Go SendAm Ltd · Legal

Data Protection

How Go SendAm handles personal data across our platforms, the rights you have as a data subject under Nigerian law, and the standards we commit to as a Data Controller.

Last Updated
Version 2.0 · August 2026
Organisation
Go SendAm Ltd
Data Contact
Compliance
NDPA 2023 + GAID 2025

Our Commitment

Go SendAm Ltd ("we," "us," or "our") is committed to protecting the personal data of everyone who uses our platforms. This page explains, in one place, how we approach data protection, the rights you have under Nigerian law, and the standards we hold ourselves to.

Our full processing details, including the specific purposes, legal bases, and data recipients for each activity, are set out in our Privacy Policy. This page focuses on the framework, principles, and rights that govern all of it.

We comply with the Nigeria Data Protection Act 2023 (NDPA) and the General Application and Implementation Directive 2025 (GAID) issued by the Nigeria Data Protection Commission (NDPC), which replaced the Nigeria Data Protection Regulation (NDPR) with effect from 19 September 2025.

Our registered address is 100 Olokonla Road, Off Lekki-Epe Expressway, Lekki, Lagos.

1. Our Role Under the NDPA

Go SendAm operates in two distinct roles under the NDPA, depending on the type of data being processed.

Sole Controller

For Most Personal Data

We are the sole Data Controller for personal data we collect and process directly. We determine the purposes and means of processing this data on our own.

  • Shipper data (vendors and everyday sellers using our platform to send products)
  • Receiver data (recipients who confirm delivery details or price)
  • Account, wallet, and transaction data
  • Marketing consent records
  • Website and analytics data
  • Support and complaint records
Joint Controller

For Rider Data (With Carriers)

We are a Joint Controller with the carrier (dispatch company) for personal data of riders. Because carriers hire riders and share operational decision-making about assignments, performance, and remuneration, we and the carrier jointly determine how rider data is processed.

  • Rider identity and verification records
  • Assignment and delivery performance data
  • Rider location data during active jobs
  • Ratings and completion history

Where we are a Joint Controller with a carrier, a written Joint Controller Agreement between us documents how responsibilities are allocated, which party responds to specific data subject requests, and how NDPC notifications are handled. This ensures each party's role is clear to riders and to the regulator.

Our third-party service providers, including our identity verification, cloud hosting, communications, and payment providers, act as Data Processors on our behalf under written contracts that meet NDPA Section 41 requirements. They do not use the data we entrust to them for their own purposes.

2. Data Protection Principles

Every activity we carry out with personal data is guided by the seven data protection principles set out in NDPA Section 24. These principles govern how we design our platform, how we train our team, and how we assess new processing activities before they go live.

Principle 01

Lawfulness, Fairness, and Transparency

We process personal data only where we have a valid legal basis, act fairly toward the data subject, and disclose our processing openly through our Privacy Policy.

Principle 02

Purpose Limitation

Data is collected for specified, explicit, and legitimate purposes. We do not use it for purposes incompatible with what we told you at collection.

Principle 03

Data Minimisation

We collect only what we actually need. Data fields that are not necessary for a specific purpose are not requested.

Principle 04

Accuracy

We take reasonable steps to keep personal data accurate and up to date, and to correct or erase inaccurate data without delay.

Principle 05

Storage Limitation

Personal data is retained only for as long as necessary. Our retention schedule is set out in Section 6 of this page.

Principle 06

Integrity and Confidentiality

We protect personal data against unauthorised access, loss, and destruction through technical and organisational security measures set out in Section 7.

Principle 07

Accountability

We document our processing, review our compliance regularly, and can demonstrate to the NDPC that we operate within the NDPA at any point.

3. Your Rights as a Data Subject

Under NDPA Sections 34 to 39, you have the following rights over the personal data we hold about you. These rights apply whether you are a shipper, receiver, rider, or carrier account holder.

Right to be Informed

To know what personal data we collect about you, why we collect it, how we use it, and who we share it with.

Right of Access

To request a copy of the personal data we hold about you and information about how we are processing it.

Right to Rectification

To have inaccurate or incomplete personal data about you corrected without undue delay.

Right to Erasure

To have your personal data deleted where we no longer have a legal basis to keep it. Some data may be retained where the law requires (for example, tax and AML records).

Right to Restrict Processing

To have us pause our processing of your data in specific circumstances, such as while accuracy is being checked or you are objecting.

Right to Data Portability

To receive your personal data in a structured, commonly used, machine-readable format, and to transmit it to another controller.

Right to Object

To object to processing based on our legitimate interests, and to object at any time to processing for direct marketing.

Rights Regarding Automated Decisions

Where we make decisions about you using automated systems that have significant effects on you, you have the right to human review, to express your view, and to contest the decision.

