Trust & Compliance

Compliance

Our commitment to data protection, security, and regulatory compliance across every part of our platform.

Last updated: 30 April 2026

Data Protection

Full compliance with the Nigerian Data Protection Act (NDPA) 2023 and alignment with GDPR principles for cross-border data flows.

Security Standards

TLS 1.2+ encryption in transit, AES-256 at rest, row-level security on all database tables, and full audit logging.

Legal & Regulatory

Operations governed by Nigerian corporate law, FIRS regulations, and applicable NITDA directives on IT services.

Incident Response

A documented breach response plan with 72-hour regulatory notification and prompt user communication upon confirmed incidents.

Our Compliance Checklist

NDPA 2023 (Nigeria) aligned
NDPR (NITDA) compliant
GDPR-equivalent safeguards for cross-border transfers
PCI-DSS payment processing
TLS 1.2+ encryption in transit
AES-256 encryption at rest
Row-level security on all data
Full audit log on every action
FIRS-aligned payroll & tax records
7-year financial record retention
72-hour breach notification
Responsible vulnerability disclosure

Data Protection & Privacy

Moatwave Technologies Ltd processes personal data in accordance with the Nigerian Data Protection Act (NDPA) 2023 and the Nigeria Data Protection Regulation (NDPR) issued by the National Information Technology Development Agency (NITDA). Where our services involve the transfer of personal data outside Nigeria, we apply additional safeguards consistent with GDPR Chapter V principles.

We act as a data controller for account and billing data, and as a data processor for the business data you manage on behalf of your employees, clients, and vendors. Our Data Processing Agreement (DPA) is available to enterprise and bespoke plan customers on request.

  • Lawful basis: contract performance, legitimate interests, and explicit consent where required.
  • Data minimisation: we collect only what is necessary for the stated purpose.
  • Purpose limitation: data is not used for purposes beyond what is described in our Privacy Policy.
  • Data subject rights: access, rectification, erasure, portability, and objection requests are honoured within 30 days.
  • Automated decision-making: our behavioural intelligence (MID) scoring assists human decisions but is never solely determinative.

Security & Infrastructure

Security is built into every layer of the Moatwave platform. Our infrastructure runs on enterprise-grade cloud services with continuous monitoring, automated threat detection, and zero-downtime deployments.

  • Encryption: all data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted with AES-256.
  • Access control: role-based access control (RBAC) with row-level security ensures users can only access data scoped to their role and company.
  • Audit logging: every create, read, update, and delete action is recorded in an immutable audit log with actor identity, timestamp, and IP address.
  • Secret management: API keys, database credentials, and service tokens are stored in environment-variable vaults, never in source code.
  • Vulnerability management: dependencies are regularly reviewed and updated. Critical CVEs are patched within 48 hours.
  • Penetration testing: periodic security assessments are conducted to identify and remediate vulnerabilities.

Financial & Tax Compliance

Moatwave supports your business's compliance obligations by providing accurate, auditable records for payroll, invoicing, and financial reporting.

  • Payroll calculations include PAYE deductions in line with current FIRS tax tables and state-level tax authority requirements.
  • Invoices generated on the platform include all fields required for VAT compliance under the Value Added Tax Act.
  • Financial transaction records are retained for a minimum of 7 years in accordance with Nigerian financial regulations.
  • We do not provide tax advice. You remain responsible for verifying that your tax filings comply with current regulations and for consulting a qualified tax professional.

Third-Party Processors

We engage a limited number of sub-processors to deliver our Services. Each sub-processor is carefully vetted and bound by a data processing agreement that imposes obligations equivalent to our own.

  • Supabase — database hosting and authentication (SOC 2 Type II certified).
  • Payment processing — handled by a PCI-DSS compliant payment provider. We do not store raw card data.
  • Email delivery — transactional and notification emails are sent via a reputable email service provider.

A full list of sub-processors is available to customers on request.

Uptime & Business Continuity

We target 99.9% uptime for the Moatwave platform, excluding scheduled maintenance windows communicated in advance via status notifications. Our infrastructure uses automated failover, database replication, and daily backups with a recovery point objective (RPO) of 24 hours and a recovery time objective (RTO) of 4 hours.

Incident Response & Breach Notification

In the event of a security incident or personal data breach, we follow a documented incident response plan:

  • Immediate containment and impact assessment upon detection.
  • Notification to affected users within 72 hours of confirming a breach that poses a risk to their rights and freedoms.
  • Regulatory notification to NITDA and other applicable authorities within the timeframes prescribed by law.
  • Post-incident review and remediation to prevent recurrence.

To report a suspected security vulnerability, please email hello@moatwave.com with "Security Disclosure" in the subject line. We operate a responsible disclosure policy.

Employee & Staff Data

Moatwave is used by companies to manage their workforce. We recognise that staff members whose data is processed through the platform are data subjects with rights independent of the company account.

Staff members can access their personal data through the Staff Portal. Any requests to correct, restrict, or delete staff data that cannot be fulfilled through self-service should be directed to the company administrator or, where the issue relates to Moatwave's processing, to hello@moatwave.com.

Reporting a Compliance Concern

If you believe Moatwave or a company using our platform is processing personal data unlawfully, you may:

  • Contact our Data Protection Officer at hello@moatwave.com.
  • Lodge a complaint with the National Information Technology Development Agency (NITDA), which is the supervisory authority for data protection in Nigeria.
  • Seek independent legal advice.

We take all compliance concerns seriously and will investigate promptly.

Data Protection Officer

For data protection enquiries, subject access requests, or compliance concerns, contact our DPO directly.

hello@moatwave.com