Our Commitment
At NIHILOBA, protecting personal information is a fundamental part of how we design and develop our digital products.
Although SHIDA continues to evolve, privacy and data protection are considered from the earliest stages of product development rather than being added afterwards.
Our objective is to build services that are transparent, respectful of users and aligned with internationally recognised privacy principles, including the General Data Protection Regulation where applicable.
What Is Data Protection?
Data protection refers to the principles, practices and safeguards used to manage personal information responsibly.
It includes decisions about:
- what information is collected;
- why the information is needed;
- how it is used;
- who may access it;
- how long it is retained;
- how it is protected;
- how users can exercise control over it.
At NIHILOBA, data protection is treated as both a product responsibility and an engineering responsibility.
What Is GDPR?
The General Data Protection Regulation, commonly known as GDPR, is a European privacy regulation that establishes rules for how personal information should be collected, processed and protected.
Even when GDPR is not legally required in every situation, many of its principles represent responsible product design and sound data governance.
NIHILOBA uses these principles as guidance when designing SHIDA and its future products.
Unless explicitly stated, NIHILOBA does not claim official GDPR certification.
Privacy by Design
Privacy is not treated as a feature that is added after development.
It is considered during product design, system architecture and feature development.
Whenever new functionality is introduced, we evaluate questions such as:
- Is this information genuinely necessary?
- Can less information achieve the same result?
- Who needs access to the information?
- Can the information be shared later instead of immediately?
- How can users remain in control of their information?
- Could the workflow expose information unnecessarily?
This approach helps reduce unnecessary data collection and supports more trustworthy digital experiences.
Data Minimisation
SHIDA aims to collect only the information required to provide the requested service.
Examples include:
- employment workflows collecting information relevant to recruitment;
- housing workflows collecting information necessary for property management and visit requests;
- appointment workflows collecting only the details required to organise the meeting;
- service providers receiving only the information necessary to respond to a booking or service request;
- transport workflows using only the information necessary to organise the requested journey.
NIHILOBA continues to review its data model and workflows to avoid collecting information that is not required.
Purpose Limitation
Personal information should be used only for the purpose for which it was collected.
Examples include:
- managing appointments;
- processing employment applications;
- publishing professional services;
- organising housing visits;
- coordinating transport requests;
- providing support;
- protecting the platform from misuse.
Information should not be reused for unrelated purposes without an appropriate legal basis or clear communication to the user.
Transparency
Users should be able to understand:
- what information is collected;
- why it is collected;
- how it is used;
- who may receive it;
- how long it may be retained;
- how they can request access, correction or deletion.
NIHILOBA aims to explain these practices in clear language through its Privacy Policy and related trust documentation.
User Rights
Depending on applicable law, users may have rights including:
- requesting access to their personal information;
- correcting inaccurate or incomplete information;
- requesting deletion of personal information;
- objecting to certain types of processing;
- requesting a copy of their information where applicable;
- withdrawing consent where processing relies on consent;
- requesting restriction of certain processing where applicable;
- submitting a complaint to a competent supervisory authority where that right exists.
Requests will be reviewed in accordance with applicable legal obligations and operational requirements.
Data Security
Protecting information requires technical and organisational measures.
SHIDA is developed using practices intended to reduce unnecessary exposure of personal information.
Examples include:
- encrypted HTTPS communication;
- authenticated access to administrative functions;
- restricted access to operational information;
- secure cloud hosting;
- controlled data-sharing workflows;
- continuous software maintenance;
- review of new features before deployment;
- monitoring and troubleshooting where appropriate.
Additional measures may be introduced as the platform grows.
Data Sharing
NIHILOBA does not sell personal information.
Information is shared only when necessary to provide the requested service or when required by applicable law.
Examples include:
- employers receiving applications submitted to them;
- service providers receiving booking requests;
- housing owners receiving visit requests;
- organisations receiving appointment requests;
- transport participants receiving information required to organise a journey.
Information is not intended to be shared publicly unless required by the specific workflow or explicitly chosen by the user.
Lawful Basis
Where GDPR or similar laws apply, personal information may be processed under one or more recognised legal bases.
Depending on the activity, these may include:
- consent;
- performance of a contract or steps requested before entering into a contract;
- compliance with a legal obligation;
- legitimate interests, where those interests do not override the rights and freedoms of the user;
- protection of vital interests in exceptional circumstances;
- performance of a task carried out in the public interest where applicable.
The appropriate legal basis depends on the specific workflow and context.
NIHILOBA will continue refining how lawful bases are documented as the platform and its organisational structure develop.
Data Retention
Personal information should not be retained longer than necessary.
Retention periods may depend on:
- the purpose of the processing;
- the status of an account, listing, request or appointment;
- legal obligations;
- fraud prevention;
- dispute resolution;
- security and operational requirements.
Users may request deletion of their personal information, subject to applicable legal and operational requirements.
International Users and Data Transfers
Although SHIDA’s first use cases have focused on the Democratic Republic of the Congo, the platform is designed to support users internationally.
As NIHILOBA expands, information may be processed through service providers or infrastructure located in different countries.
Where applicable, NIHILOBA will consider appropriate safeguards for international data transfers and will continue adapting its practices to the laws of the countries in which it operates.
Children’s Data
SHIDA is not intended for children to use independently where parental or legal guardian consent is required by applicable law.
Some services, such as school appointments, may involve information submitted by a parent or legal guardian on behalf of a child.
NIHILOBA aims to limit the collection of children’s data and to process such information only where necessary for the requested service.
Continuous Improvement
Privacy and data protection are ongoing responsibilities.
As SHIDA introduces new capabilities, including the Business Layer, additional marketplaces and future integrations, privacy considerations will continue to be reviewed throughout product design and development.
Policies, data models and technical safeguards may evolve to reflect:
- changes to the product;
- changes in applicable law;
- improved engineering practices;
- new operational requirements;
- user expectations;
- security considerations.
Important Notice
Contact
If you have questions about privacy, data protection or the exercise of your rights, you may contact NIHILOBA at:
Email: privacy@nihiloba.com
Closing Statement
Protecting personal information is both a legal responsibility and an essential part of building technology that people can trust.
As NIHILOBA grows, we remain committed to developing products that balance accessibility, innovation and responsible data protection for individuals, professionals, businesses and institutions.
