Legal

Privacy Policy

Last updated: 26 July 2026

1. Who we are

Domicile Cloud (“Domicile Cloud”, “we”, “us”) operates the Compliance Engine, a platform that helps CBN-regulated payments institutions discover, evaluate, and evidence compliance with CBN Circular PSS/DIR/PUB/CIR/001/004 (data-localisation) and related Nigerian data protection law. This policy explains what information we collect through domicilecloud.com and the Compliance Engine application, and how we handle it under the Nigeria Data Protection Act 2023 (NDPA).

2. Information we collect

We collect the following categories of information:

  • Account information — name, email address, and password (stored as a salted argon2id hash, never in plain text). If you sign in with Google or GitHub, we receive your name, email address, and a provider account identifier from that provider.
  • Multi-factor authentication data — a TOTP secret (encrypted at rest) and one-time backup codes (stored as hashes), required on every account.
  • Institution and compliance data you or your organisation enter — legal name, licence type, CBN licence number, NDPC registration reference, compliance contact details, and inventory of systems, vendors, locations, and data flows you submit manually or via spreadsheet import.
  • Cloud infrastructure metadata — if you connect an AWS, Azure, or GCP account, we use a read-only credential you grant and control to discover metadata about your cloud resources (e.g. service type, region, encryption configuration) relevant to data-localisation rules. We do not access the contents of your customer transaction data, and every discovered item requires your explicit review and approval before it's added to your compliance inventory.
  • Payment information — processed by Paystack, our payment processor. We do not receive or store your card details; we retain transaction records (amount, status, reference, and subscription tier).
  • Evidence you upload — documents you submit to support compliance findings, retained with a content hash for tamper-evidence.
  • Technical and usage data — IP address, browser/device information, and session activity, used for security (e.g. detecting suspicious sign-ins) and to keep you signed in.
  • Webinar and marketing enquiries — name and work email if you register for a webinar, request a demo, or contact us.

3. How we use this information

  • To provide, operate, and secure the Compliance Engine, including MFA-gated authentication and tenant-isolated access to your organisation's data.
  • To run the compliance rule engine against your inventory and generate findings, readiness scores, and evidence packs.
  • To process payments and manage subscriptions.
  • To send account, security, and transactional emails (verification, password reset, invitations, billing).
  • To respond to support requests and, where you've opted in, webinar or marketing communications.
  • To detect, investigate, and prevent fraud, abuse, or security incidents.

4. Legal basis for processing

We process personal data on the basis of: performance of a contract (providing the service you signed up for), your consent (e.g. marketing communications, which you can withdraw at any time), and our legitimate interest in securing and improving the platform, consistent with the NDPA.

5. Who we share information with

We share information only as needed to operate the service:

  • Railway — our infrastructure/hosting provider, which runs the application and database.
  • SendGrid — for delivering transactional email.
  • Paystack — for payment processing.
  • Google / GitHub — only if you choose to sign in with those providers.
  • AWS, Azure, or GCP — only to read metadata from cloud accounts you explicitly connect and authorise; we never receive credentials to any system you haven't connected.

We do not sell your personal data.

6. Data retention

We retain account and compliance data for as long as your account is active, and for a reasonable period afterward to meet legal, audit, and evidentiary obligations relevant to CBN/NDPA compliance record-keeping. You may request deletion of your account as described in Section 8.

7. Security

Passwords are hashed with argon2id; multi-factor authentication is required on every account; TOTP secrets are encrypted at rest; sessions are individually revocable. No system is perfectly secure, and we continue to invest in this as the platform matures.

8. Your rights

Under the NDPA, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data (most account fields are editable directly in Settings).
  • Request deletion of your account and associated personal data, subject to legal retention obligations.
  • Withdraw consent for marketing communications at any time.
  • Object to certain processing, or request a copy of your data in a portable format.

To exercise any of these rights, contact us at hello@domicilecloud.com.

9. Cookies

We use a small number of essential cookies: a session cookie to keep you signed in, and short-lived cookies during OAuth sign-in (Google/GitHub) to protect against cross-site request forgery. We do not use third-party advertising or tracking cookies.

10. Children

The Compliance Engine is a business tool for regulated payments institutions and is not directed at, or intended for use by, children.

11. Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected by updating the “Last updated” date above.

12. Contact

Questions about this policy or your data can be sent to hello@domicilecloud.com.