Privacy Policy

How ConfiShare collects, uses, discloses, and protects personal data when you use our platform.

Zero-knowledge encryptionLast updated: 16 September 2026
On this page

This Privacy Policy explains how ConfiShare Limited (“ConfiShare”, “we”, “us”, or “our”), the operator of the confishare.io platform and related applications (together, the “Service”), collects, uses, discloses, and protects personal data when you visit our website, create an account, or otherwise use the Service. This Policy applies to individual users, and to businesses and their authorised team members who access the Service under a Company Plan (each a “User”, “you”, or “your”).

We are committed to protecting your privacy and to processing personal data in accordance with the Nigeria Data Protection Act, 2023 (“NDPA”), the regulations and guidance issued by the Nigeria Data Protection Commission (“NDPC”), and, where applicable to Users located outside Nigeria, other applicable data protection laws.

By using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, please do not use the Service.

1

Definitions

1.1

For the purposes of this Policy, the following terms have the meanings given to them under the NDPA:

  • (a)“Personal Data” means any information relating to an individual who is or can be identified, directly or indirectly, by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to that individual;
  • (b)“Processing” means any operation performed on Personal Data, including collection, recording, storage, use, disclosure, transmission, or erasure;
  • (c)“Data Subject” means the individual to whom Personal Data relates;
  • (d)“Data Controller” means a person who alone, or jointly with others, determines the purposes and means of processing Personal Data; and
  • (e)“Data Processor” means a person who processes Personal Data on behalf of, and on the instructions of, a Data Controller.
1.2

In respect of Personal Data that you provide to us directly to create and operate your own account (such as your name, email address, and billing details), we act as a Data Controller. In respect of the content of files you upload and share through the Service, and any Personal Data contained within those files, we act as a Data Processor on behalf of you (or, where you use the Service under a Company Plan, on behalf of your employer or organisation), who remains the Data Controller of that content. Where our business customers require a data processing agreement to govern this relationship, our Data Processing Agreement (available on request) applies in addition to, and takes precedence over, this Policy in respect of that content.

2

Personal Data We Collect

2.1

We collect the following categories of Personal Data:

CategoryExamplesSource
Account dataFull name, email address, password (stored in hashed form), company nameProvided by you on registration
Billing dataBilling name and address, payment card details (processed by our payment processor; we do not store full card numbers), transaction historyProvided by you; generated on payment
File metadataFile name, file size, file type, upload date, expiry date, access/download logs, recipient email addresses — never the content of the file itself, which is encrypted on a zero-knowledge basisGenerated automatically when you use the Service
Usage dataPages visited, features used, IP address, device identifiers, browser type, referral source, timestampsCollected automatically via cookies and similar technologies
Device and technical dataOperating system, device type, app version, crash logs, general location inferred from IP addressCollected automatically from our desktop and mobile applications
Communications dataRecords of correspondence when you contact our support team, survey responses, marketing preferencesProvided by you
Team/organisation dataNames and email addresses of team members invited to a Company Plan workspace, roles and permissions assignedProvided by the Company Plan administrator
2.2

We do not intentionally collect sensitive Personal Data (such as health, biometric, or genetic data, or data revealing racial or ethnic origin, religious belief, or political opinion) about our Users, save where such data may be contained within the encrypted files that Users choose to upload, over which we have no visibility or control due to our zero-knowledge architecture, as described in Clause 5.

3

How We Collect Personal Data

3.1

We collect Personal Data:

  • (a)directly from you, when you create an account, subscribe to a paid plan, upload or share a file, invite a team member, or contact our support team;
  • (b)automatically, through cookies, log files, and similar tracking technologies when you use our website or applications, as described in Clause 8; and
  • (c)from third parties, including our payment processor (confirmation of successful payment), and, where you sign up using a third-party single sign-on provider, basic profile information from that provider.
4

How We Use Personal Data and Our Legal Basis

4.1

We process Personal Data only where we have a lawful basis to do so under the NDPA. The table below sets out our principal processing purposes and the corresponding legal basis relied upon.

