DRAFT: pending legal review, not final. This policy is a working draft grounded in how Nimera actually operates today. It has not been reviewed by a lawyer or a data-protection specialist. Do not rely on it as a binding statement of our practices until it has been reviewed and this notice is removed.

Privacy Policy

Last updated: 15 August 2026

Who we are

This service is operated by Nimera Technologies Ltd, registered at D14 South-End Estate, Aviation Village, Abuja, Nigeria. This policy is governed by the Nigeria Data Protection Act 2023 (NDPA).

What data we collect and why

We collect and process the following categories of data to operate the Nimera platform:

  • Account and authentication data — name, email address, and login credentials, used to create and secure your account.
  • Household and membership data — roles and permissions for people you grant access to your home (family members, staff, guests), used to control who can do what within your home.
  • Device and telemetry data — status and usage data from the smart-home devices connected to your hub (e.g. lights, locks, sensors, energy monitoring), used to display your home's state and history, and to power features like energy tracking.
  • Alert and activity history — records of events such as smoke alarms, door activity, and connectivity status, used to notify you and maintain a history of your home's safety events.

We do not sell your personal data to third parties.

Biometric data

For high-sensitivity actions (such as unlocking a door), the app may prompt you for biometric verification (fingerprint or face recognition) using your device's built-in security features. This verification happens entirely on your device — your biometric data is never transmitted to us, stored on our servers, or accessible to us in any form. We only receive confirmation that verification succeeded or failed.

Children's data

Where a household includes a minor, that member's account is created directly by a parent or legal guardian through an authenticated flow — the minor cannot independently register or create their own account. The guardian provides the account information, and a temporary password is generated by the system; the minor sets their own password only after this account has been provisioned by the guardian. We do not knowingly collect personal data directly from children through a public or self-service registration process.

Third-party processors

We currently use the following third-party service to help operate Nimera:

  • Firebase Cloud Messaging (Google) — used to deliver push notifications for safety alerts (smoke, door, hub connectivity).

Additional processors (such as our hosting and infrastructure provider) will be added to this section as they are finalized, and this policy will be updated accordingly before any such processor begins handling your data.

Data retention

We retain your account and home data for the duration of your active account, and for up to 2 years following account closure, except where longer retention is required by law. Guest access data (device grants and access logs tied to a stay) is retained for 6 months following the end of a guest's stay, after which it is deleted.

Your rights

Under the Nigeria Data Protection Act 2023, you have the right to access, correct, or request deletion of your personal data, and to object to or restrict certain processing. We will respond to verified requests within 30 days.

To exercise these rights or ask questions about this policy, contact us at enquiries@nimera.ng.

Changes to this policy

We may update this policy as our practices evolve. We will post any changes on this page with an updated "Last updated" date.