Privacy Policy

Effective date: 1 March 2026 — Last updated: March 2026

Newsata Limited (“Newsata”, “we”, “us”) operates newsata.com and the Newsata mobile app. This policy explains, in plain language, what personal data we collect, why we collect it, who we share it with, and what rights you have over it.

1. Who this policy applies to

This policy applies to everyone who uses Newsata — job seekers who create accounts and submit applications, employers who post vacancies and review candidates, and visitors who browse the platform without an account. Where different rules apply to different user types, we say so explicitly.

2. What data we collect

Data you give us directly

  • Name and email address when you register
  • Professional profile: work history, education, skills, certifications
  • CV/resume files you upload (PDF or document format)
  • Salary information you contribute voluntarily to our salary database
  • Interview question submissions linked to specific employers
  • Messages you send via our contact form or in-platform messaging
  • Subscription and billing details when you upgrade to a paid plan (processed by Paystack — we do not store card numbers)

Data we collect automatically

  • Pages visited, job listings clicked, and search terms used
  • Application events: when you apply to a job and when an employer opens your application
  • Device type, browser, and operating system (via standard HTTP headers)
  • IP address (used for fraud detection and rate-limiting, not linked to your profile for advertising)
  • Push notification delivery and open events (if you opt in)

Data from our AI features

When you use AI-powered CV generation or cover letter drafting, the text you provide is processed by OpenAI's API on our behalf. We do not share your name or email with OpenAI. The generated output is stored in your account for your reference. You can delete it at any time from your dashboard.

3. How we use your data

PurposeLawful basis (NDPR)
Matching your profile to relevant job listings and alertsPerformance of contract
Tracking when employers view your application (anti-ghosting)Legitimate interest (transparency)
Sending job alert emails and push notifications (opt-in)Consent
Processing AI CV / cover letter generationConsent (triggered by your action)
Fraud detection and platform securityLegitimate interest
Aggregate usage analytics (Google Analytics)Legitimate interest
Billing and subscription managementPerformance of contract

4. Who we share your data with

Employers you apply to

When you submit a job application, we share your CV, cover letter (if provided), and profile information with the employer who posted that listing. We notify you each time your application is forwarded. We do not share your contact details with employers who you have not applied to.

Service providers (processors)

  • Supabase — database hosting and authentication (EU/US infrastructure)
  • Cloudinary — CV file and company logo storage
  • Zeptomail by Zoho — transactional email delivery
  • OpenAI — AI text generation (content only, no identifying data)
  • Paystack — payment processing (PCI-DSS compliant)
  • Google Analytics — aggregate, anonymised usage statistics

All service providers are bound by data processing agreements and may not use your data for their own marketing or profiling purposes.

We do not sell your data

Newsata does not sell, rent, or trade personal data to advertisers, data brokers, or any third party. Full stop.

5. Data retention

We keep your data for as long as your account is active. Specific retention periods:

  • Account data: retained until you delete your account
  • Application records: retained for 2 years after the application date, then anonymised
  • Salary contributions: retained indefinitely in aggregate form; your personal link is removed if you delete your account
  • Uploaded CV files: retained while your account is active; deleted within 30 days of account deletion
  • Server logs (IP, requests): 90 days, then purged automatically

6. Security measures

  • All data in transit is encrypted via HTTPS (TLS 1.2+)
  • Database access is controlled by Supabase Row Level Security (RLS) — each user can only read their own records
  • Authentication uses one-time email codes (magic links) — we do not store passwords
  • Employer application view tokens are signed with HMAC-SHA256 and expire after 7 days
  • File uploads are stored in private Cloudinary buckets with signed access URLs

No system is 100% secure. If we ever discover a data breach that affects you, we will notify you within 72 hours in line with NDPR requirements.

7. Cookies and tracking

We use the following cookies and tracking technologies:

  • Session cookies: required for login and navigation — cannot be disabled without breaking the platform
  • Google Analytics (_ga, _gid): anonymous usage tracking — you can opt out via your browser's Do Not Track setting or a GA opt-out extension
  • Push notification subscription: stored in your browser if you grant permission — you can revoke from your browser or device settings at any time

We do not use advertising cookies or third-party retargeting pixels.

8. Your rights under NDPR

As a data subject under Nigeria's Data Protection Regulation (NDPR) and the Nigeria Data Protection Act 2023, you have the right to:

  • Access — request a copy of all personal data we hold about you
  • Correction — update inaccurate or incomplete information (most updates can be done from your dashboard)
  • Erasure — request deletion of your account and all associated personal data
  • Objection — object to processing based on legitimate interests
  • Restriction — ask us to limit processing while a dispute is resolved
  • Portability — receive your profile data in a machine-readable format (JSON)

To exercise any right, email privacy@newsata.com. We will respond within 72 hours and fulfil the request within 30 days. We may ask you to verify your identity before processing sensitive requests.

9. Children's privacy

Newsata is not directed at persons under 18. We do not knowingly collect personal data from minors. If you believe a minor has registered, please contact us and we will delete the account promptly.

10. Changes to this policy

We will update this policy when our practices change. If the changes are material — for example, a new category of third-party sharing — we will notify registered users by email at least 14 days before the change takes effect. The “last updated” date at the top of this page always reflects the most recent revision.

11. Contact & complaints

Data Controller: Newsata Limited, Lagos, Nigeria

Privacy enquiries: privacy@newsata.com

General support: support@newsata.com

If you believe we have handled your data unlawfully, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.