Data Protection
Cuesoft handles personal data under the Nigeria Data Protection Act (NDPA) 2023 and NDPR 2019, the EU/UK GDPR where they apply, and applicable US state privacy laws. The public-facing commitments live in the privacy policy; this page is the internal duty of care for everyone who works with us.
The rules of the road
- Minimum necessary. Collect and access only the personal data your work actually needs. Applicant, learner and client data is looked at for the task at hand, never browsed.
- Approved systems only. Personal data lives in the company's approved systems — never in personal cloud accounts, personal devices' local copies, or chat threads. Exports are the exception, approved in writing.
- Client and licensee data is theirs. On client engagements and Cueprise™ deployments, the data belongs to the client or licensee. We access it only for maintenance, support and issue resolution — nothing else, per the engagement's terms.
- No secrets in chat. Credentials and personal data never travel through WhatsApp or other informal channels — formal email or the approved secret manager, always (see cybersecurity).
- Contractors carry the duty too. Contractor agreements bind you to applicable data-protection law (including GDPR where it applies): handle personal data securely and lawfully.
When something goes wrong
Report any suspected personal-data breach — loss, unauthorised access, accidental disclosure — immediately to hello@cuesoft.io and your engagement lead. Speed matters legally: Nigerian law requires reporting qualifying breaches to the Nigeria Data Protection Commission within 72 hours, and affected people must be informed where their rights are at risk. Your fast report is what makes the company's lawful response possible.
Rights requests
If anyone asks you about their personal data — access, correction, deletion — do not handle it ad hoc. Forward the request to hello@cuesoft.io the same day; the privacy policy commits us to answer within statutory timelines.