Fregatelab Limited, the operator of StaffNet, holds an active audit trustmark issued under the Nigeria Data Protection Regulation (NDPR) after an independent review of our processing activities, security controls, and privacy-by-design practices.
What this means for your business.
When you store staff, payroll, attendance, and customer data on StaffNet, the operator behind the platform has been formally assessed for NDPR compliance. The certificate below is the paperwork.
What was assessed
The audit covered how we operate as a data processor on behalf of every StaffNet workspace, including:
- The types of personal data we collect (see our Privacy Policy).
- Lawful bases for processing and workspace owner consent flow.
- Security controls: TLS in transit, encrypted backups, per-tenant schema separation, access logging, admin activity trails.
- Data subject rights: access, portability (CSV/JSON export), rectification, deletion.
- Retention policies and workspace-cancellation purge windows.
- Third-party processor management (Paystack, Flutterwave, Postmark, KudiSMS, hosting).
- Incident response and breach notification pathways.
Your role as a data controller
Under NDPR, the workspace owner - the business that signs up for StaffNet - is the data controller for the workforce data entered into their workspace. Fregatelab acts as the data processor on the controller's behalf.
The audit covers our side of that relationship. Your obligations as a data controller (issuing privacy notices to your staff, obtaining consents where required, honouring subject rights) sit with you. If you need help drafting a staff-facing privacy notice or exercising subject-rights within the app, contact us and we will help.
Verifying the certificate
The PDF linked here is the original issued document. If you need a signed or counter-verified copy for procurement / due diligence, email hello@fregatelab.com and we will co-ordinate.