Privacy Policy — FortressPoint Compliance Suite
Last updated: [DATE — fill in on actual publication]
⚠️ DRAFT — NOT LEGALLY REVIEWED. Do not publish as final without review by a qualified Nigerian lawyer (and ideally UK-qualified input given the platform's dual-market positioning). This draft is written to be substantively complete and accurate to the actual system architecture described in this project's build history, but every sub-processor, retention period, and legal basis stated here should be verified against the live system before publication, and reviewed for legal sufficiency.
1. Who We Are
FortressPoint Consulting Limited ("FortressPoint," "we," "us," "our") operates FortressPoint Compliance Suite (the "Service"). This Privacy Policy explains how we collect, use, share, and protect personal data belonging to users of the Service itself — this is distinct from the compliance documents (such as privacy policies) the Service generates *for* our customers about *their own* data handling practices.
Our data protection contact can be reached at: compliance@fortresspointconsulting.com
2. What Personal Data We Collect
Alongside each category below, we state plainly whether providing it is required to use the relevant part of the Service, or genuinely optional. Where something is required, it's required only because the Service genuinely cannot do that specific thing without it (e.g. we cannot create an account with no email address, or invite a teammate without their email address) — never merely because it's convenient for us to have.
- Account information: name, email address, and authentication data, collected and managed on our behalf by our authentication provider. Your email address and authentication credentials are required — without them we cannot create an account for you. Your name is requested but not technically required; leaving it blank just means we address you less personally.
- Organisation information: company name, and, where you use our team/organisation features, information about your organisation's members and their assigned roles (Admin, Editor, Viewer). A company name is required only if you are the first person setting up a new company/Dashboard account — if you're joining one that already exists, it's already set for you. Information about a teammate is required only at the point you choose to invite them — we cannot send an invitation with no email address to send it to.
- Audit response data: your answers to our compliance self-assessment questionnaires, and the compliance scores and documents generated from those answers. Entirely optional — you can hold an account without ever starting a self-assessment. Without it, you simply won't receive compliance scores or generated documents, since there is nothing yet to score.
- Payment information: processed by our payment processor (Paystack) — we do not directly store your full card details. We retain records of transaction status, subscription tier, and billing history necessary to administer your subscription. Required only if you subscribe to a paid tier or add-on; our free tier requires none of this.
- Support communications: information you submit through our support ticket system, including your messages and any information you choose to provide when raising a request. Entirely optional — provided only if and when you choose to contact us.
- Technical/usage data: standard web request data (e.g. IP address, browser type, pages visited) collected automatically for security, troubleshooting, and service-improvement purposes. This is an unavoidable by-product of operating any web service, not something you can individually opt out of while using the Service — but we do not use it to identify you personally beyond what security and troubleshooting require.
3. How We Use Your Data
We use the personal data described above to:
- Provide, operate, and maintain the Service;
- Process your compliance self-assessments and generate documents on your behalf;
- Process payments and manage your subscription;
- Communicate with you about your account, support requests, and material changes to the Service or these terms;
- Maintain the security and integrity of the Service;
- Comply with our own legal and regulatory obligations.
We do not sell your personal data to third parties, and we do not use your audit response data or uploaded evidence to train AI models beyond the processing necessary to generate your requested documents, responses, or search results in the moment.
4. Legal Basis for Processing
As a Nigerian-registered company processing personal data primarily in connection with Nigerian compliance obligations, we process your data under the Nigeria Data Protection Act 2023 and its General Application and Implementation Directive (GAID). Our legal bases include: performance of our contract with you (providing the Service you've signed up for), your consent (where separately obtained, e.g. for marketing communications), and our legitimate interests in operating and securing the Service.
Where you are located in the United Kingdom or European Union, we also process your data consistently with UK GDPR / EU GDPR principles.
