1. About this policy
This Privacy Policy describes how Techforge Developers Limited ("we," "us," or "our"), operating the Lintel platform ("Lintel," the "Service"), collects, uses, discloses, and otherwise processes personal data about you when you use our website, web application, mobile applications, and related services.
Lintel is a software-as-a-service platform that enables real estate agencies and professionals to manage clients, contracts, properties, shortlet bookings, and payments. We act as a data controller in respect of personal data about our direct customers and as a data processor in respect of personal data that our customers (the agencies) upload or process about their own clients.
This policy applies to:
- Visitors to our website at getlintel.org and app.getlintel.org
- Account holders who sign up to use Lintel (agency administrators, managers, accountants, agents, external marketers, and other staff invited to the platform)
- End users of agencies that use Lintel (tenants, buyers, shortlet guests, and prospects whose data is uploaded to the platform by our customers)
- Anyone who contacts us through our support channels, social media, or in person
We are committed to protecting your privacy and complying with applicable data protection laws, including the Nigeria Data Protection Act 2023 ("NDPA") and, where applicable, the EU General Data Protection Regulation 2016/679 ("GDPR") and the UK GDPR.
2. Who we are
The data controller for the purposes of this policy is:
| Field | Details |
|---|---|
| Legal name | Techforge Developers Limited |
| Registration number (RC) | 8371716 |
| Registered office | 27 Carter Street, Ebute Metta, Lagos, Nigeria |
| Trading name | Lintel |
| Website | https://app.getlintel.org / https://getlintel.org |
| Privacy contact email | privacy@getlintel.org |
| General contact email | hello@getlintel.org |
We are registered as a data controller with the Nigeria Data Protection Commission ("NDPC").
Data Protection Officer
We have appointed a Data Protection Officer ("DPO") who oversees compliance with this policy and applicable data protection laws. You can contact the DPO at dpo@getlintel.org.
Our role in your data
When you sign up directly for a Lintel account or visit our website, we act as the data controller of your personal data and determine the purposes and means of processing.
When you use Lintel as an end client of an agency (for example, a tenant signing a contract, or a guest making a shortlet booking), the agency is the data controller of your personal data and we act as the data processor on their behalf. In that case, you should also consult the agency's own privacy notice. If you have questions about how an agency processes your data, please contact them directly; we can also help you identify the relevant agency contact.
3. Definitions
In this policy, we use certain terms with specific meanings:
| Term | Meaning |
|---|---|
| Personal data | Any information relating to an identified or identifiable natural person, such as a name, email address, phone number, or identification number. |
| Processing | Any operation performed on personal data, including collection, storage, use, disclosure, alteration, and deletion. |
| Data controller | The person or entity that determines the purposes and means of processing personal data. |
| Data processor | The person or entity that processes personal data on behalf of a data controller. |
| Data subject | The individual to whom personal data relates. |
| NDPA | The Nigeria Data Protection Act 2023. |
| GDPR | The General Data Protection Regulation (EU) 2016/679 and the UK GDPR. |
| Agency | A real estate firm, property developer, or other organization that uses Lintel to manage its business. |
| End client | An individual whose personal data is processed in Lintel by an agency, such as a tenant, buyer, or guest. |
4. Personal data we collect
We collect personal data in several ways: when you provide it to us directly, when it is generated through your use of our services, and when we receive it from third parties.
4.1 Data you provide directly
When you sign up for an account, use our services, or communicate with us, you provide us with the following categories of personal data:
Identity and contact data
- Full name, salutation, date of birth
- Email address, phone numbers (including WhatsApp)
- Postal and residential addresses
- Job title, role within your organization, and professional credentials
- Profile photograph (optional)
Account credentials
- Username and password (passwords are stored as one-way hashes; we cannot read them)
- Two-factor authentication tokens (where enabled)
- Security questions and answers
Identification documents (where applicable)
- National Identification Number (NIN)
- Bank Verification Number (BVN)
- Driver's licence, international passport, or voter's card details
- Company registration documents (CAC)
Note: We only collect identification documents where necessary to comply with Nigerian KYC requirements or where you choose to upload them as supporting documents for contracts or transactions.
