
Privacy Policy
Learn how FloHR collects, uses, protects, and manages
your information.
Last Updated : June 22, 2026
Effective Date : June 22, 2026
1. Introduction
floHR (“floHR”, “we”, “us”, or “our”) is a payroll and human resources management platform owned and operated by I-Tech Platform Limited, a company incorporated in the Federal Republic of Nigeria with its registered office at 10th Floor, Unity Bank building, Central Business District, Abuja, FCT, Nigeria.
We are committed to protecting the privacy and personal data of everyone who interacts with us. This Policy applies to:
- our marketing website at useflohr.com (the “Website”);
- our web application at app.useflohr.com (the “Web App”);
- our mobile applications, once launched (the “Mobile App”); and
- any related features, content, sales, and support we provide.
We refer to the Website, the Web App, and the Mobile App together as the “Services.” The Web App and the Mobile App are where payroll and HR data is processed, and we refer to them together as the “Platform.”
This Policy covers everyone who interacts with us — including visitors to the Website, organisations that subscribe to floHR (our “Customers”), and the individuals whose personal data is processed through the Platform (including our Customers’ employees, contractors, and other personnel).
This Privacy Policy explains what personal data we collect, how and why we use it, who we share it with, how we protect it, and the rights available to you. We handle personal data in accordance with the Nigeria Data Protection Act, 2023 (the “NDPA”), the General Application and Implementation Directive, 2025 (“GAID”) issued by the Nigeria Data Protection Commission (“NDPC” or the “Commission”), and other applicable laws.
Please read this Policy carefully. By accessing or using the Services, you acknowledge that you have read and understood it.
2. Definitions
The following terms, drawn from the NDPA, are used throughout this Policy:
- Personal Data — any information relating to an individual who can be identified, directly or indirectly, by reference to that information (for example, a name, identification number, location data, or an online identifier).
- Sensitive Personal Data — personal data relating to an individual’s genetic or biometric data, race or ethnic origin, religious or similar beliefs, health status, sex life, political opinions, trade union membership, or other data the Commission may designate as sensitive.
- Data Subject — the individual to whom personal data relates.
- Data Controller — a party that, alone or with others, determines the purposes and means of processing personal data.
- Data Processor — a party that processes personal data on behalf of, and on the instructions of, a Data Controller.
- Processing — any operation performed on personal data, such as collection, recording, storage, use, disclosure, or erasure.
3. Our Role: When We Are a Processor and When We Are a Controller
floHR is a business-to-business platform, and our role under the NDPA depends on the type of personal data involved.
Where we act as a Data Processor. When our Customers (employers) use floHR to run payroll and HR functions for their personnel, the Customer is the Data Controller. The Customer decides what personal data is uploaded to the Platform and the purposes for which it is used. I-Tech Platform Limited acts as a Data Processor, processing that data only on the documented instructions of the Customer and in line with our agreement with them (including any Data Processing Agreement). If you are an employee or other personnel of one of our Customers, this Policy is provided to you for transparency, but your employer’s own privacy notice governs how your data is handled. You should generally direct requests about your data to your employer first.
Where we act as a Data Controller. We act as a Data Controller for the personal data we collect and decide the use of directly — for example, the contact and account details of the administrators who register and manage a floHR account, billing information, data collected through our Website, and data relating to marketing, customer support, and platform security.
4. Information We Collect
The categories of personal data we collect depend on how you interact with us.
4.1 Account and registration data (we are Controller)
When a Customer or its authorised administrator registers for floHR, we collect names, business email addresses, phone numbers, job titles, company name, and login credentials.
4.2 Payroll and HR data processed through the Platform (we are Processor)
On the instructions of our Customers, the Platform processes personal data about their personnel, which may include:
- Identity and contact details (full name, address, date of birth, phone number, personal email);
- Government and statutory identifiers such as National Identification Number (NIN), Tax Identification Number (TIN), Bank Verification Number (BVN), and pension Retirement Savings Account (RSA) details;
- Employment information (job title, department, start date, employment status, work history, leave records, performance and disciplinary records);
- Compensation and financial data (salary, allowances, deductions, bank account details, PAYE tax, pension and National Housing Fund (NHF) contributions);
- Next-of-kin and emergency contact details.
4.3 Sensitive personal data (we are Processor)
Depending on the features a Customer enables, the Platform may process sensitive personal data, such as health information relating to sick leave or medical certificates, or biometric data used for attendance and time-tracking. We process such data only on the Customer’s instructions and apply the heightened safeguards required under the NDPA.
4.4 Usage and technical data (we are Controller)
When you use the Services, we automatically collect technical information such as IP address, device and browser type, operating system, pages or screens viewed, access times, and other diagnostic data.
4.5 Mobile application data (we are Controller / Processor)
When you use the Mobile App, we may also collect mobile device identifiers, app version, crash and performance data, and push notification tokens (so we can send you alerts such as payslip or leave-approval notifications). With your permission, the Mobile App may access certain device features — for example, your camera (to upload documents or a profile photo), biometric authentication (to enable secure sign-in), and, where a Customer enables location-based attendance or clock-in, your device location. You can manage or revoke these permissions at any time in your device settings, although some features may not work without them.
4.6 Cookies and similar technologies (we are Controller)
We use cookies and similar technologies on our Website and Web App as described in Section 13. Our Mobile App uses comparable technologies, such as mobile SDKs and device identifiers, rather than browser cookies.
4.7 Communications and support data (we are Controller)
When you contact us for support, sales, or other enquiries, we collect the content of your communications and any information you choose to provide.
