DOCUMENT: AFRIEV MASTER PRIVACY POLICY
ENTITY: AfriEv (A Sfaret Technologies Brand)
WEBSITE: https://afriev.com.ng
OFFICIAL PRIVACY CONTACT: privacy@afriev.com.ng
DATA PROTECTION OFFICER: Lawrence Dike Paul (DPO Lead)
1. INTRODUCTION
AfriEv is committed to protecting the privacy, security, confidentiality and lawful use of personal information entrusted to us by individuals, organizations, event organizers, attendees, participants, speakers, volunteers, sponsors, exhibitors, staff, administrators, credential holders, partners and other users of our services.
This Privacy Policy explains how AfriEv collects, receives, uses, stores, protects, discloses, transfers and otherwise processes personal information when you:
- visit or use the AfriEv website;
- create or use an AfriEv account;
- register for an event;
- purchase or receive an event ticket;
- receive an invitation to an event;
- check in or obtain accreditation at an event;
- use an AfriEv QR code, digital credential or verification service;
- receive or verify a certificate;
- participate in an event managed through AfriEv;
- communicate with an event organizer through AfriEv;
- use AfriEv's event-management tools;
- use AfriEv's organization or administrator dashboard;
- interact with AfriEv customer support;
- subscribe to communications from AfriEv;
- use AfriEv's APIs or integrations;
- access AfriEv through a mobile application or other supported technology; or
- otherwise interact with AfriEv.
AfriEv may operate as a platform provider, data processor, data controller, joint controller, service provider or another legally recognized role depending on the service being provided and the relationship between AfriEv, the event organizer and the individual whose information is processed.
This distinction is important. For example, where an organization uses AfriEv to organize an event and determines why participant information is collected, that organization may be the primary data controller, while AfriEv may process the information on that organization's behalf. Where AfriEv determines the purposes and means of processing information for its own services, AfriEv may act as a data controller. The applicable role will depend on the specific processing activity.
2. OUR COMMITMENT TO PRIVACY
AfriEv is built around the principle that personal information belongs to the individual to whom it relates. We therefore seek to:
- collect only information that is reasonably necessary for identified purposes;
- explain how personal information is used;
- process information lawfully and fairly;
- maintain appropriate security controls;
- protect information against unauthorized access, alteration, disclosure, loss or destruction;
- respect applicable data-subject rights;
- provide mechanisms for individuals to exercise applicable privacy rights;
- retain information only for as long as reasonably necessary or legally required;
- use appropriate safeguards when information is transferred across borders;
- require appropriate privacy and security commitments from relevant service providers;
- investigate and respond to privacy and security incidents;
- provide additional protections where required for children and vulnerable individuals; and
- continuously review our privacy practices as our products, technologies and legal obligations develop.
3. APPLICABLE PRIVACY LAWS
AfriEv is headquartered or operates in connection with Nigeria and therefore takes the Nigerian data protection framework seriously, including the Nigeria Data Protection Act 2023 (NDPA) and applicable requirements, regulations, guidelines and directives issued by the Nigeria Data Protection Commission (NDPC).
The NDPC's published compliance guidance emphasizes organizational privacy policies, transparent privacy notices and cookie notices, data-security measures, compliance schedules and appropriate privacy governance.
Depending on the location of the individual, the nature of the service, the location of an event, or AfriEv's activities, additional privacy laws may apply, including:
- Nigeria's data protection legislation;
- the EU General Data Protection Regulation (GDPR);
- the UK GDPR and Data Protection Act framework;
- the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA);
- Australia's Privacy Act and Australian Privacy Principles;
- applicable data-protection laws of other African countries;
- applicable U.S. state privacy laws;
- applicable telecommunications, electronic communications and cookie laws;
- sector-specific privacy legislation; and
- other applicable national, regional or local privacy requirements.
The GDPR provides individuals with rights and protections concerning the processing of personal data and regulates organizations that fall within its territorial and material scope. Similarly, the CCPA provides qualifying California residents with rights including rights to know, delete and correct certain personal information, opt out of sale or sharing in applicable circumstances, limit certain uses of sensitive personal information and receive equal treatment when exercising privacy rights.
Where another law provides a higher level of protection than this Privacy Policy, AfriEv will seek to apply the higher standard where legally required.
4. DEFINITIONS
For purposes of this Privacy Policy:
- "AfriEv", "we", "us" or "our": Means AfriEv and, where applicable, its affiliated companies, subsidiaries, successors and authorized representatives (under Sfaret Technologies).
