Skip to content
Dyaar

Privacy Notice

Last updated Draft

This document is a working draft and is not yet in force. It is under legal review and will be finalised before launch.

1. Who we are and the Data Protection Officer

DYAAR LIMITED (controller). DPO contact to be published before launch.

2. Data we collect

Account (name, email, phone); identity-verification data (see section 3); bank details (encrypted); booking and payment records; messages; reviews and reports.

3. Identity verification — what we store and what we do not

To verify your identity we ask the national identity registry and keep a record of what it returns — your full name (including any middle name), passport photograph, phone number, date of birth and nationality. We keep this for verification and identification only; it is never merged into your public profile and never shared with hosts. We do not store your NIN — only a one-way index that prevents one NIN being used on two accounts. We also do not store your residence address, next-of-kin details, signature, or the other fields the registry returns.

4. Why we process your data (lawful basis)

Contract, consent, legitimate interest and legal obligation, mapped per activity by the lawyer.

5. Who we share data with

Hosts (guest name and email), payment and identity providers, and other sub-processors — see the sub-processor list.

6. International transfers

Some processors are outside Nigeria, under contractual safeguards.

7. How long we keep it

Profile and identity anonymised on deletion; financial records 6 years; logs 90 days.

8. Automated decisions

Identity verification compares your details against the NIN registry. You can ask for a human review.

9. Your rights

Access, correction, deletion, export, objection, withdrawing consent, and complaining to the NDPC.

10. Children

The platform is for users 18 and over.

11. Cookies

See the Cookie Policy.

12. Changes to this notice