On this page
This Privacy Policy explains how ConfiShare Limited (“ConfiShare”, “we”, “us”, or “our”), the operator of the confishare.io platform and related applications (together, the “Service”), collects, uses, discloses, and protects personal data when you visit our website, create an account, or otherwise use the Service. This Policy applies to individual users, and to businesses and their authorised team members who access the Service under a Company Plan (each a “User”, “you”, or “your”).
We are committed to protecting your privacy and to processing personal data in accordance with the Nigeria Data Protection Act, 2023 (“NDPA”), the regulations and guidance issued by the Nigeria Data Protection Commission (“NDPC”), and, where applicable to Users located outside Nigeria, other applicable data protection laws.
By using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, please do not use the Service.
Definitions
For the purposes of this Policy, the following terms have the meanings given to them under the NDPA:
- (a)“Personal Data” means any information relating to an individual who is or can be identified, directly or indirectly, by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to that individual;
- (b)“Processing” means any operation performed on Personal Data, including collection, recording, storage, use, disclosure, transmission, or erasure;
- (c)“Data Subject” means the individual to whom Personal Data relates;
- (d)“Data Controller” means a person who alone, or jointly with others, determines the purposes and means of processing Personal Data; and
- (e)“Data Processor” means a person who processes Personal Data on behalf of, and on the instructions of, a Data Controller.
In respect of Personal Data that you provide to us directly to create and operate your own account (such as your name, email address, and billing details), we act as a Data Controller. In respect of the content of files you upload and share through the Service, and any Personal Data contained within those files, we act as a Data Processor on behalf of you (or, where you use the Service under a Company Plan, on behalf of your employer or organisation), who remains the Data Controller of that content. Where our business customers require a data processing agreement to govern this relationship, our Data Processing Agreement (available on request) applies in addition to, and takes precedence over, this Policy in respect of that content.
Personal Data We Collect
We collect the following categories of Personal Data:
| Category | Examples | Source |
|---|---|---|
| Account data | Full name, email address, password (stored in hashed form), company name | Provided by you on registration |
| Billing data | Billing name and address, payment card details (processed by our payment processor; we do not store full card numbers), transaction history | Provided by you; generated on payment |
| File metadata | File name, file size, file type, upload date, expiry date, access/download logs, recipient email addresses — never the content of the file itself, which is encrypted on a zero-knowledge basis | Generated automatically when you use the Service |
| Usage data | Pages visited, features used, IP address, device identifiers, browser type, referral source, timestamps | Collected automatically via cookies and similar technologies |
| Device and technical data | Operating system, device type, app version, crash logs, general location inferred from IP address | Collected automatically from our desktop and mobile applications |
| Communications data | Records of correspondence when you contact our support team, survey responses, marketing preferences | Provided by you |
| Team/organisation data | Names and email addresses of team members invited to a Company Plan workspace, roles and permissions assigned | Provided by the Company Plan administrator |
We do not intentionally collect sensitive Personal Data (such as health, biometric, or genetic data, or data revealing racial or ethnic origin, religious belief, or political opinion) about our Users, save where such data may be contained within the encrypted files that Users choose to upload, over which we have no visibility or control due to our zero-knowledge architecture, as described in Clause 5.
How We Collect Personal Data
We collect Personal Data:
- (a)directly from you, when you create an account, subscribe to a paid plan, upload or share a file, invite a team member, or contact our support team;
- (b)automatically, through cookies, log files, and similar tracking technologies when you use our website or applications, as described in Clause 8; and
- (c)from third parties, including our payment processor (confirmation of successful payment), and, where you sign up using a third-party single sign-on provider, basic profile information from that provider.
