Privacy Policy

Last Updated: August 19, 2026

SPLURGE
PRIVACY POLICY

IMPORTANT NOTICE: This is an expanded first-draft template for legal review, not legal advice. Multi-jurisdiction data protection compliance (GDPR, UK GDPR, Nigeria's NDPA/NDPR, CCPA/CPRA, POPIA, PIPEDA, LGPD, and others) requires review by qualified local counsel, and in most of these regimes, formal registration or notification with the competent data protection authority before processing personal data at this scale, plus execution of data processing agreements with every vendor named below.


Table of Contents
1. Scope, Controller, and Roles
2. Categories of Personal Data We Process
3. How We Use Personal Data
4. Legal Bases for Processing
5. KYC, AML, and Financial Data
6. Cookies and Similar Technologies
7. Artificial Intelligence and Automated Decision-Making
8. Sharing and Disclosure of Personal Data
9. Sub-Processors and Categories of Recipients
10. International Data Transfers
11. Data Retention Schedule
12. Data Security
13. Children's Privacy
14. Your Privacy Rights by Jurisdiction
15. Marketing Communications
16. Changes to This Policy
17. Contact Us


1. Scope, Controller, and Roles
1.1 This Privacy Policy explains how [SPLURGE LEGAL ENTITY NAME] (“Splurge,” “we”), acting as data controller for account and platform data, collects, uses, discloses, and protects personal data of Listeners, Creators, Professional Users, and visitors (“you”) in connection with the Splurge mobile applications, website, and related services (the “Platform”).
1.2 This Policy is designed to align with the EU/EEA General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, Nigeria's Data Protection Act 2023 and NDPR, the California Consumer Privacy Act as amended by the CPRA, Brazil's Lei Geral de Proteção de Dados (LGPD), Canada's PIPEDA, South Africa's POPIA, the Australian Privacy Act 1988, and Singapore's Personal Data Protection Act (PDPA), among other applicable laws. Jurisdiction-specific rights are set out in Section 14.
1.3 Where Splurge processes personal data on behalf of another User (for example, contact details a Professional User uploads about a prospective collaborator), Splurge acts as a processor for that data and the uploading User is the controller, subject to a separate data processing arrangement.
1.4 Worldwide operation. The Platform is offered to Users worldwide, and this Policy applies to your personal data regardless of where you are located. Because no single national law covers every User, Splurge applies this Policy as a common baseline across all jurisdictions and layers on additional, jurisdiction-specific obligations (for example, an EU/UK representative, a Nigerian data-protection compliance officer, or a CPRA “Do Not Sell or Share” mechanism) where your local law requires something beyond that baseline. Where a right described in Section 14 is specific to one jurisdiction, we will honor an equivalent request from a User elsewhere where reasonably practicable, even if not strictly required by the law of that User's country.
2. Categories of Personal Data We Process
Category Examples Primary Source
Identity data Name, date of birth, government ID number, profile photo Provided by you
KYC/verification data ID documents, liveness-check images, verification status, source-of-funds information Provided by you / verification vendor
Contact data Email, phone number, mailing address Provided by you
Financial & wallet data Wallet balances, transaction history, payout bank details, tax IDs Generated by Platform / payment processor
Content & usage data Listening history, viewing history, uploads, playlists, likes, search queries Generated by Platform
Networking data Connections, messages, professional credentials, shared contracts/EPKs Provided by you
Device & technical data Device identifiers, IP address, browser/OS, crash logs Generated automatically
Cookies & analytics data Session identifiers, advertising identifiers, analytics events Generated automatically
Geolocation data Approximate or precise location, where enabled Provided by you / device
AI-derived data Recommendation scores, fraud-risk scores, moderation flags Generated by Platform
Support data Correspondence with customer service, call/chat transcripts Provided by you

