect identity documents and related verification information only to verify identity, prevent fraud, improve safety, comply with legal obligations, enforce our Terms of Service, or protect users. We will restrict access to such information and retain it only for as long as necessary for the purposes stated in this Policy or as required by law.
7. Purposes and Lawful Basis for Processing
We process personal data only where we have a lawful basis under Nigerian law. The bullet-points below explains the main purposes for which we process personal data and the lawful basis we rely on. More than one lawful basis may apply to a processing activity depending on the context.
- Create and manage accounts
- Personal Data Used: Account, contact, profile, authentication and device data.
- Lawful Basis: Performance of a contract; legitimate interests in operating a safe marketplace.
- Connect customers with artisans
- Personal Data Used: Profile, artisan/business, service area, booking, location and communication data.
- Lawful Basis: Performance of a contract; legitimate interests in providing matching, search and marketplace services.
- Facilitate bookings and messaging
- Personal Data Used: Booking data, messages, service location, quotations and booking status.
- Lawful Basis: Performance of a contract; legitimate interests in providing Platform functionality and resolving disputes.
- Verify identity and prevent fraud
- Personal Data Used: Verification data, device data, security logs, profile data and complaint records.
- Lawful Basis: Legal obligation where applicable; legitimate interests in fraud prevention and user safety; consent where required.
- Process Platform fees or subscriptions
- Personal Data Used: Transaction reference, amount paid, payment status and billing records.
- Lawful Basis: Performance of a contract; legal obligation for accounting, tax and record-keeping.
- Provide customer support and handle complaints
- Personal Data Used: Support correspondence, account data, booking data, messages, reviews and evidence submitted.
- Lawful Basis: Performance of a contract; legitimate interests in resolving issues; legal claims.
- Send service communications
- Personal Data Used: Email, phone number, push notification token, account and booking data.
- Lawful Basis: Performance of a contract; legitimate interests in account security and service administration.
- Send marketing communications
- Personal Data Used: Contact details, marketing preferences and campaign interaction data.
- Lawful Basis: Consent, and legitimate interests where permitted by law for limited business communications. You can opt out at any time.
- Improve Platform performance and user experience
- Personal Data Used: Technical data, cookie data, analytics data and usage patterns.
- Lawful Basis: Legitimate interests; consent for non-necessary cookies or tracking tools where required.
- Use location features
- Personal Data Used: Approximate or precise location and service location.
- Lawful Basis: Consent for precise device location; performance of a contract or legitimate interests for service-location matching where applicable.
- Publish reviews, ratings and public profiles
- Personal Data Used: Profile data, reviews, ratings, portfolio photos and service descriptions.
- Lawful Basis: Performance of a contract; legitimate interests in marketplace trust and user information.
- Comply with legal and regulatory obligations
- Personal Data Used: Any relevant personal data required by law, court order, regulator or lawful authority.
- Lawful Basis: Legal obligation; public interest where applicable; establishment or defence of legal claims.
- Protect rights, safety and security
- Personal Data Used: Security logs, account data, messages, booking history, complaint records and device data.
- Lawful Basis: Legitimate interests; legal claims; vital interests where necessary to protect life or safety.
8. Consent and Withdrawal of Consent
Where we rely on consent, we will ask for it in clear and simple language and in a manner that requires an affirmative action. Silence, inactivity, pre-ticked boxes or bundled consent will not be treated as valid consent where the law requires specific consent.
You may withdraw consent at any time by using the relevant Platform settings, cookie settings, unsubscribe link, device permission settings, or by contacting us. Withdrawal of consent will not affect processing that occurred lawfully before the withdrawal. In some cases, if you withdraw consent, certain features may no longer be available.
9. Cookies and Similar Technologies
We use cookies, software development kits, pixels, local storage and similar technologies ("cookies") to operate the website and app, protect accounts, remember preferences, understand how the Platform is used and improve our services. We will provide a conspicuous cookie notice or banner on the Platform and will give users clear options to accept, reject or manage non-necessary cookies.
