Preparing the details that protect your business.
This Policy explains what KOMERRA collects, where information comes from, why it is processed, how AI and connected services use it, who may receive it, how long it is retained, and the rights and choices available to you.
This Privacy Policy explains how KOMERRA Technologies Limited collects, receives, uses, stores, organizes, analyzes, shares, protects, transfers, retains, and deletes personal data when people use or interact with KOMERRA.
It applies to KOMERRA websites, web applications, mobile applications, business workspaces, Mini Stores, Trust Passports, public business pages, support channels, connected services, artificial-intelligence features, verification processes, communications, and other products or services collectively referred to as the “Services”.
This Policy should be read together with the KOMERRA Terms of Service, Cookie Policy, Data Retention Policy, Account Deletion Policy, Data Processing Agreement, Subprocessors page, Business Verification and Trust Passport Policy, Mini Store Policy, and any feature-specific privacy notice presented when information is collected.
This Policy was last updated on 20 July 2026. The effective date is the date displayed when this Policy is published or otherwise presented to you.
KOMERRA Technologies Limited is a company registered in the Federal Republic of Nigeria with registration number 9681120.
KOMERRA is generally responsible as a data controller for personal data used to operate the platform, administer Accounts, manage billing and Credits, verify businesses, provide support, secure the Services, prevent fraud, maintain legal records, communicate with users, and improve platform reliability.
A business using KOMERRA is generally responsible as the data controller for personal data concerning customers, prospective customers, staff, contractors, suppliers, and other persons that the business chooses to enter, import, connect, generate, or otherwise process through its Workspace.
For business-controlled Workspace information, KOMERRA generally acts as a data processor by processing that information on the instructions of the relevant business and in accordance with the KOMERRA Data Processing Agreement.
The precise legal role of KOMERRA and a business may depend on the feature, processing purpose, information involved, instructions given, and applicable law.
Questions, concerns, complaints, and requests concerning privacy or personal data may be sent to KOMERRA Technologies Limited.
Email: support@komerra.app.
Website: www.komerra.app.
Company registration number: 9681120.
Please include “Privacy Request” in the subject of an email concerning your personal data. Include enough information to help us identify the relevant Account, Workspace, Mini Store, Trust Passport, communication, or transaction without sending unnecessary sensitive information.
Where KOMERRA appoints or publishes contact details for a Data Protection Officer or dedicated privacy team, the current details will appear on the KOMERRA website and may replace or supplement the general support contact.
This Policy applies to people who visit a KOMERRA website, create or use an Account, operate or join a business Workspace, purchase Credits, communicate with support, apply for verification, connect a third-party channel, or use an AI-assisted feature.
It also applies to Business Customers who visit a KOMERRA-powered Mini Store, place an order, submit contact or delivery details, upload payment evidence, communicate with a business, or interact with a Trust Passport or other public business page.
It applies to staff members, contractors, administrators, suppliers, prospective users, professional advisers, job applicants, event participants, and other people who communicate with KOMERRA in a business or professional context.
Where you interact with a business using KOMERRA, the business’s own privacy notice may also apply. You should review that notice because the business determines why and how it uses the customer or staff information placed in its Workspace.
KOMERRA is designed to process personal data fairly, lawfully, transparently, and only for specified and legitimate purposes.
We seek to collect information that is relevant and reasonably necessary for the purpose for which it is processed, maintain appropriate accuracy, apply proportionate retention periods, and use technical and organizational safeguards appropriate to the relevant risk.
We seek to build privacy into product design, access controls, workflows, data architecture, provider selection, verification processes, AI features, retention rules, and incident-response procedures.
We do not treat access to personal data as permission to use it for any purpose. Access and processing must remain connected to a disclosed, lawful, and legitimate purpose.
“Personal data” means information relating to an identified or identifiable individual. It can include a name, telephone number, email address, online identifier, device identifier, government identification number, photograph, voice recording, location information, financial information, or information linked to a person’s activities or relationships.
Information about a company or business may not always be personal data. However, information relating to a sole trader, director, employee, representative, customer, beneficial owner, or other identifiable person may be personal data.
Aggregated, anonymized, or effectively de-identified information that cannot reasonably be connected to an identifiable person is not treated as personal data to the extent permitted by applicable law.
We may combine information received from different parts of the Services where the combination is necessary for a disclosed purpose, such as Account security, Workspace activity history, verification, customer support, or fraud prevention.
We obtain personal data directly from you, from a business using KOMERRA, from an Authorized User, from a Business Customer, through connected services, from payment and verification providers, from publicly available records, and automatically when the Services are used.
We may receive information from another person where that person is authorized to provide it, such as when a Workspace administrator invites a staff member, a business records a customer order, or a customer provides delivery information for another recipient.
We may obtain business-registration, company-director, ownership, verification, or similar information from official registries, approved verification providers, issuing authorities, or other lawful sources.
Where information is not collected directly from the person concerned, we seek to provide or facilitate appropriate notice unless the person already has the information, providing notice is legally exempted, or doing so is impossible or would involve disproportionate effort.
