Skip to main content
FortressSphere

Privacy Policy — FortressSphere

Last updated: [DATE — fill in on actual publication]

1. Who We Are

FortressPoint Consulting Limited ("FortressPoint," "we," "us," "our") operates FortressSphere (the "Service"). This Privacy Policy explains how we collect, use, share, and protect personal data belonging to users of the Service itself — this is distinct from the compliance documents (such as privacy policies) the Service generates *for* our customers about *their own* data handling practices.

Our data protection contact can be reached at: compliance@fortresspointconsulting.com

2. What Personal Data We Collect

Alongside each category below, we state plainly whether providing it is required to use the relevant part of the Service, or genuinely optional. Where something is required, it's required only because the Service genuinely cannot do that specific thing without it (e.g. we cannot create an account with no email address, or invite a teammate without their email address) — never merely because it's convenient for us to have.

  • Account information: name, email address, and authentication data, collected and managed on our behalf by our authentication provider. Your email address and authentication credentials are required — without them we cannot create an account for you. Your name is requested but not technically required; leaving it blank just means we address you less personally.
  • Organisation information: company name, and, where you use our team/organisation features, information about your organisation's members and their assigned roles (Admin, Editor, Viewer). A company name is required only if you are the first person setting up a new company/Dashboard account — if you're joining one that already exists, it's already set for you. Information about a teammate is required only at the point you choose to invite them — we cannot send an invitation with no email address to send it to.
  • Audit response data: your answers to our compliance self-assessment questionnaires, and the compliance scores and documents generated from those answers. Entirely optional — you can hold an account without ever starting a self-assessment. Without it, you simply won't receive compliance scores or generated documents, since there is nothing yet to score.
  • Payment information: processed by our payment processor (Paystack) — we do not directly store your full card details. We retain records of transaction status, subscription tier, and billing history necessary to administer your subscription. Required only if you subscribe to a paid tier or add-on; our free tier requires none of this.
  • Support communications: information you submit through our support ticket system, including your messages and any information you choose to provide when raising a request. Entirely optional — provided only if and when you choose to contact us.
  • Technical and log data: when you use the Service we automatically receive standard web request information, in particular your IP address and your user-agent string (the text your browser sends identifying its make, version, and operating system). We collect and keep this for three specific and separate purposes, not one broad "for security" catch-all. First, a security activity log: when you take a significant action in the Service (for example starting or completing a self-assessment, generating or downloading a document, uploading, downloading, or deleting an evidence file, inviting a teammate or changing their role, or requesting deletion of your account) we record the IP address and user-agent behind that action alongside a description of what was done, so that your organisation's own Administrators can review who did what, and so that we can investigate a security incident such as an unexpected evidence-file download. Second, rate limiting and abuse prevention: we use the IP address a request comes from to limit how often the same source can call the Service, and to place a temporary, self-expiring block on automated traffic that trips several different parts of the Service in quick succession; this matters most for the parts of the Service that work without an account, namely emailing yourself a link back to a free self-assessment, the "Request a Demo" and Enterprise contact forms, the public Trust Page and its "request full report" action, and the one-time links we send your vendors and staff so they can complete an assessment or a training module. Third, signup abuse prevention: we store the IP address present at the moment your account is first created, on your account record, and use it only as a cross-reference to detect one person creating several accounts from the same machine to get around our free-tier limits or a launch promotion; it is never used on its own to decide what you can access, and it is cleared if your account is deleted. Retention periods for each of these are set out in Section 7. Separately from the above, our hosting and analytics provider gives us cookieless, aggregate statistics about which pages of the Service are visited and the general browser, device, and country mix of visitors; this is derived from the same request information, but that provider does not retain raw IP addresses and we do not use it to identify you (see Sections 5 and 10). You cannot individually opt out of the operational collection described here while using the Service, because each purpose above is part of operating and securing it rather than a matter of preference, and we do not use this data to build a personal profile of you or to identify you beyond what these security and integrity purposes require.

3. How We Use Your Data

We use the personal data described above to:

  • Provide, operate, and maintain the Service;
  • Process your compliance self-assessments and generate documents on your behalf;
  • Process payments and manage your subscription;
  • Communicate with you about your account, support requests, and material changes to the Service or these terms;
  • Maintain the security and integrity of the Service;
  • Comply with our own legal and regulatory obligations.

We do not sell your personal data to third parties, and we do not use your audit response data or uploaded evidence to train AI models beyond the processing necessary to generate your requested documents, responses, or search results in the moment.

4. Legal Basis for Processing

As a Nigerian-registered company processing personal data primarily in connection with Nigerian compliance obligations, we process your data under the Nigeria Data Protection Act 2023 and its General Application and Implementation Directive (GAID). Our legal bases include: performance of our contract with you (providing the Service you've signed up for), your consent (where separately obtained, e.g. for marketing communications), and our legitimate interests in operating and securing the Service.

