Ozikol Master Privacy Notice & Data Sovereignty Charter
Comprehensive legal transparency detailing how Ozikol isolates, processes, safeguards, and respects institutional data across our 9 operational suites, web portals, executive MIS, mobile apps, and edge desktop clients.
1. Executive Scope & Architectural Context
At Ozikol (""Ozikol"", ""Platform"", ""we"", ""our"", or ""us""), protecting the sovereignty, privacy, and integrity of our client organizations' data is foundational to everything we engineer. This Master Privacy Notice applies to all visitors, subscriber institutions, tenant administrators, staff, members, residents, contractors, and end-users interacting with the Ozikol ecosystem across all delivery channels:
- Ozikol Central Web Portals: Central marketing, marketplace directory, developer API documentation, billing management, and customer support helpdesk.
- Dedicated Organization Workspaces: Dedicated web portals provisioned uniquely for each subscribing enterprise, residential estate, educational institution, corporate association, or religious body.
- Executive Management Information Systems (MIS): Comprehensive administrative web consoles utilized by executive leadership, estate managers, accountants, and security directors.
- Native Cross-Platform Mobile Applications: iOS and Android applications providing member self-service, real-time push notifications, offline digital QR passes, and dues payments.
- Windows Desktop Enterprise Applications: Native WinUI 3 / WPF desktop clients engineered for high-throughput gatehouses, front-desk receptionists, and accounting offices with direct peripheral hardware drivers.
Core Privacy Principle: Ozikol is built on an uncompromising privacy-first philosophy. We do not sell your data, we do not monetize user activity, we do not serve third-party behavioral advertisements, and we never train public artificial intelligence models on your private institutional records.
2. Classification of Roles: Data Controller vs. Data Processor
Under international data protection laws, including the EU General Data Protection Regulation (GDPR Article 4), the UK Data Protection Act 2018 (UK GDPR), the California Consumer Privacy Act (CCPA/CPRA), and the Nigeria Data Protection Act 2023 (NDPA), our legal role depends on the context of the data processed:
- Ozikol as a Data Processor (Service Provider): When client organizations (such as residential estates, clubs, corporate entities, or faith organizations) deploy Ozikol to manage their internal rosters, member dues, gate security, and staff records, the client organization acts as the Data Controller. Ozikol processes this tenant data strictly on behalf of and according to the documented instructions of the client organization.
- Ozikol as a Data Controller: Ozikol acts as a Data Controller solely for direct account management data, including prospective client inquiries, enterprise contract billing, subscription administrator credentials, and central support ticket submissions.
3. Categories of Information Processed by Operational Suite
Ozikol delivers modular cloud functionality organized into nine specialized operational suites. We process only the minimum necessary data required to deliver each suite's capabilities:
3.1 Financial Accounting & Dues Suite
Processes invoice ledgers, assessment dues schedules, utility billing calculations, split-payment distribution instructions, and transaction settlement records. Payment Card Security: All credit/debit card transactions are processed via PCI-DSS Level 1 certified payment gateways. Ozikol never stores raw credit card Primary Account Numbers (PAN) or CVV security codes on its servers.
3.2 Estate, Asset & Facility Management Suite
Processes physical unit registers, tenant occupancy records, commercial lease terms, preventive maintenance logs, asset serial numbers, and utility sub-meter readings (electricity, water, gas).
3.3 Community Engagement & Social Portal
Processes member profile details, opt-in directory listings, community discussion posts, event RSVPs, facility amenity bookings, classified ads, and direct communication threads. Members maintain granular privacy toggles to hide phone numbers and email addresses from general member directories.
3.4 Access Control, Visitor Management & Gate Pass Automation
Processes visitor pre-clearance tokens, digital QR pass generation, visitor names, phone numbers, vehicle license plate numbers captured via Automated Number Plate Recognition (ANPR) cameras, and timestamped entry/exit logs recorded at boom barriers, turnstiles, and pedestrian gates.
3.5 Governance, Secret Elections & Digital Balloting
Processes verified voter roll eligibility, quorum tracking, and digital ballot casting. Irrevocable Ballot Secrecy: Voting choices are cryptographically blinded using homomorphic encryption protocols. Once a vote is submitted and verified against the electoral roll, the ballot is permanently detached from the voter's personal identity, rendering it mathematically impossible for administrators or Ozikol engineers to correlate an individual voter with their candidate choice.
