Who we are
This website, apatira.me, is operated by the Office of Hon. Opeyemi Apatira, Leader of the Legislative Arm of Ojodu LCDA, Lagos, Nigeria (referred to in this notice as “the Office”, “we”, “us” or “our”).
For the purposes of the Nigeria Data Protection Act 2023, the Office is the data controller — the organisation that decides why and how your personal information is handled. The Office is also supported by ORISUN Systems and Technologies, which builds and maintains the platform on the Office's instructions.
This notice covers personal information collected through this website and in the course of constituency communications, including the contact form, the newsletter, and the constituency SMS and phone outreach run by the Office.
Our commitment
As an elected public office, we hold ourselves to a high standard. We commit to handling personal information lawfully, fairly and transparently under the Nigeria Data Protection Act 2023 and the Nigeria Data Protection Regulation (NDPR), and to the following principles:
- We collect only the information we genuinely need to serve the constituency.
- We use it only for the purpose we collected it for, or a purpose closely related to it.
- We never sell, rent or trade your personal information.
- We do not use your information for advertising, and we do not share it for anyone else's marketing.
- We keep it only for as long as it is needed and then delete it securely.
- We give you clear ways to withdraw consent and to reach us about your information.
Information we collect
We collect the following categories of personal information, each only when there is a reason to do so:
- Messages you send through the contact form
- Your name, email address, subject, selected category and message. These submissions are stored in the Office's secure messaging system, are visible to authorised staff in the admin console, and may be replied to by email.
- Newsletter subscriptions
- Your name, email address and (optionally) your phone number, collected when you subscribe to updates. We use your name to greet you in the emails we send. If you supply a phone number you are agreeing to receive constituency SMS updates, and that SMS opt-in is recorded separately on your record together with the date it was given. Details are stored on secure office infrastructure and used only for the updates you asked for.
- Constituent records collected offline
- Names and/or phone numbers collected in person, at community events or from lists provided to the Office, for constituency SMS and phone outreach. The consent basis for each record is recorded (for example, 'offline-collected').
- Email you send to the Office
- Messages sent to info@apatira.me are received through our email provider and stored in the Office system so staff can read and respond to them.
- Empowerment and support applications
- When you apply for empowerment or business support you give your name, age (optional), email, phone number, address, community and ward, details of your business or trade (including approximate monthly income and staff numbers if you provide them), what you need support for, your situation, your plan, and any priority group you choose to declare. This is used for one purpose — assessing your application, contacting you about it and, if you are awarded support, delivering and recording it. It is stored on secure office infrastructure, is visible only to authorised staff in the admin console, and can be deleted on request. An automated assistant scores and summarises each application to help staff read them consistently; it only advises, and the decision is always made by a person at the Office.
- Your NIN and LASSRA ID (support applications)
- The empowerment application starts with your National Identity Number. We send it to our identity verification provider (Dojah) so that your name, date of birth and gender come from the national identity record rather than from anything typed — those details are then locked on the form and cannot be edited by the applicant. The NIN itself is stored with your application, is masked in the admin list and only shown in full to authorised staff who are assessing it, and is never written to our server logs. We also ask for a photo or scan of your LASSRA (Lagos State Residents' Registration Agency) ID as proof that you live or trade in the constituency; that file is stored on secure office infrastructure and can be opened only by signed-in staff. Both are used solely to confirm who you are and that you are eligible for this programme, and both are deleted with your application on request.
- Device alerts (browser notifications)
- You can switch on device alerts to be told when a new story is published. If you do, your browser gives us an anonymous push address for that device together with the two keys needed to encrypt a message to it. We store only those, plus a coarse note of the browser type and the dates the alert last worked — no name, no email address and no IP address. Alerts are sent by us directly through your browser's own push service, never sold or shared, and switching alerts off in the same button removes the record. On iPhone and iPad, browser alerts only become available once the site has been added to the Home Screen.
- Chats with the site assistant
- If you use the assistant on this site you give your name, email address and phone number before the first message, and the conversation is stored with those details so the Office can follow up with you properly. The transcript and your details are visible to authorised staff in the admin console, are used only to answer your enquiry and any follow-up, and are deleted when a member of staff removes the conversation. Please do not include information you would not want recorded — the assistant is automated, and anything sensitive is better sent through the contact form or discussed directly with the Office.
