Legal framework
Privacy policy
Last update: 1 January 2026
Nafirka processes personal data to operate safe, measurable, and compliant urban mobility. This policy explains what we collect, why we collect it, retention periods, sharing rules, and your rights.
Data minimization
We collect only the data required to operate service, ensure safety, and meet regulatory obligations.
Control and transparency
Sensitive processing (rides, incidents, verification) is governed by internal access and security controls.
1. Data controller
- Nafirka is the data controller for personal data processed through its applications, websites, and operational services in Niamey, Niger.
2. Data categories
- Account data: name, phone number, email, profile information, and account status.
- Verification data: role-specific documents for drivers and fleet operators.
- Service data: subscriptions, QR validations, trip records, payments, and invoicing.
- Support data: tickets, complaints, and incident-resolution trace.
- Technical data: device details, app version, security logs, and audit events.
- Location data: coordinates required for dispatching, navigation, safety, and incident handling.
3. Purposes
- Deliver transport services and real-time operations.
- Validate access rights, subscriptions, and compliance status.
- Prevent fraud and protect users and partners.
- Maintain service quality and technical continuity.
- Meet legal, accounting, and compliance obligations.
4. Legal bases
- Processing is based on contract performance, legal obligations, legitimate interests for safety/fraud prevention, or consent where required.
- In Niger, processing of personal data is governed by Law No. 2017-28 of May 3, 2017 on the protection of personal data, as amended by Law No. 2019-71 of December 24, 2019, under the supervision of the Haute Autorite de Protection des Donnees a caractere Personnel (HAPDP).
5. Retention periods
- Active account data: during service relationship and post-closure retention period.
- Trip and evidence data: according to safety, dispute, and compliance needs.
- Billing/accounting records: according to fiscal and legal obligations.
- Security logs: according to internal incident-detection policy.
- Guardian/parent notification logs for minor accounts: 12 months.
6. Recipients and sharing
- Authorized internal teams based on operational need-to-know.
- Contracted technical providers (hosting, support, payments).
- Operational partners strictly required to deliver requested services.
- Competent authorities when required by law.
7. Security and transfers
- Nafirka applies technical and organizational measures to protect data (access control, logging, segmentation, and periodic reviews).
- When cross-border transfer is necessary, contractual safeguards are applied according to applicable regulation.
8. Cookies and trackers
- Cookies may be used for authentication, security, analytics, and service improvement. You can manage preferences through browser or device settings.
9. Your rights
- Access, rectification, and update of your personal data.
- Objection, restriction, or consent withdrawal when applicable.
- Erasure where legally and operationally possible.
- Complaint to the competent authority: in Niger, the Haute Autorite de Protection des Donnees a caractere Personnel (HAPDP).
- Requests: privacy@nafirka.com
10. Policy updates
- This policy may evolve with legal, technical, and operational changes. The latest revision date is shown on this page.