Data Protection and Compliance Policy
Our compliance commitments under UK GDPR and the Nigeria Data Protection Act.
RC No: 9235708
DATA PROTECTION AND COMPLIANCE POLICY
Effective Date: July 11, 2026
Version: 1.0 (Regulatory Standards Alignment)
1. PURPOSE, SCOPE, AND OBJECTIVES
The Global ManityHQ Network ("ManityHQ," "we," "us," or "our") handles highly sensitive personal, behavioral, and experiential data across multiple sovereign jurisdictions. As an organisation grounded in our BASE framework, particularly Empathy and Service, safeguarding the integrity of the data assets entrusted to us by our members, partners, and volunteers is a fundamental priority.
The purpose of this Data Protection Policy is to define the technical, administrative, and organisational frameworks that ManityHQ enforces to protect personal information. This Policy applies universally to all international branches, cloud database servers, operational workflows, research data processes, and data processors acting on behalf of ManityHQ.
To ensure complete compliance across our global network, this policy is structured to meet or exceed the requirements of:
- The Nigeria Data Protection Act (NDPA).
- The United Kingdom General Data Protection Regulation (UK GDPR).
- The Personal Information Protection and Electronic Documents Act (PIPEDA) of Canada
2. CORE DATA PROTECTION PRINCIPLES
ManityHQ demands that all data processing operations adhere strictly to the following six international core pillars. Personal data must be:
2.1. Fair, Lawful, and Transparent: Collected only with explicit, uncoerced consent, ensuring the user is fully aware of how their information is used.
2.2. Purpose-Limited: Gathered strictly for specified, legitimate organisational purposes (e.g., onboarding into The BASE, distributing Gratitude Challenge behavioral prompts, or conducting Hug-a-Man Day research) and never repurposed for third-party commercial exploitation.
2.3. Minimised: Confined exclusively to the minimum baseline data required to execute our specific community initiatives.
2.4. Accurate and Current: Regularly audited and updated, ensuring that incorrect, incomplete, or outdated user records are immediately rectified or deleted.
2.5. Storage-Limited: Retained only for as long as necessary to fulfill the core operational community functions or to meet statutory accounting and transparency compliance laws.
2.6. Secure and Airtight: Protected by industry-standard encryption, firewalls, and restricted administrative management layers to prevent accidental leaks, theft, or unauthorised alteration.
3. RIGHTS OF THE DIGITAL USER (DATA SUBJECTS)
ManityHQ establishes a uniform global standard for data subject rights. Regardless of whether a user is interacting from Lagos, Abuja, Halifax, or London, or any other part of the world, they possess the following executable rights via our platform terminal:
3.1. Right to Direct Information: The right to clear, plain-language explanations of how their information is being processed before data input occurs.
3.2. Right of Access: The right to request and receive a full digital copy of all personal records compiled by ManityHQ regarding their identity.
3.3. Right to Data Portability: The right to request that their structured, machine-readable profile data be safely exported and transferred directly to another non-profit or entity.
3.4. Right to Rectification: The right to modify, correct, or update their personal files or contact criteria at any time.
3.5. Right to Erasure ("The Right to be Forgotten"): The right to demand that all personal tracking data, mailing list subscriptions, and profiles within The BASE be permanently deleted from ManityHQ's live databases.
3.6. Right to Restriction of Processing: The right to opt out of automated notifications or marketing tracks while retaining basic membership inside our peer safety spaces.
4. TECHNICAL SECURITY IMPLEMENTATION MATRIX
To achieve maximum operational defense as we complete our platform digitisation, ManityHQ mandates the following engineering and structural safeguards:
4.1. Data Encryption Standards
- In-Transit: All information passed through web forms, checkout terminals ("Shop with Purpose"), or user onboarding portals must be shielded using end-to-end Secure Socket Layer (SSL) and Transport Layer Security (TLS) encryption protocols.
- At-Rest: Main database spreadsheets, research survey results, and digital archives stored on cloud computing servers must be secured using advanced encryption standard algorithms (AES-256).
4.2. Role-Based Access Control (RBAC)
To eliminate structural vulnerabilities, access to un-anonymised databases containing real names, phone numbers, or emails is strictly segregated.
- Executive Level (CEO & Board): Full strategic oversight and administrative data review permissions.
- Community Management Level (The BASE Community Manager): Access limited purely to communication vectors, onboarding tracking, and safety monitoring inside community portals.
- Volunteer & Field Level: Absolute zero access to master databases. Field volunteers operate solely via localised, front-end digital collection tools that mask backend records.
4.3. Anonymisation and Data Segregation Protocols
For our data-centric research initiatives (such as the surveys deployed on Hug-a-Man Day), data must be split at the point of origin. Well-being statistics, stress ratings, and thematic challenges must be systematically divorced from names, telephone handles, or IP addresses. The final research report must reflect entirely aggregate, non-identifiable demographic arrays
5. DATA PROCESSOR & THIRDPARTY VETTING POLICY
ManityHQ routinely coordinates with specialised third-party providers (e.g., Landbank Homes for graphic assets, video streaming networks for Man Talk, and secure payment gateways).
- All third-party processors must be bound by a formal Data Processing Agreement (DPA).
- Partners are legally prohibited from extracting, retaining, sharing, or repurposing our community data for external marketing or commercial initiatives.
6. DATA BREACH MANAGEMENT AND NOTIFICATION PROTOCOLS
A personal data breach refers to any accidental, unlawful, or unauthorised destruction, loss, alteration, disclosure of, or access to personal data transmitted, stored, or processed by ManityHQ.
In the event of a verified or suspected data compromise, the following rapid-response protocol is initiated under the leadership of the Chief Executive Officer:
Immediate Containment: Isolation of affected web servers, rotation of database credentials, and deployment of security counter-measures within 24 hours.
Impact Risk Assessment: Determination of the scale, sensitivity, and potential emotional or privacy risk presented to affected data subjects.
Regulatory Notification: If the breach presents a high risk to individual privacy, ManityHQ will officially report the incident to the appropriate regulatory body (e.g., the Nigeria Data Protection Commission - NDPC) within 72 hours of discovery.
User Notification: Affected members of our global network will be directly notified via email or official channels without undue delay, outlining the nature of the breach and clear steps to protect their accounts.
7. PRIVACY BY DESIGN AND ACCOUNTABILITY
ManityHQ embeds privacy directly into the design phase of all new programs, code deployments, and data systems. Our executive team conducts periodic Data Protection Impact Assessments (DPIAs) prior to rolling out high-volume digital tools or international cross-border data migrations.
8. COMPLIANCE ENFORCEMENT AND AMENDMENTS
All administrative staff, board representatives, and designated managers are bound to read, sign, and uphold this compliance framework. Failure to adhere to these standards will result in immediate disciplinary action or termination of partnership arrangements. This document will be reviewed annually to maintain strict alignment with evolving international data laws.
ACKNOWLEDGMENT
I, ________________________________________, acknowledge that I have read, understood, and agree to comply with this Data Protection and Compliance Policy.
Signature: _______________________________
Date: ____________________________________
