Attenova logo
Attenova

Data Protection Policy

Effective Date: August 14, 2026

Last Updated: August 14, 2026

Version: 1.0

This is an internal governance policy for DWS CODES LTD, prepared for compliance with the Nigeria Data Protection Act, 2023 (NDPA) and enforced by the Nigeria Data Protection Commission (NDPC). It sits alongside, and above, the Privacy Policy: the Privacy Policy tells users what we do with their data; this Policy tells our own staff, contractors, and partner institutions how we are required to handle it.


1. Purpose and Scope

This Data Protection Policy ("Policy") sets out how DWS Codes Ltd ("the Company," "we," "us") collects, processes, stores, shares, and protects personal data — including biometric and location data — through the Attenova attendance platform ("Attenova," "the Service").

This is an internal governance document. It is distinct from, and sits above, the public-facing Attenova Privacy Policy: the Privacy Policy tells users what we do with their data; this Policy tells our own staff, contractors, and partner institutions how we are required to handle it, and who is accountable when something goes wrong.

This Policy applies to:

2. Legal Framework

This Policy is written to comply with:

Where local law and this Policy differ, the stricter standard applies, unless doing so would make the Service unusable for its stated attendance-verification purpose — in which case Legal and the Data Protection Officer (DPO) must jointly approve the exception in writing.

3. Definitions

4. Data Protection Principles

DWS Codes Ltd processes personal data in line with the following principles. Every new feature, integration, or data flow must be checked against this list before it ships.

  1. Lawfulness, fairness and transparency — data is collected with a valid legal basis and users are told what is collected and why.
  1. Purpose limitation — data collected for attendance verification is not repurposed (e.g., for marketing) without fresh consent.
  1. Data minimisation — we collect the least data needed; biometric data is converted to a mathematical embedding on-device rather than stored as an image.
  1. Accuracy — users can correct inaccurate profile or attendance data through the app or by contacting support.
  1. Storage limitation — data is kept only as long as necessary, per the retention schedule in Section 9.
  1. Integrity and confidentiality — data is encrypted in transit and at rest, with access restricted by role.
  1. Accountability — the Company can demonstrate compliance with this Policy at any time, through audit logs, this document, and the associated Data Protection Impact Assessment (DPIA).

5. Roles and Responsibilities

5.1 Data Controller

DWS Codes Ltd is the Data Controller for personal data processed through Attenova. Partner institutions (e.g., a university using Attenova) act as an independent controller for their own administrative decisions (e.g., who is enrolled, exam eligibility policy) and as a joint controller for data collected through the platform.

5.2 Data Protection Officer (DPO)

The DPO is responsible for monitoring compliance with this Policy, advising on DPIAs, acting as the point of contact for data subjects and the NDPC, and leading the breach-response process described in Section 12.

Contact: getattenova@gmail.com · 0905 575 2651

5.3 All Staff and Contractors

6. Categories of Data Processed

CategoryExamplesSensitivity
Account dataName, email, phone, role, institutionStandard
Biometric dataFacial embedding vector (512-dimension), liveness resultHigh
Location dataGPS coordinates at time of attendance markingHigh
Attendance recordsSession, timestamp, present/absent/late statusStandard
Payment dataTransaction reference, amount, status (via Paystack)Standard
Device & usage dataDevice type, OS, crash logs, app versionLow

Biometric and location data are treated as high-sensitivity categories throughout this Policy and receive the additional safeguards described in Sections 7 and 8.

7. Biometric Data — Special Safeguards

Facial recognition is core to Attenova's anti-proxy attendance model, so it carries the highest processing risk and the strictest controls:

8. Consent

Where processing relies on consent — most notably biometric enrolment — DWS Codes Ltd ensures that:

Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal, but may mean the student can no longer use attendance features that depend on biometric verification.

9. Data Retention Schedule

Personal data is not retained indefinitely. The following schedule is the authoritative reference for automated purge jobs and manual deletion requests; it mirrors the retention appendix of the Attenova DPIA and must be kept in sync with it.

