Privacy Policy

KusuConsult — Digital Innovation & Solutions

Last Updated: August 2026

01Introduction

KusuConsult (“KusuConsult”, “we”, “us”, or “our”) is a technology, software development, digital innovation and consulting company that designs, develops, deploys, operates and supports digital products and technology solutions for individuals, businesses, government institutions, organisations and other clients.

This Master Privacy Policy explains how KusuConsult collects, uses, stores, protects, discloses and otherwise processes personal data in connection with:

  • our corporate website;
  • websites and web applications developed or operated by KusuConsult;
  • mobile applications developed or operated by KusuConsult;
  • software-as-a-service products and digital platforms;
  • artificial intelligence and machine-learning solutions;
  • APIs, integrations and other technology services;
  • cloud-hosted applications and systems;
  • customer support and technical support services;
  • software development and implementation projects;
  • consulting, training and technology services; and
  • other digital products and services provided by KusuConsult.

This Policy is intended to provide a general privacy framework applicable across KusuConsult’s technology ecosystem.

Because KusuConsult develops and operates technology on behalf of different clients, the specific processing of personal data within a particular application may also be governed by an application-specific privacy notice, terms of service, client privacy policy, consent notice or other applicable documentation.

Where a KusuConsult-developed application is operated on behalf of a client, that client may determine the purposes and means of processing personal data and may therefore act as the Data Controller, while KusuConsult may act as a Data Processor or technology service provider.

Where KusuConsult determines the purposes and means of processing personal data for its own services, KusuConsult may act as the Data Controller.


02Our Commitment to Privacy

KusuConsult recognises that privacy and responsible handling of personal data are fundamental to the development and operation of trustworthy technology.

We are committed to processing personal data in a manner that is lawful, fair, transparent, secure and proportionate to the purpose for which the information is collected.

Our privacy practices are guided by applicable data protection and privacy laws, including the Nigeria Data Protection Act 2023 and applicable regulations, guidelines and regulatory requirements.

The Nigeria Data Protection Commission identifies principles including lawful and transparent processing, purpose limitation, data minimisation, accuracy, storage limitation and appropriate security of personal data.


03Scope of This Policy

This Policy applies generally to personal data processed through KusuConsult’s services and technology ecosystem.

It applies regardless of whether the service is accessed through:

  • a website;
  • mobile phone;
  • tablet;
  • desktop computer;
  • web browser;
  • application;
  • API;
  • cloud platform;
  • third-party integration; or
  • another supported digital interface.

Some KusuConsult products or client projects may have additional privacy notices. Where an application has a specific privacy notice, that notice should be read together with this Policy.

If there is a conflict between this general Policy and a specific privacy notice relating to a particular service, the specific notice may apply to the processing described in that notice.


04Personal Data We May Collect

The information collected depends on the particular service, application or relationship involved. Depending on the circumstances, we may process categories of information such as:

4.1 Identity Information

  • name;
  • username;
  • account identifier;
  • profile information;
  • photograph or avatar;
  • date of birth where necessary;
  • identification information where required for a particular service.

4.2 Contact Information

  • email address;
  • telephone number;
  • postal or contact address;
  • business address;
  • emergency contact information where relevant to a particular service.

4.3 Account and Authentication Information

  • account credentials;
  • authentication identifiers;
  • login information;
  • verification information;
  • account preferences;
  • security and authentication records.

Passwords and other authentication credentials are intended to be protected using appropriate technical and organisational safeguards.

4.4 Transaction and Service Information

Depending on the application, we may process information relating to:

  • purchases;
  • subscriptions;
  • payments;
  • invoices;
  • service requests;
  • orders;
  • bookings;
  • customer interactions;
  • transaction references;
  • account balances or related records.

Where payments are processed through an external payment provider, payment information may be processed directly by that provider under its own privacy policy and terms.