When you create or use an Account, we may collect your name, email address, telephone number, country, preferred language, profile image, role, job title, business relationship, login methods, communication preferences, verification status, and Account settings.
We may also process the Workspace you belong to, your assigned permissions, invitations, acceptance status, administrator status, Account creation date, last login, authentication events, active sessions, and Account status.
You may be able to provide optional profile information. The interface will indicate where information is optional or required for a particular feature.
We use Account and profile information to create and administer Accounts, authenticate users, display appropriate Workspace information, enforce permissions, provide support, communicate service information, and protect the Services.
When a business creates or configures a Workspace, we may collect the business name, trading name, registration number, business type, industry, country, addresses, contact details, website, logo, description, operating preferences, currency, language, tax information, payment instructions, and authorized representatives.
Business information may be connected to identifiable owners, directors, administrators, staff members, beneficial owners, or representatives and may therefore contain personal data.
We may process business information to create the Workspace, provide localized functionality, generate business documents, configure tax or currency displays, support Mini Store functionality, conduct verification, prevent misuse, and provide customer-facing business information.
The business is responsible for keeping its Workspace and public-facing business information accurate and current.
Where verification is required or requested, we may collect or receive names, dates of birth, telephone numbers, addresses, government-issued identification details, identification documents, facial images, verification recordings, business-registration documents, directorship information, beneficial-ownership information, tax information, proof of address, bank-account details, and evidence of authority to represent a business.
Verification may involve information associated with a National Identification Number, Corporate Affairs Commission registration, business registry, bank account, telephone number, email address, or another identity or business credential.
Verification information is used to confirm identity or business information, reduce impersonation and fraud, protect customers and businesses, satisfy provider requirements, determine eligibility for a feature, and comply with applicable legal obligations.
Where a provider can return a verification result without requiring KOMERRA to retain the full underlying identifier or document, we prefer to retain a verification status, reference, timestamp, provider response, or limited result rather than unnecessary underlying information.
Where retention of an underlying document or identifier is necessary, access is limited according to role and purpose, and the information is not intended to be displayed publicly.
A Trust Passport or verification badge will not publish a person’s full government identification number, private identity document, facial-verification recording, password, authentication secret, or full financial credentials.
A business or its Authorized Users may enter, import, generate, upload, approve, or store information relating to customers, leads, orders, products, inventory, staff, suppliers, payments recorded, debts, reminders, conversations, files, documents, complaints, deliveries, and other business activities.
The relevant business determines which Business Content is placed in its Workspace and is responsible for having an appropriate lawful basis and legitimate purpose for doing so.
KOMERRA processes Business Content to provide the features requested by the business, maintain the Workspace, enforce permissions, synchronize connected channels, generate documents, support AI-assisted workflows, protect the platform, troubleshoot problems, and comply with lawful obligations.
KOMERRA does not independently decide that every customer, staff, transaction, or communication record should be created. Those decisions are generally made by the relevant business and its Authorized Users.
Authorized Users should only access Business Content that is appropriate for their role and responsibilities.
Business-controlled records may include names, contact details, delivery addresses, customer identifiers, conversations, orders, preferences, complaint information, payment status, invoices, employment information, staff roles, attendance-related information, assignments, and other records selected by the business.
A business must provide appropriate privacy information to the customers, staff members, contractors, and other people whose personal data it chooses to process through KOMERRA.
A business must not collect excessive personal data merely because a KOMERRA field, note, upload, integration, or document feature is available.
A business must not use information obtained through KOMERRA for an incompatible purpose, unlawful marketing, unauthorized disclosure, sale, discrimination, harassment, or another prohibited purpose.
Where a business receives a valid privacy request concerning information in its Workspace, the business remains responsible for responding and may request reasonable technical assistance from KOMERRA.
When a person visits or uses a Mini Store, we or the business operating the Mini Store may collect information such as the visitor’s name, telephone number, email address, customer-account details, delivery information, selected products or services, cart contents, order instructions, communications, payment method, payment status, and uploaded payment evidence.
The business operating the Mini Store is generally responsible for the personal data it uses to sell products, provide services, fulfil orders, communicate with customers, arrange delivery, manage refunds, and resolve complaints.
KOMERRA processes Mini Store information to provide the storefront, create customer accounts where enabled, record orders, display order status, route communications, provide security, support the business, and maintain the Services.
A Business Customer should review the seller’s identity, product information, payment details, delivery terms, privacy notice, return policy, and other relevant terms before completing a transaction.
Payment evidence uploaded through a Mini Store may contain names, account references, transaction identifiers, timestamps, amounts, bank or payment-provider details, and other financial information. Businesses must only use that evidence to review and administer the relevant transaction, prevent fraud, maintain appropriate records, or satisfy lawful obligations.
A Trust Passport or other public business page may display information selected by the business or approved for publication, such as the business name, logo, description, public contact details, registration status, verification indicators, business category, policies, products, services, and other trust signals.
The business controls the information it submits for publication and is responsible for ensuring that it has authority to publish personal information relating to owners, staff members, representatives, or other people.
KOMERRA may review or verify selected information before displaying a verification status, but a verification status does not mean that every item on a public page has been independently verified.
