Interested in Capital Markets? Let's Brainstorm with You.Client Login

Privacy Policy

Dime Legacy Partners · RC. 1927994

Applies to: dimelegacy.com (Client Portal), herohr.dimelegacy.com, partners.dimelegacy.com, careers.dimelegacy.com, and admin.dimelegacy.com where personal data of the surfaces above is processed internally.

Controller: Dime Legacy Partners ("DLP", "we", "us", "our"), RC. 1927994, a company registered in Nigeria, operating across Nigeria, Ghana, and Kenya.

Effective date: 26 August 2026

Last reviewed: Pending qualified legal counsel review

This document is an initial legal framework generated from a technical audit of the DLP platform. It is not a substitute for advice from qualified legal counsel. It must be reviewed, and adapted as necessary, by a lawyer licensed in Nigeria (and, where DLP operates directly in those markets, Ghana and Kenya) before publication.


1. Scope

This Policy explains how DLP collects, uses, discloses, and protects personal data across every surface of the DLP platform: the public marketing and regulatory-intelligence site, the authenticated client workspace, the HeroHR talent services surface, the delivery and referral partner workspace, and the careers recruitment site. It also covers data collected through related channels such as email, WhatsApp, and session bookings.

It does not cover the practices of third-party sites we link to (including government regulator portals) or of DLP's offline advisory and filing work once a matter leaves the platform, which is governed by the relevant engagement letter.


2. The hybrid platform model

DLP's platform is a digital workspace, not a full replacement for DLP's advisory and filing services. It prepares, compiles, and pre-vets information before a matter is handed to DLP's advisors and, where applicable, legal counsel for offline government filing. Some steps in a client's journey therefore happen online (assessment, document upload, pipeline tracking, e-signature) and some happen offline (government submissions, capital escrow, hearings, certificate dispatch, and all fee discussions and payment). This Policy covers the online steps only. Offline steps are covered by the applicable engagement letter and DLP's standard client-care practices.

DLP does not process payments on the platform. No payment card, bank account, or similar financial instrument data is collected through the platform.


3. Who this Policy applies to

  • Prospective and active clients of the Client Portal, including

incorporated companies, pre-incorporation founders, and guest users who have started but not completed registration.

  • HeroHR clients submitting a talent brief, whether standalone or as

part of another practice engagement.

  • Delivery and referral partners applying to, or working within, the

Partner Portal.

  • Candidates considered for placement through HeroHR search and

selection work. Candidates are not platform users; see Section 9.

  • Talent network members who submit their details for future

consideration, without seeking an active role.

  • Job applicants to DLP itself via the careers site.

  • Website visitors using the public regulatory tools and content

(license finder, capital calculator, market estimator, insights).


4. Personal data we collect

We collect only what is needed for the purpose stated at the point of collection.

Category

Examples

Collected from

Identity and contact

Name, email, phone number, job title, company name

Registration, brief/intake forms, session booking

Account credentials

Password (hashed, never stored or logged in plain text), one-time passcodes (hashed)

Registration, login, password reset

Verification data

Corporate email domain, self-declaration text (pre-incorporation founders)

Registration

Engagement content

Questionnaire responses, documents uploaded, docket notes, messages to advisors or partners

Assessment flow, portal use, partner communication

AI-generated content

Assessment reports, debrief conversation transcripts

Gate 1/Gate 2 assessment, debrief interface

Session and scheduling data

Slot preferences, confirmed session time, session notes

Session booking

Signature data

Drawn signature image, IP address, device fingerprint, timestamp, OTP verification record

E-signature flow

Partner application data

Profile summary, LinkedIn URL, CV (optional), current employer disclosure, practice area selection, authority and indemnification attestations

Partner application form

Candidate data (HeroHR)

Name, contact details, employment history, assessment notes

HeroHR search process, with consent (Section 9)

Talent network data

Name, contact details, skills, self-submitted profile

Talent network submission forms

Communications preferences

WhatsApp opt-in status

Account settings

Technical data

IP address, device and browser identifiers, authentication cookies

Automatically, on platform use (see our Cookie Policy)

Support and correspondence

Content of emails or messages sent to DLP

Any support channel

We do not knowingly collect special category or sensitive personal data beyond what a candidate or client voluntarily discloses in the course of an engagement (for example, in a document uploaded as part of a filing). Where such data is disclosed, it is handled under the same technical and organisational safeguards as all Class B data described in Section 11.