- Strictly necessary cookies
- Purpose: Enable core functionality such as security, network stability, account login, accessibility, fraud prevention and session management.
- Consent Position: Required for the Platform to work. These are not used for optional marketing or analytics.
- Preference cookies
- Purpose: Remember language, region, display and user-interface preferences.
- Consent Position: Used with consent where required or where you select the relevant preference.
- Analytics cookies
- Purpose: Help us understand visits, usage, feature performance, errors and service improvement opportunities.
- Consent Position: Used only where permitted by law and subject to cookie controls where required.
- Marketing cookies
- Purpose: Help us measure campaigns or show relevant promotions.
- Consent Position: Used only with consent where required. You may reject or withdraw consent.
You may manage cookies through the Platform cookie settings and your browser settings. If you disable some cookies, certain Platform features may not work properly. SabiWell should publish a separate Cookie Notice or cookie settings page listing the exact cookies, providers, duration and purposes.
10. Location Data
With your permission, we may collect approximate or precise location data to show nearby artisans, improve search results, support booking logistics, enhance safety and reduce fraud. You may disable location permissions through your device settings. If you disable location data, some features may be unavailable or less accurate.
11. User Profiles, Messages, Reviews and Public Content
Some information you provide may be visible to other users or to the public, depending on the feature used. This may include artisan names, profile photographs, trade categories, service descriptions, service areas, portfolio photographs, ratings and reviews. Customers and artisans may also see relevant booking and communication information necessary to complete or manage a booking.
Please do not upload or disclose personal data of other people unless you have the lawful right to do so. We may moderate, restrict, remove or retain content where necessary to enforce our Terms of Service, investigate complaints, comply with law, protect users, prevent fraud or establish, exercise or defend legal claims.
12. Payments
Where you purchase Platform services, pay subscription fees, pay promotional fees, or make other payments through the Platform, payments may be processed by third-party payment providers such as Flutterwave or any other provider we appoint. Those providers may collect and process payment-card, bank or mobile-money details under their own terms and privacy notices. SabiWell does not store your debit card, credit card, bank login or banking credentials.
SabiWell does not collect payments made directly by customers to artisans for artisan services rendered outside Platform payment features, unless a specific SabiWell payment feature is introduced and covered by updated terms and notices.
13. Communications and Marketing
We may send you service and administrative communications relating to account verification, OTPs, bookings, complaints, safety alerts, support, security notices, policy updates and other non-marketing Platform messages. These messages are necessary for the Platform and may not always offer an unsubscribe option.
Where you opt in or where otherwise permitted by law, we may send promotional messages, newsletters, offers or updates by email, SMS, push notification, in-app message or other channels. You may unsubscribe from marketing communications at any time. We will maintain a suppression list to ensure we respect your opt-out choice.
14. How We Share Personal Data
We do not sell personal data. We may share personal data only where lawful and necessary for the purposes described in this Policy.
- Other users: Customers and artisans receive information necessary for bookings, quotations, communication, ratings, reviews and service delivery.
- Service providers / processors: Cloud hosting, database providers, payment processors, identity verification providers, email/SMS/OTP providers, analytics providers, customer-support systems, cybersecurity tools and professional technology providers.
- Payment providers: Transaction processing, payment confirmation, fraud monitoring, refunds and payment dispute handling.
- Professional advisers: Lawyers, auditors, consultants, insurers and accountants where necessary for business, legal, audit, insurance or compliance purposes.
- Lawful authorities: Courts, regulators, law-enforcement agencies, government bodies or other authorities where required by law or lawful process.
- Business transaction parties: Prospective or actual buyers, investors, successors, lenders, advisers or counterparties in connection with a merger, acquisition, restructuring, financing or sale of assets, subject to appropriate safeguards.
- Emergency or safety parties: Where necessary to protect life, safety, property, rights, Platform integrity or vital interests of any person.