Financial data
- Bank account name and account number (for payments and disbursements)
- Payment card details (handled by our payment processor; we do not store full card numbers)
- Transaction records, including amounts, dates, channels, and references
- Invoice and receipt details
Content you upload
- Contract documents and signed agreements
- Property photographs, descriptions, and titles
- Client records (where you are an agency user uploading data about your clients)
- Notes, messages, and other free-text content you create within Lintel
- Digital signatures (drawn, typed, or uploaded)
Communications data
- Emails, messages, and correspondence you exchange with us
- Customer support tickets and chat logs
- Feedback, survey responses, and testimonials
4.2 Data we collect automatically
When you use our services, we automatically collect certain technical and usage data:
Device and connection data
- IP address and approximate geographic location derived from it
- Browser type and version, operating system, device identifiers
- Screen resolution, timezone, and language preference
- Mobile network information and unique device identifiers (mobile apps)
Usage data
- Pages and features accessed, time spent, click and tap patterns
- Referring URL and exit URL
- Search queries entered within the platform
- Actions taken (contracts created, payments recorded, properties added, etc.)
- Crash reports and error logs
Email engagement data
- Whether emails we send to you were delivered, opened, and which links were clicked
- Bounce notifications, spam complaints, and unsubscribe requests
- Engagement is tracked using transparent pixels and link redirects in marketing and transactional emails
Cookies and similar technologies
See Section 13 for full details about cookies and other tracking technologies we use.
4.3 Data we receive from third parties
We may receive personal data about you from the following third-party sources:
- Authentication providers (such as Google or Apple) when you sign in using a third-party account
- Payment processors (such as Flutterwave) when you make or receive a payment
- Email service providers (such as Resend) regarding the delivery and engagement of emails sent through Lintel
- KYC verification providers when you complete identity checks
- Public registries (such as the Corporate Affairs Commission) where we need to verify company details
- Your employer or the agency you work with, when they invite you to join Lintel
4.4 Sensitive personal data
We generally do not collect sensitive personal data (such as racial or ethnic origin, religious beliefs, health data, or biometric data) about you, unless you voluntarily upload such information as part of contract documents or supporting records. We do not knowingly process this category of data for any analytical or marketing purpose.
If we need to process sensitive personal data for a specific lawful purpose, we will obtain your explicit consent or rely on another lawful basis as required by the NDPA and, where applicable, the GDPR.
5. How we use your personal data
We use personal data for the purposes described below. For each purpose, we identify the categories of data involved and the lawful basis for processing in Section 6.
5.1 To provide and operate the Lintel service
- Creating, authenticating, and managing your account
- Enabling you to create, edit, sign, and store contracts and other documents
- Enabling you to record bookings, payments, and property records
- Generating PDFs, receipts, and other documents on your behalf
- Synchronizing data across web and mobile applications
- Providing customer support and responding to enquiries
5.2 To process payments
- Routing card payments and bank transfers through our payment processor
- Recording payment history, issuing receipts, and reconciling transactions
- Charging subscription fees and managing renewals
- Detecting and preventing fraudulent transactions
5.3 To communicate with you
- Sending service-related notifications (e.g. invitation emails, booking confirmations, payment receipts, signing requests)
- Sending billing-related communications (e.g. invoices, renewal reminders, payment failures)
- Responding to your support requests and feedback
- Sending product updates, security alerts, and other administrative messages
- With your consent, sending marketing emails about new features, tips, and offers (you can unsubscribe at any time)
5.4 To improve and personalize Lintel
- Analyzing how users interact with the platform to identify usability issues
- Measuring the performance of features and the success of email campaigns
- Conducting research, surveys, and A/B testing
- Personalizing your experience based on your role and preferences
- Developing new features and improving existing ones
5.5 To keep Lintel secure
- Authenticating users, detecting suspicious login activity, and preventing unauthorized access
- Logging actions for audit and forensic purposes
- Detecting and responding to abuse, fraud, malware, and other security threats
- Backing up data to enable disaster recovery
5.6 To comply with legal obligations
- Meeting our tax, accounting, and corporate reporting obligations
- Responding to lawful requests from regulators, courts, and law enforcement
- Complying with KYC, anti-money laundering, and counter-terrorism financing requirements
- Enforcing our terms of service and protecting our legal rights
5.7 For business operations and transactions
- Operating, evaluating, and improving our business
- Identifying usage trends and demographic information on an aggregated basis
- Facilitating mergers, acquisitions, financing, reorganizations, or sales of assets, where applicable
6. Legal bases for processing
Under the NDPA and the GDPR, we must have a lawful basis for processing your personal data. We rely on the following bases:
| Legal basis | When we rely on it |
|---|---|
| Performance of a contract | When we need to process your data to provide our services to you under our Terms of Service, including creating your account, processing payments, and providing customer support. |
| Legitimate interests | When we process your data for purposes that are in our or a third party's legitimate interests, balanced against your rights. Examples include improving Lintel, detecting fraud, securing the platform, and conducting non-intrusive analytics. |
| Consent | When you have given specific, informed, and freely given consent for a particular purpose, such as receiving marketing emails or allowing non-essential cookies. You can withdraw consent at any time. |
| Compliance with legal obligation | When we are required by law to process your data, such as for tax reporting, KYC compliance, or responding to lawful requests from authorities. |
| Vital interests | In rare cases where processing is necessary to protect someone's life or physical integrity. |
| Public interest | Where processing is necessary for the performance of a task carried out in the public interest, where applicable. |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights and freedoms. You have the right to object to processing on this basis (see Section 11).