4. How to Exercise Your Rights

To exercise any of the rights listed above, please send us a written request by email to [email protected]. Include:

  • The right you are exercising (for example, "access request" or "erasure request").
  • The account or profile the request relates to, so we can locate the correct records.
  • Identification sufficient to confirm you are the data subject, so we do not disclose your data to the wrong person.

We respond to data subject requests within 30 calendar days, as required by NDPA Section 34. Where a request is complex or where we need additional information from you to identify the correct data, we may extend this period by up to two further months and will explain the reason.

There is no fee for exercising your rights, except where a request is manifestly unfounded or excessive, in which case we may charge a reasonable administrative fee or decline to act, and will explain why.

Note on joint processing: where your data is processed jointly by Go SendAm and a carrier (this applies primarily to riders), you may send your request to either party. Under our Joint Controller Agreements, whichever party receives the request routes it to the party best placed to respond, and the response reflects both parties' obligations.

5. Data Categories We Handle

The specific categories of personal data we handle, and the purposes for each, are set out in detail in our Privacy Policy. In summary, we handle:

  • Identity and account data — names, phone numbers, email addresses, business names, CAC numbers, director NINs, and login credentials.
  • Verification data — identity verification results from our verification provider, used to confirm carrier and rider eligibility.
  • Location data — pickup and delivery addresses, and rider GPS during active jobs.
  • Transaction and wallet data — payment records, wallet balances, funding history, and payout records.
  • Delivery and job data — job details, timestamps, proof-of-delivery photos, one-time passwords, and delivery status history.
  • Communication data — in-app messages between users, support tickets, and delivery confirmation exchanges.
  • Device and usage data — technical information about the devices and browsers used to access our platforms, and how users interact with our features.
  • Marketing and consent records — consent given or withdrawn for marketing communications and cookies.

We do not knowingly collect personal data of children under 18. Our platforms are not directed at children.

6. How Long We Keep Your Data

We retain personal data only for as long as necessary for the purposes for which it was collected, or for as long as required by law. The retention periods below reflect Nigerian legal requirements and our internal retention discipline.

Data Category Retention Period Basis
Carrier verification records (CAC, NIN, KYB) 5 years after end of business relationship Money Laundering (Prevention and Prohibition) Act 2022, Section 4
Rider verification records 5 years after rider deactivation Money Laundering Act 2022 + Labour Act 2004
Transaction, wallet, and payment records 6 years after transaction date Companies and Allied Matters Act 2020 + FIRS tax retention rules
Delivery records (job data, timestamps, proof photos, OTP logs) 5 years after delivery completion Dispute and evidence retention window
In-app messages and voice notes between users 2 years after last message Dispute window + NDPA storage limitation principle
Support tickets (Freshdesk) 2 years after ticket closure Customer service continuity + NDPA storage limitation
Marketing consent records Duration of consent + 3 years after withdrawal NDPA accountability principle
Analytics data (Google Analytics) 14 months (GA4 default retention) Product configuration
Access and audit logs 24 months Security incident investigation window
Cookie consent records 12 months after consent given or withdrawn GAID 2025
Active account data For duration of account Contractual necessity
Account data after closure 30 days for immediate deletion, then anonymised NDPA Section 24(1)(e) storage limitation

Periodic re-verification. Carrier business verification (CAC and director NIN) is repeated every 90 days to ensure records remain accurate and to confirm the carrier's continued eligibility to operate on the platform. Re-verification does not extend the retention window for previously collected verification records — those follow the 5-year AML retention rule set out above.

Where data is retained beyond the primary retention period for a legally-mandated reason (for example, tax or AML records), access to that data is restricted to the specific compliance purpose and is not used for operational purposes.

7. How We Secure Your Data

We apply technical and organisational security measures proportionate to the risk of the processing. Our security controls include:

  • Encryption in transit — all data exchanged between users and our platforms is transmitted over Transport Layer Security (TLS).
  • Encryption at rest — sensitive data stored in our infrastructure is encrypted at the storage layer.
  • Access controls — role-based access is enforced within our systems. Team members can only access personal data required for their role, and access is logged.
  • Authentication — administrative accounts require strong authentication. Password policies are enforced for all users.
  • Segregation of environments — production data is segregated from development and testing environments.
  • Vulnerability management — we monitor our infrastructure for security vulnerabilities and apply patches promptly.
  • Vendor due diligence — third-party service providers are assessed for security before engagement and reviewed periodically thereafter.
  • Incident response — we operate a personal data breach response process consistent with NDPA Section 40, described in Section 11 of this page.

Despite our controls, no system is entirely immune from security incidents. Where we detect a personal data breach that affects your rights, we notify you as required by NDPA Section 40.

8. Sub-Processors and Service Providers

To operate our platforms, we engage third-party service providers that process personal data on our behalf under written contracts. These sub-processors act as Data Processors and are contractually bound to process data only on our documented instructions, to apply appropriate security measures, and to assist us in meeting our obligations under the NDPA.

