Privacy Policy
How Digital Vortex Tech Limited handles personal information across Hubtoll ERP and this website.
This Privacy Policy (the “Policy”) explains how Digital Vortex Tech Limited, a company incorporated in the Federal Republic of Nigeria (“Digital Vortex”, “Hubtoll”, “we”, “us”, or “our”) collects, uses, discloses, protects, and retains personal information in connection with the Hubtoll ERP platform, our websites, applications, APIs, and related services (together, the “Services”). It should be read together with our Terms & Conditions, of which it forms a part.
1. Introduction
1.1 Scope. This Policy applies to (i) visitors to our marketing website; (ii) individuals who sign up for, administer, or use the Hubtoll platform; and (iii) personal information contained in data our customers process through the Services, including data from mailboxes that users choose to connect.
1.2 Hubtoll in brief. Hubtoll is an all-in-one, multi-tenant ERP platform. Its modules include Human Resources, Performance Management, Document Management (EDMS), Sales & Finance, and Customer Relationship Management (CRM). Each customer organisation (a “Corporate” or “Customer”) operates its own isolated workspace.
2. Who We Are & Our Roles
2.1 Controller vs. processor. Our role under data-protection law depends on the context:
- As a data controller — for information we collect directly for our own purposes, such as account registration details, billing information, website analytics, and support communications.
- As a data processor — for the content and records a Customer submits to, generates in, or connects to the Services (“Customer Data”), including personal data of the Customer’s employees, contacts, and the contents of any mailbox a user connects. Here, the Customer is the controller and determines the purposes of processing; we process such data only on the Customer’s documented instructions and as needed to provide the Services.
2.2 This Policy and Customer Data. Where we act as a processor, the relevant Customer’s own privacy notice governs how that data is handled, and data-subject requests should be directed to that Customer. This Policy describes the safeguards we apply as processor.
3. Information We Collect
3.1 Account & identity information. When you register or are provisioned as a user, we collect your name, work email address, phone number (where provided), the organisation you belong to, your role and permissions, and authentication data (such as a securely hashed password and session tokens).
3.2 Customer Data you enter. The Services let Customers store and process business records — for example employee records, leave and appraisal data, documents, financial records, and CRM contacts, companies, and deals. This may include personal data about third parties (such as a Customer’s own staff or clients), which the Customer is responsible for having the right to process.
3.3 Connected mailbox data. If a user chooses to connect a Google (Gmail) or Microsoft (Outlook) mailbox to the CRM, we access, with that user’s explicit authorisation via the provider’s OAuth consent screen, the data needed to power the connected features — namely the user’s basic profile (name and email address) and the email messages required to display conversation history against CRM records and to send or reply to messages the user composes in Hubtoll. Access can be revoked at any time (see Section 15). Our handling of Google data is further described in Section 5.
3.4 Payment information. Subscription payments are processed by our third-party payment provider (Paystack). We do not store full card numbers; we receive limited transaction metadata (such as a reference, status, and amount) needed to activate and reconcile your subscription.
3.5 Usage, device & log data. When you use the Services we automatically collect technical information such as IP address, approximate location derived from IP, browser and device type, pages and actions, timestamps, and diagnostic logs. We use a per-request identifier to trace and resolve issues.
3.6 Cookies & similar technologies. Our website uses cookies and comparable technologies for essential functionality, preferences, and analytics, as described in Section 10.
3.7 Support & communications. When you contact us (by email, form, or messaging), we collect the information you provide and our correspondence with you.
4. How We Use Information
We use personal information to:
- provide, operate, secure, maintain, and support the Services, and authenticate users;
- power features the user has enabled — including, for connected mailboxes, showing email history against CRM records and sending or replying to messages the user composes;
- process subscriptions, payments, renewals, and invoicing;
- communicate with you about your account, service updates, security notices, and support requests;
- monitor, diagnose, debug, and improve performance, reliability, and security, and prevent fraud and abuse;
- understand website usage through analytics (in aggregate) to improve our marketing and product; and
- comply with legal obligations and enforce our Terms.
We do not sell personal information, and we do not use data obtained from connected Google or Microsoft mailboxes for advertising.
5. Google User Data & Limited Use
When you connect a Google account, Hubtoll requests only the OAuth scopes needed to provide the features you
use: your basic profile (openid, email, profile), read access to your
Gmail messages (gmail.readonly) to display conversation history against your CRM records, and the
ability to send messages on your behalf (gmail.send) for emails you compose within Hubtoll.
Limited Use disclosure. Hubtoll’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, in relation to data obtained through Google APIs, Hubtoll:
- only uses the data to provide and improve the user-facing features (CRM email sync and sending) for which the user granted access;
- does not transfer the data to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to users;
- does not use the data for serving advertisements, and does not sell the data; and
- does not allow humans to read the data, unless: (a) we have your affirmative agreement for specific messages; (b) it is necessary for security purposes (such as investigating abuse); (c) it is necessary to comply with applicable law; or (d) the data is aggregated and anonymised and used to improve internal operations.
5.1 Storage & encryption. Mailbox access and refresh tokens are encrypted at rest. We retain the minimum message data needed to provide the connected features and delete stored mailbox data when you disconnect the mailbox or delete the associated records (see Sections 12 and 15).
6. Microsoft (Outlook) Account Data
When you connect a Microsoft account, Hubtoll requests, with your consent, delegated Microsoft Graph permissions to read and send your mail and read your basic profile (Mail.Read, Mail.Send, User.Read, and offline_access), used solely to power the same CRM email-history and sending features. We apply the same limited-use, minimisation, encryption, and deletion principles described in Section 5 to Microsoft account data, and we do not use it for advertising or sell it.
