Legal

Privacy Policy

Effective 30 May 2026· Version 1.0

Imprezzle Express handles two kinds of sensitive material on your behalf: your personal contact details and the documents you upload for printing. This policy explains what we collect, why, how long we keep it, and the rights you have under the Nigeria Data Protection Regulation (NDPR) and the Nigeria Data Protection Act.

1. Data controller

Imprezzle Express, a sub-brand of Imprezzle, is the data controller for the personal data described here. Imprezzle is a Nigerian business registered with the Corporate Affairs Commission and registered with NITDA as a data controller under the NDPR.

For data-protection enquiries see the Data Compliance page, which lists our Data Protection Officer (DPO) and the ways you can exercise your rights.

2. What we collect

From you, directly, when you use the service:

  • Contact details: name, phone number, email address.
  • Delivery details: address line, landmark, zone, and any optional saved addresses.
  • Order details: the file(s) you upload, page counts, paper / binding / cover / colour selections, copies, and pricing snapshot.
  • Payment metadata: we do not store your card or bank details. Paystack processes the payment and returns only a reference, masked card prefix, and status.
  • Account preferences: notification channel choices, saved addresses, marketing opt-ins.
  • Identity verification: one-time codes sent to your phone or email.

Collected automatically when you visit the site:

  • Technical data: IP address, user-agent, session cookies, device type, referring URL, approximate location derived from IP.
  • Usage data: pages visited, buttons clicked, error reports, and performance metrics. We do not run third-party advertising trackers.

3. Why we collect it (purposes & legal bases)

Under the NDPR we must have a lawful basis for each use.

  • To fulfil your order— printing, binding, dispatching, and confirming delivery. Basis: performance of a contract.
  • To communicate with you about that order (WhatsApp, SMS, email). Basis: performance of a contract.
  • To take payment via Paystack and to handle refunds. Basis: performance of a contract; legal obligation (tax records).
  • To prevent fraud and abuse— rate limiting, signature checks, capping wrong delivery-code attempts, retaining audit logs. Basis: legitimate interest in running a secure service.
  • To improve the service— error monitoring, aggregate analytics, capacity calibration. Basis: legitimate interest.
  • To send you marketing only if you opt in. Basis: consent. You can withdraw consent at any time from your account settings.
  • To comply with the law— tax filing, regulatory requests from NITDA, law-enforcement requests properly served. Basis: legal obligation.

4. The documents you upload

Your PDFs are the most sensitive material on the service. They are stored in encrypted-at-rest object storage and accessed only via short-lived signed URLs — 10 minutes for uploads, 15 minutes for downloads. Production-floor staff see server-rendered thumbnail previews, not raw PDFs in a browser. Raw downloads happen only in our press tooling, with full audit logging of every access.

Retention.Your file is retained until delivery is confirmed plus a 30-minute grace window. There is a hard cap of 72 hours after print confirmation, regardless of order status, with a 96-hour storage-level safety net that deletes anything older. We do not offer a “keep my file” option at launch.

Auto-deletion. A scheduled job runs every five minutes and deletes files whose retention window has expired. Every deletion is logged. If the job fails, our error monitoring alerts the team.

5. Who we share data with

We do not sell your personal data. We share only what is needed for the listed purposes, with the following categories of processors:

  • Payments— Paystack (card, transfer, USSD), which you interact with directly at checkout.
  • Messaging— WhatsApp Business API for order receipts and notifications (via an accredited Business Solution Provider), plus an SMS provider as fallback and a transactional-email provider for receipts and magic links.
  • Hosting and database— our cloud hosting, database, and edge-compute provider, used to run the application and store account and order data.
  • File storage and processing— our object-storage provider, where uploaded PDFs are held encrypted-at-rest, and a sandboxed processing layer that scans and sanitises uploads.
  • Maps— our maps provider, for geocoding addresses and rendering delivery zones.
  • Delivery partners— we share only the recipient name, phone, address, landmark, and order reference with the dispatch partner we route a given order through.
  • Operational tooling— an error- monitoring service (configured to scrub personal data from automatic captures) and a team password manager for staff credentials.
  • Regulators and law enforcement— only when properly served with a lawful request, and only the specific data covered by that request.

We choose processors with appropriate security and data-protection practices, and we are responsible for how they handle data on our behalf. Where a processor is based outside Nigeria, transfers are covered by their standard data-protection commitments and, where applicable, the safeguards required by the NDPR. The current list of named processors is available on request from our Data Protection Officer — see the Data Compliance page.

6. How long we keep things

  • Uploaded PDFs: deleted within 30 minutes of delivery confirmation; hard maximum 72 hours after print confirmation; 96-hour storage-level backstop.
  • Order metadata (name, contact, address, items, totals): retained for up to 7 years for accounting and tax compliance, then anonymised or deleted.
  • Account profile: for as long as your account is active. Deleted on request (see Section 8).
  • Audit logs and security events: 12 months, then rolled off.
  • Marketing preferences: until you opt out or delete your account.

7. How we protect it

  • TLS in transit; encryption at rest for both the database and uploaded files.
  • Row-level security (RLS) on every database table; access gated by role (customer, press operator,rider, admin, super admin).
  • Multi-factor authentication mandatory for all staff accounts.
  • A ten-step PDF validation and sanitisation pipeline that strips JavaScript, embedded files, and other active content from uploads before printing.
  • Short-lived signed URLs for all file access.
  • Web Application Firewall, bot defence, and rate limiting at the edge.
  • Secrets held in a SOC 2-aligned vault, never in source control.

No system is perfect. If we become aware of a breach affecting your personal data, we will notify NITDA and the affected users in line with the NDPR's 72-hour notification timeline.

8. Your rights

Under the NDPR you have the right to:

  • Access the personal data we hold about you.
  • Rectify data that is wrong or out of date.
  • Deleteyour account and personal data (“right to be forgotten”), subject to data we must keep for tax or legal compliance.
  • Restrict or object to processing in certain circumstances.
  • Port your data to another service in a machine-readable format.
  • Withdraw consent at any time where consent is the legal basis (e.g. marketing).
  • Complain to NITDA if you believe we have mishandled your data.

The fastest way to delete your account and trigger immediate file deletion is the “Delete my account” control in your account settings. We confirm and execute deletion within 30 days; in practice it happens within an hour. For any other request, contact us via the Data Compliance page.

9. Cookies and local storage

We use first-party cookies and browser local storage only for things the service can't work without — keeping you signed in, remembering your theme preference, holding your in-progress upload so you don't lose it on refresh, and measuring whether the site is working. We do not run third-party advertising or cross-site tracking cookies.

10. Children

The service is not directed at children under 18. We do not knowingly collect personal data from a child. If you believe a child has used the service, contact us and we will delete the relevant data.

11. Changes

We may update this policy. The current version lives at this URL with the effective date at the top. Material changes will be communicated to active users by WhatsApp, email, or in-app notice.

12. Contact

For privacy questions or to exercise any right above, email privacy@imprezzle.com, or see the dedicated Data Compliance page for the full escalation path including our DPO and NITDA.