Skip to content
Engineering Digital Excellence
Damhills

Data Protection Policy

Effective Date: January 2024
Last Updated: July 2025
Policy Owner: Damhills Technologies Limited

1. Introduction

Damhills Technologies Limited ("Damhills," "we," "us," or "our") is committed to protecting the privacy, confidentiality, and security of all personal and business data entrusted to us by our clients, partners, employees, and website visitors. This Data Protection Policy outlines our principles, practices, and obligations in handling, processing, storing, and transmitting data.

This policy applies to all data processing activities conducted by Damhills Technologies, including but not limited to software development projects, cybersecurity audits, network infrastructure installations, training programmes, and all interactions through our website and communication channels.

2. Regulatory Compliance

We operate in compliance with the following data protection regulations and frameworks:

  • Nigeria Data Protection Regulation (NDPR) — issued by the National Information Technology Development Agency (NITDA)
  • Nigeria Data Protection Act (NDPA) 2023 — the principal data protection legislation in Nigeria
  • General Data Protection Regulation (GDPR) — for data processing related to UK and EU data subjects
  • ISO 27001 Information Security Management — as the international standard for information security

3. Data We Collect

Depending on the nature of our engagement, we may collect and process the following categories of data:

Personal Information

Names, email addresses, phone numbers, job titles, and professional affiliations provided during project onboarding or contact form submissions.

Business Data

Company names, registration details, financial records, and operational data shared for the purpose of software development or consulting engagements.

Technical Data

IP addresses, browser type, device information, and usage analytics collected automatically when you visit our website.

Project Data

Source code, database records, design files, and infrastructure configurations created or accessed during service delivery.

4. How We Use Your Data

We process personal and business data strictly for the following purposes:

  • To deliver, maintain, and improve the software services and solutions contracted by our clients
  • To communicate project updates, deliverables, and support responses
  • To comply with legal, regulatory, and contractual obligations
  • To ensure the security and integrity of our IT systems and infrastructure
  • To send marketing communications only with explicit consent (opt-in)
  • To process payments and manage financial records related to our services

5. Data Security Measures

We implement robust technical and organisational measures to protect data against unauthorised access, alteration, disclosure, or destruction:

Encryption

AES-256 encryption at rest and TLS 1.3 in transit for all data transmissions

Access Control

Role-based access, multi-factor authentication, and principle of least privilege

Auditing

Regular vulnerability assessments, penetration testing, and compliance audits

6. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable laws and regulations. Project-related data is retained for the duration of the client engagement plus a reasonable period for warranty, support, and legal compliance purposes. Upon expiry of the retention period, data is securely deleted or anonymised.

7. Your Rights

Under applicable data protection laws, you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — request correction of inaccurate or incomplete data
  • Erasure — request deletion of your personal data where there is no compelling reason for continued processing
  • Restriction — request restriction of processing in certain circumstances
  • Portability — request transfer of your data in a structured, machine-readable format
  • Objection — object to processing of your data for direct marketing or legitimate interests

To exercise any of these rights, please contact us at info@damhillstechnologieslimited.com.

8. Data Breach Notification

In the event of a personal data breach, Damhills Technologies will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with NDPR and GDPR requirements. Where the breach is likely to result in a high risk to the rights and freedoms of individuals, we will also notify the affected data subjects without undue delay.

9. Contact Us

For any questions, concerns, or requests related to this Data Protection Policy or our data processing practices, please contact:

Damhills Technologies Limited

Data Protection Officer

Okpanam Road, GRA Phase I, Asaba, Delta State, Nigeria

Email: info@damhillstechnologieslimited.com