Where you are located in the United Kingdom or European Union, we also process your data consistently with UK GDPR / EU GDPR principles.

5. Who We Share Your Data With

We share personal data with service providers who help us operate the Service, each engaged under contractual terms requiring them to protect your data appropriately. These providers fall into the following categories:

  • Identity and account management providers, who authenticate your access to the Service
  • Cloud database and hosting providers, who store your account, organisation, and audit data
  • Content management providers, who host our question sets and document templates
  • AI processing providers, who assist in generating your compliance documents and grounded responses (including our compliance assistant), and in creating searchable representations of your evidence to support features like questionnaire automation
  • Payment processors, who handle subscription and purchase transactions
  • Email delivery providers, who send transactional notifications on our behalf
  • File storage providers, who host generated documents
  • Analytics providers, who give us cookieless, aggregate statistics about which pages of the Service are visited and the general browser, device, and country mix of visitors, without identifying you individually
  • Error monitoring and observability providers, who help us detect and diagnose technical problems with the Service (added 2026-08-13, following an internal review that found this category of provider built into the Service but not yet disclosed here — a same-day follow-up correction confirmed it hadn't actually gone live yet either, and fixed that the same day, so this disclosure is accurate as of the fix)

We do not sell your personal data to any third party. A current list of our specific sub-processors is available on request — contact compliance@fortresspointconsulting.com.

6. International Data Transfers

Some of our sub-processors host or process data outside Nigeria (including in the European Union and United States). Where this occurs, we take steps intended to ensure an adequate level of protection for your data during transfer, consistent with the GAID's requirements for cross-border data transfers — including, where applicable, standard contractual clauses or other approved transfer mechanisms.

7. Data Retention and Deletion

We retain your account and compliance data for as long as your account remains active. If you request deletion of your account, the following process applies — this reflects our actual, built system, not a generic promise:

Grace period. Once you request deletion, your account enters a 14-day grace period during which it is scheduled for deletion but not yet purged — this exists to protect against accidental requests or a change of mind. You (or, where applicable, our support team) can cancel a pending deletion during this window.

What is deleted. What "permanently delete" means here depends on whether your account stands alone or belongs to a company:

  • Solo users (no Company). Once the grace period ends, we permanently delete your compliance content in full — audit responses and scores, generated documents and their underlying files, uploaded evidence files, vendor assessments, and training records, chat/ assistant conversation history, support tickets, and incident reports. Your account identity itself is also removed — *unless* you have billing history with us, in which case your account row is anonymized rather than deleted outright, for the same reason described under "What is retained, and why" below.
  • Company members. Your personal account is anonymized, not deleted outright (see below), and your access to the company is removed. Compliance content that belongs to your organisation — audit runs, generated documents, evidence, vendor assessments, training records, chat/assistant history, and anything else shared with your team — is not deleted when you personally leave or delete your account. It remains your organisation's data, available to your former colleagues, the same way a departing employee's work product stays with their employer's records rather than leaving with them. Only content that was genuinely personal to you and never tied to your company (e.g. work from before you joined, or under a separate personal account) is deleted.

How your account itself is handled. For a company member, or a solo user with billing history, your User record is anonymized rather than removed: your email is replaced with a non-reversible internal reference, your sign-in with us is deleted, and your name, phone number, job title, industry, and any recorded street address are all cleared — but the row itself stays (company members are also detached from the organisation). This is necessary because other records — your organisation's data, or our own retained financial records — refer back to your account and need to stay valid. For a solo user with no billing history, the account row is removed outright.

What is retained, and why. Nigerian tax law (the Companies Income Tax Act, the Companies and Allied Matters Act, and FIRS guidance) requires us to retain financial and transactional records for six (6) years. We retain the minimum necessary financial facts (payment amounts, dates, subscription plan, and payment processor reference) for this period — but we do not keep these records linked to your full personal profile once your account relationship ends; your name and email on these records are replaced with an internal reference, consistent with NDPA's principle that personal data should only be retained as long as necessary for the specific purpose it serves — here, that purpose narrows from "operating your account" to "our own tax record-keeping obligation."

Accountability record. We keep a minimal internal log confirming that a deletion request was made and completed, using a one-way cryptographic reference that cannot be reversed to identify you. This exists solely so we can demonstrate, if ever required, that we genuinely honour deletion requests — it does not retain your personal data.

Internal administrative records. Where a member of our team takes an action on your account or your organisation's behalf — for example, resolving a support ticket that required a team-membership or billing correction — we keep an internal record of that action (what was done, and which staff member did it) for five years. This is separate from, and not affected by, your own account's data lifecycle described above: it exists so we can hold our own team accountable for actions taken on the platform, not to track your activity, and it is retained for a genuinely decided period (long enough to support a real after-the-fact review — e.g. a billing dispute — short enough that it isn't indefinite by default) rather than kept forever.

