Legal
Privacy Policy
This policy explains how ProtenConnect — a product of Proten International Limited — collects, uses, stores, and protects the personal data of everyone who uses our platform, including job seekers (candidates) and hiring organisations (employers).
1. About This Policy & ProtenConnect
ProtenConnect is a talent acquisition and job-matching platform built and operated by Proten International Limited, a human resources and recruitment company registered in Nigeria. ProtenConnect helps Nigerian professionals discover job opportunities and helps employers find, screen, and hire qualified candidates — all in one place.
This Privacy Policy describes every category of personal data we collect, the specific purposes for which we process it, the legal grounds that justify each processing activity, how long we keep it, and the rights you can exercise at any time. We have written this policy to meet the requirements of the Nigeria Data Protection Act 2023 (NDPA 2023) and the Nigeria Data Protection Regulation 2019 (NDPR) which preceded it.
By creating an account on ProtenConnect — whether as a candidate or an employer — you acknowledge that you have read and understood this policy. If you do not agree with any part of it, please do not use the platform or contact us to discuss your concerns before registering.
2. Who This Policy Applies To
This policy applies to all individuals and organisations who interact with ProtenConnect, including:
Candidates (Job Seekers)
Individuals who create a profile, upload a CV, browse job listings, and submit applications through ProtenConnect. As a candidate, you are the primary subject of data processing on this platform. Your profile, CV, and application data are processed to match you with relevant jobs, score your fit for specific roles, and share your profile with employers whose vacancies you have applied to.
You remain in control: you decide which jobs to apply for, what information to include in your profile, and whether to make your profile discoverable to employers.
Employers (Hiring Organisations)
Companies, recruitment agencies, and individual hiring managers who create an employer account, post job vacancies, and review candidate applications through ProtenConnect. As an employer, your company information and the personal data of your account users (HR staff, hiring managers) are processed to enable you to manage your hiring pipeline on the platform.
Employers are also data controllers in their own right when they receive candidate data through ProtenConnect. You are responsible for handling that candidate data in accordance with NDPA 2023 and your own privacy obligations.
This policy also applies to visitors who browse the platform without an account, Proten International staff who access the admin dashboard, and any third party who contacts us by email or through the platform's messaging system.
3. Data Controller
The data controller responsible for ProtenConnect is:
Proten International Limited
Registered in Nigeria
Product: ProtenConnect (protenconnect.com)
Data Protection contact: [email protected]
As data controller, Proten International Limited determines the purposes for which your personal data is processed and the means by which that processing occurs. We are accountable for ensuring that all processing activities comply with NDPA 2023 and that appropriate technical and organisational measures are in place to protect your data.
Where employers receive candidate data through the platform (for example, when a candidate applies for one of their jobs), the employer becomes an independent data controller for that data and must comply with NDPA 2023 in their own right. ProtenConnect is not responsible for how employers use candidate data after it has been shared with them through the platform.
4. Data We Collect
The data we collect depends on whether you are a candidate, an employer, or an unauthenticated visitor. Below we describe each category in detail.
👤 Candidates — Data We Collect
Account & Identity Data
Full name, email address, password (stored as a bcrypt hash — we never store your plain-text password), profile photo URL, account creation date, and last login timestamp. If you sign in via Google or LinkedIn, we also store your OAuth provider ID so we can recognise you on future logins.
Professional Profile Data
CV/resume file (PDF or Word), work experience history (job titles, companies, dates, responsibilities), education history (institutions, qualifications, graduation years), skills list, professional summary, portfolio links, publications, certifications, volunteer experience, and awards. This is the core data used to match you with jobs and generate your AI match score.
Job Preferences
Desired job titles, preferred industries, salary expectations, preferred work arrangement (remote, hybrid, on-site), preferred locations, and availability to start. This data is used to surface relevant job listings and personalise your dashboard.
Application Data
Records of every job application you submit through the platform, including the job applied for, the date of application, the version of your CV submitted, any cover letter or supplementary answers, your application status (under review, shortlisted, rejected, offered), and the AI match score generated for that application.
