NDPR Policy

How personal data is handled in line with the Nigeria Data Protection Regulation (NDPR).

Last updated: May 25, 2026

This NDPR Policy explains how Certifly Systems Solutions Limited (“Certifly”, “we”, “us”, “our”) handles personal data in line with the Nigeria Data Protection Regulation (NDPR) and applicable Nigerian data protection requirements when you use our platform and services (the “Services”).

This policy should be read together with our Privacy Policy and Terms of Service.

1. Data Controller

Certifly Systems Solutions Limited acts as a Data Controller for personal data processed for our own business operations (e.g., platform administration, security, billing records). Where an Institution/Organization configures and administers assessments, that organization may act as a Data Controller for candidate data collected for their assessment purposes.

2. Personal Data We Process

  • Account data: name, email address, phone (if provided), login history.
  • Assessment data: exam attempts, answers, scores, time spent, completion status.
  • Billing data: purchases, invoices/records, and transaction references (payment card details are processed by payment providers).
  • Technical data: IP address, device/browser details, cookies, and security logs.
  • Proctoring data (where enabled): monitoring signals and integrity artifacts used to protect assessment integrity. The exact data depends on the features enabled by the exam owner.

3. Lawful Basis for Processing

We process personal data on lawful bases such as:

  • Contract (to provide the Services you request)
  • Legal obligation (to meet regulatory or accounting requirements)
  • Legitimate interest (platform security, fraud prevention, service improvement)
  • Consent (where required for specific optional processing)

4. Data Subject Rights (NDPR)

Subject to NDPR and applicable law, you may request to:

  • Access your personal data
  • Correct inaccurate data
  • Delete data (where legally permitted)
  • Restrict or object to certain processing
  • Withdraw consent (where processing relies on consent)

To submit a request, contact us via /contact.

5. Data Sharing

We may share personal data with:

  • Service providers (hosting, email delivery, analytics, customer support) under appropriate safeguards
  • Payment processors to complete transactions
  • Institutions/organizations administering your assessments
  • Authorities where required by law or to protect users and the platform

6. Data Security

We implement technical and organizational measures to protect personal data. No system is completely secure; however, we continuously work to improve our safeguards.

7. Retention

We retain data for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce agreements. Retention may vary by data type and organization requirements.

8. Cross-Border Transfers

Where personal data is transferred outside Nigeria (e.g., due to cloud hosting), we take steps to ensure appropriate safeguards are in place in line with NDPR and applicable requirements.

9. Complaints

If you have concerns about data processing, contact us first so we can address them. You may also have the right to lodge a complaint with the appropriate regulatory authority.

10. Contact

For NDPR-related questions or requests, contact Certifly Systems Solutions Limited via /contact.