Privacy Policy
Last updated: 11 September 2026
We collect bank-account details so we can pay testers and AI-data contributors safely in naira. That is a serious responsibility under the Nigeria Data Protection Act 2023 and the NDPC General Application and Implementation Directive 2025, which replaced the older NDPR on 19 September 2025. This page explains, in plain English, what we collect, why, how long we hold it, and how you exercise your rights.
1. Who this policy applies to
This policy describes how 9jatesters ("we", "us", "our") handles personal information when you visit our websites at 9jatesters.com, create an account, or take part in a user-testing session or AI-data contribution job.
It applies whether you are a tester, an AI-data contributor, a client running a test, or simply a visitor browsing the marketing pages.
2. What we collect
Account data: your full name, email address, phone number, role (tester or client), and your password hash held in our self-hosted authentication system.
Tester profile data: bank account number, bank name, date of birth, gender, state of residence, languages spoken, device and network details, and a Flutterwave-verified account name.
Session data: screen + voice recordings you submit while testing a client's product, the transcripts and summaries our AI generates from them, and metadata such as timestamps and durations.
Annotation data: voice recordings, transcripts, and any text you produce while completing AI training-data jobs.
Payment data: payout amounts in naira, Flutterwave transfer references, and the limited account metadata Flutterwave returns to us. We never receive or store your full card number — only the bank-account details needed to match and pay you.
Technical data: IP address, browser user agent, and the cookies described in the Cookies section below.
3. How we verify your identity
We verify your identity by confirming that the Nigerian bank account you give us for payouts actually belongs to you. Flutterwave — a CBN-licensed payment processor — resolves the account-holder name from your bank, and we match it to your profile. This check runs only when you set up payout, never at signup.
For duplicate-account prevention we keep only a one-way HMAC-SHA256 hash (with a server-side pepper) derived from your verification details. It cannot be reversed to recover the underlying number.
We never reveal your bank-account details to clients, AI-data buyers, or any third party other than our payment processor (Flutterwave), and we only ever transmit them over TLS.
We do not perform credit checks, marketing, or any secondary use of your payment data. You may request deletion of your verification data at any time by emailing [email protected] — note that doing so disables payouts until you re-verify.
3a. Screen and voice recording handling
When you complete paid tasks, your screen and voice are recorded to verify the work is your own. Recording files are stored on our own server — hardware we own and control, not a third-party cloud platform — and are never exposed at a public URL. They are served only through authenticated, ownership-checked streaming proxies, so a recording can only be played back by someone authorised to see it. They are accessible only by 9jatesters QA reviewers and never shared with third parties without your explicit consent. Section 10 states where that hardware is located.
Session metadata (timestamps, duration, task ID, device info) accompanies each recording for quality assurance and billing purposes.
You may request a copy of your own recordings at any time by emailing [email protected].
4. Lawful basis for processing
Under the Nigeria Data Protection Regulation 2019 and the Nigeria Data Protection Act 2023, we process personal data on the following bases:
Performance of a contract: to operate the marketplace, route tests, pay testers, and deliver results to clients.
Consent: for marketing emails, optional demographic fields, and the use of session recordings in case studies (we ask separately for case-study consent).
Legitimate interests: fraud prevention, security monitoring, and product analytics that do not override your rights.
Legal obligation: tax reporting, AML record-keeping, and lawful requests from Nigerian regulators.
5a. Automated decision-making and AI
We use Google Gemini to generate transcripts and short summaries of recorded test sessions. The transcript and summary are reviewed and editable by a human before being delivered to clients; no significant decision about you is made by Gemini alone.
You have the right under section 37 of the NDP Act 2023 to request human review of any AI-generated transcript or summary that concerns you, to contest its content, and to have demonstrably inaccurate output corrected. Email [email protected] to invoke this right.