2.1 We do not intentionally collect special-category or sensitive personal data (e.g., health, biometric, genetic, or religious data) except where strictly necessary for identity verification or fraud prevention and permitted under applicable law (for example, facial-image liveness checks during KYC), in which case a separate Biometric/Data Processing Notice will apply before such processing begins.
3. How We Use Personal Data
●To create, verify, and administer accounts, including KYC and eligibility checks;
●To provide streaming, live-streaming, professional networking, collaboration, and marketplace features;
●To process payments, wallet transactions, currency conversion, and creator payouts;
●To personalize content recommendations, search results, and marketplace matching;
●To detect, investigate, and prevent fraud, account takeover, and money laundering;
●To comply with legal, tax, sanctions-screening, and regulatory obligations;
●To communicate with you, including service, security, and transactional notices;
●To maintain the security, integrity, and availability of the Platform;
●To improve and develop the Platform, including through aggregated or de-identified analytics;
●To enforce these Terms, the Community Standards, and other incorporated policies.
4. Legal Bases for Processing
4.1 Where GDPR or UK GDPR applies, we rely on: performance of a contract with you (e.g., providing the Platform); compliance with a legal obligation (e.g., AML/KYC, tax reporting); our legitimate interests (e.g., fraud prevention, product improvement, direct marketing to existing customers), balanced against your rights and freedoms; and, where required, your consent (e.g., certain cookies, biometric verification, or marketing to prospects), which you may withdraw at any time without affecting the lawfulness of prior processing.
4.2 Where the Nigeria Data Protection Act/NDPR applies, we rely on equivalent lawful bases, including consent, contractual necessity, legal obligation, and legitimate interest, and will conduct a data protection impact assessment for processing likely to result in high risk, such as large-scale KYC or biometric verification.
5. KYC, AML, and Financial Data
5.1 Creators, Professional Users, and Users conducting wallet transactions above applicable thresholds must complete identity verification before certain features are unlocked, as described in the KYC & Identity Verification Policy.
5.2 This may involve sharing data with third-party identity-verification and payment providers, and, where legally required, screening against sanctions lists and politically-exposed-person (PEP) databases, consistent with the AML/CFT Compliance Policy.
5.3 Financial and KYC records are retained for the periods required by applicable AML/CFT record-keeping obligations (commonly five to seven years after account closure), which may exceed the retention period applied to other categories of data (see Section 11).
6. Cookies and Similar Technologies
6.1 We use strictly necessary cookies (authentication, security, load balancing), functional cookies (preferences), analytics cookies (usage measurement), and, where applicable, advertising cookies.
6.2 Where required by law, we will request your consent before placing non-essential cookies and will provide an in-app or web cookie-preference center. Further detail, including a list of cookies and their duration, is provided in our separate Cookie Policy.
7. Artificial Intelligence and Automated Decision-Making
7.1 We use automated systems for content recommendations, fraud-risk scoring, marketplace/talent matching, and content-moderation flagging.
7.2 Where an automated decision produces a legal or similarly significant effect on you (for example, an automated fraud score resulting in account suspension or wallet freeze), you have the right to request human review, to express your point of view, and to contest the decision, consistent with applicable law.
7.3 We do not use special-category personal data as an input to automated decision-making without a lawful basis permitting that use.
8. Sharing and Disclosure of Personal Data
●Payment processors and banking partners (e.g., for wallet funding, currency conversion, and payouts);
●Identity-verification and KYC/AML screening vendors;
●Cloud hosting, storage, and content-delivery infrastructure providers;
●Analytics, crash-reporting, and fraud-detection vendors;
●Other Users, to the extent you choose to share profile, portfolio, messaging, or collaboration content;
●Professional advisers (lawyers, auditors) under confidentiality obligations;
●Regulators, tax authorities, courts, or law enforcement, where legally required or to protect the rights, safety, or property of Splurge or others;
●A successor entity in the event of a merger, acquisition, reorganization, or sale of assets, subject to continued protection of your data.
8.1 We do not sell personal data for monetary consideration. Where applicable law (e.g., the CPRA) treats certain data-sharing arrangements as a “sale” or “share,” we will provide the required disclosures, an opt-out mechanism, and honor recognized opt-out signals.
9. Sub-Processors and Categories of Recipients
Category of Recipient Purpose Location (indicative)
Payment/KYC processors Payments, identity verification [To be confirmed per vendor]
Cloud hosting (e.g., AWS/GCP) Storage, compute, CDN [To be confirmed per region]
Analytics providers Product analytics, crash reporting [To be confirmed per vendor]
Communications providers Email/SMS/push notifications [To be confirmed per vendor]

