NC

Naijacloud

Legal

Legal/Privacy Policy

Privacy Policy

What personal data Naijacloud collects, why we hold it, where it lives, and how you get it back or get it deleted.

Effective 30 August 2026
Version 1.0
Naijacloud Technologies Ltd · RC 8842219

1. Two different kinds of data

It matters which hat we are wearing. For data about you as our customer (your name, email, billing details, support tickets, dashboard activity), Naijacloud is the data controller and this policy describes what we do with it.

For the data inside your services, databases and buckets, you are the controller and we are your processor. We handle that data only on your instructions, under the Data Processing Addendum available on request at [email protected]. This policy does not decide what happens to your end users’ data; your own privacy notice does.

2. What we collect

Category

What it includes

Account

Name, email address, password hash, organisation name, team roles, two-factor settings.

Billing

Billing contact, address, VAT/TIN where supplied, plan, invoices. Card details go directly to our payment processor, and we store only the last four digits and expiry.

Platform activity

Projects, services and environments you create, deploy history, commit SHAs and messages pulled from your connected Git provider, configuration and non-secret environment metadata.

Technical logs

IP address, user agent, timestamps, request paths and error traces from the dashboard and API. Kept for security and debugging.

Support

Ticket contents, attachments you send, and any diagnostic material you share with us.

Product analytics

Coarse first-party usage events: which pages and features are used, in aggregate. No third-party advertising trackers, ever.

We do not knowingly collect special-category data, and we ask that you keep it out of support tickets.

3. Why we use it

  • To provide the Service and your account: performance of our contract with you.
  • To bill you and keep tax records: contract and legal obligation.
  • To keep the platform secure, detect abuse and investigate incidents: legitimate interests.
  • To answer support requests and send operational notices such as incidents, maintenance and policy changes: contract and legitimate interests. You cannot opt out of operational notices while you hold an account.
  • To improve the product using aggregate usage patterns: legitimate interests.
  • To send occasional product news: consent, withdrawable in one click.

4. Where your data lives

Customer content stays in the region you choose for each service. Port Harcourt (af-west-1) data is stored and processed in Nigeria. London (eu-west-2) data is stored and processed in the United Kingdom. We do not silently move a service between regions; a region change is a rebuild you trigger.

Account, billing and support data is stored in Nigeria and replicated to the United Kingdom for redundancy. Where that involves a transfer out of Nigeria we rely on the transfer mechanisms permitted by the Nigeria Data Protection Act 2023, and on standard contractual clauses for UK and EU personal data.

5. Who else sees it

We share personal data only with the subprocessors listed on the Subprocessors page, each under a written agreement limiting them to our instructions. We also disclose data where we are legally required to, and we will tell you about a request affecting your data unless we are prohibited from doing so.

If Naijacloud is acquired or merges, data may transfer to the successor. You will be notified before that happens and before any change in how your data is used.

6. How long we keep it

Data

Retention

Account records

For the life of the account, then 30 days.

Customer content (services, databases, buckets)

Deleted 14 days after account closure or resource deletion. Backups purge within a further 30 days.

Invoices and tax records

7 years, as Nigerian law requires.

Technical and security logs

90 days, then aggregated or deleted.

Support tickets

3 years from closure.

7. Your rights

You can access, correct, export, restrict or delete your personal data, object to processing based on legitimate interests, and withdraw consent where consent is the basis. Most of this is self-service in workspace settings; for anything else write to [email protected] and we will respond within 30 days.

If you are unhappy with our response you can complain to the Nigeria Data Protection Commission, or to your local supervisory authority if you are in the UK or EU.

8. Cookies

We use a small number of first-party cookies: a session cookie to keep you signed in, a CSRF token, and a preference cookie holding your theme choice. There is no advertising or cross-site tracking on any Naijacloud property, so there is no consent banner to dismiss.

9. Changes and contact

We will post any change to this policy here, and email account owners before a material change takes effect. Our data protection contact is [email protected], Naijacloud Technologies Ltd, 14 Aba Road, Port Harcourt, Rivers State, Nigeria.

Questions about this policy?

We answer legal and privacy mail within five business days.

Email legal →

Naijacloud Technologies Ltd · 14 Aba Road, Port Harcourt, Rivers State, Nigeria. Previous versions of every policy are archived and available on request.