Skip to content

Privacy Policy

This covers the data Bitnox handles through this website, through enquiries and newsletter signups, and in the course of a project.

Effective
1 January 2025
Last updated
Governed by
the laws of Nigeria
01

Who this is from

Bitnox Technology Solutions is a technology company based in Abeokuta, Ogun State, Nigeria. This policy explains how we handle personal data when you visit this website, send an enquiry, subscribe to the newsletter, book the Event Space or engage us on a project.

It is made under the Nigeria Data Protection Act 2023. Using the site or sending us your details means you have been told what is in it.

For data you give us directly, Bitnox is the data controller. Where we process data on behalf of a client, on a system we built or host for them, we are a data processor and act on that client's instructions under the agreement with them.

02

What we collect

What you give us

  • Your name, email address, phone number and organisation, when you send an enquiry or ask for a quote.
  • The date, expected number of people and what the room is for, when you enquire about the Event Space.
  • Your email address alone, when you subscribe to the newsletter.
  • Briefs, specifications, files and content you send us during a project.
  • Billing details needed to invoice you and record the payment.

What is collected automatically

  • Your IP address, taken when a form is submitted and used to rate-limit the form. It is stored against the submission and nothing else.
  • Server logs generated by requests, held for a short period for security and diagnosis.
  • Where a Google Tag Manager container is configured and you have accepted analytics, the data that container collects, subject to Google's own policies. Decline and it collects nothing.

We do not fingerprint devices, we do not buy contact lists, and we do not track visitors across other websites.

03

What we use it for

  • Answering enquiries. Replying to what you sent, confirming an Event Space date, and quoting for work.
  • Delivering a project. Doing the work, managing it, and handing over what was agreed.
  • Billing. Issuing invoices and keeping the financial records Nigerian law requires.
  • Newsletter. Sending the newsletter you asked for, until you stop it.
  • Security. Rate-limiting forms, detecting abuse and protecting the site and its data.
  • Legal obligations. Meeting our obligations and responding to lawful requests.

We do not sell, rent or trade personal data, and we do not use enquiry details for marketing you did not ask for.

05

Who else sees it

We share personal data only in these circumstances:

  • Service providers we depend on. Resend, which sends our transactional email and the newsletter. Cloudinary, which stores images uploaded through the admin. Our hosting and database providers. Each processes data on our instructions under its own agreement.
  • Subcontractors on a project. Vetted specialists brought onto a piece of work, under the same confidentiality and data protection obligations we are under.
  • Where the law requires it. In response to a court order or a lawful request from a competent authority, including the NDPC.
  • A business transfer. If the business is merged, acquired or sold, data may move with it. Affected people are told, as the law requires.
  • Anything else, with your consent. Asked for at the time, and specific to the purpose.
06

How long we keep it

  • Project records, including contracts, deliverables and correspondence: at least 7 years after the project ends, as Nigerian tax and company law requires.
  • Financial and billing records: 7 years, under the Federal Inland Revenue Service Act and the Companies and Allied Matters Act.
  • Enquiries, including Event Space bookings: 24 months after the last contact, so we can pick up a conversation that resumes.
  • Newsletter subscriptions: until you unsubscribe. The record of the unsubscribe itself is kept, so you are not added back by mistake.
  • Rate-limiting records: hours, not days. They exist only for the window they cover.

When data is no longer needed it is deleted or anonymised.

07

Your rights, and how to use them

Under the Nigeria Data Protection Act 2023 you have the right to:

  • Access a copy of the personal data we hold about you.
  • Correct anything inaccurate or incomplete.
  • Erase your data, subject to the retention periods above where the law requires us to keep something.
  • Restrict how we use it, in defined circumstances.
  • Withdraw consent at any time, without affecting anything done lawfully before you did.

Write to info@bitnoxsolution.com with what you want and enough detail to find your records. We answer within 30 days, as the NDPA requires. Every newsletter also carries a one-click unsubscribe link, which needs no request at all.

08

Cookies and storage

This site sets very little in your browser, and none of it is used to build a profile of you.

  • A session cookie, set only when somebody signs in to the admin. It holds a signed session identifier, nothing about you, and it is required for signing in to work. It is strictly necessary, so it is not covered by the banner below.
  • Analytics, only where a Google Tag Manager container has been configured for the site, and only after you have accepted it. Until you do, the analytics tags run in a mode that stores nothing in your browser and sets no cookie.
  • Your answer to the banner, kept in your browser's local storage rather than in a cookie, so we do not have to ask again on every page. It records the word granted or denied and nothing else, and it never reaches our servers.

The banner appears once, on your first visit. You can change your answer at any time using the Analytics settings link at the bottom of any page, and declining costs you nothing: no feature of this site depends on it.

There are no advertising cookies, no social network pixels and no cross-site trackers. You can clear or block cookies in your browser at any time; blocking the session cookie prevents signing in to the admin and affects nothing else.

09

How it is protected

  • Data in transit is encrypted with TLS.
  • Admin access is limited by role, and every action that changes data checks the session on the server rather than trusting the browser.
  • Public forms are rate-limited by address and by email, to cap what an abusive run can cost.

No system is completely secure. If a personal data breach occurs, we will notify the people affected and the NDPC within 72 hours of becoming aware of it, as the NDPA requires.

10

Links to other sites

This site links to the two sister Bitnox properties, edu.bitnoxsolution.com and cleaning.bitnoxsolution.com, and to third-party sites in blog posts and portfolio entries. Each operates under its own privacy policy, and a link is not an endorsement of how it handles data.

11

Changes to this policy

We update this policy when our practices or the law change. The last updated date at the top of the page is when it last changed, and material changes are announced by email to anyone on the newsletter.

12

How to reach us about this

Data protection questions and requests go to info@bitnoxsolution.com, or by post to the office address on the contact page. Include enough detail for us to find the records you are asking about.

Ask before you sign, not after

If anything here needs clarifying for your situation, say which clause and what you need to know. We would rather answer it now than have it come up halfway through a project.