RelilQ Legal
Privacy Policy
Effective date: 20 September 2026
Last updated: 20 September 2026
This Privacy Policy explains how RelilQ (“RelilQ”, “we”, “us”) processes personal information when businesses use our workforce reliability and workforce management software, and when people visit our public website at www.relilq.com.
RelilQ is a business-to-business (B2B) service used primarily by organisations in Nigeria. This Policy is written with the Nigeria Data Protection Act 2023 (NDPA) in mind and is intended to be understandable for Nigerian SMEs and international customers where they use RelilQ.
RelilQ does not sell personal data. We do not claim NDPC certification, ISO certification, SOC 2, GDPR certification, or similar seals unless separately documented.
1. Who RelilQ is and who this Policy covers
RelilQ provides software that helps businesses manage attendance, workforce reliability signals, recruitment pipelines, notifications, and related staff operations.
This Policy distinguishes:
- RelilQ — the service provider that operates the RelilQ platform.
- Customer organisations — businesses that create RelilQ workspaces and decide how RelilQ is used for their workforce.
- Owners, managers, and other authorised business users — people invited to operate a RelilQ workspace.
- Employees / workers — people whose attendance, profiles, welfare check-ins, or related records are managed in a customer workspace.
- Job applicants / candidates — people whose applications, CVs, or contact details are processed through RelilQ recruitment features.
- Website visitors — people who browse public RelilQ pages without signing in.
In many workforce scenarios, the customer organisation decides why employee or applicant information is processed (for example, to manage attendance or hiring). RelilQ processes that information to provide the service. RelilQ may also act as an independent controller for limited purposes such as operating accounts, securing the platform, billing the customer, product analytics that do not sell personal data, and complying with law. Where roles are mixed, we describe the practical arrangement rather than overstating a single label.
[LEGAL REVIEW REQUIRED] RelilQ’s registered legal entity name and registered office address are not yet published in the product codebase. Privacy requests: privacy@relilq.com.
2. Information we process
Depending on how a customer configures RelilQ, we may process categories such as:
- Account information — name, email, phone (where provided), authentication credentials handled by our identity provider, role, and workspace membership.
- Business / company information — business name, industry, address, contact details, logo, verification status, subscription and plan settings.
- Branch and workplace information — branch names, schedules, workplace clock points (including map coordinates and allowed radius where configured).
- Employee records — profile details, position, department, employment dates, emergency contacts, skills, schedules, salary fields where the customer stores them, and related operational notes.
- Attendance records — clock-in/out timestamps, attendance status, exceptions, leave, device identifiers used for shared attendance terminals, and related audit metadata.
- Location used for attendance verification — approximate or precise location captured when a person clocks in/out or when a workplace clock point is set (see Location).
- Pulse / check-in and welfare responses — responses to RelilQ check-in and welfare prompts configured for the workspace.
- Recruitment and applicant information — applications, contact details, CVs / resumes and attachments, interview/stage status, and vacancy-related records.
- Uploaded documents — staff documents such as contracts, certificates, or ID-related files the customer chooses to store.
- Verification information — verification outcomes and operational status (for example identity verification status). RelilQ is designed so sensitive identity numbers are not kept in general staff files where the product forces them null.
- Face Match information — approved reference photographs and encrypted biometric representations used for 1:1 identity verification (see Biometric section).
- Notification information — alert content, delivery preferences, device push tokens where native push is enabled.
- Billing information — subscription status, plan entitlements, Paystack customer / subscription references and webhook events. Full payment card details are handled by the payment provider, not stored as full card numbers in RelilQ.
- Audit and security logs — operational audit records and security-related diagnostics needed to protect the service.
- OAuth / recruitment inbox information — mailbox connection status, authorised mailbox identifiers, OAuth tokens, and email content RelilQ is permitted to read for recruitment intake (see Google / Gmail section).
- Ask RelilQ usage — workforce questions and answers generated from workspace data; optional AI fallback may send relevant tool results to an AI provider when configured.
We only process categories that the product actually supports. If a customer does not enable a feature (for example Face Match or Gmail connect), related processing does not occur for that workspace beyond what is needed to show setup state.
3. Biometric / Face Match information
RelilQ offers optional Face Match for 1:1 identity verification during attendance on shared devices. It compares a fresh attendance selfie with an approved reference face for the same employee. It is not marketed as workplace surveillance and is not continuous video monitoring.
As implemented today:
- An authorised business user may enrol an approved staff reference photo for Face Match.
- RelilQ derives a biometric representation (embedding) from that reference and stores the reference embedding in encrypted form.
- During verification, a fresh selfie embedding is processed server-side, compared to the reference, and designed to be ephemeral (candidate embeddings are not retained as ongoing staff profiles).
- Face Match results and similarity details are restricted to authorised owner/manager roles for audit; employees are not shown similarity scores in the product design.
- Face Match does not directly change Reliability Score, Engagement Score, Retention Risk, or Workforce Health Score.
- RelilQ does not currently perform liveness detection. Face Match compares photos; it does not prove a living person is present beyond the photo comparison itself.
- RelilQ does not claim broader facial recognition (for example searching a crowd or matching unknown faces across a database) beyond this 1:1 verification flow.
Biometric information can be sensitive personal data. Customers remain responsible for providing any legally required notices to staff and obtaining any required permissions or consent before enrolling workers for Face Match. RelilQ provides in-product notices and confirmation checkboxes for authorised enrolments; those notices do not replace the customer’s employment-law obligations.
See also the Biometric / Face Match Notice.
4. Location data
RelilQ does not continuously track employees in the background.
Location may be collected when:
- a worker clocks in or out using RelilQ attendance flows that request geolocation; or
- an authorised user sets or updates a workplace clock point with map coordinates.
