Privacy Policy
Contents
- 1. Who this policy covers & who we are
- 2. What data we collect
- 3. How we use it, and our legal basis
- 4. Who we share it with
- 5. International transfers
- 6. How long we keep it
- 7. Security
- 8. Your rights
- 9. Automated moderation
- 10. Children's privacy
- 11. Cookies
- 12. If you're an organization, not a reader
- 13. Changes to this policy
- 14. Contact & complaints
1. Who this policy covers & who we are
Update ("we", "us") operates a live-coverage platform: organizations run events, and contributors — people at those events — send updates in by instant messaging, the web, or the Update mobile app. Organizations moderate what goes public on their own event pages ("reader pages") and inside the app.
This policy covers everyone whose personal data we process through that: readers/contributors (people who send in or view updates, whether or not they create an account), organization staff (people who sign up an organization and moderate its events), and site visitors to our marketing pages.
For updates you send to a specific organization's event, that organization is generally the data controller for the content itself (they decide what's approved/published) and we act as their data processor. For platform-level account data (your contributor account, your login, cross-org discovery/search, the mobile app's own operation), we are the controller.
Ham Events & Media Ltd (RC-9401983), Premiere Academy Street, Lugbe – FHA, Abuja, Nigeria.
2. What data we collect
What we collect depends on how you interact with us — sending a message via WhatsApp is different from creating a full reader account. Here's the actual breakdown:
| Category | Examples | Source |
|---|---|---|
| Channel identity | Phone number (WhatsApp/SMS), Telegram user ID, email address | Whichever channel you send a message from |
| Account profile | Display name, username, bio, avatar/banner image, social handles (Twitter/Instagram/Facebook/website) you choose to add | You, when you sign in or edit your profile |
| OAuth profile data | Name, email, profile photo | Google or Facebook, only if you choose "Continue with Google/Facebook" — we never see your password |
| Content you submit | Update text, photos, videos, documents, reply/comment text, live-chat messages | You, when you post |
| Location | Latitude/longitude, only if your sending app/channel attaches one to a message (e.g. a shared WhatsApp location) | Your device, via the sending channel — we never request background/continuous location |
| Social graph | Who you follow, who you're "associated" with (mutual connection), likes | You, through the app's follow/associate/like actions |
| Messages | Public per-event live-chat messages (encrypted at rest), 1-to-1 direct messages between associated readers (mobile app only) | You, when you use messaging |
| Technical data | IP address, User-Agent, request timestamps | Automatically, on every request — used for abuse/rate-limit protection, not tracking |
| Raw message payload | The original inbound message as received from WhatsApp/Telegram, for audit and troubleshooting | Automatically captured on inbound webhook; retained only as long as configured — see §6 |
We do not ask channel-only contributors (a phone number or Telegram ID with no linked account) to create a password or hand over any more information than the message itself — you can contribute without ever "signing up."
3. How we use it, and our legal basis
Both the EU General Data Protection Regulation (GDPR) and Nigeria's Data Protection Act / NDPR require a lawful basis for every use of personal data. Here's ours:
| What we do | Legal basis |
|---|---|
| Route your message to the right event, moderate it, and publish it if approved | Performance of a contract (the org's terms with you as a contributor) / legitimate interest in running the service you asked us to run |
| Show your name, avatar, and content on an event page you posted to | Consent (implicit in the act of posting to a channel you know is public) / contract |
| Let you sign in, follow, associate with, and message other readers | Consent — these are all opt-in actions you take |
| Rate-limit and block abusive senders, log security events | Legitimate interest in keeping the platform safe and usable |
| Send you an OTP code or account-related email | Contract (you asked to sign in) / legitimate interest (account security) |
| Improve the product, fix bugs, understand usage patterns | Legitimate interest, using aggregated/de-identified data wherever practical |
| Comply with a legal obligation (e.g. a lawful request from an authority) | Legal obligation |
5. International transfers
Update operates across multiple countries, and our infrastructure/processors may be located outside your own country (including outside the EEA or Nigeria). Our servers and processors are located in Nigeria, the United States, the United Kingdom, and South Africa. Where we transfer personal data internationally, we rely on recognized safeguards — Standard Contractual Clauses (GDPR Art. 46) for transfers out of the EEA/UK, and NDPR-compliant adequacy/contractual safeguards for transfers out of Nigeria.
6. How long we keep it
We keep data only as long as it's actually needed:
- Published content (approved updates) — kept for as long as the organization's event page exists, since it's the historical record of that event.
- Raw inbound message payloads (the original webhook data) — retention is configurable per deployment; by default it is not automatically deleted, but any organization can set a retention window after which raw payloads are permanently erased while the approved content itself remains.
- Rejected/unmatched messages — kept only long enough for moderation review, then eligible for deletion.
- Account data — kept while your account is active, deleted (or anonymized where deletion would break another user's own record, e.g. a reply thread) within a reasonable period after you delete your account.
- Security/rate-limit logs — short-lived, rolling windows, purged automatically.
7. Security
We apply technical safeguards proportionate to the sensitivity of the data:
- Passwords are hashed, never stored in plain text.
- Public per-event live chat messages are encrypted at rest.
- API access is rate-limited and access-controlled per organization — one organization can never read another's private data.
- Administrative actions (blocks, deletions, key changes) are recorded in an append-only security log.
- We run automated checks against known scraping/bot signatures and enforce upload size limits to reduce abuse surface.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify affected users and the relevant supervisory authority as required by applicable law (GDPR: within 72 hours where feasible; NDPR: without undue delay).
8. Your rights
Subject to the conditions and exceptions in applicable law, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten"), including deleting your account.
- Restrict or object to certain processing, including processing based on legitimate interest.
- Port your data to another service in a structured, machine-readable format.
- Withdraw consent at any time, where processing is based on consent (this doesn't affect processing already carried out).
- Lodge a complaint with your local data protection authority — see §14.
To exercise any of these, use the in-app account deletion/edit tools where available, or contact us — see §14.
9. Automated moderation
Approved updates can be published automatically without human review when the sender has an established trust level an organization has configured as sufficient (for example, a verified, previously-approved contributor). This is a content-publishing decision, not a decision that produces legal or similarly significant effects about you as an individual — but in the interest of transparency, we disclose it here. An organization may always manually review, unpublish, or reject any update regardless of how it was published.
10. Children's privacy
Update is not directed at children, and we do not knowingly collect personal data from children under the age required by applicable law to consent to data processing on their own behalf (13 in many jurisdictions; higher in some EU member states, and under Nigeria's framework). If you believe a child has provided us personal data, contact us and we will delete it.
12. If you're an organization, not a reader
If you sign up an organization, we also process your organization's staff accounts, API keys, and branding settings as necessary to operate your account. As a data controller for the content posted into your events, you have your own obligations under GDPR/NDPR toward your contributors — this platform gives you the tools (moderation, retention settings, block/removal) to meet them, but the underlying legal responsibility for how you use those tools is yours.
13. Changes to this policy
We'll update this page when our practices change, and update the "last updated" date at the top. Material changes will be highlighted in the app or by email where we have one on file.
14. Contact & complaints
Data Protection Officer: Hanniel Jafaru — hi@updateapp.co
Ham Events & Media Ltd, Premiere Academy Street, Lugbe – FHA, Abuja, Nigeria.
If you're in the EU/EEA and unhappy with our response, you may lodge a complaint with your national data protection authority. If you're in Nigeria, you may contact the Nigeria Data Protection Commission (NDPC).
