Ileny

Legal

Privacy Policy

Version
2026-08-02
Effective
2 August 2026

In short. Ileny holds two kinds of personal data, and our obligations differ between them. The account details of the organisation that subscribes to Ileny are ours to control. The employee records that organisation loads into the platform — salaries, attendance, bank details, biometric enrolments — belong to that organisation; we only process them on its instructions.

If you are an employee whose records are held in Ileny by your employer, your first point of contact is your employer, not us. Section 11 explains why, and what we will do if you contact us directly.

1. Who we are

Ileny is a human resource, attendance, and payroll platform operated by CODEWITHFIDEL LTD(“we”, “us”, “our”), a private company limited by shares incorporated in the Federal Republic of Nigeria on 11 June 2026 under the Companies and Allied Matters Act 2020, with registration number RC 9608345 and Tax Identification Number 2623717605965.

This policy explains what personal data we handle, on what legal basis, who we share it with, how long we keep it, and the rights available to you. It applies to the Ileny web application, the Ileny mobile application, our websites, and our application programming interfaces (together, the Service).

2. The two roles we occupy

Data protection law distinguishes the party that decides why and how personal data is processed (the data controller) from the party that processes it on that party’s behalf (the data processor). Ileny is both, depending on whose data is in question, and the distinction governs everything that follows.

Category of dataOur roleWhat that means
Subscriber data— the organisation that buys Ileny: its name, its administrators’ contact details, billing records, and how those administrators use the Service.ControllerWe decide the purposes and means. The obligations in this policy are owed by us directly, and requests about this data come to us.
Employee data — the HR records a subscribing organisation loads into Ileny about its own staff: identity, salary, attendance, leave, discipline, bank details, biometric enrolments.ProcessorThe subscribing organisation is the controller. We act only on its documented instructions, and it — not us — decides what is collected, who may see it, and how long it is kept.

Where we act as processor, our obligations to the subscribing organisation are set out in our Data Processing Agreement, which forms part of the Terms of Service. Nothing in this policy diminishes the rights an employee has against their own employer as controller.

3. Personal data we handle

3.1 Data we collect as controller

  • Registration data. Organisation name, contact email address, telephone number, country, currency, industry, and the name and email address of the first administrator.
  • Account credentials.A cryptographic hash of each administrator’s password — never the password itself — and, where two-factor authentication is enabled, the codes issued to complete a sign-in.
  • Billing data. Chosen plan, billing interval, payment references and amounts. Card and bank credentials are entered directly with our payment processor and are never received or stored by us.
  • Acceptance records. The version of this policy and of the Terms of Service accepted at registration, the time of acceptance, the IP address the acceptance came from, and the browser that submitted it. We keep this as evidence of the agreement between us.
  • Technical and usage data. IP address, browser and device identifiers, pages and endpoints accessed, timestamps, and diagnostic logs.
  • Correspondence. Messages you send to our support or sales addresses, and our replies.

3.2 Data we process as processor, on a subscriber’s instructions

The categories below are typical of what an employer loads into Ileny. The employer decides which of them it actually uses; we do not require any particular field.

  • Identity and contact data. Name, employee number, date of birth, gender, photograph, home address, state and local government of origin, personal email and telephone number, and emergency contacts.
  • Employment data. Job title, department, branch, start and end dates, employment status, salary and salary history, and uploaded employment documents.
  • Financial data. Bank name, account name, account number and bank code, used to pay salaries; payroll calculations, deductions, and payslips.
  • Attendance and location data.Clock-in and clock-out records and their source. Where an employer enables geofenced clock-in, this includes the geographic coordinates recorded at the moment of clocking in, which are checked against the branch’s permitted radius.
  • Biometric data. Where an employer uses a biometric attendance device, the enrolment reference that links an employee to that device. Biometric data is a special category of personal data and is addressed separately in section 6.
  • Leave and absence data. Leave requests, balances, approvals, and any supporting documents the employer requires — which may include information about health where an employer operates sick leave.
  • Disciplinary data. Cases, actions, and outcomes recorded by the employer, including any related financial penalty.
  • Recruitment data. Candidate details, applications, and interview records where the employer uses the recruitment features.

3.3 Data we do not want

The Service is not designed to hold data about children, and it should not be used to process the records of anyone under 18 other than a lawfully employed person. Where Ileny is used by a school, it holds records about staff — not about pupils. Do not upload pupil records into Ileny.

4. Why we process it, and on what lawful basis

Under the Nigeria Data Protection Act 2023 and, where it applies, the GDPR, every act of processing needs a lawful basis. Ours, in our capacity as controller, are these.

