Privacy Policy
Dime Legacy Partners · RC. 1927994
Applies to: dimelegacy.com (Client Portal), herohr.dimelegacy.com, partners.dimelegacy.com, careers.dimelegacy.com, and admin.dimelegacy.com where personal data of the surfaces above is processed internally.
Controller: Dime Legacy Partners ("DLP", "we", "us", "our"), RC. 1927994, a company registered in Nigeria, operating across Nigeria, Ghana, and Kenya.
Effective date: 26 August 2026
Last reviewed: Pending qualified legal counsel review
This document is an initial legal framework generated from a technical audit of the DLP platform. It is not a substitute for advice from qualified legal counsel. It must be reviewed, and adapted as necessary, by a lawyer licensed in Nigeria (and, where DLP operates directly in those markets, Ghana and Kenya) before publication.
1. Scope
This Policy explains how DLP collects, uses, discloses, and protects personal data across every surface of the DLP platform: the public marketing and regulatory-intelligence site, the authenticated client workspace, the HeroHR talent services surface, the delivery and referral partner workspace, and the careers recruitment site. It also covers data collected through related channels such as email, WhatsApp, and session bookings.
It does not cover the practices of third-party sites we link to (including government regulator portals) or of DLP's offline advisory and filing work once a matter leaves the platform, which is governed by the relevant engagement letter.
2. The hybrid platform model
DLP's platform is a digital workspace, not a full replacement for DLP's advisory and filing services. It prepares, compiles, and pre-vets information before a matter is handed to DLP's advisors and, where applicable, legal counsel for offline government filing. Some steps in a client's journey therefore happen online (assessment, document upload, pipeline tracking, e-signature) and some happen offline (government submissions, capital escrow, hearings, certificate dispatch, and all fee discussions and payment). This Policy covers the online steps only. Offline steps are covered by the applicable engagement letter and DLP's standard client-care practices.
DLP does not process payments on the platform. No payment card, bank account, or similar financial instrument data is collected through the platform.
3. Who this Policy applies to
Prospective and active clients of the Client Portal, including
incorporated companies, pre-incorporation founders, and guest users who have started but not completed registration.
HeroHR clients submitting a talent brief, whether standalone or as
part of another practice engagement.
Delivery and referral partners applying to, or working within, the
Partner Portal.
Candidates considered for placement through HeroHR search and
selection work. Candidates are not platform users; see Section 9.
Talent network members who submit their details for future
consideration, without seeking an active role.
Job applicants to DLP itself via the careers site.
Website visitors using the public regulatory tools and content
(license finder, capital calculator, market estimator, insights).
4. Personal data we collect
We collect only what is needed for the purpose stated at the point of collection.
Category | Examples | Collected from |
|---|---|---|
Identity and contact | Name, email, phone number, job title, company name | Registration, brief/intake forms, session booking |
Account credentials | Password (hashed, never stored or logged in plain text), one-time passcodes (hashed) | Registration, login, password reset |
Verification data | Corporate email domain, self-declaration text (pre-incorporation founders) | Registration |
Engagement content | Questionnaire responses, documents uploaded, docket notes, messages to advisors or partners | Assessment flow, portal use, partner communication |
AI-generated content | Assessment reports, debrief conversation transcripts | Gate 1/Gate 2 assessment, debrief interface |
Session and scheduling data | Slot preferences, confirmed session time, session notes | Session booking |
Signature data | Drawn signature image, IP address, device fingerprint, timestamp, OTP verification record | E-signature flow |
Partner application data | Profile summary, LinkedIn URL, CV (optional), current employer disclosure, practice area selection, authority and indemnification attestations | Partner application form |
Candidate data (HeroHR) | Name, contact details, employment history, assessment notes | HeroHR search process, with consent (Section 9) |
Talent network data | Name, contact details, skills, self-submitted profile | Talent network submission forms |
Communications preferences | WhatsApp opt-in status | Account settings |
Technical data | IP address, device and browser identifiers, authentication cookies | Automatically, on platform use (see our Cookie Policy) |
Support and correspondence | Content of emails or messages sent to DLP | Any support channel |
We do not knowingly collect special category or sensitive personal data beyond what a candidate or client voluntarily discloses in the course of an engagement (for example, in a document uploaded as part of a filing). Where such data is disclosed, it is handled under the same technical and organisational safeguards as all Class B data described in Section 11.
5. How we use personal data
Purpose | Legal basis (Nigeria Data Protection Act 2023 (NDPA) / analogous Ghana and Kenya bases) |
|---|---|
Creating and administering an account | Contract necessity |
Verifying identity (OTP, corporate domain check) | Contract necessity, legitimate interest (fraud prevention) |
Running the Gate 1 assessment and generating Gate 2 AI reports | Contract necessity, consent for AI processing where required |
Operating the debrief conversation feature | Contract necessity |
Scheduling and confirming sessions | Contract necessity |
Creating and progressing dockets and pipelines | Contract necessity |
Sending transactional emails and WhatsApp notifications | Contract necessity; WhatsApp specifically requires opt-in consent |
Countersigning and storing agreements | Contract necessity, legal obligation (evidentiary record) |
Assigning delivery partners to dockets | Contract necessity |
Tracking referral partner conversions | Legitimate interest (commercial relationship management) |
HeroHR candidate sourcing and shortlisting | Consent (Section 9) |
Talent network contact for future roles | Consent (opt-in at submission) |
Careers applications | Contract necessity (pre-contractual steps), forwarded to our recruitment system provider |
Regulatory update notifications to subscribers | Consent (subscription opt-in, with unsubscribe link) |
Security, fraud prevention, and audit logging | Legitimate interest, legal obligation |
Aggregated analytics on platform usage and AI report quality | Legitimate interest |
We do not use personal data for automated decision-making that produces legal or similarly significant effects without human involvement. AI- generated assessment reports are decision-support only; every result that affects a client's engagement is reviewed and actioned by a DLP advisor, not the AI system alone.
6. AI processing
DLP uses a third-party large language model provider to generate structured assessment reports (Gate 2) and to power a scoped debrief conversation, strictly limited to the findings of a client's own report. DLP selects, and may from time to time change, which provider is used; the current provider is included in the sub-processor categories listed in Section 8. Only structured, compiled questionnaire data, not raw free-text submissions, is sent to the AI system for report generation. AI processing is a server-side function; no client browser communicates directly with the AI provider. AI-generated reports and debrief transcripts are retained for a limited period (see Section 12) and are not used to train any third-party AI model.
AI-generated content is informational and does not constitute regulatory, legal, tax, or financial advice. See our AI Assessment Disclaimer for further detail.
7. Disclosures of personal data
We disclose personal data only as necessary to operate the platform and deliver the engagement:
To DLP personnel (admin users), scoped by role and, for compliance
matters, by practice area, on a need-to-know basis.
To delivery partners, limited to the docket they are assigned to,
and never including a client's company name or full profile, only a reference number, consistent with DLP's internal access controls.
To service providers acting on our behalf (sub-processors), under
contractual confidentiality and data protection obligations. See Section 8.
Where required by law, including in response to a valid request
from a regulator, court, or law enforcement authority.
In connection with a corporate transaction (merger, acquisition, or
asset sale), subject to the same protections described in this Policy.
We do not sell personal data, and we do not share personal data with third parties for their own independent marketing purposes.
8. Sub-processors and international transfers
The platform relies on the following categories of service provider, each acting as a data processor on DLP's instructions:
Function | Provider category | Data involved |
|---|---|---|
Database, authentication, file storage | Managed database and backend platform provider | All account, engagement, and document data |
Application hosting | Cloud hosting platform | All data in transit to and from the platform |
DNS and network security | Content delivery and security provider | Technical and connection data |
Transactional email | Email delivery provider | Name, email address, message content |
WhatsApp messaging | WhatsApp Business API provider | Phone number, message content, only for opted-in users |
AI processing | AI model provider | Structured assessment data, debrief conversation content |
Document backup | Cloud storage provider | Signed agreements, expired assessment reports, uploaded documents |
Error tracking and logging | Error monitoring and log management providers | Technical error data, scrubbed of passwords, tokens, and OTPs |
Uptime monitoring | Uptime monitoring provider | Service availability data only |
Careers applicant tracking | Recruitment system provider | Job applicant data submitted via the careers site |
A current list naming each provider is maintained internally and is available on request. We select providers that offer contractual data protection commitments consistent with this Policy.
Our primary database is hosted in the United Kingdom. Other sub-processors we use are based in the United States, the European Union, and other jurisdictions where those providers operate. This means most personal data collected through the platform is transferred outside Nigeria, Ghana, and Kenya as a routine part of how the platform runs, not as an exception. For each such transfer, we rely on the sub-processor's contractual data protection commitments and, where applicable, standard contractual clauses or another safeguard recognised as adequate under the NDPA, and the Ghana and Kenya data protection regimes described in Section 13. A current list naming each sub-processor's country of operation is maintained internally and is available on request (see Section 16).
9. HeroHR candidate data (special handling)
HeroHR sources, assesses, and places candidates for executive search, specialist, and contractor roles. Candidates are never platform users; they do not log in and are never shown to a client directly through the platform.
Candidate personal data is stored only after consent has been recorded,
either as a verbally logged confirmation or a written, emailed confirmation.
At the longlist stage, a client sees only an anonymised profile: no
name, no contact details, no employer named.
A named, fully identified profile is released to a client only once a
candidate is promoted to the shortlist by a DLP admin.
Candidate personal data is held for the duration of the placement
process, and, if placed, for the duration of the placement plus two years, after which it is anonymised.
Candidates may withdraw consent, or request access to, correction of,
or deletion of their data, by contacting us using the details in Section 16. A withdrawal made after a shortlist has been shared with a client may not be capable of undoing that specific disclosure.
10. Talent network members
Talent network submissions (via HeroHR or the careers site) are a separate, lighter-weight channel from active candidate sourcing. Talent network members submit their details once for future consideration; there is no ongoing portal relationship. DLP may contact a talent network member directly when a relevant opportunity arises, and may export talent network data to our recruitment system provider for that purpose. A talent network member may ask to be removed from the network at any time.
11. How we protect personal data
All data is encrypted in transit (TLS) and at rest.
Backups are encrypted before storage.
HeroHR candidate personal data (name, email, phone) receives additional
column-level encryption.
Access to personal data is governed by role-based and, where relevant,
practice-based access controls, enforced both in the application and at the database level.
File access is granted only through short-lived signed links, not
public URLs.
We classify data by sensitivity (highly sensitive, sensitive, internal)
and apply protections accordingly, including logging access to the most sensitive categories.
Passwords and one-time passcodes are never stored, logged, or
transmitted in plain text.
No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the data involved.
12. Retention
Data type | Active retention | Backup retention |
|---|---|---|
Active client accounts | While the account remains active | Retained after deletion, per Section 15 |
Unverified guest accounts and their dockets | 30 days, then soft-deleted | 30 days, in backup |
AI assessment reports (in-portal) | 30 days, then removed from active storage | Retained indefinitely in secure backup; a record of the report having existed remains visible in the portal |
Signed agreements | Retained indefinitely (evidentiary and legal requirement) | Retained indefinitely in secure backup |
Audit logs | 90 days in the active system | Archived indefinitely thereafter |
Candidate data | Duration of the placement process, plus two years after placement | Anonymised thereafter, retained indefinitely in anonymised form |
One-time passcodes | 10 minutes | Not backed up |
Session (login) revocation records | Until the underlying token naturally expires | Not backed up |
Where we no longer need personal data for the purposes described in this Policy, we delete or anonymise it, subject to any legal obligation to retain it for longer, such as our obligation to preserve signed agreements as an evidentiary record.
13. Your rights
Depending on your jurisdiction, and consistent with the Nigeria Data Protection Act 2023 (NDPA), the Ghana Data Protection Act 2012, and the Kenya Data Protection Act 2019, you may have the right to:
Access the personal data we hold about you. Client requests can be
made through account settings; we fulfil these within 30 days.
Correct inaccurate personal data. Client profile data can be updated
directly in account settings.
Request deletion of your account and associated personal data. This
is actioned as a soft delete immediately, with backup data retained per the schedule in Section 12. Signed agreements cannot be deleted while an evidentiary obligation applies to them.
Object to, or restrict, certain processing, including withdrawing
consent for WhatsApp notifications, the regulatory update digest, or, for candidates and talent network members, further contact.
Data portability, where technically feasible, for data you provided
to us directly.
Lodge a complaint with the relevant supervisory authority: the
Nigeria Data Protection Commission (NDPC), the Ghana Data Protection Commission, or the Kenya Office of the Data Protection Commissioner, as applicable to your circumstances.
To exercise any of these rights, contact us using the details in Section 16.
14. Children's data
The platform is intended for business use by adults acting on behalf of themselves or an organisation. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected a child's personal data, we will delete it.
15. Data minimisation
We collect only the personal data reasonably necessary for the stated purpose at each point of collection, and we periodically review the fields requested on our forms against that standard.
16. Contact us
For any question about this Policy, or to exercise a right described in Section 13, contact:
Dime Legacy Partners 6, Anetor Ogie Close, Ojodu, Ogun State, Nigeria Email: partners@dimelegacy.com
We recommend routing privacy-specific requests through a dedicated mailbox (for example, privacy@dimelegacy.com) once established; until then, the address above will be monitored for such requests.
17. Changes to this Policy
We may update this Policy from time to time to reflect changes in the platform or in applicable law. The "Last reviewed" date at the top of this Policy will be updated accordingly. Material changes will be communicated to active account holders by email.
18. Governing law
This Policy, and any dispute over its interpretation or DLP's handling of personal data collected in Nigeria, is governed by the laws of the Federal Republic of Nigeria, without prejudice to any mandatory data protection right available to you under the law of Ghana or Kenya where the platform is used, and where the data collected relates to, activity in that jurisdiction.
Last updated: 12 September 2026