Legal
“OHMFLEX” PRIVACY POLICY
1. About this Privacy Policy
1.1 What this Policy does. This Privacy Policy explains how we collect, use, share, retain and delete personal data when you use OhmFlex, and what rights you have in relation to that data.
1.2 It forms part of the Agreement. This Privacy Policy is referred to in clause 15.1 of the Core Platform Terms and forms part of the Agreement between you and us. It must be read together with the Core Platform Terms and with any Schedule that applies to you. Words and expressions defined in the Core Platform Terms, including “App”, “App Developer”, “Comfort Window”, “Device”, “Dispatch”, “Flexibility Share”, “Hub”, “Marketplace”, “Merchant”, “Plan”, “Plan Capacity”, “Platform”, “Space”, “Telemetry”, “Unit”, “Sub-Unit” and “Wallet”, have the same meaning in this Privacy Policy.
1.3 Who it applies to. This Privacy Policy applies to you if you selected Nigeria as your country when you registered. It applies to individual accounts and to corporate accounts, and to users invited into a corporate account, subject to clause 11.
1.4 Governing framework. This Privacy Policy is given under, and is to be read in accordance with, the Nigeria Data Protection Act 2023 (the “NDPA”).
1.5 Interpretation. This Privacy Policy is made in English. Headings are for convenience only. “Including” means “including without limitation”. References to a statute include that statute as amended or replaced.
2. Who we are
2.1 The data controller. OhmFlex is operated by Escrow Tech Nigeria Limited, a company incorporated in Nigeria under the Companies and Allied Matters Act 2020 with registration number RC 8826047 (“OhmFlex”, “we”, “us”, “our”). We are the data controller in respect of the personal data described in this Privacy Policy, except where clause 11 provides otherwise for corporate accounts.
2.2 What OhmFlex is. OhmFlex is a platform for electricity monitoring, optimization and flexibility. Through OhmFlex you can connect compatible Devices and Hubs, monitor and control your electricity use, organise your Devices into Spaces and Units, buy hardware and software from third parties through our marketplaces, and, where available, enrol Devices in flexibility programmes and earn a share of the value they generate. The personal data described in this Privacy Policy is the data generated by those activities.
2.3 HASIP infrastructure. OhmFlex operates over infrastructure provided by HASIP, our group’s device and telemetry platform. Your agreement is with OhmFlex, and it is we, and not HASIP, who are answerable to you under this Privacy Policy for personal data processed through that infrastructure.
2.4 Other Escrow Tech products. Your OhmFlex account is specific to OhmFlex. If you wish to use another Escrow Tech product you must register separately for it, and this Privacy Policy does not apply to that separate registration.
3. The personal data we collect
3.1 Registration data. To register you must provide the information requested on the sign-up form. For an individual account this is your full name, email address, phone number, country and a password. For a corporate account this is the company name, company type, office address, company email address, registration status, contact person and phone number.
3.2 Verification data. We verify your email address by sending a one-time code. Access to the Platform is conditional on identity verification, and until your account is approved your account status will show as pending and your access will be limited. You must upload the documents we request. These vary by account type and may change. At the date of this Privacy Policy we require:
(a) for individual accounts: a national identity card, licence, or residence permit; and
(b) for corporate accounts: identification for the contact person, certificate of incorporation, letter of authorization, and where applicable a professional certificate or licence.
3.3 Further verification data. We may ask for additional or updated documents at any time, including where required by law, by a payment provider, or where we have reason to doubt information you have given us. We also hold the outcome of our review, being the approval, rejection or suspension of your account.
3.4 Authentication and security data. Your password; your two-factor authentication settings where you enable two-factor authentication by email or by authenticator application; and records of the re-authentication, password resets and additional verification that we require where we consider it necessary to protect your account.
3.5 Records of acceptance. We keep a record of your acceptance of this Privacy Policy and of every other document forming part of the Agreement, including the version accepted and the date and time of acceptance. You can view and download every document you have accepted at any time from Documents and Agreements in your account.
3.6 Telemetry. Telemetry is data generated by or about your Devices and Hubs, including power, voltage, current, energy, connection status and command history. Telemetry is collected continuously for as long as your Devices and Hubs are connected.
3.7 Device and Hub data. The Hubs and Devices on your account, their pairing to your account and their connection to your internet connection, their firmware version, and the number of Devices and Hubs you hold against your Plan Capacity.
