Privacy Policy
Last Updated: December 13, 2025
Privacy-by-Design Architecture
Your Data Stays With You — Always
🏠 Local-First
All data stored on YOUR device
🔒 Zero Collection
We do NOT collect your data
👤 User-Owned
You control everything
Introduction
WAZOBIA Smartech LTD ("WAZOBIA", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how WAZOBIA-invoice application ("App") handles data and why your privacy is protected by design.
WAZOBIA-invoice is built with a Privacy-by-Design, Client-Side (Local-First) Architecture. This means the software is designed so that user data stays with the user. We do not collect, store, or transmit your personal or business data to our servers.
By using WAZOBIA-invoice, you acknowledge that you retain full ownership and control of your data. If you do not agree with the terms of this privacy policy, please do not access the App.
🏛️ Self-Sovereign Data / User-Owned Data Architecture
⚠️ Important Notice
WAZOBIA-invoice operates on a Self-Sovereign Data model. This means YOU are the sole owner, controller, and custodian of your data. WAZOBIA Smartech LTD does not have access to, and cannot retrieve, your business data.
What This Means for You:
Your Device = Your Database
All invoices, receipts, customer data, and business records are stored exclusively on your device
No Server Collection
WAZOBIA does NOT collect, store, or have access to your business data on any server
No Transmission
Your data is NOT transmitted to us unless YOU explicitly share it (e.g., sending invoice via WhatsApp)
Your Cloud, Your Choice
If you enable Google Drive backup, data goes to YOUR Google account — not ours
Full Deletion Control
You can delete all your data at any time. We cannot recover it because we never had it
No Cloud Dependency
App works 100% offline. No internet required for core functionality
✅ Privacy Guarantee
Because we never collect your data, we cannot sell it, share it, or lose it in a data breach. Your privacy is protected by architecture, not just policy.
⚖️ Data Liability & Responsibility
📋 Important Legal Notice
Due to our Self-Sovereign Data Architecture where all data processing happens locally on your device or on your personal Google Drive account, WAZOBIA Smartech LTD is not liable for the security, loss, corruption, or unauthorized access of your data.
Your Responsibilities as Data Owner:
- 🔐
Secure your device with strong passwords, PINs, and biometric locks
- 💾
Regularly backup your data using the in-app backup feature
- 📱
Keep your device and app updated for security patches
- 🚫
Do not share your device or login credentials with unauthorized persons
- ☁️
If using Google Drive backup, secure your Google account with 2FA
- 🗃️
Maintain your own off-device backups for critical business records
WAZOBIA Is NOT Liable For:
- •Data loss due to device damage, theft, or malfunction
- •Unauthorized access to your device by third parties
- •Data stored in your personal Google Drive account
- •Data shared via WhatsApp, email, or other third-party services
- •Failure to backup data before device reset or app uninstallation
- •Data breaches resulting from weak device security
💡 Why This Matters
This liability structure exists because your data never passes through our systems. We cannot protect what we don't have access to. This architecture gives you maximum privacy but also maximum responsibility.
📋 Information Stored on YOUR Device (Not Collected by Us)
🔒 Important Clarification
The following data is stored locally on your device only. WAZOBIA Smartech LTD does NOT collect, access, or store this information on any server.
1. Data You Enter (Stored Locally)
- Business Information: Business name, address, phone number, email, logo, bank details — stored on your device
- Tax Registration Details: TIN, CAC Number, RC Number, VAT Registration Number — stored on your device
- Customer Data: Customer names, phone numbers, email addresses — stored on your device
- Transaction Data: Invoices, receipts, payments — stored on your device
- Account Credentials: Password and PIN — encrypted and stored on your device
- Inventory Data: Product names, prices, quantities — stored on your device
2. Optional Cloud Backup (Your Google Drive)
- If you enable Google Drive backup, your data is stored in YOUR personal Google Drive account
- WAZOBIA does NOT have access to your Google Drive
- You authenticate directly with Google — we never see your Google credentials
- You can revoke access at any time from your Google account settings
3. AI Feature Data (Processed Locally)
- Voice Commands: Processed 100% on your device using Edge AI. Voice data NEVER leaves your device.
- Camera Scans: Processed entirely on your device. Images are NOT uploaded anywhere.
4. Minimal Subscription Data (Only for Paid Users)
For paid subscription management only, we store:
- Device ID: Anonymous identifier for license verification
- Subscription Status: Active, expired, or cancelled
- Payment Reference: For transaction verification only
Note: We do NOT store your business data, invoices, customer information, or any content you create in the app.
✅ Zero-Knowledge Architecture
We have designed WAZOBIA-invoice so that we have zero knowledge of your business operations. Your invoices, customers, sales figures, and financial data remain completely private.
🎯 How Your Data Is Processed (Locally)
💻 Client-Side Processing
All data processing happens on YOUR device. The app performs all calculations, report generation, and data management locally without sending data to our servers.
