Privacy Policy
This policy explains what personal data airmirate collects, why, and the rights available to you, whether you visit our website, engage us as a client, or interact with an automation system we have built for one of our clients, anywhere in the world.
On this page
- Who we are
- Scope of this policy
- Information we collect
- How we use information
- Our legal basis for processing
- Who we share information with
- International visitors and cross border transfer
- Data retention
- Data security
- Cookies and tracking
- Your rights
- Additional rights for the EU and UK
- Additional rights for California residents
- Children's privacy
- Data breach notification
- Changes to this policy
- Contact us
1. Who we are
airmirate is an ecommerce automation service based in Abuja, Federal Capital Territory, Nigeria. For the purposes of applicable data protection law, airmirate is the data controller for the personal data described in this policy, unless stated otherwise below, and can be reached using the details in section 17.
2. Scope of this policy
This policy applies to three groups of people:
- Visitors to our website, wherever in the world they are located.
- Clients who engage airmirate for automation services, and the individuals who represent those clients.
- Client customers whose personal data, such as order details or support messages, passes through an automation system airmirate has built for a client. In this case, airmirate typically acts as a data processor on behalf of the client, who remains the data controller for their own customers, as also noted in our Terms of Service.
3. Information we collect
From website visitors
- Contact form submissions, including name, business name, email address, phone number, platform used, and message content.
- Basic technical information such as browser type, device type, approximate location derived from IP address, and pages visited, typically gathered through standard analytics tools.
From clients
- Business details, billing information, and communication history related to the engagement.
- Access credentials or authorized connections to platforms such as Shopify, WooCommerce, BigCommerce, or WhatsApp Business, provided solely to deliver the agreed automation service.
From client customers, via automation systems
- Order data, such as products purchased, order status, and delivery address, where needed to power an automated reply.
- Support and sales messages sent through channels such as WhatsApp, Instagram, or email, where these are connected to an automation we manage for a client.
4. How we use information
We use the information described above to:
- Respond to enquiries and provide quotes for our services.
- Deliver, maintain, and support the automation systems we build for clients.
- Send invoices and process payments.
- Improve our website and services, including understanding which pages and offers are most useful to visitors.
- Meet our legal, accounting, and tax obligations in Nigeria.
We do not sell personal data to third parties, and we do not use client customer data passing through an automation for our own marketing purposes.
5. Our legal basis for processing
Where the Nigeria Data Protection Act 2023 (NDPA), the General Data Protection Regulation (GDPR), or a similar law applies, we rely on one or more of the following bases to process personal data:
- Consent, for example when you submit our contact form or opt in to receive updates.
- Performance of a contract, for example processing a client's data to deliver an agreed automation service.
- Legitimate interest, for example basic website analytics, balanced against your right to privacy.
- Legal obligation, for example retaining invoices for Nigerian tax purposes.
6. Who we share information with
We share personal data only where necessary to deliver our services, including with:
| Category | Examples | Purpose |
|---|---|---|
| Ecommerce platforms | Shopify, WooCommerce, BigCommerce | Powering order and customer data used in an automation |
| Automation infrastructure | n8n, cloud hosting providers | Running the automated workflows we build |
| Messaging providers | WhatsApp Business, Meta, email service providers | Sending and receiving automated messages |
| Payment processors | Bank transfer partners, online payment gateways | Processing client payments to airmirate |
| Professional advisers | Accountants, legal counsel | Meeting our legal and financial obligations |
We may also disclose information where required by law, such as in response to a valid request from a Nigerian regulatory or law enforcement authority.
7. International visitors and cross border transfer
airmirate operates from Nigeria, and the platforms listed in section 6 may store or process data in other countries, including the United States and the European Union. Where personal data is transferred outside the country in which it was originally collected, we take reasonable steps to ensure it continues to receive an appropriate level of protection, including relying on the data protection commitments of the third party platforms we use, and, where applicable, standard contractual clauses recognized under the GDPR.
Clients located outside Nigeria who send us their own customers' personal data for use in an automation are responsible for ensuring they have a lawful basis to transfer that data to airmirate for processing, in line with their own applicable law.
8. Data retention
We retain personal data only for as long as necessary for the purposes described in this policy. As a general guide:
- Contact form enquiries that do not become a client engagement are retained for up to 12 months.
- Client business and billing records are retained for as long as the engagement continues, and for a further period afterward as required by Nigerian tax and accounting law, typically six years.
- Client customer data flowing through an automation is retained only as long as necessary for that automation to function, in line with the specific arrangement agreed with the client, and is not retained by airmirate beyond the engagement unless otherwise agreed.
9. Data security
We apply reasonable technical and organizational measures to protect personal data, including restricting access to authorized personnel, using platforms with their own security certifications where possible, and avoiding storage of sensitive credentials outside secure, access controlled systems. No system can be guaranteed completely secure, and we encourage clients to use strong, unique credentials for any account connected to an automation.
10. Cookies and tracking
Our website may use cookies or similar technologies to understand site usage and improve the browsing experience. You can control cookies through your browser settings, including blocking or deleting them, though this may affect how parts of our website function.
11. Your rights
Depending on your location and applicable law, including the NDPA, you may have the right to:
- Request access to the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request deletion of your data, subject to our legal retention obligations.
- Object to or request restriction of certain processing.
- Request a portable copy of data you provided to us.
- Withdraw consent at any time where processing is based on consent.
- Lodge a complaint with the Nigeria Data Protection Commission (NDPC), or the relevant authority in your own country.
To exercise any of these rights, contact us using the details in section 17. We will respond within a reasonable time and in line with applicable law.
12. Additional rights for the EU and UK
If you are located in the European Union or United Kingdom, the GDPR or UK GDPR gives you the rights listed in section 11, along with the right to request that we transfer your data directly to another provider in a structured, commonly used format where technically feasible, and the right to object specifically to processing based on legitimate interest.
13. Additional rights for California residents
If you are a California resident, the California Consumer Privacy Act (CCPA) gives you the right to know what personal information we collect, request its deletion, and opt out of any sale or sharing of personal information. airmirate does not sell personal information as defined under the CCPA.
14. Children's privacy
Our services are directed at businesses and individuals aged 18 and older. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us using the details in section 17 and we will take steps to delete it.
15. Data breach notification
In the event of a personal data breach that poses a risk to your rights, we will notify affected individuals and relevant authorities, including the NDPC where required, within the timeframe set out under applicable law.
16. Changes to this policy
We may update this policy from time to time to reflect changes in our practices or applicable law. Material changes will be reflected by an updated date at the top of this page, and where appropriate, we will notify active clients directly by email.
17. Contact us
Questions about this policy, or requests relating to your personal data, can be sent to airmiratedigital@gmail.com, or by WhatsApp to +234 704 735 8504. airmirate is based in Abuja, Federal Capital Territory, Nigeria.