15. Service Providers and Data Processing Agreements
Where we engage a data processor to process personal data on our behalf, we will take reasonable steps to ensure that the processor provides sufficient guarantees regarding confidentiality, security, integrity, availability, breach notification, rights assistance, deletion or return of data, sub-processor controls, audit support and compliance with applicable data protection law. Where required, we will put a written data processing agreement in place.
16. International Transfers
Some of our service providers, cloud infrastructure, analytics tools, payment providers, email providers or support systems may process or store personal data outside Nigeria. Where personal data is transferred outside Nigeria, we will take reasonable steps to ensure that the transfer is lawful and protected by appropriate safeguards under the NDPA and applicable NDPC guidance.
Safeguards may include an adequacy determination, contractual safeguards, standard contractual clauses or similar transfer mechanisms approved or recognised by the NDPC, binding corporate rules, consent where required, transfer necessity for contract or legal claims, or any other lawful basis permitted under Nigerian law. We will also assess vendor security and limit transfers to what is necessary for the relevant purpose.
17. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including to provide the Platform, comply with legal obligations, resolve disputes, prevent fraud, enforce agreements, support security and maintain legitimate business records. The exact retention period may depend on the category of data, legal requirements, risk, user relationship and dispute status.
- Account data: For as long as the account is active, and thereafter for up to 6 years where required for legal, audit, tax, dispute, fraud-prevention or enforcement purposes.
- Booking and service records: For the life of the account and up to 6 years after the relevant transaction or dispute, unless a longer period is required by law.
- Messages: For as long as needed to provide messaging, maintain booking history, investigate complaints, enforce terms or comply with law. Deletion may be limited where messages involve another user, complaint or legal claim.
- Payment and transaction records: Usually up to 6 years or any longer period required for accounting, tax, audit, anti-fraud or legal purposes.
- Verification documents: Only for as long as necessary to complete verification, maintain trust and safety, prevent fraud, comply with law, or defend claims; access is restricted.
- Reviews, ratings and public profile content: For as long as the content remains published or the account remains active, unless removed under our policies or retained for legal reasons.
- Support and complaint records: Usually up to 6 years after closure of the complaint or for as long as needed for legal, regulatory or dispute purposes.
- Marketing data: Until you withdraw consent or opt out, after which we may retain minimal suppression records to respect your choice.
- Cookie and analytics data: For the duration stated in the cookie settings or Cookie Notice, usually not longer than necessary for the stated purpose.
- Security logs: For a limited period necessary for security, fraud prevention, incident investigation and compliance, unless longer retention is required due to suspicious activity or legal claims.
- Prospective user or failed contract data: Where a proposed contract or onboarding does not materialise, personal data should be deleted within a reasonable period, unless there is a lawful reason to retain it, such as fraud prevention or legal claims.
When personal data is no longer required, we will securely delete, anonymise or restrict it where practicable.
18. Data Security
We implement reasonable technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, misuse, alteration, unauthorised disclosure, unauthorised access or other unlawful processing. These measures may include encryption in transit, access controls, password protection, least-privilege access, secure hosting, monitoring, vulnerability management, staff confidentiality obligations, backups, incident response procedures and periodic review of security controls.
No method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security, but we will use reasonable measures appropriate to the nature, scope, context, purposes and risk of our processing.
19. Personal Data Breaches
If a personal data breach occurs, we will assess the nature, scope, sensitivity and likely impact of the breach. Where the breach is likely to result in a risk to the rights and freedoms of individuals, we will notify the NDPC within 72 hours of becoming aware of the breach, where required and feasible. Where a breach is likely to result in a high risk to affected data subjects, we will communicate the breach to affected data subjects in clear and plain language, including information on likely consequences and steps they may take to mitigate potential harm.
We will keep internal records of personal data breaches, including the facts of the breach, its effects and remedial action taken.