3.8 Control and scheduling data. The commands you issue to your Devices, and the schedules you set, including start time, end time and repeat frequency.
3.9 Spaces and shared access data. The Spaces you create, the names and images you give them, the aggregated consumption shown for a Space, and, where you use Share Access, the email address of the person you invite, the role you give them and the period of validity of the invitation.
3.10 Content you submit. Reviews you write about products and Apps, and any feedback or suggestions you give us.
3.11 Flexibility and Dispatch data. Which Devices you have enrolled in a flexibility programme, the Comfort Window you set for each enrolled Device, the Dispatches issued to it, your participation in the programme, and the Flexibility Share and other earnings credited to you.
3.12 Plan, billing and payment data. Your Plan and its price, billing cycle and capacity limits; any Overage you purchase; changes of Plan or billing cycle, renewals and cancellations; the amounts charged to you in Naira together with the value added tax applied; and the record of successful and failed payments. Payment is made through our payment provider’s gateway. We do not receive or store your full card details, and your use of a payment provider is subject to that provider’s own terms.
3.13 Wallet data. Your Wallet balance and the credits and debits made to it, including flexibility earnings, refunds, Marketplace purchases, App subscriptions, Plan fees and other amounts you owe us under the Agreement.
3.14 Marketplace data. Your orders; the delivery address you give at checkout; the product price, shipping fee and value added tax shown to you at checkout; and the order status the Merchant reports, being ordered, payment confirmed, processing, shipped, in transit and delivered.
3.15 App Marketplace data. The Apps you subscribe to, your trials, subscriptions and billing in respect of them, and the permissions you have granted to each App.
3.16 Support and complaints data. The support tickets you raise through the in-app ticketing system, including the category and priority you select and your description of the issue; the status of each ticket; your correspondence with us through the help centre or through the email and phone details published in the Platform; and your support history.
3.17 Derived data. From Telemetry, and from tariff and rate information we hold, the Platform derives your consumption over time, estimated cost, amounts earned and net cost. As explained in Schedule A, clause A.6, these figures are indicative only and are not a meter reading.
4. What Telemetry can reveal
4.1 Sensitivity. You should understand that Telemetry from your Devices is collected continuously and at a granularity that can reveal when premises are occupied, when appliances are used, and patterns in your daily routine. We treat this data accordingly.
4.2 How we treat it. The controls described in this Privacy Policy, in particular those governing access by our staff, the permissions you grant to Apps and the access you give through Share Access, are applied with that sensitivity in mind.
4.3 Your decisions. You should take that sensitivity into account whenever you decide to invite a person to a Space, to grant a permission to an App, or to enrol a Device in a flexibility programme.
5. Why we use your personal data, and our lawful bases
5.1 Purposes and lawful bases. We use personal data only for the purposes set out below, and only where we have a lawful basis for doing so under the NDPA.
Purpose Lawful basis Registering you, creating and maintaining your account, and giving you access to the Platform. Performance of the Agreement. Verifying your email address and your identity, obtaining the documents we request, and deciding whether to approve, reject or suspend your account. Compliance with a legal obligation; performance of the Agreement; and our legitimate interest in preventing fraud and unlawful use of the Platform. Discovering, pairing, monitoring and controlling your Devices and Hubs, Performance of the Agreement.
Purpose Lawful basis storing Telemetry and presenting it to you, and running the schedules you set. Organising Devices into Spaces, Units and Sub-Units, and operating the Share Access feature. Performance of the Agreement. Enrolling the Devices you choose to enrol in a flexibility programme, issuing Dispatches within the Comfort Window you set, and calculating and crediting your Flexibility Share. Your consent, given when you enrol a Device; and performance of the Agreement. Selling and administering Plans and Overage, billing you, taking payment, applying value added tax, processing refunds, and operating your Wallet. Performance of the Agreement; and compliance with a legal obligation in respect of tax. Operating the Marketplace, including passing your order and delivery address to the Merchant, displaying the order status the Merchant reports, and assisting with disputes. Performance of the Agreement. Operating the App Marketplace, including administering subscriptions and trials and giving each App the access permitted by the permissions you have granted it. Your consent, given when you grant a permission; and performance of the Agreement. Providing support, handling tickets, complaints and escalations, and maintaining your support history. Performance of the Agreement. Sending you account security, billing and service notices, and notices of changes to the Agreement or to Plans, prices, capacity limits and overage rates. Performance of the Agreement; and compliance with a legal obligation. Keeping the Platform and your account secure, including authentication, two-factor authentication, re-authentication, logging of staff access, investigating suspected breaches of clause 13 of the Core Platform Terms, and reversing credits obtained in breach of clause
13.1(g). Our legitimate interest in protecting the Platform, our users and ourselves against fraud, unlawful use and misuse.