- "Personal Information": Means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identifiable individual. Depending on applicable law, this may also be referred to as personal data or personally identifiable information.
- "Sensitive Personal Information": Means personal information that receives additional protection under applicable law, including health, biometrics, precise location, financial information, identification documents, religious beliefs, racial or ethnic origin, criminal records, children's information and other specially protected categories.
- "Data Subject": Means the individual to whom personal information relates.
- "Processing": Includes collecting, recording, organizing, structuring, storing, adapting, retrieving, using, disclosing, transmitting, combining, restricting, deleting or otherwise handling personal information.
- "Controller": Means the organization that determines the purposes and means of processing personal information.
- "Processor": Means an organization that processes personal information on behalf of a controller.
- "Event Organizer": Means an organization, company, institution, church, NGO, school, community, government organization, conference organizer or other entity that uses AfriEv to organize or administer an event.
- "Event": Means a conference, seminar, workshop, training, meeting, competition, exhibition, festival, program, campaign, ceremony, church program, community activity, online event, hybrid event or other organized activity managed through AfriEv.
- "Credential": Means a digital or physical identification, accreditation, ticket, participant pass, certificate, badge or other event-related credential.
5. INFORMATION WE COLLECT
The information AfriEv collects depends on how you use the platform. We may collect the following categories of information:
5.1 Account Information
When you create an account, we may collect:
- full name; username; email address; telephone number;
- password or authentication credentials (never stored in plain text);
- organization name; job title; profile photograph;
- country; state or region; city; preferred language;
- account preferences; communication preferences; account type; verification information; and other information you voluntarily provide.
Passwords should never be stored by AfriEv in readable or reversible form. Authentication credentials are protected using strong hashing algorithms.
6. EVENT REGISTRATION INFORMATION
When you register for an event, AfriEv may collect:
- name, email address, phone number, organization, job title;
- participant category, ticket type, registration number;
- event-specific responses, session/workshop selections;
- dietary or accessibility requirements where relevant;
- emergency contact information where required;
- attendance information, payment status, transaction references;
- invitation information, referral information, accommodation details where relevant; and other information requested by the event organizer.
The exact information collected will depend on the requirements of the particular event. AfriEv encourages event organizers to avoid collecting unnecessary personal information.
7. ACCREDITATION AND IDENTITY VERIFICATION
AfriEv may provide event accreditation services involving:
- participant name, photograph, organization, role, participant category;
- registration number, identification information, credential number, QR code identifier;
- badge information, accreditation status, access permissions, check-in status, attendance records;
- session access, credential issuance information, and credential verification information.
Where an event organizer requests government-issued identification or other sensitive identification information, the event organizer is responsible for ensuring that the collection is lawful and necessary. AfriEv will not require sensitive identification information merely because the platform is technically capable of collecting it.
8. QR CODES AND DIGITAL CREDENTIALS
AfriEv may issue QR codes or other machine-readable identifiers for event registration, event check-in, attendance tracking, participant verification, ticket validation, certificate verification, staff access, volunteer management, speaker accreditation, exhibitor access, sponsor access, restricted-area access, and other event-management purposes.
A QR code may contain or reference an identifier rather than directly displaying all personal information. Depending on the implementation, scanning a QR code may cause AfriEv to retrieve associated information from its systems. Event organizers are responsible for configuring access permissions appropriately.
9. CERTIFICATES AND CREDENTIAL VERIFICATION
AfriEv may provide digital certificate issuance and verification. A certificate may contain:
- recipient name, certificate title, event name, organization name;
- date of issue, certificate identification number, verification code, QR code;
- issuer information, participation information, completion information; and other information necessary to establish certificate authenticity.
Some verification information may be publicly accessible. For example, a person who receives a certificate may provide its verification URL or QR code to an employer, institution, sponsor, school or other third party. AfriEv will seek to minimize the information publicly displayed through certificate verification.
10. PAYMENT INFORMATION
Where AfriEv provides paid registration, ticketing or other commercial services, payment-related information may be processed (transaction amount, currency, payment status, transaction identifier, payer name, billing info, refund info).
AfriEv uses PCI-DSS compliant third-party payment processors. Unless explicitly stated otherwise, AfriEv does not store complete payment-card numbers or card security codes (CVV) on its own systems.
11. COMMUNICATIONS
If you contact AfriEv, we may collect your name, email address, phone number, organization, message contents, attachments, support tickets, and communication history to resolve requests and improve services.
