Legal
Privacy policy
Last updated 29 September 2026
How we collect, use, protect and keep personal data when you visit our website or use TinERP.
In short
- Your organization owns the data it puts into TinERP. We process it only to provide the service.
- We never sell personal data or use it for advertising, and we don't use your data to train AI.
- We use only the cookies needed to keep you signed in.
- After you cancel, we keep your data for 90 days so you can come back, then delete it. Invoices and payment records are kept for 6 years for tax.
- You can ask to see, correct, export or delete your data at any time.
This summary is for convenience. The full text below is what applies.
01
Who we are
TinERP is a business management platform made by Tinsoft Technologies Ltd ("Tinsoft", "we", "us"), a company in Nigeria with its office at Central Business District, Abuja, Nigeria.
This policy explains what personal data we collect when you visit our website, sign up for TinERP or use it, what we do with it, who we share it with, how long we keep it and the rights you have. It is written to meet the Nigeria Data Protection Act 2023 ("NDPA") and the regulations and guidance of the Nigeria Data Protection Commission ("NDPC").
For any privacy question or request, email [email protected] with "Privacy" in the subject, call +234 706 970 1471, or write to us at the address above.
02
Our role: controller and processor
Data protection law distinguishes between the party that decides why and how personal data is used (the controller) and a party that handles it on the controller's behalf (the processor).
- We are the controller of the data we need to run our own business: visitors to our website, the people who sign up, account and billing contacts, the users of each organization's account (names, emails, sign-in and security records), and support conversations.
- Our customers are the controllers of the data they put into TinERP about their own people and business - for example employee records, leave, timesheets, vendors, customers, invoices, funds and grants ("Customer Data"). We handle Customer Data as their processor, only to provide TinERP and only on their instructions, as set out in our Terms of Service.
If you are an employee, vendor or other person whose details an organization keeps in TinERP, that organization decides how your data is used. Please send requests about it to them first; we will help them respond.
03
What we collect
| Data | Examples | Where it comes from |
|---|---|---|
| Account and contact details | Name, work email, phone number, job title, organization name and address | You, when you sign up, are invited or update your profile |
| Sign-in and security records | Password (stored only as a one-way hash), two-factor settings, sign-in times, failed attempts and lockouts, IP address and browser | Your use of TinERP |
| Billing details | Plan, invoices, payments, bank transfer references, the last digits and expiry of a saved card | You, and our payment provider Paystack. We never see or store full card numbers |
| Support and communications | Support tickets, emails and demo requests, and our replies | You |
| Activity records | An audit log of changes made in the organization's account and who made them | Your organization's use of TinERP |
| Customer Data | Whatever your organization records in TinERP, such as staff records, leave, timesheets, invoices, vendors and files | Your organization (we process it for them - see section 2) |
| Website visits | Pages requested, browser type and IP address in our server logs | Your browser, when you visit our website |
Sensitive data. Organizations may record details that need extra care, such as an employee's national identification number (NIN), tax and pension numbers, bank details, date of birth, home address or the fact that someone was on sick leave. TinERP restricts these fields to people given a specific permission, hides their values in the audit log, and requires approval for changes to bank details. Organizations should record only what they need.
04
How we use it, and our lawful basis
| Purpose | Lawful basis under the NDPA |
|---|---|
| Creating and running your account, and providing TinERP and its features | Performance of our contract with your organization |
| Billing, collecting payments, issuing VAT invoices and keeping financial records | Contract, and our legal obligations (tax and company law) |
| Keeping accounts secure: sign-in checks, two-factor authentication, lockouts, fraud and abuse prevention, audit logs | Our legitimate interest in protecting our customers and service, and legal obligations on security |
| Service emails: invitations, password resets, approvals, reminders, renewal and payment notices | Contract |
| Support, onboarding and the free setup we provide | Contract |
| Improving TinERP and fixing faults | Legitimate interest. We use service records for this, not the content of Customer Data |
| Product news and marketing emails | Your consent, which you can withdraw at any time using the link in the email or by writing to us |
| Meeting legal requests and enforcing our terms | Legal obligation and legitimate interest |
We do not sell personal data, and we do not use Customer Data for advertising or to train artificial intelligence models.
06
Data stored outside Nigeria
Some of our providers store or process data outside Nigeria. Where personal data is transferred abroad, we do so only as the NDPA allows - for example where the destination has adequate data protection, under contract terms that protect the data, or where another lawful ground applies - and we make sure the same level of protection continues.
07
How long we keep it
| Data | How long |
|---|---|
| Account and Customer Data while you subscribe | For as long as your organization has an account |
| After cancellation, non-payment or a trial that ends without a subscription | 90 days, with reminders, so your organization can resubscribe and carry on or export its records. After that it is due for deletion, and a member of our staff deletes it after checking |
| Invoices, payment records and the records we must keep for tax | 6 years after the end of the financial year they relate to, as tax and company law require, even when other data is deleted |
| Security and audit records | As long as the organization's account exists, then deleted with it |
| Support conversations | As long as the account exists and 90 days after, unless we need them for a dispute |
| Backups | Deleted data is removed from backups as those backups expire |
Your organization can ask us to delete its data sooner. We will confirm the request with the account owner first, because deletion cannot be undone.
08
How we protect it
- Each organization's data is kept separate from every other organization's, and every request is checked against the organization it belongs to.
- Passwords are stored only as strong one-way hashes (argon2). Accounts lock after repeated failed sign-ins, and a password change signs out every other device.
- Two-factor authentication is available to every user, and an organization can require it for all its users.
- Two-factor secrets and payment authorization codes are encrypted at rest (AES-256), and reset and invitation links are single-use and short-lived.
- Data travels over encrypted connections (HTTPS), and sign-in cookies cannot be read by other scripts on the page.
- Roles and permissions control who can see and change what, down to a person's own department, and changes are recorded in an audit log.
- Uploaded files are stored in private storage and only shown to people allowed to see the record they belong to.
No system is perfectly secure. If a personal data breach is likely to put people's rights at risk, we will notify the NDPC within 72 hours of becoming aware of it, as the NDPA requires, and tell affected organizations without undue delay so they can meet their own obligations.
10
Your rights
Under the NDPA you have the right to:
- be told how your personal data is used (this policy) and get a copy of it;
- have inaccurate or incomplete data corrected;
- have your data deleted, where there is no longer a lawful reason to keep it;
- restrict or object to how it is used, including to marketing at any time;
- receive your data in a commonly used format and have it sent to another provider;
- withdraw consent where we rely on it, without affecting what was done before;
- not be subject to decisions based solely on automated processing that significantly affect you - TinERP does not make such decisions about people.
To use these rights, email [email protected]. We may need to confirm your identity first. We will respond within 30 days. If the request is about data an organization keeps about you in TinERP, we will pass it to that organization and help them respond.
You can also complain to the Nigeria Data Protection Commission (ndpc.gov.ng). We would appreciate the chance to put things right first.
11
Children
TinERP is a service for organizations and is not meant for children. Our users must be at least 18 years old. Organizations that record details of children, such as a staff member's next of kin or beneficiaries of an NGO programme, are responsible for having a lawful basis to do so.
12
Changes to this policy
We will update this policy when our practices or the law change, and change the date at the top. If a change materially affects how we use personal data, we will tell account owners by email or in TinERP before it takes effect.
13
Contact us
Tinsoft Technologies Ltd
Central Business District, Abuja, Nigeria
Email: [email protected]
Phone: +234 706 970 1471