01Who we are and scope
TT Design & Concepts (“TT”, “we”, “us” or “our”) provides website and e-commerce development, software development, authorised cybersecurity, branding, social-media and SEO services, technical support, digital products, affiliate programmes, campaign tools and related consulting. This policy explains how we process personal data through ttdesignconcepts.com, WordPress forms, WooCommerce, SliceWP, TT companion plugins, email, WhatsApp and project delivery.
Controller contactFor privacy questions or requests, email hello@ttdesignconcepts.com. Do not send passwords, payment PINs, recovery codes or highly sensitive documents through an ordinary email or contact form.
03How information is obtained
We receive data directly from you, from a person authorised to act for your organisation, when a referred customer uses an affiliate link or code, through WooCommerce and connected forms, and from technical systems used to operate and secure the website. We may also receive limited information from payment gateways, booking providers, email platforms, social networks, hosting providers and public business sources where appropriate.
04Purposes and lawful bases
We process personal data only where there is an appropriate lawful basis, including performance of a contract or steps requested before a contract, consent, compliance with legal obligations, protection of vital interests where relevant, and legitimate interests that are not overridden by your rights.
- Responding to enquiries, preparing quotations and delivering contracted work.
- Creating accounts, processing orders, managing licences, downloads, referrals and commissions.
- Operating Spin & Win, verifying entries, preventing duplicate or abusive participation and managing claims.
- Protecting websites, accounts, users and infrastructure from fraud, malware, misuse and unauthorised access.
- Maintaining records, resolving complaints, enforcing agreements and meeting tax, accounting or legal requirements.
- Improving services, measuring website performance and developing new features using aggregated or appropriately protected data.
05Service-specific processing
Different TT services require different information:
- Cybersecurity and account recovery: we may request proof of ownership, authorisation, incident evidence, account identifiers and limited logs. We do not request passwords, OTPs or payment PINs through public forms.
- WooCommerce and developer products: order, licence, download and support records may be retained to provide access and updates.
- Appointments and forms: information is used to schedule the session, prepare for the call and follow up on the requested service.
- Testimonials: WhatsApp screenshots or client feedback are published only with permission or after appropriate redaction.
06Marketing choices
Campaign entry, service delivery and marketing consent are separate. You may participate in a campaign or request a service without agreeing to promotional messages unless marketing is essential to the specific service you requested.
- Marketing is sent only where we have consent or another lawful basis.
- You may unsubscribe through the message link or email us at any time.
- Withdrawing marketing consent does not stop necessary transactional, security, account, claim or project messages.
- We do not sell personal data to advertisers.
07Cookies and similar technologies
We use cookies, signed tokens, local storage and comparable technologies for login sessions, carts, affiliate attribution, saved Brand Builder projects, campaign anti-abuse controls, preferences, security and—where enabled—analytics or advertising measurement. Non-essential cookies should be controlled through the website consent tool. See the Cookie Policy for details.
08Sharing and processors
We share personal data only as reasonably necessary with service providers acting for us, such as hosting and cloud providers, WordPress/WooCommerce extensions, SliceWP, email and SMTP providers, booking platforms, payment gateways, analytics providers, security services, professional advisers and approved project collaborators.
We may also disclose information where required by law, to protect rights or safety, to investigate fraud, or as part of a business restructuring. Each independent provider may also process data under its own privacy notice.
09International transfers
Some providers or project collaborators may operate outside Nigeria. Where personal data is transferred internationally, we will use an available lawful transfer mechanism and reasonable contractual, organisational or technical safeguards. Contact us if you want information about the safeguards relevant to a particular service.
10Security and incident response
We use proportionate controls such as access restriction, role-based permissions, secure hosting, encryption in transit, backups, signed claim links, hashed identifiers, rate limits, malware protection and staff or contractor confidentiality obligations. No online system is completely risk-free.
If a personal-data incident creates a material risk, we will investigate, contain it, preserve relevant records and make notifications required by applicable law.
11Retention periods
We keep information only for as long as reasonably needed for the relevant purpose, dispute resolution, security, contracts and legal obligations. Our working schedule is:
- General enquiries and unsuccessful proposals: normally up to 24 months after the last meaningful contact.
- Client contracts, invoices, orders, commission and payout records: up to seven years after the relevant transaction or longer where law requires.
- Campaign entries, claims and consent records: normally up to 24 months after the campaign; shorter-lived device and risk signals may be deleted or irreversibly aggregated earlier.
- Unclaimed or expired magic links and verification tokens: deleted or invalidated promptly after expiry.
- Brand Builder projects and generated kits: normally up to 24 months unless the user deletes them sooner or a longer period is required for an active service.
- Security logs and support records: retained according to risk, contractual and incident-response needs.
12Your data-protection rights
Subject to applicable law and any valid limitations, you may request access, correction, deletion, restriction, objection, portability, withdrawal of consent and information about automated processing. You may object at any time to direct marketing.
To make a request, email hello@ttdesignconcepts.com with the subject “Data Rights Request”. We may need to verify your identity and will not disclose another person’s data. We will respond within the period required by law and explain any lawful reason we cannot fully comply.
13Children and sensitive data
TT services are intended primarily for adults and businesses. A person under 18 should use the website only with appropriate parent or guardian involvement. Do not send health, biometric, government-identity, financial-authentication or other sensitive data unless TT has specifically requested it through an approved secure channel and explained why it is needed.
14Complaints and policy changes
Contact us first so we can investigate a concern. You may also complain to the Nigeria Data Protection Commission or another competent regulator where applicable. We may update this policy to reflect legal, service or technical changes. The updated date will appear at the top, and material changes may be highlighted through the website or direct communication.