7. Sharing your personal data
We do not sell your personal data. We share personal data only with the categories of recipients described below and only where necessary for the purposes set out in this policy.
7.1 Within the agency you belong to
If you are a staff member of an agency, your personal data is visible to other staff at that agency in accordance with their respective roles and permissions. Different roles see different subsets of data; for example, an agent typically sees only their own clients, while a manager sees all clients in the agency. Row-level security enforces these boundaries at the database level.
If you are an end client of an agency (e.g. a tenant or guest), your personal data is visible to authorized staff of that agency.
7.2 Service providers (data processors)
We share personal data with carefully selected third-party service providers who process personal data on our behalf and under our instructions. These include:
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, file storage, and edge computing | United States / EU |
| Cloudflare | Website hosting, content delivery, and DDoS protection | Global |
| Resend | Transactional and marketing email delivery | United States |
| Flutterwave | Payment processing (cards, bank transfers, wallets) | Nigeria |
| Analytics, authentication, and developer services | Global | |
| Apple | App Store distribution and authentication | United States / Ireland |
| Sentry (or similar) | Error monitoring and crash reporting | United States |
We have data processing agreements in place with each of these providers, requiring them to protect your data and to process it only in accordance with our instructions.
7.3 Other agencies
We do not share personal data between agencies. Each agency's workspace is isolated from every other agency's. The only exception is administrative access by our support staff under controlled conditions and only when required to provide support.
7.4 Professional advisers
We may share your data with our lawyers, accountants, auditors, insurers, and other professional advisers where this is necessary to obtain professional advice or to manage business risks.
7.5 Regulators, law enforcement, and authorities
We may disclose your personal data to regulators, law enforcement agencies, and other public authorities where required by law, regulation, court order, or in response to a lawful request. We carefully review every request and only disclose what is strictly required.
7.6 Business transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of company assets, your personal data may be transferred as part of that transaction. We will notify you in advance and you will have the option to object where required by law.
7.7 With your consent
We may share your personal data with other third parties where you have given us specific consent to do so.
8. International data transfers
Lintel is operated from Nigeria, but some of our service providers (such as Supabase, Cloudflare, Resend, and Google) host data and operate infrastructure in other countries, including the United States, the European Union, and the United Kingdom.
When we transfer personal data from Nigeria, the EU, or the UK to a country that does not provide an equivalent level of data protection, we put appropriate safeguards in place. These safeguards may include:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- UK International Data Transfer Agreement (IDTA) where applicable
- Adequacy decisions by the European Commission or the UK government
- Equivalent contractual arrangements with our service providers requiring them to protect your data to standards no less stringent than those required by the NDPA
- Encryption of data in transit and at rest
For transfers from Nigeria, we comply with the NDPA's requirements on cross-border data transfer, including obtaining your consent or relying on another lawful basis where required.
You can request a copy of our cross-border transfer safeguards by contacting privacy@getlintel.org.
9. Data retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying legal, accounting, or reporting requirements.
Our retention periods vary depending on the type of data and the purpose of processing:
| Category | Retention period |
|---|---|
| Account data (active accounts) | For the duration of your account, plus 6 years after closure to meet contract law and tax requirements |
| Contract documents and signing audit trails | 10 years from contract date (Nigerian statute of limitations for written contracts) |
| Payment and transaction records | 6 years from transaction date (tax records) |
| Identification documents and KYC data | 5 years after the end of the business relationship (anti-money laundering requirements) |
| Marketing data | Until you unsubscribe or withdraw consent, plus 30 days for processing the request |
| Support and correspondence records | 3 years from the last interaction |
| Email engagement data | 24 months from the email send date |
| Server access logs and security data | 12 months, except where extended for security investigations |
| Backups | Rolling 90-day window; data deleted from production is also purged from backups within this period |
| Activity/audit logs | 7 years (for forensic and dispute purposes) |
When personal data is no longer needed, we securely delete or anonymize it. Anonymized data (which cannot be linked back to you) may be retained indefinitely for statistical and analytical purposes.
