1. Introduction
EasyCity Systems Ltd. ("we", "us", "our", or the "Company") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use Zolar (the "Platform"), our solar energy planning and marketplace services.
This policy applies to all users of the Platform, including individual users planning solar installations, installers, dealers, and other professional users. By using Zolar, you agree to the collection and use of information in accordance with this policy.
Compliance Framework
This Privacy Policy is designed to comply with:
- Nigeria Data Protection Regulation (NDPR) 2019 - National Information Technology Development Agency (NITDA)
- General Data Protection Regulation (GDPR) - EU Regulation 2016/679 (EU Market Ready)
- Protection of Personal Information Act (POPIA) - South Africa (Aligned)
- Data Protection Act (DPA) - Kenya (Compliant)
- Data Protection Act (DPA) - Ghana (Ready)
2. Information We Collect
2.1 Personal Information You Provide
We collect information you directly provide to us, including:
- Account Information: Name, email address, phone number, password, and authentication credentials
- Location Data: Country, state, city, GPS coordinates, and address information for solar forecasting
- Energy Profile: Appliance inventory, energy consumption patterns, roof specifications, and system sizing preferences
- Professional Information: For installers and dealers: business name, registration details, certifications, capabilities, and service areas
- Communication: Messages, support requests, feedback, and correspondence
- Payment Information: Payment method details (processed securely through third-party payment processors)
- Marketplace Activity: Orders, quotes, bookings, reviews, and transaction history
2.2 Information Collected Automatically
We automatically collect certain information when you use the Platform:
- Device Information: Device type, operating system, browser type, unique device identifiers
- Usage Data: Pages visited, features used, time spent, click patterns, and navigation paths
- Log Data: IP address, browser type, referring/exit pages, and timestamps
- Session Data: Session IDs, authentication tokens, and user preferences
- Performance Data: Load times, error reports, and crash diagnostics
2.3 Third-Party Information
We may receive information about you from third parties, including:
- Weather Data Providers: Open-Meteo and other meteorological services for solar forecasting
- Payment Processors: Transaction verification and fraud prevention data
- Identity Verification Services: For professional user verification
- Business Partners: With your consent, for integrated services
2.4 Special Categories of Personal Data
We may process the following special categories of personal data only with your explicit consent:
- Location Data: Precise GPS coordinates for solar forecasting (Article 9 GDPR)
- Energy Consumption Patterns: Detailed household energy usage data
- Financial Information: Payment and transaction history
3. Legal Basis for Processing
We process your personal data based on the following legal grounds (GDPR Article 6, NDPR Section 2.1):
3.1 Contract Performance
We process data necessary to:
- Provide solar forecasting and energy planning services
- Facilitate marketplace transactions between users, installers, and dealers
- Manage user accounts and authentication
- Process orders, bookings, and service requests
3.2 Legal Obligation
We process data to comply with:
- Nigerian regulatory requirements (NDPR, NITDA guidelines)
- Anti-money laundering and counter-terrorism financing laws
- Tax reporting and financial record-keeping obligations
- Consumer protection regulations
3.3 Legitimate Interests
We process data for our legitimate business interests when balanced against your rights:
- Platform security, fraud prevention, and abuse detection
- Service improvement, analytics, and product development
- Network and infrastructure security
- Marketing communications (where permitted by law)
3.4 Consent
We obtain your explicit consent for:
- Processing precise location data for solar forecasting
- Marketing communications and promotional content
- Data sharing with third-party service providers
- Cookies and similar tracking technologies
You may withdraw your consent at any time by contacting us or using your account settings.
