Trust
Privacy Policy & Data Privacy Notice
At ANAKALICE DIGITAL LIMITED, we design, build and operate digital products, provide technology and digital services, and deliver creative and media solutions.
When you visit our website, contact us, request a service, submit information through one of our forms, work with us, or otherwise interact with our digital platforms, you may provide us with information that relates to you.
We take that responsibility seriously.
This Privacy Policy explains what personal data we collect, why we collect it, how we use it, when we may share it, how we protect it, how long we keep it, and the choices and rights available to you.
It is written to be understandable because privacy information should not require a law degree to read.
This notice is intended to operate in accordance with the Nigeria Data Protection Act 2023 (NDPA) and applicable guidance and directives issued by the Nigeria Data Protection Commission (NDPC).
1. Who We Are
The organisation responsible for the processing of your personal data under this Privacy Policy is:
ANAKALICE DIGITAL LIMITED
Country: Nigeria
Location: Abuja, FCT, Nigeria
Website: anakalicedigital.com
Privacy contact: info@anakalicedigital.com
For the purposes of applicable Nigerian data protection law, our role may vary depending on what we are doing with personal data.
For example, we may act as a data controller when we determine why and how personal data is processed for our own business operations.
Where we process personal data strictly on behalf of a client under that client's instructions, we may instead act as a data processor.
That distinction matters because responsibility for personal data depends on the particular processing activity.
2. What Personal Data Do We Collect?
We do not collect personal data simply because it is available.
The information we collect depends on how you interact with us.
Information you provide directly
This may include:
- full name;
- email address;
- telephone number;
- company or organisation name;
- job title or professional information;
- billing and transaction information;
- information you provide when requesting a quotation;
- information contained in messages, enquiries or project briefs;
- information you provide when applying for an opportunity;
- information contained in documents you voluntarily send to us; and
- any other information you choose to provide.
Information collected when you use our website
Depending on how our website is configured, we may collect technical or usage information such as:
- IP address;
- browser type;
- device type;
- operating system;
- pages visited;
- approximate location derived from technical information;
- referring website;
- interaction with website features; and
- information collected through cookies or similar technologies.
We only use these technologies for purposes for which they are permitted under applicable law and, where consent is required, we will seek it.
Information received from other sources
We may sometimes receive personal data from another person or organisation.
For example, a client may provide contact information for a project, or a business partner may introduce us to a prospective client.
Where another party provides personal data to us, we expect the party providing it to have an appropriate lawful basis for doing so.
3. We Try to Collect Only What We Need
A person's personal data is not a raw material that should be collected endlessly.
We aim to follow the principle of data minimisation.
This means we seek to collect information that is relevant and reasonably necessary for the particular purpose for which we are processing it.
For example, if you contact us to discuss a website project, we may need your name, contact details and information about your business.
We would not ordinarily need unrelated personal information simply because we could ask for it.
4. Why Do We Use Your Personal Data?
The reason we use your information depends on your relationship with us and the service involved.
We may process personal data to:
Provide our services
We may use information to:
- understand your requirements;
- prepare proposals and quotations;
- communicate with you about a project;
- deliver technology, digital or media services;
- manage projects and client relationships;
- provide technical support;
- administer accounts or digital platforms; and
- fulfil our contractual obligations.
Respond to enquiries
If you contact us through our website, email, social media or another channel, we may use the information you provide to respond to you and manage the enquiry.
Manage our business
We may process information for purposes such as:
- invoicing and payments;
- accounting;
- maintaining business records;
- managing suppliers and contractors;
- internal administration;
- protecting our systems and services; and
- complying with legal and regulatory obligations.
Improve our services and website
We may analyse information about how our website and services are used so that we can identify problems, improve performance, understand what users find useful and make better decisions about our digital products.
Where analytics or similar technologies involve personal data, we will process that information in accordance with applicable data protection requirements.
Marketing and communications
Where permitted by law, we may use your contact information to send information about our services, products, events, publications or other business updates.
Where consent is required, we will ask for it.
You can also object to direct marketing or unsubscribe from marketing communications.
Choosing not to receive marketing messages will not prevent you from receiving important communications relating to a service or transaction you have with us.
5. What Makes Our Processing Lawful?
The NDPA does not require a company to obtain consent for every single use of personal data.
Depending on the circumstances, we may rely on one or more lawful bases recognised under Nigerian data protection law.
These may include:
Consent
Where we ask for your consent, we will explain what you are agreeing to and what the consent relates to.
You can withdraw consent where applicable.
Contract
We may process information where it is necessary to enter into or perform a contract with you, or to take steps at your request before entering into a contract.
Legal obligation
We may process information where we are required to do so by law.
This can include legal, accounting, tax, regulatory or compliance requirements.
Legitimate interests
We may process information where it is necessary for our legitimate interests or those of another party, provided those interests do not override your fundamental rights, freedoms or interests protected by law.
Examples may include maintaining the security of our systems, managing business relationships, preventing misuse of our services and improving our operations.
We do not treat "legitimate interests" as a blank cheque to use personal data however we want. The processing must still be lawful, fair, necessary and proportionate.
Vital interests
In limited circumstances, personal data may be processed where necessary to protect the vital interests of you or another person.
Public interest or official authority
Where applicable, personal data may be processed where necessary for a task carried out in the public interest or under official authority recognised by law.
The NDPA expressly recognises these lawful bases for processing.
6. What We Do Not Do
We do not sell your personal information as a commercial product.
We also do not collect personal data for purposes that are unrelated to the reason it was obtained without a lawful basis for doing so.
Where we intend to use information for a new purpose that is materially different from the original purpose, we will consider whether that further processing is lawful and whether additional information or consent is required.
7. Who May Receive Your Personal Data?
We may need to disclose personal data to other parties to operate our business or deliver a service.
Depending on the circumstances, these may include:
- technology and software providers;
- cloud and hosting providers;
- email and communication providers;
- payment service providers;
- professional advisers;
- accountants, auditors or legal advisers;
- contractors and service providers working on our behalf;
- business partners where disclosure is necessary for a particular service; and
- government, regulatory or law-enforcement authorities where disclosure is legally required.
We do not give third parties unrestricted access to personal information.
Where another organisation processes personal data on our behalf, we seek to ensure that appropriate contractual, technical and organisational safeguards are in place.
8. Third-Party Services and Technology
Modern digital services rarely operate entirely on one company's own servers.
We may use third-party technology to provide functions such as:
- website hosting;
- cloud infrastructure;
- email;
- analytics;
- payment processing;
- customer communication;
- security;
- form submissions;
- project management; and
- other business or technical functions.
These providers may process personal data as part of providing their services.
Where applicable, their own privacy policies and terms may also apply.
We aim to select providers that provide appropriate privacy and security safeguards and to configure our services in a way that limits unnecessary collection or disclosure of personal information.
Important: We will maintain an internal record of the specific providers we use and update this section or our supporting privacy documentation when material changes occur.
9. International Transfers of Personal Data
Some of the technology providers we use may operate outside Nigeria.
This means that personal data may, depending on the service, be stored or processed in another country.
Where personal data is transferred outside Nigeria, we will take steps required by applicable Nigerian data protection law to ensure that the transfer is lawful and that appropriate safeguards are in place.
The fact that a service provider is based outside Nigeria does not remove our responsibility to consider how your personal data is protected.
10. How We Protect Your Personal Data
No internet system can honestly be described as completely risk-free.
However, that does not mean security should be treated casually.
We use appropriate technical and organisational measures designed to protect personal data against risks such as:
- unauthorised access;
- accidental loss;
- destruction;
- alteration;
- unauthorised disclosure; and
- other forms of unlawful or unauthorised processing.
Depending on the nature of the system and information involved, these measures may include:
- access controls;
- authentication mechanisms;
- encryption or secure transmission where appropriate;
- secure hosting configurations;
- software and security updates;
- backups;
- monitoring and logging;
- restricted administrative access;
- staff or contractor confidentiality obligations; and
- procedures for responding to security incidents.
The exact security measures may vary depending on the nature and risk of the processing.
We do not publish sensitive security details that could make our systems easier to attack.
11. How Long Do We Keep Your Data?
We do not keep personal data forever simply because storage is cheap.
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, unless a longer period is required or permitted by law.
The appropriate retention period depends on the type of information and why we need it.
For example:
- client and transaction records may need to be retained for accounting, contractual or legal purposes;
- project information may be retained for as long as reasonably necessary to provide the service and manage the business relationship;
- marketing information may be retained until you withdraw consent or object where applicable; and
- technical logs may be retained for a limited period for security, troubleshooting and operational purposes.
When personal data is no longer required, we will take reasonable steps to securely delete it, anonymise it or otherwise dispose of it in accordance with our retention practices.
12. Your Data Protection Rights
Depending on the circumstances and applicable law, you may have rights including the right to:
- know how your personal data is being processed;
- request access to your personal data;
- request correction of inaccurate information;
- request erasure of personal data;
- request restriction of processing;
- object to certain processing;
- withdraw consent where processing is based on consent;
- request data portability where the right applies;
- object to certain automated decision-making; and
- lodge a complaint with the Nigeria Data Protection Commission.
We explain these rights in more detail on our Your Data Rights page.
These rights are important, but they are not all absolute. In certain circumstances, applicable law may allow or require us to continue processing particular information.
13. Children's Privacy
Our services are primarily intended for businesses, professionals, organisations and other users who can lawfully engage with our services.
We do not knowingly collect personal data from children for purposes that are not appropriate or lawful.
Where a service is directed at children or involves children's personal data, additional safeguards may apply.
If you believe that a child has provided us with personal data in circumstances where this should not have happened, please contact us so that we can investigate and take appropriate action.
14. Cookies and Similar Technologies
Our website may use cookies and similar technologies.
Some cookies are necessary for the website to function properly. Others may help us understand website usage, remember preferences, improve performance or support other functionality.
Where applicable, we will provide appropriate information and choices regarding non-essential cookies.
You can also manage cookies through your browser settings, although disabling certain cookies may affect how some parts of the website function.
Where we use analytics, advertising or other technologies that involve additional processing of personal data, the relevant processing will be subject to applicable legal requirements.
See our Cookie Notice for more detail.
15. Direct Marketing
We do not believe that giving us your email address means you have agreed to receive an endless stream of promotional messages.
Where we send direct marketing, we will do so on a lawful basis and provide an appropriate way to stop receiving it.
You can unsubscribe from marketing communications at any time by using the unsubscribe mechanism provided in the message or by contacting us.
We may still send essential service-related communications where necessary.
16. When We Are Working for a Client
Anakalice Digital may build or operate technology systems for clients that involve personal data belonging to the client's customers, employees, candidates, users or other individuals.
In those circumstances, the client may be the data controller and Anakalice Digital may act as the data processor.
For example, if we build a platform for a company and that company collects customer information through the platform, the company may determine why that customer information is collected and how it should be used.
Our responsibilities in such circumstances will be governed by the relevant contract, applicable data protection law and the client's lawful instructions.
If you are a user of one of our client's platforms, your first point of contact for questions about why the client collects your information may therefore be the client itself.
This distinction is particularly important because being the company that builds or hosts a system does not automatically make us the controller of every piece of personal data processed through that system.
17. Data Breaches and Security Incidents
We maintain procedures for identifying, assessing and responding to personal data breaches and other security incidents.
Where a breach occurs, we will assess the nature and severity of the incident and take the steps required under applicable Nigerian data protection law, including notification to the relevant authority and/or affected individuals where legally required.
Our objective is not merely to respond after something goes wrong but to reduce the likelihood and potential impact of incidents through appropriate security and governance measures.
18. Changes to This Privacy Policy
Our business, technology and legal obligations may change.
We may therefore update this Privacy Policy from time to time.
When we make material changes, we will take reasonable steps to draw attention to them, particularly where the change affects how we use personal data.
The "Last updated" date at the top of this page indicates when the policy was most recently revised.
We encourage you to review this page periodically rather than assuming that the policy will remain unchanged forever.
19. How to Contact Us About Privacy
If you have a question, concern or request relating to your personal data, please contact:
ANAKALICE DIGITAL LIMITED
Privacy/Data Protection Email: info@anakalicedigital.com
Location: Abuja, FCT, Nigeria
Website: anakalicedigital.com
When making a data protection request, please provide enough information for us to understand what you are asking for and to reasonably verify your identity.
You do not need to use legal terminology.
Simply tell us what you want us to do with your information.
20. Your Right to Complain
We would prefer to resolve privacy concerns directly with you where possible.
If you believe that we have not handled your personal data appropriately, you can contact us and give us an opportunity to investigate.
You also have the right to complain to the Nigeria Data Protection Commission (NDPC), the regulator responsible for administering Nigeria's data protection framework.
You do not lose your right to complain simply because you first contacted us.
21. Our Approach to Privacy
Privacy should not begin when somebody clicks "Accept".
It should begin when a system is designed.
At ANAKALICE DIGITAL LIMITED, we aim to build privacy considerations into the way we collect, store, use and protect personal data.
That means asking a simple question before collecting information:
Do we actually need this?
If the answer is no, there is usually no good reason to collect it.
Where personal data is necessary, we aim to be clear about why we need it, use it only for legitimate purposes, protect it appropriately and respect the rights of the person behind the data.
That is the standard we want our own digital operations to meet, and the standard we aim to bring to the technology we build for others.
ANAKALICE DIGITAL LIMITED
Nigeria
Privacy Policy version: 1.0
Last reviewed: 9 August 2026