If your account is inactive for more than 24 months, we may notify you and subsequently delete or anonymize your data, subject to any legal retention requirements.
10. Security measures
We take the security of your personal data seriously and have implemented appropriate technical and organizational measures to protect it against unauthorized access, alteration, disclosure, or destruction. These measures include:
Technical safeguards
- Encryption of personal data in transit using TLS 1.2 or higher
- Encryption of personal data at rest using AES-256 or equivalent
- Strong password hashing using bcrypt or equivalent algorithms
- Multi-factor authentication available on all accounts
- Row-level security policies enforced at the database level for multi-tenant isolation
- Regular security patching and vulnerability scanning
- Web application firewall and DDoS protection via Cloudflare
- Continuous monitoring of system logs for anomalous activity
Organizational safeguards
- Role-based access control: staff only access personal data necessary for their role
- Confidentiality undertakings signed by all staff and contractors
- Mandatory data protection training for all staff
- Documented incident response and breach notification procedures
- Regular security and privacy reviews
- Vendor due diligence and data processing agreements with all service providers
Breach notification
In the unlikely event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Nigeria Data Protection Commission and, where applicable, the relevant EU or UK supervisory authority, within 72 hours of becoming aware of the breach. We will also notify you directly without undue delay where the breach is likely to result in a high risk to your rights and freedoms.
Your role in security
No system is 100% secure. You also play a role in keeping your data safe:
- Use a strong, unique password for your Lintel account
- Enable multi-factor authentication
- Do not share your login credentials with anyone
- Log out of shared or public devices
- Report suspicious activity to us immediately at security@getlintel.org
11. Your rights
Under the NDPA and, where applicable, the GDPR and UK GDPR, you have a number of rights in relation to your personal data. These include:
11.1 Right to be informed
You have the right to be informed about how we collect and use your personal data. This privacy policy is the primary way we provide this information; we may also provide more specific notices at the point of data collection.
11.2 Right of access
You have the right to request a copy of the personal data we hold about you, together with information about how we use it. We will provide this information free of charge in most cases, within one month of your request.
11.3 Right to rectification
You have the right to ask us to correct any inaccurate personal data we hold about you, or to complete any incomplete personal data. You can update many fields yourself by signing in to your Lintel account.
11.4 Right to erasure (right to be forgotten)
You have the right to ask us to delete personal data we hold about you in certain circumstances, including where the data is no longer necessary for the purposes it was collected for or where you have withdrawn consent. Note: this right is not absolute, and we may retain data where we are legally required or permitted to do so.
11.5 Right to restrict processing
You have the right to ask us to restrict the processing of your personal data in certain circumstances, including while we verify a rectification request or assess an objection.
11.6 Right to data portability
You have the right to receive personal data you provided to us in a structured, commonly used, and machine-readable format, and to ask us to transmit it to another data controller where technically feasible.
11.7 Right to object
You have the right to object to the processing of your personal data:
- At any time, where we process your data for direct marketing purposes
- On grounds relating to your particular situation, where we process your data on the basis of legitimate interests or public interest
11.8 Right to withdraw consent
Where we rely on your consent to process your data, you have the right to withdraw that consent at any time. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
11.9 Rights related to automated decision-making
You have the right not to be subject to a decision based solely on automated processing, including profiling, where it produces legal or similarly significant effects on you. See Section 15 for more details.
11.10 Right to lodge a complaint
You have the right to lodge a complaint with a data protection authority. See Section 18 for details.
12. How to exercise your rights
To exercise any of the rights set out in Section 11, please contact us using the details in Section 17. You can also exercise many of these rights directly through your account settings.
12.1 What we may need from you
To protect your privacy, we may need to verify your identity before responding to a rights request. We may ask you to provide:
- Your full name and contact details
- Confirmation of the account you are asking about
- A description of the right you wish to exercise and any specific data involved
- In some cases, a copy of an identification document to verify your identity
12.2 Response timeframes
We aim to respond to all legitimate rights requests within 30 days. In some cases, particularly for complex requests or where we receive a high volume, we may extend this period by up to a further 60 days. We will let you know if we need to extend the response time and explain why.
12.3 Fees
Exercising your rights is generally free of charge. However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. We may also refuse to act on such requests.
12.4 Requests from end clients of agencies
If you are an end client of an agency (e.g. a tenant or guest) and you would like to exercise rights in respect of personal data held about you by the agency, you should contact the agency directly. We will support agencies in responding to such requests in our capacity as data processor. If you cannot reach the agency, contact us and we will help you identify the relevant contact.
