// Legal

Privacy Policy

We ask organisations to trust us with sensitive information about their compliance posture. This policy explains exactly what we collect, why, who else touches it, and the rights you hold over it — under Nigerian, European, and other applicable data protection law.

Nigeria NDPA 2023EU GDPRUK GDPRGhana DPA 2012Kenya DPA 2019South Africa POPIACalifornia CCPA/CPRA

Last updated: 7 August 2026

1. Scope and who this policy covers

This policy applies to everyone who uses Nalevra — the Gap Assessment, the Assessment Hub, the Verification Service, and Nalevra Command — and to visitors of nalevra.com. It covers personal data we handle as a data controller (decisions we make about your account and our platform) and explains our role as a data processor where we handle personal data on your organisation's behalf.

Which laws apply to you. Data protection law follows the person, not the company. If you are in Nigeria, the Nigeria Data Protection Act 2023 applies to our handling of your data. If you are in the EEA or UK, the GDPR or UK GDPR applies. Section 13 sets out the specific rights and regulator for each jurisdiction we serve. Where laws overlap, we apply the standard most protective of you rather than the minimum we could get away with.

Nalevra is a compliance platform. Some of the personal data you enter belongs to your employees, customers, or data subjects — for example, when you name an obligation owner or upload evidence. For that data your organisation is the controller and we act on your documented instructions.

2. Who we are and how to reach us

Nalevra Limited ("Nalevra", "we", "us", "our") is a company incorporated in the Federal Republic of Nigeria. We operate the compliance intelligence platform at nalevra.com, and we are the data controller responsible for the personal data described in this policy.

Data controllerNalevra Limited
Incorporated inFederal Republic of Nigeria
Privacy contactprivacy@nalevra.com
General contactadmin@nalevra.com

Still to add. RC registration number and registered office address — both are required identification details for a data controller under NDPA s. 27 and GDPR Art. 13. Also confirm whether Nalevra Limited meets the NDPA s. 32 threshold for a "data controller of major importance" (which triggers NDPC registration and a designated Data Protection Officer), and whether an EU/UK representative is required under GDPR Art. 27 given that we serve data subjects in those regions without an establishment there.

For any privacy question, request, or complaint, contact privacy@nalevra.com. We aim to acknowledge within 5 working days and to respond substantively within 30 days, or within any shorter period your local law requires.

3. Data we collect

Account and registration data

  • Full name and email address
  • Company or organisation name
  • Password, stored only as a salted hash — we never hold your password in readable form
  • Account creation date, login history, IP address and device of each sign-in
  • Two-factor authentication settings and backup codes, where enabled

Assessment data

  • Your answers across all phases of the Gap Assessment — jurisdiction, risk profile, control existence and effectiveness
  • Evidence notes or files you attach to specific questions
  • Sector, employee count, revenue range, and country of incorporation
  • Countries you operate in and where your data subjects are located
  • Whether you process sensitive, financial, children's, or biometric data
  • Existing certifications and regulatory registrations

Compliance programme data (Nalevra Command)

  • Obligation titles, descriptions, domains, severity ratings, and statuses
  • Owner assignments, due dates, and remediation notes
  • Evidence attached to obligations
  • Team member names, email addresses, and roles in your organisation
  • Posture snapshots recording compliance score and obligation counts over time
  • Regulatory monitoring data relevant to your jurisdictions

Verification service data

  • Assessment outputs submitted for review
  • Evidence documents and policy materials shared with a reviewer
  • Reviewer notes, decisions, and supporting comments
  • Verification tier, status, date of issue and expiry, and any revision history

Payment data

  • Billing name and address
  • Payment method type and last four digits — held by our payment processor; we never store full card numbers
  • Transaction history and subscription status

Nalevra is currently in free early access and is not collecting payments. This section describes handling once payment processing is live.

Technical and usage data

  • IP address and approximate location derived from it
  • Browser, operating system, and device type
  • Pages visited, features used, assessment progress, and session duration
  • Authentication tokens and session identifiers held in secure cookies
  • Error logs, email delivery logs, and diagnostic data used to keep the platform reliable

4. How we use your data

To provide the service. Your account data and assessment answers operate the platform, generate your report, populate your Hub, and activate Command. Without this data the service cannot function.

To run the Verification Service. If you request verification, your assessment outputs and submitted evidence are shared with the assigned reviewer, who forms a professional opinion and issues a verified outcome.

To operate Command. Obligation data, team assignments, posture snapshots, and regulatory monitoring power the dashboard and reports including the Investor Pack.

To process payments. Billing data is passed to our payment processor. We retain transaction records for accounting and tax compliance.

To communicate with you. We use your email address for account confirmations, report delivery, team invitations, security alerts about new sign-ins, renewal reminders, and support replies. We do not send marketing email without your consent, and every marketing message carries an unsubscribe link.

