This is an internal governance policy for DWS CODES LTD, prepared for compliance with the Nigeria Data Protection Act, 2023 (NDPA) and enforced by the Nigeria Data Protection Commission (NDPC). It sits alongside, and above, the Privacy Policy: the Privacy Policy tells users what we do with their data; this Policy tells our own staff, contractors, and partner institutions how we are required to handle it.
1. Purpose and Scope
This Data Protection Policy ("Policy") sets out how DWS Codes Ltd ("the Company," "we," "us") collects, processes, stores, shares, and protects personal data — including biometric and location data — through the Attenova attendance platform ("Attenova," "the Service").
This is an internal governance document. It is distinct from, and sits above, the public-facing Attenova Privacy Policy: the Privacy Policy tells users what we do with their data; this Policy tells our own staff, contractors, and partner institutions how we are required to handle it, and who is accountable when something goes wrong.
This Policy applies to:
All employees, contractors, and interns of DWS Codes Ltd who have access to Attenova systems or data.
All personal data processed through Attenova on behalf of partner institutions (students, lecturers, hostel managers, and school administrators).
All environments in which Attenova data is stored or processed, including production servers, backups, and third-party processors.
2. Legal Framework
This Policy is written to comply with:
The Nigeria Data Protection Act, 2023 (NDPA), and regulations issued by the Nigeria Data Protection Commission (NDPC).
Applicable sector-specific rules of partner educational institutions.
International good practice for biometric and location data, including principles consistent with the EU General Data Protection Regulation (GDPR), applied as a baseline of care even where not directly binding.
Where local law and this Policy differ, the stricter standard applies, unless doing so would make the Service unusable for its stated attendance-verification purpose — in which case Legal and the Data Protection Officer (DPO) must jointly approve the exception in writing.
3. Definitions
"Personal Data" — any information relating to an identified or identifiable individual, including a name, email address, phone number, location data, or a biometric identifier.
"Sensitive Personal Data" — personal data requiring heightened protection, including biometric data (facial embeddings), precise location data, and financial/payment information.
"Data Subject" — the individual to whom personal data relates: a student, lecturer, hostel manager, or administrator using Attenova.
"Data Controller" — the entity that determines the purposes and means of processing personal data. DWS Codes Ltd is the Data Controller for Attenova; a partner institution is a joint controller for its own administrative decisions.
"Data Processor" — a third party that processes personal data on the Company's instructions (e.g., our cloud hosting provider).
"Processing" — any operation performed on personal data, including collection, storage, use, disclosure, or deletion.
"Consent" — a freely given, specific, informed, and unambiguous indication of a data subject's agreement to processing, given through a clear affirmative action.
"DPO" — the Data Protection Officer designated under Section 5.2 of this Policy.
"NDPA" — the Nigeria Data Protection Act, 2023. "NDPC" — the Nigeria Data Protection Commission, which enforces it.
4. Data Protection Principles
DWS Codes Ltd processes personal data in line with the following principles. Every new feature, integration, or data flow must be checked against this list before it ships.
Lawfulness, fairness and transparency — data is collected with a valid legal basis and users are told what is collected and why.
Purpose limitation — data collected for attendance verification is not repurposed (e.g., for marketing) without fresh consent.
Data minimisation — we collect the least data needed; biometric data is converted to a mathematical embedding on-device rather than stored as an image.
Accuracy — users can correct inaccurate profile or attendance data through the app or by contacting support.
Storage limitation — data is kept only as long as necessary, per the retention schedule in Section 9.
Integrity and confidentiality — data is encrypted in transit and at rest, with access restricted by role.
Accountability — the Company can demonstrate compliance with this Policy at any time, through audit logs, this document, and the associated Data Protection Impact Assessment (DPIA).
5. Roles and Responsibilities
5.1 Data Controller
DWS Codes Ltd is the Data Controller for personal data processed through Attenova. Partner institutions (e.g., a university using Attenova) act as an independent controller for their own administrative decisions (e.g., who is enrolled, exam eligibility policy) and as a joint controller for data collected through the platform.
5.2 Data Protection Officer (DPO)
The DPO is responsible for monitoring compliance with this Policy, advising on DPIAs, acting as the point of contact for data subjects and the NDPC, and leading the breach-response process described in Section 12.
