Airsense Outsourcing

Privacy Policy

How Airsense handles personal data as a controller

Document ownerAirsense Bridge Limited
Versionv1.0
Effective date31 August 2026
Last updated13 August 2026
StatusPublished

About this notice. This Privacy Policy explains how Airsense Outsourcing, under Airsense Bridge Limited, handles Personal Data as an independent Data Controller for example, data about Website visitors, prospective clients, business contacts, vendors, employees, contractors and job applicants.

Where Airsense instead handles Personal Data on behalf of a Client (as a Data Processor or Subprocessor) to deliver outsourcing services, that Processing is governed by the Client's own privacy notice and the Data Processing Agreement (Document 5), not by this Policy. See section 3.

1.Who we are

1.1Airsense Outsourcing ("Airsense", "we", "us", "our") is a business process outsourcing (BPO) and customer experience (CX) company. Registered entity name under parent company: Airsense Bridge Limited. Registered address: Surulere, Lagos State, Nigeria. Company/CAC number: RC-9660686.
1.2For Personal Data we control, we are the Data Controller. Our data protection contact is set out in section 18. Data Protection Officer:info.compliance.airsenseinc.com .
1.3Scope of law. We process Personal Data in accordance with the Nigeria Data Protection Act 2023 (NDPA) and applicable NDPC guidance. Where our processing, clients or Data Subjects fall within their scope, we also take account of the EU GDPR, the UK GDPR and UK Data Protection Act 2018, and the CCPA/CPRA and other US state privacy laws. This Policy uses NDPA concepts, noting GDPR/CCPA equivalents where helpful.

2.Summary

In short: we collect Personal Data to run our business, provide and market our services, recruit, meet legal obligations and keep our systems secure. We rely on recognised lawful bases, share data only with parties who need it, apply safeguards to international transfers, keep data only as long as needed, and respect the rights available to individuals under Applicable Law. The detail follows.

3.Controller data vs client (processor) data

3.1When we are a Controller. We decide the purposes and means of Processing for data about our Website visitors, prospects, business contacts, vendors, marketing contacts, employees, contractors and job applicants, and our own business records. This Policy governs that Processing.
3.2When we are a Processor/Subprocessor. When we deliver outsourcing services (for example customer support, growth and community, business operations), we Process Personal Data about our Clients' Customers on the Client's documented instructions. For that Processing, the Client is the Controller and is responsible for the applicable privacy notice and lawful basis; we act as Processor/Subprocessor under the DPA. Individuals with questions about that data should contact the relevant Client (the organisation whose service they were using).
3.3The controller/processor allocation for each activity is analysed in the Controller/Processor Analysis (Document 12).

4.Personal data we collect

Depending on the relationship, we may collect the following categories of Personal Data (as a Controller):

CategoryExamples
IdentityName, user ID, company/employer, job title
ContactBusiness email, telephone number, business address
ProfessionalEmployer, role, CV/résumé, qualifications, work history
AccountLogin credentials, account identifiers, settings and preferences
TransactionBilling details, payment records, transaction history
CommunicationsEmails, chat messages, call recordings/notes, support tickets, feedback
TechnicalIP address, browser, device, operating system, cookies and similar technologies, server logs, usage data
RecruitmentApplication data, CV, interview notes, references (where provided)
MarketingPreferences, subscription status, engagement with our communications
4.1Client Customer data. Separately, and only as a Processor on a Client's behalf, we may handle Personal Data about the Client's Customers as needed to deliver the Services. The categories depend on the Client's instructions and are recorded in the DPA and its processing annex.

5.Sensitive / special-category data

5.1We do not seek to collect sensitive or special-category Personal Data (such as data revealing health, biometric, or similar sensitive information) about our business contacts, prospects or applicants as a matter of routine.
5.2Where sensitive Personal Data is genuinely necessary (for example limited HR-related information about our own personnel, or Client Customer data handled on instruction as a Processor), we apply enhanced safeguards and process it only where permitted by Applicable Law and, where required, with an appropriate lawful basis or explicit consent. We ask that you do not send us sensitive Personal Data unless we specifically request it.

