Acceptable Use Policy
National Digital Alphanumeric Postcode System (NDAPS)
1. Purpose and scope
1.1 This Acceptable Use Policy (AUP) establishes the rules and requirements governing access to and use of the National Digital Alphanumeric Postcode System (NDAPS), including its websites, applications, portals, application programming interfaces (APIs), databases, developer services and related digital services.
1.2 NDAPS provides the postcode and location-reference framework that enables organizations to identify the appropriate postal/geographic area associated with a location and use that information to support service delivery.
1.3 This AUP applies to all persons and organizations accessing or using NDAPS, including:
- individuals;
- developers;
- enterprise customers;
- logistics and delivery organizations;
- government agencies;
- public institutions;
- commercial organizations;
- research and academic institutions; and
- other authorized users.
1.4 By accessing or using NDAPS, you agree to comply with this AUP and the applicable NDAPS Terms and Conditions of Use.
1.5 This AUP should be read together with:
- the NDAPS Terms and Conditions of Use;
- the NDAPS Privacy Policy;
- the NDAPS Cookie Policy;
- applicable API terms;
- enterprise agreements;
- Data Processing Agreements;
- Service Level Agreements; and
- other service-specific agreements issued by NIPOST.
1.6 A violation of this AUP may result in restriction, suspension or termination of access to NDAPS and, where appropriate or required by law, referral to a relevant regulatory or law-enforcement authority.
2. Permitted uses
Subject to this AUP, applicable terms and applicable law, permitted uses of NDAPS include:
- Postcode lookup and identification.
- Postcode and location-reference services.
- Authorized use of postcode and location information to support service coverage, field operations, logistics and public-service delivery.
- Authorized integration with NDAPS APIs for postcode lookup, location referencing, service coverage and related postcode-enabled services in accordance with applicable API documentation, licensing terms, technical restrictions and data-use requirements.
- Government and public-service applications authorized by NIPOST or otherwise permitted by law, including applications that use postcode and location information to support planning, coordination and delivery of services.
- Logistics, delivery, e-commerce and other commercial applications where authorized under an applicable agreement.
- Academic and research activities conducted in compliance with applicable law and any applicable NDAPS licence or agreement.
- Postcode and location data-quality reporting and submission of corrections through authorized NDAPS channels.
- Any other use expressly authorized by NIPOST in writing.
3. Prohibited activities
Users must not use NDAPS to engage in any activity prohibited by this AUP, applicable law or the applicable NDAPS agreement.
3.1 Unlawful or harmful activities
- engage in fraud, identity theft, money laundering, terrorism financing or other unlawful activity;
- harass, threaten or unlawfully target another person;
- distribute malware, ransomware, malicious code or other harmful software;
- facilitate unlawful activity through NDAPS; or
- impersonate NIPOST, its personnel, agents, partners or another person or organization.
3.2 Unauthorized access and data misuse
- access or attempt to access accounts, systems, databases, networks or information for which they do not have authorization;
- circumvent authentication, access-control or security mechanisms;
- access, collect, extract, disclose, modify or otherwise process Personal Data through NDAPS without appropriate authorization and lawful basis;
- use Personal Data obtained through NDAPS for a purpose incompatible with the purpose for which access was authorized;
- attempt to obtain another person's Personal Data without appropriate authorization and lawful basis;
- probe, scan or test NDAPS systems for vulnerabilities except through an expressly authorized security-testing programme or with NIPOST's prior written permission.
3.3 API abuse
- exceed applicable API rate limits;
- circumvent API authentication or usage restrictions;
- share, transfer, expose or misuse API credentials except as authorized;
- systematically extract or reproduce NDAPS data beyond the scope authorized by the applicable agreement;
- retain NDAPS data beyond the period authorized by the applicable agreement or law;
- resell, sublicense, redistribute or commercially exploit NDAPS API access or data without NIPOST's prior written authorization; or
- use NDAPS APIs to create an unauthorized service that materially replicates or substitutes for NDAPS.
3.4 Intellectual property and database rights
- copy or reproduce protected NDAPS content except as expressly authorized;
- remove copyright, trademark, ownership or proprietary notices;
- use NIPOST trademarks, logos or branding without prior written authorization;
- systematically extract, reproduce or compile substantial portions of the NDAPS Database without authorization;
- create a competing or substantially similar postcode or location-reference database from NDAPS data without NIPOST's written authorization.
