Privacy Policy

WorkflowPro Enterprise Edition

Last updated: October 3, 2026

CRITICAL SECURITY ADVISORY FOR ALL STAFF

The specific threat addressed in the CERRT.NG advisory is human behavior: staff members must be reminded never to copy and paste confidential memos, citizen NINs, or voucher details out of WorkflowPro into public web chatbots on their browsers or phones. As long as work is conducted within the secure WorkflowPro system, your data remains sovereign, encrypted, and compliant.

AI Data Governance, Privacy Protection & NITDA / NDPA Compliance

Data and privacy are fully protected on WorkflowPro. Organizational data is never shared with public consumer AI training pools and is never used to train public foundation models.

All core financial, administrative, and payroll operations in WorkflowPro — such as General Ledgers, Trial Balances, Automated Bank Reconciliations, Payment Vouchers, and Overtime calculations — run through native, deterministic database logic. They do not pipe citizen PII or financial vouchers to external third-party AI models.

Every table and record in WorkflowPro is locked down by database-level Row-Level Security rules. Only authenticated officers holding the verified workflow role (e.g., DFI, Head Accounts, DG/CEO, State Coordinator) can access relevant records.

Every login, document view, signature, and approval stage transition is recorded in tamper-evident logs (WorkflowTransitionLog, UserActivityLog) with actor IDs, timestamps, and IP addresses, fulfilling federal compliance requirements under NITDA and the NDPA.

1. Introduction

WorkflowPro ("we", "our", or "us") operates the WorkflowPro enterprise workflow management application. This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our application and the choices you have associated with that data.

2. Types of Data Collected

We collect the following types of data:

  • Personal Identification: Name, email address, employee number, job title, department, unit
  • Organizational Data: Department affiliation, reporting structure, role assignments, access permissions
  • Financial Data: Salary information, overtime records, cash advances, voucher approvals
  • HR Data: Disciplinary records, leave requests, promotion history, staff exit information
  • Workflow Data: Memos, approvals, signatures, comments, workflow history
  • Technical Data: IP address, browser type, device information, usage patterns
  • Authentication Data: Two-factor verification codes, session tokens

3. How We Use Your Data

We process your personal data for the following purposes:

  • Providing workflow management, approval routing, and document processing
  • Authenticating users and securing access to the application
  • Maintaining audit trails and compliance records
  • Generating reports for organizational management
  • Sending workflow notifications and reminders
  • Improving system performance and user experience
  • Detecting and preventing fraud or unauthorized access
  • Meeting legal and regulatory obligations

4. Data Storage & Security

Your data is stored on secure servers with industry-standard encryption. We implement:

  • End-to-end encryption for sensitive data
  • Role-based access control to limit who can view data
  • Audit logging of all data access
  • Regular security audits and penetration testing
  • Automated backups and disaster recovery procedures

However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your personal data.

6. Data Retention

We retain your data for as long as necessary to provide the service and comply with legal obligations:

Active Records: Retained while you are an active user
Workflow Documents: Retained for 7 years for audit and compliance purposes
Financial Records: Retained per applicable financial regulations
Audit Logs: Retained for 2 years minimum
Deleted Accounts: Personal data deleted within 90 days, except where legally required to retain

7. Data Sharing

We do not sell your personal data. We may share data with:

Your Organization: Managers and administrators as part of normal workflow operations
System Administrators: For technical support and system maintenance
Legal Compliance: When required by law, regulation, or court order
Service Providers: Third-party providers who assist with hosting and security (under data processing agreements)

8. Your Data Rights

You have the right to:

Access your personal data held by us
Correct inaccurate data
Request deletion of your data (subject to legal retention requirements)
Receive a copy of your data in portable format
Object to certain processing of your data
Lodge a complaint with your data protection authority

To exercise these rights, contact your system administrator or the data protection officer.

9. International Data Transfers

Your data may be stored and processed in Nigeria and other jurisdictions. By using WorkflowPro, you consent to the transfer of your information to countries outside your country of residence, which may have different data protection rules.

10. Children's Privacy

WorkflowPro is not intended for children under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take steps to delete such information and terminate the child's account.

11. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date above.

12. Data Breach Notification

We are committed to protecting your personal data and responding transparently to any security incidents. In the unlikely event of a data breach, we will take the following actions:

Our Breach Response Protocol:

  • Detection & Assessment: We maintain monitoring systems to detect unauthorized access and promptly assess the scope of any breach.
  • Notification Timeline: We will notify affected users within 30 days of confirming a breach, in accordance with Nigerian Data Protection Regulation.
  • Notification Method: Notifications will be sent via email to the address registered in your account, with clear guidance on next steps.
  • Information Provided: Our notifications will include what data was compromised, when the breach occurred, what we are doing to contain it, steps you should take to protect yourself, and security contact details.
  • Authority Reporting: We will report the breach to relevant data protection authorities as required by law.
  • Remediation: We will implement corrective measures to prevent future incidents and document all actions taken.

For security concerns or to report a suspected breach, contact us immediately at security@nimc.gov.ng

13. Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact your system administrator or submit a complaint through the application's feedback mechanism.

© 2026 WorkflowPro. All rights reserved. Sovereign. Encrypted. Compliant.