Privacy Policy

Last updated: To be confirmed on publication

This policy explains what personal data Preenio collects, why we use it, who we share it with, and the rights available to you under Nigerian data protection law.

1. About this policy

This policy explains how we collect, use, share, retain, and protect personal data when you use the Preenio website, applications, and related services (the "Platform"). It applies to customers, to businesses that list on the Platform, and to visitors.

We process personal data in accordance with the Nigeria Data Protection Act 2023 and subsidiary instruments issued by the Nigeria Data Protection Commission.

Please read this policy together with our Terms of Service.

2. Who is responsible for your data

Preenio Nigeria Limited, a company incorporated in Nigeria with registration number [RC NUMBER] and registered office at [REGISTERED OFFICE ADDRESS], is the data controller in respect of the processing described in this policy.

You may contact us about data protection at privacy@preenio.com.

Where a Provider you book with collects or uses information about you for its own purposes, including anything you tell it directly at or before an appointment, that Provider acts as a separate and independent data controller. It is responsible for its own handling of your data and for its own compliance obligations, and this policy does not cover that processing.

3. Personal data we collect

We collect the following categories of personal data:

  • Account data: your name, email address, Nigerian mobile telephone number, authentication credentials held by our identity provider, and any profile image you upload.
  • Booking data: the Services you select, the Provider and any staff member chosen, appointment dates and times, notes you enter, and the status and history of your bookings.
  • Payment and transaction data: amounts, currency, payment method type, transaction and authorisation references, wallet balances and movements, refunds, vouchers, gift cards, and promotional codes applied. Full payment card numbers are handled by our payment service provider and are not stored by us.
  • Communications data: messages and support requests you send us, and records of confirmations, reminders, and notifications sent to you by email or SMS.
  • Technical data: internet protocol address, device and browser type, operating system, pages viewed, timestamps, referring pages, and diagnostic and error logs.
  • Location data: approximate location derived from your internet protocol address, and, where you choose to enable it, more precise location used to show Providers near you.

We do not ask you to provide sensitive personal data through the Platform. If a Service depends on information about your health, such as an allergy, skin condition, medication, or pregnancy, please give that information directly to the Provider at or before your appointment rather than entering it into free text fields on the Platform.

4. How we collect personal data

  • Directly from you, when you register, make a booking, buy a voucher or gift card, contact support, or complete a form.
  • Automatically, through cookies and similar technologies, as you use the Platform.
  • From Providers, when they record, update, cancel, or complete a booking.
  • From our service providers, including our identity provider and payment service provider, in relation to authentication, payment authorisation, and fraud screening.

5. Why we use personal data, and our lawful basis

We rely on the following lawful bases under section 25 of the Nigeria Data Protection Act 2023:

  • To create and administer your account, and to authenticate you: performance of a contract with you.
  • To process bookings, take payment, operate wallets, vouchers, gift cards, and refunds: performance of a contract with you.
  • To send booking confirmations, reminders, changes, and other service messages: performance of a contract with you.
  • To provide customer support and handle complaints: performance of a contract with you, and our legitimate interests in resolving issues.
  • To detect, investigate, and prevent fraud, abuse, and security incidents: our legitimate interests in protecting the Platform, its users, and Providers, and compliance with legal obligations.
  • To maintain, secure, troubleshoot, and improve the Platform: our legitimate interests in operating a reliable and secure service.
  • To send marketing communications about Preenio: your consent, which you may withdraw at any time.
  • To meet tax, accounting, audit, regulatory, and law enforcement obligations: compliance with a legal obligation.
  • To establish, exercise, or defend legal claims: our legitimate interests in protecting our legal position.

Where we rely on legitimate interests, we have considered whether those interests are overridden by your interests and rights, and you may object as described in the section on your rights.

6. Who we share personal data with

  • The Provider you book with, to the extent needed to deliver the Service. This ordinarily includes your name, contact details, the Service booked, the appointment time, and any notes you added.
  • Our identity and authentication provider, for account creation and sign in.
  • Payment service providers licensed by the Central Bank of Nigeria, for authorisation, settlement, refunds, and chargeback handling.
  • Email and SMS delivery providers, for confirmations, reminders, and account notifications.
  • Cloud hosting, database, media storage, and content delivery providers.
  • Analytics, logging, and error monitoring providers, to keep the Platform working.
  • Professional advisers, including lawyers, auditors, accountants, and insurers, where reasonably required.
  • Regulators, law enforcement agencies, and courts, where disclosure is required by law or is necessary to establish, exercise, or defend legal claims.
  • A purchaser or successor, in connection with a sale, merger, reorganisation, or transfer of all or part of our business, subject to appropriate confidentiality protections.

