Update
Legal

Privacy Policy

Last updated: · Applies to the Update website, mobile app, organization portal, and every organization's reader page
Before you publish this This is a detailed working draft, tailored to what Update actually collects and does with data — not generic filler. It's filled in with your entity, contact, and processor-location details, but still needs a pass from qualified legal counsel in each jurisdiction you operate in (Nigeria, and anywhere else you have users) before publishing. It is not legal advice.

Contents

  1. 1. Who this policy covers & who we are
  2. 2. What data we collect
  3. 3. How we use it, and our legal basis
  4. 4. Who we share it with
  5. 5. International transfers
  6. 6. How long we keep it
  7. 7. Security
  8. 8. Your rights
  9. 9. Automated moderation
  10. 10. Children's privacy
  11. 11. Cookies
  12. 12. If you're an organization, not a reader
  13. 13. Changes to this policy
  14. 14. Contact & complaints

1. Who this policy covers & who we are

Update ("we", "us") operates a live-coverage platform: organizations run events, and contributors — people at those events — send updates in by instant messaging, the web, or the Update mobile app. Organizations moderate what goes public on their own event pages ("reader pages") and inside the app.

This policy covers everyone whose personal data we process through that: readers/contributors (people who send in or view updates, whether or not they create an account), organization staff (people who sign up an organization and moderate its events), and site visitors to our marketing pages.

Data controller

For updates you send to a specific organization's event, that organization is generally the data controller for the content itself (they decide what's approved/published) and we act as their data processor. For platform-level account data (your contributor account, your login, cross-org discovery/search, the mobile app's own operation), we are the controller.

Ham Events & Media Ltd (RC-9401983), Premiere Academy Street, Lugbe – FHA, Abuja, Nigeria.

2. What data we collect

What we collect depends on how you interact with us — sending a message via WhatsApp is different from creating a full reader account. Here's the actual breakdown:

CategoryExamplesSource
Channel identityPhone number (WhatsApp/SMS), Telegram user ID, email addressWhichever channel you send a message from
Account profileDisplay name, username, bio, avatar/banner image, social handles (Twitter/Instagram/Facebook/website) you choose to addYou, when you sign in or edit your profile
OAuth profile dataName, email, profile photoGoogle or Facebook, only if you choose "Continue with Google/Facebook" — we never see your password
Content you submitUpdate text, photos, videos, documents, reply/comment text, live-chat messagesYou, when you post
LocationLatitude/longitude, only if your sending app/channel attaches one to a message (e.g. a shared WhatsApp location)Your device, via the sending channel — we never request background/continuous location
Social graphWho you follow, who you're "associated" with (mutual connection), likesYou, through the app's follow/associate/like actions
MessagesPublic per-event live-chat messages (encrypted at rest), 1-to-1 direct messages between associated readers (mobile app only)You, when you use messaging
Technical dataIP address, User-Agent, request timestampsAutomatically, on every request — used for abuse/rate-limit protection, not tracking
Raw message payloadThe original inbound message as received from WhatsApp/Telegram, for audit and troubleshootingAutomatically captured on inbound webhook; retained only as long as configured — see §6

We do not ask channel-only contributors (a phone number or Telegram ID with no linked account) to create a password or hand over any more information than the message itself — you can contribute without ever "signing up."

3. How we use it, and our legal basis

Both the EU General Data Protection Regulation (GDPR) and Nigeria's Data Protection Act / NDPR require a lawful basis for every use of personal data. Here's ours:

What we doLegal basis
Route your message to the right event, moderate it, and publish it if approvedPerformance of a contract (the org's terms with you as a contributor) / legitimate interest in running the service you asked us to run
Show your name, avatar, and content on an event page you posted toConsent (implicit in the act of posting to a channel you know is public) / contract
Let you sign in, follow, associate with, and message other readersConsent — these are all opt-in actions you take
Rate-limit and block abusive senders, log security eventsLegitimate interest in keeping the platform safe and usable
Send you an OTP code or account-related emailContract (you asked to sign in) / legitimate interest (account security)
Improve the product, fix bugs, understand usage patternsLegitimate interest, using aggregated/de-identified data wherever practical
Comply with a legal obligation (e.g. a lawful request from an authority)Legal obligation

4. Who we share it with

We don't sell personal data. We share it only where it's necessary to run the service:

Every one of these is bound to only use your data for the purpose we've given it to them for — none of them may use it for their own independent marketing.

5. International transfers

Update operates across multiple countries, and our infrastructure/processors may be located outside your own country (including outside the EEA or Nigeria). Our servers and processors are located in Nigeria, the United States, the United Kingdom, and South Africa. Where we transfer personal data internationally, we rely on recognized safeguards — Standard Contractual Clauses (GDPR Art. 46) for transfers out of the EEA/UK, and NDPR-compliant adequacy/contractual safeguards for transfers out of Nigeria.

6. How long we keep it

We keep data only as long as it's actually needed:

7. Security

We apply technical safeguards proportionate to the sensitivity of the data:

No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify affected users and the relevant supervisory authority as required by applicable law (GDPR: within 72 hours where feasible; NDPR: without undue delay).

8. Your rights

Subject to the conditions and exceptions in applicable law, you have the right to:

To exercise any of these, use the in-app account deletion/edit tools where available, or contact us — see §14.

9. Automated moderation

Approved updates can be published automatically without human review when the sender has an established trust level an organization has configured as sufficient (for example, a verified, previously-approved contributor). This is a content-publishing decision, not a decision that produces legal or similarly significant effects about you as an individual — but in the interest of transparency, we disclose it here. An organization may always manually review, unpublish, or reject any update regardless of how it was published.

10. Children's privacy

Update is not directed at children, and we do not knowingly collect personal data from children under the age required by applicable law to consent to data processing on their own behalf (13 in many jurisdictions; higher in some EU member states, and under Nigeria's framework). If you believe a child has provided us personal data, contact us and we will delete it.

11. Cookies

Our website and portals use a limited set of cookies/local storage for sign-in sessions and essential site function. See the full Cookie Policy for details and how to control them.

12. If you're an organization, not a reader

If you sign up an organization, we also process your organization's staff accounts, API keys, and branding settings as necessary to operate your account. As a data controller for the content posted into your events, you have your own obligations under GDPR/NDPR toward your contributors — this platform gives you the tools (moderation, retention settings, block/removal) to meet them, but the underlying legal responsibility for how you use those tools is yours.

13. Changes to this policy

We'll update this page when our practices change, and update the "last updated" date at the top. Material changes will be highlighted in the app or by email where we have one on file.

14. Contact & complaints

Data Protection Officer: Hanniel Jafaru — hi@updateapp.co
Ham Events & Media Ltd, Premiere Academy Street, Lugbe – FHA, Abuja, Nigeria.

If you're in the EU/EEA and unhappy with our response, you may lodge a complaint with your national data protection authority. If you're in Nigeria, you may contact the Nigeria Data Protection Commission (NDPC).

All policies Terms of Service Acceptable Use Policy Cookie Policy