Contact: getattenova@gmail.com · 0905 575 2651
5.3 All Staff and Contractors
Complete data protection induction before receiving access to production data.
Access only the data required for their specific role (least-privilege principle).
Report suspected data incidents to the DPO within 24 hours of discovery — see Section 12.
Never export biometric or attendance data to personal devices, email, or unapproved storage.
6. Categories of Data Processed
Category
Examples
Sensitivity
Account data
Name, email, phone, role, institution
Standard
Biometric data
Facial embedding vector (512-dimension), liveness result
High
Location data
GPS coordinates at time of attendance marking
High
Attendance records
Session, timestamp, present/absent/late status
Standard
Payment data
Transaction reference, amount, status (via Paystack)
Standard
Device & usage data
Device type, OS, crash logs, app version
Low
Biometric and location data are treated as high-sensitivity categories throughout this Policy and receive the additional safeguards described in Sections 7 and 8.
7. Biometric Data — Special Safeguards
Facial recognition is core to Attenova's anti-proxy attendance model, so it carries the highest processing risk and the strictest controls:
Face images are processed on-device only. They are converted to a 512-dimension mathematical embedding and are never uploaded or stored as an image, on-device or on our servers.
The server independently re-validates every liveness and match result; a client-reported "pass" is never trusted on its own.
Biometric embeddings are never shared with third parties, including our own infrastructure providers, beyond what is strictly necessary for storage.
Active biometric embeddings are retained only while the account is active. Inactive or superseded embeddings are cryptographically erased within 30 days.
Any new use of facial data beyond identity verification and liveness detection requires a fresh DPIA and DPO sign-off before development begins.
8. Consent
Where processing relies on consent — most notably biometric enrolment — DWS Codes Ltd ensures that:
The specific purpose is explained in clear, plain language before consent is requested.
Consent is freely given, and is never implied by silence, inactivity, or a pre-ticked box.
Consent for sensitive personal data, including facial biometric enrolment, is explicit — a generic app permission or terms acceptance is not sufficient; the user must take a distinct affirmative action (e.g., confirming "Enrol my face") within the app.
Users are told, in the same flow, how to withdraw consent later — by deleting their account or requesting biometric deletion via getattenova@gmail.com.
Where a student is a minor, consent is grounded in the institution's existing enrolment relationship with the parent or guardian, per Section 15.
Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal, but may mean the student can no longer use attendance features that depend on biometric verification.
9. Data Retention Schedule
Personal data is not retained indefinitely. The following schedule is the authoritative reference for automated purge jobs and manual deletion requests; it mirrors the retention appendix of the Attenova DPIA and must be kept in sync with it.
Data category
Retention period
Purge method
Biometric embeddings (active account)
Duration of active account
N/A — deleted on account closure
Biometric embeddings (inactive/superseded)
30 days after deactivation
Cryptographic erasure
Hostel manager identity images
12 months after role ends
Secure delete
Attendance location (GPS)
Current academic year, to Sept 30
Anonymised, then deleted
Leave / permission requests
2 years
Delete
Offline queue (unsynced data)
Max 30 days pending sync
Delete, data overwritten
Audit logs
12 months
Archive, then delete
Payment debug logs
7 days
Delete
Payment records (tax/audit)
7 years
Retained — no deletion
A data-subject deletion request is honoured within 30 days, except where a longer retention period above is required by law (e.g., payment records for tax purposes), in which case the user is told which data is retained and why.
10. Data Security Measures
10.1 Technical Controls
Encryption in transit (TLS/SSL) and at rest (AES-256) for all personal data.
Role-based access control — staff see only the data their role requires.
Access logging on every read of sensitive data, retained for 12 months.
Automated retention/purge jobs implementing Section 9 without manual intervention.
10.2 Organisational Controls
Annual internal security review; DPIA reviewed at least every 6 months for biometric processing.
Data Processing Agreements (DPAs) with all third-party processors (Section 13).
Mandatory data-protection induction for new staff before any production access is granted.
