Privacy Policy
Last updated: May 2026
Next review: May 2027
Introduction
This Privacy Policy explains how Techspecialist Consulting Limited (“TCL”, “we”, “our”, or “us”) collects, uses, stores, discloses, transfers, and protects personal data obtained through our website, products, services, training programmes, managed IT services, consulting engagements, recruitment processes, and all related business interactions.
This Privacy Policy is issued in compliance with the provisions of the Nigeria Data Protection Act 2023 (NDPA), applicable regulations issued by the Nigeria Data Protection Commission (NDPC), including the Nigeria Data Protection Regulation (NDPR), and other applicable international data protection laws where relevant, including the General Data Protection Regulation (GDPR).
By accessing our website or engaging with our services, you acknowledge that your personal data may be processed in accordance with this Policy.
1. About Us
Techspecialist Consulting Limited (TCL) is an information technology consulting and managed services company providing technology advisory, digital transformation, cybersecurity, cloud computing, and enterprise infrastructure, software solutions, IT support services, capacity building, and business technology consulting services to public, private, and development sector organizations across Nigeria.
Registered Office: Goldlink House, No. 2 Harare Street, Off Rabat Street, Zone 6, Wuse, Abuja, Nigeria.
Website: https://techspecialistlimited.com
Email: info@techspecialistlimited.com
Telephone: +234 9 291 1443
TCL is a licensed Data Protection Compliance Organization (DPCO) registered with the Nigeria Data Protection Commission (NDPC). We operate both as a Data Controller — for data collected in the course of its own operations — and as a Data Processor when processing personal data on behalf of client organizations. Where TCL acts as a Data Processor, it does so solely in accordance with the written instructions of the relevant Data Controller under a binding Data Processing Agreement.
2. Scope of This Privacy Policy
This Privacy Policy applies to:
- Visitors to our website
- Clients and prospective clients
- Employees and job applicants
- Vendors, contractors, and consultants
- Training participants and event attendees
- Business partners
- Individuals who communicate or interact with us in any capacity
This Policy explains: the categories of personal data we collect; how we collect and process personal data; the lawful basis for processing; how we use and disclose personal data; data retention periods; international data transfers; security measures; your rights under applicable data protection laws; and how to contact our Data Protection Officer or the NDPC.
3. Definitions of Personal Data
Under the NDPA 2023, “Personal Data” means any information relating to an identified or identifiable natural person (a “Data Subject”). This includes: full name; email address; telephone number; residential or business address; government-issued identification details; IP address and online identifiers; employment records; financial information; device identifiers; location data; photographs or audiovisual recordings; and any information capable of identifying an individual directly or indirectly.
“Sensitive Personal Data” includes information relating to: health or medical conditions; biometric data; ethnicity or racial origin; religious or philosophical beliefs; political opinions; trade union membership; sexual orientation or gender identity; criminal convictions or offences; and such other categories as the NDPC may prescribe from time to time.
“AI-Derived Data” means personal data generated through automated analysis, inference, or profiling by artificial intelligence systems — including data produced through Microsoft Copilot, Agentic AI tools, Power BI analytics, or similar technologies in the course of delivering TCL’s services.
4. Categories of Personal Data We Collect
Depending on your interaction with us, we may collect and process various categories of personal data including identity data, contact data, professional and employment data, technical and device data, usage data, marketing data, and AI-derived data.
5. How We Collect Personal Data
We collect personal data through various channels, including:
- Website contact forms, online registrations, and subscriptions
- Service agreements and contracts
- Recruitment and onboarding processes
- Training and event registrations
- Telephone calls, meetings, and email correspondence
- Vendor registration processes
- Cookies and website analytics technologies
- Social media interactions
- Third-party referrals or business introductions
- Publicly available sources where legally permitted
- Integrated Microsoft platform services like Microsoft 365, Azure, Power Platform, and Microsoft Copilot, through which interaction, usage, and telemetry data may be collected as part of service delivery
We may also automatically collect certain technical data when you access or use our website.
6. Purpose and Legal Basis for Processing
We process personal data only where we have a lawful basis. The six lawful bases we rely on are: contractual necessity, legal and regulatory obligations, legitimate interests, consent, vital interests, and public interest. Where we process sensitive personal data, enhanced safeguards apply.
Where we rely on legitimate interests, we have conducted a Legitimate Interests Assessment (LIA) documenting that such interests do not override the fundamental rights and freedoms of data subjects. The LIA is available upon written request to our Data Protection Officer.
8. Disclosure and Sharing of Personal Data
We may disclose personal data to trusted third parties where necessary for legitimate business purposes, including:
- Cloud hosting and infrastructure providers
- IT support and cybersecurity partners
- Payment processors
- Legal, financial, and professional advisers
- Recruitment and HR service providers
- Training and certification partners
- Regulators and government authorities
- Law enforcement agencies where legally required
We execute Data Processing Agreements (DPAs) with all third-party processors. All processors are contractually required to implement appropriate technical and organizational safeguards, process personal data only in accordance with our documented instructions, notify us promptly of any personal data breach affecting data we have shared with them. A list of our key processors is available upon written request.
We will provide at least 30 days’ prior notice where we intend to engage a new sub-processor whose activities may materially affect the processing of your personal data.
We do not sell personal data to third parties.
9. International Data Transfers
Where personal data is transferred outside Nigeria, we ensure that appropriate safeguards are implemented. Such transfers are governed by Standard Contractual Clauses approved by the NDPC, binding corporate rules, adequacy decisions, or explicit consent of the data subject, as applicable to the specific transfer.
Additional safeguards we implement for international transfers include Data Processing Agreements, confidentiality obligations, and NDPC-approved transfer mechanisms. Where required by the NDPA, we notify the NDPC of international transfers.
10. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal and regulatory compliance, contractual obligations, audit and accounting purposes, dispute resolution, and business continuity requirements. The following indicative retention periods apply:
| Category of Personal Data | Retention Period | Basis |
|---|---|---|
| Client contract & engagement data | 7 years | Contractual & legal obligation |
| Employee & HR records | 7 years post-termination | Employment law (Labour Act) |
| Recruitment & application records | 1 year post-rejection | Legitimate interests |
| Training & certification records | 5 years | Contractual/regulatory |
| Website analytics & cookies | 24 months | Legitimate interests |
| Marketing consent records | Duration of consent + 3 years | Legal obligation |
| Vendor & contractor data | 7 years | Tax & contractual obligation |
| Data breach & incident logs | 5 years | Legal/regulatory obligation |
| DPIA documentation | Life of processing + 3 years | Regulatory (GAID 2025) |
| CCTV / access logs (if any) | 30 days | Security / legitimate interests |
11. Data Subject Rights
Under the NDPA 2023 and applicable data protection laws, you have the following rights: access, rectification, erasure, withdrawal of consent, objection or restriction of processing, data portability, objection to direct marketing, information on automated decision-making, non-discrimination, and the right to lodge a complaint with the NDPC.
We will respond to all data subject requests within 30 days of receipt. We will not charge a fee for reasonable requests.
12. Automated Decision-Making, AI Processing, and Profiling
TCL does not make decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects on individuals in the course of its internal business operations.
However, TCL provides and deploys artificial intelligence systems, Agentic AI solutions, Microsoft Copilot, and Power BI decision intelligence tools on behalf of client organizations. Where such deployments involve automated or AI-assisted decision-making that may have significant effects on individuals, TCL acts as a Data Processor under the instructions of the relevant client as Data Controller. Data subjects affected by such systems should direct enquiries and rights requests to the relevant client organization.
We conduct a Data Protection Impact Assessment (DPIA) before deploying any AI or automated system likely to pose a high risk to the rights and freedoms of individuals. DPIAs are submitted to the NDPC where required and are reviewed periodically. Our DPIA framework is overseen by our Data Protection Officer.
Where any future automated processing with significant individual effects is carried out by TCL in its own capacity as Data Controller, TCL will implement appropriate safeguards, disclose the logic involved, and provide mechanisms for human review and objection as required.
13. Data Security
We implement appropriate technical and organizational measures (TOMs) designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include:
- Secure hosting infrastructure and Microsoft Azure Security Centre integration
- Zero Trust network architecture and access controls
- Multi-factor authentication and role-based access management
- Encryption of personal data in transit and at rest
- Microsoft Defender endpoint protection and firewall systems
- Monitoring, logging, and anomaly detection systems
- Employee confidentiality obligations and regular data protection training
- Periodic security assessments, vulnerability reviews, and compliance audits
Despite these measures, no transmission or storage system can be guaranteed to be completely secure. In the event of a security incident, we will act promptly to contain, assess, and remediate.
13A. Data Breach Notification
In the event of a personal data breach, TCL will take the following:
(a) Notify the NDPC within 72 hours of becoming aware of a breach that is likely to pose a high risk to the rights and freedoms of data subjects, providing details of the breach, the categories, and approximate volume of data and individuals affected, the likely consequences, and the remedial measures taken or proposed.
(b) Notify affected data subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms, including clear guidance on the steps they may take to protect themselves.
(c) Maintain an internal Breach Register documenting all breaches, including those not reported to the NDPC, recording the facts, effects, and remedial actions taken. The Breach Register is maintained by the Data Protection Officer and is available to the NDPC on request.
Notifications will be made to: Nigeria Data Protection Commission — ndpc.gov.ng / info@ndpc.gov.ng.
13B. Record of Processing Activities (RoPA)
We maintain a Record of Processing Activities (RoPA) documenting: the categories of personal data processed; the purposes and lawful bases of processing; data retention periods; data sharing practices and third-party processors; and technical and organizational security measures. The RoPA is maintained by the Data Protection Officer, reviewed at least semi-annually, and made available to the NDPC upon request.
14. Third-Party Websites and Services
Our website may contain links to third-party websites or services. TCL is not responsible for the privacy practices, policies, or content of external websites. Users are encouraged to review the privacy policies of third-party platforms before providing personal data.
15. Children’s Privacy
Our services are not directed at individuals under the age of 18. We do not knowingly collect or process personal data relating to children without an appropriate legal basis or verifiable parental or guardian consent where required under the NDPA, the Child Rights Act 2003, or other applicable law.
If we become aware that we have collected personal data from an individual under the age of 18 without appropriate consent, we will delete such data promptly and, where required by law, notify the relevant guardian or authority.
16. Complaints and Regulatory Authority
If you are dissatisfied with how we handle your personal data, we encourage you to first contact our Data Protection Officer directly. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.
If you remain unsatisfied following our internal resolution process, you have the right to lodge a complaint with:
17. Contact Information
For enquiries, requests, or complaints relating to this Privacy Policy or our data processing activities, please contact:
Techspecialist Consulting Limited
General Email: info@techspecialistlimited.com
Address: Goldlink House, No. 2 Harare Street, Off Rabat Street, Zone 6, Wuse, Abuja, Nigeria.
Telephone: +234 9 291 1443
18. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in legal, regulatory, operational, or business requirements. Any updates will be published on our website together with the revised “Last Updated” date.
For material updates to this Policy, including changes to the legal bases for processing, categories of data collected, or the introduction of new third-party processors, we will provide at least 14 days’ prior notice via email (where we hold your email address) or through a prominent notice on our website before changes take effect. Your continued use of our services after that period constitutes acceptance of the revised Policy.
We encourage all users to review this Policy regularly to remain informed about how their personal data is processed and protected.