Privacy Policy โ€” SortAm

On-Demand Home Repairs Marketplace ยท sortam.com

Effective: 2 March 2025   Version 1.0

1. Data Controller & Contact

CompanyMediSeen Health Systems Limited (trading as SortAm)
RC Number9352905
TIN2620199413538
Data Protection OfficerKalu Ifeanyi Mba
Email[email protected]
3, Inyima Lane, Ebem, Abia State, Nigeria
Phone+234 816 516 0797

2. Scope

This Privacy Policy explains how we collect, process, store, and protect personal data through the SortAm platform at sortam.com ("the Platform"). It applies to all users including homeowners/customers, artisans/service providers, and administrators.

3. Personal Data We Collect

3.1 Customer Data

CategoryExamplesLawful Basis
Identity DataFull name, email address, phone number, profile photoPerformance of contract
Location DataService address, GPS coordinates (for matching nearby artisans)Performance of contract; Consent
Booking DataService requests, booking history, reviews, ratingsPerformance of contract
Payment DataTransaction history, payment method references (we do not store full card details)Performance of contract

3.2 Artisan / Service Provider Data

CategoryExamplesLawful Basis
Identity & KYC DataFull name, National Identification Number (NIN), photograph, date of birthLegal obligation (KYC/AML); Performance of contract
Financial DataBank account details, BVN, payout historyPerformance of contract; Legal obligation
Professional DataSkills, certifications, work portfolio, service areaPerformance of contract
Location DataReal-time location during active jobs (with consent)Consent; Legitimate interest (safety)
Performance DataRatings, reviews, response times, job completion ratesLegitimate interest

3.3 Technical Data

Browser type, device information, IP address, cookies, and usage analytics collected automatically.

4. How We Use Your Data

5. Third-Party Processors & Cross-Border Transfers

ProcessorPurposeLocation
DigitalOcean, LLCCloud hosting & infrastructureLondon, United Kingdom
Paystack Payments LimitedEscrow payment processingNigeria / International

Cross-border transfer: Data is stored on DigitalOcean servers in the UK. We ensure adequate protection pursuant to Section 43 of the NDP Act 2023, through contractual safeguards (Data Processing Agreements), the UK's adequate data protection framework, and encryption in transit and at rest.

6. Data Retention

Data TypeRetention PeriodBasis
User account dataDuration of account + 2 yearsContract; Legitimate interest
Artisan KYC dataDuration of account + 5 yearsAML/KYC regulations
Transaction & financial records7 yearsTax & financial regulations (FIRS)
Booking & review dataDuration of account + 2 yearsLegitimate interest; Dispute resolution
Technical logs12 monthsSecurity & operational necessity

After the retention period, data is securely deleted or irreversibly anonymised.

7. Your Rights as a Data Subject

Under the NDP Act 2023 and GDPR (where applicable), you have the right to:

To exercise any right, contact our DPO at [email protected]
3, Inyima Lane, Ebem, Abia State, Nigeria
. We will respond within 30 days.

8. Security Measures

9. Cookies

TypePurposeDuration
EssentialAuthentication, session management, securitySession / 24 hours
FunctionalUser preferences, language, location settingsUp to 12 months
AnalyticsAnonymised usage statisticsUp to 12 months

We do not use advertising or third-party tracking cookies. Manage preferences via your browser settings.

10. Data Breach Notification

In the event of a personal data breach posing risk to your rights:

11. Complaints

  1. Contact us first: Email [email protected]
    3, Inyima Lane, Ebem, Abia State, Nigeria
    or call +234 816 516 0797.
  2. Nigeria Data Protection Commission:
    Website: https://ndpc.gov.ng ยท Email: [email protected]
  3. EU/UK residents: You may also contact your local supervisory authority.

12. Changes to This Policy

We may update this policy periodically. Material changes will be communicated via the Platform and/or email. The "Effective" date at the top indicates the latest revision.

13. Governing Law

This Privacy Policy is governed by the laws of the Federal Republic of Nigeria, including the Nigeria Data Protection Act 2023 and the NDPA 2019 Implementation Framework. For international users, the EU GDPR and UK GDPR apply where relevant.