Privacy & Data Protection
Version 1.0 (NDPA 2023 & GDPR)Effective: 15 September 2026

Privacy Policy.

How Davo Solutions Limited collects, uses and protects personal information, and the rights you have over it.

Privacy Inquiries
Compliant with NDPA 2023 & International Privacy Standards
Data Controller

Davo Solutions acts as data controller for corporate operations, inquiries, and client relationships.

Client Software

For custom apps built for clients, we act as data processor only. We never own or market end-user data.

No Data Selling

We never sell, rent, or trade personal data. Data is shared strictly with vetted operational vendors.

Your Rights

Under NDPA 2023 & GDPR, you have the right to access, correct, erase, restrict, or export your data anytime.

Preamble & Application

This policy explains what information we collect, why we need it, how we keep it safe, and what you can ask us to do with it. We have tried to write it in plain language. If anything is unclear, please ask us.

1

Who we are and what this policy covers

Overview of Davo Solutions Limited as a registered Nigerian software company and data controller for our corporate operations.

Davo Solutions Limited is a software development company registered in Nigeria. We design and build mobile applications, web applications, backend systems and blockchain solutions for businesses.

This policy explains what personal information we collect, why we collect it, how we look after it, and the choices you have. It applies when you:

• visit our website or any page we operate;

• contact us by email, phone, WhatsApp, a contact form or social media;

• request a quote, submit a project brief or book a discovery call;

• become a client of ours, or work for a company that is our client; or

• apply to work with us or supply services to us.

For the information described above, Davo Solutions is the data controller. That means we decide why and how it is used, and we are responsible for it.

Using an app we built for someone else? This policy is probably not the one you need. Section 5 explains why, and who to contact instead.

2

Information we collect

Direct contact details, business information, project briefs, and technical telemetry collected automatically.

2.2Information you give us

Most of what we hold is information you give us directly. Depending on how you deal with us, this can include:

• Contact details: your name, email address, phone number and, where relevant, your job title.

• Business details: your company name, address, industry and registration details.

• Project information: your requirements, ideas, designs, documents, timelines and budget, whether shared through a form, a proposal, an email or a call.

• Contract and billing details: the information needed to prepare agreements, raise invoices and receive payment. We do not store full card numbers; payments go through your bank or a payment provider.

• Communications: the messages, emails and meeting notes that pass between us.

• Recruitment information: if you apply to work with us, your CV, portfolio, references and anything else you choose to send.

2.3Information collected automatically

When you visit our website, some information is collected automatically by our servers and the tools we use to run the site:

• your IP address and approximate location, at the level of city or country;

• the type of browser and device you are using, and its operating system;

• the pages you view, how long you stay, and the website that referred you to us; and

• information stored in cookies and similar technologies, which section 10 explains.

This information does not usually identify you by name. We use it to understand how our site is used and to keep it secure.

2.4Information from other sources

Occasionally we receive information about you from someone else. For example, a colleague may introduce you to us, a client may give us your contact details because you are part of their project team, or we may look at publicly available business information such as a company website or a professional networking profile when preparing for a meeting.

We do not buy personal information from data brokers.

3

How we use your information

Delivering projects, customer communications, invoicing, relationship management, and security monitoring.

We use personal information only for purposes we have a genuine reason for. In practice, that means:

• Replying to you. Answering your questions, preparing proposals and estimates, and arranging calls.

• Delivering your project. Understanding your requirements, planning the work, sharing progress updates, running tests with you, handing over the finished work and providing support afterwards.

• Managing our relationship. Preparing and keeping contracts, sending invoices, receiving payment and keeping business records.

• Keeping you informed. Sending occasional updates about our services where you have agreed to receive them or where you are an existing client. Every marketing message includes a way to stop receiving them.

• Improving our website. Understanding which pages are useful, fixing problems and making the site faster and easier to use.

• Keeping things secure. Protecting our website, systems and your information from misuse, fraud and unauthorised access.

• Meeting our legal duties. Keeping records required by tax, company and other laws, and responding to lawful requests from authorities.

• Recruitment. Considering your application and contacting you about it.

We do not use your personal information to make decisions about you that are based solely on automated processing and that have a legal or similarly significant effect on you.

5

Software we build for our clients

Davo Solutions acts as a data processor for software built for clients; clients remain data controllers for their end-users.

