Table of Contents
- Who we are 2
- Data Collection 2
- Collection of Personal Data 3
- Use of your Personal Data 4
- Use of Information for automated decisions 8
- Fraud prevention agencies 10
- Disclosures of your personal data 10
- Our Third Parties 11
- Data Security 12
- How long your personal data will be used 12
- Your legal rights 12
- Glossary 15
- Who we are
1.2 Crest Hill Law Office Role
Crest Hill Law Office is responsible for deciding why and how your personal data is collected and processed, this makes Crest Hill Law Office “CHLOF” the Data Controller.
Our contact details are: Crest Hill Law Office email@example.com.
We have appointed a Data Protection Officer (“DPO”) to help make sure we are transparent and fair about how we use your data and comply with any Law that may affect your privacy.
Our DPO contact details are:
DPO Legal Department, Crest Hill Law Office (No. 4, Rahama Close, off Dunokofia Street, Area 11, Abuja, Federal Capital Territory)
It is important that the personal data we hold about you is current and accurate, so please let us know if your personal data changes during your relationship with us.
We may modify this policy at any time, if you do not agree to the changes, you must discontinue using the website.
- Data Collection
2.1 What is Personal Data?
Personal data, or personal information, means any information about an individual from which that person can be identified (either on its own or when combined with other information). It does not include data where identity has been removed (anonymized data).
The following are groups of different personal data we may process about you.
- Identity Data: such as title, names, occupation, username or similar identifiers.
- Contact Data: such as addresses, email addresses and telephone numbers.
- Financial Data: such as your income, credit card details or other financial accounts that you may have.
- Account Data: such as details of your account, history of changes, financial summaries, statements.
- Transaction Data: such as payment for Services, purchases/other transactions made on your account and payments to and from you.
- Technical Data: such as device information and identifiers, internet protocol (IP) address, your login data and versioning data based on the devices you use to access our digital platforms.
- Survey and Research Data: such as your responses to questionnaires, surveys, feedback requests and design or research activities.
- Usage Data: such as information about when and how you use our products, services, processes or platforms (e.g. how often you use our mobile applications or how you use your credit card with us)
- Marketing Data: such as your preference on receiving marketing information from us and information used in your interactions with us (or our partners)
2.2 It is important to tell you that while we need to collect certain personal data, and you fail to provide the data when requested, we may not be able to perform the contract we have or are trying to enter into with you.
In this case, we may have to cancel a product or service you have with us, but we will notify you if this is the case at that time.
- Collection of Personal Data
We use different methods to collect data from and about you, including through;
- Direct Interactions:
This is collected when you:
- Apply or register for our products or services
- Use our products or services
- Use our website or mobile device applications
- Make contact with us (e.g. making a phone call or sending an email or SMS)
- Request marketing information to be sent to you.
- Enter a competition or promotion
- Give us feedback or take part in research or surveys.
- Automated Technologies or Interactions:
As you interact with us either through the website or mobile applications, we may automatically collect data including Technical Data about your equipment, browsing actions and patterns. This personal data maybe collected and other similar technologies.
- Third parties or publicly available sources:
We may receive personal data about you from various third parties (and public sources) as set out in ‘Our third parties’.
We may receive personal data about you from individuals or people appointed to act on your behalf, family members, employers, and others who are acting in your best interests or providing us with information in relation to your contact details for the provision of our Services.
- Use of your personal data
We collect and use your personal data for different reasons, to provide, improve, protect and promote our Services. Most commonly, we will use your personal data in the following circumstances:
Where it is necessary for us to perform the contract, we are about to enter into or have entered into with you.
Where it is necessary for our Legitimate Interests (or those of a third party) and your interests and fundamental rights do not override those interests.
Where we need to provide additional services and support.
Where we need to improve our Services by implementing aggregate customer or user preferences;
Where we need to comply with a legal or regulatory obligation.
When you consent to it.
We are only allowed to use your personal data if we have legal grounds to do so. You can find out more about the types of legal ground that we rely on in the Glossary.
4.1 Purposes for which we will use your personal data
We have set out below a description of the ways we plan to use your personal data, the purposes for this usage and which of the legal grounds we rely on to do so. We have also identified what our Legitimate Interests are where appropriate. Note that we may process your personal data for more than one legal ground depending on the specific purpose for which we are using your data.