Information intentionally published on a Mini Store, Trust Passport, or other public page may be viewed, copied, shared, or indexed by search engines and other third parties.
Removing information from KOMERRA may not immediately remove copies previously indexed, cached, archived, downloaded, or independently republished by third parties. We may provide reasonable assistance with matters under our control but cannot control independent third-party copies.
KOMERRA may allow an authorized business to connect communication or business channels such as WhatsApp, Instagram, Facebook Messenger, email, SMS, cloud storage, payment platforms, and other supported services.
Connected-channel processing begins only after an Authorized User completes the applicable connection, authorization, configuration, or request.
Depending on the integration, we may receive channel account identifiers, profile information, conversation content, message metadata, attachments, customer identifiers, delivery or read status, template information, webhook events, permissions, access tokens, refresh tokens, connection status, and error information.
We process connected-channel information to synchronize communications, identify possible leads or orders, prepare summaries, propose actions, send approved communications, maintain conversation history, troubleshoot the connection, and provide the requested workflow.
The information available through a connected channel depends on the permissions granted, the provider’s API, the provider’s terms, the user’s settings, and the features selected by the business.
Disconnecting a channel stops or limits future access but does not necessarily delete information already lawfully imported, organized, or recorded in the Workspace. Imported information may be deleted separately, subject to retention obligations.
We may process communications sent to or through KOMERRA, including email, SMS, connected-channel messages, support conversations, customer-business communications, notifications, message templates, and delivery information.
Communication information may include sender and recipient identifiers, telephone numbers, email addresses, message content, attachments, timestamps, delivery status, reply history, opt-out status, and provider references.
Businesses are responsible for ensuring that they have a lawful basis to contact recipients and that their messages comply with applicable privacy, marketing, consumer-protection, and connected-provider requirements.
We may use message content to provide requested AI extraction, summarization, classification, translation, drafting, search, reminder, or customer-management functionality.
We may scan or analyze communications using automated safeguards for malware, prohibited activity, abuse, fraud, security threats, and delivery failures.
When an AI-assisted feature is used, we may process the information submitted to the feature, relevant Workspace context, instructions, selected settings, generated Output, feedback, confirmation decisions, corrections, confidence indicators, model information, token or usage information, safety results, timestamps, and error records.
AI inputs may include text, images, documents, screenshots, voice notes, transcripts, customer conversations, product information, order details, or other Business Content selected by the user or relevant to the requested workflow.
We process AI information to extract or organize business information, classify activity, generate summaries, translate content, prepare documents, suggest replies, identify possible follow-ups, provide analytics, and perform other functions requested by the user.
Where an AI provider is required, KOMERRA may transmit the minimum information reasonably necessary to the approved provider to perform the requested function.
An AI provider does not receive independent authority to communicate with customers, make business commitments, alter records, or act for the business merely because it processes information for an AI feature.
Important actions remain subject to authentication, permissions, workflow rules, validation, and human confirmation where the feature requires it.
KOMERRA does not use identifiable Workspace Business Content to train general-purpose AI models for unrelated customers unless the Workspace owner knowingly and expressly opts into a separately explained improvement program.
We seek to use production AI-provider offerings and contractual arrangements that restrict provider use of Business Content for unrelated general-model training.
We may use voluntarily submitted feedback, test data, synthetic data, aggregated information, and appropriately de-identified information to assess accuracy, improve prompts, evaluate safety, diagnose failures, measure performance, and improve KOMERRA features.
Where human review of AI interactions is necessary for support, safety, investigation, or quality assurance, access is limited to authorized personnel or providers with a legitimate need and appropriate confidentiality obligations.
You should not submit information to an AI feature unless it is relevant to the requested business purpose and you are authorized to process it.
KOMERRA may process images, photographs, screenshots, receipts, invoices, identity documents, product images, business logos, delivery records, and other files uploaded or received through the Services.
We may use optical character recognition, document analysis, image classification, file scanning, metadata extraction, and AI-assisted processing to identify text or structured information within a file.
Files may contain metadata such as filename, file type, size, creation information, device information, or other embedded details.
Uploaded payment evidence is treated as information requiring review and is not independent proof that money moved, settled, or cannot be reversed.
Uploaded files may be scanned for malware, prohibited content, corruption, security threats, duplicate content, and processing errors.
Users should remove unnecessary sensitive information before uploading a file and should not upload passwords, private keys, card security codes, or other authentication secrets.
Where voice or audio functionality is used, we may process the audio recording, voice note, language, duration, transcript, extracted details, speaker information supplied by the user, processing status, and related metadata.
Audio may be sent to an approved speech-processing or AI provider where necessary to transcribe, translate, summarize, classify, or extract information from the recording.
The business is responsible for having an appropriate lawful basis to record, upload, or process a person’s voice or conversation.
Automatically generated transcripts may be inaccurate and should be reviewed before they are used to update records, contact a customer, issue a document, or make another material decision.
KOMERRA does not use voice recordings to create an advertising profile or biometric voice identity unless a separately disclosed and lawfully authorized feature expressly requires it.
KOMERRA may support fingerprint unlock, facial unlock, passkeys, device credentials, or similar authentication methods through compatible devices, browsers, and operating systems.