13. Cookies and similar technologies
Cookies are small text files that are placed on your device when you visit a website. We use cookies and similar technologies (such as web beacons, pixels, and local storage) for the following purposes:
13.1 Categories of cookies we use
| Category | Purpose | Examples |
|---|---|---|
| Strictly necessary | Required for the platform to function, including authentication and security | Session cookies, CSRF tokens |
| Functional | Remember your preferences and settings | Language, timezone, theme |
| Analytics | Help us understand how users interact with Lintel | Google Analytics (anonymized) |
| Marketing | Measure the effectiveness of our marketing campaigns | Email open pixels, link tracking |
13.2 Email engagement tracking
We track engagement with emails we send (such as deliveries, opens, and clicks) using transparent pixels and link redirects. This helps us understand which emails are useful and improve our communications. You can prevent open tracking by configuring your email client to block remote images, and you can prevent click tracking by typing URLs directly rather than clicking links in emails.
13.3 Managing cookies
You can manage your cookie preferences at any time through your browser settings. Note that disabling strictly necessary cookies will prevent the Lintel platform from functioning properly.
Most browsers also allow you to refuse to accept cookies and to delete cookies. Methods for doing so vary from browser to browser, and from version to version. You can obtain up-to-date information about blocking and deleting cookies via the support pages of your browser.
13.4 Do Not Track
Some browsers offer a "Do Not Track" feature. Because no industry standard for this signal has been finalized, we do not currently respond to Do Not Track signals.
14. Children's data
Lintel is a business-to-business platform intended for use by real estate professionals. Our services are not directed at children, and we do not knowingly collect personal data from children under the age of 18.
If you become aware that a child has provided us with personal data, please contact us at privacy@getlintel.org and we will take steps to delete that data.
Where personal data about a child appears in a contract or supporting document uploaded by an agency (for example, where a minor is named as a beneficiary or future occupant), we process that data in our role as data processor on behalf of the agency. The agency is responsible for ensuring it has a lawful basis to process such data.
15. Automated decision-making and profiling
We do not currently make decisions based solely on automated processing of your personal data that produce legal or similarly significant effects on you.
We use certain automated tools to support human decision-making, such as:
- Detecting suspicious login activity or potential fraud
- Filtering spam and abusive content
- Recommending features or settings within the platform
Where any automated processing materially affects you, a human will always be involved in the final decision, and you have the right to request human review, express your views, and contest the decision.
16. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes, we will update the "Effective date" at the top of the policy and notify you of material changes by:
- Posting a notice on our website or within the Lintel platform
- Sending you an email to the address associated with your account
- Where required by law, obtaining your consent before the changes take effect
We encourage you to review this policy periodically to stay informed about how we protect your personal data. Your continued use of Lintel after any changes constitutes acceptance of the updated policy.
17. Contact us
If you have any questions, concerns, or requests regarding this Privacy Policy or our processing of your personal data, please contact us using the details below:
| Channel | Details |
|---|---|
| Privacy enquiries | privacy@getlintel.org |
| Data Protection Officer | dpo@getlintel.org |
| Security issues | security@getlintel.org |
| General support | hello@getlintel.org |
| Postal address | Techforge Developers Limited, 27 Carter Street, Ebute Metta, Lagos, Nigeria |
We aim to acknowledge your enquiry within 5 working days and to provide a substantive response within 30 days. For urgent matters, please use the privacy@getlintel.org address and mark your message as urgent.
18. Complaints and supervisory authorities
If you have a complaint about how we have handled your personal data, we encourage you to contact us first so we have an opportunity to resolve it. You can reach us using the details in Section 17.
You also have the right to lodge a complaint with a supervisory authority:
Nigeria
The Nigeria Data Protection Commission (NDPC) is the supervisory authority responsible for the NDPA.
- Website: www.ndpc.gov.ng
- Email: info@ndpc.gov.ng
- Address: National Data Protection Bureau, Abuja, Nigeria
European Union
If you are based in the EU, you can lodge a complaint with the data protection authority of the EU member state where you live, work, or where the alleged infringement occurred. A list of EU data protection authorities is available at edpb.europa.eu.
United Kingdom
If you are based in the UK, you can lodge a complaint with the Information Commissioner's Office (ICO):
- Website: www.ico.org.uk
- Helpline: 0303 123 1113
- Address: Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, United Kingdom
End of Privacy Policy
This document is provided as a template. We recommend seeking legal advice tailored to your specific business before adopting it.
← Back to home