Legal · Privacy policy

What we collect. Why. And for how long.

What we collect, why we are allowed to, how long each kind is kept, who else sees it, and what you can require of us.

Revised — the date on this page is the one that counts. If the text changes materially, it says so here and the date moves.

Privacy policy register
in force
  1. document Privacy policy under the Nigeria Data Protection Act 2023, s.27
  2. controller Ratelsoft Nigeria Limited, RC 1094064, Port Harcourt
  3. revised 1 September 2026
  4. clauses 11, numbered so they can be cited
  5. trackers none — the one cookie is the session cookie
  6. we answer in thirty days, free
  7. write to info@ratelsoft.com

Your exams, results and pupil records never reach us. They stay on your own server — clause 2.3.

The document's own register: who answers for it, what it covers, when it last changed.

Answers in a hurry

The questions people arrive with.

Most people open a privacy policy to check one thing. These are the four we are asked most, answered in the policy's own words, each pointing at the clause that governs.

  1. Do you sell my information?

    No. Five companies see parts of it because they do a job for us, and we name all five. Nobody buys it, and nothing about you is used for anyone's advertising.

    Clause 04 · Who else sees it
  2. How long do you keep it?

    It depends what it is, and the table says so for each kind. A photograph of a bank transfer has the shortest life of anything we hold; the accounting record has the longest, because tax law says so.

    Clause 06 · How long we keep it
  3. Can I have my account deleted?

    Yes. Write to us and we do it, at no charge, within the time this page commits to. What was bought stays in the accounting record with the personal details reduced to what that record needs.

    Clause 07 · What you can require of us
  4. Do you see our exams or pupil records?

    No. Exams, results and student records stay on your own server. Pupil records are the school's; we process them only on the school's instruction.

    Clauses 2.3 and 10

These are summaries. The clause each one points to is the text that governs. Read all 11 clauses ↓

Contents

This is the policy the Nigeria Data Protection Act 2023 requires us to give you, and it covers ratelsoft.com together with the Ratelsoft desktop and mobile applications. It is written to be read, not to be survived: a bursar should be able to get through it without a lawyer, and everything in it is checkable against the law it cites.

Revised 11 clauses Controller Ratelsoft Nigeria Limited

Who is responsible Clause 01

Ratelsoft Nigeria Limited (RC 1094064), No. 4 Crush Close, off Ada-George Road, Port Harcourt, Rivers State, Nigeria, is the data controller — the company that decides what is collected about you and what happens to it.

Write to info@ratelsoft.com about anything on this page. It reaches the person responsible for data protection here.

What we collect, and why Clause 02

One subsection for each moment we collect something. Each says what is taken, what it is for, and which lawful basis in section 25(1) of the Act allows it — because a policy that lists all six bases and leaves you to guess has told you nothing.

2.1 When you create an account

Your name, email address, phone number, and the state and local government area you give us. If you sign in with a code from before 2026 we also hold the account number the old system gave you, so that your purchases still find you.

What for. To sell you a licence, tie an activation code to you, and reach you when something goes wrong with it. Lawful basis. Performance of a contract — NDPA s.25(1)(b)(i).

2.2 When you set a password or turn on two-factor sign-in

A one-way hash of your password — never the password — and, if you turn it on, an encrypted second-factor secret and the hashes of your recovery codes.

What for. To let you back in, and to stop anybody else getting in. Lawful basis. Performance of a contract, and our legitimate interest in keeping accounts secure — NDPA s.25(1)(b)(i) and (v).

2.3 When you activate software

A device identifier, the device name and operating system, the product and version being activated, and the device clock reading. The clock reading is compared with ours and discarded; it is not stored.

What for. To bind a licence to the machines you are entitled to run it on, and to notice a code being used on more devices than it covers. Lawful basis. Performance of a contract, and our legitimate interest in preventing licence abuse — NDPA s.25(1)(b)(i) and (v).

We do not collect the contents of your exams, your results or your student records. Those stay on your own server and never reach us.

2.4 When you sign in, or try to

The address that was tried, whether it worked, the IP address, the browser, and the time. This is recorded for failed attempts too, including attempts on addresses that have no account here.

What for. To show you your own recent sign-ins, and to recognise somebody working through a list of passwords. Lawful basis. Our legitimate interest in the security of accounts — NDPA s.25(1)(b)(v).

2.5 When you pay

What was bought, when, for how much, the reference the payment processor returns, and the IP address the order was placed from. For a bank transfer we also record the name on the transfer and the bank reference you give us, because that is how an unmatched credit is matched to your order.

