NDPA 2023 · v1.0
Henry Onyx processes personal data as a data controller under the Nigeria Data Protection Act 2023. This policy names every category of data collected, the lawful basis under NDPA §25, the sub-processors who receive data on the controller's behalf, the retention windows tied to statute, and the rights every data subject can exercise. The canonical version is English; 11 locales are available for reference.
Some content may still be refreshing.
1. Controller identity
Henry Onyx Limited (RC 9594234), trading as Henry Onyx, with registered office at 001 Airport Road, Emene, Enugu State, Nigeria , is the data controller for personal data processed across henryonyx.com and every division surface. NDPC registration: [OWNER-TO-CONFIRM: NDPC registration reference]. Data Protection Officer: [OWNER-TO-CONFIRM: DPO name + email + phone, or 'External DPO consulted on material changes'].
— In plain English: One Nigerian company runs all the Henry Onyx divisions, and it is the entity legally answerable for how your data is handled.
Henry Onyx Limited
9594234
Emene, Enugu State
[OWNER-TO-CONFIRM: NDPC registration reference]
[OWNER-TO-CONFIRM: DPO name + email + phone, or 'External DPO consulted on material changes']
2. Lawful bases
Every processing activity on this platform rests on one or more lawful bases listed in NDPA 2023 §25. The basis used for each activity is named alongside the data category in the next section. We do not rely on a generic "applicable law" phrasing — each ground is cited.
— In plain English: For every kind of data we touch, we name the legal reason we are allowed to touch it, instead of waving at "the law".
Newsletter signup, WhatsApp opt-in, marketing push notifications, optional analytics cookies.
Order fulfilment, logistics pickup, care booking, studio milestones, learn enrolment, property viewing coordination.
KYC under CBN AML/CFT Regulations, transaction records under CITN/CAMA, audit-log retention under CBN guidance.
Emergency contact in safety-critical incidents during logistics dispatch or care home visits.
Fraud-prevention signals shared with FCCPC or NDPC on lawful request.
Trust scoring, device-risk signals, abuse prevention, service security — each balanced against the data subject's rights.
3. Categories of personal data
The categories below are concrete. Each row names the data, the purpose it serves, and the lawful basis under NDPA §25. The list replaces the rubric-banned phrasing "information we may collect" — we collect these categories, full stop.
— In plain English: This is the exact list of personal data we hold, paired with the reason we hold it.
Full name, date of birth, nationality, photograph. Purpose: Account creation, KYC verification, signed-document attribution. Lawful basis: Contract (§25(1)(b)); legal obligation for KYC (§25(1)(c)).
Email address, phone number, postal address. Purpose: Order updates, support correspondence, delivery, statutory notices. Lawful basis: Contract (§25(1)(b)); legitimate interests for security-critical notifications (§25(1)(f)).
NIN, BVN, government-ID image, selfie liveness, address proof. Purpose: AML/CFT screening, payout eligibility, fraud prevention. Lawful basis: Legal obligation under CBN AML/CFT Regulations and Money Laundering (Prevention and Prohibition) Act 2022 (§25(1)(c)).
Bank account, payment-method token (processed by our PCI-compliant payment processor; Henry Onyx does not store full card numbers), payout history, wallet balance, invoices. Purpose: Order settlement, vendor payout, refund processing, tax reporting. Lawful basis: Contract (§25(1)(b)); legal obligation for tax records (§25(1)(c)).
Order content, line items, shipping addresses, dispatch and proof-of-delivery records, ratings. Purpose: Fulfilment, dispute resolution, performance analytics within a tenant. Lawful basis: Contract (§25(1)(b)); legitimate interests for analytics (§25(1)(f)).
Support messages, hiring messages, studio briefs and assets, listing photos, proof-of-delivery photos, claim evidence, audio and video from booked sessions (recorded only with explicit consent screen). Purpose: Service delivery, dispute evidence, training data only with explicit opt-in. Lawful basis: Contract (§25(1)(b)); consent for recordings (§25(1)(a)); legitimate interests for dispute evidence (§25(1)(f)).
Page views, search queries, click paths, time-on-task, conversion events. Purpose: Service improvement, A/B testing, fraud signals. Lawful basis: Legitimate interests (§25(1)(f)); consent where analytics cookies are non-essential (§25(1)(a)).
IP address, browser, OS, device identifier, device-risk visitor ID, locale. Purpose: Session security, abuse prevention, trust scoring. Lawful basis: Legitimate interests (§25(1)(f)).
Email open/click events, WhatsApp delivery receipts, push-notification delivery, support-ticket timestamps. Purpose: Deliverability, SLA tracking, opt-out enforcement. Lawful basis: Legitimate interests (§25(1)(f)); contract for transactional notifications (§25(1)(b)).
