Privacy Policy

    Operating Entity: Moveguide Technologies Ltd (United Kingdom & Nigeria)

    SECTION 1: DATA CONTROL AND PROCESSING

    1.1 Scope and Operating Entities

    This Privacy Policy governs the data processing activities of Moveguide Technologies (operating as Moveguide Technologies Ltd in the United Kingdom and Nigeria, hereinafter referred to as "Moveguide", "we", "us", or "our").

    This policy applies to individuals accessing our services directly, as well as users interacting with our spatial intelligence engine, API endpoints, and embedded widgets ("Integrate") deployed on third-party partner websites and platforms across Nigeria, Kenya, Ghana, the United Kingdom, and internationally.

    1.2 Dual Capacity: Data Controller vs. Data Processor

    Depending on how you interact with Moveguide, our legal classification under applicable data protection laws—including the UK GDPR, Nigeria Data Protection Act (NDPA), Kenya Data Protection Act (DPA 2019), and Ghana Data Protection Act (DPA 2012)—is defined as follows:

    • Moveguide as a Data Controller: We act as a Data Controller when you directly visit our website, communicate with us, or register for client accounts. In this role, we directly determine the purposes and means of processing your account or communication data.
    • Moveguide as a Data Processor: When enterprise partners (such as prop-tech platforms, real estate websites, or stay booking services) integrate our API widget ("Integrate"), Moveguide acts strictly as a Data Processor. The partner platform remains the Data Controller responsible for establishing the lawful basis to handle your interaction on their site.

    1.3 Principle of Ephemeral Processing (Zero Personal Data Storage)

    Moveguide is designed on a privacy-by-architecture model:

    • No Persistent PII Storage: We do not collect, store, profile, or retain Personally Identifiable Information (PII), end-user identity records, or precise user tracking histories.
    • Stateless Query Handling: When a user interacts with a stay listing or inputs dwelling preferences on a partner platform, our API widget receives telemetry parameters (such as search preferences, general location points, or listing identifiers) purely to compute real-time spatial intelligence scores (e.g., safety, micro-climate, community fit).
    • Immediate Discard: Once the real-time spatial scores are computed and returned to the display interface, the query payload is immediately purged from active memory. We do not construct persistent personal profiles from your browsing queries.

    1.4 Lawful Bases for Processing

    We process telemetry parameters and service data under the following recognized legal grounds:

    • Contractual Necessity: To deliver spatial intelligence query outputs requested through our B2B partners’ integration.
    • Legitimate Interests: To maintain system uptime, detect malicious security threats, and optimize real-time API latency without compromising individual privacy.
    • Consent: Managed directly by our enterprise partners (Data Controllers) at the point of end-user interaction on their respective platforms.

    1.5 Cross-Border Data Processing

    While Moveguide processes queries in real time without storing personal data, backend computations rely on secure cloud infrastructure hosted across compliant international regions. All cross-border data routing complies with transfer mechanisms under the UK GDPR, NDPA, Kenya DPA, and Ghana DPA through strict encryption in transit (TLS 1.3) and stateless execution nodes.

    1.6 Data Protection Contact

    For inquiries, exercise of statutory privacy rights, or regulatory oversight matters across all operating regions, please contact our privacy desk at: privacy@moveguide.co

    SECTION 2: TELEMETRY DATA AND QUERY PARAMETERS PROCESSED

    2.1 Categories of Non-PII Data Processed

    To compute real-time living intelligence scores without capturing or storing personal identities, Moveguide processes only non-personally identifiable telemetry parameters ("Non-PII") and stateless query inputs. When an end-user interacts with our Integrate widget or API endpoints on a partner platform, our system processes the following categories of technical data:

    • Spatial and Geographic Parameters: Property-centric coordinates (latitude/longitude), H3 spatial index cells, neighborhood bounding boxes, and search radii. These parameters relate strictly to the listing or geographic area being queried, not the personal physical tracking history of the individual user.
    • Dwelling and Preference Telemetry: Unlinked search filters and preference weights selected during a query session (e.g., safety priorities, transit accessibility criteria, environmental noise thresholds, micro-climate indicators, and Maslow-aligned welfare parameters).
    • Listing and Property Identifiers: Anonymized property IDs, listing metadata, stay parameters (such as stay duration or housing type), and contextual attributes passed directly from the enterprise partner's database.
    • Technical and Session Metadata: Short-lived technical diagnostics required for API request routing and interface optimization, including truncated/hashed IP addresses (processed temporarily for rate-limiting, security validation, and DDoS protection), user-agent strings, device display parameters, and API response timestamps.

