Privacy notice
Last updated: 14 August 2026This notice explains how Teasoo Consulting handles personal data in Teasoo SET, and the rights you have. We follow the EU General Data Protection Regulation (GDPR) and the Nigeria Data Protection Act 2023 (NDPA).
Who is responsible for your data
There are two situations:
- When your organisation uses Teasoo SET. Your organisation decides how its people and stakeholder data are used, so your organisation is the data controller and we are the data processor acting on its instructions. If you want to know how your organisation uses your data, please ask them.
- For our own account and enquiry data (for example when you contact us, or as the holder of an account), Teasoo Consulting is the data controller.
Our Data Protection Officer is Efeosasere Okoro. You can contact them at efeosasere.okoro@teasooconsulting.com.
What data we handle
- Account data: your name, email address, role, and the organisation you belong to.
- Stakeholder data your organisation enters: such as names, organisations, notes, engagement history, commitments, risk and sentiment.
- Technical data: sign-in records and basic logs we need to run and secure the service.
Why we handle it, and our legal basis
- To provide the service under our contract with your organisation. Lawful basis: GDPR Article 6(1)(b); NDPA, performance of a contract.
- To keep the service secure and working properly. Lawful basis: our legitimate interests; NDPA, legitimate interest.
- To meet legal obligations, where they apply.
We do not sell your data, and we do not use it for advertising.
Who we share it with
We use a small number of trusted providers to run the service. They only process data to provide their service to us, under contract:
- Supabase: database and sign-in hosting.
- Vercel: application hosting.
- Brevo: sending emails such as invitations and reminders.
We don't share your data with anyone else unless the law requires it.
Where your data is processed
Our providers may process data on servers outside Nigeria and the European Economic Area. Where data is transferred internationally, we rely on appropriate safeguards, such as standard contractual clauses, to keep it protected.
How long we keep it
We keep personal data for as long as your organisation uses the service, and for a reasonable period afterwards. We keep it longer only where the law requires. When it's no longer needed, we delete or anonymise it.
Keeping your data safe
Each organisation's data is isolated at the database level, so one organisation can never see another's. Access is controlled by role, data is protected in transit, and we test these controls continuously.
Your rights
Under the GDPR and the NDPA you can ask to:
- see the personal data we hold about you (access);
- correct it if it's wrong (rectification);
- delete it (erasure);
- limit or object to how it's used;
- get a copy in a portable format;
- withdraw your consent, where we relied on it.
If your organisation is the data controller, please ask them first and we'll help them respond. For data we control, contact our Data Protection Officer at efeosasere.okoro@teasooconsulting.com.
Cookies
We only use essential cookies, the ones needed to sign you in and keep the service secure. We don't use advertising or tracking cookies.
Complaints
If you're unhappy with how we handle your data, please tell us first so we can put it right. You can also complain to a data protection authority:
- in Nigeria, the Nigeria Data Protection Commission (NDPC);
- in the EU or UK, your local data protection supervisory authority.
Changes to this notice
We may update this notice. The date at the top shows when we last reviewed it.
Contact us
Efeosasere Okoro (Data Protection Officer)
Teasoo Consulting
43 Oghosa Crescent, Benin City, Edo State, Nigeria
efeosasere.okoro@teasooconsulting.com