Last updated: 28 March 2024 · Version 1.0
Summary: Xorus collects only the data necessary to deliver our services. We do not sell your personal data to any third party. We use industry-standard security practices to protect your information. You have the right to access, correct, or delete your data at any time.
1. Who we are
Xorus Analytics Ltd ("Xorus", "we", "us", or "our") is a data analytics consultancy registered in Nigeria. Our registered address is available upon request at hello@xorus.co.
We are the data controller for personal data collected through our website (xorus.co), consultation forms, client engagements, and any other touchpoints described in this policy.
Questions about this policy should be directed to our Data Protection contact: privacy@xorus.co.
2. Data we collect
2.1 Data you provide directly
When you interact with Xorus — whether by submitting a consultation request, contacting us by email, or entering into a client engagement — we may collect:
- Full name and job title
- Work email address and phone number
- Company name, size, industry, and country
- Information about your data infrastructure, tools, and challenges
- Budget, timeline, and engagement preferences
- Communications you send us (emails, messages, documents)
- Payment and billing information (processed via secure third-party providers)
2.2 Data we collect automatically
When you visit our website, we may automatically collect:
- IP address and approximate geographic location
- Browser type, device type, and operating system
- Pages visited, time on page, and referral source
- Cookie identifiers (see Section 9)
2.3 Data from client engagements
In the course of delivering analytics services, we may process data that belongs to or relates to your organisation, including business data, transactional records, customer datasets, and operational metrics. This data is processed under the terms of your client agreement and a Data Processing Agreement (DPA) where applicable.
3. How we use your data
We use your personal data for the following purposes:
- Responding to consultation requests — to review your submission and contact you to arrange a discovery call
- Delivering contracted services — to fulfil the analytics engagements you have hired us to perform
- Client communication — to send reports, updates, and insights related to your engagement
- Billing and administration — to issue invoices, process payments, and maintain financial records
- Service improvement — to analyse how our website and services are used, in order to improve them
- Marketing communications — to send newsletters, case studies, or event invitations, where you have given consent or where we have a legitimate interest
- Legal compliance — to comply with applicable laws, regulations, and court orders
4. Legal basis for processing
We rely on the following legal bases to process your personal data:
- Contract performance — processing necessary to fulfil our obligations under a client agreement
- Legitimate interests — responding to enquiries, improving our services, and preventing fraud
- Consent — for marketing communications and non-essential cookies, where we have asked for and obtained your consent
- Legal obligation — where we are required by law to retain or disclose data
5. Data sharing and disclosure
We do not sell your personal data. We may share data with the following categories of recipients only to the extent necessary:
- Service providers — cloud hosting providers, CRM platforms, payment processors, and email delivery services that process data on our behalf under strict confidentiality agreements
- Analytics tools — website analytics platforms (e.g. Google Analytics) that process aggregated, anonymised usage data
- Professional advisers — lawyers, accountants, and auditors bound by professional confidentiality obligations
- Law enforcement or regulators — where we are legally required to disclose data to comply with a court order, law enforcement request, or regulatory requirement
- Business transfers — in the event of a merger, acquisition, or sale of substantially all assets, your data may be transferred as part of that transaction
6. International data transfers
Xorus operates from Nigeria and may use service providers located in other countries, including the European Economic Area (EEA), United Kingdom, and United States. Where we transfer personal data internationally, we ensure adequate protections are in place through:
- Standard Contractual Clauses (SCCs) approved by relevant data protection authorities
- Binding Corporate Rules, adequacy decisions, or other recognised transfer mechanisms
7. Data retention
We retain personal data for as long as necessary to fulfil the purposes for which it was collected, or as required by law:
- Consultation enquiries (not converted to clients): 12 months from the date of submission
- Active client data: For the duration of the engagement plus 7 years for financial and legal compliance
- Marketing contacts: Until you unsubscribe or withdraw consent
- Website analytics: Up to 26 months in anonymised or aggregated form
When data is no longer required, we securely delete or anonymise it.
8. Your rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you
- Rectification — request correction of inaccurate or incomplete data
- Erasure — request deletion of your data (subject to legal retention obligations)
- Restriction — request that we limit how we process your data
- Portability — request your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests or for direct marketing
- Withdraw consent — where processing is based on consent, withdraw it at any time
To exercise any of these rights, contact us at privacy@xorus.co. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
9. Cookies and tracking
Our website uses cookies and similar technologies to improve your experience and analyse site usage. We use:
- Essential cookies — necessary for the website to function (cannot be disabled)
- Analytics cookies — to understand how visitors use our site (e.g. Google Analytics). Enabled only with your consent.
- Marketing cookies — to track the effectiveness of marketing campaigns. Enabled only with your consent.
You can manage your cookie preferences at any time via your browser settings or our cookie consent tool. Withdrawing consent does not affect any processing that took place before withdrawal.
10. Security measures
Xorus implements appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit (TLS 1.2+) and at rest
- Role-based access controls limiting data access to authorised personnel only
- Regular security assessments and penetration testing
- Employee training on data protection and security practices
- Incident response procedures and breach notification protocols
While we take all reasonable precautions, no system is completely secure. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and relevant authorities as required by law.
11. Children's data
Our services are directed at businesses and professionals. We do not knowingly collect personal data from individuals under the age of 18. If you believe we have inadvertently collected such data, please contact us at privacy@xorus.co and we will delete it promptly.
12. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will indicate the date of the most recent update at the top of this page. Where changes are material, we will notify existing clients by email.
We encourage you to review this policy periodically. Continued use of our website or services after changes take effect constitutes acceptance of the updated policy.
For any questions, requests, or concerns related to this Privacy Policy or our data practices, please contact:
© 2024 Xorus Analytics Ltd. This policy applies to xorus.co and all associated services.