Skip to main content
NDP Act 2023 · GAID 2025 aligned

Privacy Policy

Last updated: 11 September 2026

We collect bank-account details so we can pay testers and AI-data contributors safely in naira. That is a serious responsibility under the Nigeria Data Protection Act 2023 and the NDPC General Application and Implementation Directive 2025, which replaced the older NDPR on 19 September 2025. This page explains, in plain English, what we collect, why, how long we hold it, and how you exercise your rights.

1. Who this policy applies to

This policy describes how 9jatesters ("we", "us", "our") handles personal information when you visit our websites at 9jatesters.com, create an account, or take part in a user-testing session or AI-data contribution job.

It applies whether you are a tester, an AI-data contributor, a client running a test, or simply a visitor browsing the marketing pages.

2. What we collect

Account data: your full name, email address, phone number, role (tester or client), and your password hash held in our self-hosted authentication system.

Tester profile data: bank account number, bank name, date of birth, gender, state of residence, languages spoken, device and network details, and a Flutterwave-verified account name.

Session data: screen + voice recordings you submit while testing a client's product, the transcripts and summaries our AI generates from them, and metadata such as timestamps and durations.

Annotation data: voice recordings, transcripts, and any text you produce while completing AI training-data jobs.

Payment data: payout amounts in naira, Flutterwave transfer references, and the limited account metadata Flutterwave returns to us. We never receive or store your full card number — only the bank-account details needed to match and pay you.

Technical data: IP address, browser user agent, and the cookies described in the Cookies section below.

3. How we verify your identity

We verify your identity by confirming that the Nigerian bank account you give us for payouts actually belongs to you. Flutterwave — a CBN-licensed payment processor — resolves the account-holder name from your bank, and we match it to your profile. This check runs only when you set up payout, never at signup.

For duplicate-account prevention we keep only a one-way HMAC-SHA256 hash (with a server-side pepper) derived from your verification details. It cannot be reversed to recover the underlying number.

We never reveal your bank-account details to clients, AI-data buyers, or any third party other than our payment processor (Flutterwave), and we only ever transmit them over TLS.

We do not perform credit checks, marketing, or any secondary use of your payment data. You may request deletion of your verification data at any time by emailing [email protected] — note that doing so disables payouts until you re-verify.

3a. Screen and voice recording handling

When you complete paid tasks, your screen and voice are recorded to verify the work is your own. Recording files are stored on our own server — hardware we own and control, not a third-party cloud platform — and are never exposed at a public URL. They are served only through authenticated, ownership-checked streaming proxies, so a recording can only be played back by someone authorised to see it. They are accessible only by 9jatesters QA reviewers and never shared with third parties without your explicit consent. Section 10 states where that hardware is located.

Session metadata (timestamps, duration, task ID, device info) accompanies each recording for quality assurance and billing purposes.

You may request a copy of your own recordings at any time by emailing [email protected].

4. Lawful basis for processing

Under the Nigeria Data Protection Regulation 2019 and the Nigeria Data Protection Act 2023, we process personal data on the following bases:

Performance of a contract: to operate the marketplace, route tests, pay testers, and deliver results to clients.

Consent: for marketing emails, optional demographic fields, and the use of session recordings in case studies (we ask separately for case-study consent).

Legitimate interests: fraud prevention, security monitoring, and product analytics that do not override your rights.

Legal obligation: tax reporting, AML record-keeping, and lawful requests from Nigerian regulators.

5. Who we share data with

Clients only see what is necessary to act on your session: your first name, state, age band, language, device, and the redacted recording + summary. They do not see your full name, phone number, or bank details.

AI-data buyers receive your voice recordings under an anonymous contributor ID, plus the demographic stratification (state, age band, language). They never receive your name, contact details, or bank information.

How we run our infrastructure: our PostgreSQL database, our self-hosted authentication system, your session recordings, our nightly encrypted database backups, and the web application itself all run on hardware we own and operate ourselves, not on a third-party cloud platform such as AWS, Google Cloud, or Azure. These are not third-party sub-processors — we operate them directly. Section 10 states where that hardware is located.

Third-party sub-processors (the only external parties that touch data): Cloudflare, Inc. (CDN, DDoS protection, and the secure tunnel that exposes the app to the internet — it terminates TLS at its global edge and proxies requests to our origin server, handling in-flight request metadata such as IP, headers, and URL, but does not persistently store our users' data); Flutterwave (Nigerian, CBN-licensed, PCI-DSS payment processing for client billing and bank-account verification — same-jurisdiction, no cross-border transfer for payments); Mailtrap, operated by Railsware (transactional email delivery, including login one-time codes and receipts — it receives the recipient email address and message content; jurisdiction EU/US); country.is (IP-to-country lookup for display only — the request IP is used transiently to compute a country code and is not persisted by us); Meta Platforms (the Meta Pixel on our public marketing pages measures whether our Facebook/Instagram ads led to a visit or signup — it sets Meta cookies and receives page-view and button-click events with browser metadata; it does not run inside the logged-in dashboard); and Sentry (error monitoring — receives technical crash reports, which can include your IP and the page you were on when an error occurred, so we can fix bugs). Each is bound by data-processing terms compatible with the NDPR. A full live list with legal basis is at /trust/data-residency.

