HOLSECURE LIMITED
PRIVACY POLICY
Document Classification: Public
Document Owner: HolSecure
Policy Number: HS-PRIV-001
Version: 1.0
Effective Date: July 1, 2026
Review Frequency: Annually or whenever required by applicable law or material business changes
Approved By: Managing Director
1. Introduction
HolSecure Limited (“HolSecure”, “we”, “our” or “us”) is committed to protecting the privacy, confidentiality and security of personal data entrusted to us.
As a cybersecurity and data privacy consulting firm, we recognise that information is one of our clients’ most valuable assets. We therefore maintain the same high standards of care in protecting personal data that we advise our clients to adopt.
This Privacy Policy explains how HolSecure collects, uses, stores, protects, shares and otherwise processes personal data in connection with our business activities, including our cybersecurity consulting services, data privacy advisory services, governance, risk and compliance engagements, cybersecurity training programmes, website operations, recruitment activities, marketing communications and other legitimate business functions.
Our objective is to ensure that every processing activity involving personal data is conducted lawfully, fairly, transparently and securely while respecting the rights and freedoms of the individuals whose information we process.
HolSecure processes personal data in accordance with the Nigeria Data Protection Act, 2023, regulations and guidance issued by the Nigeria Data Protection Commission (NDPC), applicable contractual obligations, and internationally recognised privacy and information security principles. Where we process personal data relating to individuals outside Nigeria, we also seek to comply with applicable foreign privacy laws to the extent required by those jurisdictions.
This Privacy Policy applies to all personal data processed by HolSecure regardless of the medium in which that information is stored, including electronic records, cloud platforms, paper records, mobile devices and other business systems.
2. Scope
This Privacy Policy applies to all personal data processed by HolSecure in the course of its business operations.
It applies to:
- Clients and prospective clients, Website visitors, Training participants, Employees, Job applicants, Independent consultants and contractors, Business partners, Suppliers and vendors,Event attendees, Newsletter subscribers,
- Individuals who communicate with us by telephone, email, social media, messaging platforms or other communication channels
- Visitors to our offices
- Any other individual whose personal data is processed by HolSecure in connection with our legitimate business activities.
This Policy applies irrespective of whether the personal data is collected directly from the individual or obtained through lawful third-party sources.
3. Purpose of this Policy
The purpose of this Privacy Policy is to:
- Explain how HolSecure processes personal data.
- Ensure transparency in our processing activities.
- Protect the privacy rights of individuals.
- Demonstrate compliance with applicable privacy legislation.
- Describe the safeguards implemented to protect personal information.
- Provide information about the rights available to data subjects.
- Promote accountability throughout our organisation.
- Support HolSecure’s commitment to ethical information governance.
4. Our Privacy Commitment
Privacy is fundamental to trust. At HolSecure, we believe that responsible data stewardship is essential to maintaining the confidence of our clients, partners, employees and the wider public.
Accordingly, we are committed to ensuring that personal data is:
- processed lawfully and fairly;
- collected for specified, explicit and legitimate purposes;
- limited to what is necessary for those purposes;
- accurate and kept up to date;
- retained only for as long as necessary;
- protected against unauthorised access, disclosure, alteration and destruction; and
- processed in a manner that respects the dignity, rights and freedoms of every individual.
Privacy considerations are integrated into the design, development and delivery of our services through the principles of privacy by design and privacy by default.
5. Definitions
For the purposes of this Policy:
Personal Data means any information relating to an identified or identifiable natural person.
Sensitive Personal Data includes information relating to health, genetics, biometrics, racial or ethnic origin, religious beliefs, political opinions, trade union membership, sexual orientation, financial account information and any other category recognised under applicable law.
Processing means any operation performed on personal data including collection, recording, organisation, storage, adaptation, retrieval, consultation, disclosure, transmission, analysis, deletion or destruction.
Data Subject means the individual to whom personal data relates.
Data Controller means a person or organisation that determines the purposes and means of processing personal data.
Data Processor means a person or organisation that processes personal data on behalf of a Data Controller.
