Effective Date: July 2026
Data Controller: Devatop Centre for Africa Development
Devatop Centre for Africa Development adheres to strict privacy principles: Lawfulness, Fairness, Transparency, Purpose Limitation, Data Minimization, Accuracy, Storage Limitation, Integrity, Confidentiality, and Accountability.
This Privacy Policy regulates how Devatop Centre for Africa Development collects, uses, processes, and safeguards the personal information of its users.
In line with the provisions of the Nigeria Data Protection Act (NDPA) 2023, the General Data Protection Regulation (GDPR) of the European Union, the Australian Privacy Act (AU), U.S. State Privacy Laws, the Personal Information Protection and Electronic Documents Act (PIPEDA) of Canada, the African Union Convention on Cybersecurity and Personal Data Protection, and other applicable global data privacy frameworks, Devatop Centre for Africa Development adheres to strict privacy principles. These principles govern how we collect, use, record, organize, structure, store, adapt, retrieve, disclose, restrict, erase, or otherwise manage your personal data (“processing”).
Your privacy is important to us. It is our policy to respect your privacy and comply with any applicable law and regulation regarding any personal information we may collect about you across DEVATOP websites, and all associated services, platforms, or data processing mediums (collectively referred to as the “Platforms”).
As the Data Controller, we understand and respect the privacy rights of all natural persons who interact with us. These individuals are our Data Subjects.
1. Scope of This Policy
This policy applies globally to all visitors to our websites (including www.devatop.org) and related digital platforms, regardless of their geographic location. It governs data collected directly through our Platforms and does not apply to any offline or external activities engaged in outside of our services.
2. Information We Collect
The information we collect falls into two distinct categories: Voluntarily Provided Information and Automatically Collected Information.
Voluntarily Provided Information: Refers to any information you knowingly, actively, and willingly provide to us while registering, reporting a case, or interacting with our services.
Automatically Collected Information: Refers to any technical metadata automatically sent by your device or web browser in the course of accessing our Platforms.
2.1 Personal Information
We may collect and process the following personal data:
Identity Information: Name, email address, phone number, gender, age, and location.
Location Information: Real-time geo-location data (only when explicitly permitted by the user via device settings).
Account Details: Username, profile preferences, and authentication logs.
Device Information: Operating system type, device model, unique device identifiers, and browser type.
2.2 Information About Abuses (Case Reporting)
Detailed reports of human rights abuses, which may include sensitive personal data regarding victims, witnesses, or alleged perpetrators.
2.3 Non-Personal and Analytical Information
Anonymized usage patterns, traffic metrics, and aggregated data that do not identify you directly.
2.4 Data Relating to Minors
In the course of our child protection and anti-trafficking mandate, we may receive, process, and store personal data relating to individuals under the age of 18, including as reported victims, witnesses, or subjects of case reports submitted by third parties.
We recognize that children’s data requires heightened protection under the NDPA, GDPR, and other applicable frameworks. Accordingly:
1. Data relating to minors is collected only where necessary to facilitate case management, protection interventions, or legal compliance.
2. Access to case data involving minors is restricted to authorized case managers and verified child protection partners on a strict need-to-know basis.
3. Where a report is submitted on behalf of a minor by a parent, guardian, or authorized third party, we rely on substantial public interest (child protection/human rights advocacy), legal obligation, and vital interests as our legal bases for processing.
4. We do not use data relating to minors for marketing, profiling, or any purpose beyond case management, protection response, and legal compliance.
5. Any party who becomes aware of a data protection concern involving a minor’s information may contact our Data Protection Officer directly for priority review.
3. How We Use Your Information
Information gathered through DEVATOP platforms is utilized strictly for the following purposes:
Case Management: To facilitate, record, and track reports of human rights abuses.
Actionable Response: To coordinate interventions regarding reported human rights abuses.
User Optimization: To personalize platform features, enhance layout, and improve user experiences.
Support Services: To provide technical assistance and respond to user inquiries.
System Improvements: To optimize platform health through anonymized usage analytics and feedback.
Legal & Safety Compliance: To uphold statutory legal obligations and protect public/user safety.
4. Legal Basis for Processing
We process personal information under the following legal frameworks:
User Consent: Explicitly obtained during account creation, form submissions, or prior to collecting sensitive information.
Legitimate Interests: To improve platform functionality, secure our infrastructure, and drive human rights advocacy.
Legal Obligation: To comply with statutory legal processes, judicial warrants, or law enforcement mandates.
4.1 Information Sharing and Case Management
In fulfillment of our organizational mandate, reported human rights abuses are shared with verified legal entities responsible for responding to such violations. These entities include:
Anti-human trafficking agencies (e.g., NAPTIP)
National and international human rights commissions
Relevant law enforcement authorities within the country of operation
Note on Confidentiality: All case managers, external experts, and legal entities operate under strict confidentiality and data protection agreements, regardless of the country in which they operate.
