How OneCluster Ltd collects, uses and protects personal data, in line with the Nigeria Data Protection Act 2023 and the GDPR where it applies.
Last updated 10 August 2026 · OneCluster Ltd, registered in Nigeria
OneCluster Ltd is a company registered in Nigeria with its office in Lagos. We are the data controller for personal data collected through this website and through our client and recruitment relationships. Contact us at privacy@onecluster.co.
We do not collect special category data, and we ask that you do not include it in free-text fields.
Enquiry data is kept for twenty-four months from last contact. Recruitment data is kept for twelve months from the close of the process unless you ask us to delete it sooner or consent to a longer period. Client engagement records are kept for the duration of the contract plus seven years where required for tax and audit purposes. Server logs are kept for ninety days.
We share personal data with service providers who process it on our behalf under written agreement: our email and productivity provider, our website host, and our applicant tracking tooling. We do not sell personal data and we do not share it for third-party advertising. We may disclose data where required by law, regulation or a valid order of a competent court.
Some of our processors operate outside Nigeria. Where personal data is transferred abroad we rely on an adequacy determination by the Nigeria Data Protection Commission, standard contractual clauses, or your explicit consent, and we assess the protections in place before transferring.
Subject to the conditions in applicable law, you may request access to your personal data, correction of inaccurate data, deletion, restriction of processing, portability, and you may object to processing based on legitimate interest. Where processing relies on consent you may withdraw it at any time without affecting prior processing.
To exercise a right, email privacy@onecluster.co. We respond within thirty days. If you are not satisfied you may complain to the Nigeria Data Protection Commission, or to your local supervisory authority if you are in the EEA or UK.
We apply access controls, encryption in transit, least-privilege administration and vendor due diligence appropriate to the sensitivity of the data. No system is perfectly secure, and we will notify you and the relevant regulator of a qualifying breach within the periods required by law.
This website is not directed at children and we do not knowingly collect data from anyone under eighteen.
We may update this policy. Material changes will be signalled by the date at the top of this page, and where the change is significant we will notify affected individuals directly.