PRIVACY POLICY
EFFECTIVE DATE: July 19, 2026
1. Our Approach to Privacy
1.1 The Startup Desk (“we,” “our,” or “us”) is committed to protecting your privacy. This privacy policy sets out how we collect, store, process, transfer, share, and use data that identifies or is associated with you (“personal information”), and our use of cookies.
1.2 Regulatory Notice: The Startup Desk is a compliance consultancy providing post-incorporation, tax, and data protection compliance services to early-stage Nigerian startups. We are not a law firm and do not provide legal representation or legal advice.
1.3 This privacy policy applies to our website, our contact forms, our AI chat assistant, and any client communications conducted in connection with our services.
1.4 Before using our website or engaging our services, please ensure you have read and understood our collection, storage, use, and disclosure of your personal information as described below. By using our website or services, you accept and consent to the practices described in this policy.
2. Personal Information We Collect and How We Use It
2.1 Information you give to us: We collect personal information you voluntarily submit directly to us via our website forms, WhatsApp, phone, email, or our AI chat assistant. This includes information provided when you request a consultation, sign up for a service tier, or submit an enquiry.
2.2 If you choose not to provide certain personal information, we may be unable to deliver the relevant service to you.
2.3 The table at Annex 1 sets out the categories of personal information you provide directly, the purpose, the lawful basis we rely on, and applicable retention periods.
2.4 We also automatically collect certain personal information about how you access and use our website.
2.5 The table at Annex 2 sets out the categories of personal information collected automatically, the purpose, lawful basis, and retention periods.
3. Disclosure of Your Personal Information
3.1 We do not sell your personal information. We only share it in the limited circumstances below.
3.2 Regulatory Filings: We may be required to disclose personal information in response to lawful requests by public authorities, including regulatory bodies such as the Corporate Affairs Commission (CAC), Federal Inland Revenue Service (FIRS), or the Nigeria Data Protection Commission (NDPC), where necessary to deliver the compliance filing services you have engaged us for.
3.3 Legal Protections: We may disclose personal information to comply with a legal obligation, enforce our Terms of Service, or protect the rights, property, or safety of The Startup Desk or our clients.
3.4 Third-Party Sub-processors: We work with a limited number of trusted third-party service providers who process personal data on our behalf:
- Cloudflare: Website hosting, performance, and security infrastructure.
- Zoho Mail: Secure corporate business email communications.
- Tally.so: Client intake and enquiry form processing.
- Secure payment processing (we do not process or store your card details).
- AssistLoop AI: Our AI-powered web chat assistant (see Section 9).
- Google Analytics: Anonymous website usage analytics (see Section 8).
4. Storing and Transferring Your Personal Information
4.1 Security: We implement administrative, technical, and physical safeguards to protect your information. Where any account access credentials or corporate login details are shared for compliance tasks, you are responsible for keeping them confidential.
4.2 Risk Acknowledgment: While no transmission over the internet is completely secure, we take reasonable measures to protect your personal information. We cannot guarantee absolute security; any transmission is at your own risk.
4.3 Safeguards: Technical measures include access controls limiting data access to authorised personnel, secure handling of digital form submissions, and periodic review of our internal data-handling workflows.
4.4 Cross-Border Transfers: Your personal information is processed primarily within infrastructure operated by our third-party providers listed in Section 3.4, some of which operate global server networks (e.g., Cloudflare). Where your data is processed outside Nigeria as a result, we take reasonable steps to ensure it remains protected to a standard consistent with the Nigeria Data Protection Act 2023.
5. Retaining Your Information
5.1 We retain personal information only as long as necessary to fulfil the purpose it was collected for, including our legitimate business interests and legal, statutory, or reporting obligations.
5.2 Execution Criteria: To determine retention periods, we consider the nature and sensitivity of the information, the potential risk of harm from unauthorised use, the specific purpose of processing, and statutory legal requirements. See Annexes 1 and 2 for data schedules.
6. Your Rights Under the NDPA 2023
6.1 In accordance with the Nigeria Data Protection Act 2023, you possess the following statutory rights regarding your personal data:
- Right of Access: To obtain confirmation of, and direct access to, your personal information.
- Right to Rectification: To correct inaccurate, outdated, or incomplete personal information.
- Right to Erasure (“Right to be Forgotten”): To request deletion of your personal information where it is no longer necessary for the purpose collected.
