Legal

Privacy Notice

Last updated July 27, 2026

This notice describes how Crimson Strande ("we", "us") collects, uses, and shares your personal information when you use crimsonstrande.app (the "Service"). It is maintained by Crimson Strande and is aligned with the Nigeria Data Protection Act (NDPA) 2023 and the EU General Data Protection Regulation (GDPR) for visitors in scope.

Data controller

Crimson Strande is the data controller for personal information processed through the Service. Contact the data protection team at privacy@crimsonstrande.com.

What we collect

  • Account data — name, email, phone, company, billing address.
  • Service requests — the service you selected, brief description, location, urgency, and any attachments you upload.
  • Payment evidence — the proof-of-payment file you upload after a bank transfer. We do not store card details.
  • Communications — emails we send you and support messages you send us.
  • Technical data — IP address, user agent, and standard server logs used for security and reliability.

How we use it

  • To fulfil your service request, dispatch technicians, and issue invoices.
  • To send you transactional emails: booking confirmation, quote, payment confirmation, scheduling, and completion.
  • To authenticate you and secure your account (sign-in alerts, rate limiting, honeypot).
  • To comply with tax, accounting, and legal obligations in Nigeria.
  • To improve the Service, only where you have accepted analytics cookies.

Legal bases (GDPR)

  • Contract — processing needed to deliver the service you requested.
  • Legal obligation — tax records, invoice retention.
  • Legitimate interest — fraud prevention, service security, and dispute handling.
  • Consent — optional analytics; you can withdraw at any time.

Who we share with

We share personal information only with processors needed to run the Service. Current subprocessors are listed in our Trust page. We do not sell your data.

Retention

  • Account and ticket records: for the life of the account plus 12 months.
  • Invoices and tax records: 7 years, as required by Nigerian tax law.
  • Deletion requests: soft-deleted immediately, hard-deleted after 30 days (invoice records retained per above).
  • Server logs: 90 days.

Your rights

You have the right to access, correct, delete, restrict, or object to processing of your data, and to data portability. Signed-in customers can:

  • Download a copy of their data from the Privacy tab of their account.
  • Request account deletion from the same page.

You may also contact us at privacy@crimsonstrande.com to exercise any right. You may lodge a complaint with the Nigeria Data Protection Commission (NDPC) or, in the EU/UK, your local supervisory authority.

International transfers

Data may be processed on infrastructure located outside Nigeria (see our Trust page for the current list). Where required, we rely on Standard Contractual Clauses or equivalent safeguards.

Security

We apply role-based access controls, database row-level security, encrypted transport (TLS), encrypted storage at rest, and audit logging of privileged actions. Report suspected vulnerabilities to security@crimsonstrande.com.

Changes to this notice

We will post material changes on this page and update the "last updated" date above.

Questions? Contact privacy@crimsonstrande.com