Purpose Lawful basis Updating Device and Hub firmware. Performance of the Agreement; and our legitimate interest in security, regulatory compliance and continued operation of the Devices and Hubs. Hosting, reproducing, displaying and adapting content you upload, including Space names, images and reviews, to the extent necessary to operate and promote the Platform. Performance of the Agreement and the licence you grant under clause 14.3 of the Core Platform Terms. Complying with the law and with a regulator and complying with the rules of a flexibility programme set by the Nigerian Electricity Regulatory Commission, a distribution company or a market operator. Compliance with a legal obligation. Keeping a record of your acceptance of the Agreement, including the version accepted and the date and time of acceptance. Compliance with a legal obligation, including section 84 of the Evidence Act 2011; and our legitimate interest in establishing the terms agreed between us. Establishing, exercising or defending legal claims, and handling disputes and investigations. Our legitimate interest in establishing, exercising or defending legal claims; and compliance with a legal obligation.
5.2 No incompatible use. We do not use your personal data for purposes that are incompatible with those set out in clause 5.1.
5.3 Withdrawing consent. Where we rely on your consent, you may withdraw it at any time. You may withdraw a Device from flexibility enrolment under Schedule B, clause B.2.3, and you may review and withdraw an App’s permissions under Schedule D, clause D.3.3. Withdrawal does not af fect processing carried out before the withdrawal takes effect, and withdrawing a permission may stop an App from working.
6. Communications we send you
6.1 Service communications. We use the email address on your account for account security, billing and service notices. You must be able to receive email at the address you give us.
6.2 Notices you will receive. We will notify you if a payment fails; when a Merchant accepts your order; of planned maintenance, where we will give reasonable notice; of material changes to the Agreement, on not less than 30 days’ notice; and of changes to Plans, prices, capacity limits and overage rates, on not less than 30 days’ notice.
6.3 Method of notice. We may give notice by email to the address on your account or by notification on the Platform, and both are effective.
7. Who we share personal data with
7.1 HASIP. Telemetry is processed through the HASIP infrastructure described in clause 1.5 of the Core Platform Terms. We and our infrastructure provider may also update Device and Hub firmware.
7.2 Cloud and payment providers. Your personal data is processed by the cloud providers that host and operate the Platform and by our payment provider, whose gateway processes your payments. We do not receive or store your full card details.
7.3 Merchants. Where you buy a physical product through the Marketplace, your contract of sale is with the Merchant. We provide the listing, the checkout, the payment processing and the order status display, and we pass to the Merchant the information it needs to accept, process and deliver your order, including the delivery address you gave at checkout. The Merchant reports the order status back to us for display in the Platform. Where Escrow Tech Nigeria Limited or a group company is itself the Merchant, it receives tha t information in its capacity as seller.
7.4 App Developers. Where you subscribe to an App and grant it permissions, the App Developer receives the access those permissions allow. Clause 10 sets out what each permission discloses.
7.5 People you invite. A person you invite to a Space can see consumption data for that Space and can operate the Devices in it.
7.6 Regulators, authorities and programme operators. We share personal data where we are required to do so by law or by a regulator, and where the rules of a flexibility programme set by the Nigerian Electricity Regulatory Commission, a distribution company or a market operator apply to your participation.
7.7 Business transfers. We may assign the Agreement to a group company or in connection with a transfer of our business, provided your rights are not adversely affected, and personal data may transfer with it.
7.8 No other sharing. Apart from the disclosures described in this clause 7 and elsewhere in this Privacy Policy, we do not share your personal data with third parties.
8. Transfers outside Nigeria
8.1 Where processing takes place. Telemetry is processed through the HASIP infrastructure, and personal data is processed by cloud and payment providers, some of which are outside Nigeria. Your personal data may therefore be transferred to, stored in and processed in countries other than Nigeria.
8.2 Our responsibility. Where personal data is transferred outside Nigeria we transfer it in accordance with the NDPA, and we remain answerable to you for it under this Privacy Policy.
9. Access by our staff
9.1 Who can see your data. Our customer service and administrative staff can access your account information, including your profile, Devices, flexibility participation, Wallet balance and support history, where necessary to provide support or to operate the Platform.
