Privacy Policy

Last updated: 25 July 2026

Suwebatu Limited, a company registered in Nigeria, is the data controller for this Service ("Suwebatu", "we", "us"). This policy is written against Nigeria's NDPA 2023 and NDPR. It does not cover the additional obligations of the EU GDPR; we do not currently offer the Service to organisations established in the EU/EEA, and this policy will be extended before we do.

1. What we collect

Account details you provide (name, email, password - stored as a salted hash, never plain text); organisation and billing details; invoice, client, and payment records you enter; usage and log data (IP address, timestamps) for security and rate limiting; payment metadata from our payment processor (we do not store full card numbers).

2. Why we process it (legal basis)

To perform our contract with you (running the Service you signed up for); to comply with legal obligations (tax and audit records); and, for security logs and fraud prevention, our legitimate interest in keeping the Service safe - balanced against your rights.

3. Who we share it with

Sub-processors that help run the Service: Neon (database hosting), Vercel (application hosting), Cloudinary (file and logo storage), our SMTP email provider (delivery of invoices and notifications), Paymish (subscription payment processing), Upstash (rate limiting, which processes IP addresses), and Sentry (error monitoring, which may capture technical request context when something fails). Each processes data only as needed to provide their function to us, under agreement. We do not sell your data.

4. Where your data is stored

Our providers operate data centres outside Nigeria; the database and application currently run in the United States, and some providers may process data elsewhere. Where data leaves Nigeria we rely on the safeguards required under the NDPA/NDPR for cross-border transfer. If your organisation needs its data held in a specific region, contact us before signing up.

5. How long we keep it

Active account data is kept for as long as your subscription is active. After cancellation we keep it for 90 days so you can still sign in and export it, then delete or anonymise it, except where longer retention is required by tax or audit law - financial records and audit logs are commonly subject to multi-year statutory retention, and those are kept for as long as the law requires.

6. Your rights

Under the NDPA/NDPR you can request access to, correction of, or deletion of your personal data, and request a portable export of your organisation's data. Contact us to exercise these rights; some data (e.g. audit logs required for financial compliance) may be exempt from deletion while a legal retention obligation applies.

7. Security

Passwords are hashed, not stored in plain text. Sessions can be revoked server-side. Optional multi-factor authentication (TOTP) is available. Access to your organisation's data is restricted to your own team by design (tenant isolation). If a breach affecting your personal data occurs, we will notify affected users and, where legally required, the relevant regulator, without undue delay.

8. Cookies

We use only the session cookie required to keep you signed in - no third-party advertising or tracking cookies.

9. Children

The Service is intended for business use by adults; it is not directed at children.

10. If you invoice other companies through the Service

When you use the Service to invoice your own clients, you are the controller of your clients' personal data and we process it on your instructions (a processor relationship). Once the Service is offered to organisations other than Suwebatu itself, a separate Data Processing Agreement covering this relationship will be provided before onboarding.

11. Changes

We may update this Policy; material changes will be notified by email or in-app before they take effect.

12. Contact

Data protection questions: billing@suwebatu.co.uk.