Security and activity logs. Separately from the account and compliance data above, we keep short operational logs of technical request data (IP address and user-agent) for the security and abuse-prevention purposes described in Section 2, each with its own retention period. The activity log of significant account actions is deleted after 90 days. The counters and temporary block records used for rate limiting and automated-abuse prevention are deleted within 24 to 48 hours. Where an automated abuse block is actually triggered, a security-incident record of that event (including the IP address involved) is kept for five years, and is also sent to the error monitoring and observability provider referred to in Section 5. The IP address captured when an account is first created is held on that account and cleared when the account is deleted or anonymised, as described under "How your account itself is handled" above.

Sole administrators. If you are the sole Administrator of an organisation account, self-service deletion is not available to you directly, since it would leave your organisation's data without anyone able to manage it. Please contact compliance@fortresspointconsulting.com to arrange this — we will work with you to transfer administration to a colleague first. If what you actually want is deletion of your organisation's entire data footprint, we can also arrange that — contact us at the same address above to request it. This isn't a self-service action you can trigger directly, given how irreversible it is, but once confirmed, we carry it out using a dedicated deletion process that removes your organisation's data completely and reliably.

Data about third parties we process on your behalf. In the course of providing the Service, we also process personal data about people who are not our own users and have no direct relationship or account with FortressPoint — specifically, your own employees (where you use our staff training feature) and your vendors and their staff (where you use our vendor risk assessment feature). You are the data controller for this information; we act as processor. Because this population never consented to a relationship with us directly, we apply defined retention periods rather than keeping this data indefinitely:

  • *Staff training roster records* are retained for 12 months after you mark a staff member as inactive/removed, then permanently deleted. This is intended to cover a full annual training-compliance audit cycle after someone leaves, without retaining their data indefinitely.
  • *Vendor assessment records* (vendor profiles, questionnaire answers, and any follow-up requests/answers, including uploaded evidence files) are retained for 24 months from the last activity on that vendor relationship (the most recent assessment completion, or follow-up completion, whichever is later), then permanently deleted, including the underlying evidence files.

These purges run automatically; there is no manual step required on your part, and no way to opt out of them, since indefinite retention of this specific population's data is the underlying problem they exist to fix.

8. Your Rights

Depending on your location, you may have rights including: access to your personal data, correction of inaccurate data, deletion of your data, objection to certain processing, and data portability.

Deletion specifically can be requested directly within the Service itself, from your account settings — see Section 7 above for exactly what happens once you do. For all other rights requests, or if you are a sole Administrator needing to arrange deletion of an organisation account, contact us at compliance@fortresspointconsulting.com or through our in-Service support ticket form.

We will respond to legitimate requests within the timeframes required by applicable law. If you are unsatisfied with our response, you may escalate your concern to Nigeria's National Data Protection Commission (NDPC), or, where applicable, your local data protection authority.

9. Automated Decision-Making

We reviewed every automated and AI-assisted feature in the Service to determine whether any of them make a decision about you that produces a legal or similarly significant effect, without meaningful human involvement.

Our compliance scoring, AI Compliance Assistant, proactive reminders, vendor risk-tier recommendations, AI-assisted questionnaire answer drafting, AI-generated compliance documents, and regulatory update monitoring are all informational or advisory: each either shows information back to you for your own review, or produces draft content that a human must review and choose to act on before it has any real-world effect. None of these features make a decision about you.

One specific, disclosed exception. If a scheduled subscription payment fails, our payment processor notifies our system automatically, and the paid features of your account are suspended immediately (reverting to our free tier) without a FortressPoint staff member reviewing the failure first. This is a mechanical application of our payment terms based on an objective, verifiable fact (whether a charge succeeded) rather than an evaluation of you as a person. If you believe this happened in error, or you've since corrected your payment method, contact us at compliance@fortresspointconsulting.com and we will review and restore your access.

10. Cookies

We use essential cookies necessary for authentication and maintaining your signed-in session. We do not currently use non-essential tracking or advertising cookies. The usage analytics described in Section 2 are cookieless and set no identifier on your device.

11. Children's Data

The Service is intended for use by business professionals and is not directed at or intended for use by individuals under the age of 18. We do not knowingly collect personal data from children.

12. Security

We apply reasonable technical and organisational measures to protect your data, including encryption in transit and access controls. No system can be guaranteed fully secure, and we encourage you to use a strong, unique password for your account.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes through the Service or by email before they take effect.

14. Contact and Complaints

If you have questions, concerns, or a complaint about how we handle your personal data, please contact us at: compliance@fortresspointconsulting.com, or through our in-Service support ticket form (selecting the appropriate category).

We aim to acknowledge and address all data protection concerns directly and promptly, consistent with the same standard of accessible, no-legal-knowledge-required complaint handling (in the spirit of the GAID's Standard Notice to Address Grievance approach) that we help our own customers build for their users.