Privacy Policy
Last updated: 1 August 2026
1. Introduction
This Privacy Policy explains how FlexiGrid Solutions(“FlexiGrid”, “we”, “us” or “our”) collects, uses, shares and protects personal data. We are the data controller for the personal data described in this policy.
Our registered details: FlexiGrid Solutions Ltd, RC 8642152, Plot 1366, Edmund Madani Crescent, Abuja, FCT, Nigeria.
We process personal data in accordance with the Nigeria Data Protection Act (NDPA) 2023 and the guidance of the Nigeria Data Protection Commission (NDPC). By using our website or any of our products, you agree to the practices described here. If you do not agree with this policy, please do not use our services.
2. Services covered by this policy
This single policy applies across everything FlexiGrid Solutions operates:
- Our website— flexigridsolutions.com, including the contact form and any enquiry you send us.
- Haske— our online Islamic school, on which guardians create an account, add the students in their care, and select teachers for them.
- PassGuard— our event planning platform, on which users create events and share them with other people.
- Client engagements— the software development, web, mobile and cloud services we deliver to business clients.
Where a product has its own additional privacy notice, that notice sits alongside this policy and, in the event of a conflict on a point specific to that product, prevails.
3. Personal data we collect
3.1 Website visitors
- Contact form submissions— your name, email address, subject and the content of your message. We receive this so that we can reply to your enquiry.
- Technical data— IP address, browser type and version, device type, referring page and timestamps, recorded automatically in server logs by our hosting provider for security and reliability purposes.
3.2 Haske — guardians
Only an adult aged 18 or over may open an account. From a guardian we collect: full name, email address, phone number, a password (stored in hashed form), the students they add to their account, lesson bookings, and billing information needed to take payment.
3.3 Haske — students under 18
Students under 18 cannot register themselves. A guardian creates the account and adds each student. For a student profile we collect only what is needed to deliver lessons: the student’s name (or preferred name), age or age range, learning level, lesson schedule, attendance, and progress notes recorded by their teacher.
3.4 Haske — teachers
In addition to name, email address, phone number and password, teachers provide:
- Professional information— qualifications, certifications and credentials (including ijazah or equivalent where applicable), teaching experience, languages spoken, availability, a written biography and a profile photograph. Parts of this are displayed publicly on the teacher’s profile so that guardians can choose a teacher.
- Payout information— bank account or mobile money details and, where required by law, tax identification details, so that we can pay teachers for lessons delivered.
3.5 PassGuard
- Account data— name, email address, password and profile details.
- Event content— the events you create, including title, description, date, time, location, images and any other details you add.
- Data shared with other users— when you share an event, the details of that event and your identity as its organiser become visible to the people you share it with, and to anyone they forward a public share link to. Please do not put information in an event that you would not want those recipients to see.
- Guest and invitee details— where an organiser uploads or enters names, email addresses or phone numbers of guests, we process that data on the organiser’s behalf. The organiser is responsible for having a lawful basis to share those people’s details with us.
- Usage data— RSVPs, check-ins and other interactions with an event.
3.6 Client engagements
For business clients we process contact details of the individuals we work with, contract and billing information, and correspondence. Where a client gives us access to their own systems or data during a project, we act as a data processor on that client’s instructions and under the terms of our engagement contract.
4. How we use personal data
- To respond to enquiries and provide quotations.
- To create and administer accounts, and to authenticate users.
- To deliver the services requested — matching students with teachers, scheduling and running lessons, creating and sharing events.
- To process payments and pay teachers.
- To send service messages such as booking confirmations, event notifications, security alerts and changes to our terms.
- To maintain the security, integrity and availability of our systems, and to prevent fraud and abuse.
- To improve our services, diagnose faults and understand how our products are used.
- To comply with legal, regulatory, accounting and tax obligations.
- To send marketing communications, where you have opted in. You can withdraw at any time using the unsubscribe link or by emailing us.
We do not sell your personal data, and we do not use it for automated decision-making that produces legal or similarly significant effects on you.
5. Lawful basis for processing
Under the NDPA 2023 we rely on the following lawful bases:
- Consent— for marketing communications, non-essential cookies, and a guardian’s consent to the processing of a child’s data.
- Performance of a contract— to provide the services you or your organisation have asked us for.
