Data Protection Policy
Last Updated: August 2026
1. Our Commitment
As a firm specializing in risk and technology consulting, Nay & Joe Risk and Tech Consulting is fully committed to safeguarding the data of our clients, partners, and website visitors. We adhere to the provisions of the Nigeria Data Protection Act (NDPA) and other relevant global data protection standards.
2. Data Processing Principles
We process personal and corporate data in accordance with the following principles:
- Lawfulness, Fairness, and Transparency: Data is processed legally and with clear communication to the data subject.
- Purpose Limitation: Data is collected only for specified, explicit, and legitimate business consulting purposes.
- Data Minimization: We only collect data that is strictly necessary for our services.
- Confidentiality and Integrity: We utilize enterprise-grade security architectures to protect against unauthorized access and processing.
3. Client Data & Confidentiality
Given the sensitive nature of financial risk management (including ECL modeling and ORRM implementation), all client financial and operational data is handled under strict Non-Disclosure Agreements (NDAs). Client data is isolated, encrypted in transit and at rest, and never utilized outside the agreed scope of engagement.
4. Your Rights
Under applicable data protection laws, you possess several rights regarding your data, including:
- The right to request access to the personal data we hold about you.
- The right to request correction of inaccurate data.
- The right to request erasure of your data under certain conditions.
- The right to object to or restrict processing.
5. Data Protection Officer (DPO)
For any matters relating to data protection, to exercise your rights, or to report a concern, please reach out to our Data Protection Officer at contactus@nayandjoerisktechconsult.com with the subject line "Data Protection Inquiry".