5. Lawful Basis for Processing
Under the NDPA, we (or our Customers, where they are the Controller) rely on one or more of the following lawful bases to process personal data:
- Consent — where you have given clear, informed, specific, and freely given consent;
- Performance of a contract — where processing is necessary to provide the Platform or to perform a contract with you;
- Compliance with a legal obligation — where processing is required by law (for example, tax, pension, and statutory payroll obligations);
- Legitimate interests — where processing is necessary for our legitimate business interests (such as securing the Platform or improving our services), provided those interests are not overridden by your rights and freedoms;
- Vital interests — where processing is necessary to protect someone’s life or health;
- Public interest — where processing is necessary for a task carried out in the public interest or under official authority.
Where we rely on consent, you may withdraw it at any time (see Section 10). Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
6. How We Use Personal Data
As a Controller, we use personal data to:
- Create, administer, and secure floHR accounts;
- Provide, maintain, and improve the Platform and its features;
- Process subscriptions, billing, and payments;
- Respond to enquiries and provide customer support;
- Communicate service updates, security alerts, and (where permitted) marketing;
- Detect, prevent, and respond to fraud, abuse, and security incidents;
- Produce aggregated or anonymised analytics that do not identify any individual;
- Comply with our legal and regulatory obligations.
As a Processor, we use the personal data within the Platform solely to deliver the payroll and HR services that our Customers have instructed us to provide.
7. How We Share Personal Data
We do not sell personal data. We may share it with:
- Sub-processors and service providers — trusted third parties who help us operate the Platform (for example, cloud hosting, payment processing, email delivery, and analytics providers). We require them to provide adequate protection and to process data only on our instructions.
- Your organisation — where you are an employee or personnel of a Customer, your personal data is accessible to your employer, who controls it.
- Professional advisers and authorities — where required to comply with the law, a court order, or a lawful request from a regulator such as the NDPC.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality and data protection safeguards.
8. Cross-Border Transfers of Data
Some of our service providers may store or process personal data outside Nigeria. Where we transfer personal data outside Nigeria, we do so in accordance with Section 41 and 42 of the NDPA — that is, only where the recipient country or organisation affords an adequate level of data protection, or where another lawful basis or appropriate safeguard for the transfer applies (such as your consent or contractual safeguards). You may contact us for more information about the safeguards we use.
9. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, accidental loss, or destruction. These include encryption in transit and at rest, access controls and role-based permissions, network security controls, monitoring, and regular review of our security practices. No method of transmission or storage is completely secure, but we work continuously to protect the data entrusted to us. In the event of a personal data breach that meets the relevant threshold, we will notify the NDPC and affected individuals as required under the NDPA.
10. Your Rights as a Data Subject
Subject to the conditions and exemptions in the NDPA, you have the right to:
- Be informed about how your personal data is processed;
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete personal data;
- Request erasure of your personal data in certain circumstances;
- Restrict processing in certain circumstances;
- Object to processing, including processing for direct marketing;
- Data portability — to receive your data in a structured, commonly used, machine-readable format;
- Withdraw consent at any time where processing is based on consent;
- Not be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, except as permitted by law;
- Lodge a complaint with the NDPC (see Section 16).
To exercise these rights, contact us using the details in Section 15. If you are an employee or personnel of one of our Customers, please direct your request to your employer (the Data Controller) in the first instance; we will support them in responding. We will respond within the timeframe required by the NDPA and may need to verify your identity before acting.
11. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, tax, or reporting requirements. Where we act as a Processor, we retain Customer data in line with our agreement with the Customer and their instructions, and we delete or return it on termination of the service, except where retention is required by law. When personal data is no longer required, we securely delete or anonymise it.
12. Children’s Data
floHR is a workplace tool intended for use by adults. Under Nigerian law, a child is a person under the age of 18. We do not knowingly collect personal data directly from children through the Services. Where a Customer processes data relating to a person under 18 through the Platform (for example, a young worker), the Customer is responsible for obtaining any required parental or guardian consent in accordance with the NDPA.
13. Cookies and Tracking Technologies
Our Website and Web App use cookies and similar technologies to enable core functionality, remember your preferences, and understand how the Services are used. In line with the GAID, we obtain your opt-in consent before placing non-essential cookies (such as analytics or marketing cookies); essential cookies necessary for the Services to function do not require consent. Our Mobile App uses comparable technologies, such as mobile SDKs and device identifiers, rather than browser cookies. You can manage your preferences through our cookie banner, your browser settings, or your device settings. For more detail, please see our [Cookie Policy] (if published separately).
14. Third-Party Links
The Services may contain links to third-party websites or services that we do not control. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy notices of any third-party services you use.
15. Contact Us and Our Data Protection Officer
If you have questions about this Policy or wish to exercise your rights, please contact:
I-Tech Platform Limited
Data Protection Officer / Privacy Team
Email: info@itechplatform.net
Address: 10th Floor, Unity Bank building, Central Business District, Abuja, FCT, Nigeria
Phone: +234-8036157642
16. Complaints to the Regulator
If you believe we have not handled your personal data in accordance with the law, we encourage you to contact us first so we can address your concern. You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC):
Website: ndpc.gov.ng
Email: info@ndpc.gov.ng
Address: No. 12, Dr. Clement Isong Street, Asokoro, Abuja.
17. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will update the “Last updated” date at the top of this page and, where appropriate, notify you. We encourage you to review this Policy periodically.
18. Governing Law
This Policy is governed by the laws of the Federal Republic of Nigeria, including the Nigeria Data Protection Act, 2023, and is subject to the regulatory oversight of the Nigeria Data Protection Commission.