Privacy Policy

Riskgratis Technologies Limited

Last updated: 01 August 2026

1. Introduction

1.1. This Privacy Policy explains how Riskgratis Technologies Limited (“Riskgratis”, “we”, “us” or “our”), a limited liability company incorporated in the Federal Republic of Nigeria, collects, uses, shares, retains and protects personal data. Riskgratis provides IT service management and software development services.

1.2. For the purposes of the Nigeria Data Protection Act 2023 (the “NDPA”), Riskgratis is the data controller responsible for the personal data described in this Policy. This means that we determine the purposes for which, and the manner in which, your personal data is processed.

1.3. This Policy applies to personal data we collect from and about our customers, prospective customers, website and application users, and other individuals who interact with our products, services and communications (together, “you”). It describes your rights under the NDPA and how you can exercise them.

1.4. We are committed to processing personal data in accordance with the NDPA, the regulations, directives and guidance issued by the Nigeria Data Protection Commission (the “NDPC”), and, to the extent it remains relevant on a supplementary basis, the Nigeria Data Protection Regulation 2019 (the “NDPR”). Where any provision of the NDPR is inconsistent with the NDPA, the NDPA prevails.

2. Definitions

2.1. In this Policy, the following terms have the meanings given below:

  • (a) “Data Subject” means an identified or identifiable individual to whom personal data relates;
  • (b) “Personal Data” means any information relating to a Data Subject who can be identified, directly or indirectly, by reference to that information;
  • (c) “Sensitive Personal Data” means personal data which, by its nature, carries a heightened risk to the Data Subject, including government-issued identifiers and financial information as further described in this Policy;
  • (d) “Processing” means any operation performed on Personal Data, whether or not by automated means, including collection, recording, storage, use, disclosure and erasure;
  • (e) “Data Processor” means a person or organisation that processes Personal Data on our behalf and on our instructions;
  • (f) “Lawful Basis” means one of the grounds recognised under the NDPA that permits the Processing of Personal Data.

3. Personal Data We Collect

3.1. We collect and process the following categories of Personal Data:

  • Identity and contact details — your name, email address, telephone number and postal address;
  • Account and login credentials — usernames, passwords and other authentication information used to access our products and services;
  • Payment and financial information — billing details, transaction records and payment card or bank information necessary to process payments and orders;
  • Government identifiers — where strictly necessary, government-issued identifiers such as your National Identification Number (NIN), Bank Verification Number (BVN) and passport details;
  • Device and usage data — technical information including your IP address, cookie identifiers, browser and device details, and analytics data relating to how you use our website and applications;
  • Location data — information about your approximate or precise location where you enable such features or where it is derived from your device or network.

3.2. The government identifiers described in Clause 3.1(d) and the payment and financial information described in Clause 3.1(c) are treated as Sensitive Personal Data. We collect these categories only where strictly necessary for a specific, lawful purpose, and we apply the heightened safeguards described in Clause 9. We rely on a clear Lawful Basis for each such collection, being performance of a contract with you, compliance with a legal obligation to which we are subject, or your explicit consent, as applicable to the relevant Processing.

4. Purposes of Processing and Lawful Basis

4.1. We process your Personal Data only where we have a Lawful Basis to do so under the NDPA. The table below sets out each purpose for which we process Personal Data and the corresponding Lawful Basis.

Purpose of ProcessingLawful Basis under the NDPA
Providing our products and services to youPerformance of a contract
Processing payments and ordersPerformance of a contract and compliance with a legal obligation
Customer support and communicationsPerformance of a contract and our legitimate interests
Marketing and promotionsConsent
Analytics and service improvementOur legitimate interests
Legal and regulatory complianceCompliance with a legal obligation

4.2. Where we rely on our legitimate interests as a Lawful Basis, we do so only after balancing those interests against your rights, freedoms and reasonable expectations, and we will not process your Personal Data where our interests are overridden by your interests or fundamental rights.

4.3. Our marketing and promotional communications relate solely to Riskgratis’s own products and services (first party marketing). We rely on your consent for such communications, and you may withdraw that consent at any time as described in Clause 8. We do NOT sell your Personal Data and we do NOT share your Personal Data with any third party for that third party’s own marketing purposes.

4.4. Where we rely on your consent as a Lawful Basis, you have the right to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of any Processing carried out before the withdrawal.

5. How We Share Personal Data

5.1. We share Personal Data only with the following recipients and only to the extent necessary:

  • (a) Data Processors and service providers who help us operate our business, such as hosting, infrastructure and IT support providers, acting on our instructions under appropriate data-processing terms;
  • (b) Payment processors engaged to process payments and orders securely on our behalf;
  • (c) Regulators, courts and public authorities where we are required to disclose Personal Data to comply with a legal obligation.

5.2. When we engage a Data Processor, we put in place a written contract that requires the Data Processor to process Personal Data only on our documented instructions, to apply appropriate security measures, and to comply with the NDPA.

5.3. We do NOT sell Personal Data, and we do NOT share Personal Data with third parties for their own marketing purposes.

6. International Transfers of Personal Data

6.1. As a matter of routine, we store and process your Personal Data within Nigeria and do not transfer it outside Nigeria.

