Privacy Policy
Mymofaz Solutions Ltd. Enterprise Data Governance & Protection Charter
At Mymofaz Solutions Limited (RC 6895964, incorporated in Nigeria) (“Mymofaz”, “we”, “us”, or “our”), safeguarding the privacy, confidentiality, and integrity of your corporate and personal information is foundational to how we build technology. This Privacy Policy comprehensively explains how we collect, store, process, transfer, and protect personal and enterprise data when you interact with our website (www.mymofazsolutions.com), use our AI consultation assistants, engage our digital transformation services, or access our proprietary venture studio platforms (including GetSureSpace and StyleSnap).
- 1. Categories of Information We Collect
We collect information in three primary categories: information you provide voluntarily, technical telemetry gathered automatically, and data exchanged during project delivery.
- Direct Inquiries & Contact Details: When you complete our contact forms, book technical consultations, or request proposals, we collect your full name, work email address, phone number, company organization, job title, and project specifications.
- Technical & Telemetry Data: When you navigate our platform, we automatically record server logs including your IP address, browser type and version, operating system, referring URL, pages viewed, time spent per module, and clickstream interaction data.
- AI Assistant Interactions: Queries, system prompt parameters, and conversation transcripts submitted to our on-site AI Assistant are processed to answer your technical questions, guide service discovery, and capture qualified project briefs.
- Commercial & Contractual Data: For retained clients, we collect billing details, corporate registration data, authorized signatory contacts, and Statement of Work (SOW) deliverables.
- 2. Lawful Bases for Processing (NDPA & GDPR)
We only process personal data when permitted by applicable data protection laws. Our legal grounds include:
- Performance of a Contract: Processing necessary to fulfill discovery agreements, engineering contracts, software maintenance SLAs, and client deliverables.
- Legitimate Business Interests: Operating, monitoring, and securing our digital infrastructure; preventing cybersecurity threats or fraudulent activity; and refining our service offerings.
- Consent: Where you have granted explicit consent, such as receiving technical newsletters or permitting non-essential analytical cookies.
- Legal Obligation: Complying with regulatory, tax, accounting, or law enforcement mandates.
- 3. How We Utilize Your Information
Mymofaz Solutions processes collected data strictly for defined operational objectives:
- To evaluate project scopes, architect technical proposals, and prepare accurate budget milestones.
- To deliver agile software development, autonomous AI workflows, and managed cloud deployments.
- To provide ongoing technical support, emergency incident remediation, and SLA uptime maintenance.
- To detect, investigate, and prevent malicious attacks, unauthorized repository access, or platform exploits.
- To communicate product updates, technological whitepapers, and operational announcements (with full opt-out options).
- 4. Artificial Intelligence & Prompt Data Handling
As a modern software and AI studio, we uphold strict standards regarding artificial intelligence and client data confidentiality:
- Zero Public Model Training: Any proprietary business requirements, architectural schematics, or confidential source code shared with Mymofaz Solutions is never fed into public foundation models (e.g. public OpenAI, Anthropic, or Google models) for general training.
- Isolated Enterprise Environments: All bespoke AI agent pipelines, Retrieval-Augmented Generation (RAG) vector stores, and automated agents built for clients reside in dedicated, access-controlled virtual private clouds (VPCs) with zero-retention API agreements.
- Assistant Telemetry: Conversations with our website AI Assistant are retained temporarily for quality assurance and qualified lead fulfillment, encrypted at rest.
- 5. Cookies, Local Storage & Tracking Technologies
- Strictly Essential Cookies: Critical for navigation, security token validation, load balancing, and anti-CSRF protection. These cannot be disabled without breaking website functionality.
- Performance & Analytics Cookies: Allow us to measure page visits, bounce rates, and navigation paths to optimize site responsiveness. All analytics are anonymized.
- Managing Your Preferences: You can review, update, or revoke cookie consent at any time via the in our website footer, or by adjusting your web browser settings.