What for. To take the payment, issue the codes, raise the invoice, and keep the accounting record the law requires of us. Lawful basis. Performance of a contract, and compliance with a legal obligation — NDPA s.25(1)(b)(i) and (ii).

Card details never reach us. They are entered on the payment processor's own page and we are told only whether the payment succeeded.

2.6 When you send us a payment receipt on WhatsApp

Your WhatsApp phone number, the profile name WhatsApp shows us, what you typed, and the photograph of the transfer if you send one. We also keep the message exactly as Meta delivered it, encrypted, for long enough to fix a fault in reading it.

What for. To match a bank credit to your order without telephoning you about it. Lawful basis. Performance of a contract — NDPA s.25(1)(b)(i).

A photograph of a bank transfer is the most sensitive thing we hold, and it is the thing we hold for the shortest time. See clause 06.

2.7 When we send you email

Whether the message was delivered, bounced or was marked as spam, and the words the receiving mail server used. If a mailbox is closed we stop sending to it.

What for. So that reminders and activation codes go to an address that exists, and so that we stop sending to one that does not. Lawful basis. Our legitimate interest in mail that arrives — NDPA s.25(1)(b)(v).

A dead mailbox never costs you your account. You can still sign in, see your codes and release a device with a suppressed address.

2.8 When you subscribe to the newsletter

Your email address, the name you gave, which of the two lists you chose, and the IP address you signed up from.

What for. To send what you asked for, and to prove later that somebody asked for it. Lawful basis. Your consent — NDPA s.25(1)(a). You can withdraw it from the link in any newsletter, and that link needs no password.

2.9 When you read the blog

Which article you arrived on, which site sent you, and a one-way fingerprint of your session. If you already have an account and are signed in, that is recorded against your account.

What for. To learn which articles are worth writing more of. Lawful basis. Our legitimate interest in knowing what our own writing achieves — NDPA s.25(1)(b)(v).

This is not advertising and it is not shared. Nothing about you is sent to another company for it, and no advertising tracker runs on this site.

2.10 When you write to us

The message and the address it came from. The website's contact form stores nothing — it sends an email and forgets.

What for. To answer you, and to notice a fault that several people are reporting. Lawful basis. Our legitimate interest in answering our own post — NDPA s.25(1)(b)(v).

2.11 When you browse this site

The web server's ordinary request log: address, page, time, browser. One cookie is set, and it is the session cookie the site needs to keep a form submission safe from forgery.

What for. To serve the page and to keep the form honest. Lawful basis. Our legitimate interest in a working website — NDPA s.25(1)(b)(v).

The lawful bases, in one place Clause 03

Section 25(1) of the Act lists six grounds on which personal data may lawfully be processed. We rely on four of them, and clause 02 says which one applies where.

  • Performance of a contract — s.25(1)(b)(i). Selling you a licence, issuing the codes, activating your devices, taking the payment.
  • A legal obligation — s.25(1)(b)(ii). The accounting and tax records we are required to keep, and nothing beyond them.
  • Our legitimate interest — s.25(1)(b)(v). Stopping licence abuse, keeping accounts secure, making sure our email arrives, and knowing which of our own articles are worth writing. Section 25(2) says an interest is not legitimate if it overrides your rights, is incompatible with another basis, or is something you would not reasonably expect. You can object to any of it — clause 07.
  • Your consent — s.25(1)(a). The newsletter, and only the newsletter. You can take it back at any time and it is as easy to withdraw as it was to give.

We do not rely on vital interests or on a public-interest task, and we do not use consent as a cover for something the other three bases already require.

Who else sees it Clause 04

These are all of them, named rather than described as "our providers". Each does one job for us and may use your data only for that job.

  • HostGator (United States) — The server this site and your account run on. Everything stored here, because it is stored there.
  • Mailgun (United States and the European Union) — Delivers every email we send — verification links, password resets, activation codes, renewal reminders and the newsletter. Your email address, your name, and the contents of the message. It tells us back whether the message arrived.
  • Paystack (Nigeria) — Takes card payments and returns a reference. Your email address and the amount. Your card number is entered on Paystack's own page and never passes through our servers. Card checkout is not switched on at the moment. School orders reach us by bank transfer, and a bank transfer does not go through Paystack.
  • Meta Platforms (United States and Ireland) — Carries WhatsApp messages between you and our published numbers. Your phone number, your WhatsApp profile name, and whatever you send. We are testing the connected WhatsApp inbox on our preview website. Messages sent to the connected number during testing are stored here and may be linked to an order for staff review. A message or receipt does not confirm payment.

