Last updated: August 31, 2026. This policy explains how NaliGrid collects, protects, and handles your data.
This Privacy Policy explains how NaliTech Consults Limited collects, uses, shares, and protects personal information through the NaliGrid platform ("Platform").
We are committed to handling personal information responsibly and in accordance with the Nigeria Data Protection Act 2023 and the Nigeria Data Protection Regulation 2019.
NaliTech acts in two different capacities depending on the type of data:
As a Data Controller; for account information you provide directly to us (such as your name, email, phone number, and business details when you register), NaliTech determines how and why this data is processed, and is the controller for this data.
As a Data Processor; for information about other individuals that Planners or Coordinators input into the Platform (such as guest lists, client contact details, or vendor contacts; "Event Data"), the Planner or Coordinator who entered that data is the controller, and NaliTech processes it only on their instructions, as described in our Terms of Service.
If you are a guest, client, or vendor whose information has been added to the Platform by a Planner or Coordinator, your relationship for data protection purposes is primarily with that Planner or Coordinator, who can address requests regarding your data. NaliTech will support such requests as the processor.
Name, email address, phone number, business/organisation name, role (Planner, Coordinator, Vendor, Client), and password (stored securely, encrypted).
Information entered by Planners and Coordinators about events, including event details, vendor records, task assignments, guest lists (names, contact details, RSVP status, dietary or accessibility notes, table assignments), team member information, and budget/financial entries.
When you activate an event, payment is processed by third-party processors (Paystack and/or Korapay). We receive confirmation of payment status and a transaction reference, but we do not collect or store your full card details.
Photographs, documents, and files you upload (such as event photos, contracts, proposals, and receipts).
The Platform includes several in-app messaging features scoped to your events: direct messages between two people who share an event (such as a Planner and a vendor), the Vendor Group and other custom group conversations among people added to an event, and the Live Board for event-wide updates. We store the content of these messages, any attached photos or files, and metadata such as when a message was sent, read, pinned, or deleted, for as long as the conversation exists. Only people who share the relevant event relationship can access a given conversation. If you have a WhatsApp number linked to your account, some of these updates (such as a new message in a group you belong to) may also be delivered to you via WhatsApp, in addition to in-app and push notifications; see 3.6 below and section 6 for how WhatsApp is involved in delivering these.
If you sign up or log in using Google or Facebook, we receive your name, email address, and profile picture from that provider. We use this information solely to create and authenticate your NaliGrid account. We do not store tokens or access additional data from these providers beyond what is necessary for authentication. Google and Facebook are independent data controllers for the information they process on your behalf; please refer to their privacy policies for details on how they handle your data.
Where required under the NDPA, we process personal information on the basis of:
We retain account information for as long as your account is active. Event Data is retained for the duration of the event lifecycle and for a reasonable period afterward to support reporting and historical records, unless you request earlier deletion.
Guest information (names, contact details, dietary notes, etc.) is retained as part of Event Data under the same terms. We recommend Planners review and remove guest information they no longer need once an event has concluded.
Messages (direct messages, group conversations, and Live Board posts) are retained for as long as the underlying event relationship exists, or until a participant deletes an individual message they sent. Deleting a message removes it for everyone in that conversation; it does not delete the conversation itself.
Credit balance and transaction records are retained for a minimum of seven (7) years in compliance with applicable financial regulations and anti-money laundering requirements. After this period, records may be anonymised or securely deleted.
If you close your account, we will delete or anonymise your personal information within a reasonable period, except where retention is required for legal, accounting, or fraud-prevention purposes.
We use industry-standard security measures to protect your information, including encrypted connections (HTTPS), encrypted password storage, and role-based access controls that restrict who can view sensitive information (for example, financial data is visible only to the Planner who entered it).
No system is completely secure, and we cannot guarantee absolute security of information transmitted to or stored on the Platform.
Under the NDPA, you have the right to:
To exercise these rights regarding your account information, contact us using the details below. If your information was added to the Platform by a Planner or Coordinator as part of Event Data (for example, as a guest), please also contact that Planner or Coordinator directly, as they control that data.
The Platform is not directed at individuals under 18, and account registration requires users to be 18 or older.
We recognise that guest lists managed by Planners may include information about minors (for example, children attending a family event). Where this occurs, the Planner is responsible as the data controller for ensuring appropriate care is taken with such information, including limiting what is collected to what is necessary for the event.
We may update this Privacy Policy from time to time. We will notify users of material changes via the Platform or email, and update the "Effective Date" above.
For privacy-related questions or to exercise your rights under the NDPA, contact:
privacy@naligrid.com
NaliTech Consults Limited
Abuja, Nigeria
You may also lodge a complaint with the Nigeria Data Protection Commission (NDPC) via their official channels.