Sub-processor change notice: we publish any addition or replacement of a sub-processor on /trust/data-residency at least 30 days before it goes live. Enterprise customers receive email notice; if you object on reasonable grounds and we cannot resolve within 30 days, you may terminate the affected service with a pro-rata refund.

We will disclose data when legally compelled by a Nigerian court or regulator, and we will tell you about it unless prohibited from doing so.

5a. Automated decision-making and AI

We use Google Gemini to generate transcripts and short summaries of recorded test sessions. The transcript and summary are reviewed and editable by a human before being delivered to clients; no significant decision about you is made by Gemini alone.

You have the right under section 37 of the NDP Act 2023 to request human review of any AI-generated transcript or summary that concerns you, to contest its content, and to have demonstrably inaccurate output corrected. Email [email protected] to invoke this right.

AI data reuse: with your explicit opt-in consent, your recordings and written answers may be included in a language dataset we license to other companies to train AI models. Consent is optional and refusing it does not affect your pay, your account, or the work you can take. You give or refuse it at the start of each task, and for paid work you finished before 11 September 2026 you are asked separately, because that work was collected before we asked. Every answer is recorded with the date it was given, and we never backdate one. You can see and change everything on file at Data permissions in your dashboard, or by emailing [email protected]. Withdrawing removes your work from dataset copies built after you withdraw; a copy already delivered to a company cannot be recalled.

Open release, which is a separate and permanent choice: with your explicit opt-in consent — a different tick from the one above — your work may also be published in a free, open dataset. We publish these under an open licence, currently Creative Commons Attribution 4.0. In plain terms that means anyone in the world may download it, keep it, use it in their own business and make money from it, change it, build new things from it, and pass it on to other people, indefinitely and at no charge, provided they credit 9jatesters. This is optional, it is never required to do a task or to be paid, and it is asked separately from every other permission.

Open release cannot be undone, and we will not pretend otherwise. Once a dataset is published, copies exist on other people's computers and inside other people's systems. If you withdraw, we remove your work from our published repository and from every later version, and we will not include it again — but we cannot retrieve a copy somebody has already downloaded. That is why we ask for this one on its own, in its own words, and why an unticked box changes nothing about your pay or your account.

One thing about recordings specifically: a read-aloud task has two people in it, the person whose voice it is and the person who wrote the sentence. Where your written work is read aloud by another contributor, publishing that recording also publishes your words. We therefore ask the writer as well as the speaker, and we exclude a recording from an open release unless both have given open-release consent.

Gemini is configured on its paid-tier API, which contractually excludes customer inputs from Google's model-training pipeline. Any third-party AI-model training with your data is governed by a separate Data Licence Agreement requiring your explicit, informed consent.

6. How long we keep data

Account data: PII is retained while your account is active. On deletion, PII is redacted or tombstoned within 30 days. A certificate of deletion is available on request by emailing [email protected].

Recordings: Screen and voice recordings are deleted within 30 days of account deletion (or earlier if the client engagement concludes sooner), unless the recording is part of a buyer-licensed AI dataset with your explicit consent — in which case retention follows the buyer's licence terms.

Identity-verification and audit-log entries are retained for 7 years to satisfy CBN anti-money-laundering and Nigerian tax-record-keeping obligations.

Marketing email subscriber lists: until you unsubscribe, plus 30 days.

Anonymised, non-re-identifiable aggregate metrics may be retained indefinitely.

Identity is verified by matching the account-holder name Flutterwave resolves from your bank. For duplicate-account prevention we keep only a one-way, peppered hash; we never retain card numbers or full bank credentials in plaintext.

7. Your rights under the NDP Act 2023

You have the right to access the personal data we hold about you, correct it, request its deletion, restrict our processing, object to processing, request a portable copy of it, and (where processing relies on consent) withdraw that consent at any time.

To exercise any of these rights, email [email protected] — our Data Protection Officer is reachable at the same address. We will respond within 30 days. Note: deletion is also self-serve at /account/delete for signed-in users (instant redaction + a scheduled purge of stored recording files within 30 days).

You also have the right under section 46 of the NDP Act 2023 to lodge a complaint with the Nigeria Data Protection Commission (NDPC) directly at [email protected] or ndpc.gov.ng — you do not need to contact us first.

7a. Children

9jatesters is not intended for, and we do not knowingly accept registrations from, persons under 18. If we learn we have collected personal data from a person under 18, we delete it within 30 days.

If you are a parent or guardian and believe your child has registered, contact [email protected] and we will action the deletion within 30 days.

This clause implements section 31 of the Nigeria Data Protection Act 2023, which requires parental consent for the processing of personal data of persons under 18.

8. Security

Data in transit is protected by TLS, terminated at Cloudflare's edge and proxied to our origin server. Primary data is held on our own server — hardware we own and control rather than a third-party cloud platform — where session recordings are access-controlled and served only via authenticated, ownership-checked proxies rather than public URLs. We take nightly encrypted database snapshots (pg_dump), retained for roughly 14 days and held on that same hardware. Access to production data is limited to named engineers and audit-logged. Section 10 states where that hardware is located.

