Privacy Policy

Last Updated: May 13, 2026

1. Introduction & NDPR Compliance

Lightandra Technology ("we," "our," or "us") respects your privacy. This policy explains how we collect, use, and safeguard your data when you use the Epass platform. We are committed to complying with the Nigeria Data Protection Regulation (NDPR) and ensuring your data is handled securely.

2. Controller vs. Processor Status

It is important to understand our role:
Data Controller: The Estate Administration using Epass is the Data Controller. They decide why and how resident and visitor data is collected.
Data Processor: Lightandra Technology (Epass) is the Data Processor. We provide the secure database and software infrastructure to store and process this data exclusively on behalf of the Estate Administration.

3. Data We Collect

To provide our services, the platform processes the following data:
Estate Admins: Names, email addresses, phone numbers, and estate branding details. Billing information is processed directly via Flutterwave.
Residents: Names, phone numbers, email addresses, residential unit numbers, and encrypted account passwords.
Visitors: Names, vehicle license plates (if recorded by security), entry and exit timestamps, and generated access codes.
Transport & Staff: Driver names, shuttle routes, and live location data (if shuttle tracking is enabled).

4. How We Use the Data

We do not sell, rent, or trade your personal data to third-party marketers. Data is used strictly to:
- Authenticate users and provide role-based dashboard access.
- Generate automated visitor passes and maintain security logs.
- Send transactional emails (e.g., subscription invoices, payment receipts) and broadcast alerts to residents.
- Prevent fraud and enforce our Terms of Service.

5. Data Security

We implement strict technical measures to protect your data. All user passwords are cryptographically hashed in our database. We utilize secure hosting environments, SSL/TLS encryption for data in transit, and strict database query parameterization to prevent unauthorized access or SQL injection attacks.

6. Data Retention and Deletion

If an Estate's subscription expires, their data is locked but retained in our secure database to allow for seamless reactivation upon renewal.
Resident Rights: If you are a Resident and wish to have your data permanently deleted from Epass, you must contact your Estate Administrator directly, as they legally control your community's directory. If an Estate Admin wishes to permanently delete their entire workspace and all associated data from Lightandra Technology's servers, they may submit a formal request to our support team.

7. Third-Party Services

Epass utilizes carefully selected third-party services to function effectively, including Flutterwave (for payment processing) and automated email/SMTP providers (for sending receipts and alerts). These providers have their own strict privacy policies and only process data necessary to perform their specific functions.


By continuing to use Epass, you acknowledge that you have read and understood this Privacy Policy.