Your business relationship,
handled with care and transparency.
This Client Fair Processing Notice explains how Pintop Technologies Limited collects, uses, shares, protects and retains personal data relating to clients, prospective clients, authorised representatives, business contacts and users connected with client engagements.
Who this notice covers.
This notice applies when Pintop communicates with, evaluates, contracts with, delivers services to, supports or otherwise manages a relationship with an organisation and processes personal data about people connected with that organisation.
It should be read together with the Privacy Policy, applicable contracts, service-specific notices and any instructions agreed with a client. Where Pintop processes personal data solely on a client’s documented instructions, the client generally determines the purpose and means of that processing and Pintop acts as a data processor.
The client data
journey.
Personal data is handled through a defined lifecycle from first contact to secure deletion or anonymisation.
Collect
Receive information directly from you, your organisation, authorised users, referrals, public business sources and systems used during an engagement.
Assess
Review requirements, eligibility, authority, security needs, risks and the information required to respond or deliver the requested service.
Use
Operate accounts, projects, products, support workflows, billing, communications, reporting and agreed service activities.
Share
Provide limited information to approved personnel, vendors, professional advisers, regulators or integration partners where necessary and permitted.
Retain or delete
Keep records for operational, contractual, legal and security needs, then securely delete or anonymise them under the applicable retention schedule.
Information we may
process.
The exact information depends on the relationship, product, service, project and role of the individual involved.
Identity and contact details
Names, work email addresses, telephone numbers, job titles, organisation details, signatures and identifiers used to manage the relationship.
Examples include a client administrator’s name, official email address and authorised role.
Commercial and engagement records
Proposals, contracts, instructions, approvals, meeting notes, correspondence, billing contacts, invoices and records of services requested or delivered.
These records support contracting, delivery, accountability and dispute management.
Account and access data
Usernames, account identifiers, roles, permissions, login events, device or browser information and security records associated with authorised access.
Support and technical information
Tickets, issue descriptions, diagnostic information, safe reference identifiers, logs and troubleshooting records supplied during support or implementation.
Compliance and risk information
Due-diligence information, authority checks, audit evidence, security assessments, regulatory correspondence and records needed to prevent fraud or meet legal duties.
Purposes and lawful bases.
Pintop processes personal data only where there is a defined business purpose and an applicable lawful basis under data-protection law.
The lawful basis may differ by activity. Contract, legal obligation and legitimate interests are commonly relevant to client relationships; consent is used where the activity genuinely requires a voluntary choice.
Deliver services
To create accounts, implement products, manage projects, provide support and perform agreed services. Usually necessary for a contract or steps requested before a contract.
Manage the relationship
To communicate, arrange meetings, maintain authorised contacts, document decisions and provide service notices. Based on contract and legitimate operational interests.
Billing and administration
To issue invoices, reconcile payments, maintain financial records and administer commercial terms. Based on contract, legal obligations and legitimate interests.
Security and fraud prevention
To authenticate users, manage permissions, investigate suspicious activity, preserve logs and protect systems, clients and users. Based on legal duties and legitimate security interests.
Compliance and legal claims
To meet regulatory, tax, audit and record-keeping duties and to establish, exercise or defend legal claims. Based on legal obligation and legitimate interests.
Relevant business communications
To share product updates, service information or carefully selected business communications with appropriate contacts. Based on legitimate interests or consent where required.
Shared only where
there is a valid reason.
Pintop does not disclose client personal data indiscriminately. Access and disclosure are limited to what is reasonably necessary for the relevant purpose, subject to confidentiality, security and contractual controls.
Pintop personnel
Authorised employees, contractors and project teams who need the information to perform their responsibilities.
Approved service providers
Hosting, communications, payment, productivity, analytics, support and professional-service providers operating under appropriate terms.
Authorities and advisers
Regulators, courts, law-enforcement bodies, auditors, insurers and professional advisers where disclosure is legally required or reasonably necessary.
How international transfers are handled
Identify the transfer
Determine whether personal data will be accessed, hosted or otherwise processed outside Nigeria.
Assess the destination
Review the recipient, destination, processing purpose and available legal or contractual protections.
Apply safeguards
Use approved contractual, organisational and technical measures where required for the transfer.
Maintain oversight
Document relevant providers and periodically review whether the transfer and safeguards remain appropriate.
Retention and
security.
Records are kept only for as long as reasonably required and protected through proportionate technical and organisational measures.
How long information is kept
Retention depends on the type of record, the service delivered, contractual commitments, regulatory and tax requirements, security needs, limitation periods and whether a dispute or investigation is active. When information is no longer required, it is deleted, anonymised or securely archived under the applicable retention schedule.
How information is protected
Pintop applies access controls, role-based permissions, secure authentication, encryption where appropriate, backups, monitoring, logging, staff confidentiality duties, vendor controls and incident-response procedures. No security measure eliminates every risk, so clients should also use approved channels and protect their own credentials and devices.
Your data-protection rights
Subject to applicable law and relevant exemptions, individuals may request access to their personal data, correction of inaccurate information, deletion, restriction, objection, portability, withdrawal of consent and information about certain automated decisions. A complaint may also be made to the Nigeria Data Protection Commission. Pintop may need to verify identity and authority before acting on a request.
When clients provide personal data
A client supplying personal data to Pintop should have authority and an appropriate lawful basis to do so, provide required notices to affected individuals, limit the information to what is necessary, keep instructions accurate and notify Pintop when records should be corrected, restricted or deleted. Clients should not place passwords, OTPs, private keys or unrelated sensitive information in tickets, emails or project documents.
Clear internal
responsibilities.
Different teams contribute to lawful, transparent and secure handling of client personal data.
Client and Account Teams
Maintain accurate contacts, communicate transparently, use approved systems and avoid collecting information that is not needed for the engagement.
Product, Engineering and Support
Apply access controls, data minimisation, secure design, logging, troubleshooting discipline and approved handling procedures.
Finance and Administration
Protect billing and commercial records, limit access and retain information according to legal and operational requirements.
Data Protection Officer
Oversees this notice, advises on lawful processing, supports rights requests and reviews privacy risks and compliance.
All Personnel
Follow confidentiality, security, retention and incident-reporting requirements whenever handling client or user information.
Related privacy and
governance documents.
These documents explain Pintop’s wider privacy framework, rights procedures, consent controls, cookies and retention practices.
Need to understand, correct or question a client data record?
Tell Pintop which organisation, account, project, communication or processing activity is involved. Do not send passwords, OTPs, private keys or unnecessary confidential information with the initial request.
