Trust

The commitments behind the platforms we build and operate.

Public institutions place real assets in the systems we build. The terms on which we hold those assets, the legal basis on which we process them, and the operational standards we maintain are set out below.

01
PRIVACY
Privacy policy

How we handle personal data.

This policy covers personal data processed through stridedigital.ai. Data processed through the platforms we operate for state partners is governed separately, by the engagement agreement with each state.

What we collect on this site

  • Email correspondence. When you write to partners@stridedigital.ai, press@stridedigital.ai, or careers@stridedigital.ai, we receive your email address, name, and the contents of your message.
  • Server logs. Standard web-server access logs, including IP address, browser identifier, page requested, and timestamp. Retained for ninety days for operational and security purposes.
  • No tracking. This site does not deploy advertising trackers, behavioural cookies, or third-party analytics that profile individual visitors.

Why we process it

Correspondence is processed to reply to your message and to maintain a record of the engagement. Server logs are processed to operate the site, investigate security incidents, and comply with our legal obligations.

Who we share it with

We do not sell personal data. We do not share correspondence with third parties except where required by law or where you have explicitly asked us to introduce you to a named partner.

Your rights

  • Right to access. You may request a copy of the personal data we hold about you.
  • Right to correction. You may ask us to correct inaccurate personal data.
  • Right to erasure. You may ask us to delete personal data we hold, subject to our legal retention obligations.
  • Right to lodge a complaint. You may complain to the Nigeria Data Protection Commission about how we have processed your personal data.

Requests may be sent to privacy@stridedigital.ai. We respond within thirty days.

Draft for counsel review. This page sets out the operational posture. The final published version should be reviewed by qualified data-protection counsel before going live, particularly the rights and retention provisions.
Last updated. To be set on publication.
02
TERMS
Terms of use

The terms on which we publish this site.

These terms govern your use of stridedigital.ai. Engagement agreements with state partners are governed by separate contracts.

Purpose of this site

This site is informational. It describes the platforms StrideDigital builds and operates, the services we offer, and the institutions we engage with. It does not constitute an offer, a representation of capacity, or a binding commitment of any kind. Engagement begins with a written agreement.

Content ownership

The text, design, software, and brand assets on this site are owned by StrideDigital Technologies Limited or its licensors. The mark, wordmark, and platform names are trademarks of StrideDigital. You may not reproduce or redistribute substantial portions of the site without written permission.

No warranties

Information on this site is provided on an as-is basis. Operational claims about live platforms, partner engagements, and accreditations are accurate as of the date of publication. We make no warranty that the information remains current at the time you read it.

Limitation of liability

To the extent permitted by Nigerian law, StrideDigital is not liable for any loss arising from reliance on information published on this site. This limitation does not affect liabilities that cannot be excluded under applicable law.

Governing law

These terms are governed by the laws of the Federal Republic of Nigeria. The courts of Lagos State have exclusive jurisdiction over any dispute arising from them.

Draft for counsel review. The limitation of liability and governing law provisions should be reviewed by qualified counsel before publication. Specific liability caps and indemnity terms have been omitted pending review.
Last updated. To be set on publication.
03
DATA PROTECTION
Data protection posture

NDPR and NDPA compliance.

StrideDigital operates in compliance with the Nigeria Data Protection Regulation 2019 and aligned with the Nigeria Data Protection Act 2023. The commitments below apply to every platform we build and operate.

Sovereign data, by design

Subscriber, clinical, and operational data collected under a state engagement is state-owned. The state is the data controller. StrideDigital operates as the data processor under the engagement agreement.

Data residency

  • Hosted in-country. All personal data is processed and stored within Nigeria, on infrastructure located in Nigerian data centres.
  • State-scoped isolation. Each state engagement operates on logically isolated infrastructure with separate encryption keys.
  • No cross-border transfer. Personal data is not transferred outside Nigeria except where the state partner has issued a written instruction and the transfer satisfies NDPA cross-border conditions.

Legal basis for processing

The lawful basis for processing personal data under a state engagement is the public-interest basis available to public institutions, supplemented by explicit consent where the platform interacts directly with citizens.

Rights of data subjects

Citizens and patients whose data is processed through our platforms have the full set of rights provided under the NDPA: access, correction, erasure, restriction, portability, and complaint. Requests are handled by the state institution that owns the service. We support the institution in fulfilling them.

Data Protection Officer

StrideDigital has appointed a Data Protection Officer. Enquiries on data protection matters may be sent to dpo@stridedigital.ai.

Breach notification

Personal data breaches are notified to the state partner within 72 hours of detection. Where the breach meets the threshold for notification under the NDPA, the state partner and StrideDigital coordinate the report to the Nigeria Data Protection Commission.

Operational document. The detailed Data Processing Agreement that governs each state engagement is available to partners under NDA on request to dpo@stridedigital.ai.
Last updated. To be set on publication.
04
SECURITY
Security posture

How we secure the platforms we operate.

Security is treated as a primary design specification, not a feature added afterwards. The posture below applies to every platform; specific commitments on each engagement are set out in the relevant security schedule.

Encryption

  • In transit. All connections are encrypted using current TLS standards. We disable legacy protocols.
  • At rest. All personal and operational data is encrypted at rest using AES-256 or equivalent.
  • State-scoped keys. Encryption keys are scoped to the state engagement and managed in a hardware-backed key management service.

Access control

  • Least privilege. Access is granted on a need-to-know basis and reviewed quarterly.
  • Multi-factor authentication. Required for all administrative and operational access.
  • Role-based access. Application access is scoped by role within the state institution.

Audit and accountability

  • Append-only audit log. Every access to personal data, every administrative action, and every configuration change is logged.
  • Audit retention. Logs are retained for seven years, in line with public-sector record-keeping expectations.
  • State partner access. The state institution has direct read access to its own audit log.

Operational security

  • Background checks. All operational staff with production access pass standard background checks before access is granted.
  • Patch management. Production systems are patched on a defined schedule, with emergency patching for critical vulnerabilities.
  • Independent review. Each platform is subject to independent security review before going live and at defined intervals afterwards.

Incident response

StrideDigital maintains a documented incident response procedure. In the event of a security incident affecting personal data, the state partner is notified within 24 hours of detection and a full report is delivered within 14 days.

Responsible disclosure

Security researchers who identify a vulnerability are invited to report it confidentially to security@stridedigital.ai. We acknowledge reports within 48 hours and work in good faith toward remediation.

Last updated. To be set on publication.