7. Legal Bases for Processing
Where the Nigeria Data Protection Act, 2023 (“NDPA”) or, where applicable, other data-protection laws require a legal basis, we rely on: (i) performance of a contract (to provide the Services you request); (ii) consent (for example, connecting a mailbox, or non-essential cookies — which you may withdraw at any time); (iii) our legitimate interests in operating, securing, and improving the Services, balanced against your rights; and (iv) legal obligation. Where we process personal data as a processor, the relevant Customer is responsible for establishing the legal basis.
8. How We Share Information
We share personal information only as needed and as described here:
- Within your organisation — Customer Data is accessible to authorised users of the same Corporate according to the roles and permissions the Customer configures.
- Service providers / sub-processors — with vetted providers that help us deliver the Services, under contractual confidentiality and data-protection obligations (see Section 9).
- Payment provider — transaction details necessary to process payments.
- Legal & safety — where required by law, legal process, or to protect the rights, property, or safety of Hubtoll, our Customers, or the public.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, with notice consistent with this Policy.
We do not sell personal information, and we do not share data from connected mailboxes except as strictly necessary to provide the connected features or as required above.
9. Sub-Processors & Integrations
We rely on the following categories of third-party providers. Their processing is governed by their own agreements and privacy policies:
- Cloud hosting & storage — Amazon Web Services (compute, database, and document storage), where the Services and Customer Data are hosted.
- Payments — Paystack, for subscription payment processing.
- Transactional email — Amazon Simple Email Service, for account, notification, and system emails we send.
- Email integrations — Google and Microsoft, only where a user connects their own mailbox.
- Analytics & monitoring — website analytics and application-performance/observability tooling used to measure usage and diagnose issues.
10. Cookies & Analytics
10.1 Essential cookies. Some cookies are strictly necessary to sign you in, maintain your session, and protect against cross-site request forgery. The platform delivers authentication via secure, HttpOnly cookies.
10.2 Analytics. On our marketing website we use analytics and measurement tools (which may include Google Analytics and a Meta/Facebook pixel) to understand aggregate traffic and improve our content and campaigns. These may set cookies or use similar identifiers.
10.3 Your choices. You can control cookies through your browser settings and, where offered, our on-site consent controls. Blocking essential cookies may prevent the Services from working.
11. International Transfers
We and our providers may process and store information in locations outside your country, primarily within the European Union and in other regions where our infrastructure providers operate. Where personal data is transferred across borders, we take steps to ensure an appropriate level of protection consistent with the NDPA and applicable law, including contractual safeguards with our providers.
12. Data Retention & Deletion
12.1 Retention principle. We retain personal information for as long as needed to provide the Services, comply with our legal obligations, resolve disputes, and enforce our agreements.
12.2 Platform data. Deletion of Customer Data (including on account termination) follows the 60-day Retention Window and permanent-deletion process described in Section 9 of our Terms & Conditions. Free-trial accounts are subject to the shorter timeline described there.
12.3 Connected mailbox data. When you disconnect a mailbox, we revoke stored tokens and delete or de-associate the mailbox data we hold for the connected features, subject to short-lived residual copies in encrypted backups that rotate out on our ordinary cycle.
13. Security
We apply appropriate technical and organisational measures designed to protect personal information, including: encryption of data in transit (TLS) and encryption at rest for stored data and mailbox tokens; role-based access controls and least-privilege administration; tenant isolation; secure session handling; rate limiting and abuse detection; audit logging of security-relevant events; and monitored, access-controlled infrastructure. No method of transmission or storage is completely secure, but we work continuously to protect your information and to detect and respond to incidents.
14. Your Rights & Choices
Subject to applicable law, you may have the right to access, correct, update, delete, restrict, or object to the processing of your personal data, to withdraw consent, and to data portability. To exercise these rights for data we control, contact us at cloud@digitalvortextech.org. Where the data is Customer Data that we process on a Customer’s behalf, please contact the relevant Customer (your organisation), and we will support them in responding. You may also lodge a complaint with the Nigeria Data Protection Commission or your local supervisory authority.
15. Managing & Revoking Access
15.1 In Hubtoll. You can disconnect a connected Google or Microsoft mailbox at any time from the CRM settings within the platform, which revokes Hubtoll’s ongoing access and removes the stored connection.
15.2 With the provider. You can also review and revoke Hubtoll’s access directly with the provider:
- Google: myaccount.google.com/permissions
- Microsoft: myaccount.microsoft.com → Apps & services with access.
Revoking access stops future syncing and sending; data already deleted cannot be recovered.
16. Children’s Privacy
The Services are intended for use by organisations and their authorised adult users. They are not directed to children, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, please contact us so we can delete it.
17. Third-Party Links
Our website and the Services may link to third-party websites or services that we do not control. This Policy does not apply to those third parties, and we encourage you to review their privacy notices.
18. Changes to this Policy
We may update this Policy from time to time. The updated version becomes effective when posted on our website, with the “Last updated” date revised. For material changes, we will provide additional notice (for example by email or in-app). Your continued use of the Services after changes take effect constitutes acceptance of the revised Policy.
19. Contact Us
Questions, requests, or complaints about this Policy or your personal information can be sent to:
Digital Vortex Tech Limited
No 10, Oluwakemi Street, Shangisha, Magodo, Lagos, Nigeria
Email: cloud@digitalvortextech.org
Phone: +234 708 601 1838