TASA Logo
TASA Logo

Welcome Guest

Sign in to access your profile

1. Overview & Scope

Legal applicability across web, mobile apps, and services

TL;DR Key Summary:TASA Africa operates a global freelance marketplace connecting Clients with Vendors across Africa and internationally. This Privacy Policy details how we handle personal information collected via our website, mobile application, APIs, and escrow payment systems.

TASA Africa (“TASA”, “we”, “us”, or “our”) is committed to maintaining the trust and confidence of our users globally. This Privacy Policy applies to all individuals who access or use our services, including:

  • Clients: Individuals or entities seeking freelance services, contracting talent, or making payments.
  • Vendors / Freelancers: Professionals listing service offerings, building portfolios, or executing projects.
  • Platform Visitors: Anyone browsing our web applications or downloading our mobile apps.

By accessing or using TASA Africa platforms, you acknowledge that you have read, understood, and agree to the data collection and processing practices described herein.

3. Information We Collect

Granular breakdown for Clients, Vendors, and Mobile App users

A. Account & Identity Verification (KYC)

To build trust and comply with statutory financial requirements across Nigeria, Africa, and global markets, we collect:

  • Full Legal Name, Email Address, Phone Number, Country of Residence.
  • Government-issued ID documents (Passport, National Identity Number / NIN, Voter ID, BVN verification for payout compliance in Nigeria where required by financial regulators).
  • Profile photographs, professional bio, and account authentication credentials.

B. Client vs. Vendor Specific Data

For Vendors / Freelancers:Service portfolio items, hourly rates, skill certifications, past work history, payout bank account details, and ratings/reviews.
For Clients:Project briefs, budget specifications, organization name, payment billing address, contract milestones, and review feedback.

C. Mobile Application & Technical Telemetry

When accessing TASA Africa via our iOS/Android mobile applications or web apps:

  • Device Information: Device hardware model, operating system version, unique device identifiers (IDFA/GAID), app version.
  • Usage & Crash Metrics: Application event logs, crash reports, performance analytics.
  • Location Data: Approximate location (via IP) for currency/locale setting; precise location only if voluntarily enabled for proximity-based vendor discovery.
  • Push Notifications: Device tokens used to send project alerts, contract updates, and messaging notifications.

4. How We Use & Protect Your Information

Core operational purposes and safety mechanisms

Platform Operation & EscrowFacilitating job postings, matching clients with suitable African vendors, executing escrow payments, and managing disputes.
Trust, Security & VerificationVerifying vendor credentials, preventing identity fraud, detecting unauthorized access, and maintaining platform integrity.
Communication & SupportSending project status notifications, security alerts, system updates, and assisting with customer support inquiries.
Regulatory ComplianceFulfilling tax withholding, anti-money laundering regulations, and compliance reporting across legal jurisdictions.

5. Regional Privacy Laws & Addendums

Provisions tailored for Nigeria, Pan-Africa, Europe, UK, and North America

NIGERIANigeria Data Protection Act (NDPA 2023)

NDPC Compliant

For data subjects located in Nigeria, TASA Africa strictly complies with the Nigeria Data Protection Act 2023 (NDPA) and guidelines issued by the Nigeria Data Protection Commission (NDPC):

  • Data Subject Rights: Right to object to processing, right to withdraw consent at any time without penalty, right to request restriction, and right to lodge a complaint directly with the NDPC.
  • Lawful Safeguards: Personal data is processed in accordance with strict principles of accountability, data minimization, and purpose limitation.
  • Cross-Border Data Transfers: Any transfer of Nigerian residents' data outside Nigeria is protected through adequate legal mechanisms in compliance with NDPA Section 41.

PAN-AFRICAPOPIA (South Africa) & AU Malabo Framework

African Union Aligned

TASA Africa operates across the African continent and aligns with major national data privacy legislation and pan-African frameworks:

  • South Africa (POPIA): Compliance with the Protection of Personal Information Act, ensuring conditionality for lawful processing of special personal information.
  • Kenya & Ghana: Full alignment with Kenya DPA 2019 and Ghana Data Protection Act 2012 (Act 843).
  • African Union Malabo Convention: TASA Africa upholds the principles of the AU Convention on Cyber Security and Personal Data Protection across all operating African jurisdictions.

