Controller and scope
HMJP Limited (RC1203744), trading as Enterprise IT, is responsible for the personal data it processes in operating this website, its private subdomain registry, public lookup, support, and compliance services. A registrar, hosting provider, or linked website may be an independent controller for its own activities.
This policy explains our practices for registrants, partner representatives, administrators, visitors, correspondents, and abuse reporters. Privacy enquiries and rights requests may be sent through the compliance desk or to support@enterprise.biz.ng, with “Privacy request” in the subject.
Information we process
| Category | Examples and source |
|---|---|
| Identity and contact | Name, organisation, email, telephone, address, and authority evidence supplied by you or your registrar. |
| Registration records | Domain, sponsoring registrar, transaction identifiers, status, dates, and DNS configuration. |
| Support correspondence | Your enquiry, reference number, replies, and information needed to resolve it. |
| Abuse and legal reports | Allegations, reported URLs, technical indicators, evidence, reporter details, and case updates. |
| Security and access | IP address, browser information, request timestamps, login events, and audit records. |
| Account credentials | Password hashes, authentication setup, and recovery information needed to secure authorised access. |
Do not submit unrelated personal information, passwords, private keys, or unlawfully obtained material. Evidence may contain information about other people; limit it to what is relevant.
Purposes and lawful grounds
We process information to administer registrations and accounts, respond to enquiries, maintain accurate records, investigate abuse, protect services, resolve disputes, and meet legal obligations.
Contractual necessity may apply to a registrant or partner service. Legitimate interests may support security, abuse investigation, and responding to correspondence, after considering the impact on individuals. Legal obligations apply where information must be retained or disclosed. Consent is used where specifically requested for an optional purpose and may be withdrawn without affecting earlier lawful processing.
The applicable framework includes the Nigeria Data Protection Act, 2023. We do not treat merely visiting this policy as consent to unrelated processing.
Registration data and public lookup
Public lookup is designed to show operational facts such as a domain’s status, dates, nameservers, and sponsoring registrar. It is not a public address book for registrants or reporters. Personal contact fields may be withheld or redacted.
Requests for non-public registration data are assessed for purpose, lawful basis, necessity, proportionality, and the rights of affected people. See the Registration Data and RDAP Policy. A person’s ability to submit a request does not guarantee disclosure.
Recipients and service providers
Information may be shared as necessary with the sponsoring registrar, infrastructure and security providers, professional advisers, or authorities with a valid legal basis. Limited report information may be provided to the affected operator so that an allegation can be answered.
Cloudflare provides network and security services. Google Fonts supplies fonts requested by the website; those requests disclose network information, including an IP address, to that provider. Providers process information according to their role and applicable terms.
We do not sell personal data. Access is limited according to operational need, confidentiality, and the purpose for which information is shared. A lawful business transfer may require controlled disclosure subject to continuing privacy obligations.
International processing
Network delivery, support, or infrastructure providers may process information outside Nigeria. Before a restricted transfer, the appropriate legal basis and safeguards must be assessed, including the recipient’s protections and applicable contractual measures.
A domain’s Nigerian suffix does not mean every network request or service record stays in Nigeria. Contact us for information about safeguards relevant to your data.
Retention and deletion
We retain information only for as long as reasonably necessary for its purpose and applicable legal requirements.
| Record | Retention considerations |
|---|---|
| Registration and transaction data | Active service, lifecycle reconciliation, applicable registry obligations, and legal claims. |
| Enquiries and correspondence | Resolution, necessary follow-up, and evidence of the service provided. |
| Abuse evidence and case records | Investigation, review, prevention of recurring harm, and legal preservation requirements. |
| Security and audit records | Detection, accountability, incident investigation, and protection of accounts. |
| Backups | The backup rotation and any applicable preservation hold. |
These criteria do not create an indefinite retention entitlement. When the relevant purpose ends, records are deleted or anonymised subject to legal holds and backup rotation. Ask the privacy contact for the period or criteria applicable to a specific record. Deletion from active systems may precede expiry from protected backups.
Security and incidents
We use access controls, secured transport, authentication protections, and audit records appropriate to the service. Evidence and administrative functions are restricted to authorised access. No internet service can eliminate every security risk.
Report a suspected exposure promptly through the contact page. Include enough information to locate the issue without sending passwords or exploiting the vulnerability further. We assess incidents and make notifications to the Nigeria Data Protection Commission and affected individuals where required by law.
Your rights and requests
Depending on applicable law and the circumstances, you may request access, correction, deletion, restriction, portability, or objection to processing. You may withdraw consent for an optional purpose and challenge a decision based solely on automated processing where the law provides that right.
Send a request describing the information or service concerned and the outcome sought. We may seek proportionate identity or authority evidence, using a secure channel where needed. We respond within applicable statutory periods and explain any lawful refusal, extension, or information withheld to protect another person’s rights.
A data request does not automatically cancel contractual or legal retention duties. Registration-data corrections should also be submitted to the sponsoring registrar.
Cookies, children, and external services
The website uses essential session and security mechanisms. The Cookie Policy explains their purpose and your controls. Optional analytics or advertising is not a condition of reading the site.
Services are intended for people with capacity to enter the relevant agreement or an authorised representative. If you believe a child’s information has been submitted without an appropriate basis, contact the privacy desk. External sites and registrar portals have their own privacy notices.
Complaints and policy updates
Raise concerns with our privacy contact using the details in Section 1. You may also complain to the Nigeria Data Protection Commission or another competent authority without first exhausting our internal process.
The version and dates above identify this notice. Material changes to processing will be explained through the appropriate website or service channel, with a new consent request where consent is required.