For ordinary device-based biometric login or unlock, biometric matching is generally performed by the user’s device, operating system, browser, or credential provider. KOMERRA ordinarily receives an authentication assertion, credential identifier, public-key information, status, or similar security result rather than the person’s raw fingerprint or facial template.
KOMERRA does not control how a device manufacturer or operating-system provider independently processes biometric information stored on the device.
A user should review the privacy and security settings of the relevant device, browser, and operating-system provider before enabling biometric or passkey authentication.
Device-based authentication is different from facial or identity verification performed to confirm a person’s identity. Identity-verification processing is described separately in this Policy and in any notice presented during verification.
Some features may involve information treated as sensitive under applicable law, such as biometric data, government identification information, financial information, health-related information, information about children, or information capable of creating a heightened risk to a person.
We process sensitive personal data only where a valid legal condition applies and the processing is reasonably necessary for the disclosed purpose.
We apply additional safeguards where appropriate, such as restricted access, purpose limitation, encryption, masking, redaction, provider due diligence, shorter retention, enhanced logging, impact assessment, or human review.
Sensitive personal data should not be placed in ordinary notes, descriptions, prompts, messages, or upload fields where a designated secure workflow is available.
A business is responsible for determining whether its use of KOMERRA involves sensitive personal data and for satisfying any additional notice, consent, authorization, documentation, or compliance requirement that applies to the business.
When Credits, subscriptions, or other paid Services are purchased, we may collect or receive the payer’s name, billing contact information, country, amount, currency, tax information, payment-provider reference, transaction status, timestamps, Credit allocation, invoice information, refund information, dispute status, and fraud indicators.
Payment-card, bank-transfer, mobile-money, or similar payment credentials are generally collected and processed directly by the applicable payment provider.
KOMERRA is designed not to store full payment-card numbers or card security codes. We may receive masked payment-instrument information, card type, bank name, account-name result, provider token, payment reference, payment status, and other limited information necessary to reconcile and support the transaction.
We process billing information to complete purchases, allocate Credits, issue transaction records, verify server-side payment outcomes, prevent fraud, manage refunds, resolve disputes, maintain accounting records, and comply with tax or legal obligations.
Payment providers process information under their own privacy notices and legal responsibilities.
When the Services are accessed, we may automatically collect limited technical and usage information required to operate, secure, diagnose, and improve the platform.
This information may include IP address, approximate country or region derived from an IP address, browser type, operating system, device type, application version, language, time zone, request identifiers, session identifiers, authentication events, page or feature interactions, referring page, network information, error events, performance timing, and security signals.
We may collect audit information concerning actions performed within a Workspace, including the acting user, action type, affected record, timestamp, result, permission context, and relevant request or device information.
We use technical information to authenticate users, protect tenant isolation, identify abuse, maintain service availability, investigate errors, enforce limits, support users, understand feature performance, and improve accessibility and reliability.
We do not use precise device location unless a feature specifically requests it, the user enables it, and an appropriate notice and permission are provided.
KOMERRA may use cookies, local storage, session storage, software-development-kit identifiers, pixels, or similar technologies to operate websites and applications.
Strictly necessary technologies may be used for authentication, session management, security, load balancing, fraud prevention, language preferences, consent records, and other functions required to provide the Services.
Preference technologies may remember settings such as language, appearance, dismissed notices, or interface choices.
Analytics or performance technologies may be used to understand how the Services perform and how features are used. Where consent is required, these technologies will not be activated until the appropriate choice has been made.
Advertising or cross-site tracking technologies will not be used unless they are clearly disclosed and an appropriate lawful basis is established.
The KOMERRA Cookie Policy and cookie-management interface provide additional information about available technologies, their purposes, providers, and durations.
KOMERRA may use privacy-configured analytics, error monitoring, performance monitoring, interaction diagnostics, and session-replay tools to diagnose failures, understand navigation problems, identify broken workflows, investigate crashes, improve accessibility, and detect repeated unsuccessful interactions such as rage clicks.
Depending on the tool and configuration, diagnostics may include page paths, clicks, scroll activity, navigation events, browser information, performance timing, application state, error traces, request identifiers, and a masked visual reconstruction of an interaction.
Designated sensitive fields should be masked, suppressed, or excluded from session replay and diagnostic capture. We do not intentionally use session replay to record passwords, full card details, card security codes, private authentication secrets, full identity numbers, or unrestricted message content.
Where non-essential analytics or replay requires consent, the feature will be controlled through the applicable cookie or tracking preference.
Diagnostic information is restricted to authorized personnel and providers who need it for reliability, security, support, or product improvement.
Users should not enter highly sensitive information into an ordinary field that is not specifically designed to receive it.
When you contact support, submit a complaint, report a security concern, provide feedback, respond to a survey, or participate in product research, we may collect your contact information, Account information, Workspace information, messages, attachments, screenshots, recordings, transaction references, device details, and other information you choose to provide.
We process this information to understand and respond to your request, investigate the issue, verify authority, protect the Services, maintain support history, improve documentation, and resolve disputes.
Support communications may be reviewed by authorized KOMERRA personnel and approved support providers.
