DEAN
Features Pricing Contact
Sign in Get started
Features Pricing Contact
Sign in Get started

Dean-Studios Limited

Privacy Policy

Last updated: 9 May 2026

This Privacy Policy ("Policy") is issued by Dean-Studios Limited ("Dean," "we," "us," or "our") and sets forth the formal legal framework governing the collection, use, processing, storage, transfer, retention, protection, and disposal of Personal Data in connection with the operation of Dean's digital scheduling, booking, communication, and ancillary technology-driven service platform ("Services").

This Policy is promulgated pursuant to the Nigeria Data Protection Act, 2023 ("NDPA 2023"), and is intended to satisfy Dean's statutory obligations, including transparency, accountability, lawfulness, data-subject rights, and implementation of adequate technical and organisational safeguards.

By accessing or using our Services, you formally acknowledge that you have read, understood, and agree to be bound by the terms and data-processing practices contained herein.

If you do not agree, you are required to immediately discontinue use of the Services.

1. Definitions and Interpretation

For clarity and to avoid ambiguity, the following expressions shall bear the meanings assigned below:

1.1 "Personal Data"

Any information relating to an identified or identifiable natural person, including but not limited to: names, contact details, financial information, device identifiers, booking records, authentication credentials, identifiers used in messaging channels (including WhatsApp), and any data defined as personal under the NDPA 2023.

1.2 "High-Impact Personal Data"

Personal Data whose compromise may result in significant harm, including but not limited to: financial records, health-related information, identity documents, biometric identifiers, and any data classified as sensitive under the NDPA 2023.

1.3 "Processing"

Any operation or set of operations performed on Personal Data, whether or not automated, including collection, storage, retrieval, transmission, dissemination, structuring, or destruction.

1.4 "Data Subject"

Any natural person whose Personal Data is processed by Dean.

1.5 "Data Controller"

Dean, or, where applicable, an independent business customer using Dean's Services to operate its own WhatsApp presence, as described in Section 10.4.

1.6 "Data Processor"

A third party acting solely on Dean's documented instructions and not determining independently the purposes or means of processing or, where Dean acts on behalf of a business customer, Dean as processor to that customer where applicable.

1.7 "Applicable Law"

The NDPA 2023, all regulations, guidelines, decisions, and circulars issued by the NDPC, and any other laws governing data protection, cybersecurity, and digital transactions in Nigeria and, where relevant, the jurisdictions in which Dean's subprocessors operate.

These definitions reflect best practices in policy drafting and are aligned with international standards and statutory interpretation provisions.

2. Scope and Applicability

This Policy applies to all Processing of Personal Data undertaken by Dean in relation to:

  • Users booking services through the platform;
  • Service providers registered on the platform;
  • Individuals interacting via WhatsApp, including WhatsApp Business Platform (Cloud API), or other integrated channels;
  • Visitors engaging with the website or mobile interfaces; and
  • Persons whose Personal Data is transmitted through Dean's APIs or digital tools.

This Policy applies irrespective of platform (web, mobile, API), mode of transmission, or geographic location of the Data Subject.

3. Categories of Personal Data Processed

Pursuant to Sections 24, 26, and 27 of the NDPA 2023, Dean hereby discloses the categories of Personal Data processed:

3.1 Data Provided Directly by Data Subjects

This includes:

  • Full name and business name
  • Email address and telephone number
  • Securely stored login credentials
  • Payment and settlement data (bank accounts, wallet details)
  • Booking preferences, service descriptions, pricing and schedules
  • Communications transmitted via WhatsApp or external channels
  • Identification documents for verification or compliance purposes

3.2 Data Automatically Collected by Dean

Including, without limitation:

  • IP address and geolocation metadata
  • Device specifications (device ID, IMEI, OS, browser type)
  • Access timestamps and session logs
  • Usage analytics (clickstream, page views, feature utilisation)
  • Transaction logs, audit histories, and diagnostic reports

3.3 Data Obtained from Integrated Processors and Messaging Infrastructure

Dean may obtain or process Personal Data from:

