Last updated: October 2026
01 / DATA WE COLLECT
Information We Collect
We collect only what is necessary to deliver our services and respond to inquiries:
- Contact form submissions: Name, email, project description, company name (optional), build type selection, reference links
- Project communications: Email threads, meeting notes, requirements documents, credentials shared for project access
- Analytics: Anonymous, aggregate usage data via privacy-respecting tools (no cookies, no personal identifiers)
- Technical data: IP address, browser type, device type (for security and abuse prevention only)
02 / HOW WE USE YOUR DATA
Purpose of Processing
- Respond to inquiries and prepare project proposals
- Deliver contracted services (development, design, strategy)
- Send project updates, invoices, and service-related communications
- Maintain security and prevent fraud/abuse
- Comply with legal and regulatory obligations
We do not use your data for advertising, profiling, or automated decision-making.
03 / DATA SHARING
Third-Party Disclosure
We do not sell your personal data. We share data only in these limited circumstances:
- Subcontractors: Vetted partners bound by written confidentiality agreements, solely for service delivery
- Legal obligations: When required by law, court order, or government request
- Payment processors: Stripe, bank transfer details (for billing only)
- Business transfers: In a merger/acquisition, with notice and continued privacy protection
04 / DATA RETENTION
How Long We Keep Data
- Project data: Duration of engagement + 2 years for support/warranty
- Contact inquiries (no engagement): 12 months
- Financial records: 7 years (tax compliance)
- Security logs: 90 days
You may request deletion at any time, subject to legal retention requirements.
05 / SECURITY
Data Protection Measures
- TLS 1.2+ encryption for all web traffic
- Encrypted storage for credentials, project data, and communications
- Access controlled on strict need-to-know basis within the team
- Regular security reviews and dependency audits
- Incident response plan with 72-hour breach notification
06 / YOUR RIGHTS
Data Subject Rights
You may exercise the following rights at any time by contacting privacy@nexvori.com:
- Access: Receive a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion (where not legally required to retain)
- Portability: Receive data in a structured, machine-readable format
- Objection: Opt out of non-essential communications
- Restriction: Limit processing in certain circumstances
We respond to all requests within 30 days.
07 / INTERNATIONAL TRANSFERS
Cross-Border Processing
Our distributed team operates across Nigeria, the United Kingdom, and the United States. Your data may be processed in these jurisdictions. We apply adequate safeguards including Standard Contractual Clauses and UK/US adequacy frameworks where applicable.
08 / CHANGES
Policy Updates
We may update this Policy. Material changes will be notified via email (if we have your address) and posted here with a revised "Last updated" date. Continued use of our Services constitutes acceptance.
09 / CONTACT
Data Protection Officer
For privacy inquiries, requests, or complaints: privacy@nexvori.com