You should not send identity documents, passwords, private keys, card security codes, or other highly sensitive information through ordinary support channels unless we specifically request it through an appropriate secure process.
Participation in optional surveys, interviews, testimonials, or research is voluntary. Additional notice or consent will be provided where the intended use is not reasonably apparent.
KOMERRA processes personal data only where an applicable lawful basis or other legal condition supports the processing.
The lawful basis depends on the information, relationship, context, and purpose. More than one lawful basis may apply to different operations involving the same category of information.
Where KOMERRA relies on consent, the request will be presented separately or clearly enough for the person to understand what is being requested.
Consent must be freely given, specific, informed, unambiguous, and expressed through an appropriate affirmative action. Silence, inactivity, or a preselected option will not be treated as consent where affirmative consent is legally required.
You may withdraw consent at any time through the relevant setting, unsubscribe control, cookie interface, connected-provider control, or privacy-request process.
Withdrawal does not affect processing that was lawful before consent was withdrawn.
Withdrawing consent may prevent an optional feature from continuing where the feature cannot operate without the relevant processing.
We will not describe processing as consent-based where the processing is actually necessary to perform a contract or satisfy another applicable lawful basis.
We use personal data only for purposes that are reasonably connected to providing, administering, protecting, supporting, and lawfully developing KOMERRA.
We may analyze Account activity, device information, verification results, transactions, payment references, message patterns, login attempts, permission changes, provider events, and other relevant signals to protect users and the platform.
Security and fraud systems may generate alerts, confidence indicators, risk scores, unusual-activity flags, rate limits, or recommended restrictions.
A risk signal does not necessarily prove wrongdoing. It may result in additional verification, temporary limitation, manual review, notification, or a request for clarification.
We may use information from payment providers, connected services, affected users, public records, or other lawful sources to investigate suspected impersonation, account compromise, fraudulent payment evidence, abuse, or prohibited activity.
We retain security and fraud records for a period proportionate to the risk, applicable legal obligations, and the need to prevent repeated abuse.
KOMERRA uses automated processing to organize information, extract possible order details, identify likely business activities, detect security risks, prioritize alerts, recommend actions, personalize permitted settings, and provide other requested functionality.
Automated processing may involve profiling where information is evaluated to identify patterns, preferences, risks, activity categories, or likely workflow outcomes.
KOMERRA does not intend to use solely automated processing to make a decision that produces a legal or similarly significant effect on an individual without an applicable lawful basis and required safeguards.
Where a legally significant automated decision is permitted and used, the affected person will be provided with appropriate information and, where required, a way to request human intervention, express a point of view, obtain meaningful review, or contest the decision.
Businesses must not use KOMERRA Output as the sole basis for high-impact decisions concerning employment, credit, insurance, access to essential services, legal rights, or similar matters unless their use is lawful and suitable human safeguards are provided.
We may use Account contact information to send communications necessary to operate the Services or administer our relationship with you.
These communications may include email-verification links, login alerts, one-time codes, password-reset messages, security notifications, billing notices, Credit confirmations, material product notices, policy updates, incident communications, Workspace invitations, support replies, and legally required information.
Service and security communications are not marketing and may continue while an Account remains active or while a relevant legal, billing, security, or support matter remains unresolved.
You are responsible for keeping your email address and telephone number current so that important notices reach you.
We may send product news, feature announcements, educational content, event information, promotions, or similar marketing communications where an appropriate lawful basis applies.
You may unsubscribe from email marketing through the unsubscribe control in the message or update an available communication preference.
You may object to direct marketing at any time. When a valid objection applies, we will stop processing the relevant personal data for that direct-marketing purpose.
Unsubscribing from marketing does not prevent necessary service, billing, legal, Account, security, or transaction communications.
A business using KOMERRA is independently responsible for the marketing communications it sends to its customers and must maintain appropriate consent, opt-out, suppression, and lawful-basis records.
The Workspace owner and authorized administrators control which staff members and other Authorized Users may access information in the Workspace.
Depending on permissions, Authorized Users may be able to view customer records, orders, communications, files, reports, billing information, staff activity, audit history, connected channels, and other Business Content.
Workspace administrators may invite or remove users, change permissions, review user activity, export information, connect providers, and request Workspace closure.
KOMERRA provides permission controls, but the Workspace owner is responsible for assigning appropriate roles, reviewing access, and removing access when it is no longer required.
Information created through an organization-controlled Workspace should not be treated as private from the Workspace owner or authorized administrators.
Certain information is shared because a business chooses to publish it, send it, or use it in a customer-facing workflow.
Examples include a Mini Store listing, Trust Passport, business profile, invoice, quotation, receipt, delivery note, customer message, order status, return policy, public contact detail, or payment instruction.
Before publishing or sending information, a business must ensure that it has authority to disclose any personal data contained in the material.
KOMERRA may display platform-generated indicators such as verification status, document identifiers, order status, or transaction references where necessary to provide the customer-facing functionality.
Public and customer-facing information should not contain government identification numbers, passwords, private staff information, authentication secrets, or other information that is inappropriate for the intended audience.
