
Privacy Policy & Data Governance
How His Love Foundation (H.L.F) and the SIMPER platform collect, safeguard, and responsibly process stakeholder, partner, and beneficiary data.

Accountable Impact with Uncompromising Privacy
His Love Foundation is committed to absolute transparency in Christian Social Responsibility (CSR) reporting while strictly safeguarding the confidentiality, dignity, and statutory rights of every stakeholder, volunteer, and community beneficiary.
Last Revised: September 2026 · Complies with the Nigeria Data Protection Act 2023 (NDPA) and international humanitarian data protection standards.
Data Controller Identity & Governance
His Love Foundation (H.L.F), the global Christian Social Responsibility arm of The Redeemed Christian Church of God (RCCG), acts as the primary Data Controller for personal data collected through the Sustainability Impact Management, Performance & Evaluation Reporting (SIMPER) platform.
Scope and Categories of Data Collected
Depending on how you interact with SIMPER, we collect and process the following categories of data:
- Public Visitors & Inquiries: Name, email address, phone number, and message content submitted via contact forms or newsletter subscriptions.
- Registered Stakeholders & Partners: Name, professional email address, stakeholder classification (e.g., Development Agency, UN Body, Corporate Partner, Philanthropist), organization name, and assigned administrative province.
- Reporting & Activity Data: Intervention descriptions, project locations (State, LGA, community), expenditure allocations, implementation dates, and photos documenting project completion.
- Beneficiary Data: De-identified, aggregated figures indicating counts of individuals assisted (e.g., number of meals served, medical treatments administered, scholarships awarded). We never publish identifying personal details of vulnerable beneficiaries on public dashboards without explicit consent.
- Technical & System Logs: IP address, browser type, operating system, and access timestamps captured for security monitoring, fraud prevention, and audit integrity.
Lawful Bases for Data Processing
In accordance with Section 25 of the Nigeria Data Protection Act 2023, we process personal data exclusively under the following lawful bases:
Explicit Consent
Provided by public visitors submitting contact forms, event registrations, or stakeholder signups.
Legitimate Interest
Conducting charitable monitoring, evaluation, and transparent reporting to maintain public trust and donor accountability.
Contractual Necessity
Administering partnership Memoranda of Understanding (MoUs) and donor agreements.
Legal & Regulatory Compliance
Fulfilling statutory annual audit requirements, corporate filings, and compliance with anti-financial crime laws.
Beneficiary Protection & Child Safeguarding
Protecting vulnerable individuals and children is foundational to His Love Foundation's mission:
- Anonymized Public Metrics: Beneficiary metrics published on SIMPER are aggregated and de-identified. Individual names, domestic addresses, and contact details of beneficiaries are strictly classified as confidential.
- Child Safeguarding & Media Consent: Photographs, case studies, or video footage involving minors (under 18 years of age) require prior verified written consent from a parent, legal guardian, or recognized school authority. Images are framed respectfully to preserve child dignity.
- Medical Confidentiality: Health interventions (e.g., dialysis treatments, cancer screenings, surgeries) record only clinical volumes and outcomes. Personal health records (PHR) are managed by certified medical personnel and are never stored on public reporting servers.
Security Architecture & Access Controls
SIMPER employs defense-in-depth security measures to protect data against unauthorized access, alteration, disclosure, or destruction:
- Server-Enforced Role-Based Access Control (RBAC): Access privileges are strictly governed on the server. Self-registered public accounts cannot access administrative, parish-entry, or approval endpoints.
- Cryptographic Safeguards: All data transmissions are encrypted using TLS 1.3 (HTTPS). Sensitive fields and passwords are cryptographically hashed using PBKDF2/bcrypt.
- Multi-Factor Authentication (MFA): Two-factor TOTP authentication is enforced for all administrative and data entry personnel.
- Immutable Audit Trails: Every project approval, submission, modification, and data export is logged with user identity and timestamp in an audit log.
Your Statutory Rights under NDPA 2023
Under Sections 34 through 39 of the Nigeria Data Protection Act 2023, data subjects possess enforceable rights regarding their personal information:
To exercise any of these rights, submit a written request to privacy@hislove.org. We respond to all verified requests within 30 calendar days.
Data Retention & Breach Protocol
Retention Schedules:Project activity records and aggregated impact indicators are maintained indefinitely as part of His Love Foundation's historical institutional archive. Personal contact details and unverified account requests are purged within 24 months of inactivity.
Breach Protocol: In the event of a personal data breach posing a risk to individuals, His Love Foundation will notify the Nigeria Data Protection Commission (NDPC) within 72 hours and directly alert affected data subjects with remediation advice without undue delay.
Have questions about our data practices?
Contact our Data Protection Officer or our CSR Legal Compliance team for any questions regarding this policy or your data rights.