Privacy Policy
Last updated · Version 1.0
In short
We collect what we need to teach you Hausa and run your account: your email, your progress, and payment records (Flutterwave handles your card; we never see the full number).
No ads, no analytics trackers, no selling your data. You can ask for a copy of your data or for it to be deleted at contact@gohausa.com.
1. Who we are
GoHausa (app.gohausa.com) is run by Xernu LTD, a company registered in Nigeria (RC 9404266), of 355, (CR) 1R, Lugbe Federal Housing, Airport Road (Opp. Pyakasa), Abuja, FCT, Nigeria. We decide how your personal data is used, so we are its data controller under the Nigeria Data Protection Act 2023 (NDPA) and, for learners in the UK and EU, the UK GDPR and GDPR.
Questions or requests about your data: contact@gohausa.com. Our Data Protection Officer: [Data Protection Officer — to be added].
This policy covers the GoHausa app and the emails it sends. The waitlist at gohausa.com has its own short notice at gohausa.com/privacy.
2. What we collect
When you create an account
- Your email address and, if you give one, your name.
- Your password, stored only as a one-way hash (argon2id). We can never read it.
- If you sign up with Google: your Google account ID, email address, whether Google has verified it, and the name on your Google profile.
- That you confirmed you are 18 or older, and which versions of our Terms and this policy you agreed to, with the date.
- Your timezone (for streaks and your daily goal) and your settings.
When you learn
- The lessons and units you start and finish, the answers you give in exercises, your practice schedule, XP, streaks and time spent learning.
When you pay
- Your plan, the amount, currency and date of each payment, and its status. Flutterwave takes the payment on its own secure page: we never see or store your full card number or security code.
- Flutterwave’s record of each payment, which can include the payment method, the card type, the first and last digits of a card, its expiry month and the issuing country.
- If you joined our waitlist: your waitlist position, matched to your account by the same verified email address, so we can apply the founding price.
To keep GoHausa safe and working
- For each signed-in session: your IP address and your browser’s user agent (its name and version).
- Server logs of requests, including IP addresses, kept for a short time to find faults and stop abuse.
- The country your connection comes from (from Cloudflare), used only to show prices in your currency. We don’t store it with your account.
- Whether an email to you bounced or was reported as spam, so we stop sending to that address.
What we don’t collect
We don’t record your voice, use your microphone or camera, read your contacts, track your precise location, or build advertising profiles. We use no analytics or advertising trackers (see the Cookie notice). We don’t ask for sensitive data such as religion, health or ethnicity, and we never sell personal data.
3. Why we use it, and our legal bases
To give you the course: your account, lessons, progress and settings
- Legal basis
- Performing our contract with you (the Terms)
To take payments, apply the founding price and keep financial records
- Legal basis
- Our contract with you, and legal obligations (tax and accounting law)
To send account emails: confirm your email, reset a password, receipts, failed payments and renewal reminders
- Legal basis
- Our contract with you
To keep accounts and payments secure, prevent fraud and abuse, and fix faults
- Legal basis
- Our legitimate interests in a safe, working service (balanced against yours)
To improve lessons, for example finding exercises many people find too hard, using combined figures
- Legal basis
- Our legitimate interests
To meet legal requests and defend legal claims
- Legal basis
- Legal obligations and our legitimate interests
4. Who receives your data
These providers process data for us, only on our instructions and under contracts that protect it:
Contabo GmbH
- What they do
- Hosts our servers and database
- Data
- Everything GoHausa stores about your account and learning
- Where
- Germany (EU)
Cloudflare, Inc.
- What they do
- Domain names, network delivery and security, staff access control, and file storage (R2) for lesson audio and backups
- Data
- Your IP address and requests as they pass through; database backups; lesson audio files
- Where
- Global network; storage in the EU
Flutterwave
- What they do
- Takes payments for plans
- Data
- Your name, email and payment details (we never see full card numbers), the amount and the plan
- Where
- Nigeria and other countries where Flutterwave operates
Zoho Corporation (ZeptoMail)
- What they do
- Sends account emails (confirm your email, password reset, payment receipts and reminders), once switched on
- Data
- Your email address, display name and the email’s contents
- Where
- Zoho’s data centres for our account region
Google LLC
- What they do
- Sign-in with Google, only if you choose it
- Data
- Google tells us your Google account ID, email address, whether it is verified, and your name
- Where
- United States and other countries
Hugging Face, Inc.
- What they do
- Hosts and trains our computer voice model
- Data
- No learner data. Only public speech datasets and model files
- Where
- United States and EU
We may also share data when the law requires it (for example with the NDPC, tax authorities or the police with a valid request), with our professional advisers, or with a buyer if GoHausa is ever sold, who would have to keep these promises.
5. Data outside Nigeria
Our servers are in Germany, and some providers above work from other countries. We only transfer personal data abroad as the NDPA allows (sections 41 to 43): to countries with adequate protection, under contracts with appropriate safeguards (such as standard contractual clauses in our providers’ terms), or where the transfer is needed to provide the service you asked for. Ask us at contact@gohausa.com for details of the safeguards.
6. How long we keep it
- Your account and learning history: while your account is open. When you ask us to delete it, we close it at once and erase or anonymise the data within 30 days.
- Payment records: 6 years after the payment, because tax and accounting law requires it.
- Sign-in sessions: a session lasts up to 30 days unless you sign out; its record is deleted with your account.
- Server logs: a short time, normally no more than 30 days.
- Bounced or complained-about email addresses: for as long as we need to avoid emailing that address again.
7. Your rights
You can ask us to:
- tell you what data we hold about you and give you a copy;
- correct data that is wrong or incomplete;
- delete your data (we keep only what the law makes us keep);
- restrict how we use it, or object to uses based on legitimate interests;
- send your data to you or another service in a common format (portability);
- withdraw any consent you gave, without affecting what was done before.
Email contact@gohausa.com from the address on your account. We may ask you to confirm it’s you. We answer within 30 days, and free of charge unless a request is clearly excessive.
We make no decisions about you by automated means that have legal or similarly significant effects. (The app does choose which words to practise next for you, which has no such effect.)
If you’re unhappy with how we handle your data, please tell us first. You can also complain to the Nigeria Data Protection Commission (NDPC); in the UK to the Information Commissioner’s Office; in the EU to your country’s data protection authority.
8. GoHausa is for people aged 18 and over
You must be 18 or older to create an account, and you confirm this when you sign up. We don’t knowingly collect data from anyone younger. If you think a child has made an account, tell us at contact@gohausa.com and we’ll delete it.
9. How we protect your data
Every connection is encrypted (HTTPS). Passwords are stored only as strong one-way hashes. Your sign-in key is kept in your browser’s memory, and the cookie that keeps you signed in can’t be read by scripts. Staff tools sit behind separate access control, and only people who need data to do their job can see it.
If a breach puts people at risk, we notify the NDPC within 72 hours of learning of it, and we tell you directly, without delay, if it is likely to put you at high risk.
10. Changes to this policy
When we change this policy we update the date and version at the top. If a change matters to how your data is used, we’ll tell you by email or in the app before it takes effect.
11. Contact
Privacy: contact@gohausa.com. Everything else: contact@gohausa.com. Postal address and phone are on our contact page.