Privacy notice
Last updated: 27 August 2026
This notice explains how Ozah Digital Limited handles personal data. It is written to align with the Nigeria Data Protection Act 2023 and the Nigeria Data Protection Commission's General Application and Implementation Directive 2025.
Who controls your data
Ozah Digital Limited is the data controller for the processing described here. We operate from Asaba, Delta State, Nigeria, and provide services across Nigeria.
Send privacy questions or rights requests to contact@ozahdigitalgroup.com. The Privacy Lead handles these requests and records the response.
What we collect
When you request a Digital Health Check
You may provide:
- Your name, business name, industry and location
- Your email address and, when supplied, your phone number
- Your website address or confirmation that the business has no website
- Your contact and channel preferences
We inspect public business information needed to prepare the report. Depending on what is available, this can include public website pages and metadata, contact details, DNS and email-domain configuration, HTTPS availability, performance and accessibility signals, technology signals, public social profiles, and Google Business Profile or Places details. We may keep the evidence, source URL and observation time needed to support a finding.
We do not sign in to private areas, bypass access controls, or collect private inbox or payment-card contents for a Health Check. Signals that cannot be verified are marked as not checked. We also record request metadata and a protected network-address fingerprint for security, fraud prevention and rate limiting.
When we discover a public business profile
Our staff can research business information that the business has made public, including its name, category, public telephone number, website, public email address, location, ratings and profile status. We use it to avoid duplicates, assess whether our services are relevant and prepare an evidenced, human-reviewed introduction. A public listing does not remove channel rules or a person's right to object. Suppression and opt-out records are checked before outbound activity.
When you become a customer
We collect the business, contact, delivery, contract, support and billing information needed to provide the service. Payment providers process card or bank details under their own controls. We receive transaction references, status and reconciliation records, not full card numbers.
Why we process it
| Purpose | Lawful basis |
|---|---|
| Run a requested Health Check and deliver its report | Consent and steps you ask us to take before a service agreement |
| Send a message through an optional channel you selected | Consent, plus the rules of that channel |
| Research public business information and assess service relevance | Legitimate interests, after necessity and rights checks |
| Prevent abuse, secure accounts and keep an audit trail | Legitimate interests and applicable legal obligations |
| Deliver and bill a paid service | Contract and legal obligations |
How long we keep it
- Private Health Check report links expire after 30 days.
- Prospect and contact records are reviewed under the workspace retention settings and are deleted, anonymised or suppressed when no longer needed.
- Security and rate-limit evidence is retained only for its stated protection period.
- Contracts, invoices, payment evidence and tax records are kept for the period required by Nigerian law and legitimate dispute needs.
A suppression record can be retained after an opt-out so that we do not contact the person again. It is used only for that purpose.
Providers and international transfers
We do not sell or rent personal data. Hosting, database, email, payments, public business data and AI providers process limited data for us when they are configured. Our sub-processor register explains their purpose and current status. Where data leaves Nigeria, we assess the transfer and use safeguards required by the NDPA.
Analytics and cookies
Essential security and session storage can operate without marketing consent. Optional analytics storage remains disabled until a visitor chooses it. We do not use advertising cookies on the public site.
Your rights
You can ask us to:
- Confirm whether we hold personal data about you and provide access to it
- Correct inaccurate or incomplete data
- Delete data where no lawful reason requires continued retention
- Restrict or object to processing, including direct marketing
- Withdraw consent without affecting earlier lawful processing
- Provide eligible data in a portable form
We acknowledge and track requests, verify identity proportionately, and aim to complete them within 30 days. A legal or security obligation can require us to retain a limited record. If so, we will explain what is retained and why.
If you are not satisfied, you may complain to the Nigeria Data Protection Commission.
How we protect data
Data is protected in transit and at rest. Sensitive contact fields are encrypted, access is role-based, tenant records are separated by database row-level security, privileged access requires stronger authentication, and security-relevant activity is audited. No control can eliminate all risk, so we also maintain incident and recovery procedures.
Changes to this notice
We review this notice on the schedule shown above and sooner when processing or law changes. The updated date records the latest review. Material changes affecting an existing consent or agreement are communicated where required.