3.6 Procurement & Vendor Marketplace
Processes vendor company profiles, tax identification numbers, compliance accreditations, Request for Proposal (RFP) submissions, formal bids, purchase orders, and contractor service delivery ratings.
3.7 Incident Dispatch, Security Patrols & Emergency SOS Broadcasts
Processes real-time emergency SOS trigger alerts, GPS coordinates transmitted during active distress calls, security guard GPS patrol checkpoint waypoints, incident investigation logs, and emergency muster roll headcounts.
3.8 Events, Ticketing & Banquet Facility Booking
Processes banquet hall and conference room reservations, attendee ticketing tiers, seating allocations, ticket QR scan check-ins, and guest catering dietary preferences.
3.9 Workforce, Security Personnel & Payroll Suite
Processes employee contact details, duty shift rosters, overtime records, performance evaluations, and net payroll calculations. Biometric Data Protection: Where biometric clock-in devices (fingerprint or facial geometry scanners) are integrated, raw biometric images are never uploaded to the cloud. Hardware devices generate irreversible mathematical feature hashes that reside in localized hardware memory, ensuring complete protection of biological markers.
4. Architectural Tenant Fleet Data Isolation (Zero Commingling Guarantee)
Unlike conventional multi-tenant architectures that pool multiple organizations' confidential records into shared, row-level database tables, Ozikol employs an architectural fleet isolation model:
- Dedicated Relational Storage Rings: Each subscribing organization is provisioned with a dedicated relational database ring. Operational tables, financial ledgers, member rosters, and security logs are physically and logically segregated from all other tenants.
- Master vs. Tenant Layer Separation: The central platform master catalog (containing pricing, licensing tiers, and central system routing) is completely isolated from tenant databases. Tenant encryption keys are independently generated and isolated.
- Zero AI Model Training: We guarantee that private tenant operational data, documents, chat messages, and member rosters are never used to train or fine-tune public artificial intelligence models or machine learning algorithms.
5. Multi-Channel Edge Clients, Offline SQLite Cache & Hardware Privacy
Ozikol provides dedicated native applications for mobile devices and Windows desktop environments designed to operate reliably in intermittent connectivity environments:
- Encrypted Offline SQLite Cache: When using the Windows Desktop application or mobile apps in offline mode, local data is stored in an encrypted SQLite database using SQLCipher AES-256 encryption. Local data is protected by the operating system's cryptographic credential storage (Windows DPAPI, Apple Keychain, Android Keystore).
- Cryptographic Delta-Sync: Upon re-establishing network connectivity, local changes synchronize with the cloud instance via a secure delta-sync protocol with cryptographic conflict detection and validation.
- Peripheral Hardware Drivers: The Windows Desktop client interfaces with hardware peripherals, including ESC/POS thermal receipt printers, barcode/QR scanners, turnstiles, and USB biometric readers. Hardware drivers process data strictly in volatile system memory; peripheral print streams and raw scanner inputs are never cached on permanent unencrypted disk storage.
6. Lawful Grounds for Processing
We process personal data only when substantiated by recognized lawful grounds under Article 6 of the GDPR and equivalent international statutes:
- Contractual Performance (Article 6(1)(b)): To provision your dedicated cloud instance, process dues, authenticate authorized users, and deliver operational suite capabilities defined in our Master Subscription Agreement.
- Legal & Regulatory Compliance (Article 6(1)(c)): To retain accounting records, tax invoices, and statutory financial ledgers for mandatory legal retention periods (typically 6 to 7 years depending on jurisdiction).
- Legitimate Interests (Article 6(1)(f)): To maintain system cybersecurity, mitigate DDoS attacks, prevent fraudulent transactions, monitor 99.99% service availability, and safeguard institutional safety at access control checkpoints.
- Explicit Consent (Article 6(1)(a)): When users voluntarily opt-in to receive non-critical platform announcements, community forum notifications, or enable optional mobile location tracking for incident reporting.
7. Sovereign Regional Cloud Hosting & International Transfers
Ozikol partners with premier tier-1 sovereign cloud infrastructure providers (Microsoft Azure and Amazon Web Services) adhering to ISO/IEC 27001, SOC 2 Type II, and PCI-DSS standards. Subscribing organizations select their primary data residency zone during onboarding:
- United Kingdom (UK Sovereign Hub): London / Cardiff data center regions.
- European Union (EU Sovereign Hub): Frankfurt (Germany) and Dublin (Ireland) data center regions.
- North America (US Hub): Northern Virginia / Ohio data center regions.