Trust score, risk flags, vendor performance bands, learner skill maps. Purpose: Fraud prevention, marketplace ranking, certification eligibility. Lawful basis: Legitimate interests (§25(1)(f)); contract for ranking (§25(1)(b)).
4. Purposes paired with categories
Purposes are not stated in abstract — they are paired one-to-one with the data category that serves them in section 3. The categories table is the authoritative reference. If a new purpose is added, the categories table is updated and the policy version is bumped per section 17.
— In plain English: Every purpose maps back to exactly one or two data categories. Nothing is collected for vague "future use".
Identity, contact, transaction, financial, content categories
KYC and identity-verification category under CBN AML/CFT Regulations
Device, behavioural, and inferred categories
Contact, content, communication-metadata categories
Behavioural and inferred categories (consent for non-essential analytics)
Contact and behavioural categories (consent only; transactional notifications are contractual)
5. Sub-processors
These are the named sub-processors that receive personal data to help operate the platform. Each is bound by a written data-processing agreement and is selected for capability, security posture, and jurisdictional fit. Changes to this list are announced in advance under section 17.
— In plain English: These specific companies help us run the platform. We name them rather than saying "third-party service providers".
Database, authentication, and file storage. Region: European Union and United States.
Application hosting. Region: European Union and United States.
Image storage and delivery. Region: Global.
Card and bank payment processing. Region: United States.
Transactional email delivery. Region: United States.
Editorial and newsletter email delivery. Region: European Union.
Application error monitoring. Region: United States.
Push notification delivery. Region: United States.
Video and voice calls for studio and jobs interviews. Region: United States.
Electronic signature for contracts and proposals. Region: United States.
Device-risk and abuse signals. Region: United States and European Union.
Translation services. Region: European Union.
SMS notifications. Region: United States.
Mapping and routing for logistics and property. Region: United States.
Search index. Region: European Union.
WhatsApp messaging for support and order updates. Region: Global.
Address autocomplete and booking calendar sync. Region: United States and European Union.
Support-ticket intake and routing. Region: United States and India.
6. International data transfers
Personal data may leave Nigeria when processed by a sub-processor named in section 5 with infrastructure outside Nigeria. Transfers rely on adequacy decisions where they exist, on Standard Contractual Clauses Module 2 (controller-to-processor) issued by the European Commission, and on the UK International Data Transfer Addendum for UK-origin data subjects. The lawful basis for transfer is set out under the Nigeria Data Protection Act 2023, supported by NDPC's general guidance on cross-border transfers.
— In plain English: When your data is processed outside Nigeria, we use the same standard contracts the EU and UK use to make sure your protections travel with it.
European Union, United Kingdom, United States
SCCs Module 2 (controller-to-processor) + UK IDTA
Nigeria Data Protection Act 2023 + NDPC general guidance
Encryption in transit and at rest, named regions, regular DPA review
7. Retention periods
Retention is tied to the statute that drives it, not to vague phrasing. Concrete windows below. Where multiple statutes apply, the longest applicable window controls.
— In plain English: We keep data for a specific number of years tied to a specific Nigerian law, then it is deleted.
5 years after account closure. Driver: CBN AML/CFT Regulations 2022.
7 years after transaction close. Driver: CAMA 2020 and CITN guidance.
3 years after ticket close. Driver: FCCPA 2018 dispute window.
7 years. Driver: CBN cyber-resilience guidance.
13 months. Driver: NDPA 2023 cookie guidance + GDPR e-Privacy alignment.
90 days suppression only, then deleted. Driver: NDPA 2023 §37.
30 days soft-delete window, then permanent erasure subject to legal-hold exceptions. Driver: NDPA 2023 §36.
8. International users
Users outside Nigeria retain rights under their home data-protection framework, including (where applicable) the EU/EEA GDPR, UK GDPR, California CCPA/CPRA, Brazil LGPD, South Africa POPIA, Kenya Data Protection Act 2019, Ghana Data Protection Act 2012, Singapore PDPA 2012, Canada PIPEDA, and Australia Privacy Act 1988. The regulator route for each jurisdiction is listed below.
— In plain English: If you live outside Nigeria, your home country's privacy law still protects you, and you can complain to its regulator.
Regulator: Nigeria Data Protection Commission (NDPC). Route: complaints@ndpc.gov.ng.
Regulator: Your national supervisory authority. Route: https://edpb.europa.eu/about-edpb/about-edpb/members_en.
Regulator: Information Commissioner's Office (ICO). Route: https://ico.org.uk/make-a-complaint/.
