Privacy policy
What we collect, why we have it, who else sees it, and how to make us delete it.
Last updated 13 September 2026
Contents
Who we are
Greencrest Integrated Services Limited (RC 1797334) decides what happens to the personal information described here. In data protection law that makes us the data controller.
Plot 536, J.K Zaphaniah StreetZone ‘A’ Extension, Apo Resettlement
Abuja, FCT, Nigeria
info@greencrestisl.com
+234 806 824 6347
Privacy questions, requests and complaints go to info@greencrestisl.com. A person reads that mailbox; it is not automated.
What this policy covers
This policy covers greencrestisl.com. It does not cover other companies’ websites we link to, or the systems we build and run for clients under contract. On a client project the client decides what happens to the data in it and publishes its own policy; we act on their written instructions.
What we collect
What you type into the enquiry form
Your name, your organisation, your email address, the service you picked from the list, and whatever you write in the message box. The form will not submit without the first three and the message. Please do not put anything confidential in it; it reaches us as ordinary email.
What the server records on its own
Our host keeps standard web server logs: the IP address the request came from, the time, the page asked for, and the browser’s user agent string. These exist so the host can spot attacks and diagnose faults.
What we do not do
- This website sets no cookies at all. There is no consent banner because there is nothing to consent to.
- There is no analytics, no advertising pixel, no session recording and no fingerprinting. We do not know who you are until you write to us.
- We never sell personal information, and we never share it for cross-context behavioural advertising. We have not done so in the past twelve months.
Why we use it, and on what legal basis
- Answering you
- Replying to your enquiry, quoting for work, and the correspondence that follows. Legal basis: taking steps at your request before entering a contract, and our legitimate interest in running the business.
- Delivering work
- Performing a contract once you have one with us. Legal basis: performance of a contract.
- Keeping the site up
- Server logs, fault diagnosis and abuse prevention. Legal basis: our legitimate interest in a site that works and is not attacked.
- Meeting obligations
- Tax, company, procurement and anti-money-laundering records. Legal basis: a legal obligation we are under.
We will not use what you sent us for a different purpose without asking you first, unless the law requires it. We do not make decisions about you by automated means.
Who else sees it
A short list, and it is the whole list.
- Namecheap
- Hosts the website and the email that the enquiry form sends. They can technically reach data held on the server and are bound by their own terms to protect it.
- Professional advisers
- Our accountants and lawyers, when a matter needs them.
- Authorities
- Where a law, a court order or a regulator compels disclosure. We tell you when we are allowed to.
Everyone on that list is required to protect your information to at least the standard in this policy and to use it only for the purpose we gave it to them for. Nobody on it may sell it.
Where it is held
We are in Nigeria. The web and mail servers are operated by Namecheap in the United States. If you write to us from the European Union, the United Kingdom or anywhere else, your message crosses a border to reach us.
Nigeria is not the subject of a European Commission adequacy decision, so for transfers out of the EU or UK we rely on the standard contractual clauses approved for that purpose, and on the safeguards in this policy. Transfers out of Nigeria are made on the bases allowed by section 41 of the Nigeria Data Protection Act 2023. Write to us if you want the detail of the safeguards that apply to you.
How long we keep it
- Enquiries
- 24 months from the last contact about that enquiry.
- Server logs
- 30 days, then overwritten by the host.
- Contract records
- 6 years after the contract ends, which is what tax and company law require.
When a period ends we delete the information or strip it of anything that identifies you. You can ask us to delete something sooner, and we will unless a law requires us to keep it.
How we protect it
The site is served only over HTTPS; a plain HTTP request is redirected. The enquiry form checks what it receives before doing anything with it, and is built so that nothing typed into it can be turned into an instruction to our mail server. Access to the hosting account and the mailboxes is limited to the few people who need it.
No system is perfectly secure, and we will not pretend otherwise. If a breach happens that is likely to put you at risk, we will tell the Nigeria Data Protection Commission within 72 hours of becoming aware of it, and we will tell you directly and in plain language where the risk to you is high.
Your rights
These rights come from the Nigeria Data Protection Act 2023 and, where they apply to you, the UK and EU GDPR and the California Consumer Privacy Act. We do not charge for any of them, and exercising one will never get you worse service.
- Know and see. Ask what we hold about you, why, and who we gave it to, and get a copy.
- Correct. Have anything wrong put right.
- Delete. Have it erased, unless a law makes us keep it.
- Restrict and object. Tell us to stop a particular use, including any use we base on our legitimate interest.
- Take it with you. Receive what you gave us in a machine-readable file, or have it sent to someone else.
- Withdraw consent. Where we relied on your consent, take it back at any time. That does not undo what was lawful before you withdrew it.
- Opt out of sale or sharing. Nothing to opt out of: we do not sell personal information and we do not share it for cross-context behavioural advertising. We offer no financial incentive for your data.
- No retaliation. We will not discriminate against you for using any of these rights.
Write to info@greencrestisl.com. We reply within 30 days. If your request is complicated we may need longer, and we will tell you why before the 30 days are up. We may have to ask you something that proves you are who you say you are, because handing your data to the wrong person is the thing these rights exist to prevent. An authorised agent may act for you if you confirm it in writing.
Children
This is a business-to-business service. It is not directed at children, and we do not knowingly collect information from anyone under 18. If you believe a child has sent us something, write to info@greencrestisl.com and we will delete it.
Changes to this policy
When this policy changes, the date at the top of the page changes with it. If a change materially affects what we do with information we already hold, we will say so prominently, and where the law requires it we will ask for your consent before the change applies to you. We do not change it quietly.
Contacting us, and complaining
Write to info@greencrestisl.com, or to the address at the top of this page. Enquiries from outside Nigeria can also go to global@greencrestisl.com.
If we have not put something right, you can complain to a regulator. In Nigeria that is the Nigeria Data Protection Commission, ndpc.gov.ng. In the European Union it is the supervisory authority in the country where you live, work, or where you think the problem happened. In the United Kingdom it is the Information Commissioner’s Office. We would rather you came to us first, but you are not required to.