We require our processors to act only on our documented instructions and to apply appropriate security measures.

We do not sell your personal data.

7. Cookies and similar technologies

  • Strictly necessary cookies, which support sign in, session management, and security. The Platform cannot function properly without these.
  • Functional storage, which remembers preferences such as the contents of your booking cart.
  • Analytics and performance cookies, which help us understand how the Platform is used, where you consent to them.

You can control or delete cookies through your browser settings. Blocking strictly necessary cookies will prevent parts of the Platform from working.

8. Storage and transfers outside Nigeria

Personal data may be stored or processed outside Nigeria by service providers such as our hosting, identity, payment, messaging, and media providers.

Where personal data is transferred outside Nigeria, we do so on a basis permitted by the Nigeria Data Protection Act 2023, which may include a determination of adequacy, appropriate contractual safeguards with the recipient, or another lawful ground such as necessity for the performance of a contract with you.

9. How long we keep personal data

We keep personal data only for as long as is necessary for the purposes described in this policy, after which we delete it or render it anonymous.

  • Account data is retained while your account remains open, and for a period afterwards to handle disputes, chargebacks, and legal obligations.
  • Booking, payment, wallet, and transaction records are retained for the period required for tax, accounting, and audit purposes, and for so long as a legal claim may be brought.
  • Communications and support records are retained for as long as needed to resolve the matter and evidence its resolution.
  • Technical and security logs are retained for a shorter period, appropriate to their purpose.

10. Security

We apply technical and organisational measures appropriate to the risk, including encryption of data in transit, access controls and role based permissions, credential handling by a specialist identity provider, rate limiting, and monitoring and logging.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your login credentials confidential and for notifying us promptly of any suspected unauthorised access.

11. Your rights

Subject to the conditions and exemptions in the Nigeria Data Protection Act 2023, you have the right to:

  • request access to the personal data we hold about you
  • request correction of personal data that is inaccurate or incomplete
  • request deletion of personal data where there is no continuing lawful basis to keep it
  • request restriction of processing in certain circumstances
  • object to processing carried out on the basis of our legitimate interests
  • request portability of personal data you provided to us, in a structured, commonly used, machine readable format
  • withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal
  • not be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you

To exercise any of these rights, contact privacy@preenio.com. We may ask you to verify your identity before we act. We will respond within the period required by law.

Some rights are qualified. We may decline a request where we are required or permitted by law to retain the data, for example to meet accounting obligations or to defend a legal claim, and we will explain our reasons.

12. Marketing

Messages relating to your bookings and account, including confirmations, reminders, changes, and security notices, are service messages. They are necessary to provide the Platform and are not marketing.

Marketing messages about offers and new features are sent only with your consent. Every marketing message includes a means of opting out, and you may withdraw consent at any time through your account settings or by contacting us.

13. Children

The Platform is intended for use by adults aged 18 and over. We do not knowingly collect personal data from children.

If you believe a child has provided personal data to us, contact privacy@preenio.com and we will take steps to delete it.

14. Automated processing

We use automated checks to screen payments and detect fraudulent or abusive activity. These checks may result in a payment being declined or an account being flagged for review.

Where such a decision would produce a legal effect concerning you or similarly significantly affect you, it is subject to human review. You may ask us to review any such decision by contacting privacy@preenio.com.

15. Personal data breaches

We maintain procedures to detect, investigate, and respond to personal data breaches.

Where a breach is likely to result in a risk to your rights and freedoms, we will notify the Nigeria Data Protection Commission and, where required, affected individuals, within the timeframes set by the Nigeria Data Protection Act 2023.

16. Changes to this policy

We may update this policy from time to time. The revised version takes effect when published on the Platform, and the date at the top of this page will be updated.

Where changes are material, we will take reasonable steps to bring them to your attention.

17. Contact and complaints

For any question about this policy or about how we handle your personal data, contact privacy@preenio.com, or write to Preenio Nigeria Limited, [REGISTERED OFFICE ADDRESS].

If you are not satisfied with our response, you may lodge a complaint with the Nigeria Data Protection Commission.