Consent means any freely given, specific, informed and unambiguous indication of the individual’s wishes by which they signify agreement to the processing of their personal data.
Personal Data Breach means any security incident resulting in accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data.
Third Party means any natural or legal person other than the data subject, HolSecure, authorised employees or authorised processors acting under our instructions.
Additional definitions shall have the meanings assigned to them under the Nigeria Data Protection Act, 2023.
6. Privacy Principles
Our privacy programme is built upon the following principles in accordance with Data Protection:
Lawfulness: We process personal data only where there is a lawful basis for doing so.
Fairness: We process information in ways that individuals would reasonably expect and without causing unjustified harm.
Transparency: We provide clear information regarding how personal data is processed.
Purpose Limitation: Personal data is collected only for legitimate, specified and communicated purposes.
Data Minimisation: We collect only the personal data reasonably necessary to fulfil the identified purpose.
Accuracy: We take reasonable steps to ensure personal data remains accurate and current.
Storage Limitation: Personal data is retained only for as long as necessary to satisfy legal, contractual or operational requirements.
Integrity and Confidentiality: Appropriate technical and organisational safeguards are implemented to protect personal data against unauthorised or unlawful processing.
Accountability: We maintain governance structures, policies, procedures and oversight mechanisms to demonstrate compliance with applicable privacy obligations.
7. Roles and Responsibilities
For us, protecting personal data is a shared responsibility
The Managing Director has overall responsibility for ensuring that the organisation maintains an effective privacy governance framework.
Management is responsible for implementing appropriate privacy controls within their areas of responsibility and ensuring employees understand their obligations.
Employees, contractors and consultants are required to process personal data only in accordance with authorised business purposes, applicable policies and confidentiality obligations.
Where appointed, the Data Protection Officer or designated Privacy Lead is responsible for monitoring compliance, advising on privacy matters, supporting privacy impact assessments, responding to data subject requests and serving as a point of contact with regulatory authorities.
Third-party service providers engaged by HolSecure are required to implement appropriate safeguards and process personal data only in accordance with contractual obligations and applicable law.
8. HOW WE COLLECT PERSONAL DATA
We collect personal data through lawful, fair and transparent means. The information we collect depends on the nature of our relationship with you and the services you request.
We may collect personal data directly from you when you:
- Register for our cybersecurity training programmes or workshops.
- Complete forms on our website.
- Request information about our services.
- Engage us for cybersecurity, governance, risk management or data privacy consulting services.
- Subscribe to newsletters or marketing communications.
- Participate in surveys, webinars or industry events.
- Apply for employment opportunities.
- Communicate with us through email, telephone, social media platforms, messaging applications or other communication channels.
- Visit our offices or attend meetings organised by HolSecure.
- We may also collect information automatically when you interact with our website or digital platforms through cookies, server logs, analytics technologies and other similar tools that help us understand website usage, improve user experience and protect our digital infrastructure.
- Where permitted by law, we may obtain personal information from third parties including:
- Business partners.
- Professional advisers
iii. Recruitment agencies.
- Background verification providers.
- Publicly available sources.
- Regulatory authorities.
vii. Training partners.
viii. Technology service providers.
- Referral partners.
Any information obtained from third parties will only be processed where there is a lawful basis to do so.
9. LAWFUL BASES FOR PROCESSING PERSONAL DATA
HolSecure processes personal data only where there is a lawful basis under the Nigeria Data Protection Act, 2023 or other applicable laws.
Depending on the circumstances, our processing activities may rely on one or more of the following legal bases.
Consent
We process personal data where you have voluntarily provided your consent for a specific purpose.
Examples include:
Subscription to newsletters; Participation in surveys.; Registration for promotional events.; Certain categories of marketing communications.; Use of optional website cookies.
Where processing is based on consent, you may withdraw your consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal.
Performance of a Contract
We process personal data where it is necessary to perform a contract with you or to take steps at your request before entering into a contract.