5. How we use personal data

Purpose

Legal basis (Nigeria Data Protection Act 2023 (NDPA) / analogous Ghana and Kenya bases)

Creating and administering an account

Contract necessity

Verifying identity (OTP, corporate domain check)

Contract necessity, legitimate interest (fraud prevention)

Running the Gate 1 assessment and generating Gate 2 AI reports

Contract necessity, consent for AI processing where required

Operating the debrief conversation feature

Contract necessity

Scheduling and confirming sessions

Contract necessity

Creating and progressing dockets and pipelines

Contract necessity

Sending transactional emails and WhatsApp notifications

Contract necessity; WhatsApp specifically requires opt-in consent

Countersigning and storing agreements

Contract necessity, legal obligation (evidentiary record)

Assigning delivery partners to dockets

Contract necessity

Tracking referral partner conversions

Legitimate interest (commercial relationship management)

HeroHR candidate sourcing and shortlisting

Consent (Section 9)

Talent network contact for future roles

Consent (opt-in at submission)

Careers applications

Contract necessity (pre-contractual steps), forwarded to our recruitment system provider

Regulatory update notifications to subscribers

Consent (subscription opt-in, with unsubscribe link)

Security, fraud prevention, and audit logging

Legitimate interest, legal obligation

Aggregated analytics on platform usage and AI report quality

Legitimate interest

We do not use personal data for automated decision-making that produces legal or similarly significant effects without human involvement. AI- generated assessment reports are decision-support only; every result that affects a client's engagement is reviewed and actioned by a DLP advisor, not the AI system alone.


6. AI processing

DLP uses a third-party large language model provider to generate structured assessment reports (Gate 2) and to power a scoped debrief conversation, strictly limited to the findings of a client's own report. DLP selects, and may from time to time change, which provider is used; the current provider is included in the sub-processor categories listed in Section 8. Only structured, compiled questionnaire data, not raw free-text submissions, is sent to the AI system for report generation. AI processing is a server-side function; no client browser communicates directly with the AI provider. AI-generated reports and debrief transcripts are retained for a limited period (see Section 12) and are not used to train any third-party AI model.

AI-generated content is informational and does not constitute regulatory, legal, tax, or financial advice. See our AI Assessment Disclaimer for further detail.


7. Disclosures of personal data

We disclose personal data only as necessary to operate the platform and deliver the engagement:

  • To DLP personnel (admin users), scoped by role and, for compliance

matters, by practice area, on a need-to-know basis.

  • To delivery partners, limited to the docket they are assigned to,

and never including a client's company name or full profile, only a reference number, consistent with DLP's internal access controls.

  • To service providers acting on our behalf (sub-processors), under

contractual confidentiality and data protection obligations. See Section 8.

  • Where required by law, including in response to a valid request

from a regulator, court, or law enforcement authority.

  • In connection with a corporate transaction (merger, acquisition, or

asset sale), subject to the same protections described in this Policy.

We do not sell personal data, and we do not share personal data with third parties for their own independent marketing purposes.


8. Sub-processors and international transfers

The platform relies on the following categories of service provider, each acting as a data processor on DLP's instructions:

Function

Provider category

Data involved

Database, authentication, file storage

Managed database and backend platform provider

All account, engagement, and document data

Application hosting

Cloud hosting platform

All data in transit to and from the platform

DNS and network security

Content delivery and security provider

Technical and connection data

Transactional email

Email delivery provider

Name, email address, message content

WhatsApp messaging

WhatsApp Business API provider

Phone number, message content, only for opted-in users

AI processing

AI model provider

Structured assessment data, debrief conversation content

Document backup

Cloud storage provider

Signed agreements, expired assessment reports, uploaded documents

Error tracking and logging

Error monitoring and log management providers

Technical error data, scrubbed of passwords, tokens, and OTPs

Uptime monitoring

Uptime monitoring provider

Service availability data only

Careers applicant tracking

Recruitment system provider

Job applicant data submitted via the careers site

A current list naming each provider is maintained internally and is available on request. We select providers that offer contractual data protection commitments consistent with this Policy.

Our primary database is hosted in the United Kingdom. Other sub-processors we use are based in the United States, the European Union, and other jurisdictions where those providers operate. This means most personal data collected through the platform is transferred outside Nigeria, Ghana, and Kenya as a routine part of how the platform runs, not as an exception. For each such transfer, we rely on the sub-processor's contractual data protection commitments and, where applicable, standard contractual clauses or another safeguard recognised as adequate under the NDPA, and the Ghana and Kenya data protection regimes described in Section 13. A current list naming each sub-processor's country of operation is maintained internally and is available on request (see Section 16).


9. HeroHR candidate data (special handling)

HeroHR sources, assesses, and places candidates for executive search, specialist, and contractor roles. Candidates are never platform users; they do not log in and are never shown to a client directly through the platform.

  • Candidate personal data is stored only after consent has been recorded,

either as a verbally logged confirmation or a written, emailed confirmation.

  • At the longlist stage, a client sees only an anonymised profile: no

name, no contact details, no employer named.