We do not sell personal information, we do not share it for anybody else's marketing, and we do not use it to build a profile of you. We disclose it to a public authority only where a law actually requires it of us, and we would tell you unless telling you were itself unlawful.

Data that leaves Nigeria Clause 05

Four of the five are outside Nigeria, so some of your data leaves the country. NDPA s.41 to s.43 allow that where the recipient is bound by rules giving adequate protection or where the transfer is necessary to perform your contract — sending you an email you asked for is the ordinary case. We have not applied to the Commission for any other basis, and we do not transfer your data anywhere else.

How long we keep it Clause 06

Section 24(1)(d) of the Act says personal data may be retained no longer than is necessary. Different things are necessary for different lengths of time, so there is no single number here — there is a row for each kind, saying how long and, just as importantly, when the clock starts.

Your account — name, email, phone, and the licences attached to it — While the account is open
Ends when you ask us to close it. Ask, and we delete the account and the personal details on it.
Activation codes, and the devices a licence is bound to — While the account is open
A device you release is removed at once. The codes go with the account.
Orders, invoices, payments and the bank-transfer details on them — Six years
From the end of the year of assessment the sale falls in. This one survives closing your account, with the personal details reduced to what the record needs. Companies and Allied Matters Act 2020 s.375(2) and the Nigeria Tax Administration Act 2025 s.31(5) both require six years of accounting records, and NDPA s.25(1)(b)(ii) is the basis for keeping them.
A receipt photograph you send us on WhatsApp — 180 days
From the day we resolve the order it was sent about — not from the day you sent it, so a payment that takes months to sort out keeps its evidence throughout. Six months is the period the Commission itself names: GAID 2025 Article 49(3) says storage lapses "not later than six (6) calendar months when the original purpose of the processing has been accomplished". The original purpose of your photograph is matching one payment. After that it is deleted from disk, and what survives is the description of it — size, dimensions, checksum — not the picture.
The WhatsApp message itself — your number, what you typed, what we matched it to — 730 days
From the day we resolve the order. Two years, kept under GAID Article 49(4) for the defence of a legal claim, and defensible only because the photograph is already gone. Two years covers a full academic cycle and the dispute a school actually raises, which is "you never sent our codes".
The unread copy of a WhatsApp message, exactly as Meta delivered it — 14 days
From the moment it arrives. Stored encrypted and read by nothing once the message has been parsed. It is the most sensitive thing here per byte, so it has the shortest life of anything on this page.
Newsletter subscription, and whether a message was delivered — While you are subscribed
Unsubscribing stops the sending immediately. We keep the record that you unsubscribed, because losing it would mean writing to you again.
Sign-in records — when and from where your account was signed into, and failed attempts against it — 540 days
From the attempt. We always keep your most recent successful sign-in, whatever its age, so your security page can still tell you when you were last here. Eighteen months, and it is two numbers rather than a round one: the year our security checks look back over to recognise an address you have used before, plus the six months the Commission names as a default. Deleting sooner would not protect you — it would make our own warnings start telling you that your own office is somewhere you have never signed in from.
The admin audit log — what a member of our staff did to an account, and when — Kept indefinitely
From the action. This one we do not delete, and we would rather say so than publish a period we do not mean. It is the record of what was done to your account and by whom; it includes approvals of money you sent us, which company and tax law require us to keep for six years; and it is what we would answer you with if you asked us what has happened to your data.
Your signed-in session — 7 days
From your last activity. The session itself stops working after a couple of hours; the row is deleted a week later.
The web server's request log — No fixed period yet
— The one thing on this page still without a schedule. It is our hosting provider's log rather than our own application's, and it is the remaining piece of this work.
Which article brought you to the site, and what you read — 180 days for what you read; the single first article for as long as you have an account
From the visit. What you read is a session fingerprint and a referring site rather than a name, and it is deleted after six months. The one thing we keep longer is which article first brought you here, because that is how we know which writing earns its keep — and six months after you arrived we erase the fingerprint on that record too, so what is left is an article and a customer, not a browser.

What this table means if you ask for a copy of your data: we can give you only what we still hold. Ask in March about a receipt photograph you sent last May and it will already have been deleted, and we will tell you that rather than say we never had it. Nothing here is deleted because you asked a question — a request pauses the clock on anything it concerns until we have answered you.

What you can require of us Clause 07

Part VI of the Act gives you these. They are rights, not favours, and the section number is there so you can check us against the text.