Location is used to verify that a clock action is within the customer-configured workplace radius (subject to accuracy checks). Authorised workspace users may see related attendance location fields as part of attendance records. Retention follows attendance and audit retention practices described below.
5. Google / Gmail recruitment inbox access
Customers may optionally connect a Gmail or Google Workspace mailbox so RelilQ can help intake recruitment emails and CVs. This is separate from Google sign-in used only to authenticate RelilQ user accounts (when that login option is enabled).
When a customer explicitly starts Connect for a recruitment inbox, RelilQ requests these Google scopes:
openidemailhttps://www.googleapis.com/auth/gmail.readonly
With those permissions, RelilQ may receive OAuth account identifiers and read permitted mailbox content for the recruitment workflow, including identifying likely application emails, processing CV attachments, and creating or updating applicant records in the customer workspace. RelilQ does not obtain the user’s Google password.
Google Limited Use. RelilQ’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Gmail content obtained through this integration is used to provide and improve the customer’s recruitment intake features in RelilQ, not for serving ads, and not for selling personal data. Human access to that data is limited to cases needed to operate, secure, or support the service, or where required by law, or with appropriate authorisation.
Customers can Disconnect a connected inbox in RelilQ. Disconnect deletes stored OAuth access and refresh tokens from RelilQ and, for Google, attempts to revoke those tokens with Google. Customers can also revoke RelilQ in their Google Account permissions. Pausing an inbox stops sync without deleting tokens; Disconnect is the privacy control for removing mailbox access from RelilQ.
6. How we use information
We use personal information to:
- provide, maintain, and secure RelilQ;
- support workforce administration, attendance, identity verification, and records;
- compute decision-support workforce indicators (see Automated analysis);
- operate pulse/welfare check-ins, recruitment, replacement pools, and role coverage tools;
- send notifications and alerts configured by the customer;
- process subscriptions and billing;
- provide customer support;
- prevent fraud and abuse;
- meet legal obligations; and
- improve the service in ways that do not sell personal data.
7. Automated analysis and workforce indicators
RelilQ calculates indicators such as Reliability Score, Engagement Score, Retention Risk, Workforce Health Score, Role Coverage / Replacement Readiness signals, and related alerts. These are decision-support tools for authorised business users. They should not automatically be treated as definitive employment decisions.
At a high level (without exposing proprietary algorithms):
- Reliability Score — primarily attendance, punctuality, tenure, manager assessment, and conduct-related signals. Welfare/mood responses are designed not to feed Reliability Score directly.
- Engagement Score — check-in participation, welfare response patterns, and related responsiveness signals.
- Retention Risk — combines reliability/engagement patterns with attendance stress signals and certain welfare/mood confidence inputs.
- Workforce Health — a weighted blend of reliability, engagement, attendance, and retention-related points.
- Role coverage / replacement readiness — staffing levels, spare applicants, and vacancy/criticality context for roles.
Ask RelilQ may answer workforce questions from workspace data. When AI fallback is enabled and configured, limited relevant context may be sent to an AI provider to answer free-text questions.
9. Retention
We retain personal information for as long as needed to provide RelilQ to the customer, comply with law, resolve disputes, and maintain security/audit trails. Practical retention follows:
- active customer relationship and customer instructions;
- recruitment and employment-record needs determined by the customer;
- Face Match reference data until revoked or replaced by an authorised user;
- billing and webhook records needed for subscription administration; and
- backups and logs that may persist for a limited period after deletion.
Closing a business workspace in RelilQ is designed as a soft close that retains business records rather than immediately wiping all historical data. RelilQ does not currently provide a complete “delete my RelilQ identity everywhere” self-serve flow for end users.
[LEGAL REVIEW REQUIRED] Confirm customer-facing retention schedules and hard-deletion SLAs with counsel before publishing fixed day counts.
10. Security
RelilQ uses reasonable technical and organisational measures appropriate to a multi-tenant SaaS product, including authentication, role-based access, tenant-oriented data isolation and database row level security where implemented, encryption of Face Match reference embeddings, server-to-server processing for face inference, and audit logging. No method of transmission or storage is 100% secure.
11. Your privacy rights
Depending on applicable law (including the NDPA where it applies), individuals may have rights to request access, correction, deletion/erasure, restriction or objection, withdrawal of consent where consent is the basis, data portability where applicable, and to lodge a complaint with the relevant authority.
Employees and applicants often need to direct employment-record requests first to the employer / customer organisation that controls the relevant RelilQ workspace. RelilQ can assist customers with those requests where appropriate.
Contact: privacy@relilq.com.
12. Children
RelilQ is a workforce and business service. It is not directed to children. Customers must not use RelilQ to process children’s data except where lawful employment of a young person requires it and the customer has a lawful basis.
[LEGAL REVIEW REQUIRED] Confirm any minimum age statement against Nigerian child labour and NDPA guidance before asserting a numeric age threshold in marketing.
13. International transfers
RelilQ and its infrastructure/providers may process information in countries outside Nigeria (including where cloud hosting, email, payments, or AI providers operate). Where cross-border transfers occur, we rely on appropriate contractual and organisational safeguards available from those providers and our own controls.
[LEGAL REVIEW REQUIRED] Document specific transfer mechanisms preferred under NDPA for RelilQ’s production vendor stack.
15. Changes to this Policy
We may update this Policy from time to time. The “Last updated” date at the top will change when we do. Material changes may also be communicated through the product or email where appropriate.
16. Contact
Privacy and rights requests: privacy@relilq.com
General support: support@relilq.com
Related documents
- Terms of Service
- Cookie Policy
- Data Processing Addendum
- Acceptable Use Policy
- Biometric / Face Match Notice
Privacy and rights requests: privacy@relilq.com