LEGAL
PRIVACY NOTICE
Effective Date: April 28, 2025
Last Revised: April 20, 2026
Jurisdiction: U.S. & Nigeria
Digital Information Security Solutions LLC ("Digiss," "we," "us," or "our") is committed to protecting the privacy of our website visitors and the individuals whose personal information we may encounter in delivering our services. This Privacy Notice explains what information we collect, how we use and protect it, and what rights you have over your data. We encourage you to read it carefully and revisit it periodically, as we may update it from time to time.
01
Information We Collect
Information You Provide Directly
When you interact with our website, request a consultation, purchase services, or sign up for our newsletter, we may collect: your name, email address, phone number, company name, and details about your interest in our products or services.
Information Collected Automatically
When you visit our website, we automatically collect certain technical information, including browser type and version, operating system, referring URLs, IP address, device type, and pages visited along with timestamps. This data helps us maintain service quality, diagnose technical issues, and understand how our site is used.
Information Collected in Service Delivery
In performing managed detection and response (MDR), security assessments, GRC consulting, or other cybersecurity services, we may be exposed to personal or sensitive data belonging to your organization or your customers. In these contexts, Digiss acts as a data processor on your behalf, and our handling of that information is governed by the terms of your service agreement.
02
How We Use Your Information
We use the information we collect to:
Service Delivery & Communication
Provide, operate, and improve our services; respond to inquiries; and communicate changes, updates, or alerts relevant to your account or our offerings.
Marketing & Outreach
Send newsletters, security advisories, and promotional content where you have provided consent or where a legitimate interest applies. You may opt out at any time (see Section 8).
Analytics & Site Improvement
Understand how visitors use our website so we can improve navigation, content, and user experience.
Legal & Compliance Obligations
Fulfill obligations under applicable law, including the Nigeria Data Protection Regulation (NDPR), U.S. state privacy laws, and any applicable sector-specific requirements.
03
Sharing of Information
We do not sell your personal information. We may share information in the following limited circumstances:
Service Providers
We engage trusted third-party vendors (such as hosting providers, email delivery services, and analytics platforms) who process data on our behalf under contractual data protection obligations. These parties may not use your information for their own purposes.
Third-Party Analytics
We use analytics tools that may independently collect certain usage data, such as pages visited and session duration. These providers operate under their own privacy policies. We encourage you to review them.
Legal Requirements
We may disclose information where required by law, court order, or governmental authority, or where necessary to protect the rights, property, or safety of Digiss, our clients, or others.
Business Transfers
In the event of a merger, acquisition, or sale of assets, personal information may be transferred to the acquiring entity, subject to equivalent privacy protections.
04
Data Retention
We retain personal information for as long as necessary to fulfill the purposes described in this Policy, comply with our legal obligations, resolve disputes, and enforce our agreements. When information is no longer needed, we securely delete or anonymize it.
For marketing communications, we retain your contact information until you opt out or request deletion. For service-related records, retention periods are determined by applicable legal and contractual requirements and are specified in your service agreement where relevant.
05
Security Safeguards
We implement technical and organizational measures designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These measures include data encryption in transit and at rest, access control and authorization frameworks, network-layer security controls including firewalls and intrusion detection, and regular review of our information security practices.
As a cybersecurity firm, we apply the same rigor to our own data handling that we recommend to our clients. That said, no transmission over the Internet can be guaranteed to be 100% secure. We encourage you to exercise caution when sharing personal information online.
06
Cookies & Tracking Technologies
Our website uses cookies, web beacons, and similar technologies to operate core site functions, remember your preferences, and analyze site usage. Cookies are small files stored on your device that can be removed at any time.
Essential Cookies
Required for the website to function. These cannot be disabled without affecting site functionality.
Analytics Cookies
Help us understand how visitors interact with the site. You may opt out by adjusting your browser settings or using standard opt-out tools provided by our analytics vendors.
Managing Your Preferences
Most browsers allow you to block or delete cookies through their settings menus. Disabling non-essential cookies will not prevent you from using core features of our website.
07
Third-Party Analytics & Links
Our website may link to third-party websites or integrate social sharing tools. Once you leave our site, this Privacy Notice no longer applies, and we are not responsible for the privacy practices of those external sites. We encourage you to review the privacy notices of any third-party sites you visit.
Third-party analytics providers we engage may use cookies and similar technologies to collect usage data independently. Their collection and use of your information is governed by their own privacy notices.
08
Your Privacy Rights
Depending on your jurisdiction, you may have the following rights with respect to your personal information:
Right of Access
Request a copy of the personal information we hold about you.
Right to Correction
Request that inaccurate or incomplete information be corrected.
Location Services
Disable location-based features via your browser or device settings at any time.
Right to Deletion
Request that we delete your personal information, subject to legal retention requirements.
Right to Object
Object to processing based on legitimate interests, including for direct marketing.
Right to Restrict Processing
Request that we limit how we use your information in certain circumstances.
Right to Data Portability
Receive your information in a structured, machine-readable format where applicable.
Opt Out of Marketing
Unsubscribe from marketing communications at any time via the link in our emails or by contacting us directly.
To exercise any of these rights, contact us at info@digiss.io. We will respond within 30 days of receiving your verified request.
09
Nigeria (NDPA) Compliance
Nigeria Operations
Digiss operates in Nigeria and is subject to the Nigeria Data Protection Act 2023 (NDPA), which superseded the Nigeria Data Protection Regulation (NDPR) and is now the primary data protection legislation in Nigeria. The NDPA is administered by the Nigeria Data Protection Commission (NDPC). We are committed to full compliance with the NDPA and its implementing regulations.
Lawful Basis for Processing
We process personal data only where we have a lawful basis to do so, including your consent, the performance of a contract, compliance with a legal obligation, or our legitimate interests where these do not override your rights.
Data Minimization
We adhere strictly to the principle of data minimization. This means we collect only the personal information that is directly necessary to deliver the service or fulfill the purpose for which it was requested, nothing more. We do not collect data speculatively or in excess of what is required. Where a service can be delivered with less information, we will always prefer the less intrusive approach. This principle applies equally to our Nigerian operations and to all data subjects whose information we process, regardless of jurisdiction.
Cross-Border Data Transfers
Where personal data is transferred outside of Nigeria, we ensure that adequate protections are in place consistent with NDPA requirements, including contractual safeguards with receiving parties.
Data Subject Rights Under the NDPA
Nigerian data subjects have the right to access, correct, and request deletion of their personal data, as well as the right to object to or restrict its processing. To exercise these rights, contact us at info@digissllc.com. Complaints may also be directed to the Nigeria Data Protection Commission (NDPC).
10
Children's Privacy
Our services and website are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected such information, we will promptly delete it. If you believe we have collected information from a minor, please contact us immediately.
11
Changes to This Notice
We reserve the right to update this Privacy Notice at any time. When we make material changes, we will update the effective date at the top of this page and, where appropriate, notify you by email or through a notice on our website. Continued use of our services after any update constitutes your acceptance of the revised notice. We recommend reviewing this page periodically.
This notice was last reviewed and updated on April 28, 2025. We recommend revisiting this page periodically. Significant revisions will be communicated directly to registered users and service clients.