- Purposes and Legal Grounds
- We may process your information to:
- Understand how you use products, services, processes and related customer experiences provided by us and other third parties;
- Inform the way that we manage our products, services, processes and platforms;
iii. Develop, test and change our products, services, processes and platforms;
- Monitor usage and performance of our products, services, processes and platforms; perform analysis (e.g. statistical, market, product analysis), reporting, forecasting and accounting;
- Tell you about our products, services, events and activities that may be of interest to you;
- Understand how you interact with our marketing; develop, test or change our marketing activities;
vii. Communicate with our third parties to help them understand, improve and fulfil on marketing activities (including supporting behavioral advertising techniques e.g. use of cookie data);
viii. Promote our products and services.
When processing your information for these purposes, we are relying on our Legitimate Interest to help us understand, develop, improve and market our products and services.
- We may process your information to:
- Allow you to begin using or register for our products or services;
- Report activities to law enforcement authority, regulators or court orders in line with our legal, regulatory or business requirements;
iii. Communicate with you to provide updates and information while you are using, registering or continuing to use one of our products or services;
- Communicate with you for design or research purposes or to ask you about our current or potential products, services, processes and customer experiences.
When processing your information for these purposes, we rely on our Legitimate Interest to allow you to access our products and services. In addition, in relation to some of the purposes, it is necessary for us to process your information for the Performance of the Contract between us.
- We may process your information to:
- Enable you to access and use our online services and functionality;
- Understand how you use and navigate our online services;
iii. Tailor online experiences or develop and/or change these services;
- Service and fulfil on your products and services (e.g. processing transactions, managing account information and settings);
- Provide you with rewards, offers or promotions where we (or our partners) think you may be interested;
- Keep our records up to date including updating preferences and making changes to your account;
vii. Manage requests from you where you are exercising your data privacy rights;
viii. Develop, improve or change the products and services that you are using;
viii. Offer you additional products, services and promotions;
- Monitor usage and performance of our products, services, processes and platforms; perform analysis (e.g. statistical, market, product analysis), reporting, forecasting and accounting.
When processing your information for these purposes, we rely on our Legitimate Interest to fulfil on our products and services. In addition, in relation to some of the purposes, it is necessary for us to process your information for the Performance of the Contract between us.
- We may process your information to:
- Perform checks to prevent, detect, investigate and report fraud, crime and/or terrorist activity;
- Protect the security and resilience of our networks/applications and respond to technical and security incidents;
iii. Devise defense strategies (e.g. in relation to fraud, crime, terrorist or cyber-attack risks) and develop, test or change our defenses.
When processing your information for these purposes, we rely on our Legitimate Interest to manage risk, security and crime prevention. In addition, in relation to some of the purposes, we may process your information to comply with a Legal Obligation.
- We may process your information to:
- Improve, test, investigate and remediate any issues with our internal processes and practices;
- Maintain your data and ensure the data that we hold about you is accurate and up to date.
When processing your information for these purposes, we rely on our Legitimate Interest to manage and improve our business processes.
- We may process your information to:
- Cooperate with (and respond to) requests from courts, regulators, law enforcement bodies and other institutions (e.g. fraud prevention agencies);
- Appropriately handle and process complaints or disputes – this may include contacting relevant parties;
iii. Exercise our rights in relation to complaints, disputes or litigation;
- Manage policy affairs, public relations issues, media enquiries or customer interactions with the media;
- Manage complaints with third parties;
- Manage disputes;
vii. Manage litigation against third parties;
viii. Enable us to provide legal and/or regulatory advice in line with our business activities;
When processing your information for these purposes, we rely on our Legitimate Interest to satisfy our industry, regulatory and legal requirements and exercise our rights. In addition, in relation to some of the purposes, we may process your information to comply with a Legal Obligation or it may be necessary to assist in relation to a task performed in the Public Interest.
We may use third parties for any of the purposes listed above.
We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising.
You will receive marketing communications from us if you have requested information from us or provided us with your details when you applied or registered for one of our products or services and, in each case, you have not opted out of receiving that marketing. However, you can ask us to stop sending you direct marketing at any time.
If you ask us to stop sending you marketing messages, you will still receive communications pertaining to your account, our products, and services or relationship with us.
We may also use third parties to conduct marketing activities on our behalf.
4.4 Change of purpose
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal ground which allows us to do so.
Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
- Use of information for automated decisions
Automated Decision Making, including profiling, is the processing of personal data (that we have collected or are allowed to collect from others) by automated means and without human involvement to evaluate personal aspects about you.
In particular, we may process data to analyze or predict (amongst other things) your personal preferences, interests or behaviours. This means that automated decisions without human involvement could be made about you for example in relation to the products and services we offer you.