9.2 Controls. That access is controlled, logged and subject to confidentiality obligations. Our staff do not access your account information for any other purpose.
10. Sharing you control
10.1 Share Access. You may invite another person to a Space by email, giving them a role and a period of validity. An individual account may invite only individual accounts, and a corporate account may invite only users within its own organization. A person you invite can se e consumption data for that Space and can operate the Devices in it. You should only invite people you trust, and you should set the shortest validity period that meets your needs. You may revoke an invitation at any time, and access ends automatically whe n the validity period expires.
10.2 Your confirmation. Where you invite someone, you confirm you are entitled to give them access to the data and Devices concerned. You remain responsible under the Agreement for everything done in your account, including by people you invite.
10.3 App permissions. Before an App can operate, you choose which permissions to grant it. The permissions, and what each of them discloses or allows, are:
Permission What it allows the App to do, and what it discloses Device energy data Read Telemetry from your Devices: consumption, power, voltage, current, and the times your Devices are in use. This discloses patterns that can reveal when your premises are occupied. Control device Switch your Devices on and off and create or change schedules. This lets a third party operate mains-connected equipment in your premises. Dispatch with comfort window settings Issue Dispatches to your enrolled Devices and read and apply your Comfort Window settings. This lets a third party vary the operation of your equipment as part of a flexibility programme.
10.4 Grant only what is needed. Grant only the permissions the App needs. You can review and withdraw permissions at any time. Where you grant Control device or Dispatch with comfort window settings, the App Developer determines what happens to your Devices. Subject to clause 18.1 of the Core Platform Terms, we are not liable for what an App does with a permission you granted it.
10.5 Our review of Apps. We review Apps before publication against a checklist covering the App’s description, pricing, endpoints and security. That review is a screening step. It is not an endorsement, a security audit, a certification, or a warranty that the App is fit for your purposes or will work as described.
11. Corporate accounts, staff and guests
11.1 The account holder. A corporate account is held by the organization, not by the individual who registered it. The organization is responsible for all activity in its account, including activity by its staff, unit admins and guests. The organization controls who has access to what, and at what level, and we act on the instructions given through the account.
11.2 Data attributable to individuals. Consumption data from Devices assigned to a Unit or Space may be attributable to an identifiable individual, and may reveal that individual’s presence, absence and patterns of activity.
11.3 Roles of the parties. As between the organization and us, the organization is the data controller in respect of data about its staff and guests, and we process that data on its instructions.
11.4 The organization’s obligations. Where the organization enrols Devices located in an individual’s home or personal space or assigns Devices in a way that makes data attributable to an individual member of staff, the organization warrants that it has a lawful basis under the NDPA for doing so, has given the individual the notice that Act requires, and will handle the data in accordance with it. The organization indemnifies us against claims by its staff or guests arising from a breach of clause E.4 of Schedule E.
11.5 Requests from staff and guests. A member of staff or guest who wishes to exercise rights in relation to data held in a corporate account should raise the request with the organization. Where such a request is made to us directly, we will refer it to the organization.
11.6 End of access. The organization may revoke access at any time, and access ends automatically when the validity period expires. Termination of the corporate account ends the access of all its staff and guests. Devices, Wallet balances and orders belong to the organization and not to individual users.
12. Security
12.1 Our measures. We protect your personal data through access controls, the logging of staff access, confidentiality obligations on our staff, and the authentication measures described in this clause 12.
12.2 Authentication. The Platform supports two-factor authentication by email and by authenticator application, and we strongly recommend that you enable it. We may require you to re-authenticate, reset your password, or complete additional verification where we consider it necessary to protect your account.
12.3 Your responsibilities. You are responsible for everything done through your account. Keep your password confidential and do not let anyone else use your credentials. Sharing credentials is prohibited; Share Access is the only permitted way to give another person access. Tell us immediately if you suspect your account has been accessed without your authority.
12.4 Payment security. Payment is processed through our payment provider’s gateway. We do not receive or store your full card details.
12.5 Firmware updates. We and our infrastructure provider may update Device and Hub firmware automatically. Updates may be necessary for security, compliance or continued operation, and you must not prevent, delay or tamper with an update.
12.6 Breaches. Where a breach of security affects your personal data, we will notify you and the Nigeria Data Protection Commission to the extent the NDPA requires.
