Data & Compliance
Last updated: 25 May 2026
BuildLedger is committed to responsible data handling and compliance with applicable data protection regulations. This page outlines our security practices, regulatory posture, and your rights.
1. Our Compliance Commitment
Webxpress Technologies operates BuildLedger in accordance with applicable data protection and privacy laws, including the Nigeria Data Protection Act 2023 (NDPA) and, where applicable, the EU General Data Protection Regulation (GDPR).
We treat data protection as a core business obligation, not an afterthought.
2. Data Security Measures
2.1 Encryption
All data in transit is encrypted using TLS 1.2 or higher. Passwords are hashed using bcrypt with a minimum cost factor of 12. Sensitive configuration values are stored as environment variables, never in source code.
2.2 Access Controls
Access to production systems is restricted to authorised personnel only, using SSH key authentication. All API endpoints require authentication via Laravel Sanctum bearer tokens. Rate limiting is applied to authentication and payment endpoints to prevent brute-force attacks.
2.3 HTTP Security Headers
All responses include security headers: X-Content-Type-Options, X-Frame-Options, X-XSS-Protection, Referrer-Policy, Permissions-Policy, and Strict-Transport-Security (HSTS) on HTTPS connections.
2.4 Infrastructure
BuildLedger is hosted on dedicated VPS infrastructure. File uploads are stored on isolated storage with access-controlled signed URLs. Database and uploaded-file backups are performed regularly, encrypted before storage, and retained on a rolling schedule.
2.5 Backup Policy
- Database snapshots are created daily during off-peak hours.
- Uploaded files and company logos are included in the same encrypted backup archive.
- Snapshots are encrypted before they are written to the backup disk.
- Expired backups are pruned automatically after the retention window, which is 30 days by default.
- Backups are intended for recovery, audit, and continuity purposes only and are not used for day-to-day access.
3. Data Residency
By default, BuildLedger stores data on servers located in Africa or Europe. We do not transfer personal data to jurisdictions without adequate data protection frameworks without appropriate safeguards (e.g. Standard Contractual Clauses).
4. Nigeria Data Protection Act (NDPA) 2023
As a Nigerian-operated platform, we comply with the NDPA 2023, which includes:
- Lawful basis for all data processing activities.
- Data subject rights: access, correction, deletion, portability, and objection.
- Appointment of a Data Protection Officer (DPO) where required.
- Data breach notification to the Nigeria Data Protection Commission (NDPC) within 72 hours of discovery.
- Data Protection Impact Assessments (DPIAs) for high-risk processing activities.
5. GDPR (EU Users)
For users in the European Economic Area, we comply with GDPR requirements including:
- Explicit lawful basis for processing (contract performance, legitimate interest, or consent).
- Right to erasure (“right to be forgotten”).
- Data portability in machine-readable format.
- 72-hour breach notification to the relevant supervisory authority.
6. Third-Party Sub-processors
We use the following sub-processors to deliver the Service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Paystack | Payment processing | Nigeria / Global |
| Flutterwave | Payment processing | Nigeria / Global |
| Cloud hosting provider | Server infrastructure | Africa / EU |
| Email delivery provider | Transactional email | EU / US |
All sub-processors are bound by data processing agreements consistent with applicable law.
7. Data Breach Response
In the event of a data breach, we will:
- Contain and assess the breach within 24 hours of discovery.
- Notify affected users without undue delay if the breach poses a high risk to their rights.
- Report to the NDPC (and relevant EU supervisory authority where applicable) within 72 hours.
- Conduct a post-incident review and implement remediation measures.
8. Audit & Certifications
We conduct periodic internal security reviews. We are working towards formal compliance certifications and will update this page as certifications are obtained.
9. Contact Our DPO
For data protection enquiries, to exercise your rights, or to report a concern, contact our Data Protection Officer at dpo@buildledger.com.
