ComplianceNG ("we", "us", "our") facilitates business, travel, vehicle, and personal compliance services in Nigeria, and operates an agent referral program. This policy explains how we collect, use, store, and protect personal data under the Nigeria Data Protection Act, 2023 (NDPA) and its implementing General Application and Implementation Directive (GAID).
Under Section 25 of the NDPA, we rely on one or more of the following depending on the situation:
We don't sell personal data. We share it only with the vendors that help us operate the service, each acting under their own data processing terms:
| Vendor | What they process | Purpose |
|---|---|---|
| Airtable | Client and agent records, applications, payments | Our primary database |
| Vercel | All data in transit through our site and API | Website and server hosting |
| Paystack | Payment card details, transaction data | Payment processing — we never see or store your card details |
| Supabase | Client and agent records (planned migration from Airtable) | Database and authentication infrastructure |
Referral partner agents see only the name, phone number, and services relevant to applications they personally referred.
Some of the vendors above operate infrastructure outside Nigeria. The NDPA requires that when we transfer personal data outside the country, the recipient must provide a level of protection adequate to what the NDPA guarantees within Nigeria — through a qualifying law, contractual safeguard, binding corporate rules, or certification mechanism.
We maintain an internal register documenting each vendor, what data is transferred, where, and the safeguard that applies, reviewed as part of our compliance process. If you'd like more detail on a specific transfer, contact us using the details in Section 12.
We retain application and payment records for as long as needed to provide the service and meet our tax and legal obligations, and agent records for the duration of the agent relationship plus a reasonable period afterward for financial reconciliation. You can request deletion at any time — see Section 9 — and we'll act on it unless we're legally required to retain specific records.
We apply technical and organisational measures proportionate to the sensitivity of the data involved, including: credentials and database access restricted to server-side infrastructure and never exposed in client-facing code, authenticated and rate-limited access to personal data, server-side verification of payments before any financial record is created, and field-level access controls so agents can only view or edit their own records.
Under the NDPA, you have the right to:
Our services are intended for individuals who can lawfully enter into agreements in Nigeria. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
We may update this policy as our services or legal obligations change. Material changes will be reflected in the "Last updated" date at the top of this page, and where appropriate, we'll take further steps to bring changes to your attention.
ComplianceNG
WhatsApp: +234 704 738 1886
For data rights requests, please use our Data Rights Request page so we can verify and track your request properly.