    2.2 Explicit Exclusions (Data We Never Process or Collect)

    Moveguide’s system architecture explicitly restricts the collection of personal telemetry. We do not collect, process, or request:

    • Names, email addresses, physical home addresses, or phone numbers.
    • Financial, billing, or payment card information.
    • Continuous GPS tracking, device movement histories, or persistent device identifiers (e.g., IDFA or Android Advertising ID).
    • User cross-site browsing history outside the active Integrate widget interaction.
    • Special category or sensitive personal data as defined under the UK GDPR, Nigeria Data Protection Act (NDPA), Kenya Data Protection Act (DPA 2019), or Ghana Data Protection Act (DPA 2012).

    2.3 Aggregated and Anonymized Insights

    Moveguide may aggregate and anonymize raw query parameters to evaluate macro-level spatial trends (e.g., regional shifts in safety interest or environmental risk query frequency). All such analytical data is fully decoupled from individual sessions, stripped of any technical identifiers, and processed such that re-identification of any individual is technically impossible. Aggregated datasets are utilized solely to refine our proprietary spatial ontologies and risk forecasting models.

    SECTION 3: DATA SECURITY, EPHEMERAL DISCARD, AND THIRD-PARTY SHARING

    3.1 Technical and Organizational Data Security

    Moveguide implements industry-standard technical and organizational measures to ensure a level of security appropriate to the risk of processing non-PII telemetry and API interactions. These safeguards protect our infrastructure against unauthorized access, alteration, disclosure, or destruction:

    • Encryption in Transit: All telemetry parameters, API calls, and spatial score responses transmitted between enterprise partner platforms and Moveguide’s backend infrastructure are encrypted using Transport Layer Security (TLS 1.3) protocols.
    • API Key Authentication and Rate Limiting: Access to the Integrate API engine is restricted to authenticated enterprise clients via secure API tokens. Automated rate-limiting and threat-detection systems continuously monitor traffic to prevent Distributed Denial-of-Service (DDoS) attacks and unauthorized endpoint exploitation.
    • Zero Persistent Database Exposure for Telemetry: Because Moveguide operates a stateless execution environment for search queries, incoming query payloads are never committed to persistent disk storage or long-term database tables.

    3.2 Ephemeral Discard Mechanisms (Zero-Retention Architecture)

    To uphold our commitment to privacy-by-design, Moveguide enforces an automated ephemeral discard lifecycle for all incoming search telemetry:

    • In-Memory Execution: Query parameters (e.g., search location, dwelling preferences) received via the Integrate API widget are loaded exclusively into volatile RAM for real-time computation against our spatial knowledge graph.
    • Instant Discard Pipeline: The instant the calculated spatial intelligence scores are formatted and returned to the partner interface, the volatile memory buffer holding the original query payload is immediately flushed and overwritten.
    • Diagnostics Retention: Short-lived server diagnostic logs (containing truncated IP hashes and timestamp metadata used exclusively for system health and security auditing) are automatically purged on a rolling 30-day schedule.

    3.3 Third-Party Data Sharing Restrictions

    Moveguide operates strict data boundary controls across all operating regions:

    • No Sale or Monetization of Telemetry: Moveguide does not sell, rent, license, or trade end-user search telemetry, query inputs, or spatial behavior patterns to advertising networks, data brokers, or third-party marketers.
    • Infrastructure Sub-Processors: We may engage vetted third-party cloud infrastructure and hosting providers (such as enterprise-grade cloud compute, database, and edge network vendors) solely to execute our stateless API services. All sub-processors are bound by strict Data Processing Agreements (DPAs) and are legally obligated to maintain encryption standards compliant with the UK GDPR, Nigeria Data Protection Act (NDPA), Kenya Data Protection Act (DPA 2019), and Ghana Data Protection Act (DPA 2012).
    • Enterprise Partner Boundaries: Output delivered back to enterprise partners consists strictly of calculated spatial scores, risk indices, and location insights. Moveguide does not share one enterprise partner's proprietary listing analytics or traffic data with competing platforms.
    • Statutory and Legal Disclosures: Moveguide will only disclose technical logs or operational data to public authorities or law enforcement if explicitly compelled to do so by a binding court order, lawful subpoena, or mandatory statutory obligation under applicable UK, Nigerian, Kenyan, or Ghanaian laws.