We use carefully selected companies and service providers to help operate KOMERRA. These providers may support cloud hosting, database infrastructure, object storage, security, error monitoring, email, SMS, messaging, AI processing, speech processing, verification, customer support, analytics, payment processing, and other technical functions.
Providers receive only the information reasonably necessary to perform the relevant service and are expected to process it for authorized purposes and under appropriate contractual, confidentiality, security, and data-protection obligations.
Some providers act as processors or subprocessors for KOMERRA. Others, such as banks, payment providers, connected communication platforms, or identity providers, may act as independent data controllers for parts of their processing.
The current categories and identities of material providers are described on the KOMERRA Subprocessors page or in an applicable enterprise agreement.
We assess providers based on factors such as purpose, data involved, security, privacy terms, location, reliability, legal requirements, and ability to support our obligations.
When you connect or use a third-party service, information may be exchanged between KOMERRA and that provider to provide the requested integration.
The third party’s own terms, privacy policy, permissions, retention practices, and security measures apply to information processed independently by that third party.
We do not control how an independent third party uses information outside the scope of the KOMERRA integration.
You should review requested permissions before connecting a provider and should disconnect access when it is no longer required.
A provider may retain information previously received through the integration according to its own legal responsibilities and policies even after the connection is removed.
We may share personal data with lawyers, accountants, auditors, insurers, security specialists, consultants, compliance advisers, and other professional advisers where reasonably necessary to obtain advice, protect rights, satisfy obligations, investigate incidents, or operate the business.
Professional advisers are expected to protect information through professional duties, contractual confidentiality, or other applicable obligations.
We limit disclosure to information relevant to the matter for which the adviser is engaged.
We may preserve, use, or disclose information where reasonably necessary to comply with applicable law, a court order, regulatory requirement, lawful government request, or other binding legal process.
We may also disclose information where reasonably necessary to investigate fraud, protect a person’s safety, defend legal claims, enforce agreements, protect the rights of users, prevent serious abuse, or maintain the security and integrity of the Services.
We assess requests for personal data and may reject, narrow, challenge, or request clarification of a request that appears invalid, excessive, unlawful, or insufficiently specific.
Where legally permitted and reasonably practicable, we may notify the affected person or business before disclosure.
We may preserve information subject to a legal hold even where it would otherwise have been deleted under an ordinary retention schedule.
Personal data may be reviewed, transferred, or disclosed in connection with a proposed or completed merger, acquisition, financing, restructuring, investment, sale of assets, insolvency process, or transfer of part or all of the KOMERRA business.
We will limit information shared during due diligence, use appropriate confidentiality safeguards, and disclose information only where reasonably necessary for the transaction.
Where responsibility for personal data is transferred to another organization, we will provide appropriate notice where required and require the recipient to respect applicable privacy obligations.
KOMERRA does not sell or rent personal data to advertisers, data brokers, or unrelated third parties.
We do not disclose identifiable Workspace Business Content to unrelated third parties so that they can independently market their products to the business’s customers.
We do not use customer conversations, identity documents, payment evidence, or private Workspace records for third-party behavioral advertising.
A disclosure to a service provider, connected integration, payment provider, professional adviser, business customer, lawful authority, or corporate successor for the purposes described in this Policy is not treated as a sale of personal data.
We may create aggregated, statistical, anonymized, pseudonymized, or de-identified information from use of the Services.
We may use this information to evaluate performance, improve features, understand usage trends, measure reliability, develop fraud-prevention controls, conduct capacity planning, create benchmarks, and produce non-identifying business insights.
Where information is only pseudonymized and could still be connected to a person using additional information, we continue to treat it as protected personal data.
We take reasonable measures designed to prevent de-identified information from being used to re-identify an individual where re-identification would be unlawful or inconsistent with the purpose for which the information was prepared.
We do not publicly disclose aggregated information where the group, context, or combination of details would reasonably identify a particular person or reveal confidential Business Content.
KOMERRA is based in Nigeria, but some infrastructure, service providers, subprocessors, connected platforms, support systems, and technical personnel may process information in other countries.
Where personal data is transferred from Nigeria to another country, we assess the purpose, recipient, information involved, legal conditions, available protections, and risks to the people concerned.
We may rely on applicable adequacy findings, contractual clauses, binding corporate rules, certifications, codes, consent where legally valid, contractual necessity, legal claims, public interest, or another transfer condition permitted by applicable law.
We seek to limit international transfers to information reasonably necessary for the relevant service and maintain records of the applicable transfer basis where required.
The privacy and data-protection laws of a recipient country may differ from those of Nigeria. We use contractual, technical, organizational, or other appropriate safeguards where required.
Provider locations and transfer arrangements may change. Material provider information is maintained on the KOMERRA Subprocessors page or communicated through an applicable contractual process.
Certain businesses, industries, contracts, or jurisdictions may impose data-location, localization, secrecy, or sector-specific storage requirements.
A business is responsible for determining whether its use of KOMERRA is subject to a special data-location or sector-specific restriction.
Unless a particular hosting region or residency arrangement is expressly agreed in writing, the Services may use infrastructure located in more than one jurisdiction.
