Privacy Policy
1. Introduction
Welcome to Exprt.Pro ("we," "our," or "us"). We are committed to protecting your personal data and respecting your privacy. This Privacy Policy explains how we collect, use, disclosure, and safeguard your information when you visit our platform www.exprt.pro.
This policy is drafted in compliance with global best practices and specific African data protection regulations, including but not limited to:
- Nigeria: The Nigeria Data Protection Act (NDPA) 2023 and the Nigeria Data Protection Regulation (NDPR) 2019.
- South Africa: The Protection of Personal Information Act (POPIA) 2013.
- Kenya: The Data Protection Act (DPA) 2019.
- Ghana: The Data Protection Act, 2012 (Act 843).
2. Information We Collect
We strictly adhere to the principle of "Data Minimization." We only collect data that is necessary for the provision of our services.
2.1. Personal Data
- Identity Data: Name, username, date of birth, gender, and photograph/avatar.
- Contact Data: Email address, telephone numbers, and physical/billing address.
- Professional Data (For Experts): CV/Resume, portfolios, certifications, educational background, employment history, and references.
- Verification Data: Government-issued ID (Passport, Driver’s License, NIN) required for our "Verified Expert" badge (processed securely via third-party identity verification partners).
2.2. Financial Data
- Bank account details and payment card details.
- Note: We do not store full credit card numbers. All payment transactions are processed through PCIDSS-compliant payment processors (e.g., Paystack, Stripe).
2.3. Technical Data
- Internet Protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system, and platform.
3. How We Use Your Data & Legal Basis
| Purpose/Activity | Type of Data | Legal Basis for Processing |
|---|---|---|
| To register you as a new user | Identity, Contact | Performance of a Contract |
| To process and deliver your order/booking | Identity, Financial, Transaction | Performance of a Contract |
| To verify Expert identity (Trust & Safety) | Identity, Verification | Legitimate Interest (Fraud Prevention) & Legal Obligation |
| To manage our relationship with you/Support | Identity, Contact, Usage | Performance of a Contract |
| To improve our website & services | Technical, Usage | Legitimate Interest (Analytics) |
4. International Data Transfers
Exprt.Pro operates globally with a focus on Africa. Your personal data may be transferred to and processed in countries other than the country in which you are resident. These countries may have data protection laws that are different from the laws of your country.
- For Nigerian Users: We comply with the NDPR restrictions on cross-border transfer. We only transfer data to countries with adequate data protection laws or rely on standard contractual clauses approved by the Nigeria Data Protection Commission (NDPC).
- For South African Users: We comply with Section 72 of POPIA regarding transborder information flows.
5. Your Rights (The "Data Subject")
Depending on your jurisdiction, you have specific rights regarding your data:
5.1. General Rights
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate data.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your data where there is no good reason for us to continue processing it.
- Right to Object: Object to processing where we are relying on a legitimate interest.
5.2. Jurisdiction-Specific Rights
- Nigeria (NDPA/NDPR): Right to data portability; Right to withdraw consent at any time.
- South Africa (POPIA): Right to object to the processing of personal information for the purpose of direct marketing by means of unsolicited electronic communications (Section 11(3)).
- Kenya (DPA): Right to be informed of the use to which personal data is to be put; Right to correction of false or misleading data.
To exercise any of these rights, please contact our Data Protection Officer (DPO) at privacy@exprt.pro.
6. Data Security and Retention
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way.
- Encryption: Data is encrypted in transit (TLS 1.2+) and at rest.
- Access Control: Access to your personal data is limited to those employees, agents, contractors, and other third parties who have a business need to know.
- Retention: We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
7. Fees
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive.
8. Contact Us
If you have any questions about this privacy policy or our privacy practices, please contact us:
Exprt.Pro Legal Team
Email: legal@exprt.pro
Address: Lagos, Nigeria (HQ)