4.5 Technical and Device Information

When you interact with our websites, applications or digital services, we may collect technical information such as:

  • IP address;
  • browser type;
  • operating system;
  • device type;
  • device identifiers;
  • application version;
  • language and regional settings;
  • network information;
  • access times;
  • referring pages;
  • error logs;
  • diagnostic information;
  • usage information.

4.6 Location Information

Certain applications may require location information to provide particular functions. Location information may include approximate or precise location information depending on the application and the permissions granted by the user. Where location information is not necessary for a service, we seek to avoid collecting it unnecessarily.

4.7 Communications

Where users contact KusuConsult or interact with an application, we may process information contained in:

  • emails;
  • support requests;
  • feedback;
  • enquiries;
  • messages;
  • customer service interactions;
  • technical reports.

4.8 Information Provided by Organisations or Clients

Where KusuConsult provides software or technology services to an organisation, the organisation may provide information to us for processing on its behalf. In such circumstances, KusuConsult may process the information according to the client’s instructions and applicable contractual arrangements.

4.9 Information Generated Through Use of Our Services

Some applications may generate information based on interactions with the service. This may include:

  • activity records;
  • system events;
  • application usage;
  • preferences;
  • audit logs;
  • performance information;
  • security events;
  • interaction history.

05Information We Do Not Intentionally Collect

KusuConsult does not intentionally collect personal information that is unnecessary for the operation of a service.

Where an application requires sensitive or special-category information because of its legitimate purpose, the applicable application-specific privacy notice should explain the relevant processing.

We encourage clients and users to avoid submitting information that is not required for the service.


06How We Collect Information

We may obtain personal data through:

  • information provided directly by users;
  • account registration;
  • forms;
  • applications;
  • websites;
  • customer support;
  • contracts;
  • client organisations;
  • authorised integrations;
  • APIs;
  • third-party service providers;
  • cookies and similar technologies;
  • automated technical logs; and
  • other lawful sources.

07Why We Process Personal Data

Depending on the service, personal data may be processed to:

  • create and manage user accounts;
  • provide requested services;
  • operate applications and platforms;
  • authenticate users;
  • process transactions;
  • provide customer support;
  • communicate with users;
  • maintain system security;
  • prevent fraud and misuse;
  • monitor application performance;
  • diagnose technical problems;
  • improve our products and services;
  • develop and maintain software;
  • perform analytics;
  • comply with legal and regulatory obligations;
  • enforce agreements;
  • protect our rights and property;
  • respond to lawful requests; and
  • perform other purposes disclosed to the user at the point of collection.

We aim to collect and use only information reasonably necessary for the relevant purpose.


08Lawful Bases for Processing

Depending on the circumstances, KusuConsult may rely on one or more lawful bases for processing personal data, including:

  • consent;
  • performance of a contract;
  • compliance with a legal obligation;
  • protection of vital interests;
  • performance of a task carried out in the public interest where applicable; and
  • legitimate interests, where permitted by applicable law.

Where consent is relied upon, individuals may withdraw their consent where legally permitted. Withdrawal of consent does not necessarily affect processing that was lawfully carried out before the withdrawal.


09Client Applications and Client Data

KusuConsult develops technology for a wide range of organisations and industries. Where KusuConsult develops or hosts an application for a client, the client may determine:

  • what information is collected;
  • why it is collected;
  • how it is used;
  • who is authorised to access it;
  • how long it is retained; and
  • whether it is shared with other parties.

In these circumstances, the client may be the Data Controller and KusuConsult may act as a Data Processor.

KusuConsult will process such information in accordance with applicable contractual obligations, documented instructions and applicable data protection laws.

Users who have questions about information controlled by a particular KusuConsult client may also need to contact that client directly.


10Artificial Intelligence and Automated Processing

Some KusuConsult applications may use artificial intelligence, machine learning, automation, analytics or other computational technologies. Depending on the service, information may be processed to:

  • generate responses;
  • provide recommendations;
  • classify information;
  • automate workflows;
  • analyse patterns;
  • improve service functionality;
  • provide customer assistance;
  • detect potentially fraudulent or abnormal activity; or
  • perform other functions described by the relevant application.