Communication Data
Messages you exchange with employers through the ProtenConnect in-app messaging system, including message content, timestamps, and read receipts. We do not read your messages in the ordinary course of business; they may be reviewed if a safeguarding or legal concern is reported.
Contact Hashes
A SHA-256 hash of your email address (and phone number if provided) used internally to detect duplicate accounts and prevent fraud. The hash is a one-way fingerprint — it cannot be reversed to reveal your original contact details.
🏢 Employers — Data We Collect
Account User Data
Full name, work email address, password hash, job title, and role within the company (owner, admin, member) for every person in your organisation who has a ProtenConnect account.
Company Profile Data
Company name, industry, company size, registered address, website URL, company description, logo, cover image, social media links, culture information, benefits listed, and any testimonials or media uploaded to the company page.
Job Listing Data
Every job vacancy you post, including job title, description, required skills, experience level, salary range, work arrangement, location, application deadline, and the status of each listing (draft, published, closed).
Hiring Pipeline Data
The stages you create within your hiring pipeline, which candidates you move between stages, interview notes you record, offers made and their terms, and hiring decisions. This data helps your team collaborate on hiring and forms an audit trail of your recruitment process.
Candidate Data Accessed
When a candidate applies for one of your jobs, you gain access to their professional profile, CV, and AI match score for that role. You do not gain access to candidates' data for jobs they did not apply to. This data is subject to NDPA 2023 and you must handle it appropriately.
🌐All Users — Technical & Usage Data
Usage Data
Pages visited, features used, buttons clicked, search queries entered, time spent on each page, and navigation paths. This data is collected by Microsoft Clarity (with consent) and is used in aggregate to improve the platform.
Device & Network Data
IP address, browser name and version, operating system, screen resolution, and country derived from IP. This is collected for security monitoring (e.g. detecting suspicious login attempts) and performance analytics.
Consent Records
Each time you interact with the cookie consent banner — accepting, declining, or updating your preferences — we record the timestamp, your IP address, your browser user agent, and the specific choices you made. These records are retained for regulatory audit purposes.
Audit Logs
Sensitive actions taken on the platform (e.g. account deletions, role changes, admin actions) are written to a tamper-evident audit log. These logs protect both users and Proten International in the event of a dispute or regulatory investigation.
5. How We Use Your Data
👤 For Candidates
- →Account management: To create and maintain your account, authenticate you on login, and allow you to update your profile and preferences.
- →Job matching: To surface job listings that match your stated preferences, skills, and experience. Matching is based on the profile data you provide — we do not infer sensitive characteristics (race, religion, disability) for matching purposes.
- →AI scoring: When you apply for a job, your CV is sent to our AI providers to generate a fit score and a plain-language explanation of how well your experience matches the role. This score is visible to both you and the employer. It is one signal among many — it does not determine whether you are hired.
- →Application tracking: To give you a real-time view of all your applications, their statuses, and any communications from employers.
- →Notifications: To send you emails about new jobs matching your preferences, status updates on your applications, messages from employers, and important platform announcements.
- →Profile visibility: If you opt in, to make your profile discoverable by employers searching for candidates with your skills — even if you have not applied to their specific job.
🏢 For Employers
- →Account management: To create and manage your employer account, authenticate your team members, and control who in your organisation can access the platform.
- →Job posting: To publish your job vacancies on the platform and make them visible to relevant candidates.
- →Applicant review: To give you access to the profiles, CVs, and AI match scores of candidates who have applied to your jobs, so you can efficiently screen and shortlist.
- →Hiring pipeline management: To allow your team to move candidates through hiring stages, record interview notes, make offers, and close roles.
- →Team collaboration: To allow multiple members of your team to work together on hiring, with role-based access controls that limit what each team member can see and do.
- →Communications: To enable direct messaging between your hiring team and candidates through the platform's built-in messaging system.
🔒 For All Users — Platform Operations
- →Security: To detect and prevent fraud, abuse, unauthorised access, and other harmful activities. This includes IP-based rate limiting, login attempt monitoring, and account lockout protection.
- →Platform improvement: To analyse how the platform is used in aggregate and identify areas for improvement in design, performance, and functionality.