The WAZOBIA-invoice app processes data locally on your device to:
- Generate invoices and receipts using your business details
- Calculate taxes (VAT) and generate tax reports
- Store your business data in local storage
- Enable backup to your Google Drive (if you choose)
- Send documents to your customers via WhatsApp/email (when you initiate)
- Provide offline functionality without internet
Limited Server Interaction (Subscription Only)
The only server communication occurs for:
- Subscription Verification: Verifying your license status (using anonymous device ID only)
- App Updates: Checking for and downloading app updates
- Payment Processing: Verifying payment for subscription upgrades
None of your business data, invoices, customers, or financial information is ever sent to our servers.
🔐 Data Storage & Security
Local-First Architecture
WaZoBia-invoice is designed with a "local-first" approach. This means:
- Your data is stored primarily on your device
- The App works fully offline
- You maintain control over your data at all times
- Data is only transmitted when you explicitly choose to backup or sync
Security Measures
WaZoBia implements robust security measures including:
- AES-256 Encryption: Bank-level encryption for sensitive data
- PIN Protection: 4-digit PIN lock for app access
- Biometric Authentication: Fingerprint/Face ID support
- Lockout Protection: Account locks after multiple failed attempts
- SHA-256 Hashing: Secure password storage
- Fraud Detection: Anomaly detection for suspicious activities
- Secure Deletion: Multi-step verification for data deletion
💡 Your Responsibility
You are responsible for maintaining the security of your device, keeping your password and PIN confidential, and regularly backing up your data.
🤝 Data Sharing & Disclosure
🚫 We Cannot Share What We Don't Have
Because your business data is stored only on your device, we cannot share, sell, or disclose it — we simply don't have access to it.
We DO NOT (and CANNOT):
- Sell your personal or business data — we don't have it
- Share your business data with advertisers — we don't have it
- Use your data for targeted advertising — we don't collect it
- Provide your data to government requests — we don't possess it
- Transfer your data in a company acquisition — there's nothing to transfer
Data Sharing YOU Control:
Any data sharing is initiated by YOU and goes directly from your device:
- To Your Customers: When you send invoices/receipts via WhatsApp, email, or SMS
- To Your Google Drive: When you enable cloud backup (your account, not ours)
- Via Device Sharing: When you export or share files from the app
⚠️ Third-Party Services
When you share data via WhatsApp, email, or Google Drive, that data is then subject to those services' privacy policies. We recommend reviewing their policies.
🔗 Third-Party Services
WaZoBia-invoice integrates with the following third-party services:
WhatsApp (Meta)
Used for sending invoices and payment reminders. Subject to WhatsApp's Privacy Policy.
Email Services
Used for sending invoices via email. Your default email app handles transmission.
Web Share API
Used for sharing backups. Data is shared directly through your device's native sharing.
Users are encouraged to review the privacy policies of these third-party services. WaZoBia is not responsible for the privacy practices of third parties.
🇳🇬 Nigerian Data Protection Compliance
WaZoBia-invoice complies with the Nigeria Data Protection Regulation (NDPR) 2019 and the Nigeria Data Protection Act (NDPA) 2023. Under these regulations, you have the following rights:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Correct inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data
- Right to Restriction: Limit how the platform processes your data
- Right to Data Portability: Export your data in a machine-readable format
- Right to Object: Object to certain processing activities
- Right to Withdraw Consent: Withdraw consent at any time
To exercise any of these rights, please contact WaZoBia at hi@wazobia-invoice.ng.
⏱️ Data Retention
Since WaZoBia-invoice stores data locally on your device:
- Your data remains on your device until you delete it
- You can delete all data at any time through Settings → Delete All Data
- Uninstalling the App removes all locally stored data
- Backups you create are stored where you save them (cloud, device, WhatsApp)
It is recommended to retain business records for at least 6 years as required by Nigerian tax laws for FIRS compliance.
👶 Children's Privacy
WaZoBia-invoice is designed for business use and is not intended for children under 18 years of age. WaZoBia does not knowingly collect personal information from children. If you are a parent or guardian and believe your child has provided personal information to WaZoBia, please contact the support team immediately.
🍪 Cookies & Tracking
The WaZoBia-invoice App uses local storage and cookies to:
- Store your preferences and settings
- Maintain your logged-in state
- Remember your language preference
- Enable offline functionality
WaZoBia does NOT use third-party tracking cookies or analytics that follow you across websites.
🌍 International Data Transfers
Your data is primarily stored locally on your device in Nigeria. If you choose to use cloud backup services, your data may be transferred to servers located outside Nigeria. WaZoBia ensures that any such transfers comply with applicable data protection laws and that appropriate safeguards are in place.
