This Privacy Policy explains how Kletraq (“Kletraq”, “we”, “us”) collects, uses, discloses, and safeguards personal data when you visit kletraq.com, request a demo, or use the Kletraq compliance platform (the “Service”). It is written to meet the transparency obligations of the Nigeria Data Protection Act 2023 (“NDPA”) and, for customers and data subjects in the European Economic Area and United Kingdom, the GDPR and UK GDPR.
Kletraq acts as a data controller for the personal data of website visitors and the account users of our customers, and as a data processor for the compliance data our customers upload into their workspace. Where we act as a processor, our customer is the controller and their own privacy notice governs; our handling is set out in our Data Processing Agreement.
1. Who we are & how to contact us
Controller: Kletraq, reachable at hello@kletraq.com. Our registered legal entity and office address are confirmed at incorporation and published here before any binding signature. For any privacy request or question, contact hello@kletraq.com. Where required by the NDPA for a data controller of major importance, we will designate a Data Protection Officer and publish their contact details here.
2. The personal data we process
- Account & contact data — name, work email, phone, role, organization, and authentication data (including MFA enrolment).
- Usage & device data — pages viewed, feature interactions, IP address, browser and device type, collected via analytics to operate and improve the Service.
- Customer compliance data — evidence, policies, vendor records, and screening results your team uploads. We process this on your instruction as a processor.
- Communications — messages you send us (e.g. demo requests, support).
3. Why we process it & our lawful basis
| Purpose | Lawful basis (NDPA / GDPR) |
|---|---|
| Providing and securing the Service | Performance of a contract |
| Account creation, authentication, MFA | Performance of a contract / legal obligation |
| Product analytics and improvement | Legitimate interest (balanced against your rights) |
| Responding to enquiries and sales | Legitimate interest / steps prior to a contract |
| Compliance with law and lawful requests | Legal obligation |
4. Automated decision-making
Kletraq uses AI-assisted features (screening triage, evidence gap analysis, draft generation). These produce suggestions that a human reviews, edits, or rejects before any action is applied — we do not make decisions producing legal or similarly significant effects about a data subject solely by automated means. You may object to, and request human review of, any automated processing by contacting us.
5. Who we share data with (recipients & sub-processors)
We share personal data only with vetted sub-processors that support the Service under written data-processing terms, and with authorities where legally required. Our current sub-processors — including their purpose and processing region — are listed on our Trust page and in our DPA. We give notice before adding a new sub-processor.
6. International transfers
Kletraq is multi-region. Where personal data is transferred outside Nigeria or the EEA/UK, we rely on an adequacy decision or appropriate safeguards (such as Standard Contractual Clauses) and apply supplementary technical measures including encryption in transit and at rest.
7. How long we keep it
We retain personal data only as long as necessary for the purposes above or as required by law. Customer compliance data is retained per the customer’s configuration and deleted or returned on termination as set out in the DPA. Evidence records carry a default expiry; audit logs are retained to support your regulatory obligations.
8. Your rights
Subject to the NDPA and GDPR, you have the right to access, rectify, erase, restrict, and port your personal data, to object to processing, and to withdraw consent where processing relies on it. To exercise a right, email hello@kletraq.com; we respond within the statutory timeframe. You may also lodge a complaint with the Nigeria Data Protection Commission (NDPC) or your local supervisory authority.
9. Security
We implement technical and organizational measures appropriate to the risk — encryption, role-based access control, mandatory MFA on privileged roles, least-privilege tenancy isolation, logging, and routine security assessment. See the Trust page for detail.
10. Breach notification
Where a personal-data breach is likely to affect data subjects’ rights, we notify the NDPC within 72 hours of becoming aware of it and inform affected data subjects and, where we act as processor, the relevant controller without undue delay.
11. Cookies & analytics
Our website uses a small number of cookies. Essential cookies keep you signed in and maintain your session and security — these are required for the Service to work. Analytics cookies help us understand how the site is used so we can improve it: we use PostHog (product analytics) to record page views and interaction events under a first-party cookie. We do not use these for advertising, we do not sell personal data, and no customer compliance data is sent to analytics. You can block or delete cookies in your browser, and we honour a browser “Do Not Track” / opt-out signal for analytics. See our sub-processor list on the Trust page for where this data is processed.
12. Changes to this policy
We may update this policy; material changes will be posted here with a revised “Last updated” date.