Introduction
This Privacy Policy explains how the Kogi State Project Management System ("we," "our," or "us") collects, uses, and protects your personal information. We are committed to protecting your privacy and ensuring compliance with the Nigeria Data Protection Regulation (NDPR) 2019.
Data Controller: Kogi State Government
Data Protection Officer: [Name and Contact Information]
Purpose: Project management, monitoring, and reporting for World Bank and Development Partner initiatives in Kogi State.
What Personal Data We Collect
Personal Identification Information:
- Name: First name and last name
- Contact Information: Email address and phone number
- Professional Details: Designation/role and state of assignment
- User Account: User ID and role-based access permissions
Project-Related Data:
- Project Assignments: Projects assigned to users
- Activity Logs: Login attempts, system usage, and data submissions
- Performance Data: Project indicators, targets, and achievements
Technical Information:
- Device Information: IP address, browser type, and operating system
- Session Data: Login timestamps and activity tracking
- Security Logs: Authentication attempts and security events
How We Use Your Personal Data
Primary Purposes:
- User Authentication: To verify your identity and provide secure access
- Project Management: To assign and track project responsibilities
- Data Collection: To gather project performance indicators and achievements
- Reporting: To generate reports for stakeholders and development partners
- Communication: To send important updates and notifications
Legal Basis for Processing:
- Contract Performance: Processing necessary for your role and project assignments
- Legitimate Interest: Improving system security and user experience
- Legal Obligation: Compliance with government reporting requirements
- Consent: For optional communications and data processing
Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. Your data may be shared only in the following circumstances:
- Government Authorities: As required by law or government regulations
- Development Partners: World Bank and other partners for project monitoring and evaluation
- Service Providers: IT service providers who assist in system maintenance (under strict confidentiality agreements)
- Legal Requirements: When required by court order or legal process
Data Security and Protection
Security Measures:
- Encryption: All data transmitted over HTTPS with TLS encryption
- Access Controls: Role-based access with strict authentication requirements
- Password Security: Strong password policies and secure hashing
- Session Management: Secure session handling with automatic timeout
- Audit Logging: Comprehensive logging of all system activities
- Regular Updates: Security patches and system updates
Data Retention and Deletion
Retention Periods:
- Active User Data: Retained while account is active
- Project Data: Retained for 7 years for audit and reporting purposes
- Login Logs: Retained for 2 years for security monitoring
- Inactive Accounts: Deleted after 2 years of inactivity
Data Deletion:
- Automatic Deletion: Inactive accounts and expired data are automatically removed
- Manual Deletion: You can request deletion of your personal data
- Backup Retention: Backups are retained for 30 days then securely destroyed
Your Data Protection Rights
Under the Nigeria Data Protection Regulation (NDPR), you have the following rights:
Right to Access
You can request a copy of all personal data we hold about you, including how it's used and shared.
Right to Rectification
You can request correction of inaccurate or incomplete personal data.
Right to Portability
You can request your data in a structured, machine-readable format for transfer to another system.
Right to Erasure
You can request deletion of your personal data, subject to legal retention requirements.
Right to Restrict Processing
You can request limitation of how we process your data in certain circumstances.
Right to Object
You can object to processing of your data for specific purposes.
Submit your request in writing to our Data Protection Officer. We will respond within 30 days and may request additional information to verify your identity.
Cookies and Tracking
Essential Cookies:
- Session Cookies: Required for system functionality and security
- Authentication Cookies: Store login status and user preferences
- Security Cookies: CSRF protection and session validation
No Third-Party Tracking: We do not use third-party cookies, analytics, or tracking tools.
Cookie Management: You can control cookies through your browser settings, though disabling essential cookies may affect system functionality.
Children's Privacy
Our system is designed for government officials and project personnel. We do not knowingly collect personal information from children under 18 years of age. If you believe we have collected such information, please contact us immediately.
International Data Transfers
Your data is primarily stored and processed within Nigeria. Any international transfers (e.g., to World Bank systems) are conducted under appropriate safeguards and data protection agreements.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Significant changes will be communicated to users through the system or email notifications.
Contact Us
Data Protection Officer
[Name]
[Email Address]
[Phone Number]
General Inquiries
Kogi State Government
[Address]
[General Email]
Data Protection Complaints
If you have concerns about how we handle your data, you can:
- Contact our Data Protection Officer directly
- Submit a formal complaint through the system
- Contact the National Information Technology Development Agency (NITDA) if your concerns are not resolved
Privacy Policy v1.0 | Effective: January 15, 2025 | Last Updated: January 15, 2025
This policy complies with the Nigeria Data Protection Regulation (NDPR) 2019