GET A CHEF WORLDWIDE LTD

DATA PROTECTION, PRIVACY & CONFIDENTIALITY POLICY

Policy Owner Get A Chef Worldwide Ltd
Version 1.0
Effective Date 24th August, 2026
Preapared by S. A. KOR, Esq, ACIArb
Approval Status Fully Approved

Applicable to the Company’s recruitment, referral, food-ordering and general business operations.

1. PURPOSE

This Policy establishes the principles, controls and responsibilities governing the collection, use, storage,disclosure, retention and protection of personal data and confidential information by Get A Chef WorldwideLtd (the “Company”).It is designed to support compliance with the Nigeria Data Protection Act, 2023, applicable directives of theNigeria Data Protection Commission and other applicable law.

2. SCOPE

This Policy applies to directors, employees, consultants, chefs, agents, delivery personnel, contractors,recruitment partners, vendors and other persons processing information for or on behalf of the Company.It covers information obtained through the Company’s recruitment and referral activities, food-orderingplatform, website, cart and payment channels, communications, social-media channels and other authorisedbusiness processes.

3. DEFINITIONS

In this Policy, “Personal Data” means information relating to an identified or identifiable natural person;“Data Subject” means the individual to whom Personal Data relates; “Processing” includes collecting,recording, using, storing, sharing, deleting or otherwise handling Personal Data; and “ConfidentialInformation” means non-public business, commercial, operational, customer, candidate or technicalinformation

4. DATA PROTECTION PRINCIPLES

The Company shall process Personal Data fairly, lawfully, transparently and with due regard to the rights andinterests of Data Subjects.Personal Data shall be collected for specified, explicit and legitimate purposes; limited to what is relevantand necessary; kept accurate where necessary; retained no longer than necessary; and protected againstunauthorised or unlawful access, loss, alteration, disclosure or destruction.

5. CATEGORIES OF INFORMATION

Depending on the relevant service, the Company may process candidate, customer, employer, partner andsupplier information.This may include identity and contact details, addresses, date of birth, photographs, qualifications,employment history, references, guarantor information, delivery details, order and payment references,complaints, communications and website or device information.
a. Health, allergy, dietary, identification, financial or other sensitive information shall be requested onlywhere necessary and handled with enhanced care.
b. The Company shall not knowingly collect more information than is reasonably necessary for the relevantpurpose.

6. PURPOSES AND LAWFUL BASES

The Company may process Personal Data to provide recruitment, referral, food-ordering, delivery, customer-service, vendor-management and related services; to communicate with Data Subjects; to manage payments;to maintain security and records; to comply with law; and to protect its legitimate business interests.Before processing, the Company shall identify an appropriate lawful basis, which may include consent,performance of a contract, compliance with a legal obligation, protection of vital interests, public interest orlegitimate interests, as permitted by applicable law.

7. NOTICE AND CONSENT

The Company shall provide clear and appropriate privacy information at or before the point of collection,including the relevant purpose, categories of data, recipient categories, retention approach and availablerights.Where consent is the lawful basis, it shall be informed, specific, freely given and capable of withdrawal.Withdrawal shall not affect processing lawfully undertaken before withdrawal or processing supported byanother lawful basis.

8. DATA SUBJECT RIGHTS

Subject to applicable law and lawful exceptions, a Data Subject may request information about processing,access to Personal Data, correction of inaccurate data, deletion, restriction, objection, portability, withdrawalof consent and human intervention in respect of solely automated decisions.The Company shall maintain a reasonable channel for rights requests, verify the requester’s identity whereappropriate and respond within the period required by applicable law or, where no period is prescribed,within a reasonable time.

9. CONFIDENTIALITY

Company Personnel shall keep Confidential Information and Personal Data confidential and shall use it onlyfor authorised business purposes. Access shall be limited to persons with a genuine need to know.No person shall disclose, copy, download, send, discuss or use such information for a private purpose oroutside authorised systems without prior approval or a lawful basis.

10. SECURITY MEASURES

The Company shall implement proportionate technical, physical and organisational safeguards, includingaccess controls, password and device security, secure storage, role-based access, appropriate disposal, staffawareness and vendor controls.Company Personnel shall promptly report suspected loss, unauthorised access, phishing, misdirection,compromise or other data-security incident to management or the designated data-protection contact.

11. SHARING, PROCESSORS AND INTERNATIONAL TRANSFERS

The Company may share Personal Data with authorised payment processors, logistics providers, recruitmentpartners, employers, technology providers, professional advisers, regulators and other recipients wherenecessary for a lawful purpose. Before engaging a processor, the Company shall take reasonable steps to ensure that the processor providesappropriate data-protection assurances and is bound to process data only on documented instructions.International transfers shall be made only in accordance with applicable legal safeguards.

12. RETENTION AND DISPOSAL

Personal Data and Confidential Information shall be retained only for as long as required for the purpose forwhich it was collected, to meet legal, accounting, tax, dispute-resolution or audit obligations, or as otherwisepermitted by law.When retention is no longer justified, records shall be securely deleted, anonymised or destroyed in a mannerappropriate to the medium and sensitivity of the information.

13. DATA BREACH MANAGEMENT

A suspected Personal Data breach shall be assessed promptly to determine its nature, scope, affected persons,likely consequences and containment measures. The Company shall document material incidents and takereasonable remedial action.Where notification to the Nigeria Data Protection Commission, affected Data Subjects or another authority isrequired, the Company shall make the notification within the applicable legal timeframe and provideappropriate information.

14. MARKETING, COOKIES AND ELECTRONIC COMMUNICATIONS

Direct marketing messages shall be sent only where permitted by applicable law and the recipient shall begiven an accessible means to opt out. The Company shall respect a valid opt-out request.Website cookies and similar technologies shall be used transparently and in accordance with applicable lawand the Company’s published website notices.

15. CHILDREN AND VULNERABLE PERSONS

Where the Company processes Personal Data relating to a child or vulnerable person, it shall take reasonablesteps to ensure that processing is lawful, necessary and supported by any consent, authority or safeguardrequired by applicable law.

16. RECORDS, GOVERNANCE AND TRAINING:

The Company shall maintain appropriate records of its processing activities, privacy notices, consents whererelevant, data-sharing arrangements, rights requests, security incidents and corrective actions.Management shall assign appropriate responsibility for data protection, provide proportionate awarenesstraining and periodically review privacy risks in the Company’s operations.

17. POLICY BREACH

Any Company Personnel or service provider who breaches this Policy may be subject to disciplinary,contractual, corrective or legal action. The Company may suspend access, investigate the matter and takesteps necessary to protect affected information and persons.

18. REVIEW AND APPROVAL

This Policy shall be reviewed periodically and may be amended to reflect changes in the Company’soperations, technology, applicable law, regulatory guidance or risk profile.This Policy takes effect on the Effective Date once approved by authorised management of Get A ChefWorldwide Ltd.

APPROVAL

Approved By
Designation Chief Executive Officer
Signature
Date 24TH August, 2026
Scroll to Top