- →Legal compliance: To meet our obligations under NDPA 2023, respond to lawful requests from regulators or courts, and maintain the audit trail required by law.
6. AI Processing of Your CV
ProtenConnect uses artificial intelligence to score how well a candidate's CV matches a specific job description. This is one of the platform's core features and it is important that both candidates and employers understand exactly how it works.
What the AI does
When a candidate submits an application, we extract the text from their CV and combine it with the text of the job description. This combined input is sent to our AI providers (Google Gemini, Anthropic Claude, and Groq as a fallback). The AI analyses the overlap between the candidate's stated skills and experience and the requirements of the role, then returns a structured score (0–100) across several dimensions — such as skills match, experience relevance, and education fit — along with a plain-language explanation of its assessment.
What the AI score means
The score is a tool to help employers and candidates quickly understand fit. It is not a decision — it does not automatically accept or reject applications. Human reviewers (the employer's hiring team) always make the final decision. A low score does not mean you will not be hired; a high score does not guarantee it. Employers are instructed to use the score as a starting point, not a verdict.
What the AI does not do
Our AI does not make inferences about your age, gender, race, religion, disability, or any other protected characteristic. It processes only the text content of your CV and the job description. We do not use facial recognition or voice analysis anywhere on the platform.
AI provider data policies
Our AI providers (Anthropic and Google) do not use data submitted via their APIs to train their general-purpose AI models. Your CV content is processed in memory for the purpose of generating a score and is not stored or used by them for any other purpose. Groq operates under similar terms. See Section 9 (Third-Party Processors) for links to each provider's privacy policy.
Your right to object
If you do not wish your CV to be processed by AI, you can contact us at the address in Section 17. Note that AI scoring is core to how ProtenConnect matches candidates to jobs, so opting out may limit the functionality available to you. We will explain the practical implications before processing your request.
8. Legal Basis for Processing (NDPA 2023)
The Nigeria Data Protection Act 2023 requires that every processing activity has a lawful basis. The table below maps our main processing activities to their legal grounds.
| Processing Activity | Legal Basis |
|---|---|
| Account creation and authentication | Contract — necessary to provide you with the service you registered for |
| Showing your profile and CV to employers you applied to | Contract — core function of the platform you agreed to use |
| AI scoring of your CV for a specific application | Contract — you trigger this by submitting an application |
| Sending transactional emails (application updates, messages) | Contract — necessary to fulfil the service |
| Security monitoring, fraud prevention, rate limiting | Legitimate interest — we have a duty to protect the platform and its users |
| Error tracking via Sentry | Legitimate interest — necessary to maintain a reliable service |
| Microsoft Clarity (session recording) | Consent — only loads after you accept analytics cookies |
| Microsoft Clarity session recording | Consent — only loads after you accept analytics cookies |
| Marketing emails and job alert notifications | Consent — you opt in during registration or via your notification settings |
| Consent record keeping | Legal obligation — required by NDPA 2023 to demonstrate lawful processing |
| Audit logs of sensitive actions | Legal obligation and legitimate interest |
9. Third-Party Data Processors
We use the following sub-processors to operate ProtenConnect. Each is bound by a Data Processing Agreement (DPA). Click any processor name to read their privacy policy.
ProtenConnect is deployed on Vercel's cloud infrastructure. Vercel handles request routing, CDN delivery, and serverless function execution. No third-party analytics are collected via Vercel.
Data shared: IP address, page URLs, referrer, device type, browser, country
When an unexpected error occurs on the platform — for example, a failed job application or a broken page — Sentry captures the technical details automatically so our engineers can diagnose and fix it. Sentry does not receive your CV, password, or full profile data.
Data shared: Stack traces, error messages, browser/OS info, partial URL, user ID (if logged in)
When a candidate applies for a job, we send the candidate's CV content and the job description to Anthropic's Claude API. Claude analyses the match between the candidate's experience and the role requirements and produces a structured score and explanation. This score is shown to both the candidate and the hiring employer. Anthropic does not use submitted data to train its models under its API data usage policy.