    SECTION 4: STATUTORY RIGHTS AND REGULATORY COMPLIANCE

    4.1 Statutory Rights Across Jurisdictions

    Under applicable data protection legislation—including the UK General Data Protection Regulation (UK GDPR), the Nigeria Data Protection Act 2023 (NDPA), the Kenya Data Protection Act 2019 (DPA 2019), and the Ghana Data Protection Act 2012 (Act 843)—individuals possess statutory rights regarding their personal data.

    Subject to statutory limitations, these rights include:

    • Right to be Informed: The right to clear, transparent information regarding how data is collected, processed, and used.
    • Right of Access: The right to request confirmation of whether personal data is processed and obtain a copy of held records.
    • Right to Rectification: The right to request the correction of inaccurate or incomplete personal records.
    • Right to Erasure / Deletion ("Right to be Forgotten"): The right to request the deletion or removal of personal data where there is no legal justification for its continued processing.
    • Right to Restrict or Object to Processing: The right to object to or limit processing under specific conditions, including direct marketing or processing based on legitimate interests.
    • Right to Data Portability: The right to receive personal data in a structured, commonly used, and machine-readable format.
    • Rights Regarding Automated Decision-Making: The right not to be subject to decisions based solely on automated processing or profiling that produce legal or similarly significant effects.

    4.2 Application to Moveguide’s Stateless Architecture

    To exercise these statutory rights effectively, individuals must note Moveguide’s operational role:

    • For End-Users Browsing Partner Platforms (API Widget Interactions): Because Moveguide operates a zero-retention, stateless compute engine for spatial queries (as detailed in Sections 1 and 3), we do not store, profile, or retain personal records, browsing histories, or identifiable query payloads. Submitting an access or deletion request directly to Moveguide regarding end-user search telemetry will yield no identifiable personal data records. If you wish to exercise data rights regarding account details, search history, or personal profiles stored by an enterprise partner (such as a stay booking engine or real estate portal), you must submit your request directly to that partner platform as the designated Data Controller.
    • For Moveguide B2B Account Holders and Direct Site Visitors: Where you hold a client account directly with Moveguide Technologies or contact us directly, we process standard account identifiers (e.g., business contact details, billing information) as a Data Controller and will fulfill all statutory access, correction, or deletion requests in full accordance with applicable law.

    4.3 Submitting a Rights Request and Response Timelines

    To exercise any statutory data right or submit a formal request regarding personal data held directly by Moveguide:

    1. Email Request: Submit a written request detailing the nature of your request to privacy@moveguide.co.
    2. Identity Verification: To protect privacy, we may require reasonable proof of identity before processing requests related to direct account holders.
    3. Statutory Response Window: Moveguide will acknowledge receipt and provide a substantive response within thirty (30) calendar days (or the applicable statutory timeframe mandated by local regulators in Nigeria, Kenya, Ghana, or the UK).

    4.4 Supervisory Authorities and Right to Lodge a Complaint

    If you believe that Moveguide has not addressed your privacy concern satisfactorily or has processed personal data in violation of applicable legislation, you have the statutory right to lodge a complaint with the relevant regulatory supervisory authority in your jurisdiction:

    • United Kingdom: Information Commissioner’s Office (ICO) — ico.org.uk
    • Nigeria: Nigeria Data Protection Commission (NDPC) — ndpc.gov.ng
    • Kenya: Office of the Data Protection Commissioner (ODPC) — odpc.go.ke
    • Ghana: Data Protection Commission Ghana (DPC) — dataprotection.org.gh