Legal
Privacy Policy
What personal data we collect, why we hold it, where it lives, and the rights you have over it under the Nigeria Data Protection Act 2023.
Last updated: 3 September 2026. This policy is published by Sabi Networks Limited (RC PENDING, TIN PENDING), Lagos, Nigeria.
Where you have an executed order form, quotation or service level agreement with us, that signed contract prevails over this website copy to the extent of any conflict.
01Who we are
Sabi Networks Limited (RC PENDING, TIN PENDING), trading as Sabi Networks Digital Infrastructure, is the data controller for the personal data described in this policy. Our registered address is Lagos, Nigeria and privacy enquiries go to sales@sabinetworks.com.
This policy explains what we collect when you browse this website, request a quote, hold an account in the customer portal or contact our support team, and how we handle it under the Nigeria Data Protection Act 2023 (NDPA) and the guidance of the Nigeria Data Protection Commission (NDPC).
02Personal data we collect
Account and contact data — name, business email, phone number, job role, organisation name, RC and TIN details, and the roles you hold in the portal.
Quote and order data — the configurations you build, requirements you describe, quotation and order records, approvals and revision history.
Billing data — invoices, credit notes, payment references, bank transfer remittance details, withholding tax credit notes and account statements. We do not collect or store full card numbers.
Support data — tickets, messages, attachments you upload, timestamps and SLA event records.
Technical and log data — IP address, browser and device information, authentication events, portal usage, and network or platform logs generated while delivering your services.
Compliance data — identification of signatories and authorised contacts, and site access records where you visit the facility.
We do not seek sensitive personal data. Please do not include health, biometric, political or comparable sensitive information in tickets or attachments.
03Lawful bases for processing
We rely on the following bases under section 25 of the NDPA:
- Performance of a contract — provisioning, operating and supporting your services, invoicing and collections.
- Legitimate interests — securing our platform, preventing abuse and fraud, maintaining logs, improving our services, and responding to business enquiries you initiate.
- Legal obligation — tax and accounting records, VAT and withholding tax documentation, statutory retention, lawful requests from authorities.
- Consent — optional marketing communications, which you can withdraw at any time without affecting your service.
04How we use personal data
- preparing quotations and processing orders;
- provisioning, monitoring, maintaining and supporting services;
- authenticating portal access and protecting accounts;
- issuing invoices, credit notes and statements, and reconciling payments;
- sending service notifications, maintenance notices and SLA alerts;
- investigating abuse, security incidents and network faults;
- meeting tax, regulatory and audit obligations;
- improving our service catalogue and pricing using aggregated, non-identifying analysis.
05Customer content: we are a processor, not a controller
Personal data your own systems hold inside a VPS, colocated server or storage volume remains under your control. For that data you are the controller and we act as a processor: we process it only to deliver, secure and support the infrastructure, on your instructions.
We do not inspect the contents of your workloads except where necessary to investigate abuse, restore service, or comply with a lawful demand. Where you require a formal data processing agreement, contact us and we will execute one alongside your service contract.
06Data residency and cross-border transfers
Customer workloads, their backups and our operational records are held in Nigeria at our carrier-neutral Tier III facility in Lagos, unless you instruct otherwise in writing.
A limited set of business systems we use — for example email delivery, notification services and hosted business tooling — may process data outside Nigeria. Where that happens we rely on adequacy or contractual safeguards permitted by section 41 of the NDPA and keep the categories of data transferred to the minimum necessary.
08How long we keep data
- Account and contract records — for the life of the relationship and six years afterwards, for tax and limitation purposes.
- Invoices, payments and tax documents — at least six years, as required by Nigerian tax law.
- Support tickets and attachments — three years after closure.
- Authentication and security logs — up to twelve months, longer where an investigation is open.
- Terminated service data and backups — securely erased within 14 days of termination unless you have agreed a different arrangement in writing.
- Marketing consents — until withdrawn, plus a suppression record so we honour your opt-out.
09Security
We apply role-based access control, row-level authorisation in our platform database, encrypted transport for portal and API traffic, private storage for ticket attachments with time-limited signed access, audit logging of privileged actions, least-privilege staff access and controlled physical access at the facility.
No system is completely secure. We keep our controls under review and expect customers to protect their own credentials, keys and in-instance configuration.
10Your rights
Under the NDPA you may:
- ask what personal data we hold about you and receive a copy;
- have inaccurate data corrected or incomplete data completed;
- ask us to delete data where we no longer have a lawful basis to keep it — noting that tax and contractual records must be retained;
- restrict or object to processing based on legitimate interests;
- receive your data in a portable, machine-readable format;
- withdraw consent to marketing at any time;
- not be subject to a decision based solely on automated processing that materially affects you — we make no such decisions.
Write to sales@sabinetworks.com to exercise a right. We may ask you to verify your identity, and we respond within 30 days. Where the request concerns data held inside your own workloads, the request should be directed to you as the controller and we will assist you.
12Breach notification
If a personal data breach occurs that is likely to result in risk to individuals, we will notify the NDPC within 72 hours of becoming aware of it where required, and inform affected customers without undue delay with the facts known, the likely consequences and the steps we are taking. Where we act as your processor, we will notify you promptly so you can meet your own obligations.
13Complaints and contact
Raise any privacy concern with us first at sales@sabinetworks.com or +234 000 000 0000 — we would rather fix it directly. If you are not satisfied with our response you may complain to the Nigeria Data Protection Commission.
We review this policy at least annually and when our processing changes materially, and will notify account holders of significant updates.
Questions about this policy?
Write to sales@sabinetworks.com or call +234 000 000 0000. Registered office: Lagos, Nigeria.
Contact us →