6.How we collect data (sources)

We collect Personal Data from: the individuals themselves (forms, emails, calls, meetings); our Clients and their systems; employers, partners and vendors; public and professional sources (for example business directories and professional networks); the Website and cookies; recruitment channels and referrers; and our own technology and security systems.

7.Why we process data and our legal bases

The table below sets out our main Controller purposes, the data used, the lawful basis under the NDPA (with GDPR equivalents where relevant), and our role. Legal bases must be confirmed against final processing activities by counsel/DPO.

PurposeData usedLawful basisRole
Service delivery & account management (direct clients)Identity, contact, account, communications, transactionContract; legitimate interestsController
Client & prospect relationship management (CRM)Identity, contact, communicationsLegitimate interests; consent (where required)Controller
Sales & business developmentIdentity, contact, professionalLegitimate interests; consentController
Marketing communicationsContact, marketing preferencesConsent; legitimate interests (existing clients)Controller
Support & communications handlingCommunications, account, technicalContract; legitimate interestsController
RecruitmentRecruitment, identity, contact, professionalConsent; steps prior to a contract; legitimate interestsController
Billing, payments, accountingTransaction, identity, contactContract; legal obligationController
Security, fraud prevention, network integrityTechnical, logs, identityLegitimate interests; legal obligationController
Website analytics & improvementTechnical, usageConsent (non-essential cookies); legitimate interestsController
Legal & regulatory complianceAs requiredLegal obligationController
Delivery of outsourcing services (client customer data)As instructed by the ClientDetermined by the Client (Controller)Processor / Subprocessor
AI-assisted support / automation (where used)As scoped in the SOW/DPADetermined by role; per SOW/DPADepends on activity

8.Legal bases explained

We rely, as applicable, on: consent (a clear affirmative choice, which you may withdraw); performance of a contract (or steps before entering one); compliance with a legal obligation; our legitimate interests (or those of a third party), balanced against your rights; protection of vital interests; and performance of a task in the public interest, in the limited circumstances these apply. Under the NDPA and GDPR these bases are broadly comparable; where consent is the basis, we do not bundle it or rely on pre-ticked boxes.

9.Who we share data with

We share Personal Data only where necessary, with appropriate safeguards, with categories including: our Clients (where relevant to a relationship); our employees and contractors on a need-to-know basis; Affiliates; vendors and service providers (for example cloud hosting, CRM, communications, payment and analytics providers); approved AI providers (where used, as Subprocessors); professional advisers (legal, accounting, audit); regulators, courts and law enforcement where legally required; and parties to a corporate transaction (for example a merger, acquisition or financing), subject to confidentiality.

We do not sell Personal Data. We also do not "sell" or "share" Personal Data as those terms are defined under the CCPA/CPRA.

10.International data transfers

10.1Because we serve Clients and use vendors across Africa and internationally, Personal Data may be transferred to or accessed from countries other than the country in which it was collected.
10.2Where we transfer Personal Data across borders, we apply the safeguards required by Applicable Law, which may include adequacy/whitelisting mechanisms, contractual safeguards (such as standard contractual clauses or equivalent), the transfer conditions under the NDPA, and, where relevant, GDPR/UK transfer tools. and are reflected in our contracts and, for Client data, the DPA.

11.Cookies and similar technologies

Our Website uses cookies and similar technologies for essential operation, and (with consent where required) for functionality, analytics and marketing. You can manage your preferences through our consent tool and browser settings. Full detail is in our Cookie Policy (Document 3).

12.Artificial intelligence

12.1We may use AI and automation tools to help operate our business and, where agreed with a Client, to assist in delivering the Services. AI outputs can be inaccurate, and we apply human oversight proportionate to the use. Where AI is used in decisions with legal or similarly significant effects, section 17.3 (Automated decision-making) applies.
12.2We do not use Personal Data we control, or Client data we process, to train AI models for third parties, and we restrict input of Personal Data into third-party AI tools to approved, safeguarded uses.