5. Who We Share Your Data With
We share personal data with service providers who help us operate the Service, each engaged under contractual terms requiring them to protect your data appropriately. These providers fall into the following categories:
- Identity and account management providers, who authenticate your access to the Service
- Cloud database and hosting providers, who store your account, organisation, and audit data
- Content management providers, who host our question sets and document templates
- AI processing providers, who assist in generating your compliance documents and grounded responses (including our compliance assistant), and in creating searchable representations of your evidence to support features like questionnaire automation
- Payment processors, who handle subscription and purchase transactions
- Email delivery providers, who send transactional notifications on our behalf
- File storage providers, who host generated documents
- Error monitoring and observability providers, who help us detect and diagnose technical problems with the Service (added 2026-08-13, following an internal review that found this category of provider built into the Service but not yet disclosed here — a same-day follow-up correction confirmed it hadn't actually gone live yet either, and fixed that the same day, so this disclosure is accurate as of the fix)
We do not sell your personal data to any third party. A current list of our specific sub-processors is available on request — contact compliance@fortresspointconsulting.com.
6. International Data Transfers
Some of our sub-processors host or process data outside Nigeria (including in the European Union and United States). Where this occurs, we take steps intended to ensure an adequate level of protection for your data during transfer, consistent with the GAID's requirements for cross-border data transfers — including, where applicable, standard contractual clauses or other approved transfer mechanisms.
7. Data Retention and Deletion
We retain your account and compliance data for as long as your account remains active. If you request deletion of your account, the following process applies — this reflects our actual, built system, not a generic promise:
Grace period. Once you request deletion, your account enters a 14-day grace period during which it is scheduled for deletion but not yet purged — this exists to protect against accidental requests or a change of mind. You (or, where applicable, our support team) can cancel a pending deletion during this window.
What is deleted. What "permanently delete" means here depends on whether your account stands alone or belongs to a company:
- Solo users (no Company). Once the grace period ends, we permanently delete your compliance content in full — audit responses and scores, generated documents and their underlying files, uploaded evidence files, vendor assessments, and training records, chat/ assistant conversation history, support tickets, and incident reports. Your account identity itself is also removed — *unless* you have billing history with us, in which case your account row is anonymized rather than deleted outright, for the same reason described under "What is retained, and why" below.
- Company members. Your personal account is anonymized, not deleted outright (see below), and your access to the company is removed. Compliance content that belongs to your organisation — audit runs, generated documents, evidence, vendor assessments, training records, chat/assistant history, and anything else shared with your team — is not deleted when you personally leave or delete your account. It remains your organisation's data, available to your former colleagues, the same way a departing employee's work product stays with their employer's records rather than leaving with them. Only content that was genuinely personal to you and never tied to your company (e.g. work from before you joined, or under a separate personal account) is deleted.
How your account itself is handled. For a company member, or a solo user with billing history, your User record is anonymized rather than removed: your email is replaced with a non-reversible internal reference, your sign-in with us is deleted, and your name, phone number, job title, industry, and any recorded street address are all cleared — but the row itself stays (company members are also detached from the organisation). This is necessary because other records — your organisation's data, or our own retained financial records — refer back to your account and need to stay valid. For a solo user with no billing history, the account row is removed outright.
What is retained, and why. Nigerian tax law (the Companies Income Tax Act, the Companies and Allied Matters Act, and FIRS guidance) requires us to retain financial and transactional records for six (6) years. We retain the minimum necessary financial facts (payment amounts, dates, subscription plan, and payment processor reference) for this period — but we do not keep these records linked to your full personal profile once your account relationship ends; your name and email on these records are replaced with an internal reference, consistent with NDPA's principle that personal data should only be retained as long as necessary for the specific purpose it serves — here, that purpose narrows from "operating your account" to "our own tax record-keeping obligation."
Accountability record. We keep a minimal internal log confirming that a deletion request was made and completed, using a one-way cryptographic reference that cannot be reversed to identify you. This exists solely so we can demonstrate, if ever required, that we genuinely honour deletion requests — it does not retain your personal data.
Internal administrative records. Where a member of our team takes an action on your account or your organisation's behalf — for example, resolving a support ticket that required a team-membership or billing correction — we keep an internal record of that action (what was done, and which staff member did it) for five years. This is separate from, and not affected by, your own account's data lifecycle described above: it exists so we can hold our own team accountable for actions taken on the platform, not to track your activity, and it is retained for a genuinely decided period (long enough to support a real after-the-fact review — e.g. a billing dispute — short enough that it isn't indefinite by default) rather than kept forever.
