NDPR Compliance
Nigeria Data Protection Regulation (NDPR) 2019
Our Commitment
XpurseCare AI is committed to full compliance with Nigeria's Data Protection Regulation (NDPR) 2019, as issued by the National Information Technology Development Agency (NITDA).
Data Collection Lawfulness
We only collect personal data with a lawful basis — consent, contractual necessity, or legitimate interest. Users are informed of what data is collected and why.
Data Subject Rights
Nigerian data subjects have the right to: access their data, correct inaccurate data, object to processing, request deletion, and data portability.
Data Minimisation
We collect only the minimum data necessary to provide our services. Customer conversation data is used only for AI training with explicit business consent.
Cross-border Transfers
Where data is transferred outside Nigeria, we ensure adequate safeguards are in place, including Standard Contractual Clauses with processors like Supabase and Clerk.
Breach Notification
In the event of a data breach affecting Nigerian citizens, we commit to notifying NITDA within 72 hours and affected users without undue delay.
Contact our DPO
Data Protection Officer: support@xpurseai.com
Need a Data Processing Agreement?
Enterprise customers can request a formal DPA. Contact support@xpurseai.com