Here are the types of automated decisions we make:
Where you apply for (or register for) one of our products or services, we use automated processes to detect and help prevent fraud.
We may automatically decide that you pose a fraud or money laundering risk if our processing reveals your behavior to be consistent with money laundering or known fraudulent conduct; or is inconsistent with your previous submissions; or you appear to have deliberately hidden your true identity.
We may also continue to monitor your accounts, your product usage and your transactions to determine whether your account is being used for fraudulent activities.
We utilize data from several sources to help us identify fraud risks:
- information you have provided;
- information we may collect or already hold about you; and
- information provided by third parties (including fraud prevention agencies)
We combine data from these sources and defined logic to identify threats and prevent fraud losses. If we think there is a risk of fraud, we may stop activity on your account and/or refuse access.
Providing you with access to products and services
When you apply (or register) for one of our products or services, we perform checks to ensure that these are suitable for your circumstances and that we manage our business risks.
To do so, we utilize data from several sources:
- Information you have provided;
- Information we may collect or already hold about you; and
- Information provided by third parties.
These checks may include (but are not limited to):
- Checks to ensure you meet conditions for the provision of our Services;
- Checks to identify money laundering, criminal / terrorist activity or cyber security threats that may pose a risk to you and our business.
Where we identify circumstances or threats that introduce a risk to you or our business, we may not be able to provide you with access to our products or services.
Managing, tailoring and marketing our products and services
Where we have an existing relationship with you, we may use profiling and automated decision making to help manage this relationship. We use these techniques to ensure that we manage your accounts, products or services appropriately; help you get the best out of our products and services; and provide you with promotions or offers that we think you will be interested in.
We use data that you provide along with internal and third-party data to place you into groups with similar types of people. We call these groupings ‘segments’ and these are used to help us understand, test and tailor our products, services and marketing more appropriately depending on identified segment types. Some examples of how we use profiling and decision making are:
- Optimizing and fulfilling on communications different communication approaches are suitable for different types of people so we use segmentation to provide you with the most appropriate communications for you;
- Sending marketing and offers different marketing approaches may be used with certain segments where we think our marketing will perform more effectively;
- Tailoring or managing products we may tailor our products or services based on a segment that you are grouped into.
This approach helps us to manage our accounts, products, services and marketing more effectively and meet industry and regulatory requirements. This profiling and automated decision making may lead to changes to products or services or in the way that we interact with you (communications or marketing).
Your rights in relation to automated decision making
You have rights in relation to certain automated decision making which means that before the end of the period of one month beginning with receipt of the automated decision you can request us to:
- Reconsider the decision; or
- Take a new decision that is not based solely on automated decision making and ask that a person review it.
If these rights apply you will be notified. If you want to know more about these rights, please contact us. firstname.lastname@example.org
- Fraud Prevention Agencies
Before we provide products or services to you, we also undertake checks for the purposes of preventing fraud, and to verify your identity. These checks require us to process personal data about you.
The personal data you have provided, we have collected from you, or we have received from third parties will be used to prevent fraud, and to verify your identity.
Details of the personal information that will be processed include, for example: name, address, date of birth, contact details, financial information, and device identifiers including IP address.
We and fraud prevention agencies may also enable law enforcement agencies to access and use your personal data to detect, investigate and prevent crime.
We process your personal data on the basis that we have a Legitimate Interest in preventing fraud, and to verify your identity, in order to protect our business and to comply with laws that apply to us. Such processing is also a contractual requirement of the products and services you have requested.
Fraud prevention agencies can hold your personal data for different periods of time, and if you are considered to pose a fraud or money laundering risk, your data can be held for up to six (6) years.
Consequences of Processing
A record of any fraud risk will be retained by fraud prevention agencies, and may result in others refusing to provide products or services to you.
- Disclosure of your personal data
We may share personal data about you with various third party and public sources as set out in Our Third Parties section.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.
- Our Third Parties
We use third parties to enable, perform or improve a range of our business processes in certain instances. These may require us to share your data with third parties and/or they may share your data with us.
These third parties may include (but are not limited to):
- Third parties that enable us to understand, develop, improve and market our products and services:
- Product, marketing and industry monitoring services and tools;
- Market research, surveying, consultancy and benchmarking services;
iii. Product/service/communications design and development services;
- Marketing partners, affiliates and intermediaries;
- Analytics and incident management services.
