Privacy Policy
Contents
1. Who we are
EventsPro Studio ("we", "us") provides software that event planners in Nigeria use to produce proposals, agree contracts and collect deposits. This policy explains what personal data we handle, why, and what you can require of us.
We are the data controller for the account data of planners who sign up. For the client information a planner enters, the relationship is different — see section 3.
This policy is written to meet the Nigeria Data Protection Act 2023 (NDPA) and the obligations it places on data controllers and processors.
2. What we collect
Information you give us
- Account details — your name, email address, business name, phone number, and the password you choose (stored only as a cryptographic hash; we never see it).
- Branding — your logo and brand colour, if you upload them.
- Business records — the events, proposals, line items, budgets, timelines, floor plans and vendor contacts you create.
- Payout details — if you connect payouts, your bank and account number are sent to Paystack to create a settlement subaccount. We store only the resulting subaccount reference, not your account number.
Information created by using the service
- Authentication data — session tokens and sign-in timestamps.
- Payment records — the amount, currency, status, reference and timestamp of each transaction. We never receive or store card numbers. Card details are entered on Paystack's own checkout and never reach our servers.
- Signature evidence — when a contract is signed through the client portal we record the drawn signature image, the time of signing, the signer's IP address and their browser user-agent string. This exists so a signature can be evidenced later if a booking is disputed.
- Usage counters — a record of each AI generation, used to enforce plan limits.
- Server logs — standard request logs kept by our hosting providers for security and debugging.
We do not use advertising cookies, third-party analytics trackers, or cross-site tracking of any kind. The only cookies we set are the ones required to keep you signed in.
3. Your clients' data, and who controls it
When you enter a client's name, email address or phone number, or when your client signs a contract through the portal, you are the data controller for that information and we act as your data processor. We process it only to run the service for you, and on your instructions.
That places obligations on you as well as on us. You are responsible for having a lawful basis to enter a client's details, for telling your clients how their information is used, and for responding to them if they ask to see or delete it. We will help you meet those requests — see section 10.
We do not sell data, and we never use one planner's business records to benefit another. Your client list, your vendor prices and your proposals are yours. Every planner's data is separated at the database level by row-level security, not merely hidden in the interface.
4. Why we process it
| Purpose | Lawful basis (NDPA s.25) |
|---|---|
| Providing the service you signed up for | Performance of a contract |
| Taking subscription payments | Performance of a contract |
| Recording signature evidence on contracts | Legitimate interest — establishing that an agreement was made |
| Sending service emails (proposal sent, payment received, password reset) | Performance of a contract |
| Security, fraud prevention, abuse limits | Legitimate interest |
| Meeting tax, accounting and legal obligations | Legal obligation |
We do not send marketing email to your clients. Ever. The only messages they receive are the transactional ones your own workflow triggers.
5. How AI features use your data
Proposal drafting, timeline generation and contract rewriting are produced by a large language model operated by Anthropic. When you use one of these features, the details needed for that generation — event type, guest count, budget, venue, and any notes you supply — are sent to Anthropic's API to produce the result.
- These calls happen only when you trigger them. Nothing is sent for analysis in the background.
- We do not send your client list, vendor directory, payment records or signature data to any AI provider.
- Anthropic processes the request under its commercial terms and does not use API inputs or outputs to train its models.
If you would rather no data reached an AI provider at all, do not use the AI features. Every other part of the service — proposals, contracts, portals, payments — works without them.
6. Who we share it with
We use a small number of processors, each for one clearly defined job:
| Processor | What it handles |
|---|---|
| Supabase | Database, authentication and file storage |
| Render | Application hosting |
| Paystack | Card and transfer payments, and planner payouts |
| Anthropic | AI generation, only when you trigger it |
| Resend | Transactional email delivery |
We may also disclose data where the law requires it, or to establish or defend a legal claim. If we are ever involved in a merger or acquisition we will tell you before your data moves, and the acquirer will be bound by this policy.
7. Portal links and calendar links
A proposal is shared with your client through a link containing a long random token. Anyone holding that link can view the proposal, so treat it as confidential — the link itself is the key. These pages are marked so search engines do not index them, but a link forwarded to someone else will work for them too.
Your calendar subscription link works the same way. If you have shared one and want to cut it off, regenerate it in Settings; every previously shared copy stops working immediately.
8. How long we keep it
- While your account is open — we keep your data so the service works. Ending a paid plan does not delete anything; the account reverts to the free tier and the data remains.
- After you delete your account — we delete your personal data and business records within 30 days, other than what we must keep.
- Records we must keep — transaction records and signed contracts are retained for the period Nigerian tax and limitation law requires, even after account closure.
- Backups — deleted data may persist in encrypted backups for up to 90 days before being overwritten.
9. Security
- All traffic is encrypted in transit with TLS. Data is encrypted at rest by our hosting providers.
- Passwords are stored only as salted cryptographic hashes.
- Access between planners is prevented by row-level security in the database itself, so a fault in the application layer alone cannot expose another planner's records.
- Payment card data never touches our servers.
- Payment notifications from Paystack are verified by cryptographic signature before being acted on.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the Nigeria Data Protection Commission and affected users in line with NDPA requirements.
10. Your rights under the NDPA
You may ask us to:
- Access the personal data we hold about you, and receive a copy.
- Correct anything inaccurate — most of it you can edit yourself in Settings.
- Delete your data, subject to the records we are legally required to keep.
- Restrict or object to processing carried out on the basis of legitimate interest.
- Export your data in a portable, machine-readable format.
- Withdraw consent where processing relies on it, without affecting what was done before.
Write to support@eventsprostudio.com and we will respond within 30 days. If your request concerns data a planner holds about you as their client, we will pass it to that planner, who is the controller of it.
You also have the right to complain to the Nigeria Data Protection Commission if you believe your data has been mishandled.
11. Transfers outside Nigeria
Our hosting and processors operate servers outside Nigeria, currently in the European Union and the United States. Where personal data is transferred outside Nigeria we rely on the safeguards permitted by NDPA Part VIII, including contractual protections with each processor. Payment processing is handled by Paystack, which operates within Nigeria.
12. Children
The service is for businesses and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child's data has reached us, contact us and we will remove it.
13. Changes
We will post any change here and update the date at the top. If a change materially affects your rights we will email account holders before it takes effect.
14. Contact
support@eventsprostudio.com
EventsPro Studio, Lagos, Nigeria