Rople is operated by [LEGAL ENTITY NAME], a company registered in Nigeria (RC [NUMBER]), of [REGISTERED ADDRESS] ("Rople", "we", "us").
This policy explains what we do with personal data when you use Rople at rople.app. It is written to comply with the Nigeria Data Protection Act 2023 (NDPA) and, where it applies to you, the EU/UK GDPR.
1. The two roles, and why it matters to you
Rople is a workplace platform. Almost everyone who uses it does so because their employer put them there. That creates two different relationships with two different sets of rights.
Your employer is the data controller. They decide that Rople will be used, which modules are on, who is in the workspace, what goals and reviews are recorded about you, and how long it is kept. If you want your performance record corrected or explained, your employer decides that — not us.
Rople is the data processor. We hold and process that information on your employer's instructions, under DATA_PROCESSING_AGREEMENT.md. We do not decide what goes into your review.
We are a controller only for things that are ours rather than your employer's: your login credentials, our billing records, our website analytics, and support conversations you have directly with us.
If you are an employee with a question about your own data, start with your employer. If they do not respond, contact us at [PRIVACY EMAIL] and we will route it and, where the law requires, act ourselves.
2. What we collect
2.1 Given to us when a workspace is set up
Organisation name, logo, industry, size, email domain; departments and reporting lines; the workspace owner's name, work email, job title and phone number.
2.2 Given to us by users
Name, work email, password (stored only as a hash), profile photo, job title, department, manager, seat function and level. Goals, objectives, key results and progress updates. Check-in notes, feedback, recognition, comments. Performance reviews, development plans (PDP), performance improvement plans (PIP). Files you upload.
2.3 Generated by using Rople
Sign-in times and session records. An audit log of significant actions (who changed what, when). Invite links created and redeemed. Feature usage and page views via our analytics provider. Error and crash reports via our monitoring provider.
2.4 Technical data
IP address, browser and device type, approximate location derived from IP, time zone, referring page.
2.5 Billing data
Contact and company billing details, plan, seat count, invoices, payment status. We never see or store full card numbers — payments run through Paystack and/or Flutterwave, who handle card data directly.
2.6 Sensitive data
Rople is not designed to hold special-category data — health records, biometrics, religion, ethnicity, union membership, political opinion. Do not put it in. If a customer needs to process any of it, that must be agreed with us in writing first.
3. Why we process it, and on what basis
| What we do | Why | Lawful basis (NDPA s.25) |
|---|---|---|
| Run the workspace, store content | Provide the service the customer bought | Contract / legitimate interest of the employer |
| Authenticate you, keep sessions | Security | Contract |
| Audit logging | Detect misuse, prove what happened | Legal obligation / legitimate interest |
| Product analytics | Understand and improve the product | Legitimate interest; consent where required |
| AI features (see §5) | Deliver the feature you invoked | Contract |
| Support | Answer your question | Contract / legitimate interest |
| Billing and tax records | Get paid, satisfy FIRS | Contract / legal obligation |
| Marketing email to prospects | Sell Rople | Consent — withdrawable any time |
4. Who we share it with
We do not sell personal data. We never have, and the business model does not require it.
We share data with: people inside your own workspace, according to their role (managers see their reports; admins see the workspace; peers see what workspace settings permit); sub-processors that make Rople run, each listed in SUB_PROCESSORS.md; professional advisers under confidentiality; authorities where legally compelled, and we will tell the customer unless prohibited; and a buyer, if Rople is acquired, with the same protections carried over and notice to you.
Never to other customers. Workspace isolation is enforced at the database layer through row-level security, and cross-tenant access is covered by automated tests.
5. AI features
Rople includes AI assistance — drafting goals, summarising check-ins, suggesting feedback, answering questions about your own team's data.
- Prompts include your workspace data. When you ask the AI about an employee, that employee's relevant records are sent to the model to answer.
- The model provider is [MODEL PROVIDER], acting as a sub-processor under contract.
- Your data is not used to train third-party models. We use enterprise API terms that exclude training on customer inputs.
- Retention at the provider is limited to serving the request plus a short abuse-monitoring window. See
SUB_PROCESSORS.md. - AI output is a draft, not a decision. Rople does not make automated decisions with legal or significant effect on you. A human always approves. If your employer uses AI output to justify a decision about you, you may ask them to explain it.
- AI respects permissions. The AI cannot surface data you could not open yourself.
6. Where your data lives, and transfers out of Nigeria
Rople runs on Supabase (Postgres) and Vercel. Primary data is hosted in [REGION]. Some sub-processors operate outside Nigeria, so personal data is transferred internationally.
Under NDPA s.41–43 such transfers require an adequate legal basis. We rely on: the recipient country's adequacy where recognised by the NDPC; contractual data protection clauses with each sub-processor; and, where neither applies, the customer's instruction as controller. Each transfer is listed in SUB_PROCESSORS.md with its location and safeguard.
7. How long we keep it
See DATA_RETENTION_AND_DELETION.md for the full schedule. In summary: workspace content lives as long as the workspace does; when a subscription ends we keep the data for [30] days so it can be recovered or exported, then delete it; audit logs are kept [24] months; billing and tax records are kept 6 years as Nigerian law requires; backups roll off within [35] days.
8. Your rights
Under NDPA Part V you may: access your data, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent where consent was the basis.
How to use them: for anything inside a workspace, ask your employer's workspace admin — they are the controller and they can action most of it in-product. For Rople's own controller data, email [PRIVACY EMAIL]. We respond within 30 days.
If you are unhappy with our response you may complain to the Nigeria Data Protection Commission (NDPC), ndpc.gov.ng.
9. Security
See SECURITY_OVERVIEW.md. Headline controls: encryption in transit (TLS 1.2+) and at rest; passwords hashed with bcrypt via Supabase Auth, never stored in plaintext and never emailed; row-level security so a query for one workspace cannot return another's rows; role- and seat-based access control inside a workspace; private storage buckets with signed, expiring URLs; audit logging of significant actions; least-privilege access for Rople staff, logged.
No system is perfectly secure. If we suffer a breach affecting your data we will notify the NDPC within 72 hours and affected customers without undue delay.
10. Children
Rople is a workplace tool and is not for anyone under 18. We do not knowingly collect data from children. If you believe we have, contact [PRIVACY EMAIL] and we will delete it.
11. Changes
We will post a new version here and update the effective date. For changes that materially affect your rights we will email workspace owners at least 14 days in advance and re-prompt for acceptance at next sign-in.
12. Contact
| Entity | [LEGAL ENTITY NAME] |
| Address | [REGISTERED ADDRESS] |
| Privacy contact | [PRIVACY EMAIL] |
| Data Protection Officer | [DPO NAME / EMAIL] |
| Regulator | Nigeria Data Protection Commission — ndpc.gov.ng |