PurposeLegal Basis (NDPA)
Creating and administering your account, and providing the core features of the Service (upload, share, encrypt, track, and revoke files)Performance of a contract with you
Processing payments and managing subscriptions, invoicing, and free trial conversionPerformance of a contract with you; legal obligation (tax and accounting records)
Sending service-related communications (security alerts, access notifications, expiry reminders, changes to this Policy or our Terms of Use)Performance of a contract with you; legitimate interest in keeping you informed
Sending marketing communications about new features, offers, or productsConsent (which you may withdraw at any time)
Maintaining the security of the Service, detecting and preventing fraud, abuse, and unauthorised access, and enforcing our Terms of UseLegitimate interest in protecting the Service and our Users; legal obligation
Analysing usage trends to improve the Service, troubleshoot issues, and develop new featuresLegitimate interest in improving our product
Complying with applicable law, responding to lawful requests from public authorities, and establishing, exercising, or defending legal claimsLegal obligation; public interest
4.2

Where we rely on legitimate interest as our legal basis, we have assessed that our interest in the relevant processing is not overridden by your rights and freedoms as a Data Subject. You may object to processing carried out on this basis at any time, as set out in Clause 12.

5

Zero-Knowledge Architecture and File Content

5.1

The Service is built on a zero-knowledge encryption architecture. Files you upload are encrypted on your device (or immediately on upload) using AES-256 encryption before being stored on our servers. We do not hold the encryption keys required to decrypt the content of your files, and our personnel cannot, and do not, access, read, or scan the substantive content of files you upload or share in the ordinary course of providing the Service.

5.2

Because we cannot access file content, we are unable to identify whether a particular file contains Personal Data, and we cannot act as a Data Controller in respect of that content. If your file contains Personal Data relating to third parties (for example, the personal information of your clients, employees, or customers), you are responsible, as the Data Controller of that content, for ensuring you have a lawful basis to process and share that data through the Service, and for complying with your own obligations under the NDPA or any other applicable data protection law.

5.3

Notwithstanding Clause 5.1, we may be legally compelled, under a valid court order or other lawful process, to provide access to encrypted data in our possession; in such circumstances, we will only be able to provide the encrypted data itself, together with any metadata described in Clause 2, and not the decrypted content, save where you have voluntarily provided us with the means of decryption.

6

Disclosure and Sharing of Personal Data

6.1

We do not sell your Personal Data. We disclose Personal Data only in the following circumstances:

  • (a)to trusted third-party service providers who process Personal Data on our behalf and under our instructions (“Sub-Processors”), including cloud hosting and storage providers, payment processors, email and notification delivery providers, customer support tooling, and analytics providers, each of whom is bound by contractual confidentiality and data protection obligations;
  • (b)to the intended recipients of a file that you choose to share through the Service, to the extent necessary to enable access in accordance with the permissions you set;
  • (c)to your organisation's Company Plan administrator, where you access the Service as part of a team, to the extent necessary for account and workspace administration;
  • (d)where required to comply with applicable law, regulation, legal process, or a lawful request from the NDPC or another competent public authority;
  • (e)to protect the rights, property, or safety of ConfiShare, our Users, or the public, including to enforce our Terms of Use or investigate suspected fraud or security incidents; and
  • (f)in connection with a merger, acquisition, financing, reorganisation, or sale of all or part of our business or assets, subject to the acquiring party's agreement to honour the commitments made in this Policy.
6.2

We maintain a current list of our material Sub-Processors, which is available on request by emailing info@confishare.io.

7

International Data Transfers

7.1

Some of our Sub-Processors may be located, or may process Personal Data, outside Nigeria. Where we transfer Personal Data outside Nigeria, we do so only where the NDPA permits, including where: (a) the recipient jurisdiction is subject to a valid transfer mechanism recognised by the NDPC, or a decision confirming an adequate level of data protection; (b) appropriate safeguards, such as standard contractual clauses or binding corporate rules, have been put in place with the recipient; or (c) another exception under the NDPA applies, such as your explicit consent to the transfer.

8

Cookies and Similar Technologies

8.1

We use cookies, web beacons, and similar technologies to operate the Service, remember your preferences, keep you signed in, analyse traffic, and (where you have consented) deliver relevant marketing content. The categories of cookies we use are:

  • (a)Strictly necessary cookies, required for the Service to function (for example, session authentication) and which cannot be switched off;
  • (b)Performance and analytics cookies, which help us understand how the Service is used so we can improve it; and
  • (c)Functional and marketing cookies, which remember your preferences and, where you consent, support marketing communications.
8.2

You can control non-essential cookies through your browser settings or, where available, our cookie consent banner. Disabling certain cookies may affect the functionality of the Service.