Sole administrators. If you are the sole Administrator of an organisation account, self-service deletion is not available to you directly, since it would leave your organisation's data without anyone able to manage it. Please contact compliance@fortresspointconsulting.com to arrange this — we will work with you to transfer administration to a colleague first. If what you actually want is deletion of your organisation's entire data footprint, we can also arrange that — contact us at the same address above to request it. This isn't a self-service action you can trigger directly, given how irreversible it is, but once confirmed, we carry it out using a dedicated deletion process that removes your organisation's data completely and reliably.
Data about third parties we process on your behalf. In the course of providing the Service, we also process personal data about people who are not our own users and have no direct relationship or account with FortressPoint — specifically, your own employees (where you use our staff training feature) and your vendors and their staff (where you use our vendor risk assessment feature). You are the data controller for this information; we act as processor. Because this population never consented to a relationship with us directly, we apply defined retention periods rather than keeping this data indefinitely:
- *Staff training roster records* are retained for 12 months after you mark a staff member as inactive/removed, then permanently deleted. This is intended to cover a full annual training-compliance audit cycle after someone leaves, without retaining their data indefinitely.
- *Vendor assessment records* (vendor profiles, questionnaire answers, and any follow-up requests/answers, including uploaded evidence files) are retained for 24 months from the last activity on that vendor relationship (the most recent assessment completion, or follow-up completion, whichever is later), then permanently deleted, including the underlying evidence files.
These purges run automatically; there is no manual step required on your part, and no way to opt out of them, since indefinite retention of this specific population's data is the underlying problem they exist to fix.
8. Your Rights
Depending on your location, you may have rights including: access to your personal data, correction of inaccurate data, deletion of your data, objection to certain processing, and data portability.
Deletion specifically can be requested directly within the Service itself, from your account settings — see Section 7 above for exactly what happens once you do. For all other rights requests, or if you are a sole Administrator needing to arrange deletion of an organisation account, contact us at compliance@fortresspointconsulting.com or through our in-Service support ticket form.
We will respond to legitimate requests within the timeframes required by applicable law. If you are unsatisfied with our response, you may escalate your concern to Nigeria's National Data Protection Commission (NDPC), or, where applicable, your local data protection authority.
9. Automated Decision-Making
We reviewed every automated and AI-assisted feature in the Service to determine whether any of them make a decision about you that produces a legal or similarly significant effect, without meaningful human involvement.
Our compliance scoring, AI Compliance Assistant, proactive reminders, vendor risk-tier recommendations, AI-assisted questionnaire answer drafting, AI-generated compliance documents, and regulatory update monitoring are all informational or advisory: each either shows information back to you for your own review, or produces draft content that a human must review and choose to act on before it has any real-world effect. None of these features make a decision about you.
One specific, disclosed exception. If a scheduled subscription payment fails, our payment processor notifies our system automatically, and the paid features of your account are suspended immediately (reverting to our free tier) without a FortressPoint staff member reviewing the failure first. This is a mechanical application of our payment terms based on an objective, verifiable fact (whether a charge succeeded) rather than an evaluation of you as a person. If you believe this happened in error, or you've since corrected your payment method, contact us at compliance@fortresspointconsulting.com and we will review and restore your access.
10. Cookies
We use essential cookies necessary for authentication and maintaining your signed-in session. We do not currently use non-essential tracking or advertising cookies.
11. Children's Data
The Service is intended for use by business professionals and is not directed at or intended for use by individuals under the age of 18. We do not knowingly collect personal data from children.
12. Security
We apply reasonable technical and organisational measures to protect your data, including encryption in transit and access controls. No system can be guaranteed fully secure, and we encourage you to use a strong, unique password for your account.
13. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes through the Service or by email before they take effect.
14. Contact and Complaints
If you have questions, concerns, or a complaint about how we handle your personal data, please contact us at: compliance@fortresspointconsulting.com, or through our in-Service support ticket form (selecting the appropriate category).
We aim to acknowledge and address all data protection concerns directly and promptly, consistent with the same standard of accessible, no-legal-knowledge-required complaint handling (in the spirit of the GAID's Standard Notice to Address Grievance approach) that we help our own customers build for their users.