Client privacy notice

Your business relationship,

handled with care and transparency.

This Client Fair Processing Notice explains how Pintop Technologies Limited collects, uses, shares, protects and retains personal data relating to clients, prospective clients, authorised representatives, business contacts and users connected with client engagements.

Notice information
Version
1.0
Effective date
31 July 2026
Policy owner
Data Protection Officer
Privacy contact
hi@pintoptechnologies.com

Who this notice covers.

This notice applies when Pintop communicates with, evaluates, contracts with, delivers services to, supports or otherwise manages a relationship with an organisation and processes personal data about people connected with that organisation.

It should be read together with the Privacy Policy, applicable contracts, service-specific notices and any instructions agreed with a client. Where Pintop processes personal data solely on a client’s documented instructions, the client generally determines the purpose and means of that processing and Pintop acts as a data processor.

Client directors, owners and authorised representatives
Prospective clients, leads and business contacts
Administrators and authorised users of Pintop products
Support, implementation and project contacts
Signatories, approvers and commercial contacts
Individuals whose data a client supplies for service delivery

The client data

journey.

Personal data is handled through a defined lifecycle from first contact to secure deletion or anonymisation.

01

Collect

Receive information directly from you, your organisation, authorised users, referrals, public business sources and systems used during an engagement.

02

Assess

Review requirements, eligibility, authority, security needs, risks and the information required to respond or deliver the requested service.

03

Use

Operate accounts, projects, products, support workflows, billing, communications, reporting and agreed service activities.

04

Share

Provide limited information to approved personnel, vendors, professional advisers, regulators or integration partners where necessary and permitted.

05

Retain or delete

Keep records for operational, contractual, legal and security needs, then securely delete or anonymise them under the applicable retention schedule.

Information we may

process.

The exact information depends on the relationship, product, service, project and role of the individual involved.

01

Identity and contact details

Names, work email addresses, telephone numbers, job titles, organisation details, signatures and identifiers used to manage the relationship.

Examples include a client administrator’s name, official email address and authorised role.

02

Commercial and engagement records

Proposals, contracts, instructions, approvals, meeting notes, correspondence, billing contacts, invoices and records of services requested or delivered.

These records support contracting, delivery, accountability and dispute management.

03

Account and access data

Usernames, account identifiers, roles, permissions, login events, device or browser information and security records associated with authorised access.

04

Support and technical information

Tickets, issue descriptions, diagnostic information, safe reference identifiers, logs and troubleshooting records supplied during support or implementation.

05

Compliance and risk information

Due-diligence information, authority checks, audit evidence, security assessments, regulatory correspondence and records needed to prevent fraud or meet legal duties.

Why Pintop uses client data

Purposes and lawful bases.

Pintop processes personal data only where there is a defined business purpose and an applicable lawful basis under data-protection law.

The lawful basis may differ by activity. Contract, legal obligation and legitimate interests are commonly relevant to client relationships; consent is used where the activity genuinely requires a voluntary choice.

01

Deliver services

To create accounts, implement products, manage projects, provide support and perform agreed services. Usually necessary for a contract or steps requested before a contract.

02

Manage the relationship

To communicate, arrange meetings, maintain authorised contacts, document decisions and provide service notices. Based on contract and legitimate operational interests.

03

Billing and administration

To issue invoices, reconcile payments, maintain financial records and administer commercial terms. Based on contract, legal obligations and legitimate interests.

04

Security and fraud prevention

To authenticate users, manage permissions, investigate suspicious activity, preserve logs and protect systems, clients and users. Based on legal duties and legitimate security interests.

05

Compliance and legal claims

To meet regulatory, tax, audit and record-keeping duties and to establish, exercise or defend legal claims. Based on legal obligation and legitimate interests.

06

Relevant business communications

To share product updates, service information or carefully selected business communications with appropriate contacts. Based on legitimate interests or consent where required.

Recipients and transfers

Shared only where

there is a valid reason.

Pintop does not disclose client personal data indiscriminately. Access and disclosure are limited to what is reasonably necessary for the relevant purpose, subject to confidentiality, security and contractual controls.

Pintop personnel

Authorised employees, contractors and project teams who need the information to perform their responsibilities.

Approved service providers

Hosting, communications, payment, productivity, analytics, support and professional-service providers operating under appropriate terms.

Authorities and advisers

Regulators, courts, law-enforcement bodies, auditors, insurers and professional advisers where disclosure is legally required or reasonably necessary.

How international transfers are handled

01

Identify the transfer

Determine whether personal data will be accessed, hosted or otherwise processed outside Nigeria.

02

Assess the destination

Review the recipient, destination, processing purpose and available legal or contractual protections.

03

Apply safeguards

Use approved contractual, organisational and technical measures where required for the transfer.

04

Maintain oversight

Document relevant providers and periodically review whether the transfer and safeguards remain appropriate.

Retention and

security.

Records are kept only for as long as reasonably required and protected through proportionate technical and organisational measures.

How long information is kept

Retention depends on the type of record, the service delivered, contractual commitments, regulatory and tax requirements, security needs, limitation periods and whether a dispute or investigation is active. When information is no longer required, it is deleted, anonymised or securely archived under the applicable retention schedule.

How information is protected

Pintop applies access controls, role-based permissions, secure authentication, encryption where appropriate, backups, monitoring, logging, staff confidentiality duties, vendor controls and incident-response procedures. No security measure eliminates every risk, so clients should also use approved channels and protect their own credentials and devices.

Your data-protection rights

Subject to applicable law and relevant exemptions, individuals may request access to their personal data, correction of inaccurate information, deletion, restriction, objection, portability, withdrawal of consent and information about certain automated decisions. A complaint may also be made to the Nigeria Data Protection Commission. Pintop may need to verify identity and authority before acting on a request.

Client responsibilities

When clients provide personal data

A client supplying personal data to Pintop should have authority and an appropriate lawful basis to do so, provide required notices to affected individuals, limit the information to what is necessary, keep instructions accurate and notify Pintop when records should be corrected, restricted or deleted. Clients should not place passwords, OTPs, private keys or unrelated sensitive information in tickets, emails or project documents.

Clear internal

responsibilities.

Different teams contribute to lawful, transparent and secure handling of client personal data.

Role
Responsibility

Client and Account Teams

Maintain accurate contacts, communicate transparently, use approved systems and avoid collecting information that is not needed for the engagement.

Product, Engineering and Support

Apply access controls, data minimisation, secure design, logging, troubleshooting discipline and approved handling procedures.

Finance and Administration

Protect billing and commercial records, limit access and retain information according to legal and operational requirements.

Data Protection Officer

Oversees this notice, advises on lawful processing, supports rights requests and reviews privacy risks and compliance.

All Personnel

Follow confidentiality, security, retention and incident-reporting requirements whenever handling client or user information.

Client privacy enquiries

Need to understand, correct or question a client data record?

Tell Pintop which organisation, account, project, communication or processing activity is involved. Do not send passwords, OTPs, private keys or unnecessary confidential information with the initial request.