13.How we protect data (security)

We implement reasonable technical and organisational measures designed to protect Personal Data against unauthorised or unlawful Processing and accidental loss, destruction or damage. These may include access control and least-privilege, authentication controls, encryption where appropriate, personnel confidentiality and training, monitoring and logging, incident response, back-up and recovery, vendor management, and secure disposal. No system is completely secure; we do not claim that our measures are impenetrable. We describe controls at a level that does not expose sensitive security detail.

14.Data retention

14.1We keep Personal Data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, tax, regulatory or reporting requirements, and to establish, exercise or defend legal claims.
14.2Indicative categories and drivers appear below; and are set in our Data Retention & Deletion Policy (Document 4).
CategoryProposed retention driver
Client & contract recordsDuration of relationship + limitation/statutory period
Client Customer data (as Processor)Per Client instruction / DPA; deleted or returned on termination
Communications & support recordsAs needed for the relationship + a defined period
Billing & accounting recordsStatutory tax/accounting retention period
Recruitment (unsuccessful applicants)Short defined period unless consent to keep on file
Security & system logsDefined security period
Marketing dataUntil consent withdrawn / opt-out + suppression record
CookiesPer Cookie Policy; session or defined lifespan

15.Your rights

15.1Subject to Applicable Law, you may have rights to: be informed about our Processing; access your Personal Data and receive a copy; correct inaccurate or incomplete data; request erasure; restrict Processing; object to Processing (including direct marketing); data portability; withdraw consent at any time (without affecting prior lawful Processing); and not be subject to solely automated decisions with legal or similarly significant effects, with the ability to seek human review. The precise rights and any exemptions depend on the law that applies to you (NDPA, GDPR, UK GDPR or US state laws).
15.2To exercise your rights, contact us using the details in section 18, or follow our Data Subject Request procedure (Document 9). We will verify your identity and respond within the timeframe required by Applicable Law. There is normally no fee, though we may charge a reasonable fee or decline where a request is manifestly unfounded or excessive, to the extent permitted.
15.3Complaints. You may complain to us first so we can help. You also have the right to complain to a supervisory authority in Nigeria, the Nigeria Data Protection Commission (NDPC); in the EU/UK, your local data protection authority (for example the UK ICO).

16.Data deletion requests

You can ask us to delete Personal Data we hold about you as a Controller. We will (1) acknowledge the request, (2) verify your identity, (3) review the data and any legal reasons to retain it, (4) apply any lawful exceptions (for example legal, tax or dispute-related holds), (5) delete or anonymise the remaining data within the applicable timeframe, (6) notify relevant Subprocessors where appropriate, and (7) confirm completion. For data we process on a Client's behalf, deletion requests are directed to and handled by the Client as Controller.

Requests: info@compliance.airsenseinc.com.

17.Marketing, children, and automated decisions

17.1Marketing. We send marketing to business contacts on a lawful basis and honour opt-outs promptly. Every marketing message includes an unsubscribe mechanism. We do not sell your contact data for third-party marketing.
17.2Children. Our Website and services are directed at businesses, not children, and we do not knowingly collect Personal Data from children. If we learn we have inadvertently collected a child's data without an appropriate basis, we will delete it. Where we process children's data on a Client's instruction, additional protections under Applicable Law and the DPA apply.
17.3Automated decision-making. We do not routinely make decisions producing legal or similarly significant effects about individuals based solely on automated processing. Where any such processing occurs, we will provide the information and rights required by Applicable Law, including the ability to obtain human intervention and to contest the decision.

18.Contact and changes

18.1Privacy contact email: info@compliance.airsenseinc.com. Registered/postal address: Surulere, Lagos State, Nigeria.
18.2We may update this Policy from time to time. The version and effective date at the top indicate the current version. Material changes will be notified by appropriate means. Please review this Policy periodically.