AI data reuse: with your explicit opt-in consent, your recordings and written answers may be included in a language dataset we license to other companies to train AI models. Consent is optional and refusing it does not affect your pay, your account, or the work you can take. You give or refuse it at the start of each task, and for paid work you finished before 11 September 2026 you are asked separately, because that work was collected before we asked. Every answer is recorded with the date it was given, and we never backdate one. You can see and change everything on file at Data permissions in your dashboard, or by emailing [email protected]. Withdrawing removes your work from dataset copies built after you withdraw; a copy already delivered to a company cannot be recalled.
Open release, which is a separate and permanent choice: with your explicit opt-in consent — a different tick from the one above — your work may also be published in a free, open dataset. We publish these under an open licence, currently Creative Commons Attribution 4.0. In plain terms that means anyone in the world may download it, keep it, use it in their own business and make money from it, change it, build new things from it, and pass it on to other people, indefinitely and at no charge, provided they credit 9jatesters. This is optional, it is never required to do a task or to be paid, and it is asked separately from every other permission.
Open release cannot be undone, and we will not pretend otherwise. Once a dataset is published, copies exist on other people's computers and inside other people's systems. If you withdraw, we remove your work from our published repository and from every later version, and we will not include it again — but we cannot retrieve a copy somebody has already downloaded. That is why we ask for this one on its own, in its own words, and why an unticked box changes nothing about your pay or your account.
One thing about recordings specifically: a read-aloud task has two people in it, the person whose voice it is and the person who wrote the sentence. Where your written work is read aloud by another contributor, publishing that recording also publishes your words. We therefore ask the writer as well as the speaker, and we exclude a recording from an open release unless both have given open-release consent.
Gemini is configured on its paid-tier API, which contractually excludes customer inputs from Google's model-training pipeline. Any third-party AI-model training with your data is governed by a separate Data Licence Agreement requiring your explicit, informed consent.
6. How long we keep data
Account data: PII is retained while your account is active. On deletion, PII is redacted or tombstoned within 30 days. A certificate of deletion is available on request by emailing [email protected].
Recordings: Screen and voice recordings are deleted within 30 days of account deletion (or earlier if the client engagement concludes sooner), unless the recording is part of a buyer-licensed AI dataset with your explicit consent — in which case retention follows the buyer's licence terms.
Identity-verification and audit-log entries are retained for 7 years to satisfy CBN anti-money-laundering and Nigerian tax-record-keeping obligations.
Marketing email subscriber lists: until you unsubscribe, plus 30 days.
Anonymised, non-re-identifiable aggregate metrics may be retained indefinitely.
Identity is verified by matching the account-holder name Flutterwave resolves from your bank. For duplicate-account prevention we keep only a one-way, peppered hash; we never retain card numbers or full bank credentials in plaintext.
7. Your rights under the NDP Act 2023
You have the right to access the personal data we hold about you, correct it, request its deletion, restrict our processing, object to processing, request a portable copy of it, and (where processing relies on consent) withdraw that consent at any time.
To exercise any of these rights, email [email protected] — our Data Protection Officer is reachable at the same address. We will respond within 30 days. Note: deletion is also self-serve at /account/delete for signed-in users (instant redaction + a scheduled purge of stored recording files within 30 days).
You also have the right under section 46 of the NDP Act 2023 to lodge a complaint with the Nigeria Data Protection Commission (NDPC) directly at [email protected] or ndpc.gov.ng — you do not need to contact us first.
7a. Children
9jatesters is not intended for, and we do not knowingly accept registrations from, persons under 18. If we learn we have collected personal data from a person under 18, we delete it within 30 days.
If you are a parent or guardian and believe your child has registered, contact [email protected] and we will action the deletion within 30 days.
This clause implements section 31 of the Nigeria Data Protection Act 2023, which requires parental consent for the processing of personal data of persons under 18.
