Privacy
policy.
How PZ Nexa Collects, Uses, and Protects Your Personal Information
PZ Nexa ("we," "us," "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect personal information when you engage our services, visit our website at www.pznexacol.com, or otherwise interact with us. By using our services, you consent to the practices described in this Policy.
1.Who We Are
PZ Nexa is a business consulting firm headquartered in Lagos, Nigeria. We provide startup strategy, growth advisory, capital readiness, and AI consulting services to founders and businesses across Africa.
2.Information We Collect
Information You Provide Directly: We collect information you provide when you:
- (a)fill out a contact or intake form on our website;
- (b)book a consultation via our scheduling platform;
- (c)sign a service agreement or proposal;
- (d)communicate with us via email, WhatsApp, or phone; or
- (e)subscribe to our newsletter or content resources.
This information may include: full name, email address, phone number, company name and role, business details, financial information relevant to the engagement, and any other information you choose to share.
Information Collected Automatically: When you visit our website, we may automatically collect: IP address, browser type and version, pages visited and time spent, referring URLs, and device information. This data is collected via cookies and similar tracking technologies.
Information from Third Parties: We may receive information about you from: referral partners, LinkedIn and other professional networks if you engage with our content, payment processors, and publicly available sources relevant to service delivery.
3.How We Use Your Information
We use your personal information for the following purposes:
- (a)Service Delivery: to provide, manage, and improve the consulting services you have engaged us for;
- (b)Communication: to respond to enquiries, send proposals, update you on engagement progress, and provide client support;
- (c)Billing and Payments: to process invoices, payments, and maintain financial records;
- (d)Marketing (with consent): to send newsletters, case studies, and thought leadership content — you may unsubscribe at any time;
- (e)Legal Compliance: to comply with applicable Nigerian laws and regulations, including tax and anti-money laundering obligations;
- (f)Website Improvement: to analyse how visitors use our website and improve user experience;
- (g)Business Development: to manage our client relationships, including post-engagement follow-ups and referral tracking.
4.Legal Basis for Processing
We process your personal data on the following lawful bases under the Nigeria Data Protection Act 2023 (NDPA) and the Nigeria Data Protection Regulation (NDPR) 2019:
- (a)Contract Performance: processing necessary for the services you have engaged us for;
- (b)Legitimate Interests: processing necessary for our legitimate business interests, including client relationship management and business development;
- (c)Legal Obligation: processing required to comply with applicable law;
- (d)Consent: where you have expressly consented, including for marketing communications.
5.Data Sharing and Disclosure
We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.
We may share your information with:
- (a)Service Providers: trusted third-party providers who assist us in delivering services (e.g. cloud storage, scheduling platforms, payment processors), who are contractually bound to protect your data;
- (b)Professional Advisors: lawyers, accountants, or auditors under obligations of confidentiality;
- (c)Legal Authorities: where required by Nigerian law, court order, or to protect the rights and safety of PZ Nexa or others;
- (d)Business Transfers: in the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction.
6.Data Retention
We retain your personal data for as long as necessary to fulfil the purposes described in this Policy, or as required by applicable Nigerian law.
Typical retention periods are:
- (a)Client data (contact information, project files, financial records): 7 years after the end of the engagement, in line with tax and regulatory requirements;
- (b)Marketing data (newsletter subscribers): until you unsubscribe or request deletion;
- (c)Website analytics: up to 24 months.
When data is no longer required, we will securely delete or anonymise it.
7.Cookies and Tracking
Our website uses cookies to improve your browsing experience, analyse site traffic, and support marketing. Cookies are small text files placed on your device.
We use the following types of cookies:
- (a)Strictly Necessary: required for the website to function;
- (b)Analytics: to understand how visitors interact with our site (e.g. Google Analytics);
- (c)Marketing: to deliver relevant content and track campaign performance.
You may manage or disable cookies through your browser settings. Note that disabling certain cookies may affect the functionality of the website.
8.Your Rights
Under the NDPA 2023 and NDPR 2019, you have the following rights regarding your personal data:
- (a)Right of Access: to request a copy of the personal data we hold about you;
- (b)Right to Rectification: to request correction of inaccurate or incomplete data;
- (c)Right to Erasure: to request deletion of your data, subject to our legal obligations;
- (d)Right to Restrict Processing: to request that we limit how we use your data in certain circumstances;
- (e)Right to Data Portability: to receive your data in a structured, machine-readable format;
- (f)Right to Object: to object to processing based on legitimate interests, including for direct marketing;
- (g)Right to Withdraw Consent: to withdraw any consent given at any time, without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at hello@pznexa.com. We will respond within 30 (thirty) days.
9.Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or disclosure.
These measures include: encrypted data transmission (SSL/TLS), access controls and authentication, regular security reviews, and staff confidentiality obligations.
While we take reasonable precautions, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
In the event of a data breach that poses a risk to your rights, we will notify affected individuals and the Nigeria Data Protection Commission (NDPC) within the required timeframe.
10.International Data Transfers
If we transfer your data outside Nigeria (e.g. to cloud service providers located in other jurisdictions), we ensure that appropriate safeguards are in place, including standard contractual clauses or equivalent protections, in accordance with NDPA 2023 requirements.
11.Children's Privacy
Our services are not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, please contact us immediately at hello@pznexa.com.
12.Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites. We encourage you to review the privacy policies of any third-party sites you visit.
13.Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on our website. Your continued use of our services after such notice constitutes acceptance of the updated Policy.
14.Contact and Complaints
For any privacy-related queries, requests, or complaints, contact our Data Protection Officer at:
You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe your data rights have been violated.