We will notify affected individuals and the NDPC within 72 hours of becoming aware of a personal-data breach likely to result in risk to your rights and freedoms.

9. Cookies

We use essential cookies for authentication (our self-hosted auth session cookie) and security (CSRF tokens, Cloudflare's __cf_bm bot-mitigation cookie). We also use the 9jt:ref referral attribution cookie when you arrive via a /r/<code> link, and localStorage for announcement-dismissed and dev-session keys.

Advertising measurement: our public marketing pages can load the Meta Pixel, which sets Meta cookies and reports page views and key button clicks (e.g. starting a signup) back to Meta so we can measure whether our Facebook/Instagram ads work. It loads only if you accept it on the consent banner. If you decline, or if you simply never answer, it is not loaded at all — declining is the default and costs you no functionality. You can change your answer at any time with the "Cookie settings" link in the footer of any page. The pixel is blocked outright on the logged-in dashboard, your account pages and the admin area, whatever your consent choice, so it never sees the pages you use while signed in. Error monitoring uses Sentry (see section 5). Beyond these, no other third-party analytics cookies are used.

Correction, 1 August 2026: until this date the Meta Pixel loaded on every page for every visitor without a consent step, including inside the logged-in dashboard — where the page address it reported to Meta could include internal task and session identifiers. That contradicted an earlier version of this policy, which stated the pixel did not run inside the dashboard. We have fixed the code rather than the sentence: the pixel is now blocked in those areas and loads nowhere without consent. We are recording the error here instead of quietly editing it out.

10. International transfers

Your primary personal data — accounts, verification records, session recordings, payout data, and our database backups — is held on hardware that Ranked Technologies Limited owns and controls, rather than on a third-party cloud platform. That hardware is located in Türkiye. It is not located in Nigeria.

Holding your data on that hardware is an international transfer of personal data under the Nigeria Data Protection Act 2023. The basis we rely on is section 43(1)(b) of the Act: the transfer is necessary for the performance of the contract between you and us. We do not rely on an adequacy decision.

Türkiye has a general data-protection statute, the Law on the Protection of Personal Data (KVKK, Law No. 6698), which is closely modelled on the European General Data Protection Regulation. We state this as context about the destination country only. It is not a claim that the Nigeria Data Protection Commission has issued an adequacy decision in respect of Türkiye.

Administration of those systems also takes place in Türkiye. Ranked Technologies Limited is a Nigerian company registered with the Corporate Affairs Commission, but its director is resident in Türkiye and operates the systems from there. Ordinary administration, support and engineering work — which can involve viewing personal data, including recordings — therefore takes place outside Nigeria. That access is limited to the director, and the rules set out in this policy apply to it.

Payments are different. Flutterwave, our payment processor, is Nigerian and CBN-licensed, and payment processing and bank-account verification take place within Nigeria. Payments are not part of the transfer described above.

Further cross-border touchpoints are transient. First, Cloudflare terminates TLS at its global edge and proxies your request to our origin server, so in-flight request metadata (your IP, headers, and the URL) transits Cloudflare's edge; it does not persistently store our users' data. Second, Mailtrap (operated by Railsware, EU/US) delivers transactional emails such as login one-time codes and receipts, which means it processes your email address and the message content. country.is may also see your request IP transiently to return a country code for display, but we do not persist that IP.

The full live list of sub-processors with their role and legal basis is at /trust/data-residency, and it is updated within 30 days of any change.

Correction, 1 August 2026: until this date this policy stated that your primary personal data was stored in Nigeria and did not leave Nigeria for storage. That statement was false. The hardware holding that data is in Türkiye and was in Türkiye at the time the statement was published. An interim version of this section, published earlier on this same date, described the position as remote administrative access from Türkiye to servers located in Nigeria; that description was also inaccurate, because the data itself is stored in Türkiye and not merely viewed from there. We are recording the error here rather than removing it from the record.

11. Changes to this policy

We will post any material changes to this page and update the "last updated" date at the top. If a change materially reduces your rights, we will email registered users at least 14 days in advance.

12. Contact + Data Protection Officer

The data controller is Ranked Technologies Limited (RC 9522220), a Nigerian company registered with the Corporate Affairs Commission and trading as 9jatesters. It is registered with the Nigeria Data Protection Commission as a data controller and processor of major importance under registration NDPC/DCP/14538. Section 10 describes where the systems processing your data are located.

Our Data Protection Officer is reachable at [email protected] for any NDP-Act-related request (access, correction, deletion, objection, portability, complaint escalation). We aim to acknowledge within 2 business days and substantively respond within 30 days.

Other contacts: General — [email protected] · Security disclosures — [email protected] · Procurement / DPA — [email protected].

Mailing address available on request from the DPO.

You may also lodge complaints directly with the Nigeria Data Protection Commission at [email protected] or via ndpc.gov.ng — no requirement to contact us first.

Questions or a data-rights request? [email protected]