NDPR Compliance

Attrevo processes personal data on behalf of its customers. This page sets out how responsibility is divided under the Nigeria Data Protection Regulation, and the controls we provide.

Last updated: 25 July 2025

1. Regulatory framework

Attrevo is built to comply with the Nigeria Data Protection Regulation 2019 (NDPR), issued by the National Information Technology Development Agency (NITDA), and with the Nigeria Data Protection Act 2023.

Techly Marketing Limited maintains its registration as a data controller and processor with NITDA, and files the annual data protection audit return required of organisations processing personal data of more than 1,000 data subjects.

2. Who is responsible for what

The division of responsibility depends on whose data is being processed.

DataYou areAttrevo is
Your website visitors, leads, and customersData controllerData processor
Your own Attrevo account and billing recordsData subjectData controller

As a data processor, Attrevo acts only on your documented instructions. We do not determine the purposes for which your visitor data is processed, we do not use it for our own purposes, and we do not share it between tenants.

3. Your obligations as data controller

When you install the Attrevo tracking snippet or upload lead data, you take on the controller's duties under the NDPR. You must:

  • Establish and document a lawful basis for the personal data you collect through Attrevo.
  • Display a privacy notice on your own website explaining that attribution tracking takes place, what is collected, and why.
  • Obtain and record consent before any non-essential tracking runs, using the consent banner supplied with the snippet or your own equivalent.
  • Honour data subject requests you receive, using the tools we provide.
  • Only upload data you are lawfully entitled to process, and never special categories of personal data.
  • Keep your own NDPR registration and audit filings current where they apply to you.

4. Consent mechanisms

The Attrevo tracking snippet ships with a consent banner that is enabled by default. Its behaviour:

  • Tracking is held until a decision is made. No touchpoint is transmitted before the visitor accepts.
  • Declining is as easy as accepting, and a declined visitor is not tracked.
  • Each decision is recorded as a consent record with a timestamp, so you can evidence consent if challenged.
  • Visitors can change their decision later, and withdrawal stops further collection.

Disabling the banner is possible in settings, but doing so makes you solely responsible for obtaining consent by other means.

5. Data subject requests

Attrevo provides tooling to service the rights of access, correction, deletion, and portability:

  • Look up every record associated with an email address or phone number across leads, touchpoints, and revenue events.
  • Export that data in a machine-readable format.
  • Erase a data subject entirely, removing associated touchpoints and lead records.
  • Track each request through to completion, with an auditable record of the outcome.

Requests must be fulfilled within 30 days of receipt. Where a request reaches us but relates to data you control, we will forward it to you without undue delay.

6. Breach notification

If Attrevo becomes aware of a personal data breach affecting data we process on your behalf, we will notify you within 72 hours of becoming aware of it. Our notification will describe:

  • The nature of the breach and the categories of data affected.
  • The approximate number of data subjects involved.
  • The likely consequences.
  • The measures taken or proposed to address the breach and mitigate harm.

As data controller, you are responsible for notifying NITDA and, where the risk to individuals is high, the affected data subjects.

7. Retention and deletion

Tracking and attribution data is retained for a default of 12 months, after which it is deleted automatically by a scheduled retention job. The retention window is configurable, and every automated deletion is logged so the process can be evidenced during an audit.

8. Security measures

  • TLS encryption for all data in transit.
  • Encryption at rest, with third-party platform credentials stored encrypted.
  • Strict tenant isolation — every query is scoped to a single tenant.
  • Role-based access control within each customer account.
  • Least-privilege access to production data, restricted to authorised personnel and logged.

9. Sub-processors

We engage a small number of sub-processors for authentication, payments, email and messaging, cloud hosting, and AI-assisted insights. Each is bound by contractual terms requiring protection comparable to the NDPR. We will give notice before adding a sub-processor that materially changes how your data is handled.

10. Contact

For NDPR matters, data processing agreements, or audit documentation, contact olusola.a@attrevo.com.

See also our Privacy Policy, Terms and Conditions, and Cookie Policy.

Questions about this document?

Contact our Data Protection contact at olusola.a@attrevo.com.