Internal Operations Readiness
Version: v1 draft Audience: ZenWave staff only Status: Internal checklist for launch readiness
Do not publish this as user-facing legal text without review.
Legal and Compliance
- Obtain Nigerian counsel review for all public policies.
- Confirm legal entity, address, governing-law/forum language, and user-contact details.
- Confirm NDPA/NDPC registration or non-registration position.
- Confirm privacy rights workflow, breach response, DPIA needs, processor contracts, and cross-border transfer posture.
- Confirm Cybercrimes Act reporting process and incident escalation owner.
- Confirm copyright notice/counter-notice/repeat-infringer process.
Payments and Wallet
- Confirm Paystack production configuration, merchant status, webhook verification, reconciliation, refund, chargeback, and settlement workflows.
- Confirm Flutterwave fallback readiness before showing fallback claims publicly.
- Confirm ZenWave does not hold funds or issue stored value unless handled by licensed provider and reviewed.
- Keep marketplace checkout, broad escrow, and unrestricted wallet movement disabled until flags and approvals are documented.
- Define transaction limits, holds, manual review queues, and provider outage playbooks.
AML/KYC/Fraud
- Define KYC/KYB tiers for paid activity, payout, seller, event organizer, and wallet access.
- Define fraud rules for account takeover, mule behavior, fake payment proof, rapid payouts, linked accounts, high-risk devices, and sanctions concerns.
- Define escalation paths to provider, bank, NFIU/legal counsel, EFCC/police/ngCERT where appropriate.
- Train staff not to disclose internal risk rules that would aid evasion.
Trust and Safety
- Train staff on safety reports, dangerous users, harassment, doxxing, child safety, extortion, and emergency requests.
- Define safety-session data access controls and retention.
- Define appeals and user-notice templates for restrictions.
Support and Consumer Protection
- Publish clear refund and dispute support paths.
- Avoid blanket "no refund" messaging.
- Track duplicate charges, failed services, cancelled events, unauthorized payments, and provider errors.
- Maintain evidence collection templates and response SLAs.
Security
- Keep Termii and payment provider secrets backend-only.
- Verify webhook signatures.
- Review staff access controls and audit logs.
- Confirm incident-response runbook, breach-notification workflow, and security contact.
Product Launch Gate
Before public launch, record sign-offs from product, engineering, legal, compliance, payments/finance, support, trust and safety, and security.