How we handle personal data under Nigerian data protection law — as a business, and as a processor acting for our clients.
Zionstand Digital Technologies (“ZDT”), operating the STAXIS managed service, is based in Lagos, Nigeria. We handle personal data in two capacities:
We aim to align with the Nigeria Data Protection Regulation (NDPR) 2019 and the Nigeria Data Protection Act (NDPA) 2023, as administered by the Nigeria Data Protection Commission (NDPC).
We do not sell personal data. We share it only with processors needed to run the service — for example payment processing, email delivery, hosting, and the productivity platforms we manage on your behalf. Each is expected to provide protections consistent with this statement.
We keep personal data only as long as needed for the purpose collected, or as required by law. Account and billing records are retained for the statutory period; support and audit records are retained while they remain operationally relevant and then deleted or anonymised.
Subject to law, you may exercise the following rights free of charge:
To exercise any of these, email staxis@zionstand.com. We aim to respond within 30 days. If a request is made on behalf of a client whose systems we manage, we will refer it to that client as the controller.
If we become aware of a personal data breach, we investigate immediately, contain it, and notify affected clients without undue delay, along with the regulator where the law requires it. Clients receive the facts we have, the impact, and the remediation steps taken.
Where we act as a processor, we can enter a Data Processing Agreement setting out scope, instructions, security measures, sub-processors, and breach obligations. Formal NDPR compliance reporting is also available as an add-on for managed clients.
For any data protection question, or to request our DPA, email staxis@zionstand.com or get in touch. You also have the right to lodge a complaint with the Nigeria Data Protection Commission.