Privacy Policy

Last updated: June 6, 2026

1. Introduction

ComplianceAssess ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, services, and tools (collectively, the "Services"). Our Services include the NDPR & GDPR Compliance Self-Assessment Tool and Website Scanner.

This policy complies with the Nigeria Data Protection Regulation (NDPR) 2019 and the General Data Protection Regulation (GDPR) (EU) 2016/679.

2. Data Controller

The data controller responsible for your personal data is:

9jaoncloud NDPR/NDPC GDPR ComplianceAssess

Email: info@9jaoncloud.com.ng

Data Protection Officer: info@9jaoncloud.com.ng

Address: Oyo State Nigeria

Phone: +234(0)8144878297

3. Information We Collect

We collect several types of information from and about users of our Services:

3.1 Personal Information

  • Contact Information: Name, email address, company name, industry, and company size provided during registration or assessment
  • Assessment Data: Your responses to compliance assessment questions, calculated scores, and generated roadmaps
  • Scan Data: Website URLs you scan, scan results, and compliance reports
  • Communication Data: Information you provide when contacting us, such as your name and email address

3.2 Automatically Collected Information

  • Device and Usage Information: IP address, browser type, device type, operating system, pages visited, time spent on pages, and other diagnostic data
  • Cookies and Tracking Technologies: We use cookies and similar tracking technologies to collect information about your browsing activities and preferences
  • Log Data: Server logs including IP address, browser type, referring/exit pages, and date/time stamps

3.3 Images and Media

We use images, logos, and other media on our website. When you interact with these elements, we may collect usage data to understand how users engage with our content.

4. How We Use Your Information

We use the information we collect for various purposes in accordance with applicable data protection laws:

4.1 To Provide and Maintain Our Services

  • To process and deliver your compliance assessments and website scans
  • To generate and send your results and reports
  • To maintain and improve our Services
  • To provide customer support and respond to your inquiries

4.2 For Analytics and Improvement

  • To analyze usage patterns and trends to improve our Services
  • To test new features and functionalities
  • To monitor and analyze the performance of our website

4.3 For Marketing and Advertising

  • To send you marketing communications about our Services (with your consent)
  • To display targeted advertisements on third-party websites
  • To promote our Services through various marketing channels

4.4 For Legal and Security Purposes

  • To comply with legal obligations and regulations
  • To detect and prevent fraudulent activities
  • To protect the security and integrity of our Services
  • To enforce our Terms of Service

5. Legal Basis for Processing

We process your personal data based on the following legal bases under GDPR and NDPR:

5.1 Consent

We process your personal data with your explicit consent when you:

  • Register for an account or use our Services
  • Subscribe to our marketing communications
  • Accept cookies on our website

5.2 Contract Performance

We process your personal data necessary to perform our contract with you when you use our Services to receive compliance assessments and website scans.

5.3 Legitimate Interests

We process your personal data when necessary for our legitimate interests or those of third parties, provided that your interests and fundamental rights do not override those interests. This includes:

  • Analyzing usage patterns to improve our Services
  • Preventing fraud and ensuring security
  • Marketing our Services (where you have not opted out)

5.4 Legal Compliance

We process your personal data when necessary to comply with legal obligations, such as retaining records for regulatory purposes.

6. Data Sharing and Disclosure

We do not sell your personal data. We share your information only in the following circumstances:

6.1 Service Providers

We share your information with third-party service providers who perform services on our behalf, such as:

  • Hosting and Infrastructure: Cloud service providers who host our website and data
  • Analytics: Google Analytics and other analytics providers who help us understand how users interact with our Services
  • Advertising: Advertising networks who display ads on our behalf or on third-party websites
  • Email Delivery: Email service providers who deliver our communications

These service providers have access to your personal data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

6.2 Legal Requirements

We may disclose your information if required by law, court order, or other government authority, or if we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.

6.3 Business Transfers

If we are involved in a merger, acquisition, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you of any such transfer and provide you with choices regarding your information.

7. International Data Transfers

Your information may be transferred to and maintained on computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction.

If you are located in the European Economic Area (EEA) or Nigeria, your information may be transferred to countries that do not have the same data protection laws as your home country. We ensure that appropriate safeguards are in place to protect your personal data in accordance with applicable data protection laws when transferred internationally.

8. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of sensitive data in transit and at rest
  • Secure authentication and access controls
  • Regular security assessments and vulnerability testing
  • Employee training on data protection practices
  • Confidentiality agreements with third-party service providers

However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.

9. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements.

9.1 Retention Periods

  • Account Information: Retained while your account is active and for a reasonable period thereafter
  • Assessment and Scan Results: Retained for 2 years from the date of creation, However the Assessment result expires in 30 days
  • Marketing Communications: Retained until you unsubscribe or withdraw consent
  • Analytics Data: Retained for 26 months
  • Log Data: Retained for 30 days

9.2 Data Deletion

When we delete your personal data, we take reasonable steps to erase it from our systems and ensure it cannot be reconstructed. However, some residual copies may remain in our backup systems for a limited period for security and integrity purposes.

10. Your Rights Under GDPR and NDPR

Under GDPR and NDPR, you have the following rights regarding your personal data:

10.1 Right to Access

You have the right to request a copy of the personal data we hold about you. We will provide you with information about the categories of data we process, the purposes of processing, the categories of recipients, and the retention period.

10.2 Right to Rectification

You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.

10.3 Right to Erasure (Right to be Forgotten)

You have the right to request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected, or when you withdraw your consent.

10.4 Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or when the processing is unlawful.

10.5 Right to Data Portability

You have the right to receive the personal data you provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller where technically feasible.

10.6 Right to Object

You have the right to object to the processing of your personal data, particularly for direct marketing purposes.

10.7 Rights Related to Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

10.8 How to Exercise Your Rights

To exercise any of these rights, please contact us at info@complianceassess.com. We will respond to your request within 30 days in accordance with applicable data protection laws.

11. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to collect information about your browsing activities and preferences. Our use of cookies includes:

11.1 Essential Cookies

These cookies are necessary for the operation of our website and cannot be disabled. They include cookies that enable you to log in, use our Services, and ensure security.

11.2 Analytics Cookies

We use Google Analytics and other analytics services to understand how users interact with our website and Services. These cookies help us improve our Services and user experience.

11.3 Advertising Cookies

We use advertising cookies to display relevant advertisements to you on third-party websites and to measure the effectiveness of our advertising campaigns.

11.4 Cookie Consent

When you first visit our website, we will ask for your consent to use non-essential cookies. You can manage your cookie preferences at any time through our cookie consent banner or your browser settings.

12. Children's Privacy

Our Services are not intended for children under the age of 18. We do not knowingly collect personal data from children under 18. If we become aware that we have collected personal data from children under 18, we will take steps to delete that information.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The updated version will be indicated by a revised "Last updated" date and the updated version will be effective as soon as it is accessible. We encourage you to review this Privacy Policy frequently to stay informed about how we are protecting your personal data.

14. Contact Us

If you have any questions about this Privacy Policy, please contact us:

Email: info@9jaoncloud.com.ng

Data Protection Officer: info@9jaoncloud.com.ng

Address: Oyo State Nigeria

Phone: +234(0)8144878297

15. Regulatory Authorities

If you have concerns about how we handle your personal data, you have the right to lodge a complaint with the relevant data protection authority:

Nigeria: National Information Technology Development Agency (NITDA) / Nigeria Data Protection Commission. (NDPC)

European Union: Relevant data protection authority in your member state