4. How We Use Your Information
We use your information for the following purposes:
4.1 Service Provision
- Generate accurate solar generation forecasts for your location
- Calculate optimal system sizing based on your energy profile
- Match you with qualified installers in your area
- Facilitate equipment purchases through the marketplace
- Manage bookings, jobs, and service requests
- Provide customer support and technical assistance
4.2 Platform Operations
- Create and maintain user accounts
- Authenticate users and prevent unauthorized access
- Process payments and financial transactions
- Send transactional notifications and service updates
- Maintain platform performance and reliability
4.3 Safety and Security
- Detect, prevent, and respond to fraud, abuse, and security threats
- Verify professional user identities and credentials
- Comply with legal obligations and regulatory requirements
- Enforce our Terms of Service and user agreements
4.4 Improvement and Analytics
- Analyze usage patterns to improve our services
- Develop new features and functionality
- Conduct research and data analysis for product development
- Optimize solar forecasting algorithms and accuracy
4.5 Marketing (With Consent)
- Send promotional content about our services
- Personalize your experience based on preferences
- Provide relevant recommendations and offers
5. Data Sharing and Disclosure
5.1 Service Providers
We share data with trusted third-party service providers who perform services on our behalf:
- Cloud Infrastructure: Hosting, storage, and computing services
- Payment Processors: Secure payment processing and fraud prevention
- Weather Data Providers: Open-Meteo for meteorological data
- Communication Services: Email, SMS, and notification delivery
- Analytics Services: Usage analytics and performance monitoring
All service providers are contractually bound to protect your data and may only use it for specified purposes.
5.2 Professional Users
We share relevant information with professional users to facilitate services:
- Installers: Your location, energy profile, and contact information when you request installation services
- Dealers: Order information and delivery details for equipment purchases
- Verification: Professional credentials and verification status (visible to other users)
5.3 Legal Requirements
We may disclose your information when required by law:
- Compliance with legal obligations, court orders, or government requests
- Protection of our rights, property, or safety
- Prevention of fraud or illegal activity
- Cooperation with law enforcement investigations
5.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred to the new owner. We will notify you of any such transfer.
5.5 No Sale of Personal Data
We do not sell your personal data to third parties for their marketing purposes.
6. International Data Transfers
6.1 Nigeria as Primary Jurisdiction
Our primary operations and data storage are based in Nigeria. All data processing is conducted in compliance with NDPR requirements.
6.2 Cross-Border Transfers
We may transfer data to other countries in the following circumstances:
- Service Providers: To cloud infrastructure and service providers located in jurisdictions with adequate data protection laws
- EU Market Operations: When operating in the EU, we ensure transfers comply with GDPR Chapter V requirements using Standard Contractual Clauses (SCCs) or other approved mechanisms
- African Regional Operations: For operations in Kenya, Ghana, and South Africa, transfers comply with respective data protection laws and regional frameworks
6.3 Adequacy and Safeguards
For international transfers, we ensure:
- Recipient countries have adequate data protection laws, OR
- Appropriate safeguards are in place (SCCs, binding corporate rules), OR
- Specific exceptions apply under applicable law
6.4 EU Market Readiness
For EU operations, we have implemented:
- GDPR-compliant data processing agreements with all third-party processors
- Standard Contractual Clauses for international data transfers
- Data Protection Impact Assessments (DPIAs) for high-risk processing
- EU Representative designation (where required)
7. Data Retention
7.1 Retention Principles
We retain your personal data only as long as necessary for the purposes for which it was collected, in accordance with NDPR Principle 5 and GDPR Article 5(1)(e).
7.2 Specific Retention Periods
- Account Data: While your account remains active, plus 7 years after closure (legal and tax requirements)
- Transaction Records: 7 years (financial and tax regulations)
- Energy Profiles: While your account is active, plus 2 years after last activity
- Communication Logs: 2 years for support purposes
- Analytics Data: 2 years in anonymized/aggregated form
- Marketing Data: Until consent withdrawal or 2 years of inactivity
7.3 Data Deletion
When retention periods expire, we securely delete or anonymize your data. Some data may be retained in:
- Backup and disaster recovery systems (until overwritten)
- Archived logs (for security and compliance purposes)
- Anonymous/aggregated form for analytics (no longer personal data)
8. Your Data Rights
8.1 Right to Access (Article 15 GDPR, Section 2.5 NDPR)
You have the right to request:
- Confirmation of whether we process your personal data
- A copy of your personal data
- Information about processing purposes, categories of data, and recipients
- The source of your personal data (if not collected directly from you)
8.2 Right to Rectification (Article 16 GDPR, Section 2.6 NDPR)
You have the right to request:
- Correction of inaccurate or incomplete personal data
- Updates to your account information and preferences
8.3 Right to Erasure (Right to be Forgotten) (Article 17 GDPR, Section 2.7 NDPR)
You have the right to request deletion of your personal data when:
- The data is no longer necessary for the purposes for which it was collected
- You withdraw your consent (where processing is based on consent)
- You object to processing and there is no overriding legitimate ground
- The data has been processed unlawfully
- We are required to delete by law
We may retain certain data for legal, regulatory, or legitimate business purposes even after deletion requests.
