Nigeria Data Protection Act (NDPA) 2023 Certified

Data Privacy & Security Statement

How ACE ICT Consult safeguards employee personal data, ensures zero credential harvesting, and maintains strict regulatory compliance across the CyberACE platform.

Operator: ACE ICT Consult • Effective Date: October 2026 • aceictconsult.com

Zero Passwords Saved

When employees interact with simulated phishing forms, all entered credentials are discarded immediately at memory runtime. Passwords are never written to databases, logs, or disk.

Purely Educational

Our platform is designed strictly for organizational capability building and positive coaching — not punitive surveillance or unconsented tracking.

NDPA 2023 Lawful Basis

Fully compliant with Nigerian data protection legislation and international privacy standards (GDPR, ISO 27001), operating under legitimate organizational security interest.

1 Corporate Identity & Scope of this Policy

CyberACE is a proprietary enterprise cybersecurity awareness and simulated phishing training suite conceived, engineered, and maintained by ACE ICT Consult (official website: aceictconsult.com).

This Data Privacy Policy details how ACE ICT Consult collects, processes, and protects personal data pertaining to corporate personnel, enterprise administrators, and learners who use the CyberACE web application or participate in authorized cybersecurity simulations conducted on behalf of contracted partner organizations.

We process information solely in our designated capacity as a Data Processor acting on behalf of your employer (the Data Controller), under strict compliance with the Nigeria Data Protection Act (NDPA) 2023 and applicable global data protection principles.

2 The Zero Credential Harvesting Guarantee

Uncompromising Architectural Rule:

At no point does the CyberACE platform intercept, capture, store, log, or record actual employee passwords submitted during simulated phishing engagements.

During simulated phishing scenarios mimicking credential harvesting pages (such as Microsoft 365, Google Workspace, or banking login interfaces), the input fields are intercepted by our simulation receiver controller:

  • The system records a binary boolean event: submitted = true.
  • The raw password string is wiped immediately from the volatile HTTP request memory.
  • No database columns exist for learner passwords, nor are credentials saved to server error or access logs.
  • The learner is immediately redirected to a secure Teachable Moment coaching page that reinforces defensive hygiene.

3 Categories of Personal Data Processed

To deliver structured learning curricula and assess organizational resilience, we process only the minimum necessary data points:

Corporate Identity Data

  • • Employee Full Name
  • • Official Corporate Email Address
  • • Department or Organizational Unit
  • • Assigned Role (Super Admin, Admin, Manager, Learner)

Training & Simulation Telemetry

  • • Course lesson completion timestamps
  • • Comprehension quiz attempts and percentage scores
  • • Corporate policy acknowledgement signatures & timestamps
  • • Phishing metrics: Delivered, Clicked, Submitted, Reported

4 Security Safeguards & Cryptographic Standards

ACE ICT Consult implements robust organizational and technical safeguards compliant with international information security baselines:

  • Encryption in Transit: All communication between end-user browsers and CyberACE servers is enforced via TLS 1.3 encryption with strict HTTP Strict Transport Security (HSTS).
  • Data At Rest: Relational datastores and database backups are encrypted utilizing AES-256 standards.
  • Granular Access Control: Strict Role-Based Access Control (RBAC) isolates company-specific records. Managers cannot view data outside their assigned organizational groups.
  • Audit Logging: Administrative operations (such as campaign launches, password resets, and user role promotions) are immutably logged for audit verification.

5 Learner & Employee Data Subject Rights

Under the Nigeria Data Protection Act (NDPA) 2023, every employee whose data is processed by CyberACE retains enforceable rights:

Right to Information Transparent visibility into why awareness drills are conducted and what metrics are logged.
Right of Access Full access to training certificates, quiz results, and acknowledged policy documents.
Right to Rectification Correction of inaccurate names, job roles, or erroneous group assignments via enterprise admins.
Dispute Mechanism Channel to contest false-positive simulation clicks triggered by automated mail security gateways.

6 Contact Our Data Protection Office

If you have questions regarding this privacy statement, NDPA 2023 compliance, or data subject inquiries concerning CyberACE, please reach out to the dedicated data privacy desk at ACE ICT Consult:

Corporate Website aceictconsult.com

ACE ICT Consult Official Web Portal

Data Protection Officer dpo@aceictconsult.com

Regulatory inquiries & NDPA compliance

Security & Support support@aceictconsult.com

Platform technical operations

Return to CyberACE Platform