Legal
Privacy Policy
This policy explains how CIHAN AI DATA collects, uses, shares and protects information across three distinct populations: clients, contributors and research participants.
Last updated 15 September 2026
CIHAN AI DATA is operated by Cihan Business Solution Limited (RC 711803). Our practices are designed to support data-protection obligations under applicable Nigerian law, including the Nigeria Data Protection Act 2023 and applicable NDPC guidance, together with the contractual terms agreed with each client. We describe what we do; we do not claim blanket certification.
01Who this policy covers
We separate the people whose information we handle into three populations:
- Clients and prospects — organisations and their staff who enquire about, scope or run projects with us.
- Contributors and analysts — applicants and members of the Cihan AI Data Network™ who apply for, are assessed for, or perform work.
- Research participants and benchmark contributors — individuals who take part in calibration exercises, research studies or benchmark construction.
02Client and prospect data
- Account and contact details, role and organisation.
- Enquiry content, pilot briefs and project scoping information, including volumes, languages, timelines and quality requirements.
- Project datasets and instructions supplied to us by the client.
- Commercial and administrative records where a project proceeds.
Client project datasets are handled as confidential material under the applicable project terms. We do not mine client project data to build advertising profiles, and we do not sell personal data.
03Contributor and analyst data
- Application details: name, contact information, location, languages, domains, skills and experience.
- Availability, preferred task types and contact preferences.
- Agreement and status records, including NDA status and network standing.
- Certification, calibration and quality-assurance records, including agreement scores and reviewer feedback.
- Assignment history and, once commercial deployment begins, payment and administrative records.
Internal quality and audit records are used to run the network fairly — to route work, escalate review and support progression — and are visible to authorised internal roles.
04Research participant and benchmark data
- Study or calibration participation records and the responses given.
- Data collected by CIHAN under an approved project brief, with documented sourcing rules.
- Benchmark items, judgements and version records.
Research outputs are normally reported in aggregate or de-identified form. Where a study requires anything more, the participant information for that study explains it before participation.
05Technical and security data
When you use our website, client portal or contributor workspace we process authentication data, device and log data, and security events such as sign-in attempts. This supports account security, abuse prevention and service reliability. Analytics, if enabled, is used in aggregate to understand site usage.
06Why we use information
- To scope, deliver and support annotation, collection, evaluation and benchmark projects.
- For quality assurance, adjudication and reviewer escalation.
- To manage the contributor network: applications, assessment, calibration, assignment and progression.
- To administer research and benchmark work.
- For security, fraud prevention and service integrity.
- For billing, accounting and other administration where a project proceeds.
- To meet legal, regulatory and record-keeping obligations.
Where applicable law requires a legal basis, we rely on performance of a contract, legitimate interests in running and securing our operation, consent (for example for certain research participation or marketing), and compliance with a legal obligation.
07Client-supplied data
Where a client supplies datasets or instructions, the client warrants that it has the authority and rights to do so and that our processing under the project terms is lawful. We act on documented instructions, segregate project data, and restrict access to the personnel assigned to that project.
08Service providers and infrastructure
We use a limited set of providers to run the platform, which currently includes cloud hosting and database infrastructure, authentication services, and email or messaging for communications. Depending on configuration and project scope, this may also include analytics, payment providers, and AI infrastructure where a project expressly uses it. Providers act under contract and only for the purposes we specify.
09International transfers
Some infrastructure and providers operate outside Nigeria. Where information is transferred internationally, we use the safeguards available under applicable law, including contractual protections with the receiving provider, and we take account of project-specific data-residency requirements when they are agreed in writing.
10Retention
We retain information for as long as it is needed for the purpose it was collected for — the life of a project and its warranty period, the duration of network membership, the research record, or the period required for legal, tax and accounting obligations. Project data is returned or deleted in line with the applicable project terms.
11Withdrawal and its limits
Contributors and research participants can ask us to stop processing their information or to withdraw from a study. Some limits apply and we prefer to state them plainly:
- Results already de-identified or aggregated into research outputs generally cannot be traced back and removed.
- Work already incorporated into a completed commercial deliverable cannot be withdrawn from that deliverable.
- Legal, tax, accounting and dispute-related records must be retained for the required period.
12Your rights
Subject to applicable law, you may request access to your personal data, correction, deletion, restriction of or objection to processing, withdrawal of consent, and portability where it applies. You may also complain to the appropriate supervisory authority. Use the Privacy & Data Rights Request page to make a request; we may need to verify your identity before acting.
13Children
Our services are intended for organisations and adult professional contributors. We do not knowingly collect information from children, unless a specifically approved research programme states otherwise and operates under its own consent arrangements.
14Changes and contact
We will update this policy as our operation develops and will change the date at the top when we do. Questions can be sent to privacy@cihanmediacomms.com, our dedicated privacy contact.