  • A named, fully identified profile is released to a client only once a

candidate is promoted to the shortlist by a DLP admin.

  • Candidate personal data is held for the duration of the placement

process, and, if placed, for the duration of the placement plus two years, after which it is anonymised.

  • Candidates may withdraw consent, or request access to, correction of,

or deletion of their data, by contacting us using the details in Section 16. A withdrawal made after a shortlist has been shared with a client may not be capable of undoing that specific disclosure.


10. Talent network members

Talent network submissions (via HeroHR or the careers site) are a separate, lighter-weight channel from active candidate sourcing. Talent network members submit their details once for future consideration; there is no ongoing portal relationship. DLP may contact a talent network member directly when a relevant opportunity arises, and may export talent network data to our recruitment system provider for that purpose. A talent network member may ask to be removed from the network at any time.


11. How we protect personal data

  • All data is encrypted in transit (TLS) and at rest.

  • Backups are encrypted before storage.

  • HeroHR candidate personal data (name, email, phone) receives additional

column-level encryption.

  • Access to personal data is governed by role-based and, where relevant,

practice-based access controls, enforced both in the application and at the database level.

  • File access is granted only through short-lived signed links, not

public URLs.

  • We classify data by sensitivity (highly sensitive, sensitive, internal)

and apply protections accordingly, including logging access to the most sensitive categories.

  • Passwords and one-time passcodes are never stored, logged, or

transmitted in plain text.

No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the data involved.


12. Retention

Data type

Active retention

Backup retention

Active client accounts

While the account remains active

Retained after deletion, per Section 15

Unverified guest accounts and their dockets

30 days, then soft-deleted

30 days, in backup

AI assessment reports (in-portal)

30 days, then removed from active storage

Retained indefinitely in secure backup; a record of the report having existed remains visible in the portal

Signed agreements

Retained indefinitely (evidentiary and legal requirement)

Retained indefinitely in secure backup

Audit logs

90 days in the active system

Archived indefinitely thereafter

Candidate data

Duration of the placement process, plus two years after placement

Anonymised thereafter, retained indefinitely in anonymised form

One-time passcodes

10 minutes

Not backed up

Session (login) revocation records

Until the underlying token naturally expires

Not backed up

Where we no longer need personal data for the purposes described in this Policy, we delete or anonymise it, subject to any legal obligation to retain it for longer, such as our obligation to preserve signed agreements as an evidentiary record.


13. Your rights

Depending on your jurisdiction, and consistent with the Nigeria Data Protection Act 2023 (NDPA), the Ghana Data Protection Act 2012, and the Kenya Data Protection Act 2019, you may have the right to:

  • Access the personal data we hold about you. Client requests can be

made through account settings; we fulfil these within 30 days.

  • Correct inaccurate personal data. Client profile data can be updated

directly in account settings.

  • Request deletion of your account and associated personal data. This

is actioned as a soft delete immediately, with backup data retained per the schedule in Section 12. Signed agreements cannot be deleted while an evidentiary obligation applies to them.

  • Object to, or restrict, certain processing, including withdrawing

consent for WhatsApp notifications, the regulatory update digest, or, for candidates and talent network members, further contact.

  • Data portability, where technically feasible, for data you provided

to us directly.

  • Lodge a complaint with the relevant supervisory authority: the

Nigeria Data Protection Commission (NDPC), the Ghana Data Protection Commission, or the Kenya Office of the Data Protection Commissioner, as applicable to your circumstances.

To exercise any of these rights, contact us using the details in Section 16.


14. Children's data

The platform is intended for business use by adults acting on behalf of themselves or an organisation. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected a child's personal data, we will delete it.


15. Data minimisation

We collect only the personal data reasonably necessary for the stated purpose at each point of collection, and we periodically review the fields requested on our forms against that standard.


16. Contact us

For any question about this Policy, or to exercise a right described in Section 13, contact:

Dime Legacy Partners 6, Anetor Ogie Close, Ojodu, Ogun State, Nigeria Email: partners@dimelegacy.com

We recommend routing privacy-specific requests through a dedicated mailbox (for example, privacy@dimelegacy.com) once established; until then, the address above will be monitored for such requests.


17. Changes to this Policy

We may update this Policy from time to time to reflect changes in the platform or in applicable law. The "Last reviewed" date at the top of this Policy will be updated accordingly. Material changes will be communicated to active account holders by email.


18. Governing law

This Policy, and any dispute over its interpretation or DLP's handling of personal data collected in Nigeria, is governed by the laws of the Federal Republic of Nigeria, without prejudice to any mandatory data protection right available to you under the law of Ghana or Kenya where the platform is used, and where the data collected relates to, activity in that jurisdiction.

Last updated: 12 September 2026