1. Who can ask for what
| You can ask for… | Section |
|---|---|
| A copy of your data (“access”) | §3 |
| A correction to inaccurate data | §4 |
| Deletion of your data (“right to be forgotten”) | §5 |
| A portable, machine-readable export | §6 |
| Restriction or objection to processing | §7 |
| Withdrawal of consent | §8 |
| Confirmation that your data has been deleted | §9 |
| To complain or appeal our decision | §11 |
Authorities (Nigerian and foreign) can make different kinds of requests — those are handled under §13.
2. How to submit a request
Email [email protected] with the subject line “Data request — [your action]”. Include:
- Your full name and the email or phone on the account. If you no longer remember which email you signed up with, include any accounts or transaction references that may help us find you.
- The action you want (access / correction / deletion / export / restriction / objection / consent withdrawal).
- Scope — all data, or a specific kind (e.g. “donations only”).
- Verification material — see §10. We will not act on a request until we are reasonably confident it is from you.
For most requests you can also use the in-app shortcuts:
- Profile → Edit profile to correct your own profile data.
- Profile → Sign out → Delete account to close and erase your account (subject to retention obligations — see §5.2).
- Profile → Settings to opt in / out of push, email notifications, language, location sharing, AI features.
You do not need a lawyer or a formal letter to submit a request.
3. Right to access
You can ask for a copy of the personal data we hold about you.
What you’ll get
- Profile — name, email, phone, username, photo, bio, country / state / LGA, AAC member ID (if linked), creation date, last login.
- Posts and comments you’ve published.
- Reactions you’ve left.
- RSVPs and volunteer requests.
- Donations — amount, currency, campaign, payment method, paid date, and the tokenised payment reference. Card numbers are never in our system.
- Saved addresses.
- Linked accounts — which providers (AAC, future X / Facebook / IG / TikTok) you’ve connected and when. We do not include the OAuth tokens themselves.
- Notifications received and your notification preferences.
- Reports you submitted (subject + reason + status).
- AI feature usage counters (no prompt content).
- Points & rank — your balance, level, and your points ledger (each earn / spend entry).
- Referrals — your referral code, who referred you (if anyone), and referral awards credited to you.
- Point claims & support redemptions — the claims and reward requests you submitted, their status, and any reviewer note (the evidence file itself is included in the attachments archive).
Format
A JSON archive, plus binary attachments (photos, video, voice notes) in the relevant media/ directory. Machine-readable and human-readable.
Turnaround
- NDPA / NDPR: within 7 working days.
- GDPR: within 30 days.
- CCPA: within 45 days.
We may extend by 60 days for unusually complex requests, with notice.
4. Right to rectification
You can correct any inaccurate or out-of-date data about yourself.
Self-service
Most fields are editable in Profile → Edit profile (name, photo, bio, state / LGA, AAC member ID) and Settings (language, notification preferences).
When you need us
You need to email [email protected] for:
- Changing the email or phone on file (verification required).
- Correcting a donation record (we will keep an audit trail of the correction for tax compliance).
- Restoring a deleted post or comment (only if deletion was within the last 7 days and we still have a backup snapshot).
We complete rectification within 7 working days.
5. Right to deletion (“right to be forgotten”)
5.1 How to delete your account
The fastest way is Profile → Sign out → Delete account.
Within 30 days of confirmation, we hard-delete:
- Your profile, password hash, verification rows, sessions.
- Your community posts, comments, reactions, reports you submitted.
- Your messages and group-chat memberships (other participants in your group chats will see a “Deleted user” tombstone on the messages you sent).
- Your RSVPs, volunteer requests, saved addresses, push tokens, notification preferences.
- Your points balance, rank, points ledger, referral code and referral attributions, and your point claims and support redemptions (including any evidence files). Unredeemed points and unfulfilled rewards are forfeited with no compensation.
- Your linked-account OAuth tokens. (The link rows themselves are retained for 90 days as a tombstone for audit; the actual credentials are erased.)
5.2 What we cannot delete
We are required by Nigerian law to keep some data even if you delete your account:
- Donations and other financial records — kept for 7 years (Finance Act, FIRS rules). The personal fields on the donation record (your name, email, phone) are pseudonymised so we hold only what tax law requires.
- Records of safety-incident reports or moderation actions involving you — kept for 12 months so a banned account can’t resurface trivially.
- System logs and backups — purge on their own retention schedule (30 days for ordinary logs, up to 12 months for security events). The data remains inaccessible to staff outside the security team.
We will tell you exactly what is retained and why when you delete.
5.3 Deletion timeline
| Time after you confirm | What happens |
|---|---|
| Immediately | Account marked deleted, you’re signed out, public profile and posts removed. |
| Within 24 h | Push tokens revoked, sessions invalidated. |
| Within 30 days | Hard-delete from primary database. |
| Within 90 days | Tombstone purged. |
| 7 years | Tax-retained donation pseudonyms fully erased. |
6. Right to portability
You can ask us to send your data to you (or, where technically feasible, directly to another service) in a structured, machine-readable format. We use the same JSON archive as for access requests (§3).
Direct transfer to a third party — for example exporting your post history to a different community platform — is supported on a best-effort basis; the receiving platform must accept JSON.
7. Right to restriction & objection
You can ask us to stop processing your data for a specific purpose without deleting your account. Common examples:
- “Stop using my data for AI summaries.” — We turn off AI features for your account.
- “Stop sending me push notifications.” — Settings → Notification preferences (no email needed).
- “Stop showing my profile to nearby supporters.” — Disable location sharing under Settings.