PurposeLawful basis
Creating and administering a subscriber account; making the Service available.Performance of a contract with the subscriber.
Taking payment, invoicing, and recovering sums due.Performance of a contract; and compliance with a legal obligation, for tax and accounting records.
Authenticating administrators, rate-limiting sign-in attempts, and keeping audit logs.Legitimate interests — securing the Service against unauthorised access, which is also in every subscriber's interest.
Recording acceptance of this policy and the Terms of Service.Legitimate interests — being able to evidence the agreement we rely on; and compliance with the accountability principle.
Diagnosing faults, monitoring performance, and improving the Service.Legitimate interests — operating a reliable service, balanced against the limited privacy impact of diagnostic data.
Sending service messages about outages, security, billing, or changes to these documents.Performance of a contract; and legitimate interests in keeping subscribers informed.
Sending marketing about Ileny to business contacts.Consent, which you may withdraw at any time by using the unsubscribe link or writing to us.
Responding to lawful requests from courts, regulators, or law enforcement.Compliance with a legal obligation.

Where we act as processor, the lawful basis for processing employee data is determined by the employer as controller — commonly the performance of the employment contract, compliance with employment, tax and pension obligations, or the employer’s legitimate interests. The employer is responsible for identifying that basis and for telling its employees about it.

5. Sensitive and special category data

Some of what Ileny holds attracts heightened protection: biometric data, data revealing health (in sick leave records), and — depending on how an employer uses the fields — data that could reveal ethnic origin or religious belief.

Where we handle such data we do so only as a processor, on the employer’s instructions. An employer using these features must satisfy itself that it has a lawful basis under section 30 of the Nigeria Data Protection Act 2023 and, where the GDPR applies, a condition under Article 9(2) — most commonly that the processing is necessary for obligations in the field of employment law, or that the employee has given explicit consent that was genuinely freely given.

6. Biometric attendance

Where an employer enables biometric attendance, employees enrol on a physical device supplied by the employer. Ileny stores the enrolment reference and the resulting attendance events; the biometric template itself is held on the device by its manufacturer’s software, and Ileny does not receive a copy of the underlying fingerprint or facial image.

Biometric data cannot be reissued the way a password can. An employer choosing to use it should treat it accordingly: use it only where an alternative attendance method would genuinely not do, offer employees a non-biometric route where practicable, and complete a data protection impact assessment before rolling it out. We will support that assessment with information about how the integration works.

7. Location data

Geofenced clock-in records the device’s coordinates at the moment an employee clocks in or out, and compares them against the permitted radius the employer has set for that branch. It is a point-in-time check, not continuous tracking: Ileny does not follow a device between clock-ins, and it does not record location at any other moment.

Employers enabling this feature should tell their staff plainly that it is on, what radius applies, and what happens to a clock-in outside it.

8. Who we share personal data with

We do not sell personal data, and we do not share it for anyone else’s marketing. We disclose it only as set out below.

8.1 Sub-processors

We engage the service providers named here. Each is bound by a written contract requiring it to process personal data only on our instructions and to maintain appropriate security.

ProviderPurposeData involvedLocation
Paystack Payments LimitedSubscription payment collection and salary disbursement to employee bank accounts.Payer name and email, transaction references, employee bank account numbers and bank codes, amounts.Nigeria
Twilio SendGridTransactional email — invitations, password resets, payslip notifications, alerts.Recipient name and email address, and the contents of the message.United States
Google Firebase Cloud MessagingPush notifications to the Ileny mobile application.Device registration tokens and notification contents.United States
[HOSTING PROVIDER — confirm before publishing]Application hosting, database hosting, and encrypted backups.All Subscriber Data, at rest and in transit.[REGION — confirm; determines whether a transfer safeguard is needed]

8.2 Others

  • Within the subscribing organisation. Employee records are visible to the administrators and managers the employer has granted the relevant permissions to. The employer controls those permissions; we do not.
  • Professional advisers. Our auditors, lawyers, and accountants, where they need it to advise us.
  • Authorities. Courts, regulators, or law enforcement, where we are legally required to disclose. Where we are permitted to tell the affected subscriber that a request has been made, we will.
  • A successor. If our business or the Ileny product is transferred to another entity, personal data may transfer with it, subject to the acquirer being bound by protections no weaker than these.

9. International transfers

Ileny is operated from Nigeria, and personal data is stored in the location identified in the sub-processor table above. Two of our sub-processors — our email provider and our push-notification provider — process data in the United States, so a limited set of personal data leaves Nigeria.

For those transfers we rely on the safeguards permitted by section 43 of the Nigeria Data Protection Act 2023 and, where the GDPR applies, on the European Commission’s Standard Contractual Clauses. You may ask us for details of the safeguard applied to a particular transfer.