How We Use Personal Data and Our Legal Basis
We process Personal Data only where we have a lawful basis to do so under the NDPA. The table below sets out our principal processing purposes and the corresponding legal basis relied upon.
| Purpose | Legal Basis (NDPA) |
|---|---|
| Creating and administering your account, and providing the core features of the Service (upload, share, encrypt, track, and revoke files) | Performance of a contract with you |
| Processing payments and managing subscriptions, invoicing, and free trial conversion | Performance of a contract with you; legal obligation (tax and accounting records) |
| Sending service-related communications (security alerts, access notifications, expiry reminders, changes to this Policy or our Terms of Use) | Performance of a contract with you; legitimate interest in keeping you informed |
| Sending marketing communications about new features, offers, or products | Consent (which you may withdraw at any time) |
| Maintaining the security of the Service, detecting and preventing fraud, abuse, and unauthorised access, and enforcing our Terms of Use | Legitimate interest in protecting the Service and our Users; legal obligation |
| Analysing usage trends to improve the Service, troubleshoot issues, and develop new features | Legitimate interest in improving our product |
| Complying with applicable law, responding to lawful requests from public authorities, and establishing, exercising, or defending legal claims | Legal obligation; public interest |
Where we rely on legitimate interest as our legal basis, we have assessed that our interest in the relevant processing is not overridden by your rights and freedoms as a Data Subject. You may object to processing carried out on this basis at any time, as set out in Clause 12.
Zero-Knowledge Architecture and File Content
The Service is built on a zero-knowledge encryption architecture. Files you upload are encrypted on your device (or immediately on upload) using AES-256 encryption before being stored on our servers. We do not hold the encryption keys required to decrypt the content of your files, and our personnel cannot, and do not, access, read, or scan the substantive content of files you upload or share in the ordinary course of providing the Service.
Because we cannot access file content, we are unable to identify whether a particular file contains Personal Data, and we cannot act as a Data Controller in respect of that content. If your file contains Personal Data relating to third parties (for example, the personal information of your clients, employees, or customers), you are responsible, as the Data Controller of that content, for ensuring you have a lawful basis to process and share that data through the Service, and for complying with your own obligations under the NDPA or any other applicable data protection law.
Notwithstanding Clause 5.1, we may be legally compelled, under a valid court order or other lawful process, to provide access to encrypted data in our possession; in such circumstances, we will only be able to provide the encrypted data itself, together with any metadata described in Clause 2, and not the decrypted content, save where you have voluntarily provided us with the means of decryption.
Disclosure and Sharing of Personal Data
We do not sell your Personal Data. We disclose Personal Data only in the following circumstances:
- (a)to trusted third-party service providers who process Personal Data on our behalf and under our instructions (“Sub-Processors”), including cloud hosting and storage providers, payment processors, email and notification delivery providers, customer support tooling, and analytics providers, each of whom is bound by contractual confidentiality and data protection obligations;
- (b)to the intended recipients of a file that you choose to share through the Service, to the extent necessary to enable access in accordance with the permissions you set;
- (c)to your organisation's Company Plan administrator, where you access the Service as part of a team, to the extent necessary for account and workspace administration;
- (d)where required to comply with applicable law, regulation, legal process, or a lawful request from the NDPC or another competent public authority;
- (e)to protect the rights, property, or safety of ConfiShare, our Users, or the public, including to enforce our Terms of Use or investigate suspected fraud or security incidents; and
- (f)in connection with a merger, acquisition, financing, reorganisation, or sale of all or part of our business or assets, subject to the acquiring party's agreement to honour the commitments made in this Policy.
We maintain a current list of our material Sub-Processors, which is available on request by emailing info@confishare.io.
International Data Transfers
Some of our Sub-Processors may be located, or may process Personal Data, outside Nigeria. Where we transfer Personal Data outside Nigeria, we do so only where the NDPA permits, including where: (a) the recipient jurisdiction is subject to a valid transfer mechanism recognised by the NDPC, or a decision confirming an adequate level of data protection; (b) appropriate safeguards, such as standard contractual clauses or binding corporate rules, have been put in place with the recipient; or (c) another exception under the NDPA applies, such as your explicit consent to the transfer.
Data Retention
We retain Personal Data only for as long as reasonably necessary to fulfil the purposes described in this Policy, including to provide the Service, comply with our legal and regulatory obligations (including tax and accounting record-keeping), resolve disputes, and enforce our agreements. In general:
- (a)Account data is retained for as long as your account remains active, and for a period of up to the time stated in the package subscribed to, to allow for account recovery and to meet legal retention obligations;
- (b)Files and associated file metadata are retained in accordance with the retention period applicable to your plan (as set out in our Terms of Use) or until you delete the file, whichever is earlier, after which files are permanently deleted from our active systems within a reasonable period, subject to residual copies in encrypted backups which are purged on a rolling basis; and
- (c)Billing records are retained for the period required under applicable Nigerian tax and financial record-keeping laws.