9

Data Retention

9.1

We retain Personal Data only for as long as reasonably necessary to fulfil the purposes described in this Policy, including to provide the Service, comply with our legal and regulatory obligations (including tax and accounting record-keeping), resolve disputes, and enforce our agreements. In general:

  • (a)Account data is retained for as long as your account remains active, and for a period of up to the time stated in the package subscribed to, to allow for account recovery and to meet legal retention obligations;
  • (b)Files and associated file metadata are retained in accordance with the retention period applicable to your plan (as set out in our Terms of Use) or until you delete the file, whichever is earlier, after which files are permanently deleted from our active systems within a reasonable period, subject to residual copies in encrypted backups which are purged on a rolling basis; and
  • (c)Billing records are retained for the period required under applicable Nigerian tax and financial record-keeping laws.
10

Data Security

10.1

We implement technical and organisational measures designed to protect Personal Data against unauthorised access, loss, misuse, alteration, or destruction, including:

  • AES-256 encryption of files at rest and in transit, on a zero-knowledge basis;
  • multi-factor authentication support for account access;
  • role-based access controls restricting internal access to Personal Data on a need-to-know basis;
  • quarterly penetration testing and ongoing vulnerability management;
  • encrypted backups and disaster recovery procedures; and
  • logging and monitoring of access to production systems.
10.2

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for promptly notifying us of any suspected unauthorised access to your account.

11

Data Breach Notification

11.1

In the event of a Personal Data breach affecting your Personal Data, we will, where required under the NDPA, notify the NDPC within seventy-two (72) hours of becoming aware of the breach, and will notify affected Data Subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms. We maintain an internal breach register in accordance with our obligations under the NDPA.

12

Your Rights as a Data Subject

12.1

Subject to applicable law and any exemptions that may apply, you have the following rights in respect of your Personal Data:

  • (a)Right of access — to request confirmation of whether we process your Personal Data, and to obtain a copy of it;
  • (b)Right to rectification — to request correction of inaccurate or incomplete Personal Data;
  • (c)Right to erasure — to request deletion of your Personal Data, subject to our legal retention obligations;
  • (d)Right to restriction — to request that we limit the processing of your Personal Data in certain circumstances;
  • (e)Right to object — to object to processing carried out on the basis of legitimate interest, including for direct marketing;
  • (f)Right to data portability — to request your Personal Data in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible;
  • (g)Right relating to automated decision-making — to not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, save in permitted circumstances; and
  • (h)Right to withdraw consent — where processing is based on your consent, to withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
12.2

To exercise any of these rights, please contact us using the details in Clause 17. We will respond within the timeframe required under the NDPA. We may need to verify your identity before acting on your request. You also have the right to lodge a complaint with the NDPC if you believe our processing of your Personal Data infringes the NDPA.

13

Automated Decision-Making

13.1

We do not use your Personal Data to make decisions based solely on automated processing that produce legal or similarly significant effects concerning you. Our fraud and abuse detection systems may use automated flags, but any resulting account restriction is subject to human review upon request.

14

Children's Privacy

14.1

The Service is not directed at, and is not intended for use by, individuals under the age of 18. We do not knowingly collect Personal Data from children. If we become aware that we have inadvertently collected Personal Data from a child without appropriate consent, we will take steps to delete that data promptly.

15

Marketing Communications

15.1

Where you have consented to receive marketing communications from us, you may opt out at any time by using the unsubscribe link in any marketing email, or by contacting us at info@confishare.io. You will continue to receive transactional and service-related communications necessary for the operation of your account, even after opting out of marketing.

16

Changes to This Policy

16.1

We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will post the updated Policy on our website with a revised “Last Updated” date, and, where the changes are material, we will provide you with reasonable advance notice (such as by email or an in-app notice) before the changes take effect. Your continued use of the Service after the effective date of any update constitutes your acceptance of the revised Policy.

17

Data Protection Officer and Contact Information

17.1

If you have any questions, concerns, or requests regarding this Policy or our data processing practices, or if you wish to exercise any of the rights described in Clause 12, please contact our Data Protection Officer at: info@confishare.io

17.2

Where required by the NDPA on account of the scale or nature of our processing activities, we will register with the NDPC as a Data Controller or Data Processor of Major Importance and will appoint a qualified Data Protection Officer in accordance with the NDPA's requirements.

18

Governing Law

18.1

This Policy is governed by, and shall be construed in accordance with, the laws of the Federal Republic of Nigeria, including the NDPA.

Related document

Our Terms of Use set out the rights and responsibilities that govern your use of ConfiShare, including acceptable use, subscription plans, and liability.

Read the Terms of Use

Questions about this document?

Our team is happy to walk you through anything here, including requests to exercise your data protection rights.

info@confishare.io

Start Sharing Securely Today

Join thousands of teams protecting their sensitive files with ConfiShare. Enterprise-grade security, simple workflow, complete peace of mind.