IRISE as data controller
We generally act as controller for website visitors, inquiries, client contacts, account administration, billing, fraud prevention, security monitoring, marketing preferences, recruitment and our own business records.
This policy explains how IRISE GLOBAL TECH NETWORK, trading as IRISE ICT, handles personal data when you visit our website, contact our team, request a service, create an account, apply for a role, or use a platform for which this policy is incorporated by reference.
Product-specific terms, privacy notices, data-processing agreements, school agreements, project contracts or customer instructions may also apply. A more specific written document will govern the relevant service where it expressly differs from this general policy.
IRISE ICT is the technology brand of IRISE GLOBAL TECH NETWORK. References in this policy to “IRISE ICT”, “IRISE”, “we”, “us” or “our” mean IRISE GLOBAL TECH NETWORK and the teams that operate its websites, products and contracted technology services.
This policy applies to personal data processed through or in connection with:
This policy does not automatically govern a third-party website or service merely because it is linked from our website. Please review the privacy notice of each third-party service you use.
We generally act as controller for website visitors, inquiries, client contacts, account administration, billing, fraud prevention, security monitoring, marketing preferences, recruitment and our own business records.
We may act as processor or service provider when a customer, school or organisation uses our platform or contracted system to process personal data under its instructions, such as recipient data, school records or workflow data.
When we process data solely for a customer or school, that organisation normally determines why the data is processed and is responsible for providing required notices and establishing a lawful basis. Requests concerning such data may need to be directed to that organisation first.
The categories depend on how you interact with us and may include:
Name, email address, telephone or WhatsApp number, job title, location, organisation and authorised contact details.
Service requested, project objectives, users, budget range, timeline, technical requirements, integrations and correspondence.
Usernames, account identifiers, password hashes, verification records, access roles, API tokens, security events and session information.
Invoices, payment references, wallet activity, subscription records, transaction status and limited payment details supplied by a payment provider.
Position applied for, CV or résumé, employment and education history, portfolio links, cover note, interview information and referee details.
IP address, browser, device, operating system, referring page, timestamps, logs, error reports, security signals and feature usage.
Emails, support requests, call or chat notes, attachments, complaint records and troubleshooting information.
Data submitted to a product or client system, including message content, recipient details, delivery records, school records and operational files.
Please do not submit sensitive personal data unless it is necessary, lawful and specifically requested for the relevant service. Where a project requires health, biometric, financial, child or other sensitive data, additional controls and written terms may be required before processing begins.
We process personal data only where we have a recognised legal basis. Depending on the activity, this may include:
To answer inquiries, prepare proposals, open accounts, provide products, deliver projects, manage subscriptions and provide support.
Contract or pre-contract stepsTo authenticate users, maintain infrastructure, prevent abuse, investigate incidents, monitor reliability and protect accounts.
Legitimate interests / legal obligationTo issue invoices and receipts, reconcile transactions, manage credit, comply with accounting duties and resolve payment disputes.
Contract / legal obligationTo assess applicants, communicate about roles, conduct interviews, verify relevant information and maintain recruitment records.
Pre-contract steps / legitimate interestsTo analyse performance, diagnose errors, improve usability, plan capacity and develop or refine features using proportionate data.
Legitimate interestsTo send requested demonstrations, service updates or relevant business communications and to honour opt-out preferences.
Consent or legitimate interestsTo meet legal duties, respond to lawful requests, enforce agreements, protect rights and establish, exercise or defend legal claims.
Legal obligation / legitimate interestsTo process platform or project data on behalf of a customer, school or organisation in accordance with documented instructions.
Processor activityWhere we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing already carried out lawfully. Where we rely on legitimate interests, we consider the purpose, necessity and potential effect on individuals before processing.
Messaging services may process account contacts, sender identifiers, recipient telephone numbers, message content, campaign data, API requests, wallet activity, delivery status, carrier responses, opt-out or restriction information, IP addresses and security logs. Customers are responsible for ensuring that recipient data and message content are collected and used lawfully.
Zena may process school identity and subscription data, proprietor and staff accounts, applicant, student, parent or guardian records, classes, attendance, fees, receipts, results, notices and other enabled school modules. The participating school generally controls these records, while IRISE processes them to operate, secure and support the platform under the school’s instructions.
The categories depend on the agreed project. Before production data is processed, the parties may define access controls, environments, retention, sub-processors, security measures, backup duties, permitted users and data-return or deletion procedures in a project agreement or data-processing addendum.
Some infrastructure, security, communications, software or support providers may process data outside Nigeria. Where personal data is transferred internationally, we will use a transfer method permitted by applicable law, such as an adequacy decision, contractual safeguards, binding rules, certification mechanisms, your explicit consent where appropriate, or another lawful derogation.
The location and protections applicable to customer-controlled data may also be specified in the relevant project agreement, subscription terms or data-processing addendum.
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including service delivery, account administration, security, backup cycles, dispute resolution, audit, tax, accounting and other legal requirements.
Retention is determined by factors such as:
When retention is no longer justified, data is deleted, anonymised or isolated until secure deletion is completed. Residual copies may remain temporarily in protected backups and be removed through the normal backup lifecycle.
We use technical and organisational measures proportionate to the nature of the data and service. Measures may include access controls, role separation, password hashing, encrypted connections, environment isolation, logging, anti-abuse controls, least-privilege access, protected backups, vendor assessment, secure development practices and incident-response procedures.
No internet service or storage system can be guaranteed completely secure. Users must protect their credentials, API tokens, devices and authorised accounts and must notify us promptly of suspected loss, unauthorised access or misuse.
Where a personal-data breach creates a legally reportable risk, we will assess the incident and make required notifications to affected controllers, individuals or the Nigeria Data Protection Commission within the applicable legal framework.
Subject to applicable law and relevant exemptions, you may have the right to:
To exercise a right, email info@iriseict.com with the subject Data Rights Request. Describe the data or account involved and the right you wish to exercise. We may request reasonable information to verify your identity and authority.
Where the data is controlled by a customer, school or employer, we may refer the request to that organisation or assist it in responding. We will not discriminate against a person for lawfully exercising a data-protection right.
The general IRISE ICT website and business inquiry services are not directed to children. A person who is not legally able to enter a contract should use an account or submit commercial information only through a parent, guardian or authorised organisation.
Zena and school projects may process information about applicants and students, including minors. In those circumstances, the school is generally responsible for determining the lawful basis, providing notices, obtaining any required parent or guardian authorisation, limiting staff access, maintaining accurate records and responding to school-community requests. IRISE processes such data to provide the contracted platform and support services.
Our services may link to or integrate with payment gateways, telecommunications networks, cloud platforms, social networks, developer tools or customer-selected systems. Those parties may process data under their own terms and privacy notices when they act independently.
A customer that enables an integration is responsible for confirming that it is authorised to send data to that integration and for configuring permissions appropriately. We are not responsible for a third party’s independent processing, security practices or content.
We may update this policy to reflect changes in law, guidance, products, infrastructure or business operations. The revised version will be posted on this page with a new “Last updated” date. Where a change materially affects existing users, we may also provide notice through an account, service or direct communication where appropriate.
Questions, complaints or privacy requests should be sent to info@iriseict.com. Please include enough information for us to identify the relevant website, product, project, account or organisation.