📝 Changes to This Privacy Policy
WaZoBia may update this Privacy Policy from time to time. Users will be notified of any changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last Updated" date
- Sending an in-app notification for material changes
Users are encouraged to review this Privacy Policy periodically for any changes.
Controller, legal bases & your rights
This section summarises information required or recommended under the Nigeria Data Protection Act (NDPA) 2023, the EU General Data Protection Regulation (GDPR) where it applies, and U.S. state laws such as the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA). It supplements the rest of this policy.
Data controller & privacy contact (including NDPA s.32)
Controller: WaZoBia Smartech LTD ("WAZOBIA"), Nigeria. For privacy, data protection, and data subject requests, contact our privacy team (who also act as the primary contact for data-protection enquiries, including the role of Data Protection Officer / privacy lead where required):
- Email: hi@wazobia-invoice.ng
- WhatsApp: +234 707 011 5959 (see Contact page for hours)
- Postal: Kano, Lagos, and Abuja, Nigeria (operating presence)
Purposes of processing (GDPR Art. 13(1)(c) / NDPA)
We process personal data for: operating and securing the website and services; account and subscription administration; customer support; compliance with law (including tax and regulatory obligations); and, where you opt in, analytics or communications cookies on this site. The WaZoBia app's local-first design limits what reaches our systems — see the sections above.
Lawful basis (GDPR Art. 13(1)(c))
Depending on context, we rely on: contract (providing services you request); legal obligation; legitimate interests (e.g. securing our systems, fraud prevention, improving the product in a way you would expect), where not overridden by your rights; and consent where required (e.g. non-essential cookies — you can withdraw via cookie settings or browser controls).
Categories of data & recipients (GDPR Art. 13(1)(e))
We may process identifiers, contact data, technical logs, payment metadata (via payment partners), and support content. Recipients can include infrastructure and email/WhatsApp/payment processors under contract, as described in our Security and Third-Party sections. We do not sell your personal data for money.
International transfers (GDPR Art. 13(1)(f))
If data is transferred outside Nigeria or the EEA (e.g. cloud or messaging infrastructure), we use appropriate safeguards where required, such as contractual clauses and vendor diligence. See the "International Data Transfers" section above.
Retention (GDPR Art. 13(2)(a) / NDPA storage limitation)
App data is primarily retained on your device until you delete it. Server-side data (e.g. support, payments, security logs) is kept only as long as needed for the purposes above, then deleted or minimised, subject to legal, tax, or dispute-resolution requirements. Business records on your own devices may need longer retention for tax law — e.g. multi-year record-keeping in Nigeria.
Data subject rights (GDPR Art. 15–22; NDPA)
Subject to law, you may have the right to:
- Access (Art. 15)
- Rectification (Art. 16)
- Erasure ("right to be forgotten", Art. 17)
- Restrict processing (Art. 18)
- Data portability (Art. 20)
- Object to processing, including for direct marketing (Art. 21)
- Not be subject solely to automated decision-making with legal or similar effects (Art. 22) — we do not use such processing for the website in a way that produces legal effects solely by automation.
- Withdraw consent where processing is based on consent (Art. 13(2)(c)), e.g. cookie choices via the cookie banner and footer Cookie settings.
To exercise these rights, contact hi@wazobia-invoice.ng. You may also lodge a complaint with the Nigeria Data Protection Commission (NDPC) or, where the GDPR applies, your local supervisory authority (GDPR Art. 13(2)(d)).
Personal data breach (NDPA s.40; GDPR Art. 33/34 style)
If we become aware of a personal data breach likely to affect your rights, we will take appropriate steps, which may include notifying the relevant supervisory authority and, where high risk to you is likely, communicating with affected users when required. Report suspected incidents to hi@wazobia-invoice.ng.
California & U.S. state privacy (CCPA/CPRA and similar)
Right to know / access, deletion, correction: California and some other U.S. state residents can request the categories and specific pieces of personal information we hold, or request deletion or correction, subject to exceptions. Submit requests to hi@wazobia-invoice.ng with "US privacy request" in the subject.
Do not sell or share (CPRA) / "Do Not Sell or Share My Personal Information": We do not sell personal information in the CCPA/CPRA sense. We do not share personal information for cross-context behavioural advertising on this marketing site. If that changes, we will provide a clear opt-out and honour legally recognised Global Privacy Control (GPC) signals as applicable to the sale or sharing of personal information, in line with the CPRA. You can also use the Decline option in our cookie banner for non-essential cookies.
Security & Content-Security-Policy
We deploy HTTPS, Content-Security-Policy (CSP) with per-request nonces, and other security headers. Details are on our Security page. CSP helps reduce the risk of certain injection attacks; it is one layer in a broader security programme.
📞 Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
WhatsApp (MTN)
+234 707 011 5959Company
WaZoBia Smartech LTD
Address
Kano, Lagos, and Abuja, Nigeria