Enterprise customers requiring a specific processing location, transfer mechanism, dedicated environment, or additional contractual safeguard should ensure that the requirement is documented in the applicable commercial agreement before placing restricted information in KOMERRA.
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, the provision of the Services, security, fraud prevention, dispute resolution, legal compliance, accounting, tax, enforcement, and the establishment, exercise, or defense of legal claims.
Retention periods vary according to the category of information, purpose, Account status, sensitivity, legal obligations, provider requirements, risk, and whether the information belongs to a business-controlled Workspace.
The KOMERRA Data Retention Policy contains the current retention categories, deletion triggers, archival rules, legal-hold procedures, and backup treatment.
An Account or Workspace owner may request closure through the available settings or support process.
Before closing a Workspace, the business should export records that it must retain for legal, accounting, tax, customer-service, employment, or operational purposes.
A closure request may require identity, administrator, ownership, or security verification.
Deletion may be delayed or limited where information must be retained to comply with law, investigate fraud, preserve evidence, enforce an agreement, resolve an ownership dispute, protect another person’s rights, or maintain necessary transaction records.
Closing an individual Authorized User Account may remove that user’s access without deleting records created through the organization-controlled Workspace.
The Account Deletion Policy explains closure stages, export opportunities, deletion triggers, exceptions, and expected handling of associated information.
KOMERRA and its infrastructure providers may maintain encrypted or otherwise protected backups for resilience, disaster recovery, security, and service restoration.
Information deleted from active systems may remain in a backup until the backup is securely overwritten or expires under the applicable backup schedule.
Backup copies are isolated from ordinary product use and are not restored for the purpose of avoiding a valid deletion request.
Where a backup is restored following an incident, deletion records and applicable restrictions should be reapplied as part of the recovery process.
We may retain limited logs showing that a deletion occurred without retaining the deleted content itself where the log is necessary for security, accountability, or legal compliance.
We take reasonable steps to maintain accurate personal data where accuracy is important to the processing purpose.
Users can update certain Account, profile, business, customer, and preference information directly through the Services.
Businesses are responsible for reviewing and correcting the customer, order, staff, payment, document, and other records they place in their Workspaces.
AI-extracted information, transcripts, classifications, summaries, and recommendations may be inaccurate and should be reviewed before being approved or used for a material action.
You may request correction of inaccurate, incomplete, outdated, or misleading personal data that KOMERRA controls, subject to reasonable verification and legal limitations.
Subject to applicable law, the nature of our role, reasonable identity verification, and relevant exceptions, you may exercise rights concerning personal data about you.
Where your personal data was entered or collected by a business using KOMERRA, the business is generally responsible for responding to your privacy request.
Examples include customer orders, staff records, supplier details, Mini Store customer information, business messages, uploaded payment evidence, and other records controlled by the business.
You should normally direct your request to the relevant business because that business determines why the information is processed and whether it must be retained.
Where you send such a request to KOMERRA, we may refer it to the relevant business, request authorization from the business, or provide technical assistance in accordance with the Data Processing Agreement.
KOMERRA may respond directly where we independently control the information or where applicable law requires us to do so.
We may be unable to satisfy a request that would require us to override a lawful instruction from the responsible business without an applicable legal basis.
You may use available Profile, Settings, Privacy, Connected Channels, Cookie Preferences, Export, or Account Deletion controls for requests that can be completed directly.
For other requests, email support@komerra.app with “Privacy Request” in the subject and explain the Account, Workspace, Mini Store, Trust Passport, communication, or business concerned.
Please describe the right you wish to exercise and provide enough information for us to locate the relevant records.
We may ask for reasonable information to confirm your identity, authority, Account relationship, or connection to the relevant data. We will not request more identity information than is reasonably necessary for verification.
Where a request is made through an authorized representative, we may request evidence of the representative’s authority and may verify the request directly with the person concerned.
We ordinarily respond within the period required by applicable law. A complex request, request involving multiple systems, or request requiring consultation with a business may require additional time where the law allows it.
Privacy requests are normally handled without charge. We may charge a reasonable cost or decline a request only where applicable law permits, such as where a request is manifestly unfounded, excessive, repetitive, or would impose legally recognized unreasonable costs.
Privacy rights are not absolute. A request may be limited or refused where necessary to protect another person’s rights, comply with law, preserve evidence, prevent fraud, maintain security, protect confidential information, enforce a contract, or establish, exercise, or defend legal claims.
We may remove or redact information relating to another person before providing access.
We may retain transaction, billing, fraud, security, verification, or legal records after an erasure request where a valid retention basis applies.
A portability request may be limited to information within the scope of the applicable right and may not include proprietary analytics, security information, derived models, confidential information belonging to another person, or data that cannot be exported without adversely affecting another person’s rights.
Where we cannot fully satisfy a request, we will explain the general reason unless doing so would violate law, compromise security, or prejudice another person’s rights.
You may update information and preferences through the controls available within the Services.
KOMERRA uses technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, misuse, alteration, unauthorized disclosure, and unauthorized access.
