DMILZE LIMITED — Privacy Policy
Last updated: 31 July 2026
1. Introduction
DMILZE LIMITED ("DMILZE," "we," "us," or "our"), a private company limited by shares incorporated in the Federal Republic of Nigeria under the Companies and Allied Matters Act, 2020 (RC 9638639), with its registered office at B7, Apple Wood Estate 3, Princestone View Estate, Harris Drive, Lekki, Lagos State, Nigeria, respects your privacy and is committed to protecting the personal data of everyone who uses our website, platforms, and services (collectively, the "Services").
This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and the rights you have over it. It applies to our website(s) (including dmilze.com and any subdomains), our EdTech, ServTech, Labs, and Explore offerings, and any client project engagements initiated through "Start a Project" or similar features.
This Policy is issued in compliance with the Nigeria Data Protection Act, 2023 ("NDPA") and the applicable regulations of the Nigeria Data Protection Commission ("NDPC"), and, where relevant to users outside Nigeria, with international data protection standards such as the EU/UK General Data Protection Regulation ("GDPR").
By accessing or using our Services, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, please do not use our Services.
2. Who We Are
- Data Controller: DMILZE LIMITED
- RC Number: 9638639
- Registered Address: B7, Apple Wood Estate 3, Princestone View Estate, Harris Drive, Lekki, Lagos State, Nigeria
- Contact Email: official@dmilze.com
3. Information We Collect
We collect the following categories of personal data, depending on how you interact with us:
3.1 Account and Identity Information
When you register for an account, including via email/password or "Sign in with Google" (OAuth), we (or our authentication processor) collect:
- Full name
- Email address
- Profile picture (if provided via Google)
- Password (stored in encrypted/hashed form; we never store plain-text passwords)
- Authentication tokens and login timestamps
3.2 Client and Project Information
If you engage us for a project (e.g., through "Start a Project"), we collect:
- Company or organization name
- Business contact details (phone number, address, role/title)
- Project briefs, requirements, and specifications
- Communications exchanged during scoping, delivery, and support
3.3 Payment and Billing Information
If you purchase services or make payments to us:
- Billing name and address
- Transaction history, invoice, and payment records
- Limited payment metadata (e.g., last four digits of a card, payment method type)
We do not directly store full card numbers, CVV codes, or bank account credentials. All payment processing is handled by PCI-DSS-compliant third-party payment processors, who act as independent data processors/controllers for the payment data they handle.
3.4 Usage and Technical Data
- IP address, browser type and version, device identifiers, operating system
- Pages visited, features used, time spent, referring/exit pages
- Log files, error reports, and diagnostic data
- Cookies and similar tracking technologies (see Section 9)
3.5 Communications
- Emails, support tickets, chat messages, and feedback you send us
- Records of calls or meetings scheduled through our Services
4. How We Use Your Information
We use personal data for the following purposes:
- To provide and maintain the Services, including creating and managing your account, authenticating your identity, and delivering EdTech, ServTech, Labs, and Explore offerings.
- To fulfil client project engagements, including scoping, communicating, invoicing, and delivering contracted work.
- To process payments, issue invoices/receipts, and manage billing disputes or refunds.
- To communicate with you, including service updates, security alerts, administrative messages, and (where you have consented) marketing communications.
- To improve our Services, including analytics, troubleshooting, research, and product development.
- To ensure security, including fraud prevention, abuse detection, and enforcing our Terms of Service.
- To comply with legal obligations, including tax, accounting, and regulatory recordkeeping requirements under Nigerian law.
5. Legal Basis for Processing
Under the NDPA, we process your personal data on one or more of the following legal bases:
- Consent — where you have given clear consent (e.g., for marketing communications or optional cookies).
- Contractual necessity — where processing is necessary to perform a contract with you (e.g., delivering a project you commissioned, maintaining your account).
- Legal obligation — where we must process data to comply with Nigerian law (e.g., tax and financial recordkeeping).
- Legitimate interests — where processing is necessary for our legitimate business interests (e.g., securing our platform, improving our Services), provided this does not override your fundamental rights.
6. Third-Party Service Providers
We rely on trusted third-party providers ("data processors") to operate our Services. These may include:
- Authentication providers (e.g., Google OAuth) — for secure sign-in.
- Backend/database infrastructure providers (e.g., Supabase) — for hosting account and application data.
- Payment processors — for securely handling transactions.