Examples include:
Delivering cybersecurity consulting services; Conducting privacy assessments; Providing cybersecurity training; Managing client engagements; Responding to service requests; Processing payments; Managing contractual obligations.
Compliance with Legal Obligations
We may process personal data where necessary to comply with legal or regulatory obligations.
Examples include:
Maintaining financial records; Tax reporting; Regulatory reporting.; Responding to lawful requests from competent authorities; Fraud prevention; Compliance investigations; Record retention obligations.
Legitimate Interests
We may process personal data where it is necessary for our legitimate business interests, provided those interests do not override your fundamental rights and freedoms.
Legitimate interests may include:
Improving our services; Maintaining information security; Preventing fraud; Managing client relationships; Responding to enquiries; Business planning; Quality assurance; Internal administration; Conducting cybersecurity research; Website administration; Business continuity planning; Professional development.
Vital Interests
In limited circumstances, we may process personal data where necessary to protect the life, health or safety of an individual.
Public Interest
Where applicable, we may process personal data to perform tasks carried out in the public interest or pursuant to statutory obligations.
10. PURPOSES FOR WHICH WE PROCESS PERSONAL DATA
HolSecure processes personal data only for legitimate, specified and lawful purposes.
These purposes include, but are not limited to, the following.
- Service Delivery
- Client Relationship Management
- Training and Professional Development
- Website Administration
- Information Security
- Compliance and Regulatory Obligations
- Recruitment
- Marketing
- Business Operations
11. SPECIAL CATEGORIES OF PERSONAL DATA
We recognise that certain categories of personal data require enhanced protection because of their sensitive nature.
We generally do not collect or process sensitive personal data unless:
- it is necessary for the provision of our services;
- required by law;
- necessary for employment purposes;
- required for accessibility or accommodation during training programmes;
- required for legal proceedings;
- necessary to establish, exercise or defend legal claims; or
- the individual has provided explicit consent where required by law.
Where sensitive personal data is processed, HolSecure implements enhanced technical, organisational and administrative safeguards to reduce the risk of unauthorised access, misuse or disclosure.
12. DATA MINIMISATION
We are committed to collecting only the personal data that is adequate, relevant and necessary for the identified purpose.
Before collecting personal information, we assess whether:
- the information is required to deliver the requested service;
- the purpose can reasonably be achieved using less personal information;
- there is a lawful basis for collection; and
- the collection is proportionate to the intended processing activity.
We do not knowingly collect excessive or unnecessary personal information.
13. DISCLOSURE AND SHARING OF PERSONAL DATA
HolSecure treats all personal data entrusted to us as confidential and does not sell, rent or trade personal data to third parties. We only disclose personal data where there is a lawful basis to do so, where disclosure is necessary to provide our services, or where we are legally required or authorised to make such disclosure.
Depending on the nature of our engagement, personal data may be shared with the following categories of recipients:
Professional Service Providers
We may engage carefully selected third-party service providers to support our business operations, including providers of cloud hosting, cybersecurity platforms, learning management systems, customer relationship management systems, payment processing services, accounting software, document management systems, communication platforms and other technology services.
These service providers are contractually required to process personal data only on our documented instructions, implement appropriate security measures and comply with applicable data protection laws.
Business Partners
Where a project involves collaboration with approved implementation partners, subcontractors or specialist consultants, only the personal data necessary to perform the agreed services will be shared.
All such parties are required to maintain appropriate confidentiality and information security standards.
Regulatory Authorities
We may disclose personal data where required to comply with applicable laws, court orders, lawful investigations or requests from regulatory authorities, law enforcement agencies or competent governmental bodies.
Where legally permissible, we will seek to limit the scope of such disclosures and protect the confidentiality of the information disclosed.
Professional Advisers
Personal data may be disclosed to our legal advisers, auditors, insurers, accountants or other professional advisers where necessary for obtaining professional advice, defending legal claims or meeting statutory obligations.
Corporate Transactions
Should HolSecure undergo a merger, acquisition, business restructuring, investment transaction or sale of assets, personal data may be transferred as part of that transaction, subject to appropriate confidentiality obligations and applicable legal requirements.