12. TECHNICAL AND USAGE INFORMATION
When you access AfriEv, we may automatically log technical information including IP address, browser type, device type, operating system, language settings, approximate location derived from IP, time zone, referring website, pages visited, features used, timestamps, crash diagnostic logs, and security event records.
13. LOCATION INFORMATION
AfriEv processes location in limited circumstances (event venue coordination, fraud prevention, approximate IP-based location). AfriEv will not access precise GPS device location without explicit user permission.
14. COOKIES AND SIMILAR TECHNOLOGIES
AfriEv uses cookies and local storage for authentication, account security, session maintenance, preference memory, and performance monitoring. Where legally required under NDPC guidance or international law, AfriEv will seek prior consent before placing non-essential cookies.
15. WHY WE COLLECT PERSONAL INFORMATION
AfriEv processes personal data for specified operational purposes:
- 15.1 Providing the Platform: Creating accounts, authenticating users, managing events, issuing tickets and credentials, verifying certificates, and hosting dashboards.
- 15.2 Event Administration: Enabling organizers to manage attendees, speakers, volunteers, sponsors, access control, and attendance records.
- 15.3 Security: Detecting suspicious activity, preventing ticket fraud, protecting accounts, and maintaining audit trails.
- 15.4 Communications: Sending registration confirmations, passes, event reminders, and service notifications.
- 15.5 Legal Compliance: Complying with regulatory obligations, court orders, tax documentation, and enforcing contracts.
- 15.6 Service Improvement: Analyzing performance, troubleshooting bugs, and enhancing accessibility.
16. LAWFUL BASES FOR PROCESSING
Under NDPA and GDPR frameworks, processing is conducted on lawful grounds including: Consent, Contractual Necessity, Legal Obligation, Legitimate Interests, Vital Interests, and Public Interest.
17. EVENT ORGANIZERS AS DATA CONTROLLERS
An event organizer independently determines what participant information it requires, why it needs it, who should receive it, and whether special categories are collected. Where the organizer determines these matters, the organizer is the Data Controller, and AfriEv processes information as a Data Processor according to their instructions.
18. INFORMATION SHARING
AfriEv does not sell personal information. We disclose data only to legitimate recipients: event organizers, payment processors, cloud infrastructure providers (AWS, Google Cloud), email/SMS dispatchers, professional advisers, auditors, and law enforcement when legally mandated.
19. SPONSORS AND EXHIBITORS
AfriEv will not assume that an organizer automatically has unrestricted permission to share participant information with sponsors. Where applicable, the organizer must establish an appropriate legal basis and obtain explicit consent for marketing communications.
20. PUBLIC EVENT INFORMATION
Certain information is intentionally published by organizers or users: speaker names, bios, event schedules, exhibitor directories, and public certificate verification URLs. Users should not submit sensitive information to public event profiles.
21. CHILDREN AND MINORS
Where an event involves minors (such as school competitions or youth summits), the organizer is responsible for securing verifiable parental or guardian consent in accordance with applicable child protection legislation.
22. SENSITIVE PERSONAL INFORMATION
AfriEv seeks to minimize collection of sensitive personal information. Where necessary (e.g. government VIP credentials, disability access), additional technical and organizational safeguards are applied.
23. PHOTOGRAPHS, VIDEO AND EVENT MEDIA
Events managed through AfriEv may be photographed, filmed or livestreamed by organizers. Organizers are responsible for providing appropriate signage and opt-out mechanisms for attendees who do not wish to be filmed.
24. AUTOMATED PROCESSING AND ARTIFICIAL INTELLIGENCE
AfriEv uses automated systems for spam prevention, fraud detection, and ticket scanning. AfriEv will not rely solely on automated decision-making to produce legal effects on an individual without human review.
25. DATA RETENTION
AfriEv retains personal data only as long as necessary for the purpose collected, to satisfy legal, accounting, and reporting obligations, and to preserve verifiable credential records. When no longer required, data is deleted, anonymized, or securely archived.
26. DATA SECURITY
Safeguards include TLS 1.3 in transit, AES-256 at rest, strict role-based access control, cryptographic pass hashing, 24/7 automated monitoring, routine backups, employee confidentiality agreements, and regular vulnerability audits.
27. DATA BREACHES AND SECURITY INCIDENTS
In the event of a confirmed personal data breach, AfriEv will contain the incident, investigate its scope, notify affected controllers, individuals, and the NDPC within statutory deadlines, and deploy corrective actions.
28. INTERNATIONAL DATA TRANSFERS
Cross-border transfers are conducted under approved lawful transfer mechanisms, including Standard Contractual Clauses (SCCs), NDPC cross-border transfer approvals, and adequacy determinations.