- Server logs and visitor statistics
- Our web server records technical details of each visit — the page requested, the browser or user agent, and the time — for security and availability. Separately, the site counts its own visitors: page views and engaged reads of stories, with the referring site (for example WhatsApp or a search engine) and a general device type. Your IP address and browser identifier are combined with a secret held by the server and with the date, then reduced to a short anonymous code used only to count visitors for that day; the original values are not stored, and the code cannot be traced back to you or followed from one day to the next.
We do not deliberately collect sensitive categories of information (such as health, religious or biometric data). If you choose to include such details in a message to the Office, we will treat it with the same care and use it only to respond to you.
Lawful basis and consent
We rely on the following lawful bases for processing your information:
- Consent — for newsletter subscriptions, contact-form enquiries, and constituency SMS and phone outreach that you have agreed to receive. You may withdraw consent at any time.
- Legitimate interests — to respond to correspondence, to keep the Office running, and to protect the security and integrity of this website.
- Legal obligation and public task — where the Office is required to keep records or to carry out its lawful functions as a public office.
Where we rely on consent, you can withdraw it at any time by contacting us — see Email unsubscribe and SMS opt-out and How to contact us. Withdrawing consent stops future processing but does not affect the lawfulness of what we did beforehand.
How we use your information
- To read, triage and respond to the messages and enquiries you send the Office.
- To send you newsletters and constituency updates you have subscribed to.
- To conduct constituency SMS and telephone outreach to residents.
- To keep a record of constituent requests so we can follow them up to resolution.
- To keep the website secure, understand how many people genuinely visit, and measure the reach of our communications.
- To meet our legal, administrative and public-record obligations.
Who we share it with
We do not sell, rent or trade your personal information, and we do not share it for advertising or for the marketing of any other organisation. We rely on a small number of trusted service providers, who process information only on our instructions and only as needed to deliver their service:
- Identity verification (Dojah)
- When you apply for the student cash grant or an empowerment programme, the National Identity Number you enter is checked against the national identity registry through Dojah so the Office works with a verified name, date of birth and photograph rather than typed details. The Office stores the verified identity record and a masked reference to the number; the number itself is never written to a log line or shown in full to anyone.
- Bank payments (Paystack)
- For the student cash grant, the bank account you enter is verified with your bank through Paystack to confirm the account name before any transfer, and the grant is paid by transfer from the Office's Paystack balance. Paystack receives the account number, bank and account name for that purpose. The Office keeps the account name and a masked form of the number for its records, and publishes only the recipient's name, institution and the amount — never an account number, a NIN or a phone number.
- Email delivery (Resend and Amazon Web Services)
- Outbound email — replies, notices, newsletters and broadcasts — is delivered by Resend or by Amazon SES (Amazon Web Services), depending on which rail the Office has in service. Amazon SES also carries the private mailbox infrastructure and reports delivery failures and spam complaints back to the Office so an address that bounces is removed from the list automatically. Inbound mail to info@apatira.me is received and handed to the Office through the same providers.
- Termii
- Delivers SMS to recipients within Nigeria, and therefore processes the recipient's phone number and the content of the message.
- Dojah
- Validates and cleans phone numbers, so that outreach reaches the right people and we avoid messaging invalid numbers.
- Mobile network operators
- As the final step in delivering an SMS, the recipient's mobile network necessarily processes the phone number and the message content.
We may also disclose information where we are required to do so by law or by a lawful order of a competent authority.
Cookies, tracking and server logs
The public pages of this site do not use advertising trackers, third-party analytics services, or cookies for tracking. We do not follow you across other websites, and we do not build advertising profiles of visitors.
We do count how many people visit the site and which stories are read, so the Office can see whether its communication is reaching residents. This measurement is run by the Office itself on its own server. A visit records the page opened, the referring site (for example WhatsApp, Facebook or a search engine), a general device type (phone, tablet or computer) and the time. On story pages it also records whether the visit looked like a genuine read — how long the page stayed visible and how far you scrolled.
You are not identified by this. Your IP address and browser identifier are combined with a secret held by the server and with the date, then reduced to a short anonymous code used only to count visitors for that one day. The original values are never written to disk, the code changes every midnight, and it cannot be traced back to you or followed from one day to the next. These counts are kept for 180 days and then deleted automatically. Office staff see totals only — never an individual visitor's activity.