To secure and improve the platform. We use logs and aggregated, anonymised usage patterns to detect abuse, fix faults, refine our assessment questions, and improve scoring. Data used for improvement is aggregated or anonymised so it no longer identifies you or your organisation.

To meet legal obligations. We process and retain data where tax, accounting, financial-regulation, or data protection law requires it.

5. AI processing and automated decision-making

Nalevra uses AI to produce your compliance analysis. We think you should understand this clearly rather than find it buried in a sub-clause.

  • What is processed. Your assessment answers, organisation profile, and jurisdiction data are sent to Anthropic's Claude API to generate your compliance score, domain scores, gap findings, remediation roadmap, and document checklist.
  • Training. Your data is not used to train third-party AI models. Anthropic does not train its models on data submitted through its API under our agreement.
  • Human review. Our staff do not read your individual assessment answers unless you contact support, you request verification, or a specific technical fault requires investigation.
  • No decisions with legal effect. Nalevra's output is analysis and guidance. We do not use automated processing to make decisions producing legal or similarly significant effects on any individual, so GDPR Art. 22 and the equivalent NDPA provision are not engaged. Where you request the Verification Service, a qualified human reviewer — not the model — issues the verified outcome.
  • Your control. You can request an explanation of how your score was produced, challenge any finding through the revision process, or ask us to delete an assessment entirely.

7. Who we share your data with

We do not sell your personal data, and we do not share it for cross-context behavioural advertising. We share it only with the sub-processors below, each bound by a data processing agreement, and in the limited circumstances listed after the table.

Sub-processorPurposeLocationData involved
AnthropicAI analysis of assessment responsesUnited StatesAssessment answers, organisation profile
NeonDatabase hostingEuropean UnionAll platform data at rest
VercelApplication hosting and deliveryUnited States / global edgeRequests in transit, server logs
BrevoTransactional email deliveryEuropean UnionName, email address, message content
PaystackPayment processing (Africa)NigeriaBilling details, transaction records
StripePayment processing (rest of world)United States / IrelandBilling details, transaction records

We also share data in these situations:

  • Verification reviewers — qualified compliance professionals who review your report, bound by written confidentiality obligations.
  • Your own team — in Command, your organisation's compliance data is visible to other members according to their assigned role.
  • Third parties you choose — anyone you send a public verification certificate link to can see the company name, verified score, framework list, reviewer name and credentials, and validity dates. Nothing else from your assessment is exposed, and you control whether to share the link.
  • Legal and regulatory — where required by law, regulation, or court order, or to protect the rights, property, or safety of Nalevra, our users, or the public. Where we are legally permitted to tell you about such a request, we will.
  • Business transfer — if Nalevra is involved in a merger, acquisition, or asset sale, your data may transfer to the successor entity under the same protections. We will notify you before your data becomes subject to a materially different policy.

8. International data transfers

Nalevra serves organisations across Africa and Europe, and some of our sub-processors operate outside your country. Transfers happen — what matters is that they are lawful and protected.

  • From the EEA and UK. Where data moves to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses, or the UK International Data Transfer Addendum, together with supplementary technical measures including encryption in transit and at rest.
  • From Nigeria. Under NDPA ss. 41–43 personal data may leave Nigeria only where the recipient is subject to a law or binding instrument affording adequate protection, or where another lawful condition applies — including your consent or necessity for performance of a contract with you. We rely on contractual safeguards with each sub-processor and assess adequacy before onboarding any new one.
  • Other jurisdictions. For Ghana, Kenya, and South Africa we apply the equivalent cross-border conditions under Act 843, the Data Protection Act 2019, and POPIA s. 72 respectively.

Our primary database is hosted in the European Union. You can request a copy of the transfer safeguards we rely on by emailing privacy@nalevra.com.

9. How long we keep your data

DataRetention period
Account dataWhile your account is active, then 12 months after closure
Assessment data and reportsLifetime of the account, then 2 years after closure
Command obligations and snapshotsWhile Command is active, then 2 years
Verification records5 years, to support any later challenge to a verified outcome
Payment and transaction records7 years, as required by tax and accounting law
Security, email delivery, and diagnostic logsUp to 90 days

You may ask us to delete your account and data at any time from your account settings or by emailing us. We honour deletion requests except where a specific legal retention obligation overrides them — in which case we will tell you which obligation applies and when the data will finally be erased.