Regulator: California Privacy Protection Agency (CPPA). Route: https://cppa.ca.gov/.
Regulator: Autoridade Nacional de Proteção de Dados (ANPD). Route: https://www.gov.br/anpd/.
Regulator: Information Regulator (South Africa). Route: complaints.IR@justice.gov.za.
Regulator: Office of the Data Protection Commissioner (ODPC). Route: info@odpc.go.ke.
Regulator: Data Protection Commission Ghana. Route: info@dataprotection.org.gh.
Regulator: Personal Data Protection Commission (PDPC). Route: https://www.pdpc.gov.sg/.
Regulator: Office of the Privacy Commissioner of Canada (OPC). Route: https://www.priv.gc.ca/.
Regulator: Office of the Australian Information Commissioner (OAIC). Route: https://www.oaic.gov.au/.
9. Data subject rights
Every data subject has the rights set out under the Nigeria Data Protection Act 2023, including access, rectification, erasure, restriction, portability, objection, and the right not to be subject to a decision based solely on automated processing where it produces legal or similarly significant effects.
— In plain English: You can ask for your data, fix it, delete it, move it, stop us using it, and challenge automated decisions.
Request a copy of personal data held about you.
Request correction of inaccurate or incomplete data.
Request deletion subject to legal-hold exceptions named in section 7.
Request that processing be paused while a dispute is resolved.
Receive a machine-readable copy of data you provided.
Object to processing based on legitimate interests or direct marketing.
Challenge decisions based solely on automated processing with legal or significant effect.
10. How to exercise rights
Send a written request to privacy@henryonyx.com. The controller acknowledges receipt within 5 working days and responds substantively within 30 days under the Nigeria Data Protection Act 2023. Identity is verified before a request is actioned. Where a request is manifestly unfounded or excessive, a fee may be charged or the request refused with reasons.
— In plain English: Email privacy@henryonyx.com. We acknowledge in 5 working days and answer in 30 days. We verify it is really you before sending data.
privacy@henryonyx.com
dpo@henryonyx.com
5 working days
30 days (extendable once by 60 days with notice under the NDPA)
Required before action
12. Children
The platform is not directed at children under 18. The controller does not knowingly collect personal data from children under 18 without verifiable parental consent. If a child has provided data without consent, a parent or guardian should write to the privacy inbox; the data will be deleted unless retained under a legal-hold exception in section 7.
— In plain English: Under-18s should not use the site without a parent. If they do, write to us and we delete the data.
18 (with verifiable parental consent under 18)
privacy@henryonyx.com
13. Breach notification
A personal-data breach with a risk to the rights and freedoms of data subjects is reported to the Nigeria Data Protection Commission within 72 hours of becoming aware, under the Nigeria Data Protection Act 2023. Affected data subjects are notified without undue delay where the breach is likely to result in high risk. Structured logging plus a tamper-evident audit trail retained for 7 years allow forensic reconstruction.
— In plain English: If something goes wrong, we tell the regulator within 72 hours and tell affected users without delay.
Within 72 hours of becoming aware
Without undue delay where high risk
7-year audit trail + structured logging + error-tracing breadcrumbs
14. Data Protection Officer
The Data Protection Officer is the contact for any privacy concern, NDPA right exercise, or material complaint about how data is handled. [OWNER-TO-CONFIRM: DPO name + email + phone, or 'External DPO consulted on material changes']
— In plain English: The DPO is the single named person you write to about anything privacy.
[OWNER-TO-CONFIRM: DPO name + email + phone, or 'External DPO consulted on material changes']
dpo@henryonyx.com
15. Complaints
If a privacy concern is not resolved by the DPO, a complaint can be lodged with the Nigeria Data Protection Commission at complaints@ndpc.gov.ng. International users may complain to their home regulator named in section 8.
— In plain English: If we cannot solve it, you can complain to the Nigerian regulator (or your country's regulator).
complaints@ndpc.gov.ng
See section 8 for the regulator in your jurisdiction
16. Languages
This policy is published in English (canonical) and translated into 11 additional locales. In case of conflict between language versions, the English text controls.
— In plain English: English wins if a translation says something different.
English
11
17. Effective date and version
Effective 2026-05-14 · version v1.0. Material changes are emailed to account holders 14 days before they take effect and the version is bumped. Continued use after the effective date is acceptance.
— In plain English: We tell you 14 days before anything important changes, and the version number always goes up.
2026-05-14
v1.0
14 days, by email to account holders
Henry Onyx
Every Henry Onyx company surface — about, contact, governance, policy — ships under one editorial standard so what you read in public matches what we hold ourselves to in private.