Data categoryRetention periodPurge method
Biometric embeddings (active account)Duration of active accountN/A — deleted on account closure
Biometric embeddings (inactive/superseded)30 days after deactivationCryptographic erasure
Hostel manager identity images12 months after role endsSecure delete
Attendance location (GPS)Current academic year, to Sept 30Anonymised, then deleted
Leave / permission requests2 yearsDelete
Offline queue (unsynced data)Max 30 days pending syncDelete, data overwritten
Audit logs12 monthsArchive, then delete
Payment debug logs7 daysDelete
Payment records (tax/audit)7 yearsRetained — no deletion

A data-subject deletion request is honoured within 30 days, except where a longer retention period above is required by law (e.g., payment records for tax purposes), in which case the user is told which data is retained and why.

10. Data Security Measures

10.1 Technical Controls

10.2 Organisational Controls

11. Cross-Border Data Transfer

Attenova's infrastructure — including Firebase and cloud hosting — may involve processing outside Nigeria. DWS Codes Ltd only transfers personal data outside Nigeria where at least one of the following applies, consistent with NDPA requirements:

The Company maintains a record of its cross-border processors and the safeguard relied on for each, and will provide details of a specific transfer to a data subject on request (Section 14).

12. Personal Data Breach Notification

A "breach" is any confirmed or suspected unauthorised access, disclosure, loss, or destruction of personal data processed by Attenova.

  1. Any staff member who discovers or suspects a breach must notify the DPO within 24 hours, using the incident channel and getattenova@gmail.com.
  1. The DPO leads containment and assesses the scope, cause, and risk to affected data subjects within 72 hours of discovery.
  1. Where the breach poses a risk to data subjects' rights, the DPO notifies the Nigeria Data Protection Commission (NDPC) within 72 hours of the Company becoming aware of it, in line with NDPA requirements.
  1. Affected users and partner institutions are notified without undue delay, and in any case within 30 days, describing the nature of the breach, the data involved, and the steps taken.
  1. Every incident, whether or not it meets the notification threshold, is logged and reviewed at the next compliance meeting to identify preventive measures.

13. Third-Party Processors

Attenova relies on the following categories of processor. Each is bound by a Data Processing Agreement limiting use of data to the purpose we specify.

ProcessorPurposeData involved
Firebase (Google)Push notifications, crash analyticsNotification tokens, crash logs — no attendance or location data
PaystackPayment processingTransaction reference, amount, status — no card details
Google ML KitOn-device face detectionProcessed on-device only; nothing sent to Google
Cloud hosting providerApplication hosting & backupsAll application data, encrypted

New processors may only be onboarded after a data-protection review confirming they meet the security and contractual standards in this Policy.

14. Data Subject Rights

Students, lecturers, hostel managers, and administrators may exercise the following rights by emailing getattenova@gmail.com with the subject line "Data Subject Access Request":

Requests are acknowledged within 5 business days and resolved within 30 days.

15. Minors

Where a partner institution enrols students under 18, DWS Codes Ltd relies on the institution's existing enrolment relationship with the student's parent or guardian as the basis for processing, and directs parental data requests to the institution in the first instance, with DWS Codes Ltd support on request.

16. Training and Awareness

17. Related Policies and Procedures

This Policy should be read together with:

Where this Policy and a related document conflict, the DPO decides which prevails, favouring whichever gives the data subject stronger protection.

18. Policy Governance and Review

This Policy is owned by the DPO and approved by the founders of DWS Codes Ltd. It is reviewed at least every 6 months, or immediately following a material change in law, a significant new feature (e.g., a new category of biometric processing), or a personal data breach.

Version history:

VersionDateSummary of change
1.0August 14, 2026Initial policy issued, aligned to the Attenova DPIA and Privacy Policy.

19. Contact

Questions about this Policy, or requests to exercise a data-subject right, should be directed to:

Data Protection Officer — DWS Codes Ltd

Email: getattenova@gmail.com

Phone / WhatsApp: 0905 575 2651