11. Cross-Border Data Transfer
Attenova's infrastructure — including Firebase and cloud hosting — may involve processing outside Nigeria. DWS Codes Ltd only transfers personal data outside Nigeria where at least one of the following applies, consistent with NDPA requirements:
The recipient country or processor has been assessed as providing an adequate level of data protection; or
Appropriate safeguards are in place, such as a signed Data Processing Agreement obligating the processor to NDPA-equivalent standards; or
The data subject has given explicit consent to the specific transfer, after being told which safeguards apply and which do not; or
The transfer is necessary to perform a contract with the data subject, or for the establishment or defence of legal claims.
The Company maintains a record of its cross-border processors and the safeguard relied on for each, and will provide details of a specific transfer to a data subject on request (Section 14).
12. Personal Data Breach Notification
A "breach" is any confirmed or suspected unauthorised access, disclosure, loss, or destruction of personal data processed by Attenova.
Any staff member who discovers or suspects a breach must notify the DPO within 24 hours, using the incident channel and getattenova@gmail.com.
The DPO leads containment and assesses the scope, cause, and risk to affected data subjects within 72 hours of discovery.
Where the breach poses a risk to data subjects' rights, the DPO notifies the Nigeria Data Protection Commission (NDPC) within 72 hours of the Company becoming aware of it, in line with NDPA requirements.
Affected users and partner institutions are notified without undue delay, and in any case within 30 days, describing the nature of the breach, the data involved, and the steps taken.
Every incident, whether or not it meets the notification threshold, is logged and reviewed at the next compliance meeting to identify preventive measures.
13. Third-Party Processors
Attenova relies on the following categories of processor. Each is bound by a Data Processing Agreement limiting use of data to the purpose we specify.
Processor
Purpose
Data involved
Firebase (Google)
Push notifications, crash analytics
Notification tokens, crash logs — no attendance or location data
Paystack
Payment processing
Transaction reference, amount, status — no card details
Google ML Kit
On-device face detection
Processed on-device only; nothing sent to Google
Cloud hosting provider
Application hosting & backups
All application data, encrypted
New processors may only be onboarded after a data-protection review confirming they meet the security and contractual standards in this Policy.
14. Data Subject Rights
Students, lecturers, hostel managers, and administrators may exercise the following rights by emailing getattenova@gmail.com with the subject line "Data Subject Access Request":
Access — obtain a copy of the personal data we hold about them.
Rectification — correct inaccurate account data.
Erasure — request deletion of their account and associated data, subject to the legal retention exceptions in Section 9.
Restriction and objection — limit or object to specific processing, such as biometric enrolment, where feasible for the institution's policy.
Portability — receive their attendance records in a portable format.
Withdraw consent — for biometric enrolment, at any time, understanding this may affect their ability to use attendance features.
Requests are acknowledged within 5 business days and resolved within 30 days.
15. Minors
Where a partner institution enrols students under 18, DWS Codes Ltd relies on the institution's existing enrolment relationship with the student's parent or guardian as the basis for processing, and directs parental data requests to the institution in the first instance, with DWS Codes Ltd support on request.
16. Training and Awareness
All new staff complete a data-protection induction covering this Policy before receiving system access.
Refresher training is delivered annually, and immediately after any material change to this Policy.
The DPO maintains a record of completed training.
17. Related Policies and Procedures
This Policy should be read together with:
The Attenova Privacy Policy — the public-facing notice given to students, lecturers, and admins.
The Attenova Data Protection Impact Assessment (DPIA) — the risk assessment underlying the biometric and location safeguards in this Policy.
The Attenova Terms and Conditions.
Any Personal Data Breach Management Procedure and IT Security Policy separately adopted by DWS Codes Ltd.
Where this Policy and a related document conflict, the DPO decides which prevails, favouring whichever gives the data subject stronger protection.
18. Policy Governance and Review
This Policy is owned by the DPO and approved by the founders of DWS Codes Ltd. It is reviewed at least every 6 months, or immediately following a material change in law, a significant new feature (e.g., a new category of biometric processing), or a personal data breach.
Version history:
Version
Date
Summary of change
1.0
August 14, 2026
Initial policy issued, aligned to the Attenova DPIA and Privacy Policy.
19. Contact
Questions about this Policy, or requests to exercise a data-subject right, should be directed to: