9nerz
9nerz

Privacy Policy

How 9nerz handles the personal data you and your organization put into the platform.

Effective: 1 September 2026. This policy explains what personal data 9nerz processes, why, on what legal basis, who we share it with, how long we keep it, and the rights you can exercise. It is written to meet the Nigeria Data Protection Act 2023 (NDPA) and the NDPC's General Application and Implementation Directive 2025 (GAID), and the EU/UK GDPR for customers and users in those regions.

1. Who we are

9nerz (“we”, “us”) operates the 9nerz hosted service. For personal data in your own account and billing records we are the data controller. For the content your organization puts into the platform — people, structure, tasks, tickets, messages and files — we act as a data processor on behalf of your organization, which is the controller of that content. Contact our data protection contact / DPO at privacy@9nerz.app.

2. What we collect

  • Account data: your name, work email, a securely hashed password, your role and organization membership, and sign-in metadata (last login, last active).
  • Organization content: the units, roles, reporting lines, tasks, comments, tickets, inbound and outbound email messages, and attachments your team creates or receives.
  • Support-email content: if your organization points a support address at 9nerz, the sender address, subject, body and attachments of inbound emails become ticket records.
  • Billing data: your billing email, plan and subscription state, and payment records. Card details are handled entirely by our payment processor — 9nerz never receives or stores your card number.
  • Operational logs: an audit trail of state-changing actions (who did what, when), plus error and diagnostic logs and standard request metadata such as IP address.

We do not run advertising or third-party analytics trackers. We do not knowingly collect data from anyone under 18 — 9nerz is a workplace tool.

3. Why we process it, and our legal basis

  • To provide the service (create your workspace, route tasks and tickets, send in-app and email notifications, show your audit trail) — performance of our contract with you / your organization.
  • To secure the platform (authentication, malware scanning of uploads, abuse prevention, isolating each organization's data) — our legitimate interest and legal obligation to keep the service safe.
  • To bill paid plans — performance of contract and our legal obligation to keep financial records.
  • To contact you about the service (verification codes, password resets, security notices, material changes to terms) — contract and legitimate interest.
  • Product or marketing email, if any — only with your consent, which you can withdraw at any time.

We do not sell personal data, and we do not use your organization's content to train external AI models.

4. Who we share it with (sub-processors)

We share data only with the processors needed to run the service, each under a data processing agreement:

  • Supabase — database, file storage and realtime, hosted on AWS in the EU (Ireland).
  • Vercel — application hosting and delivery (Dublin region).
  • Resend — transactional and notification email delivery (United States).
  • Paystack / Paddle — payment processing for paid plans. Where a Merchant-of-Record processor is used, it is the seller of record and handles applicable taxes.

We may also disclose data where required by law, to establish or defend legal claims, or in connection with a merger or acquisition (with notice to you).

5. International transfers

Your data is stored in the EU (Ireland) and is processed by some sub-processors in the United States. Where personal data of individuals in Nigeria, the EU or the UK is transferred outside those regions, we rely on an adequacy decision where one applies, or on standard contractual clauses and equivalent safeguards with the receiving processor, consistent with the NDPA and the GAID.

6. How long we keep it

  • Account and organization content: for as long as your organization's account is active.
  • After an organization is deleted: records are removed from active systems immediately; encrypted backups age out on a rolling schedule (currently within 30 days).
  • Billing and payment records: retained for the period required by applicable financial and tax law.
  • Audit and security logs: retained for the period stated in your plan, then rotated.

7. How we protect it

  • Every organization's data is isolated; no query path exposes one organization's data to another, and this is covered by an automated test suite.
  • Passwords are hashed; connected-mailbox credentials are encrypted at rest.
  • Transport is encrypted (HTTPS). Access to production data is limited to what is needed to operate the service.
  • Uploaded files are scanned and are not downloadable until they pass.
  • Inbound webhooks are signature-verified; payment events are processed idempotently.

8. Your rights

Subject to the NDPA and, where applicable, the GDPR, you have the right to access your personal data, correct it, have it deleted, restrict or object to processing, withdraw consent, and receive a portable copy. You also have the right to lodge a complaint with the Nigeria Data Protection Commission (ndpc.gov.ng) or your local supervisory authority.

How to exercise them:

  • Correct your details — edit your profile, or change your password, in the app.
  • Export your organization's data — an admin can download a full JSON copy from Admin → Settings → Your data.
  • Delete your organization — an admin can permanently delete the organization and all its records from the same screen.
  • Anything else — email privacy@9nerz.app. We respond without undue delay and within 30 days. If we act for your organization as a processor, we will forward your request to that organization's administrators.

9. Cookies and local storage

9nerz uses only strictly necessary cookies and browser storage — there are no advertising or analytics cookies, so no consent banner is required. Specifically:

  • nerz_session, nerz_role, nerz_sa — keep you signed in and remember which console you are in.
  • A short-lived signup cookie — holds an unverified signup until you enter the emailed code.
  • Local storage keys (nerz_token, nerz_refresh_token, cached profile) — hold your session tokens and a copy of your own profile so the app loads quickly.

Clearing your browser storage signs you out; the app works with none of it pre-set.

10. Data breaches

If a personal-data breach occurs that is likely to result in a risk to individuals, we will notify the NDPC within 72 hours of becoming aware of it where required, and inform affected organizations and users without undue delay.

11. Changes

We will post any material change here and, where it affects you, tell you by email before it takes effect. The “Effective” date above always reflects the current version.

12. Contact

Privacy questions and data-subject requests: privacy@9nerz.app.