Our current sub-processors are:

Prembly
Identity and business verification (CAC and NIN checks for carriers and riders)
Nigeria
Termii
SMS delivery for OTP codes and delivery notifications
Nigeria
Nomba
Payment processing for carrier wallet funding
Nigeria
Flutterwave
Payment processing for carrier wallet funding
Nigeria
Freshdesk
Support ticket management and customer communications
May involve cross-border transfer
Cloudflare
Content delivery, bot management, and security for our web properties
May involve cross-border transfer
GoHighLevel
Marketing website hosting (gosendam.com)
May involve cross-border transfer
Google Analytics
Website usage analytics (only where consent is given)
May involve cross-border transfer

We update this list when we add or remove sub-processors. Where we intend to engage a new sub-processor that processes a materially different category of personal data, we notify affected users where the change is significant.

9. International Data Transfers

Some of the sub-processors we engage operate infrastructure outside Nigeria. This means certain personal data may be transferred to, or accessed from, countries outside Nigeria in the course of delivering our service.

Where we transfer personal data outside Nigeria, we do so only where one of the safeguards permitted under NDPA Section 41 is in place:

  • Adequacy determination — a determination by the NDPC that the destination country provides an adequate level of protection.
  • Standard contractual clauses — clauses that impose data protection obligations on the recipient equivalent to those under the NDPA.
  • Binding corporate rules or codes of conduct where applicable.
  • Explicit consent of the data subject, after being informed of the risks.

We assess each new sub-processor for the appropriate safeguard before engagement and document our assessment. If you would like to know which safeguard applies to a specific transfer, contact us at [email protected].

10. Automated Decision-Making

Some processing on our platforms involves automated systems. NDPA Section 37 gives you specific rights in relation to automated decisions that have significant effects on you.

Automated identity verification

During carrier and rider onboarding, we use our identity verification provider to automatically match submitted CAC and NIN details against government databases. If the match fails, an initial rejection is generated automatically. You have the right to request human review of this decision by contacting our support team.

Rider assignment and performance

Where automated systems influence rider assignment or performance measurement, decisions that have significant effects on the rider (for example, deactivation) are subject to human review before being finalised. Riders have the right to be informed of the logic, request review, and contest the decision.

We do not use automated decisions to profile users for marketing purposes without their consent.

11. Personal Data Breaches

A personal data breach is a security incident that leads to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

If we become aware of a personal data breach, we:

  • Contain and investigate — take immediate steps to contain the breach, assess its scope, and identify affected data subjects.
  • Notify the NDPC — where the breach is likely to result in a risk to the rights and freedoms of data subjects, we notify the Nigeria Data Protection Commission within 72 hours of becoming aware of it, as required by NDPA Section 40.
  • Notify affected data subjects — where the breach is likely to result in a high risk to your rights and freedoms, we notify you directly without undue delay, describing the nature of the breach, its likely consequences, and the steps we are taking.
  • Document and review — record the incident, our response, and the outcome, and use the review to strengthen our controls.

Where we act as Joint Controllers with a carrier, the Joint Controller Agreement between us allocates responsibility for breach notifications. Whichever party is best placed to respond takes the lead, and the other party assists.

12. Data Protection Governance

Data protection at Go SendAm is a whole-organisation responsibility. Our governance framework includes:

  • Designated data protection contact — a named contact for all data protection matters, reachable at [email protected]. Where our processing activities require the formal appointment of a Data Protection Officer under NDPA Section 32, we will make that appointment and publish contact details for the DPO.
  • Records of processing — we maintain records of our processing activities, sub-processors, and transfers as required by NDPA Section 26.
  • Data protection impact assessments — we assess new processing activities that pose higher risks to data subjects before they go live.
  • Team training — team members who handle personal data receive training on their responsibilities under the NDPA.
  • Vendor management — sub-processors are assessed before engagement and reviewed periodically.
  • Regulatory registration — where NDPA requires registration as a Data Controller of Major Importance, we will maintain that registration.

13. Complaints and Regulatory Oversight

If you are not satisfied with how we have handled your personal data, please contact us first at [email protected]. We take complaints seriously and aim to resolve them promptly.

If you remain dissatisfied after contacting us, you have the right to complain to the Nigeria Data Protection Commission at any time. The NDPC is the regulatory authority responsible for data protection in Nigeria.

Regulator
Nigeria Data Protection Commission (NDPC)
Website

Exercising your right to complain to the NDPC does not affect any other remedy available to you.

14. Contact Us

Questions about data protection at Go SendAm, or requests to exercise your rights, can be sent to us at:

Address
100 Olokonla Road, Off Lekki-Epe Expressway, Lekki, Lagos
Go SendAm Ltd · Data Protection v2.0 · August 2026 · Compliant with the Nigeria Data Protection Act 2023 and the General Application and Implementation Directive 2025 (GAID)