A large part of our work is building software for other businesses: mobile apps, web platforms, payment and fintech systems, messaging tools and custom databases. The people who later use that software are our client's customers, not ours.

In that situation the roles are different:

• Our client is the data controller. They decide what information their product collects, why they collect it, and how long they keep it. Their own privacy policy governs it.

• Davo Solutions acts as a data processor, or does not handle the data at all. Where we do have access, for example while building, testing, migrating or supporting a system, we use it only to do the work our client has asked for and only on their documented instructions.

In practice, this means we make the following commitments:

• We do not own the end-user data held in software we build for clients.

• We do not sell it, share it for our own purposes, or use it to market to anyone.

• We do not combine it with our own data or with data from other clients.

• Where we can, we build and test using sample or anonymised data rather than real customer records.

• When our work is finished, we return or delete any client data we hold, as agreed with the client, unless the law requires us to keep it.

• We treat client source code, credentials, API keys, business information and databases as strictly confidential, and we limit access to the team members working on that project.

If you use an app or website that we built for one of our clients and you have a question about your data, please contact that company directly. They are responsible for your information and are best placed to help. If you contact us instead, we will pass your request to them where we can identify who they are.

6

Who we share information with

Strict sharing with vetted infrastructure providers, cloud hosting, and professional advisers; we never sell personal data.

We do not sell, rent or trade personal information. We share it only when there is a good reason, and only as much as is needed. The people we may share it with are:

• Service providers who help us run our business. These include email and collaboration services, cloud hosting, file storage, code hosting and version control, project management tools, video conferencing, website analytics and accounting software. They may only use the information to provide their service to us, and we choose providers who protect it properly.

• Contractors and specialists. Occasionally we bring in trusted freelance developers or designers to help deliver a project. They work under written confidentiality obligations and see only what they need for their part of the work.

• Professional advisers. Lawyers, accountants, auditors and insurers, where needed to run our business or protect our legal position.

• Authorities and regulators. Where we are required to by law, by a court order or by a lawful request from a government body, or where disclosure is needed to prevent fraud, protect someone's safety or defend a legal claim. Where the law allows, we will tell you first.

• A future owner of our business. If Davo Solutions is ever merged, sold or restructured, personal information may pass to the new owner, who must continue to protect it in line with this policy.

7

Transfers outside Nigeria

International data transfers guarded by adequate legal protections and standard contractual safeguards.

Some of the tools and service providers we rely on, such as cloud hosting and email services, store information on servers outside Nigeria. Some of our clients are also based abroad.

When personal information is transferred outside Nigeria, we take steps to make sure it remains protected to the standard Nigerian law requires. This can include using providers in countries with adequate data protection laws, relying on contractual protections, or transferring information where it is necessary to carry out a contract with you or where you have agreed to it.

8

How long we keep information

Defined retention windows for client project records, billing, marketing preferences, and job applications.

We keep personal information only for as long as we need it for the purpose we collected it for, including any legal, accounting or reporting requirements. As a general guide:

• Enquiries that do not become projects: up to two years from our last contact, in case you come back to us.

• Client project, contract and billing records: for the length of our relationship and up to six years after it ends, to meet tax and legal record-keeping duties and to deal with any claim.

• Marketing preferences: until you unsubscribe. After that we keep a short record of your email address only so we can make sure we do not contact you again.

• Website analytics: for no more than 26 months.

• Job applications: up to twelve months after the role is filled, unless you ask us to keep your details on file for longer or to delete them sooner.

When information is no longer needed, we delete it securely or anonymise it so it can no longer be linked to you.

9

How we protect your information

Enterprise-grade safeguards: encryption in transit, MFA, role-based access, and secret segregation.

We build secure systems for a living, and we apply the same care to our own. Our safeguards include:

• encrypted connections (HTTPS and TLS) for our website and the services we use;

• access to code repositories, staging environments and client systems limited by role, so people see only what their work requires;

• multi-factor authentication on key accounts, and prompt removal of access when someone leaves a project;

• keeping credentials, API keys and secrets out of source code and in secure storage;

• separating each client's projects, environments and data from every other client's; and

• confidentiality commitments from everyone who works with us.

