Draft for review · Version 0.1 · Prepared 25 September 2026
Effective date: pending formal adoption. This draft explains the current application’s data handling and the proposed notice for the programme. It is not a legal opinion, a certification of compliance or permission to begin a new type of processing.
1. Who is responsible for your information
ODDRIVA LTD, Nigeria, is responsible for the purposes and means of processing personal information through Oddriva. Contact info@oddriva.app with the subject “Privacy” for a privacy question, request or complaint.
This notice covers visitors, invited account holders, analysts and authorised operators, including research submissions and private support. Oddriva remains in Funding pending status. Public onboarding, live execution and real payouts are unavailable. Identity and payout services described as future arrangements have not been activated merely because the application contains fields for provider references.
2. Information we handle
| Category | What it may include |
|---|---|
| Account and preferences | Name, email address, email-verification state, account identifiers, selected display timezone and account status. |
| Authentication and security | A protected password hash, session identifiers and expiry, IP address, browser/device information, verification or recovery records, multi-factor enrolment information and authentication events. Authenticator secrets and backup codes require protected handling; do not send them to support. |
| Research | Event and selection details, observed odds, sources, rationale, booking references, submission time, review decisions and associated screenshots. |
| Screenshot records | The processed image, a sanitised filename, file size, content hash and its relationship to the research record. |
| Support and administration | Messages, case history, relevant account references, internal review notes, reasons for decisions, role assignments and audit records. |
| Eligibility records, where a permitted review is initiated | Country, the applicable minimum-age threshold, age/ownership-check status, review outcome and an opaque evidence or provider reference. These fields do not mean an identity provider has already verified a person. |
| Future funded records | Only after activation: authorised execution and reconciliation records, cumulative results, reward calculations, statements and limited verified beneficiary/payment references. A separate collection notice will explain any additional information needed. |
We receive information from you, from your use of the service and from authorised reviewers. Future provider-supplied identity, payment or execution information will be identified when that integration is introduced. We do not currently offer a route for uploading identity documents, biometrics or raw bank-account details for provider verification.
Provide only information needed for the task. Screenshots and free-text messages can reveal more than intended. Remove unrelated names, account numbers, balances, notifications and other people’s information before submitting them.
3. How screenshots are processed
For authenticated server submissions, supported screenshots are decoded and re-encoded into a standard image format. This processing removes embedded image metadata, including EXIF, from the stored image. It does not remove personal details visible in the pixels or replace your responsibility to redact them. A content hash of the submitted file is retained for record integrity; the original file is not retained as a separate attachment by that upload flow.
Uploaded server screenshots are stored with the private research record and served through access-controlled routes. Relevant authorised reviewers may inspect them, with privileged access recorded. A screenshot is analyst-supplied evidence, not independent proof of an executed ticket or payment.
4. Purposes and proposed lawful grounds
We identify a lawful ground for each purpose instead of treating use of the website as consent to everything. The following allocation is proposed for adoption and will be checked against the final operating arrangements:
| Purpose | Proposed ground |
|---|---|
| Provide an account, respond to requested support and administer agreed research participation | Steps at your request before an agreement, or performance of the relevant agreement, where necessary. |
| Protect accounts, investigate abuse, enforce access controls and preserve an accurate decision history | Legitimate interests in a secure and accountable service, subject to a documented assessment of necessity, proportionality and your rights. |
| Meet a specific applicable recordkeeping, regulatory or disclosure requirement | The relevant legal obligation, once identified; this ground is not a general justification for collecting extra information. |
| Establish, exercise or defend a legitimate legal claim | The applicable lawful ground for that purpose, with access and retention limited to what is necessary. |
| Optional future marketing or another genuinely optional consent-based feature | A separate, specific choice that can be withdrawn. These features are not enabled by accepting programme terms. |
Identity checks, biometrics or other sensitive processing will need their own lawful-ground assessment, safeguards and notice before they begin. We do not infer that ordinary contract acceptance authorises sensitive-data processing.
If you do not provide information necessary for an account or requested function, we may be unable to provide that function. Optional information should not be required for unrelated access. Withdrawing consent affects processing based on that consent going forward; it does not invalidate lawful earlier processing or automatically remove records retained on another valid ground.
5. Who can receive information
Access within Oddriva is limited according to responsibilities, such as support, verification, risk, finance, security and audit. The system uses role controls, multi-factor checks for privileged work and access records. Other analysts do not receive access to your private account, screenshots or support case through the service.
The application is hosted on a Hostinger-provided virtual server. Hosting infrastructure necessarily processes technical information and stored service data. Hostinger SMTP has been selected for transactional email. Where configured, that service handles the address, message and delivery metadata needed for verification, recovery or an invitation. An email accepted by a sending server is not proof that it reached the recipient’s inbox.
We may disclose limited information to professional advisers or competent authorities where necessary and supported by an applicable lawful ground. Requests are assessed rather than treated as unrestricted access to the database.
The selected services for further setup are Smile ID for a hosted identity-check flow, Sportmonks for football fixture data and Monnify for payment-status information. Selection does not mean credentials have been configured, a contract or regulatory requirement has been satisfied, or personal-data processing through that service has begun. A fixture lookup is not bookmaker execution, and a payment-status connection does not itself send funds.