8.4 Right to Restrict Processing (Article 18 GDPR)
You have the right to request restriction of processing when:
- You contest the accuracy of the data (pending verification)
- Processing is unlawful but you oppose erasure
- We no longer need the data but you require it for legal claims
- You have objected to processing (pending verification of legitimate grounds)
8.5 Right to Data Portability (Article 20 GDPR)
You have the right to receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller.
8.6 Right to Object (Article 21 GDPR)
You have the right to object to processing based on legitimate interests, including profiling for marketing purposes.
8.7 Rights in Relation to Automated Decision Making (Article 22 GDPR)
You have the right not to be subject to decisions based solely on automated processing, including profiling, which produces legal or similarly significant effects. Our solar sizing algorithms provide recommendations but do not make binding decisions without human review.
8.8 NDPR-Specific Rights
Under NDPR, you also have the right to:
- Be informed of data breaches affecting your personal data within 72 hours
- Compensate for damages resulting from data processing violations
- File complaints with NITDA or seek judicial remedy
8.9 Exercising Your Rights
To exercise any of these rights, contact us at:
- Email: privacy@easycitysystems.com.ng
- Phone: [To be provided]
- Address: [To be provided]
We will respond to your request within 30 days (GDPR) or 30 days (NDPR), subject to complexity and volume of requests.
9. Data Security
9.1 Security Measures
We implement appropriate technical and organizational measures to protect your personal data:
- Encryption: Data in transit (TLS 1.3) and at rest (AES-256)
- Access Controls: Role-based access, least privilege, multi-factor authentication
- Network Security: Firewalls, intrusion detection, DDoS protection
- Application Security: Secure coding practices, regular penetration testing, vulnerability scanning
- Physical Security: Secure data centers with access controls and monitoring
9.2 Data Breach Notification
In the event of a personal data breach:
- NDPR: We will notify NITDA within 72 hours of becoming aware
- GDPR: We will notify the supervisory authority within 72 hours where feasible
- Affected Individuals: We will notify you without undue delay if the breach poses a high risk to your rights and freedoms
9.3 Third-Party Security
We require all third-party service providers to implement appropriate security measures and comply with applicable data protection laws.
10. Children's Privacy
10.1 Age Restrictions
Our services are not intended for children under the age of 18. We do not knowingly collect personal data from children under 18.
10.2 Parental Consent
If we discover that we have collected personal data from a child under 18 without parental consent, we will take steps to delete such information immediately.
10.3 Professional Users
Professional users (installers, dealers) must be at least 18 years old and legally authorized to enter into contracts on behalf of their business.
11. Cookies and Tracking Technologies
11.1 Cookie Usage
We use cookies and similar technologies to:
- Maintain your session and authentication state
- Remember your preferences and settings
- Analyze usage patterns and improve our services
- Provide personalized content and recommendations
11.2 Cookie Categories
- Essential Cookies: Required for core functionality (cannot be disabled)
- Analytics Cookies: Help us understand how users use the Platform
- Preference Cookies: Remember your settings and choices
- Marketing Cookies: Used for personalized marketing (with consent)
11.3 Cookie Consent
We obtain your consent for non-essential cookies through our cookie consent banner. You can manage your cookie preferences through your browser settings or our consent management tool.
11.4 Do Not Track
Our platform currently does not respond to Do Not Track (DNT) signals. For more information, please refer to our Cookie Policy.
12. Changes to This Privacy Policy
12.1 Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or operational needs.
12.2 Notification of Changes
We will notify you of material changes by:
- Emailing the address associated with your account
- Posting a prominent notice on the Platform
- Updating the "Effective Date" at the top of this policy
12.3 Continued Use
Your continued use of the Platform after changes to this policy constitutes acceptance of the updated policy.