  • Payment processing partners
  • Meta Platforms, Inc. / Meta Platforms Ireland Limited and affiliates ("Meta"), in connection with the WhatsApp Business Platform, including technical identifiers (such as WhatsApp Business Account IDs, phone number IDs, display numbers), message content, media-related metadata, delivery or read receipts, and timestamps, where necessary to deliver messaging features connected to the Services
  • Verification vendors (for fraud prevention or compliance)

Such third parties act under applicable contractual and statutory frameworks; Meta's WhatsApp Business and privacy terms apply alongside this Policy where WhatsApp is used.

3.4 WhatsApp Business Platform Connection Data (Organizational Customers)

Where an organizational customer connects WhatsApp through Dean (including via Embedded Signup or equivalent flows), Dean may process:

  • OAuth or authorisation artefacts necessary to obtain access subject to Meta's rules
  • Encrypted stored credentials required for Dean to call Meta APIs on the customer's behalf (for example, encrypted access tokens)
  • Associated Meta business and asset identifiers (e.g. WABA IDs, phone number IDs)

4. Legal Basis for Processing Personal Data

Dean processes Personal Data strictly in accordance with Sections 25–30 of the NDPA 2023:

4.1 Performance of a Contract

Processing necessary to provide the Services, including: scheduling, booking management, account operation, notifications, payment settlement, and WhatsApp-integrated messaging operations requested by organizational customers or necessary to honour bookings.

4.2 Consent

Processing undertaken only upon the Data Subject's explicit or implied consent, such as activation of WhatsApp notifications, marketing preferences, or connection of WhatsApp Business assets through flows presented in the product.

4.3 Compliance with Legal Obligations

Processing required under applicable Nigerian laws, including financial reporting, anti-fraud regulations, NDPC directives, or law-enforcement requests.

4.4 Legitimate Interests

Processing necessary for operational security and fraud detection, enhancing user experience, maintaining system performance and reliability, product development and internal analytics, and delivering reliable messaging integrations, subject to balancing tests required under Applicable Law.

5. Purposes for Which Personal Data Is Processed

Dean processes Personal Data for the following purposes:

5.1 Provision of Core Services

To enable bookings, scheduling, confirmations, reminders, account setup, authentication, payment execution, and—where enabled—to send and receive WhatsApp messages on behalf of organizational customers in connection with those Services.

5.2 Security and Fraud Prevention

To verify identity, prevent fraudulent activities, ensure transaction integrity, and monitor suspicious patterns.

5.3 Customer Service and Support

To respond to inquiries, troubleshoot issues, and provide assistance.

5.4 Platform Optimisation

To conduct analytics, improve product performance, assess user trends, and enhance operational efficiency.

5.5 Compliance and Enforcement

To enforce platform terms, investigate suspicious conduct, and comply with statutory obligations.

5.6 Messaging Delivery and Integrity

To verify webhook authenticity, deduplicate events, route traffic to the correct organizational customer, maintain conversation-related metadata where applicable, and support automation or AI-assisted responses only where configured by Dean or the customer in line with product functionality.

These purposes constitute lawful and proportionate processing under the NDPA, subject to Applicable Law.

6. Cross-Border Transfer of Personal Data

Where Processing requires the storage or transmission of Personal Data to jurisdictions outside the Federal Republic of Nigeria, Dean shall ensure strict compliance with Sections 41–44 of the NDPA 2023, including:

  • Conducting transfer impact assessments where required
  • Implementing contractually binding data transfer agreements
  • Ensuring that the receiving jurisdiction affords adequate data-protection safeguards or implementing compensatory measures required under Applicable Law
  • Encrypting Personal Data in transit and applying appropriate safeguards at rest
  • Applying the principle of minimality for all outbound data flows

Use of the Services constitutes acknowledgement that cross-border transfers may be necessary for technical operation of global infrastructure (including Meta/WhatsApp infrastructure, cloud hosting, queue/workflow providers, and international payment processors).

