Legal · Privacy
Your information should have a clear route.
Last updated 12 September 2026. This notice explains the data used to operate GainHub NG and the choices available to you.
Service operator
Cyber Elias Academy operates GainHub NG. Privacy correspondence can be sent to smbprivacy@cea.ng.
1. Who this notice covers
This notice applies to visitors, account holders, people who contact a listed business, listing applicants, business owners, reviewers, reporters and contact-circle participants using GainHub NG. GainHub NG is a service name; the configured deploying operator is the organisation responsible for the service.
A listed business is independently responsible for information it receives and uses outside GainHub NG, including a conversation continued by phone or WhatsApp. Ask that business about its own privacy practices where appropriate.
2. Information we collect
- Account data: name, email address, Nigerian phone number, role, account status and password-verification material. We store a salted password derivation, not the password itself.
- Business and listing data: business name, description, category, service location, public address or service area, contact channels, opening hours, website, photographs and ownership relationships.
- Conversations and feedback: enquiry contact details and message, ratings, review text, saved listings, correction suggestions and the records needed to attribute them.
- Trust and moderation data: reports, claim details, private supporting files, review decisions, contact-circle proposals, applications, membership state and personal-data requests.
- Security and usage data: request IDs, account-linked audit actions, contact-channel events and salted hashes derived from network addresses for rate limiting and abuse prevention. The event store does not need a plain network address to count an interaction.
We receive data directly from you, from a business owner or authorised representative, from someone submitting a correction or report, and from the infrastructure that safely delivers the service. Do not upload passwords, one-time codes, full payment-card details, medical records or identity documents unless a claim workflow specifically asks for relevant evidence.
3. Why we use information
- Provide accounts, directory search, listings, enquiries and owner workspaces.
- Route an enquiry to the owner of the business the sender selected.
- Review listing applications, ownership claims, reports and corrections.
- Operate explicit opt-in contact circles and enforce their published rules.
- Secure sessions, limit abuse, investigate incidents and keep accountable records.
- Respond to personal-data requests and meet applicable legal obligations.
- Measure contact-channel use in aggregate so owners can understand genuine interest.
Depending on the activity and applicable law, processing is based on steps requested by you or performance of a service, consent, compliance with law, or legitimate interests such as security, moderation and improving directory reliability. Where processing relies on consent, you may withdraw it for future use without affecting earlier lawful processing.
4. What becomes public
Published business profiles, approved reviews and aggregate ratings are public. A profile may include business contact channels and a public address or service area that an applicant supplied for publication. Do not submit a home address or personal number unless you are authorised and intend it to be public.
Password material, session tokens, enquiry sender details, report contact details, claim evidence, room applications and member contact information are not public profile fields. Contact-circle pages expose purpose, rules, capacity and aggregate membership—not a downloadable phone list or private address book.
6. How long information is kept
Active accounts, published listings, membership relationships and unresolved workflow records remain while needed to provide the service. Sessions expire after no more than 30 days. Rate-limit buckets expire shortly after their configured window and are removed by daily maintenance.
- Raw contact-channel event records are deleted after 180 days.
- Private claim files are deleted 180 days after an approval or rejection; the decision record remains for ownership accountability.
- Audit events and completed or rejected application, suggestion, report, review and personal-data-request records are deleted after 400 days.
A longer period may apply where a record is still contested or preservation is required by law. A valid deletion request is assessed against account operation, safety, disputes and legal obligations rather than silently treated as an immediate purge.
7. How information is protected
Controls include encrypted transport, secure HTTP-only session cookies, hashed session tokens, salted password derivation, origin and request-intent checks for mutations, rate limiting, role checks, bounded validation, private object storage for evidence and server-side audit records. Access is limited by role and purpose.
No online service can promise absolute security. Use a unique password, protect your device, verify who you are speaking with before sharing sensitive information, and report suspected account misuse promptly.
8. International processing
Infrastructure providers may process data outside Nigeria. The operator must evaluate those locations and use appropriate contractual, organisational and technical safeguards under applicable Nigerian data-protection law, including the Nigeria Data Protection Act 2023, before public launch.
9. Your choices and rights
Depending on your circumstances and applicable law, you may ask for access, a portable copy, correction or deletion; object to or restrict certain processing; withdraw consent; or raise a concern with the relevant data-protection authority. We may need to verify identity and may retain limited records where law or a legitimate safety need requires it.
Open the personal-data request form . Signing in ties the request to the account without asking you to send sensitive identity data over an unverified channel.
People who cannot access an account may email smbprivacy@cea.ng.
10. Children
GainHub NG is intended for adults and authorised business representatives, not for children. Do not create an account or submit personal information if you are under 18. If the operator learns that a child's data was submitted improperly, it will be assessed and removed where required.
11. Changes and contact
Material changes will be reflected by updating the date above and, where appropriate, providing an additional notice. Previous wording should be retained in deployment history for accountability.
For a safety or listing concern, use the private report form. For personal-data matters, use the route in section 9 or the configured privacy address shown above.