6.2. Where, in exceptional circumstances, a Data Processor or recipient is located outside Nigeria, we will only transfer your Personal Data outside Nigeria where one of the following NDPA safeguards applies:

  • (a) the recipient country, sector or organisation provides an adequate level of protection for Personal Data as recognised by the NDPC;
  • (b) appropriate safeguards are in place, such as binding contractual terms imposing data-protection obligations equivalent to those under the NDPA; or
  • (c) you have given your explicit consent to the transfer after being informed of the possible risks, or the transfer is otherwise permitted under the NDPA (for example, where necessary for the performance of a contract with you).

6.3. In all cases, we take reasonable steps to ensure that Personal Data transferred outside Nigeria continues to be protected in accordance with the standards required by the NDPA.

7. Data Subject Rights

7.1. Subject to the conditions and exemptions in the NDPA, you have the following rights in relation to your Personal Data:

  • Right of access — to be informed whether we process your Personal Data and to obtain a copy of that data;
  • Right to rectification — to have inaccurate or incomplete Personal Data corrected or completed;
  • Right to erasure — to request the deletion of your Personal Data where there is no lawful ground for us to continue processing it;
  • Right to object — to object to the Processing of your Personal Data, including Processing based on our legitimate interests and Processing for marketing purposes;
  • Right to restriction of processing — to request that we limit the Processing of your Personal Data in certain circumstances;
  • Right to data portability — to receive the Personal Data you have provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible;
  • Right to withdraw consent — where we rely on consent, to withdraw that consent at any time.

7.2. To exercise any of these rights, please contact our Data Protection Officer using the details in Clause 13. We will respond to your request within the timeframe required by the NDPA and may ask you to verify your identity before acting on your request.

7.3. You also have the right to lodge a complaint with the Nigeria Data Protection Commission if you believe that our Processing of your Personal Data infringes the NDPA. We would, however, appreciate the opportunity to address your concerns directly before you approach the NDPC.

8. Withdrawing Consent and Managing Marketing Preferences

8.1. Where we process your Personal Data on the basis of consent, including for marketing and promotional communications, you may withdraw your consent at any time by contacting our Data Protection Officer using the details in Clause 13, or by using any unsubscribe or opt-out mechanism provided in the relevant communication.

8.2. Following withdrawal of consent, we will stop the relevant Processing, unless we have another Lawful Basis to continue, and the withdrawal will not affect the lawfulness of Processing carried out before it took effect.

9. Security Measures

9.1. We implement appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful Processing and against accidental loss, destruction or damage.

9.2. These measures include access controls, encryption of data in transit and at rest where appropriate, secure authentication, network security, staff confidentiality obligations and regular review of our security practices.

9.3. We apply heightened controls to Sensitive Personal Data, including the government identifiers described in Clause 3.1(d) and the payment and financial information described in Clause 3.1(c). Such controls include restricting access to authorised personnel on a strict need-to-know basis, additional encryption and monitoring, and minimising the collection and retention of such data to what is strictly necessary.

9.4. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the NDPC and, where required, affected Data Subjects in accordance with the timeframes and requirements of the NDPA.

10. Data Retention

10.1. We retain Personal Data only for as long as is necessary to fulfil the purposes for which it was collected, as set out in Clause 4, or for as long as we are required to retain it to comply with applicable law.

10.2. The criteria we use to determine retention periods include the nature and sensitivity of the Personal Data, the purpose for which it is processed, the existence of any ongoing contractual relationship, and any legal, accounting, tax or regulatory requirements.

10.3. Payment and financial records may be retained for the period required by applicable Nigerian financial, accounting and tax law, even after the end of our relationship with you.

10.4. When Personal Data is no longer required, we will securely delete, destroy or anonymise it.

11. Cookies and Similar Technologies

11.1. We use cookies and similar technologies on our website and applications such as Juniper, Juniper Retail, Juniper Field Sales and Juniper Assets in order to enable core functionality, to remember your preferences, to secure your account, and to collect analytics data that helps us understand and improve how our services are used.

11.2. Some cookies are strictly necessary for the operation of our services. Others, such as analytics and preference cookies, are used on the basis of your consent where required.

11.3. You can manage or disable non-essential cookies through your browser settings or any cookie-preference tool we make available. Disabling certain cookies may affect the functionality of our website and applications.

12. Children’s Data

12.1. Our products and services are not directed at children, and we do not knowingly collect Personal Data from children.

12.2. If we become aware that we have inadvertently collected Personal Data relating to a child without an appropriate Lawful Basis or the consent of a parent or guardian where required, we will take reasonable steps to delete that data promptly.

12.3. If you believe that a child has provided us with Personal Data, please contact our Data Protection Officer using the details in Clause 13.

13. Data Protection Officer and Contact Details

13.1. We have appointed a Data Protection Officer who is responsible for overseeing our compliance with this Policy and the NDPA, and who serves as the point of contact for privacy enquiries and requests to exercise your rights.

13.2. You can contact our Data Protection Officer as follows:

Data Protection Officer: Anthony Ola
Email: eyinkofe.anthony@riskgratis.com

14. Changes to This Policy

14.1. We may update this Policy from time to time to reflect changes in our practices, our services, or applicable law.

14.2. Where we make material changes, we will update the “last updated” date at the top of this Policy and, where appropriate, notify you by email or through a notice on our website or applications before the changes take effect.

14.3. We encourage you to review this Policy periodically to stay informed about how we protect your Personal Data.