7. Data Retention

Pursuant to Section 24 of the NDPA 2023, Dean shall retain Personal Data only for the period strictly necessary for the lawful purposes for which it is processed.

General Principle

Dean retains Personal Data for up to two (2) years from the date of last interaction or account activity unless a shorter or longer period is required for a specific processing purpose, legal obligation, or dispute resolution.

WhatsApp-related Records

Message-related logs, webhook processing artefacts, and message content (if stored) may be retained for periods tied to service delivery, troubleshooting, security, and legal claims, and may differ from general account retention where technically necessary. Organizational customers should treat WhatsApp thread content as potentially retained for at least the duration required to operate the connected Services, subject to contractual arrangements and Applicable Law.

Upon expiration of the applicable retention period:

  • Personal Data shall be securely deleted, anonymised, or irreversibly de-identified where feasible;
  • Financial and transaction records may be retained longer where required by law.

8. Security Safeguards

Pursuant to Section 28 of the NDPA 2023, Dean shall implement and maintain appropriate technical and organisational measures proportionate to the nature, scope, context, and purposes of the processing, including risks to Data Subjects.

8.1 Technical Safeguards

Including encryption of Personal Data at rest and in transit where appropriate; secure architecture; access controls; monitoring and logging; webhook integrity verification; and protective tooling proportionate to Dean's environment.

8.2 Organisational Safeguards

Including access minimisation, confidentiality obligations, training, audits, and vendor due diligence.

8.3 High-Impact Personal Data

Heightened controls including restricted access and enhanced monitoring.

9. Data Breach Management and Limitation of Liability

9.1 Breach Response Protocol

Dean shall implement its Data Breach Response Framework consistent with Section 39 of the NDPA 2023, including containment, assessment, documentation, notifications where required, and remediation.

9.2 Limitation of Liability

To the maximum extent permitted by law, Dean's liability is bounded as stated in Dean's Terms of Service and Applicable Law. Dean is not liable for incidents arising solely from customer misconfiguration, compromised Meta accounts, weak credentials, end-user devices, or third-party networks outside Dean's reasonable control, except where prohibited by law.

10. WhatsApp Business Platform, Embedded Signup, and Messaging

This Section supplements earlier references to WhatsApp and replaces any inconsistent statement that Dean never stores or processes WhatsApp conversation content.

10.1 Consumer-facing Notifications (where offered separately)

Where a Data Subject opts to receive transactional or reminder notifications via WhatsApp without connecting an organizational WhatsApp Business asset through Dean, Dean may process routing identifiers, delivery metadata, and message content strictly necessary to send those notifications. Processing scope depends on the feature enabled.

10.2 Organizational Connection via Embedded Signup / Cloud API

Where an organizational customer connects WhatsApp through Dean:

  • Dean facilitates authorisation with Meta and stores technical integration data, including encrypted tokens and identifiers (e.g. WABA IDs, phone number IDs).
  • Dean receives webhooks and API payloads from Meta for connected numbers which may include message bodies, sender/recipient identifiers, timestamps, statuses, and related metadata.
  • Dean processes such data to route messages to the correct organization, enable scheduling and customer communications, maintain service reliability, prevent abuse, and support optional automation or AI-assisted workflows offered as part of or alongside the Services.

Accordingly, Dean may process—and where technically necessary for the Services, store—WhatsApp message content and associated metadata, subject to this Policy, organisational measures, and contracts with customers.

10.3 Relationship Between Organizational Customers and Their WhatsApp Users

When individuals message a business's WhatsApp number connected through Dean, the business may act as an independent controller for certain processing vis-à-vis its customers, while Dean processes data to deliver the integration as described in agreements with that business and Applicable Law. Individuals should also review the business's privacy notice.

10.4 Meta as Infrastructure Provider

WhatsApp is operated by Meta. Meta's terms, policies, and technical controls apply to WhatsApp accounts and infrastructure. Dean does not control Meta's systems. Refer to the WhatsApp Business Terms and Meta Privacy Policy / Business Tools disclosures for further information.