29 – 34. YOUR PRIVACY RIGHTS & PROCEDURES
Depending on your jurisdiction, you have the following enforceable rights:
- 29. Rights Overview: Rights to be informed, access, correct, delete, restrict, object, data portability, and withdraw consent.
- 30. Access Requests: Request copies of personal data held by AfriEv (subject to identity verification).
- 31. Correction: Update inaccurate information directly via your account or by contacting support.
- 32. Deletion: Request erasure of your data where no legal retention requirement applies.
- 33. Withdrawal of Consent: Revoke optional processing consents at any time.
- 34. Marketing: Unsubscribe from promotional messages via the one-click link in any marketing email.
35 – 40. THIRD PARTIES, VENDORS & LEGAL COMPLIANCE
- 35 – 37. Third Parties & Processors: We establish Data Processing Agreements (DPAs) with all subprocessors to ensure equivalent data protection standards.
- 38. Corporate Transactions: In the event of a merger, restructuring, or acquisition, data transfer will remain subject to this policy.
- 39. Law Enforcement: We disclose data only upon receipt of legally binding court orders and regulatory summonses.
- 40. Business Records: Essential financial, taxation, and security audit logs are preserved in accordance with statutory requirements.
41 – 46. GOVERNANCE, ACCURACY & RESPONSIBILITIES
AfriEv embeds Privacy by Design (Sec 43) and data minimization (Sec 41) into software architecture. Organizers (Sec 44) must collect data lawfully, respect attendee privacy preferences, and maintain secure credentials. Users (Sec 45) must safeguard account passwords and report unauthorized activity.
47. DATA PROTECTION OFFICER
AfriEv has designated a Data Protection Officer (DPO) / Privacy Lead responsible for overseeing organizational compliance:
Designation: Data Protection Officer / Privacy Lead
Department: AfriEv Privacy & Compliance Department
Email: privacy@afriev.com.ng
Postal Address: 620 Ikwerre Road, Port Harcourt, Nigeria
Phone: +234 704 951 5934
48 – 52. REGIONAL JURISDICTIONAL NOTICES
- 48. Nigeria (NDPA / NDPC): Users may lodge complaints directly with AfriEv or the Nigeria Data Protection Commission (NDPC at ndpc.gov.ng).
- 49. EEA & UK (GDPR): European and British data subjects may exercise rights via our DPO or national Supervisory Authorities.
- 50. California (CCPA / CPRA): California consumers have rights to know, delete, correct, opt-out of data sale/sharing, and receive non-discriminatory service.
- 51. Australia (Privacy Act): Managed in accordance with the 13 Australian Privacy Principles (APPs).
- 52. International Users: Use of AfriEv implies understanding of international data hosting under approved transfer safeguards.
53 – 57. IMPACT ASSESSMENTS, TRAINING & POLICY CHANGES
AfriEv conducts Data Protection Impact Assessments (DPIAs) for high-risk features, maintains internal Records of Processing Activities (ROPAs), provides mandatory employee privacy training, and reviews this policy annually.
58. CONTACT US
For questions, privacy requests, or regulatory inquiries, contact:
AfriEv (Sfaret Technologies)
Privacy & Data Protection Department
Email: privacy@afriev.com.ng
General Support: hello@afriev.com.ng
Address: 620 Ikwerre Road, Port Harcourt, Nigeria
Telephone: +234 704 951 5934
59 – 63. LEGAL TERMS & NON-DISCRIMINATION
- 59. Request Process: Submit requests to privacy@afriev.com.ng with sufficient identity verification. Handled within 30 statutory days.
- 60. No Retaliation: AfriEv will never discriminate against or deny services to any individual exercising privacy rights.
- 61. Severability: If any provision is found unenforceable, remaining sections remain in full effect.
- 62. Governing Law: Interpreted primarily under the laws of the Federal Republic of Nigeria, without restricting mandatory regional consumer protections.
- 63. Notice: AfriEv maintains operational compliance aligned with actual technical architecture, hosting, and encryption practices.
64. DOCUMENT CONTROL
| Field | Information |
|---|---|
| Document | AfriEv Master Privacy Policy |
| Version | 1.0 |
| Owner | AfriEv Legal, Privacy & Compliance Department |
| Effective Date | September 18, 2026 |
| Last Review | September 18, 2026 |
| Approved By | AfriEv Board of Directors / DPO Lead |
| Status | Active Operational Policy |