This policy sets out how Cyberunite handles the data entrusted to us — our own records, and the data we process on behalf of clients whose products we build and operate. It is written to the standards of the Nigeria Data Protection Act 2023 and the guidance issued by the Nigeria Data Protection Commission.
What this covers
This policy applies to everything Cyberunite provides — this website, our client portal, and every product and service line we deliver or operate:
- Web Development
- AI & AI-Powered Apps
- AI Fine-Tuning & Integrations
- Mobile App Development
- Web3 & Blockchain
- Crypto Apps & Exchanges
- Software & SaaS
- Branding & UI/UX Design
- Cloud & Hosting
- ICT Training
It applies whether the work is delivered as a one-off project, an ongoing retainer, a hosted subscription or a training course, and whether you reach us through this site, the portal, a mobile app we publish, or a contract signed directly with us. We serve clients in Nigeria and abroad; this policy applies to all of them.
Our principles
These follow the principles set out in section 24 of the NDPA:
- Lawfulness, fairness and transparency. We process data for stated purposes with a lawful basis, and we tell people what we are doing.
- Purpose limitation. Data collected for one purpose is not quietly reused for another.
- Data minimisation. We collect what the job needs and no more.
- Accuracy. We correct data promptly when told it is wrong.
- Storage limitation. We delete data when its retention period ends.
- Integrity and confidentiality. We protect data with appropriate technical and organisational measures.
- Accountability. We keep records of our processing and can demonstrate compliance to the Commission on request.
Controller and processor roles
For our own business records — enquiries, contracts, invoices, portal accounts — we are the data controller. For data inside a product we build or host for a client, the client is the controller and we are their data processor: we act only on their documented instructions, under a written data processing agreement that covers confidentiality, security, sub-processors, assistance with data subject requests, breach notification and deletion or return of data at the end of the engagement, as section 29 of the NDPA requires.
Registration and oversight
Where our processing makes us a data controller or processor of major importance under the NDPA, we register with the Nigeria Data Protection Commission, designate a Data Protection Officer, and file the annual compliance audit return the Commission requires. We review that position whenever the volume or sensitivity of what we process changes materially.
Technical and organisational measures
- Encryption in transit (TLS) for all traffic to our sites and portals.
- Passwords stored only as salted one-way hashes; never in plain text, never recoverable.
- Role-based access, granted on least privilege and reviewed when someone joins or leaves.
- Client files and generated documents held outside the public web root and served only through authenticated routes.
- Protection against common web attacks including CSRF tokens on state-changing actions, parameterised database queries, and output escaping.
- Regular backups, with restores tested periodically.
- Security patches applied promptly to the platforms and libraries we depend on.
- Staff bound by confidentiality terms and briefed on their obligations under the NDPA.
Sub-processors
We use a small number of providers to host, deliver email, monitor errors and process payments. Each is assessed before use, bound by contract, and listed to clients on request. We will tell affected clients before adding or replacing a sub-processor that handles their data.
Transfers outside Nigeria
Where data leaves Nigeria we rely on an adequacy determination by the Commission, or on appropriate safeguards — contractual clauses binding the recipient to NDPA-equivalent standards, supported by an assessment of the risk in the destination country — or on one of the derogations in section 43 of the NDPA. Hosting location is stated in each client's contract, and we will move data to a Nigerian region where a client requires it and the platform supports it.
Breach response
We investigate suspected breaches immediately, contain them, and assess the risk to the people affected. Where a breach presents a risk we notify the NDPC within 72 hours of becoming aware, as section 40 of the NDPA requires, and we notify affected individuals and client controllers without undue delay where the risk to them is high. Every incident is recorded, with the actions taken and the lessons applied.
Data protection impact assessments
Before starting work that is likely to result in a high risk to people's rights — large-scale processing of sensitive data, systematic monitoring, or automated decisions with legal effect — we carry out an impact assessment with the client and record the mitigations agreed.
Your responsibilities as a client
If you supply us with personal data to process, you confirm you have a lawful basis under the NDPA to do so and the right to share it with us. Please do not send us live personal data for testing when anonymised or synthetic data would do.
How to contact us
Reach Cyberunite on any of these:
- Email — info@cyberunite.com
- Phone — +234 907 765 1569
- WhatsApp — +234 907 765 1569 (the same number)
For anything that needs a record — a data request, an account deletion or a refund — please use email, so both sides have the request in writing. Phone and WhatsApp are best for quick questions.
Cyberunite is registered in Nigeria — CAC RC: 1475721 | FIRS TIN: 2622492622138| D-U-N-S: 66-982-6932.
We aim to acknowledge every enquiry within two working days and to resolve it within 30 days. If we need longer we will tell you why and give a revised date. Working days are Monday to Friday, excluding public holidays declared in Nigeria.
Questions about this policy?
Email info@cyberunite.com
Call +234 907 765 1569
WhatsApp +234 907 765 1569
