Sentient Innovation Lab builds intelligent systems for organisations that handle sensitive information. We hold ourselves to the same standard we design into our products: collect only what is needed, keep it secure, keep people in charge of decisions, and be clear about what we do.
1.Introduction and scope
Sentient Innovation Lab (“Sentient”, “we”, “us”) is a technology and software innovation company based at 18 Godab, Life Camp, Abuja, Nigeria. We design, develop, license and deploy software, artificial intelligence systems and digital platforms for private individuals, businesses, institutions, government agencies and public-sector organisations.
This policy explains how we collect, use, disclose and protect personal data in connection with:
- this website and our communications;
- enquiries, demonstrations, partnerships and business relationships;
- our products and services — including licensed software, hosted services (software-as-a-service) and systems deployed within a client's own infrastructure — such as the Compliance Intelligence Platform (CIP), the Compliance Intelligence Model (CIM) and the Intelligent Case Tracker.
We process personal data in accordance with the Nigeria Data Protection Act 2023, its implementing regulations and directives, and any other data protection law that applies to a particular processing activity.
2.Our role: controller and processor
As a data controller.We decide how and why personal data is used for this website, our enquiries and correspondence, our business relationships, account administration for hosted services, and our own security and record-keeping. This policy governs that processing.
As a data processor.When a client uses our products to process personal data about its own staff, customers, citizens or other people, the client is ordinarily the data controller and we act as its processor. In that case we process the data only on the client's documented instructions, under a written agreement that sets out the subject matter, duration, nature and purpose of the processing, the security measures that apply, and the client's audit rights. Individuals whose data is held in a client's system should contact that client in the first instance; we will assist the client in responding.
Deployments within client infrastructure.Several of our products are built and deployed inside the client's own environment. In those deployments the data remains on the client's machines and under the client's control. Our personnel access such environments only where the client authorises it — for example during approved maintenance — and only to the extent necessary.
3.Personal data we collect
- Enquiry and contact dataname, organisation, role, email address, telephone number, organisation type, areas of interest and the content of your messages.
- Business relationship datacontact details of client, partner and supplier representatives, contract and billing information, meeting records and correspondence.
- Account and access data(hosted services) — user names, work email addresses, roles and permissions, authentication data (stored only in protected, hashed form) and records of access.
- Support and maintenance datainformation shared with us to resolve an issue or maintain a system, handled on a need-to-know basis.
- Technical and security dataIP address, browser and device type, pages requested, timestamps and security events recorded by our hosting providers and systems.
We do not ask for sensitive personal data through this website. Please do not include sensitive personal data, privileged material or confidential information in an enquiry until an appropriate agreement is in place.
4.How we use personal data, and our lawful bases
- Responding to enquiries and arranging demonstrationsto take steps at your request before entering into a contract, and our legitimate interest in answering people who contact us.
- Delivering, supporting and improving our products and servicesperformance of a contract, and our legitimate interest in operating and improving our services.
- Managing business relationshipscontract and legitimate interests.
- Security, fraud prevention and system integritylegitimate interests and, where applicable, legal obligation.
- Legal, regulatory and record-keeping obligationslegal obligation.
- Optional communicationsabout our technology — consent, which you may withdraw at any time.
We do not sell personal data, and we do not use personal data for purposes that are incompatible with those for which it was collected.
5.Artificial intelligence and automated processing
Our intelligent systems are designed to support human judgement, not to replace it. In particular:
- our systems analyse information against criteria defined by the client and propose structured findings; they do not make decisions with legal or similarly significant effects about individuals without meaningful human review;
- findings are designed to be traceable to the evidence and reasons behind them, so they can be checked and challenged;
- client data is used to provide the contracted service. It is not used to train or improve models for other clients, or for our own purposes, unless the client has expressly authorised this in writing;
- where a system processes documents, we favour processing within the client's environment and without sending content to external services.
7.International transfers
Where personal data is transferred outside Nigeria — for example because a service provider stores data abroad — we transfer it only where the applicable legal requirements are met, such as an adequate level of protection in the receiving country, appropriate contractual safeguards, or another lawful basis for transfer. Clients whose deployments run within their own infrastructure control where their data resides.
8.Security
We apply technical and organisational measures appropriate to the risk, which may include:
- encryption of data in transit, and protected storage of credentials;
- role-based access on a need-to-know basis, multi-factor authentication and session controls;
- separation of duties, so that changes to production systems require independent approval;
- audit trails of significant actions, designed so that alteration can be detected;
- secure development practices, testing and regular review;
- an incident-response process, including notification of personal data breaches to the supervisory authority and affected individuals where the law requires it.
9.Retention
We keep personal data only for as long as necessary for the purposes described, including to meet legal, accounting and reporting requirements. As a guide:
- enquiry correspondence — up to 24 months after our last contact, unless it becomes part of a business relationship;
- business relationship and contract records — for the duration of the relationship and the period required by law afterwards;
- technical server logs — generally no longer than 90 days, unless needed to investigate an incident;
- data processed for clients — as instructed by the client and set out in the applicable agreement, after which it is returned or deleted.
10.Your rights
Subject to applicable law, you have the right to:
- be informed about, and obtain access to, personal data we hold about you;
- have inaccurate or incomplete data rectified;
- have data erased, or its processing restricted, in the circumstances the law provides;
- object to processing based on our legitimate interests, and to direct marketing at any time;
- receive your data in a structured, commonly used and machine-readable format;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects;
- withdraw consent at any time, without affecting processing carried out before withdrawal;
- lodge a complaint with the data protection supervisory authority in Nigeria.
To exercise a right, contact us using the details in the Contact section below. We may need to verify your identity. We respond within the period the law requires. If your data is held in a system we operate for a client, we will refer your request to that client and assist it in responding.
12.Children
Our website and services are intended for organisations and adults. We do not knowingly collect personal data from children through this website. If you believe a child has provided us with personal data, please contact us and we will delete it.
13.Changes to this policy
We review this policy periodically and may update it to reflect changes in our services, technology or the law. The effective date above shows when it last changed. Material changes will be highlighted on this website.
14.Contact
Questions, requests and complaints about this policy or our handling of personal data may be sent to us using any of the details below.
- Telephone
- +234 807 325 2237
- Post
- Sentient Innovation Lab, 18 Godab, Life Camp, Abuja, Nigeria
- Online
- Contact page
