Legal
Privacy Policy
1. Introduction
Klugekopf Global Concept (“Klugekopf,” “we,” “us,” or “our”) is a marketing agency providing branding, digital marketing, advertising, content creation, campaign management, analytics, lead-generation, consulting, and related services, including services for financial technology businesses.
We respect your privacy and are committed to handling personal data lawfully, fairly, transparently, and securely.
This Privacy Policy explains how we collect, use, store, disclose, and protect personal data when you:
- visit our website or digital platforms;
- contact us or request information about our services;
- subscribe to our newsletters or marketing communications;
- participate in a campaign, promotion, survey, or event;
- engage us as a client, supplier, contractor, or business partner;
- apply for employment or an internship with us; or
- otherwise interact with Klugekopf.
This Policy is designed to reflect the Nigeria Data Protection Act 2023, the Nigeria Data Protection Act–General Application and Implementation Directive 2025, and other applicable privacy and data-protection laws.
2. Our commitment to your privacy
Klugekopf does not sell, rent, or trade your personal data.
We use personal data only where necessary to:
- provide our services;
- respond to enquiries;
- manage authorised marketing activities;
- perform our contractual obligations;
- protect our website, systems, and business;
- maintain appropriate business records; or
- comply with applicable law.
We do not use personal data for purposes unrelated to those described in this Policy. We do not authorise third parties to use personal data for their own unrelated or unauthorised purposes.
3. Our role in processing personal data
Klugekopf may process personal data in different capacities.
When we collect personal data through our website, recruitment activities, business communications, or internal operations, we generally act as a data controller. This means we determine why and how the personal data is processed.
When we process personal data on behalf of a client—for example, when managing a client’s mailing list, advertising audience, customer campaign, lead-generation activity, or analytics account—we may act as a data processor. In such circumstances:
- the client generally decides why and how the data will be processed;
- the client’s privacy policy may also apply;
- we process the data according to the client’s lawful instructions; and
- requests concerning that data may need to be directed to the client.
We require clients that provide personal data to us to confirm that they are authorised to collect and share that information.
4. Personal data we may collect
The personal data we collect depends on how you interact with us.
4.1 Identity and contact information
This may include your:
- full name;
- email address;
- telephone number;
- residential or business address;
- job title;
- employer or organisation;
- social-media username; and
- other contact information you provide.
4.2 Business and professional information
This may include:
- details about your business or organisation;
- your professional role and interests;
- correspondence and meeting records;
- proposals and contracts;
- project information;
- invoices and payment records; and
- information provided during a client, supplier, contractor, or partnership relationship.
4.3 Marketing and communication information
This may include:
- newsletter subscriptions;
- marketing preferences;
- event registrations;
- survey responses;
- campaign engagement;
- promotion or competition entries;
- records of messages sent to us; and
- information about your interaction with our emails, advertisements, and content.
4.4 Website and technical information
When you use our website or digital platforms, we may collect:
- Internet Protocol address;
- browser type;
- device type;
- operating system;
- referring website;
- pages viewed;
- dates and times of visits;
- approximate location derived from an IP address;
- cookie identifiers; and
- website interaction and performance information.
4.5 Campaign and audience information
When providing marketing services, we may process information supplied by our clients or collected through authorised advertising and analytics platforms. This may include:
- customer or prospective-customer contact details;
- lead information;
- marketing preferences;
- campaign engagement;
- audience attributes;
- interests;
- conversion information;
- attribution information; and
- pseudonymised advertising identifiers.
4.6 Recruitment information
If you apply for employment, an internship, or another role with us, we may collect:
- your curriculum vitae;
- education and employment history;
- professional qualifications;
- portfolio or work samples;
- interview notes;
- references;
- contact information; and
- other information relevant to your application.
4.7 Financial and payment information
We may process billing information, invoices, account details, and records of payments made to or received from Klugekopf.
Unless expressly required for an agreed service, we do not intentionally collect customers’ online-banking passwords, card PINs, one-time passwords, or authentication codes.
4.8 Sensitive personal data
We do not ordinarily seek to collect sensitive personal data, such as health, biometric, genetic, religious, political, or sexual-orientation information.
Where processing sensitive personal data is necessary, we will use an appropriate lawful basis, apply additional safeguards, and obtain explicit consent where required by law.
5. How we collect personal data
We may collect personal data:
- directly from you;
- through our website, online forms, email, telephone, or social-media pages;
- through meetings, consultations, events, or campaigns;
- from clients that engage us to provide marketing services;
- from advertising, analytics, communications, and customer-management platforms;
- from referral partners or event organisers;
- from publicly available professional and business sources;
- through cookies and similar technologies; and
- from service providers supporting our business operations.