10. How long we keep it

DataRetention
Employee data held on a subscriber's behalfFor as long as the subscriber's account is active. On termination, deleted within 90 days unless the subscriber asks us sooner, or unless we must keep it by law.
Subscriber account and billing recordsFor the life of the account, then six years — the period for which company and tax records must be retained in Nigeria.
Acceptance records for these documentsSix years after the account ends. They evidence an agreement, and are of no use after the period in which it could be disputed.
Audit logs of actions taken in the platformFor the life of the account, then deleted with the rest of the subscriber's data.
Diagnostic and container logsRotated continuously and retained for no more than 30 days.
Encrypted backups30 days, after which they are overwritten. Data deleted from the live system persists in backups until they cycle out.

11. Your rights

Subject to the conditions in the applicable law, you have the right to be informed about processing; to access your personal data; to have inaccurate data corrected; to have data erased; to restrict or object to processing; to receive your data in a portable form; not to be subject to a decision based solely on automated processing that produces legal effects; and to withdraw consent where consent is the basis we rely on.

11.1 If you are an employee of an organisation that uses Ileny

Direct your request to your employer. Your employer is the controller of your records; it — not Ileny — decides what is held and can act on your request directly in the platform. We are not permitted to alter or release an employer’s records on the instruction of someone other than that employer, and doing so would itself be a breach of our obligations.

If you contact us anyway, we will pass the request to your employer without undue delay and tell you that we have done so.

11.2 If you are a subscriber or an administrator

Write to us at privacy@ileny.app. We will respond within one month. If a request is complex we may extend that period, and will tell you why within the first month. We do not charge for responding, unless a request is manifestly unfounded or excessive.

11.3 Complaints

If you are dissatisfied with how we have handled your data, you may complain to the Nigeria Data Protection Commission. If you are in the EU or EEA, you may complain to the supervisory authority in your country. We would rather you came to us first, and we will take the complaint seriously.

12. How we protect personal data

No system is perfectly secure, and we will not claim otherwise. The measures below are the ones actually in place.

  • All traffic between your browser or device and the Service is encrypted in transit using TLS.
  • Passwords are stored only as salted cryptographic hashes and cannot be recovered by us or by anyone who obtains the database.
  • Each subscribing organisation’s data is isolated, and every query is constrained to the organisation of the signed-in user. A request cannot address another organisation’s records.
  • Access within an organisation is governed by roles and granular permissions set by that organisation’s administrators, and enforced by the server on every request rather than merely hidden in the interface.
  • Session tokens are short-lived; the token that renews them is held in a cookie that scripts running in the browser cannot read, and is invalidated on sign-out.
  • Two-factor authentication is available and is recommended for every administrator.
  • Actions taken in the platform are recorded in an audit log showing who did what and when.
  • Databases are backed up on a schedule, backups are encrypted, and restoration is tested rather than assumed.

13. If something goes wrong

If a personal data breach occurs, we will notify the Nigeria Data Protection Commission within 72 hours of becoming aware of it, where the breach is likely to result in a risk to the rights and freedoms of individuals. Where we act as processor, we will notify the affected subscribing organisation without undue delay so that it can meet its own obligations, and we will give it the information it needs to do so.

Where a breach is likely to result in a high risk to individuals, we will communicate it to the affected individuals — or, where we are the processor, support the controller in doing so.

14. Cookies

Ileny uses a small number of cookies, all of them strictly necessary to operate the Service. The principal one holds the token that keeps you signed in; it is marked so that scripts cannot read it, is restricted to the authentication paths, and is cleared when you sign out. We do not use advertising cookies and we do not track visitors across other websites.

15. Automated decision-making

Ileny performs automated calculations — payroll figures, leave balances, and attendance penalties derived from the rules an employer configures. These produce results an employer relies on, and an employer may attach consequences to them. The rules are set by the employer, not by us, and an employer is responsible for ensuring a person reviews any decision that significantly affects an employee before it takes effect.

16. Changes to this policy

This policy is versioned. The current version is 2026-08-02, effective 2 August 2026. When we change it materially we will publish the new version here, give it a new version number, and notify subscribers by email before it takes effect. Where the change requires it, subscribers will be asked to accept the new version when they next sign in, and we record which version was accepted and when.

17. Contact us

CODEWITHFIDEL LTD

RC 9608345 · TIN 2623717605965

[REGISTERED OFFICE — confirm against the CAC filing]

Data protection enquiries and data subject requests: privacy@ileny.app

General enquiries: hello@ileny.app

  1. Supervisory authority in Nigeria: the Nigeria Data Protection Commission.