20. Your Privacy Rights
Subject to applicable law, you may have the following rights in relation to your personal data:
- right to be informed about how your personal data is processed;
- right of access to your personal data and information about the processing;
- right to request correction or rectification of inaccurate, incomplete or misleading personal data;
- right to request deletion or erasure of personal data in appropriate circumstances;
- right to withdraw consent where processing is based on consent;
- right to object to certain processing, including processing for direct marketing;
- right to request restriction of processing in appropriate circumstances;
- right to data portability where applicable;
- right not to be subject to certain decisions based solely on automated processing that produce legal or similarly significant effects, except as permitted by law;
- right to lodge a complaint with the NDPC; and
- right to seek civil remedies where your rights are violated under applicable law.
21. How to Exercise Your Rights
You may submit a privacy request by contacting us at privacy@sabiwell.com or support@sabiwell.com. Please include your name, contact details, account identifier, the right you wish to exercise and enough information for us to understand and process your request.
We may request proof of identity before processing a request, especially where the request involves access, deletion, portability, account changes or sensitive information. We will respond within the period required by applicable law and, where practicable, within 30 days. If a request is complex or we need more time, we will inform you. We may refuse or limit a request where permitted by law, including where fulfilling the request would affect the rights of another person, prejudice legal claims, conflict with legal obligations, compromise security or require disproportionate effort.
22. Automated Decision-Making, Matching and Profiling
The Platform may use algorithms, rules or automated tools to support search ranking, matching customers with artisans, fraud prevention, safety checks, account security, moderation, analytics, recommendations and Platform improvement. These tools are designed to support Platform operations and user experience.
Where we make a decision based solely on automated processing that produces legal effects or similarly significant effects concerning you, we will provide safeguards required by law, which may include the right to obtain human intervention, express your point of view and contest the decision.
23. Children and Persons Without Legal Capacity
The Platform is intended for individuals who are at least eighteen (18) years old and legally capable of entering into binding agreements. We do not knowingly collect personal data from children. If we become aware that a child or a person lacking legal capacity has provided personal data without appropriate parental or guardian consent, we will take reasonable steps to delete or restrict that information, unless we are required or permitted by law to retain it.
Parents or guardians who believe that a child has provided personal data to SabiWell should contact us at privacy@sabiwell.com or support@sabiwell.com
24. Accuracy of Data and User Responsibilities
You are responsible for providing accurate, complete and up-to-date information and for updating your account information when it changes. We may provide tools for you to access, correct or update your data. We may suspend or restrict accounts that provide false, misleading, unlawful or unsafe information.
25. Third-Party Links and Services
The Platform may contain links to third-party websites, apps, payment pages, social media pages or services. We are not responsible for the privacy practices, security or content of third-party services that we do not control. You should review the privacy notices of those third parties before providing personal data to them.
26. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, technologies, legal requirements, vendors, data practices or business model. Updated versions will be published on the Platform with a revised effective date. Where required by law or where changes are material, we will notify users by email, in-app notice, website notice or other appropriate means.
27. Contact Us
If you have questions, complaints or requests relating to this Privacy Policy or our processing of personal data, please contact:
- Organisation: SabiWell Technologies Ltd
- DPO / Privacy Lead: TBC
- Email: privacy@sabiwell.com / support@sabiwell.com
- Postal address: Craig Close, Challenge, Ibadan, Oyo State, Nigeria
- Website: www.sabiwell.com
28. Complaints to the Nigeria Data Protection Commission
We encourage you to contact us first so that we can investigate and attempt to resolve your concern. If you are dissatisfied with our response or believe that your personal data has been processed in violation of applicable Nigerian data protection law, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC) through its official website or complaint channels.
- Regulator: Nigeria Data Protection Commission (NDPC)
- Website: www.ndpc.gov.ng
- Complaint / services portal: services.ndpc.gov.ng or any updated official NDPC complaints channel
29. Acknowledgement
By accessing or using the Platform, you acknowledge that you have read and understood this Privacy Policy. Where a processing activity requires consent under applicable law, SabiWell will request that consent separately and you may withdraw it as described in this Policy.