8. Security
Data in transit is protected by TLS, terminated at Cloudflare's edge and proxied to our origin server. Primary data is held on our own server — hardware we own and control rather than a third-party cloud platform — where session recordings are access-controlled and served only via authenticated, ownership-checked proxies rather than public URLs. We take nightly encrypted database snapshots (pg_dump), retained for roughly 14 days and held on that same hardware. Access to production data is limited to named engineers and audit-logged. Section 10 states where that hardware is located.
We will notify affected individuals and the NDPC within 72 hours of becoming aware of a personal-data breach likely to result in risk to your rights and freedoms.
10. International transfers
Your primary personal data — accounts, verification records, session recordings, payout data, and our database backups — is held on hardware that Ranked Technologies Limited owns and controls, rather than on a third-party cloud platform. That hardware is located in Türkiye. It is not located in Nigeria.
Holding your data on that hardware is an international transfer of personal data under the Nigeria Data Protection Act 2023. The basis we rely on is section 43(1)(b) of the Act: the transfer is necessary for the performance of the contract between you and us. We do not rely on an adequacy decision.
Türkiye has a general data-protection statute, the Law on the Protection of Personal Data (KVKK, Law No. 6698), which is closely modelled on the European General Data Protection Regulation. We state this as context about the destination country only. It is not a claim that the Nigeria Data Protection Commission has issued an adequacy decision in respect of Türkiye.
Administration of those systems also takes place in Türkiye. Ranked Technologies Limited is a Nigerian company registered with the Corporate Affairs Commission, but its director is resident in Türkiye and operates the systems from there. Ordinary administration, support and engineering work — which can involve viewing personal data, including recordings — therefore takes place outside Nigeria. That access is limited to the director, and the rules set out in this policy apply to it.
Payments are different. Flutterwave, our payment processor, is Nigerian and CBN-licensed, and payment processing and bank-account verification take place within Nigeria. Payments are not part of the transfer described above.
Further cross-border touchpoints are transient. First, Cloudflare terminates TLS at its global edge and proxies your request to our origin server, so in-flight request metadata (your IP, headers, and the URL) transits Cloudflare's edge; it does not persistently store our users' data. Second, Mailtrap (operated by Railsware, EU/US) delivers transactional emails such as login one-time codes and receipts, which means it processes your email address and the message content. country.is may also see your request IP transiently to return a country code for display, but we do not persist that IP.
The full live list of sub-processors with their role and legal basis is at /trust/data-residency, and it is updated within 30 days of any change.
Correction, 1 August 2026: until this date this policy stated that your primary personal data was stored in Nigeria and did not leave Nigeria for storage. That statement was false. The hardware holding that data is in Türkiye and was in Türkiye at the time the statement was published. An interim version of this section, published earlier on this same date, described the position as remote administrative access from Türkiye to servers located in Nigeria; that description was also inaccurate, because the data itself is stored in Türkiye and not merely viewed from there. We are recording the error here rather than removing it from the record.
11. Changes to this policy
We will post any material changes to this page and update the "last updated" date at the top. If a change materially reduces your rights, we will email registered users at least 14 days in advance.
12. Contact + Data Protection Officer
The data controller is Ranked Technologies Limited (RC 9522220), a Nigerian company registered with the Corporate Affairs Commission and trading as 9jatesters. It is registered with the Nigeria Data Protection Commission as a data controller and processor of major importance under registration NDPC/DCP/14538. Section 10 describes where the systems processing your data are located.
Our Data Protection Officer is reachable at [email protected] for any NDP-Act-related request (access, correction, deletion, objection, portability, complaint escalation). We aim to acknowledge within 2 business days and substantively respond within 30 days.
Other contacts: General — [email protected] · Security disclosures — [email protected] · Procurement / DPA — [email protected].
Mailing address available on request from the DPO.
You may also lodge complaints directly with the Nigeria Data Protection Commission at [email protected] or via ndpc.gov.ng — no requirement to contact us first.
Questions or a data-rights request? [email protected]