If you provide personal data about another person, you must have the authority to provide it and, where required, inform that person about this Policy.
6. How we use personal data
We may use personal data to:
- respond to enquiries and requests;
- prepare proposals and quotations;
- provide and manage our services;
- communicate with clients, suppliers, contractors, and partners;
- plan, create, deliver, and evaluate marketing campaigns;
- manage authorised advertising audiences;
- conduct market research;
- analyse campaign performance;
- organise events, promotions, and surveys;
- send newsletters and other authorised marketing communications;
- operate and improve our website and digital platforms;
- personalise website content where permitted;
- process payments and maintain financial records;
- assess employment and internship applications;
- prevent fraud, misuse, and security incidents;
- investigate complaints;
- establish, exercise, or defend legal rights;
- comply with contractual, legal, regulatory, tax, and accounting obligations; and
- carry out other purposes disclosed when personal data is collected.
We will not use personal data for an incompatible or unrelated purpose unless we have a valid legal basis and provide any notice required by law.
7. Lawful bases for processing
Depending on the circumstances, we may rely on one or more of the following lawful bases:
Consent. You have freely given us permission to process your personal data for a specified purpose.
Contract. Processing is necessary to enter into or perform a contract with you.
Legal obligation. Processing is necessary for us to comply with an applicable legal or regulatory obligation.
Legitimate interests. Processing is necessary for a legitimate business purpose, provided that your rights, freedoms, and interests do not override that purpose.
Vital interests. Processing is necessary to protect your life, health, safety, or that of another person.
Public interest. Processing is necessary to perform a task in the public interest, where applicable.
Where we rely on consent, you may withdraw it at any time. Withdrawal will not affect processing lawfully performed before consent was withdrawn.
8. Direct marketing
We may send information about our services, insights, events, or offers where:
- you have consented to receive the communication;
- you have an existing business relationship with us and the communication is legally permitted; or
- another valid lawful basis applies.
You may unsubscribe at any time by:
- selecting the unsubscribe link in a marketing email;
- following the instructions contained in the message; or
- contacting us using the details in Section 20.
After you unsubscribe, we may retain limited information on a suppression list to ensure that we respect your preference.
When we deliver a marketing campaign for a client, that client may be responsible for managing your marketing preferences. We will assist the client where required by law and our agreement.
9. Cookies and similar technologies
Our website may use cookies, pixels, tags, and similar technologies to:
- provide essential website functions;
- remember user preferences;
- understand how visitors use our website;
- measure website and campaign performance;
- improve our services and content; and
- support advertising where legally permitted.
Non-essential cookies will be used only where an appropriate legal basis exists. Where required, we will obtain your consent before placing analytics or advertising cookies on your device.
You can manage your choices through our cookie-preference tool or your browser settings. Disabling certain cookies may affect the operation of some website features.
Details of the cookies used on our website should be provided through our cookie banner or a separate Cookie Notice.
10. Advertising and automated processing
We and our authorised service providers may use information about interests, campaign engagement, or website activity to create audience segments and deliver more relevant content or advertising.
Klugekopf does not ordinarily make decisions based solely on automated processing that produce legal or similarly significant effects for individuals.
If we introduce such processing, we will provide the information and safeguards required by applicable law. These may include the right to request human intervention, express your position, or challenge the decision.
11. How we share personal data
We may share personal data only where necessary and lawful. Recipients may include:
- clients for whom we provide authorised services;
- website-hosting and cloud-service providers;
- email, communications, analytics, and advertising platforms;
- information-technology and cybersecurity providers;
- payment, accounting, insurance, and professional advisers;
- approved consultants, contractors, and campaign partners;
- regulators, courts, law-enforcement agencies, or government authorities where disclosure is required or permitted by law;
- parties involved in a proposed merger, investment, restructuring, financing, acquisition, or sale of our business; and
- other parties where you instruct us or provide valid consent.
We do not sell, rent, or trade personal data.
We require service providers processing personal data on our behalf to:
- maintain confidentiality;
- implement appropriate security measures;
- process personal data only for authorised purposes;
- avoid retaining data longer than necessary; and
- comply with applicable data-protection requirements.
12. International data transfers
Some service providers, advertising platforms, clients, or technology systems we use may be located outside Nigeria.
When personal data is transferred internationally, we will use a legally recognised transfer mechanism and appropriate safeguards. Depending on the circumstances, these measures may include:
- transferring data to a country recognised as providing an adequate level of protection;
- using approved contractual safeguards;
- obtaining consent where legally appropriate;
- transferring data where necessary to perform a contract; or
- relying on another legally permitted basis.
You may contact us for more information about safeguards relevant to your personal data.