- West Africa (African Hub): Lagos data center facilities ensuring local compliance with the Nigeria Data Protection Act (NDPA).
When cross-border data transfers are necessary for central engineering support, they are protected by legally binding Standard Contractual Clauses (SCCs) approved by the European Commission and the UK International Data Transfer Addendum (IDTA).
8. Cryptographic Safeguards & Enterprise Security Posture
We maintain an enterprise-grade defense-in-depth cybersecurity posture to protect organizational records against unauthorized access, alteration, disclosure, or destruction:
- Encryption at Rest: All database storage, transaction logs, attachments, and disk volumes are encrypted at rest using FIPS 140-2 validated AES-256 cryptographic cipher suites.
- Encryption in Transit: All communications between web browsers, mobile apps, desktop clients, APIs, and cloud databases are enforced using TLS 1.3 with mandatory HTTP Strict Transport Security (HSTS) and perfect forward secrecy.
- Administrative Authentication Security: Multi-factor authentication (MFA) via FIDO2/WebAuthn hardware security keys or time-based one-time passwords (TOTP) is enforced for all system administrators and privileged staff accounts.
- Role-Based Access Control (RBAC): Granular permission matrices restrict staff access strictly to modules authorized for their operational job responsibilities.
- Immutable Audit Logging: Every administrative data read, export, modification, and credential change is recorded in an immutable, tamper-evident audit log that cannot be altered by tenant administrators or compromised credentials.
9. Sub-processors and Infrastructure Partners
We engage vetted third-party sub-processors strictly to deliver underlying cloud infrastructure, transactional communication channels, and payment gateway connectivity. All sub-processors are bound by strict Data Processing Agreements (DPAs) requiring equivalent or superior security controls:
- Cloud Infrastructure: Microsoft Azure (Cloud compute, relational storage, blob storage) and Amazon Web Services (Cloud infrastructure).
- Transactional Communications: Enterprise SMTP relay pools and carrier-grade SMS routing gateways with mandatory TLS transport.
- Payment Gateways: PCI-DSS Level 1 certified processors (Stripe, Paystack, Flutterwave) handling tokenized credit card and direct bank transfer settlements.
10. Data Retention, Archival & Cryptographic Sanitization
We retain organizational data for the duration of the active subscription agreement. Upon contract termination or formal deletion request:
- 30-Day Transition Grace Period: The organization's dedicated workspace enters a 30-day read-only grace period, allowing authorized administrators to export all database tables, financial records, and documents in standard SQL, JSON, and CSV formats.
- Cryptographic Sanitization: Following the 30-day grace period, all primary database instances, replica nodes, disk volumes, and associated backup snapshots undergo permanent cryptographic shredding in accordance with NIST SP 800-88 Revision 1 and DoD 5220.22-M data sanitization standards.
11. Protection of Minor and Student Privacy
Where Ozikol is deployed by educational institutions, youth organizations, or family residential estates, member records may include information concerning minors (individuals under 16 or 18 years of age depending on jurisdiction). Institutional administrators must verify that appropriate parental, legal guardian, or school authorization has been secured in compliance with the Children's Online Privacy Protection Act (COPPA) and GDPR Article 8 before provisioning minor accounts. Minors are shielded from public directories by default.
12. Your Statutory Privacy Rights & DPO Escalation
Depending on your jurisdiction, you possess clear statutory rights regarding your personal data:
- Right to Access & Portability: Obtain confirmation of processing and request a machine-readable copy (JSON/CSV) of your personal records.
- Right to Rectification: Request correction of inaccurate, outdated, or incomplete personal data.
- Right to Erasure ("Right to be Forgotten"): Request deletion of personal records where legal grounds for continued processing no longer exist.
- Right to Restrict or Object: Restrict processing or object to processing conducted under legitimate interests.
How to Submit a Request: If you are a member, resident, or staff member of an organization powered by Ozikol, please contact your organization administrator first. If you are an account holder or need direct assistance, visit our Privacy Choices Portal or reach our legal desk directly via our Enterprise Helpdesk.
Global Data Protection Officer (DPO):
Ozikol Cloud Global Headquarters
Attn: Legal, Governance & Regulatory Compliance Desk
100 Bishopsgate, London EC2N 4AG, United Kingdom
Support Escalation: Contact Legal Desk
Supervisory Authorities: If you believe your rights have not been respected, you have the right to lodge a complaint with your national data protection supervisory authority (such as the UK Information Commissioner's Office - ICO, or the Nigeria Data Protection Commission - NDPC).