Privacy notice · September 2026

Collect less. Use it clearly. Retain it deliberately.

This notice explains the public website, Learning Hub profiles and discussions, and the assessment-enquiry workflow. Client engagements receive additional contractual privacy terms appropriate to their scope.

Information we collect

The assessment form collects organisation name, contact name, business email, team-size range, current tools, service interest, timing, and the business context you choose to provide. Do not submit passwords, verification codes, private keys, payment-card details, or sensitive incident evidence.

Why we use it

We use enquiry information to understand your request, assess whether there is a suitable service fit, respond, arrange discovery, and prepare a written next step. A contracted email-delivery provider processes limited contact and routing details to send your acknowledgement and alert authorized staff of a new request. The full enquiry remains in the protected workspace and is not copied into the acknowledgement. We do not use the form to create public profiles, send unrelated marketing, or sell contact data.

Retention and access

Active enquiries are retained for up to 180 days unless a longer period is required for an agreed engagement or legal obligation. Access is restricted to authorized administration staff. Expired records are excluded from the active enquiry workspace and become eligible for operational deletion.

Your choices

You may request access, correction, or deletion of enquiry information by contacting hello@securityfirst.ng. We may need to verify that you are authorized to act for the relevant contact or organisation.

Learning profiles

The Learning Hub collects your display name and email address. If you register by email, it also receives your password and sends a six-digit verification code before activating the profile. If you continue with Google, Google confirms the email and supplies the account name used to create or recognise your profile; SecurityFirst.ng does not receive your Google password. In our database, the email and Google account identifier are transformed with a protected keyed one-way process and stored with a masked email hint. Email verification codes and Learning Hub passwords are stored only as protected verifiers; we do not store either one in readable form. Your display name appears beside comments, while reactions and comments are saved to your profile.

Email delivery and retention

Resend processes the full email address and verification-message content to deliver the one-time account code under its own service terms. Pending verification records expire after 10 minutes and are removed during routine cleanup. Verified learning profiles, their protected email identifiers and password verifiers, masked hints, consents, reactions, and comments remain until deletion is requested, the profile is suspended for misuse, or an operational retention decision requires removal. Contact hello@securityfirst.ng for access, correction, or deletion.

Learning-profile access

We use the protected email identifier to recognise the same learner account and reduce duplicate profiles. Learners may use Google’s verified sign-in or register with email, password, and a one-time verification code. Later access uses the chosen Google account or the registered email and password. A secure device cookie keeps the learner signed in for up to 90 days unless they sign out or it expires.

Client-service data

Service delivery may involve different systems, records, providers, and retention needs. Those responsibilities must be documented in the proposal, contract, data-handling terms, and authorized access model before work begins.