With Your Consent
Where no other lawful basis exists, we will only disclose your personal data where you have provided your consent.
14. THIRD PARTY SERVICE PROVIDERS
We carefully evaluate third-party service providers before engaging them to process personal data on our behalf.
Our vendor due diligence process considers factors including:
- Information security controls.
- Privacy governance.
- Regulatory compliance.
- Technical competence.
- Business continuity capabilities.
- Incident response maturity.
- Data residency arrangements.
- Contractual commitments.
Where third-party processors are engaged, we require appropriate contractual safeguards, including obligations relating to confidentiality, information security, breach notification, audit rights, lawful processing and secure deletion or return of personal data upon termination of services.
15. INTERNATIONAL TRANSFERS OF PERSONAL DATA
As part of our business operations, personal data may be processed or stored outside Nigeria through reputable cloud service providers or international technology platforms.
Where personal data is transferred outside Nigeria, HolSecure will implement appropriate safeguards to ensure that the transferred information receives a level of protection consistent with the requirements of the Nigeria Data Protection Act and other applicable laws.
Such safeguards may include:
- Contractual data protection clauses.
- Transfers to jurisdictions recognised as providing adequate protection.
- Appropriate technical safeguards, including encryption.
- Risk assessments relating to cross-border transfers.
- Additional organisational safeguards where appropriate.
HolSecure will take reasonable steps to ensure that international transfers do not compromise the security, confidentiality or integrity of personal data.
16. COOKIES AND SIMILAR TECHNOLOGIES
Our website may use cookies, web beacons, pixels and similar technologies to improve functionality, enhance user experience, understand website performance and maintain the security of our online services.
Cookies are small text files stored on your device when you visit a website. The categories of cookies we may use include:
Strictly Necessary Cookies
These cookies are essential for the operation and security of our website and cannot generally be disabled.
Functional Cookies
These cookies remember your preferences and improve your browsing experience.
Performance and Analytics Cookies
These cookies help us understand how visitors use our website so that we can improve its functionality, performance and user experience.
Security Cookies
These cookies assist in identifying suspicious activities, preventing fraudulent behaviour and protecting our systems against cyber threats.
Marketing Cookies
Where applicable, these cookies may be used to measure the effectiveness of marketing campaigns or provide relevant communications based on your preferences.
Where required by applicable law, users will be provided with appropriate cookie choices before non-essential cookies are placed on their devices.
Users may also manage cookies through their browser settings, although disabling certain cookies may affect website functionality.
17. ARTIFICIAL INTELLIGENCE AND AUTOMATED TECHNOLOGIES
HolSecure may utilise artificial intelligence, machine learning and other advanced technologies to improve operational efficiency, strengthen cybersecurity capabilities, enhance service delivery and support business administration.
Where artificial intelligence tools are used, HolSecure remains responsible for ensuring that processing activities are conducted lawfully, fairly and transparently.
We implement appropriate governance measures to reduce the risk of bias, inaccurate outputs, unauthorised disclosure of personal data and inappropriate automated decision-making.
We do not make decisions producing legal or similarly significant effects on individuals solely through automated processing unless authorised by applicable law or with appropriate safeguards in place.
Where artificial intelligence technologies are used to process personal data, we will implement appropriate human oversight to ensure fairness, accountability and accuracy.
18. INFORMATION SECURITY
Protecting information is fundamental to HolSecure’s business.
We implement administrative, technical and physical safeguards designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access.
Our information security programme incorporates a risk-based approach aligned with internationally recognised information security principles and may include measures such as:
- Information security governance.
- Information classification.
- Access control based on business needs.
- Multi-factor authentication.
- Encryption of personal data where appropriate.
- Network security monitoring.
- Endpoint protection.
- Secure system configuration.
- Vulnerability management.
- Security patch management.
- Regular backup procedures.
- Business continuity planning.
- Disaster recovery capabilities.
- Secure software and cloud environments.
- Continuous security monitoring.
- Logging and audit trails.
- Physical security controls.