- Legitimate interests— to secure our platforms, prevent abuse, improve our products and run our business, where those interests are not overridden by your rights.
- Legal obligation— to meet tax, accounting, regulatory and law-enforcement requirements.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before you withdrew.
6. Children’s data
Haske is designed to be used by children under the supervision of an adult, and we take particular care with their data:
- Children under 18 cannot create an account. Only a parent or legal guardian aged 18 or over may register.
- The guardian adds each student to their own account and, in doing so, provides consent to the processing of that student’s data as required by the NDPA 2023.
- We collect only the minimum data needed to deliver lessons, and a student profile is never made publicly searchable.
- The guardian may at any time review, correct, export or request deletion of the data held about a student in their care, by contacting us at info@flexigridsolutions.com.
- Teachers may see only the student information necessary to teach the lessons they have been booked for.
Our website, PassGuard and our client services are not directed at children. If we learn that we have collected a child’s data through those services without appropriate guardian consent, we will delete it.
7. Cookies and analytics
Our website currently uses only essential cookies— those needed to serve the site securely and remember basic preferences. We do not currently run third-party analytics, advertising, or cross-site tracking on this website.
Our product platforms use essential cookies and similar technologies to keep you signed in and to protect your account. If we introduce analytics or any non-essential cookies on the website or in a product, we will update this section and ask for your consent before those cookies are set.
You can control or delete cookies through your browser settings. Blocking essential cookies may stop parts of our services from working.
8. Sharing your data
We share personal data only where necessary, and only with:
- Service providers— hosting and cloud infrastructure, email delivery, error monitoring and customer support tools, acting on our instructions under written agreements.
- Payment providers— licensed payment processors handle card payments and teacher payouts. Payment card and full bank details are submitted directly to the provider; we do not store full card or bank account numbers on our systems.
- Other users— teachers and guardians see the information needed to arrange and deliver lessons; PassGuard shares event details with the people an organiser shares an event with.
- Professional advisers— accountants, auditors and lawyers, bound by confidentiality.
- Authorities— where we are required to disclose data by law, court order or a valid regulatory request.
- A successor— if our business or part of it is sold or reorganised, under equivalent protections. We will notify you if this affects your data.
We never sell or rent personal data to third parties.
9. International transfers
Some of our providers store or process data outside Nigeria. Where personal data is transferred abroad, we do so only in line with the NDPA 2023 — to a country with adequate protection, or under contractual safeguards, or with your consent — and we remain responsible for its protection.
10. Retention
We keep personal data only as long as needed for the purposes set out in this policy, or as long as the law requires. In practice:
- Contact form enquiries: up to 24 months after our last correspondence.
- Account and lesson records: for the life of the account, then up to 12 months after closure, unless a longer period is required.
- Financial and tax records: for the period required under Nigerian law.
- Server logs: typically 90 days.
When data is no longer needed we delete it or irreversibly anonymise it.
11. Security
We apply appropriate technical and organisational measures, including encryption of data in transit, hashed passwords, role-based access controls, least-privilege access for staff and teachers, and regular updates to our systems. No online service can be completely secure, but we work to protect your data and will notify you and the NDPC of a personal data breach where the law requires it.
12. Your rights
Under the NDPA 2023 you have the right to:
- Access the personal data we hold about you and be told how we use it.
- Have inaccurate or incomplete data corrected.
- Request deletion of your data where there is no continuing lawful reason for us to keep it.
- Restrict or object to certain processing, including direct marketing.
- Receive your data in a portable, machine-readable format.
- Withdraw consent at any time, where we rely on consent.
- Lodge a complaint with the Nigeria Data Protection Commission (NDPC).
To exercise any of these rights, email info@flexigridsolutions.com. We will respond within the time allowed by law, normally within 30 days. We may ask you to verify your identity first. Guardians may exercise these rights on behalf of the students in their care.
13. Changes to this policy
We may update this policy as our services develop or the law changes. The “last updated” date at the top shows when it last changed. Where a change is significant, we will give notice by email or through our services before it takes effect.
14. Contact us
For any question about this policy or about how we handle your data, contact us at info@flexigridsolutions.com, or write to us at Plot 1366, Edmund Madani Crescent, Abuja, FCT, Nigeria.
See also our Terms and Conditions and our Pricing Policy.