Data shared: CV text, job description text, extracted skills and experience
Google's Gemini API is our primary AI scoring engine. Like Claude, it receives CV and job description text to produce match scores. Google's API terms prohibit using submitted data for model training without explicit consent.
Data shared: CV text, job description text, extracted skills and experience
Groq provides high-speed AI inference and is used as a fallback when our primary AI providers are unavailable or rate-limited. The same CV and job description data processed by Gemini and Claude may also be processed by Groq under the same conditions.
Data shared: CV text, job description text
Microsoft Clarity records anonymised user sessions and generates heatmaps showing how users interact with pages. This helps us identify confusing UI patterns, broken flows, and design improvements. Clarity automatically masks sensitive input fields (passwords, etc.) and does not record CV content typed into forms. This service only loads after you provide consent.
Data shared: Mouse movements, clicks, scroll depth, page interactions, IP address, browser info
If you choose to sign in with Google, we receive your name, email address, and profile photo from Google to create or link your ProtenConnect account. We do not receive your Google contacts, Drive files, or any other Google data. Your Google password is never shared with us.
Data shared: Name, email address, profile photo URL (only at sign-in)
If you choose to sign in with LinkedIn, we receive your name and email address from LinkedIn to create or link your account. We do not receive your LinkedIn connections, messages, or endorsements. Your LinkedIn password is never shared with us.
Data shared: Name, email address, profile photo URL (only at sign-in)
Supabase provides our PostgreSQL database and file storage (for CV uploads, profile photos, and company media). All data stored on ProtenConnect lives in Supabase's infrastructure, hosted on AWS in the EU (eu-west-1 region). Supabase is SOC 2 Type II certified and encrypts data at rest and in transit.
Data shared: All platform data (profiles, CVs, job listings, applications, messages)
10. International Data Transfers
ProtenConnect is a Nigerian platform but some of our service providers are based outside Nigeria, primarily in the United States and the European Union. Transferring personal data outside Nigeria requires appropriate safeguards under NDPA 2023.
For each international transfer, we rely on one or more of the following safeguards:
- Data Processing Agreements (DPAs) — contractual clauses requiring the recipient to protect your data to at least the standard required by NDPA 2023
- Adequacy decisions — transfers to countries or frameworks the Nigerian Data Protection Commission (NDPC) has determined provide adequate protection
- Provider certifications — for US providers, certification frameworks such as ISO 27001 and SOC 2 Type II that demonstrate equivalent security standards
Our database and file storage are hosted on Supabase (EU region), which means your profile data, CV files, and application data are primarily stored within the European Union. AI processing involves temporary transfer to US-based AI providers solely for the duration of the scoring request — no persistent storage occurs on their systems.
11. Data Retention
We retain your data only for as long as necessary for the purposes described in this policy, or as required by law. The table below sets out our standard retention periods.
| Data Category | Retention Period |
|---|---|
| Active account & profile data | Duration of account |
| Data after account deletion | 30 days |
| Job application records | 2 years after job closes |
| In-app messages | 2 years |
| Consent records | 5 years |
| Security & audit logs | 5 years |
| Anonymised analytics | Indefinitely |
| Uploaded CV files | Until deleted by candidate or 6 months after account deletion |
When data reaches the end of its retention period it is either permanently deleted from our database and file storage or anonymised so that it can no longer be linked to an individual. You can request earlier deletion under your right to erasure (Section 14).
12. Security
Proten International Limited takes the security of your personal data seriously. We have implemented the following technical and organisational measures:
Encryption in transit
All data transferred between your browser and our servers is encrypted using TLS 1.2 or higher. We enforce HTTPS with HTTP Strict Transport Security (HSTS).
Encryption at rest
Data stored in our Supabase (PostgreSQL) database and file storage is encrypted at rest by the underlying infrastructure.
Password security
We never store plain-text passwords. All passwords are hashed using bcrypt with a work factor designed to resist brute-force attacks.
Session security
Authentication sessions are stored in HTTP-only, secure, same-site cookies with encrypted JWT tokens signed with a server-side secret. Admin sessions are completely separate from regular user sessions.