Measures may include role-based authorization, tenant-isolation controls, authentication safeguards, short-lived sessions, multi-factor authentication, passkeys, encryption in transit, provider-managed encryption at rest, secure credential storage, secrets management, input validation, rate limiting, network controls, backups, audit trails, monitoring, vulnerability management, dependency review, and incident-response procedures.
Access to production systems and personal data is limited according to role, responsibility, and legitimate need.
We review and update safeguards according to the sensitivity and volume of information, the nature of processing, evolving threats, available technology, and the potential impact on individuals.
No electronic service, transmission method, storage system, or security control can guarantee absolute security.
Users share responsibility for protecting their Accounts by maintaining secure credentials, enabling available authentication safeguards, reviewing permissions, securing devices, and promptly reporting suspected unauthorized activity.
KOMERRA personnel and contractors may access personal data only where access is reasonably necessary for their authorized role, such as support, security, engineering, compliance, finance, or incident response.
Personnel with access to personal data are subject to confidentiality, security, acceptable-use, and access-control obligations appropriate to their responsibilities.
Access may be logged and reviewed for security, accountability, investigation, and compliance.
We seek to use least-privilege access, meaning that a person should receive only the access reasonably necessary for the assigned task.
Production access may be restricted, time-limited, approval-based, or otherwise controlled according to system sensitivity and operational need.
KOMERRA maintains procedures for identifying, assessing, containing, investigating, documenting, remediating, and learning from suspected personal-data incidents.
Where an incident affects information for which a business is the controller and KOMERRA is the processor, we will notify and assist the relevant business in accordance with the Data Processing Agreement and applicable law.
Where KOMERRA is the responsible controller and a breach is likely to create a legally relevant risk to individuals, we will notify the Nigeria Data Protection Commission within the applicable legal period.
Where a breach is likely to create a high risk to an affected person, we will communicate with that person as required, using clear language and providing available information about the incident, likely consequences, and reasonable protective steps.
A notification may be delayed or limited where law enforcement, a regulator, security considerations, or another lawful restriction requires it.
We maintain records of personal-data breaches, their effects, investigation, notifications, and remedial action as required.
KOMERRA seeks to consider privacy and data protection when designing or materially changing products, integrations, verification features, public pages, AI workflows, analytics, communications, and security controls.
We may conduct a Data Privacy Impact Assessment or similar risk assessment where processing may create a high risk to the rights and freedoms of individuals.
Higher-risk circumstances may include sensitive information, biometric verification, profiling, significant automated decisions, systematic monitoring, large-scale processing, innovative technology, e-commerce, financial workflows, processing involving vulnerable people, or cross-border transfers.
Risk assessments may consider necessity, proportionality, lawful basis, data minimization, transparency, access, retention, provider risk, security, individual rights, human review, and risk-reduction measures.
Where a proposed activity cannot be operated with an acceptable and lawful level of risk, we may change, restrict, delay, or discontinue the activity.
KOMERRA is designed as a business-management service and is not directed to children.
A child should not independently create or control a business Account unless an authorized adult or lawful representative has the authority to create the relationship and assume responsibility for the Account.
A business must not enter or process a child’s personal data through KOMERRA unless the business has a valid and lawful purpose, appropriate authority, necessary notices or consent, and safeguards suitable for the child.
Features involving children, education, guardianship, healthcare, employment, or another sensitive context may require additional legal and privacy review before use.
We may request evidence of age, parental responsibility, guardianship, or authority where reasonably necessary.
Contact support@komerra.app if you believe that a child’s information was provided to KOMERRA improperly. We will investigate and take appropriate action subject to applicable law and any valid retention requirement.
The Services may contain links to third-party websites, applications, payment pages, social-media services, delivery providers, or other external resources.
This Privacy Policy does not govern information collected independently by a third party after you leave KOMERRA or interact directly with that party.
You should review the third party’s privacy policy, terms, permissions, security practices, and contact information before providing personal data.
A link, integration, or embedded service does not mean that KOMERRA controls or endorses every aspect of the third party’s processing.
We may update this Policy to reflect changes to the Services, providers, processing activities, security practices, business operations, regulatory guidance, or applicable law.
The “last updated” or effective date will be changed when a revised Policy is published.
Where a change materially affects how personal data is processed or the choices available to users, we will provide appropriate notice through email, the dashboard, an application notification, a website notice, or another suitable channel.
Where required, we will request consent or provide an opportunity to make a new choice before materially different consent-based processing begins.
Previous versions may be retained for accountability and reference.
We encourage you to contact KOMERRA first so that we can understand and attempt to resolve a privacy concern promptly.
Send privacy complaints to support@komerra.app with “Privacy Complaint” in the subject and include the Account, Workspace, business, public page, transaction, or communication concerned.
You also have the right to lodge a complaint with the Nigeria Data Protection Commission where you believe personal data has been processed contrary to applicable data-protection law.
Submitting a complaint to KOMERRA does not remove your right to contact a competent regulator, pursue an available civil remedy, or use another lawful dispute-resolution process.
We will not retaliate against a person for making a genuine privacy request, raising a good-faith concern, or lodging a lawful complaint.
Make a privacy request
Contact support@komerra.app or use the contact form. Privacy and security reports are routed to the responsible team.