StaffNet is a workforce operations platform operated by Fregatelab in Abuja, Nigeria. This Privacy Policy explains what we collect when you or your team use StaffNet, how we use it, who we share it with, and the choices you have.
We wrote this in plain language on purpose. If anything is unclear, email hello@fregatelab.com.
The short version.
We collect the workforce data you enter (staff, payroll, attendance, tasks, etc.) so we can run the app for you. We do not sell it. We do not use it to train external AI models. Anyone in your workspace can export or delete their own workspace data at any time.
1. Who we are
The "data controller" for the information your team enters into StaffNet is the workspace owner (the person or business that signed up). Fregatelab, the operator of StaffNet, is the "data processor" - we run the servers, ship the software, and handle security on the workspace owner's behalf.
For questions about a specific workspace's data, contact the workspace owner directly. For questions about the platform itself, email us at hello@fregatelab.com.
2. Data we collect
Data you give us directly
- Account info: name, email, phone number, workspace name, role.
- Workforce data: staff records, salary structures, attendance logs, leave requests, tasks, expenses, exams, appraisals, documents, memberships, sales, invoices - whatever your team enters into the modules you turn on.
- Payment info: when you subscribe or top up a wallet, our payment partners (Paystack, Flutterwave) handle card / bank details directly. We only store the transaction reference and status.
- Support messages: anything you send through the contact form, live chat, or the help widget.
Data we collect automatically
- Log data: IP address, browser type, pages visited, timestamps - standard web-server logs, kept for 90 days for security + debugging.
- Attendance geolocation: only when a staff member clocks in with the geofence setting enabled, and only the clock-in coordinates - never continuous location tracking.
- Session cookies: to keep you signed in. See our Cookie Policy for the full list.
- Error events: uncaught exceptions get shipped to our own error tracking (Dokwe) so we can fix bugs. Includes the request URL, user agent, and stack trace - not form data or credentials.
3. How we use it
- Deliver the features you signed up for.
- Authenticate you and keep your workspace secure.
- Send you transactional emails (payslips, invoices, password resets, notifications).
- Answer support requests.
- Debug errors and improve reliability.
- Prevent fraud and abuse.
- Comply with Nigerian tax + labour law where you've turned on the payroll / tax modules.
We do not:
- Sell your data to third parties. Ever.
- Use your workspace data to train generative AI models we sell to others.
- Read or index your data for advertising.
4. Who we share with
We share data only with service providers we need to run StaffNet, and only the minimum each needs:
- Hosting: our servers are in a data center in the United States (Vultr / Digital Ocean class), managed by us. Data at rest is encrypted; backups are encrypted and rotated weekly.
- Payment processors: Paystack and Flutterwave handle billing. They have their own privacy policies.
- Email: Postmark / Amazon SES for transactional email.
- SMS: KudiSMS and similar providers for SMS blasts.
- Error tracking: Dokwe (our own internal platform).
We do not share your data for marketing. If we ever need to disclose data because of a court order or legitimate government request under Nigerian law, we will (unless the law forbids it) notify the workspace owner first.
5. Where your data lives
StaffNet is hosted outside Nigeria on infrastructure that ships with GDPR-grade contractual safeguards. Under NDPR, cross-border transfer is permitted with adequate protection - our hosting contracts include the standard data-protection clauses.
6. How long we keep it
- Active workspaces: as long as your subscription is active.
- Cancelled workspaces: we keep your data for 90 days after cancellation so you can reactivate. After that we purge it, except for records we must legally retain (invoices, tax filings).
- Log data: 90 days.
- Backups: up to 30 days rolling.
7. Your rights under NDPR
The Nigeria Data Protection Regulation gives you the right to:
- Ask what data we hold about you.
- Ask for a copy (data portability - CSV / JSON export).
- Ask us to correct wrong data.
- Ask us to delete your data (except where we need to keep it by law).
- Object to how we use your data.
- Withdraw consent for anything you consented to.
Send these requests to hello@fregatelab.com. We respond within 30 days. Workspace admins can also self-serve most of these through the app.
8. Security
We take security seriously:
- All traffic is HTTPS (TLS 1.2+).
- Each workspace's data lives in a separate database schema - no shared tables across tenants.
- Passwords are hashed with bcrypt. We never see them in plaintext.
- Two-factor authentication is available on every account.
- Admin actions are logged (activity log).
If you discover a security issue, please email hello@fregatelab.com. We will not take legal action against good-faith security research.
9. Children
StaffNet is not intended for children under 18. We do not knowingly collect data from minors. If you are a workspace admin and become aware that a minor's data is on the platform, please remove it.
10. Changes to this policy
When we make material changes we will email the workspace owner and update the "Last updated" date at the top of this page. Continued use of StaffNet after a change counts as acceptance of the new terms.
11. Contact
Fregatelab - Abuja, Nigeria
Email:
hello@fregatelab.com
Contact form