Legal
Privacy Policy
CodeVortex is committed to protecting the privacy of those who visit this website and who engage us for professional services. This Policy explains what personal data we collect, the purposes for which it is processed, the legal bases on which we rely, and the rights available to data subjects.
1. Scope of this Policy
This Policy applies to personal data processed by CodeVortex through this website, in the course of responding to enquiries, and in the administration of client relationships. It is issued in accordance with the Nigeria Data Protection Act 2023. It does not apply to personal data that we process on behalf of a client under a written services agreement, where the client acts as controller and we act as processor. In those circumstances, the relevant data processing agreement governs our obligations.
2. Data Controller
The controller responsible for the processing described in this Policy is Code Vortex Limited.
Enquiries concerning this Policy or the exercise of data subject rights should be addressed to [email protected].
3. Personal Data We Collect
3.1 Data you provide to us
The enquiry form on this website does not transmit data to our servers. On submission, it composes a message in your own email application, which you then choose whether to send. No personal data reaches us unless and until you elect to send that message.
Where you contact us by email, we receive the information you choose to provide. This ordinarily comprises your name, business contact details, the organisation you represent, and the substance of your enquiry.
3.2 Data collected automatically
Our hosting infrastructure records standard server logs as an ordinary incident of operating a website. These logs may include the requesting IP address, the date and time of the request, the resource requested, the HTTP response status, and the user-agent string reported by your browser. These records are used for security monitoring, diagnosis of faults, and capacity planning.
3.3 Data we do not collect
We do not operate advertising technology on this website, do not build marketing profiles for use by third parties, do not purchase personal data from data brokers, and do not sell or licence personal data to any party. Usage measurement is described in section 5.
4. Purposes and Lawful Bases for Processing
We rely on the following lawful bases, each of which is provided for in section 25 of the Nigeria Data Protection Act 2023:
- Responding to enquiries and providing proposals. Processing is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the data subject's request prior to entering into a contract.
- Administration of client relationships. Processing is necessary for the performance of our services agreement with the relevant client.
- Security, fault diagnosis and service integrity. Processing is necessary for the purposes of our legitimate interests in maintaining a secure and functioning service. We rely on this basis only where those interests are not overridden by the fundamental rights, freedoms and interests of the data subject.
- Compliance with legal obligations. Processing is necessary for compliance with a legal obligation to which we are subject, including accounting, taxation and statutory record-keeping requirements.
Where we process the personal data of data subjects located in the European Economic Area or the United Kingdom, the corresponding lawful bases under Article 6 of the General Data Protection Regulation apply in addition.
6. Disclosure of Personal Data
Personal data may be disclosed to the following categories of recipient:
- Service providers. Providers of hosting, electronic mail, and business administration services, each engaged under written terms imposing confidentiality and security obligations and restricting processing to our documented instructions.
- Professional advisers. Legal, accounting and insurance advisers, where disclosure is necessary for the establishment, exercise or defence of legal claims.
- Competent authorities. Regulatory, law enforcement or judicial bodies, where disclosure is required by law or necessary to protect our rights.
- Successors in title. A purchaser or successor in the event of a merger, acquisition or reorganisation, subject to the protections of this Policy.
7. International Transfers
Our service providers may process personal data outside Nigeria. Under sections 41 to 43 of the Nigeria Data Protection Act 2023, such a transfer may take place only where the recipient is subject to a law, binding corporate rules, contractual clauses, a code of conduct or a certification mechanism affording an adequate level of protection, or where another condition specified in the Act is satisfied.
Before transferring personal data outside Nigeria we assess the recipient's jurisdiction against the factors set out in section 42, including the availability of enforceable data subject rights, the existence of effective judicial or administrative redress, the rule of law, the powers of any supervisory authority in that country, and its relevant international commitments. A copy of the safeguard relied upon for a particular transfer may be requested at the address in section 14.
8. Retention
Personal data is retained only for so long as is necessary for the purposes for which it was collected. Enquiry correspondence that does not result in an engagement is ordinarily deleted within twenty-four months. Records relating to a client engagement are retained for the duration of the engagement and thereafter for the period required to satisfy statutory limitation, taxation and accounting obligations. Server logs are retained for a short operational period consistent with their security and diagnostic purpose.
9. Security
We maintain technical and organisational measures appropriate to the risk presented by our processing, including encryption of data in transit, access control on the principle of least privilege, multi-factor authentication for administrative access, and periodic review of our security posture. No method of transmission or storage is entirely secure, and we do not warrant absolute security.
10. Your Rights
Subject to the conditions and exemptions provided by law, sections 34 to 38 of the Nigeria Data Protection Act 2023 confer on data subjects the right to be informed about the processing of their personal data; to request access to that data; to require the rectification of inaccurate data; to request erasure; to obtain the restriction of processing; to object to processing carried out on the basis of our legitimate interests; to receive the data they provided to us in a portable form; and not to be subject to a decision based solely on automated processing which produces legal or similarly significant effects. Where processing is founded on consent, that consent may be withdrawn at any time without affecting the lawfulness of processing carried out before withdrawal.
A request may be made to [email protected]. We will respond within one month of receipt, which period may be extended where permitted by law. We may request information reasonably necessary to verify the identity of the requester.
A data subject who considers that our processing infringes applicable data protection law is entitled to lodge a complaint with the Nigeria Data Protection Commission, without prejudice to any other remedy available in law. We would welcome the opportunity to address the matter directly in the first instance.
11. Children
Our services are directed to businesses and organisations. This website is not intended for children, and we do not knowingly collect personal data relating to children. Where we become aware that such data has been collected, it will be deleted without undue delay.
12. Third-Party Websites
This website may contain links to websites operated by third parties. We exercise no control over, and accept no responsibility for, the content or privacy practices of those websites. We encourage you to review the privacy notice of any third-party website you visit.
13. Amendments
We may amend this Policy from time to time to reflect changes in our practices or in applicable law. The date of the most recent revision is stated at the head of this document. Where an amendment is material, we will take reasonable steps to bring it to the attention of affected data subjects.
14. Contact
Correspondence concerning this Policy should be addressed to [email protected].