No system connected to the internet can be guaranteed completely secure. If a personal data breach occurs that is likely to put your rights at risk, we will act quickly to contain it, notify the Nigeria Data Protection Commission as the law requires, and tell you without undue delay where the law requires us to or where it would help you protect yourself.

10

Cookies and similar technologies

Essential functional cookies and opt-in analytics cookies; no third-party cross-site advertising trackers.

Cookies are small text files that a website stores on your device. We use them in two ways:

• Essential cookies make the website work, for example keeping it secure and remembering your cookie choices. The site cannot function properly without them, so they do not require consent.

• Analytics cookies help us understand how visitors use the site, such as which pages are popular and where people leave. We only set these where you have agreed to them.

We do not use cookies to show you advertising on other websites. You can accept or decline non-essential cookies when you first visit, and you can also control or delete cookies through your browser settings. Blocking essential cookies may stop parts of the site from working.

11

Your rights

NDPA 2023 and GDPR rights including access, rectification, deletion, data portability, and regulatory complaints.

Under the Nigeria Data Protection Act 2023, and similar laws in other countries such as the GDPR in the European Union and United Kingdom, you have rights over your personal information. These include the right to:

• Access it. Ask whether we hold information about you and get a copy of it.

• Correct it. Ask us to fix information that is wrong or incomplete.

• Delete it. Ask us to erase your information where we no longer have a good reason to keep it.

• Restrict it. Ask us to pause using your information, for example while we check whether it is accurate.

• Object. Object to our use of your information where we rely on legitimate interests, and to direct marketing at any time.

• Take it with you. Ask for information you gave us in a commonly used electronic format, or ask us to send it to another organisation where this is technically possible.

• Withdraw consent. Where we rely on your consent, withdraw it whenever you like.

• Complain. Lodge a complaint with the Nigeria Data Protection Commission, or with the data protection authority in the country where you live.

11.2How to use your rights

Email us at enquiry@davosolutions.com and tell us which right you want to use. To protect your information, we may need to confirm your identity before acting on the request. We will respond within one month. If a request is complex, we may need longer; if so, we will tell you why and how long it will take.

Using your rights is free. We may only charge a reasonable fee, or decline, where a request is clearly unfounded or excessive, and we will explain our reasons if we do.

Some rights have limits. For example, we may need to keep certain records to meet a legal obligation even after you ask us to delete them. If we cannot do what you ask, we will explain why.

We would always appreciate the chance to put things right first, so please contact us before going to the regulator if you are unhappy with how we have handled your information.

12

Marketing and how to opt out

Opt-in email communications with straightforward one-click unsubscribe mechanisms.

We send marketing emails only to people who have asked to receive them, or to existing clients about services similar to the ones they already use from us. We keep it occasional and relevant.

You can stop marketing messages at any time by using the unsubscribe link in any email, or by emailing Davosolutionsltd@gmail.com. Opting out of marketing does not stop us sending you messages we need to send about a project or service you are using.

13

Children

Enterprise B2B services strictly intended for individuals 18 years of age or older.

Our website and services are intended for businesses and adults. We do not knowingly collect personal information from anyone under the age of 18. If you believe a child has given us their information, please contact us and we will delete it.

15

Changes to this policy

Transparent notification protocols for policy revisions and version tracking.

We may update this policy from time to time, for example to reflect changes in the law or in how we work. The date at the top shows when it was last changed.

If we make a significant change, we will make it clear on our website and, where we have a relationship with you, let you know directly by email before the change takes effect.

16

How to contact us

Direct channels to reach our compliance and data protection team in Enugu, Nigeria.

If you have any question about this policy or about how we handle your information, or if you want to use any of your rights, please get in touch:

Company: Davo Solutions Limited

Email: enquiry@davosolutions.com

Phone: +234 916 001 2046

Address: No. 1 New Haven Junction, New Haven, Enugu, Enugu State, Nigeria

If you are not satisfied with our response, you have the right to complain to the Nigeria Data Protection Commission, which is the authority responsible for data protection in Nigeria.

Privacy & Data Protection ContactDavo Solutions Limited

Questions about your data or rights?

Our compliance team handles all personal data inquiries, subject access requests (SARs), and data portability questions directly. We reply within 30 days without fee.

+234 916 001 2046
No. 1 New Haven Junction, New Haven, Enugu, Enugu State, Nigeria
Privacy Policy | Davo Solutions Limited