12.7 No absolute guarantee. We provide the Platform with reasonable skill and care. We do not guarantee that the Platform will be uninterrupted or error-free, and the service depends on matters we do not control, including your internet connection, mains electricity supply, your Hub and Devices, and third-party infrastructure.
13. How long we keep personal data
13.1 General principle. We keep personal data for no longer than is necessary to achieve the lawful bases for which it is collected under the Agreement.
13.2 Identity documents. We retain identity documents for not longer than it is necessary to achieve the lawful bases for which they are collected under the Agreement, and we handle them in accordance with this Privacy Policy and the NDPA.
13.3 Records we are required to retain. We retain personal data for longer where we are required to retain it, including transaction and payment records, identity verification records, and records relating to a dispute or investigation.
13.4 Records of acceptance. We retain the record of your acceptance of each version of the Agreement, including the version accepted and the date and time of acceptance. Every version you have accepted remains available to you.
13.5 Suspension for non-payment. We will not delete your data or your Wallet balance during a suspension for non-payment.
14. Deleting your account
14.1 How to delete. You may delete your account from within the Platform. Deleting your account ends your Plan, and clause 6.10 of the Core Platform Terms applies to fees already paid.
14.2 What we do with your data. We will delete or anonymise your personal data except where we are required to retain it, including the records described in clause 13.3.
14.3 Other effects. On deletion of your account your right to use the Platform ends, your Devices will no longer be controllable or monitorable through the Platform, any flexibility enrolment ends subject to Schedule B, and active App subscriptions end. Orders already placed on the Marketplace are unaffected and remain governed by Schedule C, and we retain the records relating to them.
15. Your rights
15.1 Rights under the NDPA. You have the right to:
(a) be informed of how we process your personal data, which this Privacy Policy is intended to do;
(b) request access to the personal data we hold about you;
(c) request the correction of personal data that is inaccurate, out of date or incomplete; you must in any event give us accurate, current and complete information and keep it up to date;
(d) request the deletion of your personal data, including by deleting your account under clause 14;
(e) object to processing, or request that it be restricted, in the circumstances in which the NDPA allows;
(f) withdraw a consent you have given, as described in clause 5.3;
(g) request that your personal data be provided to you, or transmitted to another controller, in the circumstances in which the NDPA allows; and
(h) lodge a complaint with the Nigeria Data Protection Commission.
15.2 How to exercise a right. Raise a support ticket through the in-app ticketing system or contact us using the email and phone details published in the Platform. We may need to verify your identity before acting on a request, and we may ask for additional or updated documents for that purpose.
15.3 Limits on these rights. Some of these rights are qualified. We may be unable to delete, restrict or stop processing personal data that we are required to retain, or that we need in order to establish, exercise or defend a legal claim.
15.4 Other rights unaffected. These rights are in addition to, and do not affect, your rights under clause 20 of the Core Platform Terms or your right to complain in relation to electricity matters to the Nigerian Electricity Regulatory Commission.
16. Age
16.1 Adults only. OhmFlex is not intended for children. By accepting the Agreement, you confirm that you are at least 18 years old and have the legal capacity to enter into a binding contract. We do not knowingly collect personal data from anyone under 18.
17. Changes to this Privacy Policy
17.1 Material changes. We may change this Privacy Policy. Where a change is material, we will give you not less than 30 days’ notice by email and on the Platform, and we will ask you to accept the new version before you continue to use the affected features.
17.2 Non-material changes. Non-material changes, including corrections, clarifications, and changes required by law with immediate effect, take effect when published.
17.3 If you do not accept a change. If you do not accept a material change you may terminate under clause 19.1 of the Core Platform Terms before it takes effect.
17.4 Version history. Every version of this Privacy Policy you have accepted remains available to you in Documents and Agreements, together with the version accepted and the date and time of your acceptance.
18. Contacting us, and complaints
18.1 How to reach us. You can raise a privacy matter with us through the in-app ticketing system, the help centre, or the email and phone details published in the Platform.
18.2 Complaints to us. If you are unhappy with how we have handled a privacy matter, escalate it through the ticketing system or write to us. We will acknowledge within 5 business days.
18.3 Complaints to the regulator. You may lodge a complaint with the Nigeria Data Protection Commission at any time. Nothing in this Privacy Policy affects that right.
19. Governing law and disputes
19.1 Governing law. This Privacy Policy is governed by the laws of the Federal Republic of Nigeria, and in particular by the NDPA.
19.2 Disputes. Clause 22 of the Core Platform Terms applies to any dispute arising in connection with this Privacy Policy.