Privacy Policy

Last updated: 24 August 2026

Suwebatu Limited, a company registered in Nigeria, is the data controller for this Service ("Suwebatu", "we", "us"). This policy is written against Nigeria's NDPA 2023 and NDPR. It does not cover the additional obligations of the EU GDPR; we do not currently offer the Service to organisations established in the EU/EEA, and this policy will be extended before we do.

1. What we collect

Account details you provide (name, email, password - stored as a salted hash, never plain text); organisation and billing details; invoice, client, and payment records you enter; usage and log data (IP address, timestamps) for security and rate limiting; payment metadata from our payment processor (we do not store full card numbers). If you use Payroll, we also hold the employee records you enter: names, contact details, dates of birth, bank account details, and the tax, pension, housing fund and health insurance identifiers needed to work out and file deductions.

2. Why we process it (legal basis)

To perform our contract with you (running the Service you signed up for); to comply with legal obligations (tax and audit records); and, for security logs and fraud prevention, our legitimate interest in keeping the Service safe - balanced against your rights.

3. Who we share it with

Sub-processors that help run the Service: Neon (database hosting), Vercel (application hosting), Cloudinary (file and logo storage), our SMTP email provider (delivery of invoices and notifications), Paymish (subscription payment processing), Upstash (rate limiting, which processes IP addresses), and Sentry (error monitoring, which may capture technical request context when something fails). Each processes data only as needed to provide their function to us, under agreement. We do not sell your data.

4. Where your data is stored

Our providers operate data centres outside Nigeria; the database and application currently run in the United States, and some providers may process data elsewhere. Where data leaves Nigeria we rely on the safeguards required under the NDPA/NDPR for cross-border transfer. If your organisation needs its data held in a specific region, contact us before signing up.

5. How long we keep it

Active account data is kept while your subscription is active. Closing the account starts a 30-day grace period during which you can still sign in, export everything and cancel the closure. After that, this is the full schedule, and it is the same one shown to you before you confirm a closure and emailed to you afterwards.

WhatHow longWhy
Invoices, receipts and credit notes6 years from the end of the tax year they fall inCompanies Income Tax Act s.63 and FIRS Establishment Act s.55
Payment and transaction records6 yearsCompanies Income Tax Act s.63
Company registers, resolutions and statements6 yearsCompanies and Allied Matters Act 2020
Payroll runs and payslips6 years from the end of the tax year they fall inPart of the books of account under Companies Income Tax Act s.63, and PAYE has to be evidenced under the Personal Income Tax Act
Employee records: bank account, date of birth, address and statutory identifiersRemoved within 30 days of closingNigeria Data Protection Act 2023 s.34(1)(d). An employee record is what a payroll is worked out from, not a record of a payroll that was run, so nothing requires it to be kept
Audit log6 yearsKept alongside the records it explains
Your name, email address and sign-in detailsRemoved within 30 days of closingNigeria Data Protection Act 2023 s.34(1)(d)
Anything you uploaded that is not attached to a documentRemoved within 30 days of closingNigeria Data Protection Act 2023 s.34(1)(d)
Confirmation codes sent to youRemoved 24 hours after they expireKept no longer than it can be used, which is ten minutes

6. Your rights

Under the NDPA you can ask for access to your personal data, correction of it, deletion of it, and a portable export of your organisation's records. You can close the account yourself from Settings, which is the fastest route and does not need us. We answer any other request within 30 days, and tell you inside that window if a complex one needs longer.

7. What we cannot delete on request

Section 34(1)(d) of the NDPA gives you a right to erasure, and it does not reach data we are required by law to keep. Your invoices, receipts, payment records and audit log are tax and company records under the Companies Income Tax Act and the Companies and Allied Matters Act, so they are kept for the periods in the table above whatever else happens to the account. Your name, email address and sign-in details are not in that category, and are erased.

8. The audit log

Every action anybody takes in your organisation is recorded: who did it, what they did, what it was done to, and the address they did it from. It cannot be edited or deleted from inside the product, by you or by us, which is what makes it worth having. You can read your own at any time from the Audit logs page.

9. Security

Passwords are hashed, not stored in plain text. Sessions can be revoked server-side. Optional multi-factor authentication (TOTP) is available. Access to your organisation's data is restricted to your own team by design (tenant isolation). If a breach affecting your personal data occurs, we will notify affected users and, where legally required, the relevant regulator, without undue delay.

10. Cookies

We use only the session cookie required to keep you signed in - no third-party advertising or tracking cookies.

11. Children

The Service is intended for business use by adults; it is not directed at children.

12. Your clients and your employees

When you use the Service to invoice your own clients, or to run payroll for your own staff, you are the controller of their personal data and we process it on your instructions (a processor relationship). Your employees' rights under the NDPA - to see what is held about them, to have it corrected, and to complain - are exercised against you as their employer, not against us, and telling them what you hold and why is your duty rather than ours. We act on your instructions and on ours only where the law requires it. Once the Service is offered to organisations other than Suwebatu itself, a separate Data Processing Agreement covering this relationship will be provided before onboarding.

13. Employee data specifically

An employee never signs up for the Service and cannot sign in to it, so we hold their details only because you entered them. We do not use them for anything except running your payroll and producing your filings. Closing your account removes them: the bank account, date of birth, address and statutory identifiers of everybody on your payroll go within 30 days, because an employee record is what a payroll is worked out from rather than a record of a payroll that was run. Payroll runs and payslips are tax records and stay for the period in the table above.

14. Changes

We may update this Policy; material changes will be notified by email or in-app before they take effect.

15. Contact

Data protection questions: support@ugwo.ng.