🔒 Data Protection & Privacy

Privacy Policy

How ITSA Global Technologies collects, uses, protects and processes your personal data

Last Updated: May 6, 2026Effective: May 6, 2026Version 1.0
📋 Summary
📦
What we collect
Business information, contact details, usage data and payment information necessary to operate our platforms.
🎯
How we use it
To provide and improve our services, send important communications, and comply with legal obligations.
🔐
How we protect it
Enterprise-grade encryption, row-level security, CSRF protection and strict access controls.

1. Who We Are

ITSA Global Technologies Limited ("ITSA", "we", "our", or "us") is a technology company registered and operating in Nigeria. We develop and operate a suite of Software-as-a-Service (SaaS) platforms for businesses across Africa, including the ITSA Business Platform, ITSA EduClass, and ITSA CliniqPro.

ITSA Global Technologies Limited
📍 Suite D-10, Railway Shopping Complex, Dugbe, Ibadan, Oyo State, Nigeria

This Privacy Policy applies to all visitors, users, and businesses ("you") that access our website at itsaglobal.tech or use any of our products and services, including our WhatsApp Business messaging services.

2. Information We Collect

2.1 Information You Provide Directly

  • Account Registration: Full name, business name, email address, phone number, business address, and industry type when you register for an account.
  • Business Information: Company details, registration number, bank account details for payment processing, and KYC (Know Your Customer) documents including identification.
  • Staff Information: Names, email addresses, phone numbers, and roles of staff members you add to your organisation's account.
  • Client Data: Information about your clients that you upload or enter into our platform as part of using our services (name, contact details, document uploads, booking information).
  • Payment Information: Billing details processed securely through Paystack. We do not store card numbers — these are handled directly by Paystack in compliance with PCI-DSS standards.
  • Communications: Messages, enquiries, and support requests you send to us via email, WhatsApp Business, or our contact forms.

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, time spent, click patterns, and error logs to help us improve the platform.
  • Device Information: Browser type, operating system, IP address, and device identifiers.
  • Cookies and Similar Technologies: Session cookies for authentication, preference cookies, and analytics cookies. See Section 9 for details.
  • Log Data: Server logs including timestamps, API calls, and error reports.

2.3 Information from Third Parties

  • Payment Processors: Transaction confirmation and payment status from Paystack.
  • Meta / WhatsApp: Message metadata (not message content) when you communicate with us via WhatsApp Business.
  • Identity Verification: Verification data from KYC processes to confirm business legitimacy.

3. How We Use Your Information

We use collected information for the following purposes:

PurposeLegal Basis
Providing, operating and improving our SaaS platformsPerformance of contract
Processing payments and managing subscriptionsPerformance of contract
Sending account notifications, system alerts and platform updatesPerformance of contract
Sending marketing communications (with your consent)Consent (withdrawable at any time)
WhatsApp Business messaging for account updates and supportConsent / Legitimate interest
Customer support and dispute resolutionLegitimate interest
Fraud prevention and security monitoringLegitimate interest / Legal obligation
Complying with Nigerian law and regulatory requirementsLegal obligation
Analytics to understand platform usage and improve our servicesLegitimate interest
Onboarding and KYC verification of business clientsLegal obligation / Legitimate interest

WhatsApp Business Messaging: We use the Meta WhatsApp Business API, facilitated through Twilio, to send transactional and informational messages to users who have opted in. These include booking confirmations, payment receipts, appointment reminders, and platform alerts. By providing your WhatsApp number and opting in, you consent to receiving these messages. You may opt out at any time by replying STOP or contacting us directly.

4. How We Share Your Information

We do not sell your personal data to third parties. We share information only in the following circumstances:

4.1 Service Providers (Processors)

We engage trusted third-party service providers who process data on our behalf, bound by strict data processing agreements:

ProviderPurposeLocation
SupabaseDatabase hosting and authenticationUSA / EU (GDPR compliant)
VercelApplication hosting and deploymentUSA / Global CDN
PaystackPayment processingNigeria / USA
TwilioWhatsApp Business API and SMSUSA
TermiiSMS messaging (Nigeria)Nigeria
Zoho MailTransactional email deliveryUSA / India
Anthropic (Claude AI)AI-powered features within the platformUSA
Meta (WhatsApp)Business messaging platformUSA / Global

4.2 Legal Requirements

We may disclose your information when required by Nigerian law, court order, or regulatory authority, or when necessary to protect the rights, property, or safety of ITSA, our users, or the public.

4.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your data is transferred and becomes subject to a different privacy policy.

4.4 With Your Consent

We share data with third parties when you have explicitly consented to such sharing.

4.5 Tenant Data Isolation

Our platform is built with strict multi-tenant data isolation. Each business (tenant) on our platform can only access their own data. Row-Level Security (RLS) policies enforced at the database level ensure complete separation between tenants. ITSA staff can only access tenant data for legitimate support or operational purposes.