- “Stop including my donations in public totals.” — We make your donations anonymous from the date of the request.
We confirm restriction within 7 working days.
8. Right to withdraw consent
For features you opted into — push notifications, marketing email, location sharing, AI assistance, social cross-posting, AAC link — you can withdraw consent at any time:
- In Settings, or
- By emailing [email protected].
Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
9. Confirmation of action
When we complete an access, deletion, restriction or rectification request, we send you a confirmation email with:
- The action taken.
- The retention exceptions, if any.
- The date everything was completed.
Save this email — it is your evidence of our compliance.
10. Verifying your identity
Before we act on a request that could expose or destroy data, we need to be reasonably confident the request is genuinely from you. What we accept:
| Request | Verification |
|---|---|
| Access / portability | Reply from the email or phone on file. |
| Rectification | Same. |
| Deletion | Reply from the email AND a one-time code we send to the phone on file (or vice versa). |
| High-risk (e.g. you have changed both email and phone in the last 30 days) | Government-issued photo ID matching the name on file, redacted to the parts we need (full name + photo). The ID copy is held only until the request is processed, then deleted. |
If you cannot pass identity verification (e.g. you lost access to both email and phone), we can guide you through a delayed verification process. We will never accept a third-party password manager or social-media “screenshot” as proof.
11. Complaints & appeals
If you are unhappy with how we handled your request, you can:
- Escalate internally — reply to the same thread and ask for the Data Protection Officer to re-review. We respond within 14 days.
- Complain to the regulator:
- Nigeria — Nigeria Data Protection Commission: https://ndpc.gov.ng / [email protected].
- EU / UK — your local Data Protection Authority.
- California — California Privacy Protection Agency: https://cppa.ca.gov.
- Sue us. Nothing in this policy waives your right to a judicial remedy.
We would always rather hear from you first.
12. Special categories of data
Some data we hold about you is treated as special category / sensitive personal data:
- Political opinions — your support of the Take It Back Movement, your community posts, your AAC link.
- Financial data — your donation history.
- Biometric-adjacent data — your profile photo if it could be used for facial recognition.
These attract extra protection:
- Access and deletion requests are reviewed by a human DPO (no automated decision-making).
- We do not export them to providers outside Nigeria except where the provider’s own contract provides equivalent protection (see Privacy Policy §8).
- Deletion is irreversible — once gone, they cannot be reconstructed from backups.
13. Requests from authorities
We respond to formal requests from courts and regulators.
13.1 What we require
- A valid Nigerian court order, properly served, or
- A valid lawful-disclosure notice from a regulator with jurisdiction (NDPC, EFCC, NFIU, NCC, NITDA), or
- For foreign requests, an order obtained via the Mutual Legal Assistance Treaty the relevant country has with Nigeria — we do not respond directly to foreign police requests.
13.2 What we will not do
- Provide bulk dumps of supporter data.
- Provide the contents of private messages without a specific, narrowly-drawn court order.
- Provide identifying information about reporters or whistleblowers without a court order specifically naming them.
- Disclose contributor lists to a political opponent or partisan body except where compelled by law.
13.3 Notice to the affected user
Unless we are gagged by the order itself, we will notify the affected user before complying, so that they can challenge the order. This is consistent with NDPA §44.
13.4 Transparency
We publish an annual Transparency Report at https://soworenow.org/legal/transparency listing the number of formal requests we received, by category, and how many we complied with (without identifying users).
14. Emergency requests
For genuine life-safety emergencies — credible threat of suicide, ongoing physical harm — law enforcement can email [email protected]. We require:
- The requesting agency’s official email domain.
- A short statement of the emergency.
- The minimum data needed to act.
We respond within 4 hours where possible and document every emergency disclosure for the next Transparency Report.
15. Children’s data
If you believe a SoworeNow account belongs to someone under 18, email [email protected] with the relevant detail. We will verify and, if the account does belong to a minor, delete it within 7 days.
If you are a parent / legal guardian acting on a minor’s behalf, provide:
- Proof of guardianship (a Nigerian birth certificate naming you, or an equivalent document).
- Your own ID for identity verification.
16. Account inheritance (“deceased user”)
If a SoworeNow user has died and you are the legal next of kin or executor, contact [email protected] with:
- A copy of the death certificate.
- Proof you are the next-of-kin / executor (will, letters of administration).
- Your own ID for identity verification.
We can either:
- Memorialise the account — freeze it, hide the “last seen” state, but keep the posts visible.
- Delete the account — same process as §5.
Donations attributed to the deceased are governed by Nigerian estate law and will be addressed individually.
17. Cost
There is no fee for any of these requests except in two cases:
- Requests that are manifestly unfounded or excessive (e.g. more than one full-data export in 90 days).
- Requests for physical copies of records — we charge the printing + courier cost only.
We will tell you the fee before doing any chargeable work and you can withdraw the request.
18. Contact
| Channel | Address |
|---|---|
| Data requests / DPO | [email protected] |
| Emergency requests | [email protected] |
| Security disclosure | [email protected] |
| Legal / authorities | [email protected] |
| General support | [email protected] |
Postal address:
Take It Back Movement (SoworeNow)
[Registered office, Nigeria]
Attn: Data Protection Officer
We will acknowledge any email within 3 working days and resolve or update you on every request within the timeframes set in §§3, 4 and 5.
19. Updates to this policy
We may update this policy. Material changes are announced by email and in-app at least 14 days before they take effect. Older versions are archived at https://soworenow.org/legal/data-requests.
This document is the plain-English version. The authoritative legal text — if and where it differs — is the version filed with the Nigeria Data Protection Commission and available on request.