- Employee confidentiality obligations.
- Security awareness training.
- Third-party risk management.
- Incident detection and response processes.
- Periodic security assessments.
Despite implementing appropriate safeguards, no method of transmitting or storing information can guarantee absolute security. HolSecure therefore continually reviews and improves its security controls to address emerging threats, technological developments and changes in regulatory expectations.
19. DATA RETENTION
HolSecure retains personal data only for as long as necessary to fulfil the purposes for which it was collected, including the provision of services, compliance with legal and regulatory obligations, the resolution of disputes, enforcement of contractual rights and the protection of our legitimate business interests.
The retention period applicable to personal data depends on the nature of the information, the purpose for which it was collected, contractual obligations, applicable legislation and operational requirements.
As a general principle:
- Client engagement records shall be retained for the duration of the engagement and for an appropriate period thereafter to satisfy legal, contractual and regulatory obligations.
- Financial and accounting records shall be retained in accordance with applicable tax and financial reporting requirements.
- Recruitment records relating to unsuccessful applicants shall be retained only for the period reasonably necessary for recruitment administration and compliance with applicable laws unless a longer retention period is authorised by the applicant.
- Training records, attendance records and certificates may be retained to facilitate verification of training history and professional certifications.
- Marketing records shall be retained until an individual withdraws consent or objects to further communications, unless another lawful basis for retention exists.
- Website logs and technical records shall be retained only for as long as reasonably necessary to maintain system security, investigate incidents, improve services and satisfy legal obligations.
- Where personal data is no longer required, we will securely delete, anonymise or permanently destroy the information using appropriate methods designed to prevent unauthorised recovery or reconstruction.
- Where litigation, regulatory investigations, audits or legal proceedings are reasonably anticipated or ongoing, HolSecure may retain relevant information for longer than the standard retention period until such matters have been concluded.
20. DATA SUBJECT RIGHTS
HolSecure respects the rights of individuals under the Nigeria Data Protection Act and other applicable privacy legislation.
Subject to applicable legal limitations, every individual whose personal data is processed by HolSecure may exercise one or more of the following rights.
Right to Information
You have the right to receive clear and transparent information regarding how your personal data is collected, used, shared and protected.
Right of Access
You may request confirmation as to whether HolSecure processes your personal data and, where applicable, request access to that information.
Right to Rectification
You may request that inaccurate, incomplete or outdated personal data be corrected or updated.
Right to Erasure
You may request the deletion of your personal data where retention is no longer necessary, consent has been withdrawn or processing is otherwise unlawful, subject to applicable legal and contractual obligations.
Right to Restrict Processing
You may request that HolSecure temporarily suspend certain processing activities while the accuracy of information or the lawfulness of processing is being reviewed.
Right to Object
You may object to processing carried out on the basis of legitimate interests or for direct marketing purposes.
Where required by law, HolSecure will cease such processing unless compelling legitimate grounds exist.
Right to Data Portability
Where technically feasible and legally applicable, you may request that your personal data be provided in a structured, commonly used and machine-readable format or transferred to another organisation.
Right to Withdraw Consent
Where processing is based on consent, you may withdraw your consent at any time. Withdrawal of consent will not affect processing that occurred before the withdrawal.
Right to Lodge a Complaint
If you believe that HolSecure has processed your personal data unlawfully or failed to comply with applicable privacy legislation, you may lodge a complaint with us or with the Nigeria Data Protection Commission.
HolSecure will not discriminate against any individual for exercising their privacy rights.
21. EXERCISING YOUR PRIVACY RIGHTS
Requests relating to privacy rights may be submitted using the contact details provided in this Privacy Policy.
- To protect personal data against unauthorised disclosure, HolSecure may request reasonable evidence of identity before processing any request.
- Upon receiving a valid request, HolSecure will acknowledge receipt and respond within the period required under applicable law.
- Where a request is unusually complex or involves multiple requests, HolSecure may extend the response period where permitted by law and will notify the individual accordingly.
We reserve the right to decline requests where exemptions or restrictions apply under applicable legislation.