- Right to Restriction: To request that we pause or restrict the processing of your data in certain scenarios.
- Right to Object: To object to processing on grounds relating to your particular situation, including direct marketing.
- Right to Withdraw Consent: Where we rely on your explicit consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right to Non-Discrimination: You will not be denied services or charged differently for exercising any of your privacy rights.
6.2 Exercise of Rights: To exercise any of these rights, contact us using the details in Section 12. We may request identity verification before actioning a request, and will respond within 30 days.
6.3 Statutory Declaration: We have not sold personal information shared by you in the 12 months preceding the effective date of this policy.
6.4 Regulatory Complaints: You have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe our processing does not comply with local law. The NDPC can be contacted via their official portal at ndpc.gov.ng.
7. Data Breach Response
7.1 In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the NDPC within 72 hours of becoming aware of the breach.
7.2 Where a breach is likely to result in a high risk to your immediate rights and freedoms, we will notify you directly without undue delay, providing sufficient information to allow you to take immediate protective measures.
8. Cookies and Tracking Tools
8.1 Analytics: Our website uses Google Analytics, which sets cookies (including _ga and _gid) to help us understand how visitors interact with our site, such as pages visited, traffic channels, and general usage patterns. These cookies do not, by themselves, identify you personally.
8.2 First-Party Data Processing: To optimize performance and privacy, our tracking tags are served via a first-party Google Tag Gateway managed securely through Cloudflare. This ensures that analytics data is proxied directly via our domain framework rather than allowing direct third-party script intervention on your device.
8.3 Management: By continuing to use this website, you acknowledge and consent to this use of analytics cookies. You can disable cookies at any time via your browser settings. Doing so will not prevent you from contacting us or accessing our core services. See our full Cookie Policy for complete management details.
8.4 We do not use third-party behavioral advertising cookies on this website.
9. AI Assistant Disclaimer
9.1 Guidance Only: Our website includes an AI-powered chat assistant (provided via AssistLoop) for rapid guidance regarding our services, compliance tiers, and pricing.
9.2 Legal Disclaimer: This assistant is not a lawyer, does not provide legal advice, and is not a substitute for professional counsel. Any conversation content is processed by our third-party chat infrastructure to generate real-time responses.
9.3 Information Guardrail: Please avoid sharing sensitive personal data, corporate bank details, credentials, or highly confidential trade secrets through the chat assistant that you would not want processed by an automated system.
10. Our Policy Towards Children
10.1 The Startup Desk’s services are strictly directed at corporate operators and individuals over 18 years of age. We do not knowingly collect personal information from minors. If you become aware that a minor has provided us with personal information, please contact us so we can purge the record.
11. Changes to This Policy
11.1 We may update this policy from time to time to match changing regulatory standards or operational practices. Material updates will be reflected by modifying the effective date at the top of this page. Continued use of our website after changes are posted constitutes acceptance of the revised policy.
12. Contacting Us
12.1 If you have questions, concerns, regulatory requests, or wishes regarding your personal information or this policy, please contact us directly at:
Email: hello@thestartupdesk.com.ng
ANNEX 1 - Information You Provide Directly
| Category | Purpose | Lawful Basis | Retention |
|---|---|---|---|
| Name | Client identification and service delivery | Performance of a Contract | 6 years post-engagement |
| Email Address | Communication and service delivery | Performance of a Contract | 6 years post-engagement |
| Phone Number | Direct communication regarding compliance | Performance of a Contract | 6 years post-engagement |
| Business Details | Delivering CAC, FIRS, or NDPC compliance | Contract & Legal Obligation | 6 years post-engagement |
| Payment Info | Processing service payments (via Payment Processors) | Performance of a Contract | Per the payment processors terms (we don’t store cards) |
| Leads Data | Responding to inquiries prior to engagement | Legitimate Interest | 12 months from contact |
ANNEX 2 - Information Collected Automatically
| Category | Purpose | Lawful Basis | Retention |
|---|---|---|---|
| IP Address | Website security and fraud prevention | Legitimate Interest | 12 months |
| Device Data | Platform compatibility and UI stability | Legitimate Interest | 12 months |
| Session Data | Understanding website usage via Gateway | Legitimate Interest / Consent | Per Google Analytics standard settings |