13. Jurisdiction-Specific Provisions
13.1 Nigeria (NDPR)
For Nigerian users, we comply with the Nigeria Data Protection Regulation 2019 issued by NITDA. Key provisions include:
- Data processing must be lawful, fair, and transparent
- Data must be collected for specific, explicit, and legitimate purposes
- Data must be adequate, relevant, and not excessive
- Data must be accurate and kept up to date
- Data must not be retained longer than necessary
- Data must be processed securely
- Data subjects have rights to access, correct, delete, and object to processing
- Data breaches must be reported to NITDA within 72 hours
13.2 European Union (GDPR) - Market Ready
For EU users, our operations are designed to comply with the General Data Protection Regulation (EU) 2016/679. Our EU market readiness includes:
- Lawful bases for all processing activities (contract, legal obligation, legitimate interests, consent)
- Explicit consent for special categories of data (location, energy patterns)
- Data Protection Impact Assessments for high-risk processing
- Data Protection Officer designation (where required by scale)
- EU Representative for non-EU establishments (where required)
- Standard Contractual Clauses for international data transfers
- One-stop-shop mechanism for cross-border processing
- 72-hour breach notification to supervisory authorities
13.3 South Africa (POPIA) - Aligned
For South African users, our practices align with the Protection of Personal Information Act 4 of 2013:
- Processing must be lawful, reasonable, and fair
- Minimum necessary data collection
- Specific purpose limitation
- Openness and transparency
- Security safeguards
- Data subject participation rights
- Information Protection Regulator oversight
13.4 Kenya (Data Protection Act) - Compliant
For Kenyan users, we comply with the Data Protection Act 2019:
- Office of the Data Protection Commissioner registration
- Lawful processing with consent or other legal basis
- Data subject rights (access, correction, deletion, objection)
- Data protection principles (purpose limitation, data minimization, security)
- Data breach notification within 72 hours
- Cross-border data transfer restrictions
13.5 Ghana (Data Protection Act) - Ready
For Ghanaian users, our practices are ready to comply with the Data Protection Act 2012:
- Data Protection Commission registration
- Lawful processing with consent or other legal basis
- Data subject rights and participation
- Data protection principles and security measures
- Data controller registration requirements
14. Contact Information
14.1 Data Protection Officer
If you have questions about this Privacy Policy or our data practices, contact our Data Protection Officer:
- Email: dpo@easycitysystems.com.ng
- Phone: [To be provided]
- Address: [To be provided]
14.2 General Inquiries
For general privacy inquiries or to exercise your rights:
- Email: privacy@easycitysystems.com.ng
- Phone: [To be provided]
- Address: EasyCity Systems Ltd., [Full Address to be provided]
14.3 Regulatory Complaints
If you believe we have violated your data protection rights, you may file a complaint with the relevant supervisory authority:
- Nigeria: National Information Technology Development Agency (NITDA)
- European Union: Your local Data Protection Authority
- South Africa: Information Protection Regulator
- Kenya: Office of the Data Protection Commissioner
- Ghana: Data Protection Commission
15. Governing Law and Dispute Resolution
15.1 Governing Law
This Privacy Policy is governed by the laws of the Federal Republic of Nigeria, without regard to its conflict of law provisions.
15.2 Dispute Resolution
Any disputes arising from this Privacy Policy or our data practices will be resolved through:
- Good faith negotiation between the parties
- Mediation through a mutually agreed mediator
- Courts of competent jurisdiction in Nigeria as a final resort
15.3 Cross-Border Disputes
For users outside Nigeria, we will make reasonable efforts to resolve disputes in accordance with local laws and international data protection frameworks.
16. Severability
If any provision of this Privacy Policy is found to be invalid or unenforceable, the remaining provisions will continue in full force and effect. The invalid or unenforceable provision will be replaced with a valid provision that most closely reflects the original intent.
17. Entire Agreement
This Privacy Policy, together with our Terms of Service and other legal notices, constitutes the entire agreement between you and EasyCity Systems Ltd. regarding the collection, use, and disclosure of your personal data.
18. Acknowledgment
By using Zolar, you acknowledge that you have read, understood, and agree to this Privacy Policy. You further acknowledge that this policy may be updated from time to time and that your continued use of the Platform constitutes acceptance of any changes.