Be told what we do with your data — NDPA s.27
This page. If it does not answer your question, ask and we will answer it in writing.
Get confirmation that we hold data about you, and a copy of it — NDPA s.34(1)(a) and (b)
Ask for it in your account, under Settings, and we build it for you: a page you can open and print, and a machine-readable copy beside it. It is ready in a few minutes and we do not charge for it.
Have anything wrong corrected — NDPA s.34(1)(c)
Most of it you can change yourself in your account. For the rest, write to us. Correcting our own typing is never something you pay for.
Have your data erased — NDPA s.34(1)(d) and s.34(2)
Ask for it in your account, under Settings. We ask for your password and your second factor, then wait fourteen days before anything is erased — the account keeps working, so somebody who did not ask for this has time to stop it, and you have time to save any activation codes you still need. The order record survives — see clause 06 — with the personal details reduced to what the accounting record needs.
Have processing restricted while a question is open — NDPA s.34(1)(e)
Tell us what you are disputing and we stop using that data for anything except settling it.
Object to processing — NDPA s.36
Where we rely on our own legitimate interest, you can object and we stop unless we can show a reason that overrides yours. For marketing there is no such reason and we stop, full stop.
Withdraw consent you gave — NDPA s.35
The newsletter is the only thing here that runs on consent. Every issue carries an unsubscribe link, and it works without signing in.
Take your data elsewhere — NDPA s.38
Ask, and we export what you gave us in a common machine-readable format.
Not be judged by a machine alone — NDPA s.37
One decision here is automatic: whether a device may activate under your licence. If it goes against you, write to us and a person will look at it.
Complain to the Commission — NDPA s.46
You can go straight to the Nigeria Data Protection Commission without asking us first. Details are in clause 09.

How to use any of them. Email info@ratelsoft.com and say what you want. We acknowledge within seven days and answer within thirty days. It is free: the Act allows us to pass on the cost of a copy where that cost would be unreasonable, and ours never is, so we do not reserve the right. If we need to be sure it is you, we will ask you something only you could answer — never a fresh copy of your identity documents.

How it is protected Clause 08

  • Traffic to this site, to your account and to our activation endpoints is encrypted in transit.
  • Passwords are stored as one-way hashes. We cannot read yours, which is why a reset link is the only thing we can offer when you forget it.
  • Second-factor secrets and the raw WhatsApp messages we have not yet read are stored encrypted.
  • A receipt photograph is written outside the public web root, on a disk no route can serve from, and it is deleted on the schedule in clause 06.
  • Administrators sign in with two-factor authentication, from an address on our own domain, and every administrative action is recorded against the person who took it.
  • Access to production data is limited to the people who need it, and that is a short list.

If a breach happens that puts your rights at risk, NDPA s.40 requires us to tell the Commission within seventy-two hours and to tell you immediately. We would rather write to you about an incident you never noticed than have you read about it somewhere else.

Complaining to the Commission Clause 09

If you think we have got this wrong, tell us first and we will try to put it right. You do not have to: section 46 of the Act lets you go straight to the Nigeria Data Protection Commission, and nothing on this page takes that away from you.

Nigeria Data Protection Commission — info@ndpc.gov.ng, +234 916 061 5551, 1919 Cadastral Zone C06, Mbora District, opposite Efab City Estate, Life Camp, Abuja. The Commission takes complaints at https://services.ndpc.gov.ng and publishes its guidance at https://ndpc.gov.ng.

Children and pupil records Clause 10

Some of the people who use SmartLearn are candidates under eighteen. NDPA s.31 says a child's account needs a parent or guardian's consent, and we do not currently ask for it or check anybody's age. Where an account is a child's, it should be opened by the parent or guardian who is paying for it, and we will act on that parent's request about it as we would on the account holder's own.

Our school products hold records about pupils, entered by the school. The school is the controller of that data. We process it only on the school's instruction and have no independent use for it — and in SmartExaminer's case we never see it at all, because it does not leave the school's own server.

Changes Clause 11

If this policy changes materially we will say so on this page and date it. The revision date at the top is the one that counts. Where a change affects something you are relying on — a retention period, or who sees your data — we will tell the people it affects rather than leaving it to be discovered.

Revised · Ratelsoft Nigeria Limited, RC 1094064 Product terms →

Anything else

Something this page did not answer?
Ask a person.

Write to us about anything on this page — a copy of what we hold, a correction, a deletion, an objection — and it goes to a person, not a queue.

Ratelsoft Nigeria Limited, RC 1094064 · No. 4 Crush Close, off Ada-George Road, Port Harcourt.