3.5 Network and system interference
- interfere with the operation of NDAPS;
- conduct denial-of-service or distributed denial-of-service attacks;
- introduce malicious traffic or code;
- send spam or unsolicited bulk communications through NDAPS;
- intentionally impair the availability, integrity or performance of NDAPS.
3.6 False or misleading information
- knowingly submit false or misleading registration information;
- impersonate another person or organization;
- knowingly submit fabricated postcode or location information;
- manipulate postcode or location information for fraudulent or unlawful purposes.
3.7 Reverse engineering
Users must not decompile, disassemble, reverse engineer or attempt to derive the source code, algorithms or underlying technical architecture of NDAPS except to the extent expressly permitted by applicable law.
3.8 Unauthorized mass data collection
Users must not use bots, scripts, crawlers, automated tools or other mechanisms to:
- make bulk or systematic requests beyond authorized limits;
- harvest NDAPS data;
- download or compile substantial amounts of NDAPS data;
- create an unauthorized database;
- redistribute NDAPS data without authorization;
- commercially exploit NDAPS data outside the scope of an applicable agreement.
4. User responsibilities
Users are responsible for:
- maintaining the confidentiality and security of account credentials and API credentials;
- ensuring information submitted to NDAPS is accurate, lawful and not knowingly misleading;
- using Personal Data obtained through NDAPS only for authorized purposes and in accordance with applicable data protection law;
- implementing appropriate technical and organizational safeguards where they process NDAPS data within their own systems;
- ensuring employees, contractors and other persons authorized by them comply with this AUP;
- promptly reporting suspected unauthorized access, credential compromise, security vulnerabilities or misuse;
- cooperating reasonably with NIPOST in investigating suspected violations or security incidents.
5. Monitoring and enforcement
NIPOST may collect and review technical, security and usage information reasonably necessary to:
- operate NDAPS;
- maintain security;
- detect and investigate suspected misuse;
- enforce applicable usage restrictions;
- maintain system integrity;
- comply with legal or regulatory obligations.
Monitoring shall be conducted in accordance with applicable law and the NDAPS Privacy Policy.
Where NIPOST reasonably believes that a User has violated this AUP, applicable law or an applicable agreement, NIPOST may, subject to applicable law and the circumstances of the case:
- issue a warning;
- restrict access;
- suspend or terminate an account;
- suspend or revoke API credentials;
- impose technical restrictions;
- remove unauthorized content;
- preserve relevant evidence;
- block or restrict malicious traffic;
- refer suspected unlawful conduct to appropriate authorities.
NIPOST shall exercise enforcement rights reasonably and in accordance with applicable law.
6. Reporting violations and security vulnerabilities
Suspected violations, abuse or security vulnerabilities should be reported through NIPOST's designated reporting channels.
Security email: security@nipost.gov.ng
Abuse email: abuse@nipost.gov.ng
Reports should, where available, include:
- description of the suspected violation or vulnerability;
- relevant URL, username, account identifier or API endpoint;
- date and time of relevant events;
- supporting evidence;
- contact information for follow-up.
Users should not include passwords, API secrets, authentication tokens, private keys or other sensitive credentials in ordinary email reports unless specifically requested through an approved secure channel.
7. Policy revisions
NIPOST may update this AUP from time to time. Non-material changes may take effect upon publication. Where a change materially affects Users' rights or obligations, NIPOST will provide reasonable notice through the Platform, email or another appropriate communication channel before the change takes effect, except where an immediate change is required for security, legal, regulatory or public-interest reasons.
8. Governing law
This AUP shall be governed by and interpreted in accordance with the laws of the Federal Republic of Nigeria. Nothing in this AUP limits NIPOST's right to report suspected unlawful conduct to a competent regulatory or law-enforcement authority or to pursue remedies available under applicable law.
9. Contact
Nigerian Postal Service (NIPOST)
Address: No 1 Nkwere Street, Off Mohammadu Buhari Way, Garki II, Abuja
Email: legal@nipost.gov.ng
Website: https://www.nipost.gov.ng