4.2 Third-Party Service Providers
We partner with trusted third-party service providers to handle operational infrastructure, including cloud storage, internet connectivity, data analytics, software development, and cybersecurity defense. All such vendors are strictly bound by non-disclosure and data processing agreements.
5. Data Storage, Retention, and Security
5.1 Security Measures
We implement robust technical and organizational security protocols to shield your information from unauthorized access, loss, or alteration:
Encryption: Sensitive data is encrypted both in transit (via SSL/TLS) and at rest on secure cloud servers.
Access Controls: Access to personal or sensitive data is tightly restricted to authorized personnel and verified case managers via role-based access control.
Audits: Periodic infrastructure security reviews and vulnerability assessments are conducted.
Staff Training: Mandatory, regular data privacy and security training for all case managers and technical personnel.
Disclaimer: While we execute industry-standard measures to protect your data, no method of electronic transmission or cloud storage is 100% secure. We cannot guarantee absolute security.
5.2 User Security Responsibilities
Users play a vital role in maintaining platform security. We strongly advise that you:
Utilize unique, strong passwords for your accounts.
Log out of the platform after use.
Refrain from sharing account access or login credentials with third parties.
Maintain the security of your physical device.
5.3 Data Retention
We retain personal information only for the duration necessary to fulfill the specific purposes outlined in this policy.
Abuse Reports: Information regarding human rights violations is retained for as long as required to resolve investigations, maintain documentation, and uphold accountability mandates.
Once information is no longer operationally or legally required, it is completely deleted or strictly anonymized to prevent re-identification.
5.4 Data Breach Notification
In the event of a personal data breach that poses a risk to the rights and freedoms of affected individuals, we will:
Assess and, where required, notify the relevant supervisory authority without undue delay, and in any case within the timeframe required by applicable law (e.g., 72 hours under GDPR, or as prescribed by the NDPA).
Notify affected individuals directly where the breach is likely to result in a high risk to their rights, freedoms, or safety, particularly in cases involving sensitive case-reporting data.
Take immediate remedial steps to contain the breach and mitigate any resulting harm.
4 Document the breach, our assessment, and the actions taken, for accountability and regulatory purposes.
6. External Links
Our Platforms may contain links to external web tools or websites not operated by us. We hold no control over, and assume no responsibility for, the content, privacy policies, or practices of third-party websites. We strongly recommend reviewing the privacy policies of any third-party links you visit.
7. Your Rights under the NDPA, GDPR, and Global Frameworks
We recognize and respect your comprehensive statutory rights as a Data Subject. You possess the following rights:
Right to Be Informed: The right to know how your data is collected and processed.
Right of Access: The right to request copies of your personal data held by us.
Right to Rectification: The right to request correction of inaccurate or incomplete information.
Right to Object/Restrict Processing: The right to limit or object to how we use your data.
Right to Data Portability: The right to request a transfer of your data to another organization.
Right to Erasure (The Right to Be Forgotten): The right to request deletion of your personal information, subject to overriding legal or case-management mandates.
Right to Human Intervention: The right to contest decisions based solely on automated processing.
7.1 Withholding of Mandatory Information
Please note that certain identity and contact data points are mandatory for case managers to investigate reported abuses or follow up for critical clarifications. Withholding this required information may make it impracticable for us to process your reports or fulfill our case intervention mandate.
8. International Data Transfers
To host data and manage cases globally, the information we collect may be transferred to and stored in countries outside your local jurisdiction. Where cross-border data transfer occurs, we ensure compliance with transfer mechanisms dictated by the NDPA, GDPR, and other governing regional privacy laws to maintain an equivalent standard of protection.
9. Cookies and Tracking Technologies
We utilize cookies and similar identifiers on our websites to:
Optimize system functionality and page layout.
Analyze user engagement and traffic trends.
Deliver secure, personalized sessions.
You can modify your browser settings to reject cookies, though doing so may limit your access to certain website features.
10. Remediation and Grievance Handling
If you have concerns, complaints, or suspect an infringement regarding how your data is managed, please contact our designated Data Protection Officer (DPO). The DPO will investigate and resolve complaints within 21 working days. If an investigation requires an extension, you will be notified promptly with an explanation and an updated resolution timeline.
11. Updates to This Policy
We may update this Privacy Policy periodically to reflect shifts in international legal frameworks or operational updates. Significant revisions will be communicated directly through conspicuous website announcements or direct email alerts.
12. Contact Us
If you have questions, wish to exercise your data subject rights, or wish to report a privacy concern, please contact our Data Protection Team:
Data Protection Officer / Technical Unit: [email protected] / [email protected]
Official Address: Devatop Centre for Africa Development, Kings Park Estate IV, Kukwaba District by Galadimawa R/about, Abuja, Nigeria.
Phone Channel: +234 806 725 1727 and +234 903 000 2362