Data Security
We implement technical and organisational measures designed to protect Personal Data against unauthorised access, loss, misuse, alteration, or destruction, including:
- AES-256 encryption of files at rest and in transit, on a zero-knowledge basis;
- multi-factor authentication support for account access;
- role-based access controls restricting internal access to Personal Data on a need-to-know basis;
- quarterly penetration testing and ongoing vulnerability management;
- encrypted backups and disaster recovery procedures; and
- logging and monitoring of access to production systems.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for promptly notifying us of any suspected unauthorised access to your account.
Data Breach Notification
In the event of a Personal Data breach affecting your Personal Data, we will, where required under the NDPA, notify the NDPC within seventy-two (72) hours of becoming aware of the breach, and will notify affected Data Subjects without undue delay where the breach is likely to result in a high risk to their rights and freedoms. We maintain an internal breach register in accordance with our obligations under the NDPA.
Your Rights as a Data Subject
Subject to applicable law and any exemptions that may apply, you have the following rights in respect of your Personal Data:
- (a)Right of access — to request confirmation of whether we process your Personal Data, and to obtain a copy of it;
- (b)Right to rectification — to request correction of inaccurate or incomplete Personal Data;
- (c)Right to erasure — to request deletion of your Personal Data, subject to our legal retention obligations;
- (d)Right to restriction — to request that we limit the processing of your Personal Data in certain circumstances;
- (e)Right to object — to object to processing carried out on the basis of legitimate interest, including for direct marketing;
- (f)Right to data portability — to request your Personal Data in a structured, commonly used, machine-readable format, and to have it transmitted to another controller where technically feasible;
- (g)Right relating to automated decision-making — to not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, save in permitted circumstances; and
- (h)Right to withdraw consent — where processing is based on your consent, to withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, please contact us using the details in Clause 17. We will respond within the timeframe required under the NDPA. We may need to verify your identity before acting on your request. You also have the right to lodge a complaint with the NDPC if you believe our processing of your Personal Data infringes the NDPA.
Automated Decision-Making
We do not use your Personal Data to make decisions based solely on automated processing that produce legal or similarly significant effects concerning you. Our fraud and abuse detection systems may use automated flags, but any resulting account restriction is subject to human review upon request.
Children's Privacy
The Service is not directed at, and is not intended for use by, individuals under the age of 18. We do not knowingly collect Personal Data from children. If we become aware that we have inadvertently collected Personal Data from a child without appropriate consent, we will take steps to delete that data promptly.
Marketing Communications
Where you have consented to receive marketing communications from us, you may opt out at any time by using the unsubscribe link in any marketing email, or by contacting us at info@confishare.io. You will continue to receive transactional and service-related communications necessary for the operation of your account, even after opting out of marketing.
Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will post the updated Policy on our website with a revised “Last Updated” date, and, where the changes are material, we will provide you with reasonable advance notice (such as by email or an in-app notice) before the changes take effect. Your continued use of the Service after the effective date of any update constitutes your acceptance of the revised Policy.
Data Protection Officer and Contact Information
If you have any questions, concerns, or requests regarding this Policy or our data processing practices, or if you wish to exercise any of the rights described in Clause 12, please contact our Data Protection Officer at: info@confishare.io
Where required by the NDPA on account of the scale or nature of our processing activities, we will register with the NDPC as a Data Controller or Data Processor of Major Importance and will appoint a qualified Data Protection Officer in accordance with the NDPA's requirements.
Governing Law
This Policy is governed by, and shall be construed in accordance with, the laws of the Federal Republic of Nigeria, including the NDPA.
Related document
Our Terms of Use set out the rights and responsibilities that govern your use of ConfiShare, including acceptable use, subscription plans, and liability.
Read the Terms of UseQuestions about this document?
Our team is happy to walk you through anything here, including requests to exercise your data protection rights.
info@confishare.io