13. Data security
We use reasonable technical, administrative, and organisational measures designed to protect personal data from:
- unauthorised access;
- unlawful disclosure;
- misuse;
- alteration;
- accidental loss;
- damage; and
- destruction.
Our safeguards may include:
- access controls;
- staff confidentiality obligations;
- secure system configurations;
- password protections;
- backups;
- vendor assessments;
- encryption where appropriate;
- security monitoring; and
- incident-response procedures.
No electronic transmission or storage system is completely secure. We therefore cannot guarantee absolute security.
If a personal-data breach occurs, we will investigate it, take appropriate remedial action, and notify affected individuals and the relevant regulatory authority where required by law.
14. Data retention
We retain personal data only for as long as reasonably necessary to fulfil the purpose for which it was collected.
When determining a retention period, we consider:
- the nature and sensitivity of the personal data;
- the purpose for which it was collected;
- the duration of our relationship with you or a client;
- applicable contractual requirements;
- regulatory, tax, accounting, and legal obligations;
- applicable limitation periods;
- security and fraud-prevention needs; and
- the risks associated with continued retention.
When personal data is no longer required, we will securely delete, anonymise, or otherwise dispose of it in accordance with our retention procedures and applicable law.
15. Your privacy rights
Subject to applicable law and relevant exemptions, you may have the right to:
- be informed about the processing of your personal data;
- request confirmation that we process your personal data;
- access personal data we hold about you;
- obtain a copy of your personal data;
- correct inaccurate or incomplete personal data;
- request deletion of your personal data;
- request restriction of processing;
- object to certain processing;
- object to direct marketing;
- withdraw consent at any time;
- request the transfer of eligible personal data in a structured, commonly used, machine-readable format;
- object to decisions based solely on automated processing and request human intervention where applicable; and
- lodge a complaint with the Nigeria Data Protection Commission or another competent authority.
These rights are not absolute. We may decline or limit a request where permitted by law, including where processing is necessary to:
- comply with a legal obligation;
- establish, exercise, or defend legal claims;
- protect another person’s rights;
- prevent fraud or unlawful activity; or
- satisfy another applicable legal exemption.
16. How to exercise your rights
To exercise a privacy right, contact us using the details in Section 20 and describe your request.
We may request reasonable information to:
- verify your identity;
- locate the relevant personal data;
- clarify your request; or
- confirm another person’s authority to act on your behalf.
We will respond within the period required by applicable law.
We ordinarily do not charge a fee for responding to a request. However, we may charge a reasonable fee or decline a request where permitted by law, including where a request is manifestly unfounded, excessive, or repetitive.
Where we process personal data solely on behalf of a client, we may refer your request to the client or assist the client in responding.
17. Children’s privacy
Our website and services are not directed to children, and we do not knowingly collect children’s personal data without appropriate authority and safeguards.
Where a campaign involves children or other vulnerable individuals, we will apply heightened protections and obtain consent or authorisation from a parent, guardian, or other authorised person where required.
If you believe that a child has provided personal data to us improperly, please contact us immediately.
18. Third-party websites and platforms
Our website and communications may contain links to third-party websites, social-media services, advertising platforms, payment services, or financial-technology products.
These third parties operate independently and maintain their own privacy practices. Klugekopf is not responsible for their content, security, or handling of personal data.
You should review the privacy policy of each third party before providing personal data or using its services.
19. Complaints
If you have a concern about how we process personal data, please contact us so that we can investigate and respond.
You also have the right to submit a complaint to the:
Nigeria Data Protection Commission
Website: ndpc.gov.ng
Making a complaint will not affect any other legal rights or remedies available to you.
20. Contact us
Questions, complaints, requests, or concerns about this Privacy Policy or our processing of personal data may be directed to:
Klugekopf Global Concept
Attention: Data Protection Contact
Email: info@klugekopfglobalconcept.com
Website: klugekopfglobalconcept.com
Contact form: klugekopfglobalconcept.com/contact
If Klugekopf appoints a Data Protection Officer, the officer’s current contact information will be published in this section.
21. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in:
- our services;
- our technology;
- our business practices;
- applicable laws or regulatory guidance; or
- the way we process personal data.
The updated Policy will be published on our website with a revised “Last Updated” date.
Where a change materially affects your rights or the way we process personal data, we will provide additional notice or obtain consent where required by law.
22. Interpretation
For the purpose of this Policy:
Personal data means information relating to an identified or identifiable natural person.
Processing includes collecting, recording, organising, storing, altering, retrieving, consulting, using, sharing, restricting, deleting, destroying, or otherwise handling personal data.
Sensitive personal data means personal data requiring enhanced protection under applicable law.
If any part of this Policy conflicts with a mandatory requirement of applicable law, the applicable legal requirement will prevail.