Sendiflow
Privacy

Privacy Policy

How Sendiflow handles personal data, aligned to the Nigeria Data Protection Act 2023 (NDPA).

Effective date: 28 July 2026. Sendiflow is a service operated by Renovo Digital Innovations Limited (“REDI”, “we”, “us”).

1. Who we are and our role

Sendiflow is a field-reporting platform used by organisations to turn officers’ field notes into reviewed, standardised reports. In most processing, the organisation using Sendiflow decides what data is collected and why — it is the data controller. We act as a data processor, handling that data on the organisation’s documented instructions. For our own account and billing data, we are the controller.

2. The personal data we process

We do not add tracking or advertising profiling, and we do not sell personal data.

3. Why we process it, and our lawful basis

We process account data to provide, secure and support the service (lawful basis: performance of contract / legitimate interest). We process report content solely to deliver the reporting service on our clients’ instructions (lawful basis: the client’s own basis as controller, recorded in our agreement with them). Where sensitive personal data is involved, the client organisation is responsible for ensuring an appropriate lawful basis and any required consent under the NDPA.

4. Artificial intelligence and transfers outside Nigeria

To convert rough notes into formal report prose and short summaries, report text is sent to Google’s Gemini service for processing and returned. This means some content is processed on servers outside Nigeria. Report data is also hosted with our infrastructure provider, Hostinger. We rely on the cross-border transfer conditions permitted under the NDPA for these transfers, and we minimise what is sent. Our current sub-processors are: Google (AI processing) and Hostinger (hosting).

5. How we protect it

6. How long we keep it

Report data is retained for as long as the client organisation requires it for its purposes, or as required by law, and then deleted or returned per our agreement with that client. Account data is retained while an account is active. Specific retention periods are set with each client.

7. Your rights

Under the NDPA, individuals have rights including access to their personal data, rectification of inaccurate data, and deletion in defined circumstances. Because we usually act as processor, requests about report content are handled by the client organisation that controls that data; we assist them. For account data we control, contact us directly. We aim to respond within the timeframe the NDPA requires.

8. Restrictions on data uploads

The client organisation is solely responsible for ensuring that it is legally authorised to collect, use, disclose and upload any personal data processed through Sendiflow. We shall not be liable for any claim, loss, penalty or regulatory action arising from a client organisation’s unlawful collection, use, disclosure or submission of personal data. The client organisation remains solely responsible for any breach of these obligations.

9. Breaches

If a personal-data breach occurs, we act promptly to contain it and, where we are the processor, notify the affected client organisation without undue delay so they can meet their NDPA notification duties; where we are the controller, we notify the NDPC and affected individuals as required.

10. Contact

Questions or requests: info@sendiflow.com. We may update this policy; the effective date above shows the latest version.

For and on behalf of Renovo Digital Innovations Limited

Devaan M. Mom
Founder / CEO, Renovo Digital Innovations Limited