- 6. Third-Party Disclosures & Sub-Processors
We do not sell, rent, or trade your personal information. We only share data with vetted third-party service providers who adhere to rigorous data processing agreements (DPAs):
- Cloud & Infrastructure Providers: Vercel Inc., Amazon Web Services (AWS), and Cloudflare for secure edge hosting, CDN delivery, and database backups.
- Communications & Calendaring: Enterprise email and scheduling platforms to coordinate technical stakeholder consultations.
- Legal & Regulatory Authorities: Only when strictly mandated by enforceable court orders, subpoenas, or statutory law.
- 7. International Data Transfers & Cross-Border Compliance
Mymofaz Solutions Ltd operates with distributed cloud infrastructure across Africa, the European Union, and international regions. When personal data is transferred across international borders, we ensure adequate protections are implemented in compliance with the Nigeria Data Protection Act 2023 and the EU GDPR:
- Utilization of EU Commission Standard Contractual Clauses (SCCs) and equivalent contractual safeguards for cross-border transfers.
- Transfers only to jurisdictions or recipients providing an adequate level of data protection, as required under Part VIII of the NDPA 2023.
- Enforcement of end-to-end transport encryption (TLS 1.3) and cryptographic isolation at rest (AES-256).
- 8. Enterprise Data Security & Encryption Standards
We implement defense-in-depth technical and organizational safeguards aligned with industry standards:
- All web traffic and API endpoints are encrypted in transit using Transport Layer Security (TLS 1.3).
- Static databases, backups, and user credentials are encrypted at rest with AES-256 encryption.
- Principle of Least Privilege (PoLP) and multi-factor authentication (MFA) are enforced across all internal engineering accounts.
- Continuous vulnerability scanning, automated CI/CD dependency security audits, and intrusion detection systems.
- 9. Data Retention & Disposal Schedule
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including contractual obligations, dispute resolution, and statutory accounting requirements.
- General inquiry records and consultation submissions: Retained for up to 24 months from last contact.
- Active client project files and audit logs: Retained for the duration of the engagement plus 7 years for statutory compliance.
- Upon expiration of the retention window, data is securely scrubbed using NIST-compliant cryptographic erasure.
- 10. Your Legal Rights as a Data Subject
Under the Nigeria Data Protection Act 2023 (NDPA), the EU General Data Protection Regulation (GDPR), and related global frameworks, you hold enforceable rights:
- Right of Access: Request a copy of the personal data we hold concerning you.
- Right to Rectification: Request correction of inaccurate, outdated, or incomplete records.
- Right to Erasure (“Right to be Forgotten”): Request deletion of your personal data where retention is no longer justified.
- Right to Restrict or Object to Processing: Object to processing grounded in legitimate interest, or restrict processing during an ongoing dispute.
- Right to Data Portability: Obtain your personal data in a structured, commonly used, and machine-readable format.
- Right to Withdraw Consent: Revoke previously granted consent at any time without affecting past lawful processing.
To exercise any of these rights, email our Data Protection desk directly at [email protected]. We respond to all verified Subject Access Requests (SARs) within thirty (30) days without charge. You also hold the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) at ndpc.gov.ng, or with your local data protection authority.
- 11. Protection of Children’s Privacy
Our website and technology services are exclusively aimed at adult professionals and commercial enterprises. We do not knowingly solicit or collect personal information from individuals under 18 years of age. If we discover that a minor has submitted personal information, we immediately purge the data from our repositories.
- 12. Amendments to this Policy
We may update this Privacy Policy periodically to reflect technological changes, regulatory amendments, or new service offerings. All revisions will be posted on this page with an updated “Effective Date.” Continued use of our website or services constitutes acknowledgment of the revised terms.
- 13. Data Protection Officer (DPO) & Contact Inquiries
If you have any questions, concerns, or formal grievances regarding our data handling practices or this Privacy Policy, please contact our Data Protection desk:
Data Protection Officer[email protected]Corporate Office & JurisdictionMymofaz Solutions Limited · RC 6895964 · Lagos, Nigeria