Compliance

Data & Compliance

Last updated: 25 May 2026

BuildLedger is committed to responsible data handling and compliance with applicable data protection regulations. This page outlines our security practices, regulatory posture, and your rights.

1. Our Compliance Commitment

Webxpress Technologies operates BuildLedger in accordance with applicable data protection and privacy laws, including the Nigeria Data Protection Act 2023 (NDPA) and, where applicable, the EU General Data Protection Regulation (GDPR).

We treat data protection as a core business obligation, not an afterthought.

2. Data Security Measures

2.1 Encryption

All data in transit is encrypted using TLS 1.2 or higher. Passwords are hashed using bcrypt with a minimum cost factor of 12. Sensitive configuration values are stored as environment variables, never in source code.

2.2 Access Controls

Access to production systems is restricted to authorised personnel only, using SSH key authentication. All API endpoints require authentication via Laravel Sanctum bearer tokens. Rate limiting is applied to authentication and payment endpoints to prevent brute-force attacks.

2.3 HTTP Security Headers

All responses include security headers: X-Content-Type-Options, X-Frame-Options, X-XSS-Protection, Referrer-Policy, Permissions-Policy, and Strict-Transport-Security (HSTS) on HTTPS connections.

2.4 Infrastructure

BuildLedger is hosted on dedicated VPS infrastructure. File uploads are stored on isolated storage with access-controlled signed URLs. Database and uploaded-file backups are performed regularly, encrypted before storage, and retained on a rolling schedule.

2.5 Backup Policy

  • Database snapshots are created daily during off-peak hours.
  • Uploaded files and company logos are included in the same encrypted backup archive.
  • Snapshots are encrypted before they are written to the backup disk.
  • Expired backups are pruned automatically after the retention window, which is 30 days by default.
  • Backups are intended for recovery, audit, and continuity purposes only and are not used for day-to-day access.

3. Data Residency

By default, BuildLedger stores data on servers located in Africa or Europe. We do not transfer personal data to jurisdictions without adequate data protection frameworks without appropriate safeguards (e.g. Standard Contractual Clauses).

4. Nigeria Data Protection Act (NDPA) 2023

As a Nigerian-operated platform, we comply with the NDPA 2023, which includes:

  • Lawful basis for all data processing activities.
  • Data subject rights: access, correction, deletion, portability, and objection.
  • Appointment of a Data Protection Officer (DPO) where required.
  • Data breach notification to the Nigeria Data Protection Commission (NDPC) within 72 hours of discovery.
  • Data Protection Impact Assessments (DPIAs) for high-risk processing activities.

5. GDPR (EU Users)

For users in the European Economic Area, we comply with GDPR requirements including:

  • Explicit lawful basis for processing (contract performance, legitimate interest, or consent).
  • Right to erasure (“right to be forgotten”).
  • Data portability in machine-readable format.
  • 72-hour breach notification to the relevant supervisory authority.

6. Third-Party Sub-processors

We use the following sub-processors to deliver the Service:

Sub-processorPurposeLocation
PaystackPayment processingNigeria / Global
FlutterwavePayment processingNigeria / Global
Cloud hosting providerServer infrastructureAfrica / EU
Email delivery providerTransactional emailEU / US

All sub-processors are bound by data processing agreements consistent with applicable law.

7. Data Breach Response

In the event of a data breach, we will:

  • Contain and assess the breach within 24 hours of discovery.
  • Notify affected users without undue delay if the breach poses a high risk to their rights.
  • Report to the NDPC (and relevant EU supervisory authority where applicable) within 72 hours.
  • Conduct a post-incident review and implement remediation measures.

8. Audit & Certifications

We conduct periodic internal security reviews. We are working towards formal compliance certifications and will update this page as certifications are obtained.

9. Contact Our DPO

For data protection enquiries, to exercise your rights, or to report a concern, contact our Data Protection Officer at dpo@buildledger.com.