Our Privacy Commitment in Plain Terms
At 9jaonCloud Infrastructure & Consulting, we operate on a strict zero data-brokering principle. We never sell, monetize, or rent your personal data to advertisers or commercial tracking networks. Data gathered across our platforms is utilized strictly for technical execution, service delivery, continuous product enhancement, and safeguarding system integrity under the Nigeria Data Protection Act (NDPA) 2023 and international privacy benchmarks.
1. Information We Collect
We collect only the minimum necessary information required to deliver enterprise cloud infrastructure, software platforms, and technical consultancy:
- Direct Contact & Identity Data: Full name, professional email address, phone number, organization name, and physical location when you book consultations, request quotes, or initiate support tickets.
- Technical Environment & Diagnostic Data: IP address, device architecture, operating system, browser user-agent headers, network latency, and error tracebacks.
- Authentication & Session Identifiers: Secure hashed credentials, multi-factor authorization tokens, and single sign-on (SSO) session tokens managed via our centralized Accounts IAM platform.
- Recruitment & Contractor Submissions: Resumes, portfolios, certifications, and background verification records when applying for employment or engineering vendor contracts.
2. Transparent Disclosure: SpecForge AI & Public Feedback Ingestion
To provide world-class engineering governance, we utilize SpecForge AI (hosted at specforge.9jaoncloud.com.ng) as our official platform for managing software specifications, roadmap requirements, and public feedback intake across all 9jaonCloud initiatives (including the Nyx Programming Language, Public Opinion OrgTrust, and client custom projects).
What Data is Processed via SpecForge:
- Public Bug Reports & Feature Proposals: Issue title, severity level, reproduction steps, expected versus observed software behavior, and optional screenshots/screen recordings you submit.
- System Environment Headers: Client user-agent, operating system version, and client-side console logs specifically attached during bug submission to diagnose reproducible software faults.
- Reporter Contact Info (Optional): Your name and email address if you choose to receive ticket status updates (e.g., triage notifications, patch releases, or PRD roadmap inclusion).
Purpose & Operational Rationale: We process this data under our legitimate engineering interest and with your explicit consent to identify software regressions, debug bare-metal and cloud runtimes, coordinate developer patches, and keep contributors updated on resolution status. Feedback data is never used for advertising profiling.
3. Transparent Disclosure: First-Party Analytics & Telemetry
We believe in radical transparency regarding site analytics and operational telemetry. We collect aggregate and anonymized metrics for the following specific technical reasons:
- Latency & Edge Performance Tuning: Measuring page load durations, time-to-first-byte (TTFB), and asset rendering speeds to optimize our CDN edge caching across African and global networks.
- Defect Detection & Crash Analytics: Tracking unhandled client-side JavaScript errors, broken routes, and API timeout events to deploy rapid hotfixes.
- Infrastructure Capacity Sizing: Monitoring concurrent user volume and peak compute loads to auto-scale container clusters and database read replicas.
- Threat Mitigation & DDoS Defense: Identifying automated bot scrapers, brute-force credential stuffing attempts, and anomalous traffic bursts to protect server availability.
- Feature Adoption Analysis: Evaluating aggregate navigation trends and documentation engagement to prioritize developer tooling and UX improvements.
Note: Our telemetry is privacy-preserving and first-party. We do not use intrusive cross-site behavioral tracking beacons or third-party ad networks.
4. Legal Grounds for Data Processing
In adherence to the Nigeria Data Protection Act (NDPA) 2023 and the EU General Data Protection Regulation (GDPR), our lawful bases include:
- Contractual Performance: Providing cloud services, software deliverables, and billing commitments.
- Legitimate Technical Interests: Securing server infrastructure, triaging bugs via SpecForge, preventing fraud, and optimizing system uptime.
- Explicit User Consent: Voluntarily subscribing to engineering newsletters, participating in public community feedback, or opting into non-essential cookies.
- Legal & Regulatory Mandate: Retaining financial audit records and responding to lawful statutory requests by competent authorities.
5. Third-Party Service Providers & Infrastructure Partners
We share information strictly with vetted technical providers operating under rigorous data processing and non-disclosure agreements:
- Cloud Hosting & Compute Infrastructure: Secure tier-3/tier-4 data centers and bare-metal server infrastructure.
- Transactional Email Gateways: SMTP servers (e.g., MailChannels, cPanel Mail Services) for appointment confirmations, security OTPs, and bug tracking alerts.
- Payment Processors: PCI-DSS certified gateways (Paystack, Flutterwave, Stripe) for subscription and invoice settlement. We never store raw credit card numbers on our servers.
6. Data Security Safeguards
We employ multi-layered technical, cryptographic, and operational safeguards to defend your information:
- Mandatory SSL/TLS 1.3 encryption across all ecosystem subdomains with HTTP Strict Transport Security (HSTS).
- Zero-trust database segmentation and parameterized SQL queries to prevent injection attacks.
- Encrypted storage of sensitive authentication credentials using modern Argon2id and BCrypt algorithms.
- Statutory 72-hour data breach notification protocol in compliance with the Nigeria Data Protection Commission (NDPC) requirements.
7. Data Retention Policy
We adhere to strict data minimization. Personal data is retained only for the period necessary to accomplish stated objectives:
- Consulting & Client Projects: Active engagement duration plus 7 years for statutory corporate tax and accounting records.
- SpecForge Bug Submissions: Retained during the active software development lifecycle or until resolution/archival.
- Analytics & Server Access Logs: Rotated and anonymized after 90 days.
- Marketing & Newsletter Records: Retained until explicit user unsubscription or 24 months of inactive engagement.
8. Your Statutory Rights
Under NDPA 2023 and GDPR, you retain full sovereignty over your personal information, including:
- Right of Access: Request a full machine-readable export of your personal data.
- Right to Rectification: Promptly update inaccurate or incomplete information.
- Right to Erasure ("Right to be Forgotten"): Request complete deletion of your records, subject to legal compliance requirements.
- Right to Restrict or Object: Restrict specific processing streams or withdraw consent for marketing and analytics telemetry.
- Right to Lodge a Complaint: File a regulatory grievance with the Nigeria Data Protection Commission (NDPC) or your regional data protection authority.
To exercise any statutory right, contact our Data Protection Officer at dpo@9jaoncloud.com.ng.
9. Data Protection Officer & Institutional Contact
Data Protection Office • 9jaonCloud Infrastructure
Attention: Simeon Bala (Chief Architect & Data Controller)
Email: dpo@9jaoncloud.com.ng • info@9jaoncloud.com.ng
Phone: +234 808 532 4278
Corporate Address: 1 No 39, 1st Avenue, Festac Town, Lagos State, Nigeria
Your Consent & Continued Use
By continuing to interact with 9jaonCloud platforms, APIs, SpecForge studio, or affiliated portals, you acknowledge having reviewed this Privacy Policy and agree to our transparent, privacy-first data processing standards.