- Third parties that work with us to help us fulfil on and service your accounts, products or services:
- Communications fulfilment or development service providers;
- User account management services;
iii. Payment services, payment schemes and network services;
- Transaction enablement and dispute services;
- Third parties that support the running of our business processes:
- Business process systems and support providers;
- Technical platforms, software and tools providers (e.g. tools that we use to optimize and test on our website or mobile applications);
iii. Platform management and support services;
- Data storage, transfer and processing services;
- Disaster recovery solution services;
- Public relations support and consultancy services.
- Third parties that work with us to ensure we reach the best possible outcome:
- Regulators, advisory entities and consumer rights/advice bodies;
- Customer / User complaints and dispute resolution services.
- e. Other third parties, bodies or institutions where we are required by regulation, law, industry practices or to detect/prevent fraud, crime, terrorist activity or business risks e.g. regulators, law enforcement bodies, crime prevention bodies and sharing information with other institutions to help detect and prevent fraud.
Some of our third parties may be international.
- Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
- How long your Personal Data will be used
There are a number of reasons why we need to keep hold of your personal data and our aim is to only retain it for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
How long we keep it for depends on the type of data we are holding and why we need it, to determine the appropriate retention period for personal data, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
If you apply and/or register for our products and/or services, we will retain your personal data for up to seven years after your relationship with us ends.
If your application for one of our products is declined or you decide not to progress with the application, we will retain your personal data for up to 18 months after your application or quotation search was made.
We may keep your data for longer than explained above if we cannot delete it for legal, regulatory or technical reasons. If we do, we will continue to make sure your privacy is protected.
- Your Legal Rights
Under certain circumstances, you have rights under data protection laws in relation to your personal data.
Right of access to your personal data
Right of access to your personal data (commonly known as a “data subject access request”). This enables you to receive a copy of the personal data we hold about you.
Right to rectification
Right to rectification of the personal data that we hold about you. This enables you to have any incomplete or inaccurate data we hold about you corrected. However, please note that we may need to verify the accuracy of the new data you provide to us.
Right of erasure (“right to be forgotten”)
Right to erasure of your personal data (also known as the “Right to be forgotten”). This enables you to ask us to delete or remove personal data in the following circumstances:
- where the personal data is no longer necessary for the purpose for which it was collected;
- where there is no good reason for us continuing to process it;
- where you have successfully exercised your Right to object to processing of your personal data;
- where we may have processed your information unlawfully or where we are required to erase your personal data to comply with a legal obligation.
Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
Right to object
Right to object to processing (including profiling) of your personal data where we are relying on a Legitimate Interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms. You also have the right to object where we are processing your personal data for direct marketing purposes.
Right to restriction of processing
Right to restriction of processing of your personal data. This enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data’s accuracy (see Right of rectification); (b) where our use of the data is unlawful but you do not want us to erase it; (c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it (see Right to object).
Right to data portability
Right to data portability of your personal data to you or to a third party. We will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
Right to complain to the NITDA
Right to make a complaint to the National Information Technology Development Agency (NITDA) the Nigerian supervisory authority for data protection issues, at any time. And in the case of international users, the body responsible for data protection issues within your jurisdiction.
We would, however, appreciate the chance to deal with your concerns before you approach the NITDA so please contact us in the first instance.
Right to object to direct marketing
Right to object to direct marketing at any time by following the opt-out links on any marketing message sent to you or by contacting us.
Right to withdraw consent
Right to withdraw consent at any time. In certain circumstances, we may need to get your consent before we can access or process your personal data. If this happens, we will always ask for your consent first. If you have given us consent in the past but subsequently change your mind, you can withdraw your consent at any time.
No fee usually required
You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.
What we may need from you
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
Time limit to respond
We try to respond to all legitimate requests in relation to your legal rights within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.
If you wish to exercise any of the rights set out above, please contact us at email@example.com
Comply with a Legal Obligation means processing your personal data where it is necessary for compliance with a legal or regulatory obligation that we are subject to.
Legitimate Interest means we have a business or commercial reason to use your data. We can use your data to pursue Legitimate Interest of our own or of other service providers. When we rely on our Legitimate Interest, we make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).
Performance of the Contract means processing your data where it is necessary for the performance of a contract to which you are a party or to take steps at your request before entering into such a contract.
Process means anything we do with your data such as collecting, using, storing, sharing, monitoring, analyzing and deleting it.
Public Interest means the processing is necessary for either carrying out a specific task in the public interest which is laid down by law, or exercising official authority, e.g. a public body’s task, functions, duties or powers which is laid down by law.
Range of Products and Services means our website or tools available on our website.
Substantial Public Interest means those laid down in data protection laws.
- Governing Law