Our web server also keeps ordinary access logs — the IP address, the page requested, the browser or user agent, and the time — for security, and they are used to keep the site available and secure, not to identify individual residents.
When a NIN is verified successfully we keep the verified identity in our own verification table, keyed by a salted code rather than the NIN itself, so that a later check of the same number is answered from our records instead of paying the identity provider again. Records that could not be found are never kept. These entries are stored on secure office infrastructure, are visible only to authorised staff, and are deleted on request.
One functional cookie is set on this site: when your NIN is verified we store a random device identifier so that the free NIN check can be limited to one a day per device (the checks cost the Office money). It contains no personal information, is not used to follow you, and is never shared. We also keep a short record of each NIN check — the device identifier, a daily-rotating code derived from the connection address, the last four digits of the NIN and the outcome — so the limit can be enforced and audited.
Staff who sign in to the Office admin console receive a session token that their browser stores locally so they can stay signed in. That token authorises console requests only; it is not used for advertising and is not shared with anyone.
Your rights
Under the Nigeria Data Protection Act 2023, you have the right to:
- Ask us for a copy of the personal information we hold about you (access).
- Ask us to correct information that is inaccurate or incomplete.
- Ask us to delete information we no longer have a lawful reason to keep.
- Withdraw consent to processing, at any time.
- Object to, or ask us to restrict, certain processing.
- Ask for a copy of your information in a portable form where that right applies.
To exercise any of these rights, email the Office at info@apatira.me with enough detail for us to understand your request. We will respond within 30 days. We may ask you to confirm your identity before acting, to make sure we do not disclose or delete the wrong person's information.
If you are not satisfied with how we have handled your request, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC).
Email unsubscribe and SMS opt-out
Every bulk email we send carries an unsubscribe link. You can also manage your subscription at apatira.me/unsubscribe. Once you unsubscribe, your address is marked inactive and you will not receive further updates.
SMS and phone outreach
Constituency SMS is sent from an alphanumeric sender ID (a name, not a mobile number), so replies — including “STOP” — cannot be received. To opt out of SMS, visit apatira.me/unsubscribe and enter the phone number you signed up with; that number is added to our suppression list and receives no further messages.
You can also opt out at any time by emailing info@apatira.me or by calling the office on +234 904 910 1934, and the Office will add your number to its suppression list manually. We honour every opt-out request we receive, however it reaches us.
Opting out stops future messages. It does not affect the lawfulness of messages already sent.
How long we keep information
We keep personal information only for as long as we need it for the purpose it was collected for, together with any period we are required to keep it for record-keeping or legal reasons:
- Contact-form messages and constituent records are kept while the Office continues to serve the constituency and to follow up outstanding requests, and for as long as public-record rules require.
- Newsletter email addresses are kept until you unsubscribe or ask us to delete them.
- Assistant chat transcripts are kept while the Office may still need to follow up on the enquiry, and are deleted on request or from the admin console at any time.
- Empowerment and support applications are kept while the Office assesses them and for as long as it must account for support it has given; unsuccessful applications are kept for the current and following review cycle and can be deleted sooner on request.
- Server logs and the visitor statistics described above are kept for a short, rolling period for security and reporting, then discarded.
When information is no longer needed, we delete it securely or, where that is not immediately possible, we stop using it and restrict access to it.
How we protect information
Access to personal information is limited to authorised staff who need it for their work with the Office. Information is stored on secured office infrastructure protected by appropriate technical and organisational measures.
No system can be guaranteed completely secure. If a security incident ever affects your personal information, we will act promptly and notify you and the relevant authorities in line with the Nigeria Data Protection Act 2023.
Children
This website is not directed at children, and we do not knowingly collect information from children. If you believe a child's information has been provided to us without appropriate consent, please contact the Office and we will delete it.
Changes to this notice
We may update this notice from time to time to reflect changes in our practices or in the law. Any update will be posted on this page with a new “Last updated” date. This version was last updated on 11 September 2026.
How to contact us
Office of the Leader, Legislative Arm
For any question or request about your personal information — access, correction, deletion, or withdrawing consent:
- info@apatira.me
- Ojodu LCDA, 1-3 Secretariat Road, Power Line, Okera, Ogba, Ikeja, Lagos
- +234 904 910 1934 • Mon – Fri, 9:00am – 4:00pm (WAT)