EU / UKEU & UK General Data Protection Regulation (GDPR)

GDPR Compliant

If you reside in the European Economic Area (EEA) or the United Kingdom, you possess guaranteed legal rights under Articles 15-22 of the GDPR:

1. Right of Access
2. Right to Erasure
3. Data Portability
4. Right to Rectify
5. Right to Object
6. Restriction
7. Withdraw Consent
8. Lodge Complaint

Transfers of EEA/UK data outside those regions utilize Standard Contractual Clauses (SCCs) approved by the European Commission.

UNITED STATESCalifornia Consumer Privacy Act (CCPA / CPRA)

No Data Selling

For California and US residents: TASA Africa DOES NOT sell or share your personal data for monetary or third-party commercial consideration. You have the right to request disclosure of categories of data collected, request deletion, and exercise rights without discriminatory service pricing.

6. Third-Party Sub-Processors & Sharing

Authorized external service providers

We strictly vet and contract third-party vendors (sub-processors) bound by strict non-disclosure and data protection agreements:

Sub-Processor CategoryExample PartnersData Handled
Escrow & Payment GatewaysPaystack, Flutterwave, StripeTransaction data, payout accounts, card tokens
Cloud InfrastructureAWS, Vercel, Google CloudEncrypted application databases & storage
KYC & Identity VerificationIdentityPass, Smile IDGovernment ID validation, NIN/BVN cross-check
Push & SMS MessagingTwilio, Termii, FirebasePhone numbers, push tokens, alert content

7. Cookies & Tracking Technologies

Managing web cookies, session tokens, and analytics

We use cookies, local storage, and web beacons to enhance session security, maintain login persistence, and collect performance metrics.

Strictly NecessaryEssential for authentication, CSRF security tokens, and account access. Cannot be disabled.
Performance & AnalyticsAnonymized telemetry to evaluate platform speed, page load performance, and UI responsiveness.
Functional & PreferenceRemembers language, local currency preference (e.g. NGN, KES, ZAR, USD), and theme modes.

8. Data Retention & Erasure Schedule

Clear timelines for data storage and deletion

We retain personal data only as long as necessary to fulfill marketplace contracts and comply with legal retention requirements:

Data CategoryRetention PeriodDeletion Trigger
Active Profile & Portfolio DataDuration of Active AccountAccount Deletion Request
Financial & Escrow Invoices7 Years (Tax/CBN Law)Statutory Tax Expiry
KYC Verification Documents5 Years post-account closeAML Statutory Expiry
Server Logs & Crash Telemetry90 DaysAutomatic Log Rotation

9. Data Security Architecture

Enterprise-grade encryption and technical safeguards

TASA Africa employs robust technical and organizational security measures:

  • Encryption Standards: Data in transit is protected via TLS 1.3 encryption. Data at rest is encrypted using AES-256 standards.
  • Access Control: Strict role-based access control (RBAC) and multi-factor authentication (MFA) for administrative operations.
  • Vulnerability Monitoring: Continuous threat monitoring, annual penetration testing, and automated vulnerability scanning.

10. Children's Privacy (18+ Requirement)

Age restrictions on TASA marketplace platforms

TASA Africa services are strictly intended for individuals who are 18 years of age or older. We do not knowingly collect personal information from minors under 18. If we discover an account registered by a minor, we will promptly close the account and remove associated data.

11. Contact Us

Exercise your rights under NDPA, POPIA, GDPR, or CCPA

If you wish to submit a Data Subject Access Request (DSAR), request profile deletion, or ask questions regarding data processing in Nigeria, Africa, Europe, or globally, contact our Data Protection Officer:

Our Data Protection Officer responds to all verified Data Subject Rights Requests within 30 days as required by statutory regulations.
Privacy Policy & Data Protection | TASA Africa