Before a hosted identity flow or another new transfer of personal information begins, we will provide the relevant collection and provider notices, confirm the lawful ground and required choices, assess recipient roles and safeguards, and enable only the approved scope. No bookmaker-execution provider is represented as an active partner. We do not sell personal information or use the current application to serve targeted advertising.
6. Hosting and international transfers
Hosting, email routing, technical support or a future provider can involve processing outside Nigeria. The physical hosting location, support-access countries and approved provider arrangements are being confirmed before public onboarding. We do not claim that all data stays in Nigeria or that a particular transfer safeguard has already been approved.
Where a transfer is required, Oddriva must establish the applicable transfer ground and safeguards, assess recipients and explain the arrangement in the adopted notice. You can ask for information about relevant recipients and safeguards, subject to legitimate security and confidentiality limits. A foreign server location does not remove your applicable privacy rights.
7. Cookies, local storage and the demo
Authenticated access uses necessary session and security cookies to maintain sign-in and protect account actions. Blocking or deleting them may sign you out or prevent protected functions. The current application does not include advertising pixels or third-party behavioural analytics. We will provide any required choice before introducing non-essential tracking.
The demo stores example submissions, support cases and preferences in your browser’s local storage. Demo screenshot files are stored in that browser’s IndexedDB. These demo records are not submitted to the production research database by the demo flow. The web server still receives ordinary connection information when you load the site.
Do not place real identity, financial or confidential information in the demo. People with access to your device or browser profile may be able to see its local records. Use Reset demo records in demo Settings, or clear this site’s browser data, to remove them. Clearing local demo data does not delete a separately created production account, email or server support record. The server screenshot metadata-removal process described above does not apply to an original screenshot simply saved in the local demo.
8. Security
The deployment uses HTTPS for network transport. Account protections include password hashing, protected multi-factor credentials, role-based permissions and audit records. Private data is not deliberately placed in a public offline cache.
The backup process encrypts database exports before writing the backup files. This is different from encryption of the live database or its disk; we do not claim that the live database files are encrypted at rest. Access controls, operational security, key protection and tested recovery remain necessary. No system can promise that every security incident is impossible.
If you suspect an account or privacy incident, contact info@oddriva.app promptly. We will assess the incident, act to contain it and give the notices required by applicable law. Please do not include passwords, full bank details or authentication secrets in the report.
9. How long information is kept
Records are kept for the purpose for which they are needed, taking account of account status, unresolved support or disputes, security needs and applicable recordkeeping duties. The final category-by-category retention schedule is being reviewed before public onboarding. This draft does not claim that automated deletion already occurs on a fixed timetable.
Research and decision records may need to be preserved to explain a review. If funded operations are activated, a limited historical record may also be needed to preserve loss-recovery calculations, accounting and established liabilities after an account closes. That need does not justify keeping every screenshot or free-text message indefinitely.
Deletion, restriction or anonymisation must account for legal holds, other people’s rights and records whose integrity must be preserved. Where a specific record cannot yet be deleted, we will explain the applicable reason and limit its further use. Backup copies require a controlled expiry and restore process; a record removed from active systems may remain in a protected backup until that copy expires. The adopted schedule must address those copies too.
10. Your choices and rights
Depending on the applicable law and circumstances, you may ask for information about processing, access to your personal data, correction, erasure, restriction, portability, objection to relevant processing, or withdrawal of consent. You may also raise concerns about decisions made solely by automated processing where the law provides protection.
Send a request to info@oddriva.app. No particular form is required. We may ask for proportionate information to establish that the request concerns your data, but will not routinely ask you to email a complete identity document. We will explain any lawful limitation, refusal or extension and how to challenge it.
Our proposed service target is to respond within 30 calendar days after receiving a request and the reasonable information needed to verify it, subject to any shorter applicable legal deadline. A justified extension or restriction will be explained. An account-closure request and a personal-data deletion request are related but distinct; some limited records may still require retention.
You may complain to the Nigeria Data Protection Commission through its official website or privacy breach reporting portal, without first giving up any other available remedy.
11. Automated rules and human review
The application applies rules to submission quotas, timing, input formats, access permissions and risk restrictions. These rules can reject an invalid request or prevent an unavailable action. Their principal programme effect is described in the programme terms.
The current service does not automatically verify identity, place a bookmaker ticket or send a payout. A future reward close would apply the published arithmetic to reconciled records and record the assessment for review. We do not claim that a numeric score alone proves eligibility, profitability or misconduct. Contact support to challenge incorrect data, a calculation or a decision and request an appropriate human review.
12. Age restrictions and changes to this notice
Oddriva is intended for adults who meet the approved jurisdiction’s requirements, with a minimum age of 18. It does not offer a route for a parent to authorise an underage child to participate. If we learn that information has been collected from someone who is ineligible by age, we will assess it promptly, restrict access and handle the information lawfully.
We will date each adopted version and explain material changes before new processing begins where required. A change to this notice is not a substitute for obtaining a new consent or meeting another legal requirement. Contact ODDRIVA LTD at info@oddriva.app for questions about the version that applies to you.