9.1 A complete, current list of sub-processors will be maintained and made available on request or via a dedicated sub-processor page, consistent with GDPR Article 28 transparency expectations.
10. International Data Transfers
10.1 Where personal data is transferred outside the jurisdiction in which it was collected (for example, from the EEA/UK or Nigeria to hosting infrastructure in another country), we will rely on an appropriate transfer mechanism, such as Standard Contractual Clauses, an adequacy decision, the UK International Data Transfer Addendum, or another legally recognized safeguard, and will conduct a transfer risk assessment where required.
11. Data Retention Schedule
Data Category Indicative Retention Period Basis
Account/profile data Duration of account + [X] years Contract performance, dispute resolution
KYC/AML records 5–7 years after account closure AML/CFT legal obligation
Wallet/transaction records Per applicable financial/tax law (commonly 5+ years) Legal obligation
Content (music/video uploads) Duration of account, or per Creator Agreement Contract performance
Messages [X] months/years after last activity Contract performance, safety
Cookies/analytics data Per Cookie Policy (typically 6–24 months) Consent / legitimate interest
Support tickets [X] years after resolution Legitimate interest, legal defense

11.1 Full retention schedules by data category are set out in the separate Data Retention & Deletion Policy, which also describes secure deletion and anonymization procedures.
12. Data Security
12.1 We implement technical and organizational measures designed to protect personal data, including encryption in transit and at rest for sensitive fields, role-based access controls, multi-factor authentication for privileged and financial functions, logging and monitoring, and periodic penetration testing, as further described in the Security & Responsible Disclosure Policy.
12.2 No system is completely secure. If we become aware of a data breach affecting your personal data, we will notify you and the competent supervisory authority(ies) without undue delay as required by applicable law (for example, within 72 hours of awareness under GDPR, where feasible).
13. Children's Privacy
13.1 The Platform is not directed at children under 13, and accounts for users below the age of majority in their jurisdiction require parental or guardian consent as described in Section 3 of the Terms of Service.
13.2 We do not knowingly collect personal data from children in violation of applicable law. If we learn that we have done so without appropriate consent, we will take steps to delete such data and, where applicable, terminate the associated account.
14. Your Privacy Rights by Jurisdiction
Jurisdiction Key Rights
EEA / UK (GDPR, UK GDPR) Access, rectification, erasure, restriction, portability, objection, withdrawal of consent, right to lodge a complaint with a supervisory authority (e.g., the ICO or your member-state DPA)
Nigeria (NDPA/NDPR) Access, rectification, erasure, restriction, data portability, objection to processing, right to complain to the Nigeria Data Protection Commission
California (CCPA/CPRA) Right to know, delete, correct, opt out of sale/sharing, limit use of sensitive personal information, non-discrimination for exercising rights
Brazil (LGPD) Confirmation of processing, access, correction, anonymization/deletion, portability, information about sharing, revocation of consent
Canada (PIPEDA) Access, correction, withdrawal of consent, complaint to the Office of the Privacy Commissioner
South Africa (POPIA) Access, correction, deletion, objection to processing, complaint to the Information Regulator
Australia (Privacy Act) Access, correction, complaint to the OAIC
Singapore (PDPA) Access, correction, withdrawal of consent, complaint to the PDPC

14.1 To exercise any of these rights, contact us using the details in Section 17. We may need to verify your identity before fulfilling a request and may decline or limit a request to the extent permitted by applicable law (for example, where fulfilling a deletion request would conflict with an AML record-keeping obligation).
15. Marketing Communications
15.1 Where we send marketing communications, we will do so in accordance with applicable law (including opt-in requirements where mandated) and will provide an easy means to opt out or unsubscribe at any time; opting out of marketing does not affect transactional or service communications necessary to operate your account.
16. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Material changes will be notified through the Platform or by email prior to taking effect, and, where required by law, we will seek renewed consent.
17. Contact Us
info@splurge.ng

Be part of the next evolution of streaming and creator growth

Join the platform where creators thrive and fans make an impact.