The short version
1. Who we are
[Company legal name] (“Aqoon”, “we”, “us”) provides a gamified security and compliance training platform. Our registered address is [Street address], [City], [Country]. You can contact our Data Protection Officer at privacy@aqoonhq.com.
2. Our role: controller or processor
How we handle your data depends on how you use Aqoon:
- Members of an organization’s workspace. Your organization decides why and how your training data is used. It is the data controller; we are its data processor and act on its instructions under a data processing agreement. For requests about this data, contact your organization’s admin and we will help them respond.
- Workspace owners, website visitors and people who contact us. For account, billing, marketing and website data, we are the data controller.
- Guests who join a public challenge with a code. The organization hosting the challenge is the controller of your challenge results; we process them on its behalf.
3. Information we collect
- Account details: name, work email, job role, team, organization, profile photo or avatar, and password (stored only as a secure hash).
- Training data: games played, answers, scores, XP, badges, certificates, and challenge progress.
- Guest details: full name, department (or other fields the host requests), join code used, and results.
- Usage and device data: log-ins, pages visited, browser and device type, IP address, and approximate location derived from it.
- Communications: messages you send us, and support conversations.
- Billing data for paid plans: billing contact, invoices and transaction references. Card details are handled by our payment provider, not stored by us.
We do not intentionally collect sensitive personal data (such as health, religion or biometric data) and ask you not to include it in custom content or messages.
4. How we use it and our lawful bases
We use personal data to:
- provide the platform: accounts, games, leaderboards, certificates and reports (contract, or on our customer’s instructions);
- produce training evidence for your organization’s compliance obligations (legitimate interests / legal obligation of our customer);
- keep the service secure, prevent fraud and fix problems (legitimate interests);
- send service emails such as invites, reminders and security alerts (contract);
- send marketing to business contacts, which you can opt out of at any time (consent or legitimate interests, as the law requires);
- comply with the law and respond to lawful requests (legal obligation).
These bases are drawn from the Nigeria Data Protection Act 2023 (NDPA) and, where it applies, the EU/UK General Data Protection Regulation (GDPR).
5. Leaderboards and what others see
Leaderboards show your display name, team, score and badges to other people in the same workspace or challenge. You can choose to appear as “Anonymous player” in Settings, unless your organization requires named results for required training. Admins can always see results for training they assign.
7. International transfers
Data is stored in the region chosen for each workspace. Where personal data moves outside Nigeria, the EU or the UK, we use safeguards recognized by the NDPA and GDPR, such as adequacy decisions or standard contractual clauses, and assess the protection in the destination country.
8. How long we keep it
- Training results: for the period set by your organization (by default [3 years]) to support audits.
- Guest challenge data: deleted [90 days] after the challenge ends, unless the host sets a shorter period.
- Account data: while your account is active, then deleted or anonymised within [90 days] of closure.
- Billing records: as long as tax law requires.
9. How we protect it
We encrypt data in transit and at rest, restrict access by role, require multi-factor authentication for our staff, log administrative actions, and test our systems regularly. No system is perfectly secure; if a breach affects your personal data, we will notify the relevant authority and affected customers as the law requires.
10. Your rights
Under the NDPA and GDPR you may have the right to: access your data; correct it; delete it; restrict or object to processing; receive it in a portable format; withdraw consent; and not be subject to decisions based solely on automated processing with significant effects.
Members can use Settings → Your data. You can also email privacy@aqoonhq.com. If your data is controlled by your organization, we will pass your request to its admin. You may complain to the Nigeria Data Protection Commission (NDPC) or your local data protection authority.
11. Children
Aqoon is designed for workplaces and is not intended for children under 18. We do not knowingly collect their data.
13. Changes to this policy
We will post updates here and change the date at the top. For significant changes, we will notify workspace admins by email before they take effect.
14. Contact us
Data Protection Officer · privacy@aqoonhq.com
[Company legal name], [Street address], [City], [Country]