Where automated decision-making has legal or similarly significant effects on an individual, KusuConsult will apply appropriate safeguards required by applicable law and the particular service.

Not every KusuConsult application uses artificial intelligence or automated decision-making.


11Cookies and Similar Technologies

Our websites and some applications may use cookies, software development technologies, local storage, analytics tools and similar technologies. These technologies may be used to:

  • keep users signed in;
  • remember preferences;
  • maintain security;
  • understand how services are used;
  • diagnose technical problems;
  • improve performance; and
  • measure service effectiveness.

Users may be able to control certain cookies and similar technologies through their browser or device settings. Disabling certain technologies may affect the functionality of some services.


12How We Share Personal Data

KusuConsult does not sell personal data as a general business practice. We may disclose or provide access to personal data where reasonably necessary for legitimate business, contractual, technical or legal purposes. This may include sharing information with:

  • our authorised employees and personnel;
  • clients and organisations that control a particular application;
  • cloud hosting providers;
  • database and infrastructure providers;
  • payment service providers;
  • communication providers;
  • analytics providers;
  • authentication providers;
  • cybersecurity and fraud-prevention providers;
  • software and technology vendors;
  • professional advisers;
  • auditors;
  • regulators and government authorities where legally required; and
  • other service providers necessary to operate or support a service.

Third parties receiving personal data are expected to process it in accordance with applicable law and appropriate contractual or other safeguards.


13International Data Transfers

Because modern software infrastructure may involve cloud services and technology providers operating in different countries, personal data may in some circumstances be processed or stored outside Nigeria.

Where personal data is transferred across borders, KusuConsult will take reasonable steps to ensure that the transfer is carried out in accordance with applicable data protection requirements. The specific countries or providers involved may vary between applications.


14Data Security

KusuConsult implements reasonable technical and organisational measures designed to protect personal data against:

  • unauthorised access;
  • unlawful processing;
  • accidental loss;
  • destruction;
  • alteration;
  • disclosure;
  • misuse; and
  • other security risks.

Depending on the application, safeguards may include:

  • access controls;
  • authentication mechanisms;
  • encryption where appropriate;
  • secure development practices;
  • logging and monitoring;
  • backups;
  • vulnerability management;
  • security testing;
  • role-based permissions;
  • infrastructure security controls; and
  • organisational security procedures.

No internet-based system can be guaranteed to be completely secure. We therefore continuously review and improve our security measures.


15Data Retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, to provide the relevant service, to comply with legal obligations, resolve disputes, enforce agreements, maintain security, or for other legitimate purposes permitted by law. Retention periods may differ between applications.

For client-managed applications, retention may be determined by the client in accordance with the applicable contract, service requirements and law.

When personal data is no longer required, we may delete, anonymise or securely dispose of it, subject to applicable legal and operational requirements.


16Data Subject Rights

Subject to applicable law and relevant limitations, individuals may have rights concerning their personal data, including the right to:

  • be informed about processing;
  • request access to personal data;
  • request correction of inaccurate or incomplete information;
  • request deletion or erasure;
  • object to certain processing;
  • request restriction of processing;
  • request data portability where applicable;
  • withdraw consent where processing is based on consent;
  • object to certain automated decision-making;
  • lodge a complaint with a relevant data protection authority; and
  • exercise other rights provided under applicable data protection law.

The Nigeria Data Protection Commission identifies these rights among the rights available to data subjects under the Nigeria Data Protection Act.


17How to Exercise Your Privacy Rights

Requests concerning personal data processed directly by KusuConsult may be submitted through:

When making a request, we may need sufficient information to verify the identity of the requester and locate the relevant information.

Where the information is controlled by one of our clients, we may direct the requester to the relevant client or assist the client in responding, depending on the applicable contractual arrangement. We will respond to legitimate requests within the period required by applicable law.


18Children's Privacy

Our services are not automatically intended for children.

Where a particular application is intended for children or may reasonably be accessed by children, the relevant application-specific privacy notice and applicable legal requirements will apply.