22. CHILDREN’S PRIVACY
HolSecure’s services are intended primarily for businesses, professionals and individuals aged eighteen (18) years and above.
We do not knowingly collect personal data directly from children except where such processing is authorised by applicable law, necessary for an approved training programme or undertaken with the consent of a parent or legal guardian where required.
Where we become aware that personal data relating to a child has been collected unlawfully, we will take appropriate steps to delete the information without undue delay unless retention is required by law.
Parents or legal guardians who believe that a child has provided personal information to HolSecure may contact us to request review or deletion of the information.
23. MARKETING COMMUNICATIONS
HolSecure may send newsletters, event invitations, industry updates, service announcements and other marketing communications where permitted by law.
Individuals may opt out of receiving marketing communications at any time by:
- Selecting the unsubscribe option included within our electronic communications.
- Contacting HolSecure using the details provided in this Privacy Policy.
- Updating their communication preferences where such functionality is available.
- Operational communications relating to active services, contractual obligations, security notifications or regulatory matters may continue to be sent where necessary even if an individual has opted out of marketing communications.
24. PERSONAL DATA BREACH MANAGEMENT
HolSecure maintains documented procedures for identifying, reporting, investigating, containing and responding to actual or suspected personal data breaches.
Where a personal data breach occurs, we will promptly assess:
- The nature of the incident.
- The categories of information affected.
- The number of individuals impacted.
- The likelihood and severity of potential harm.
- The appropriate containment and remediation measures.
- Any legal or regulatory reporting obligations.
Where required by applicable law, we will notify the Nigeria Data Protection Commission and affected individuals within the prescribed timelines.
Following every significant security incident, we will conduct a post-incident review to identify root causes, implement corrective actions and strengthen preventive controls.
25. COMPLAINTS
We are committed to resolving privacy concerns fairly, promptly and transparently.
Individuals who have concerns regarding the processing of their personal data are encouraged to contact us in the first instance.
We will investigate complaints objectively and provide a response within a reasonable period.
Where an individual remains dissatisfied with our response, they may lodge a complaint with the Nigeria Data Protection Commission or any other competent supervisory authority with jurisdiction over the matter.
26. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in applicable laws, regulatory guidance, business operations, technology or security practices.
Where material changes are made, we will take reasonable steps to notify affected individuals through appropriate channels, including publication on our website where applicable.
The latest version of this Privacy Policy shall always supersede previous versions.
Individuals are encouraged to review this Privacy Policy periodically to remain informed about how their personal data is protected.
27. CONTACT US
Questions, requests or concerns relating to this Privacy Policy or the processing of personal data may be directed to:
HolSecure Limited
Email: privacy@holsecure.org
General Email: info@holsecure.org
Website: www.holsecure.org
Telephone: +2348103903172
APPENDIX A – CATEGORIES OF PERSONAL DATA
Category | Examples |
Identity Information | Name, title, date of birth, identification details |
Contact Information | Email address, telephone number, residential or business address |
Professional Information | Employer, job title, certifications, qualifications |
Technical Information | IP address, browser, operating system, device identifiers |
Client Information | Engagement records, reports, invoices, contracts |
Training Information | Attendance records, assessments, certifications |
Recruitment Information | CVs, interview notes, references |
Financial Information | Payment records and billing information |
Communications | Emails, meeting records, enquiries and support requests |
APPENDIX B – HOLSECURE’S PRIVACY PRINCIPLES
HolSecure is committed to processing personal data in accordance with the following principles:
- Lawfulness
- Fairness
- Transparency
- Purpose Limitation
- Data Minimisation
- Accuracy
- Storage Limitation
- Integrity and Confidentiality
- Accountability
- Privacy by Design
- Privacy by Default
APPENDIX C – GOVERNING LAW
This Privacy Policy shall be governed by and construed in accordance with the laws of the Federal Republic of Nigeria, including the Nigeria Data Protection Act, 2023, together with any applicable regulations, guidelines and directives issued by the Nigeria Data Protection Commission.