10.5 Disconnecting

Organizational customers may disconnect integrations through product controls where available and/or through Meta/WhatsApp account settings as Meta permits. Residual retention may apply as described in Section 7.

11. Sub-processors

Dean engages sub-processors to operate the Services. These may include hosting providers, database providers, workflow or queue providers, communications infrastructure, analytics, security vendors, artificial intelligence / agent runtime providers where used, and Meta for WhatsApp delivery where organizational customers connect WhatsApp.

Dean requires subprocessors to implement appropriate safeguards by contract where required under Applicable Law. A current subprocessor list may be published separately or provided upon request where NDPA 2023 requires transparency.

12. Data-Subject Rights

Pursuant to Sections 34–38 of the NDPA 2023, every natural person whose Personal Data is processed ("Data Subject") shall enjoy and may exercise the following enforceable rights in relation to their Personal Data:

1. Right of Access

The Data Subject is entitled to obtain confirmation from the Data Controller as to whether Personal Data concerning them is being processed and, where such processing is occurring, to access such data together with all statutorily-mandated information relating to the nature, scope, purpose, categories, and recipients of the processing activities.

2. Right to Rectification

The Data Subject has the right to request the correction or amendment of any Personal Data that is inaccurate, misleading, incomplete, or outdated, and the Data Controller shall affect such rectification within the period prescribed under the NDPA 2023.

3. Right to Erasure ("Right to be Forgotten")

The Data Subject may request the deletion or removal of their Personal Data where the data is no longer necessary for the purposes for which it was collected, where consent has been withdrawn, or where the processing is unlawful or otherwise contrary to the NDPA 2023 or any applicable regulation.

4. Right to Data Portability

The Data Subject is entitled to receive their Personal Data in a structured, commonly used, and machine-readable format and may transmit such data to another Data Controller without hindrance, where processing is based on consent or contractual necessity.

5. Right to Object to Processing

The Data Subject may, at any time and on grounds relating to their particular situation, object to the processing of their Personal Data, including processing carried out on the basis of legitimate interests, direct marketing, or automated decision-making.

6. Right to Restrict Processing

The Data Subject has the right to request the temporary or permanent restriction of processing where the accuracy of the data is contested, where processing is unlawful, where the Data Controller no longer requires the data for its original purpose, or where the Data Subject has objected to processing pending verification.

7. Right to Withdraw Consent

Where processing is based on consent, the Data Subject may withdraw such consent at any time without affecting the lawfulness of processing carried out prior to the withdrawal.

8. Right to Lodge Complaints with the Nigeria Data Protection Commission ("NDPC")

The Data Subject is entitled to file a complaint with the NDPC where they believe that the processing of their Personal Data infringes the NDPA 2023, any Regulation, or any applicable directive issued by the Commission.

Requests may be directed to contact@deanscheduling.com. Dean shall respond within the statutory period.

WhatsApp-specific Requests: Where Dean acts strictly as a processor for an organizational customer, Dean may refer certain requests to that customer where permitted by law.

13. Third-Party Links

External sites linked from Dean operate under their own policies. Dean disclaims responsibility for their practices.

14. Children's Data

Dean's Services are not intended for individuals under 18 years of age. Dean does not knowingly collect Personal Data from minors. Any such data inadvertently collected shall be deleted upon discovery.

15. Amendments to This Policy

Dean may amend this Policy. Revised versions take effect upon publication unless stated otherwise. Continued use may constitute acceptance where permitted by law.

16. Contact Details

Dean-Studios Limited

Email: contact@deanscheduling.com

Questions about this policy? Email contact@deanscheduling.com

Legal

  • Cookie preferences
  • Privacy policy
  • Terms of use
  • Refund policy

Resources

  • LinkedIn
  • Instagram
  • X


DEAN

©2025 Dean Technologies. All rights reserved.

  • Cookie preferences
  • Privacy policy
  • Terms of service
  • Refund policy