- Cloud hosting providers — for hosting our website and application infrastructure.
- Analytics providers — for understanding usage patterns (where enabled).
- Email/communication tools — for transactional and support correspondence.
These providers only process personal data on our instructions and are contractually bound to protect it in accordance with applicable data protection law. Some of these providers may process or store data on servers located outside Nigeria; where this occurs, we take reasonable steps to ensure an adequate level of protection, including standard contractual clauses or equivalent safeguards, as required under the NDPA.
7. How We Share Your Information
We do not sell your personal data. We may share personal data:
- With the third-party processors listed in Section 6, strictly to operate our Services.
- With professional advisors (lawyers, auditors, accountants) where necessary.
- With regulators, courts, or law enforcement where required by Nigerian law or a valid legal process.
- With a successor entity in the event of a merger, acquisition, restructuring, or sale of assets, subject to equivalent privacy protections.
- With your explicit consent, for any other purpose not listed above.
8. International Data Transfers
Because some of our service providers operate infrastructure outside Nigeria, your personal data may be transferred to and processed in countries other than Nigeria. Where this happens, we ensure such transfers comply with the cross-border data transfer requirements of the NDPA, including verifying that the receiving country/organization maintains an adequate level of data protection or that appropriate contractual safeguards are in place.
9. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Keep you signed in and remember your preferences.
- Understand how visitors use our website (analytics).
- Improve site performance and security.
You can control cookies through your browser settings, including blocking or deleting them. Disabling essential cookies may affect the functionality of our Services (e.g., you may not be able to stay signed in).
10. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, including:
- For as long as your account remains active, plus a reasonable period afterward to allow for account recovery.
- As required to comply with legal, tax, and accounting obligations (generally a minimum of 6 years for financial records under Nigerian law).
- As necessary to resolve disputes, enforce our agreements, and protect our legal rights.
When personal data is no longer needed, we securely delete, anonymize, or archive it in accordance with applicable law.
11. Data Security
We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction, including:
- Encryption of data in transit (TLS/HTTPS) and, where applicable, at rest.
- Access controls limiting internal access to personal data on a need-to-know basis.
- Secure authentication practices, including hashed/salted password storage.
- Regular monitoring for suspicious activity.
No method of transmission or storage is 100% secure. While we strive to protect your personal data, we cannot guarantee absolute security.
12. Your Rights
Subject to applicable law, including the NDPA (and GDPR where applicable), you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — request correction of inaccurate or incomplete data.
- Erasure — request deletion of your personal data, subject to legal retention requirements.
- Restriction — request that we limit how we process your data in certain circumstances.
- Objection — object to processing based on legitimate interests or for direct marketing.
- Data portability — request your data in a structured, commonly used, machine-readable format.
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
- Lodge a complaint — with the Nigeria Data Protection Commission (NDPC), or another applicable supervisory authority, if you believe your data protection rights have been violated.
To exercise any of these rights, contact us at official@dmilze.com. We will respond within the timeframe required by applicable law (generally within one month under the NDPA, extendable in complex cases).
13. Children's Privacy
Our general platform and account registration are not directed at, and not intended for use by, children under the age of 13 (or under 16 where required by applicable law), and we do not knowingly collect personal data directly from such children through account sign-up.
Where DMILZE delivers technology education or capacity-building programs designed for younger learners (e.g., school or youth-focused initiatives), any collection of personal data relating to minors is conducted with the verified consent of a parent, guardian, or supervising institution (such as a school), and only to the extent necessary to deliver the relevant program. If we become aware that we have collected personal data from a child without appropriate consent, we will take steps to delete such data promptly.
14. Third-Party Links
Our Services may contain links to third-party websites or services not operated by us. This Privacy Policy does not apply to those third-party sites, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party sites you visit.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will post the updated Policy on this page with a revised "Last updated" date. Material changes will be communicated via email or a prominent notice on our Services where appropriate. Your continued use of the Services after changes take effect constitutes acceptance of the revised Policy.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:
DMILZE LIMITED
Attn: Data Protection Contact
B7, Apple Wood Estate 3, Princestone View Estate, Harris Drive, Lekki, Lagos State, Nigeria
Email: official@dmilze.com
---
*This Privacy Policy is a template prepared for DMILZE LIMITED's general use and does not constitute legal advice. We recommend having this document reviewed by a licensed Nigerian attorney familiar with data protection law before publishing it as your final, binding policy.*