We do not knowingly collect personal data from children in circumstances where such collection is prohibited by applicable law. Where we become aware that personal data has been collected improperly, we will take reasonable steps to address the situation.


19Third-Party Services and Links

Our websites and applications may integrate with or contain links to third-party services. These services may include:

  • payment platforms;
  • authentication services;
  • cloud infrastructure;
  • mapping services;
  • communication platforms;
  • analytics services;
  • social media services;
  • artificial intelligence services; and
  • other external technology providers.

Third-party services operate under their own terms and privacy policies. KusuConsult is not responsible for the privacy practices of third-party services that it does not control. Users should review the privacy information applicable to those services where appropriate.


20Data Breaches and Security Incidents

KusuConsult maintains procedures intended to identify, investigate, contain and respond to suspected personal data breaches and security incidents.

Where a breach occurs, KusuConsult will take appropriate action based on the nature and circumstances of the incident and will make notifications where required by applicable law.

Where KusuConsult processes information on behalf of a client, we will follow the applicable contractual and legal requirements governing notification and incident response.


21Privacy by Design

KusuConsult seeks to incorporate privacy and data protection considerations into the design and development of its digital products. Depending on the nature of a project, this may include:

  • collecting only necessary information;
  • implementing appropriate access controls;
  • separating user roles;
  • limiting data exposure;
  • protecting sensitive information;
  • applying appropriate security controls;
  • considering data retention requirements;
  • providing privacy notices;
  • supporting user privacy controls; and
  • assessing privacy risks where appropriate.

The NDPC’s guidance specifically recognises privacy by design and privacy by default as important considerations in software development.


22Business Transfers

If KusuConsult undergoes a merger, acquisition, restructuring, sale of assets, investment, or similar corporate transaction, personal data may be transferred as part of the relevant business transaction where legally permitted.

Any such transfer will remain subject to applicable privacy and data protection requirements.


23Changes to This Privacy Policy

KusuConsult may update this Master Privacy Policy from time to time to reflect:

  • changes to our services;
  • changes in technology;
  • changes in applicable laws;
  • regulatory guidance;
  • changes in our privacy practices; or
  • improvements to our policies and procedures.

The updated version will be published on our website and may also be made available through relevant applications. The “Last Updated” date at the beginning of this Policy indicates when it was most recently revised. Where required by law, we will provide additional notice of material changes.


24Governing Privacy Framework

This Policy is intended to operate in accordance with applicable data protection and privacy laws. For services operated in or involving Nigeria, this includes the Nigeria Data Protection Act 2023 and applicable regulations, guidelines and requirements issued by the Nigeria Data Protection Commission.

Where services are provided in other jurisdictions, additional privacy requirements may apply. Nothing in this Policy is intended to remove or limit a right that cannot lawfully be excluded under applicable law.


25Contact KusuConsult

For questions, requests, complaints or concerns regarding privacy and personal data processed directly by KusuConsult, please contact:

Address

No. 23, Nenrot Plaza, Domkat Bali Road
Jos, Plateau State, Nigeria

Telephone

+234 703 617 1049

When contacting us about a privacy matter, please provide enough information for us to understand the nature of your request or concern.


26Complaints

We encourage individuals to contact KusuConsult first so that we can understand and address privacy concerns where possible.

Nothing in this Policy prevents an individual from exercising their right to lodge a complaint with the relevant data protection authority where permitted by applicable law.

For Nigeria, the relevant supervisory authority is the Nigeria Data Protection Commission (NDPC). The Commission provides mechanisms for data protection complaints and regulatory engagement.


27Final Statement

KusuConsult builds technology for people, organisations and communities. We recognise that responsible technology development requires more than functionality and security. It also requires respect for the information entrusted to the systems we build.

We therefore seek to maintain privacy and responsible data handling as part of the way we design, develop, deploy and support our technology solutions.

KusuConsult — Digital Innovation & Solutions

© 2026 KusuConsult. All rights reserved.  |  Last Updated: August 2026