10. Security and breach notification

We apply the following technical and organisational measures:

  • TLS encryption for all data in transit
  • Encryption of data at rest in our database
  • Password hashing with a modern, salted algorithm
  • Role-based access control limiting which of our people can see what
  • Multi-factor authentication, enforced for administrative and reviewer accounts
  • Session management with revocable tokens and visible login history
  • Rate limiting and account lockout to resist credential-stuffing attacks
  • Continuous logging and monitoring of authentication and delivery events

If a breach occurs. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it — the NDPC under the NDPA, your EEA supervisory authority or the ICO under the GDPR and UK GDPR, and the equivalent regulator in other jurisdictions. Where the risk is high, we will notify you directly and without undue delay, describing what happened, what data was involved, and what we are doing about it.

11. Cookies

We use a deliberately small number of cookies, all strictly necessary to run the service:

  • Authentication cookies — secure, HTTP-only session tokens that keep you signed in. These are essential; the platform cannot work without them.
  • Preference cookies — remember interface state such as assessment progress.

We use privacy-preserving, cookieless analytics to count page views and referrers. It does not set tracking cookies, does not build a profile of you, and does not follow you across other websites. We use no advertising cookies, no tracking pixels, and no cross-site retargeting — which is why you do not see a cookie consent wall on this site.

12. Your rights

We extend the following rights to every user, in every country, regardless of whether your local law requires it:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — have inaccurate or incomplete data corrected.
  • Erasure — have your data deleted, subject to legal retention obligations.
  • Portability — receive your data in a structured, machine-readable format.
  • Restriction — have processing paused while a dispute is resolved.
  • Objection — object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent — as easily as you gave it, where consent is our basis.
  • Complain — to us, and independently to your regulator (section 13).

To exercise any right, email privacy@nalevra.com. We respond within 30 days, or sooner where your law requires. We may ask you to verify your identity first — that check exists to stop someone else obtaining your data. Exercising these rights is free; we will only charge for manifestly unfounded or excessive repeat requests, and we will tell you before we do.

13. Jurisdiction-specific rights and regulators

The rights in section 12 apply to everyone. This section names the law and the regulator that apply to you specifically, and any additional rights your jurisdiction grants.

Nigeria
Applicable lawNigeria Data Protection Act 2023 (NDPA), read with the Nigeria Data Protection Regulation 2019 (NDPR)
RegulatorNigeria Data Protection Commission (NDPC)
Where to complainndpc.gov.ng

You may lodge a complaint with the NDPC directly, or ask us to escalate on your behalf. Under the NDPA we notify the NDPC of a reportable personal-data breach within 72 hours of becoming aware of it, and notify affected data subjects where the breach is likely to result in high risk to their rights.

European Union / EEA
Applicable lawGeneral Data Protection Regulation (EU) 2016/679
RegulatorThe supervisory authority of your member state
Where to complainedpb.europa.eu/about-edpb/about-edpb/members

You may complain to the supervisory authority where you live, work, or where the alleged infringement took place. Nothing in this policy limits that right.

United Kingdom
Applicable lawUK GDPR and the Data Protection Act 2018
RegulatorInformation Commissioner’s Office (ICO)
Where to complainico.org.uk

You may complain to the ICO at any time, including before contacting us.

Ghana
Applicable lawData Protection Act 2012 (Act 843)
RegulatorData Protection Commission
Where to complaindataprotection.org.gh

Rights of access, correction, and objection apply as set out in Act 843.

Kenya
Applicable lawData Protection Act 2019
RegulatorOffice of the Data Protection Commissioner (ODPC)
Where to complainodpc.go.ke

Includes the right to object to processing and to request deletion of false or misleading data.

South Africa
Applicable lawProtection of Personal Information Act 4 of 2013 (POPIA)
RegulatorInformation Regulator (South Africa)
Where to complaininforegulator.org.za

Includes the right to object on reasonable grounds and to complain to the Information Regulator.

California, USA
Applicable lawCCPA as amended by the CPRA
RegulatorCalifornia Privacy Protection Agency
Where to complaincppa.ca.gov

You have the right to know, delete, correct, and opt out of sale or sharing of personal information. We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding twelve months. We will not discriminate against you for exercising any CCPA right.

14. Children’s privacy

Nalevra is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. Under the NDPA, processing a child's data requires verifiable parental consent; we avoid this by not offering the service to minors at all. If you believe a minor has provided data through the platform, tell us at privacy@nalevra.com and we will delete it promptly.

15. Changes to this policy

We update this policy when our practices, technology, sub-processors, or legal obligations change. The "last updated" date at the top always reflects the current version. For material changes — a new category of data, a new purpose, a new sub-processor handling your data — we will notify you by email or in the platform before the change takes effect, and where the law requires consent we will ask for it rather than assume it.

16. Complaints

If something about our handling of your data concerns you, tell us first at privacy@nalevra.com — we would rather fix it than have you escalate. But you are never required to come to us first: you may complain directly to your regulator at any time, and section 13 tells you which one that is and how to reach it.