Legal
Privacy Policy
Last updated: 10 August 2026
This Privacy Policy explains how Careerlinkk Digital Ventures Ltd (“we”, “us”, “our”) processes personal data when you visit our websites, create an account, or use Business OS — our multi-tenant business operating system and industry editions (including ChurchOS, ClinicOS, RestaurantOS, HotelOS, and related modules).
We design our processing to align with the Nigeria Data Protection Act, 2023 (NDPA), the Nigeria Data Protection Regulation (NDPR) principles still relevant to practice, and guidance from the Nigeria Data Protection Commission (NDPC). Where other laws apply (for example, to users outside Nigeria), we will honour additional rights required by those laws where feasible.
1. Data controller and contact
Unless otherwise stated in a customer contract, Careerlinkk Digital Ventures Ltd (RC 9652318, Lagos, Nigeria) is the data controller for account, billing, and platform telemetry data related to Business OS. For content you upload inside a customer workspace (members, patients, guests, invoices, documents), the customer organisation is typically the controller and we act as a processor under that organisation’s instructions.
- Privacy / legal: info@careerlinkk.com
- Company website: www.careerlinkk.com
- Jurisdiction of primary operations: Lagos, Nigeria
2. Personal data we collect
Depending on how you use Business OS, we may process:
- Account data — name, email, phone, password hashes, organisation membership, roles, and authentication events (including optional TOTP 2FA).
- Customer / end-user records — contacts and industry-labelled records (for example members, patients, guests), calendar events, invoices, inventory movements, messages, and uploaded documents as entered by your organisation.
- Special / sensitive categories — only where an edition requires it (for example clinical notes, counselling notes, or legal case materials). These are tenant-scoped, access-controlled, and intended for lawful professional use by the customer.
- Payment metadata — subscription status and payment references via providers such as Paystack/Stripe. We do not store full card PAN data on our servers.
- Technical data — IP address, device / browser type, approximate location derived from IP, cookies or similar session signals, logs, and performance diagnostics.
- Communications — support emails, SMS / WhatsApp delivery logs for notifications you initiate, and in-product feedback.
3. Lawful bases (NDPA / NDPR alignment)
We process personal data only where a lawful basis applies, including:
- Contract — to create and operate your account, provide subscribed modules, and support the service.
- Consent — where required (for example certain marketing messages or optional integrations). You may withdraw consent without affecting prior lawful processing.
- Legitimate interests — securing the platform, preventing fraud/abuse, improving reliability, and limited product analytics — balanced against your rights and expectations.
- Legal obligation — tax, accounting, regulatory, or lawful information requests.
- Vital interests / public interest — only in exceptional cases (for example responding to imminent safety risks where permitted by law).
Customer organisations using ClinicOS, LawFirmOS, Church counselling modules, or similar features are responsible for their own lawful bases (including professional confidentiality duties) before storing special-category data.
4. How we use personal data
- Provide, configure, and secure multi-tenant workspaces and edition modules
- Authenticate users, enforce roles/permissions, and detect unauthorized access
- Process invoices, payroll outputs, notifications, and document storage you request
- Operate optional AI insight jobs on customer-authorised inputs, with fallbacks
- Monitor uptime, debug incidents, and prevent abuse (rate limits, audit logs)
- Communicate service notices, security alerts, and (if opted in) product updates
We do not sell personal data. We do not use customer workspace content to train public foundation models unless a separate written agreement expressly allows anonymised/aggregated learning with lawful basis.
5. Multi-tenancy and isolation
Business OS is multi-tenant. Tenant-scoped tables are keyed by organizationId. Access tokens carry organisation context; API guards reject cross-tenant reads and writes. Customers must manage staff access carefully — compromise of a user account within an organisation can expose that organisation’s records.
7. Cross-border transfers
Some subprocessors may process data outside Nigeria. Where transfers occur, we use safeguards consistent with NDPA requirements and NDPC guidance (such as contractual clauses, security assessments, and transfer risk review). You may request an overview of material international transfers related to your workspace via dpo@businessos.app.
8. Retention
We retain account and billing records for as long as your organisation remains active and thereafter as required for legal, tax, and dispute purposes. Soft-deleted financial, medical, and legal records may be retained in recoverable form for audit / compliance windows defined in product settings or customer agreements. When retention expires, we delete or irreversibly anonymise data except where a longer legal hold applies.
9. Security measures
- TLS in transit; encryption at rest via infrastructure providers
- Hashed passwords; JWT access + refresh rotation; optional TOTP 2FA
- Organisation-scoped authorization on tenant data APIs
- Least-privilege internal access and audit logging of sensitive administration
- Backup and recovery practices appropriate to the hosting environment
No method of transmission or storage is perfectly secure. Please use strong passwords, enable 2FA, and notify us promptly of suspected incidents.
10. Your rights (data subjects)
Subject to NDPA conditions and exemptions, you may request: access, correction, deletion, restriction, portability (where applicable), objection to certain processing, and withdrawal of consent. You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).
If your data is held inside a customer organisation’s workspace, contact that organisation first. We will assist controllers in fulfilling valid requests under processor instructions.
Submit requests to dpo@businessos.app. We may need to verify your identity.
11. Children
The platform is built for business and professional organisations, not for children under 18 to self-register. Where a customer (for example a church or clinic) records information about minors, that customer is responsible for obtaining required parental/guardian authority under applicable law.
13. AI features
Optional AI tasks (insights, summaries, forecasts) run through our AI module with customer-provided context. Outputs can be incomplete or incorrect — they do not replace professional judgment in clinical, legal, financial, or safety-critical decisions. Prompts and outputs may be logged for abuse prevention and quality under security controls.
14. Changes to this policy
We may update this Privacy Policy to reflect product, legal, or regulatory changes. Material updates will be posted on this page with a revised “Last updated” date and, where appropriate, notified in-product or by email.
15. Complaints
Contact dpo@businessos.app first so we can try to resolve your concern. You may also complain to the Nigeria Data Protection Commission (NDPC) through its official channels if you believe your data protection rights have been infringed.
Questions: info@careerlinkk.com · Careerlinkk Digital Ventures Ltd (RC 9652318)