Before this platform goes live: the placeholders marked [SQUARE BRACKETS] below must be completed by the operating company, and this document must be reviewed by a qualified data protection adviser for every market NDEFFO trades in. Data protection law differs by country and this text has not been tailored to any single jurisdiction.
This policy explains what NDEFFO collects when you use the marketplace, why we hold it, how long we keep it, and what you can ask us to do with it. It covers buyers, corporate suppliers, individual sellers, skill providers and community members.
The data controller is [REGISTERED COMPANY NAME], registered at [REGISTERED ADDRESS], company number [COMPANY NUMBER]. Data protection enquiries go to [PRIVACY CONTACT EMAIL].
1. What we collect
Everyone with an account
- Your name, email address and phone number.
- Your password, which is stored only as a bcrypt hash. We never hold the password itself and cannot recover it for you.
- Delivery addresses you save, and the address snapshot attached to each order.
- Your orders, carts, reviews, returns and messages sent through the platform.
- Sign in activity, including failed attempts, so we can lock an account that is being attacked.
Corporate suppliers
- Legal business name, registration number and tax number.
- Business registration certificate, tax clearance or trading licence, and bank confirmation letter.
- Trading contact details, and the payout details we settle against.
Individual sellers
- National identity number and a copy of the identity document.
- Proof of residence and residential address.
- Payout details, which may be a bank account or a mobile wallet.
- Your guarantor's name, identity number, contact details and signed guarantee.
Skill providers
- Curriculum vitae, identity document and profile photograph.
- Next of kin name, relationship, identity number and contact details.
- Referee letters.
Community and charity participants
- Donation listings, requests and the receipts uploaded to evidence a contribution.
2. Why we hold it, and on what basis
- To run your account and process orders. This is necessary to perform the contract between you and NDEFFO, and between you and the seller you buy from.
- To verify sellers and service providers. We check identity, business registration and guarantor documents before allowing anyone to trade. This protects buyers from fraud and is a legitimate interest of the marketplace and every honest participant on it.
- To calculate commission, settlements, refunds and invoices. This is necessary for the contract and, for invoices and tax records, to comply with a legal obligation.
- To keep the platform secure. We log administrative actions and access to sensitive documents so that misuse can be detected and traced.
- To send you service messages about your orders, deliveries, returns and applications. These are not marketing and you cannot opt out of them while you hold an active order.
3. What is public, and what is not
Your name is not published. What appears publicly is limited to the following.
- A seller's trading name, logo, cover image, city, rating and product listings.
- A skill provider's first name, skills, service area, rating and completed engagement count.
- Reviews you write, shown against your first name and the initial of your surname.
A skill provider's phone number and email address are never published. A consumer must submit a request, and contact details are released only after that request is approved, only to the consumer who made it, and the release is recorded.
Identity numbers are shown to administrators in masked form. The full document is opened only when a named administrator deliberately views it, and every one of those views is written to the audit log.
4. Documents and where they are stored
Identity documents, proof of residence, guarantor guarantees, next of kin details, referee letters, curricula vitae, bank confirmations and charity receipts are treated as sensitive. They are stored outside the public web root, they are not reachable by guessing a URL, and every read is authorised against the requesting account. Only the person who uploaded a document and an authorised administrator can open it.
5. Payments
Card and banking credentials are never stored by NDEFFO. Online payments are processed by Paynow, and only the reference and status of a payment are returned to us. Payout details you give us for settlement are held so that we can pay you, and are visible only to you and to authorised finance administrators.
6. Who we share information with
- The seller you buy from receives your delivery name, address, phone number and order contents, because they cannot deliver without them. They do not receive your email address or your account history.
- The buyer receives the seller's trading identity and, once a quotation is accepted, the buyer's full name is released to the winning supplier so the two can transact.
- Couriers receive the delivery details needed to carry the parcel.
- Our payment processor receives the amount and reference for the transaction.
- Authorities receive information where we are legally required to provide it.
We do not sell your personal information, and we do not share it for third party advertising.
7. International transfers
NDEFFO is an international marketplace, so buying from a seller in another country necessarily involves sending your delivery details to that country. Platform data is hosted at [HOSTING LOCATION]. Where a transfer leaves your own jurisdiction, it is made under [TRANSFER SAFEGUARD, for example standard contractual clauses].
8. How long we keep it
- Account records: while your account is open, then [RETENTION PERIOD] after closure.
- Orders, invoices and settlement records: [STATUTORY RETENTION PERIOD, commonly 5 to 7 years] to meet tax and accounting obligations.
- Verification documents: for as long as the seller or provider trades, then [RETENTION PERIOD] after the account closes.
- Audit logs: [RETENTION PERIOD], because their value is in being able to look back.
- Sessions: deleted when they expire, which is 14 days after sign in, or immediately when you sign out.
9. Your rights
Subject to the law that applies where you are, you can ask us to:
- give you a copy of the information we hold about you;
- correct anything that is wrong;
- delete your information, where we are not required to keep it for tax, accounting or fraud prevention reasons;
- restrict or object to a particular use;
- provide your information in a portable format;
- withdraw a consent you previously gave, without affecting what was done before you withdrew it.
Write to [PRIVACY CONTACT EMAIL]. We answer within [RESPONSE PERIOD, commonly 30 days]. If you are not satisfied you can complain to [SUPERVISORY AUTHORITY].
10. How we protect your information
- Passwords are hashed with bcrypt and are never stored or logged in readable form.
- Sessions use a random token; only a SHA-256 hash of that token is stored, so a database copy cannot be used to impersonate you.
- Sensitive documents are stored outside the public web root and every read is authorised.
- Administrator access is permission controlled, and administrative actions are recorded in an audit log.
- Uploaded images are re-encoded, which removes embedded location data your camera may have added.
No system is perfectly secure. If a breach affects you and presents a real risk, we will tell you and the relevant authority within the period the law requires.
11. Children
NDEFFO is not intended for anyone under [MINIMUM AGE]. We do not knowingly collect information from children. If you believe a child has given us information, write to [PRIVACY CONTACT EMAIL] and we will delete it.
12. Changes
When we change this policy we update the date shown on this page. If a change materially affects how we use your information, we will tell you directly before it takes effect.
Last updated 28 Aug 2026