5. Data Retention

We retain your personal data for as long as necessary to:

  • Maintain your active account and provide contracted services
  • Comply with legal, tax, and regulatory obligations (typically 6 years under Nigerian law)
  • Resolve disputes and enforce our agreements

When you close your account, we will delete or anonymise your personal data within 90 days, except where retention is required by law or legitimate business interest. Client data you have uploaded to the platform will be deleted within 30 days of account closure unless you request an earlier deletion.

6. Data Security

We implement comprehensive technical and organisational security measures:

  • Encryption: All data transmitted over HTTPS/TLS. Database encryption at rest via Supabase.
  • Access Controls: Role-based access control (RBAC) with principle of least privilege. Multi-factor authentication available.
  • Row-Level Security: Database-level policies ensuring tenant data isolation.
  • CSRF Protection: All state-changing API endpoints protected against cross-site request forgery.
  • Webhook Security: HMAC-SHA512 verification for all incoming webhooks.
  • Rate Limiting: API rate limiting to prevent brute force and abuse.
  • Security Audits: Regular security assessments and vulnerability management. Our platform holds a 9/10 security rating.
  • Incident Response: We have procedures to detect, report, and investigate data breaches. We will notify affected users within 72 hours of becoming aware of a breach.

7. Your Rights

You have the following rights regarding your personal data:

RightWhat it means
AccessRequest a copy of all personal data we hold about you
RectificationRequest correction of inaccurate or incomplete data
ErasureRequest deletion of your data ("right to be forgotten")
RestrictionRequest that we limit how we process your data
PortabilityReceive your data in a structured, machine-readable format
ObjectionObject to processing based on legitimate interests or for direct marketing
Withdraw ConsentWithdraw any consent given at any time, without affecting prior processing

To exercise any of these rights, contact us at privacy@itsaglobal.tech. We will respond within 30 days. We may need to verify your identity before processing your request. There is no charge for most requests, but we may charge a reasonable fee for manifestly unfounded or excessive requests.

8. WhatsApp Business Policy Compliance

Our use of WhatsApp Business API complies with the Meta WhatsApp Business Policy and Meta Commerce Policy. Specifically:

  • We only send messages to users who have provided explicit opt-in consent.
  • Every WhatsApp message from us includes a clear way to opt out.
  • We do not use WhatsApp to send unsolicited bulk marketing messages.
  • We do not use WhatsApp to send prohibited content including spam, misleading information, or content that violates Meta's policies.
  • Message templates are pre-approved by Meta before use.
  • We maintain records of all opt-ins as required by Meta's policies.
  • Users can opt out at any time by replying STOP to any of our WhatsApp messages or contacting us directly.

9. Cookies Policy

We use the following types of cookies:

Cookie TypePurposeDuration
Essential / SessionAuthentication and security (required)Session / 7 days
FunctionalRemembering your preferences and settings30 days
AnalyticsUnderstanding how the platform is used (anonymised)90 days
MarketingOnly with your explicit consent30 days

You can control cookies through your browser settings. Disabling essential cookies will affect your ability to log in and use the platform. Analytics and marketing cookies can be disabled without affecting core functionality.

10. Children's Privacy

Our services are intended for businesses and individuals aged 18 years and above. We do not knowingly collect personal data from children under 18. If we become aware that a child under 18 has provided us with personal data, we will delete such data promptly. If you believe a child has provided their data to us, please contact us immediately at privacy@itsaglobal.tech.

11. International Data Transfers

Your data may be transferred to and processed in countries outside Nigeria, including the United States and the European Union, by our service providers listed in Section 4.1. We ensure that such transfers are protected by appropriate safeguards, including standard contractual clauses and data processing agreements with our service providers.

12. Third-Party Links

Our platform may contain links to third-party websites or services. This Privacy Policy applies only to ITSA Global Technologies' platforms. We are not responsible for the privacy practices of third-party sites. We encourage you to review the privacy policies of any third-party services you access.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page
  • Send an email notification to all registered account holders
  • Display a prominent notice on our platform for 30 days

Your continued use of our services after any changes constitutes your acceptance of the updated Privacy Policy.

14. Governing Law

This Privacy Policy is governed by the laws of the Federal Republic of Nigeria, including the Nigeria Data Protection Regulation (NDPR) 2019 and the Nigeria Data Protection Act (NDPA) 2023. Any disputes will be resolved in the courts of Oyo State, Nigeria.

15. Contact Us

For any privacy-related questions, requests, or complaints, please contact us:

ITSA Global Technologies Limited
📍 Suite D-10, Railway Shopping Complex, Dugbe, Ibadan, Oyo State, Nigeria
⏰ Response within 30 business days

If you are not satisfied with our response, you have the right to lodge a complaint with the Nigerian Data Protection Commission (NDPC) at ndpc.gov.ng.

© 2026 ITSA Global Technologies Limited. All rights reserved.