Rate limiting
All API endpoints — especially authentication endpoints — are rate-limited using Upstash Redis to prevent brute-force and credential stuffing attacks.
Access controls
Admin access to the platform requires a separate admin account with role-based permissions. Support for two-factor authentication (2FA) is available for admin accounts.
Dependency security
We regularly audit our open-source dependencies for known vulnerabilities and apply patches promptly.
Incident response
In the event of a data breach affecting your rights and freedoms, we will notify the NDPC within 72 hours and affected users as soon as reasonably practicable, as required by NDPA 2023.
No system is perfectly secure. If you believe your account has been compromised or you have discovered a security vulnerability, please contact us immediately at [email protected].
14. Your Rights Under NDPA 2023
The Nigeria Data Protection Act 2023 grants you the following rights in relation to your personal data. These rights apply to both candidates and employers.
Right of Access (Section 34, NDPA 2023)
You have the right to request a copy of all personal data we hold about you, the purposes for which we process it, the categories of data involved, who we share it with, and how long we retain it. We will provide this within 30 days of your request, free of charge, in a commonly used electronic format.
Right to Rectification
If any personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct it. For profile and CV data, you can update most information directly in your account settings. For data held in logs or records, contact us and we will make the correction.
Right to Erasure (Right to be Forgotten)
You can request that we delete your personal data. We will comply unless we are required by law to retain it (for example, audit logs, consent records, or application records subject to a legal hold). If we cannot fully delete certain data, we will explain why and delete everything we legally can.
Right to Data Portability
You can request a copy of the personal data you have provided to us in a structured, commonly used, machine-readable format (JSON or CSV) so that you can transfer it to another service. This applies to data you actively provided — such as your profile, work history, and education — not to derived data such as AI scores.
Right to Withdraw Consent
Where we rely on your consent to process data (analytics cookies, marketing emails), you can withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing that occurred before you withdrew consent. To withdraw analytics consent, delete the pc_consent cookie or contact us. To unsubscribe from marketing emails, use the unsubscribe link in any marketing email.
Right to Object
You have the right to object to processing based on legitimate interest (such as security monitoring or platform analytics). We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, or we need the data to establish or defend legal claims.
Right to Restrict Processing
In certain circumstances — for example, while you contest the accuracy of your data or while we consider your objection — you can ask us to restrict processing. During restriction, we may store your data but not actively use it.
Right Not to Be Subject to Solely Automated Decisions
Our AI match scores inform human reviewers but do not automatically accept or reject applications. No significant decision about you is made solely by automated means without human involvement. Employers always review applications and make the final hiring decision.
How to exercise your rights
Email us at [email protected] with your request. Include your full name, the email address associated with your account, and a clear description of the right you wish to exercise. We will acknowledge your request within 5 working days and respond in full within 30 days as required by NDPA 2023. If your request is complex or we receive a high volume, we may extend this by a further 30 days and will notify you accordingly.
If you are not satisfied with our response, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng.
15. Children
ProtenConnect is a professional employment platform intended for adults aged 18 and above. We do not knowingly collect personal data from anyone under the age of 18. If you are a parent or guardian and believe a minor has created an account on the platform, please contact us immediately at [email protected] and we will delete the account and all associated data without delay.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, new legal requirements, or improvements to the platform. The “Last updated” date at the top of this page will always show when the policy was last revised.
For material changes — those that significantly affect your rights or how we use your data — we will notify you by email at least 14 days before the change takes effect and display a prominent notice on the platform. For minor clarifications, we will update the page and date without a separate notification.
If you disagree with a change, you may close your account before the new policy takes effect by contacting us or using the account deletion option in your settings.
17. Contact & Complaints
For any questions about this Privacy Policy, requests to exercise your data rights, or concerns about how your data is handled, please contact:
Proten International Limited
Product: ProtenConnect
Email: [email protected]
Response time: Within 5 working days (full response within 30 days)
If you are not satisfied with our response to your complaint, or if you believe we are processing your personal data unlawfully, you have the right to escalate your complaint to the:
Nigeria Data Protection Commission (NDPC)
Website: ndpc.gov.ng