THE OHRES MASTER PRIVACY POLICY & DATA PROTECTION FRAMEWORK
COMPLIANCE NOTICE FOR PAYMENT GATEWAYS AND UNDERWRITERS: THIS POLICY MANDATES THE EXPLICIT PRIVACY PATHWAYS ENFORCED BY THE OHRES COGNIZANT OF ITS DATA ROUTING PATHWAYS BETWEEN OHRES INC. (corporate body) AND THE OPERATING SUBSIDIARY IN NIGERIA.
1. OVERVIEW AND DATA CONTROLLER SEPARATION
THE OHRES ("we", "us", or "our") respects the privacy and data integrity of our corporate subscribers, enterprise clients, logistics coordinators, and trading partners. Under the regulatory mandates of the Nigeria Data Protection Act (NDPA), the specific data controllers are structurally ring-fenced as follows:
Regional Data Controller
THE OHRES LTD (RC 9626254) ("Operating Subsidiary") acts as the primary onshore data collector for local KYC verification, Paystack merchant processing, and local Nigerian customs platform interactions.
Infrastructure Data Processor
OHRES INC. (corporate body) and its offshore nodes act strictly as technical cloud processors, hosting the underlying THE OHRES Electronic Data Interchange (EDI) and Value-Added Network (VAN) routing infrastructure.
2. CATEGORIES OF DATA WE COLLECT
To seamlessly orchestrate cross-border trade and automate supply chain compliance, we process the following categories of information:
A. Corporate Identification & KYC Data: Legal business entity names, corporate registration numbers (e.g., CAC filings), tax identification numbers (TIN), corporate email addresses, and authorized executive profile credentials.
B. Commercial & EDI Transaction Data: Data embedded within electronic trade documents routed via our APIs, including Purchase Orders (EDI 850), Commercial Invoices (EDI 810), Shipping Instructions (EDI 304), Bill of Lading manifests, and Harmonized Tariff Schedule (HTS) data.
C. Financial Information: Local bank account details, routing codes, corporate billing tokens, and transactional metadata passed via our integrated payment gateways (such as Paystack).
D. Technical Infrastructure Metadata: IP addresses, cryptographic communication tokens, AS4/AS2 routing handshakes, API authorization logs, and firewall event registries.
3. LEGAL BASES FOR PROCESSING INFORMATION
In accordance with Section 25 of the NDPA and Article 6 of the GDPR, THE OHRES processes data under the following strict legal parameters:
Performance of a Contract: Processing is strictly required to execute our Master Software Licensing Agreement, parse your custom API payloads into compliant EDIFACT/X12 files, and route them to selected ocean carriers or customs boards.
Legal Obligation: Processing required to ensure compliance with the Central Bank of Nigeria (CBN) foreign exchange reporting rules, anti-money laundering (AML) laws, and automated customs compliance.
Legitimate Interests: Operating and hardening our cloud trade architecture against malicious code injection, unauthorized data leaks, and system vulnerability threats.
4. DATA RETENTION AND DISPOSAL LOGIC
Transactional Logs: Because shipping lines and customs agencies require historical validation during audit windows, all raw EDI files and processed transmission schemas are stored securely for a mandatory period of seven (7) years following the transaction date.
Technical Metadata: Server communication logs, API performance telemetry, and system token registries are automatically rotated, compressed, or anonymized after ninety (90) days.
Complete Account Erasure: Upon formal termination of your corporate enterprise tier, and subject to overriding sovereign cross-border customs or financial archiving laws, all operational account profiles will be permanently purged from active relational databases within thirty (30) business days.
5. CROSS-BORDER DATA TRANSFERS & DEPLOYMENT RAILS
As an international digital trade pipeline operating between Canada and African trade hubs, data collected within Nigeria is securely routed to our cloud architecture nodes.
Safe Harbor Frameworks: In absolute compliance with the cross-border transfer conditions set forth in the NDPA, all data transferred to our Canadian infrastructure layer is covered under mutual corporate data transfer agreements utilizing strict security protocols. Canada is recognized globally as providing adequate data protection safeguards, ensuring your enterprise assets remain uncompromised.
6. CRYPTOGRAPHIC DATA SECURITY ARCHITECTURE
THE OHRES implements institutional-grade, multi-layered security infrastructure to insulate your trade data against external intrusion:
Encryption Controls: All corporate data is encrypted at rest using industry-standard AES-256 protocols and in transit utilizing Transport Layer Security (TLS 1.3) or cryptographically signed AS4 packaging.
Access Segregation: Staff within our regional operating sub-entities have zero access to the underlying encryption keys or data silos of our master cloud database layers, preventing localized insider leaks.
Vulnerability Management: We run continuous automated penetration tests and payload filtering across all public API gateways to detect and isolate structural platform attacks instantly.
6a. INTELLECTUAL PROPERTY STATEMENT
THE OHRES' intellectual property including the EDI platform, Smart-HTS engine, Voice-to-EDI technology, and all associated patents and trademarks is held by a designated IP holding entity and licensed to group operating companies worldwide.
7. DATA SUBJECT RIGHTS
If your corporate data contains personally identifiable information of individual workers, directors, or agents subject to the protection of the NDPA or GDPR, those individuals possess the right to:
- Access and review the exact data files logged in our corporate profile
- Request immediate rectification of broken, outdated, or misaligned personal data
- Object to or restrict specific processing steps where it does not overwrite contract execution requirements
- Lodge a formal structural complaint with the Nigeria Data Protection Commission (NDPC) if they believe their statutory privacy rights have been infringed
To exercise these rights, your corporate legal desk must file a formal electronic query directly to our dedicated processing inbox: [email protected]
8. CHANGES TO THIS PRIVACY POLICY
THE OHRES reserves the right to modify this Privacy Policy at any time to reflect real-time updates in regional customs protocols, NDPA regulatory guidelines, or our intercompany infrastructure routing. Any material changes will be broadcast to our system dashboards and updated across our primary domain.
CONTACT INFORMATION
Master Corporate & IP Structure Inquiries
Entity: OHRES INC. (corporate body)
Email: [email protected]
Regional Operational & Payment Gateway Inquiries
Entity: THE OHRES LTD (RC 9626254)
Email: [email protected]
Phone: +234 201 330 9444
Operational Office: Lagos, Nigeria
By using THE OHRES Services, you acknowledge that you have read, understood, and agree to be bound by this Master Privacy Policy & Data Protection Framework.
End of Privacy Policy