Ready when you are
Book a free 30-minute consultation — no pressure, just answers.
Book a consultation →Book a free 30-minute consultation — no pressure, just answers.
Book a consultation →How Airsense handles personal data as a controller
| Document owner | Airsense Bridge Limited |
| Version | v1.0 |
| Effective date | 31 August 2026 |
| Last updated | 13 August 2026 |
| Status | Published |
About this notice. This Privacy Policy explains how Airsense Outsourcing, under Airsense Bridge Limited, handles Personal Data as an independent Data Controller for example, data about Website visitors, prospective clients, business contacts, vendors, employees, contractors and job applicants.
Where Airsense instead handles Personal Data on behalf of a Client (as a Data Processor or Subprocessor) to deliver outsourcing services, that Processing is governed by the Client's own privacy notice and the Data Processing Agreement (Document 5), not by this Policy. See section 3.
In short: we collect Personal Data to run our business, provide and market our services, recruit, meet legal obligations and keep our systems secure. We rely on recognised lawful bases, share data only with parties who need it, apply safeguards to international transfers, keep data only as long as needed, and respect the rights available to individuals under Applicable Law. The detail follows.
Depending on the relationship, we may collect the following categories of Personal Data (as a Controller):
| Category | Examples |
|---|---|
| Identity | Name, user ID, company/employer, job title |
| Contact | Business email, telephone number, business address |
| Professional | Employer, role, CV/résumé, qualifications, work history |
| Account | Login credentials, account identifiers, settings and preferences |
| Transaction | Billing details, payment records, transaction history |
| Communications | Emails, chat messages, call recordings/notes, support tickets, feedback |
| Technical | IP address, browser, device, operating system, cookies and similar technologies, server logs, usage data |
| Recruitment | Application data, CV, interview notes, references (where provided) |
| Marketing | Preferences, subscription status, engagement with our communications |
We collect Personal Data from: the individuals themselves (forms, emails, calls, meetings); our Clients and their systems; employers, partners and vendors; public and professional sources (for example business directories and professional networks); the Website and cookies; recruitment channels and referrers; and our own technology and security systems.
The table below sets out our main Controller purposes, the data used, the lawful basis under the NDPA (with GDPR equivalents where relevant), and our role. Legal bases must be confirmed against final processing activities by counsel/DPO.
| Purpose | Data used | Lawful basis | Role |
|---|---|---|---|
| Service delivery & account management (direct clients) | Identity, contact, account, communications, transaction | Contract; legitimate interests | Controller |
| Client & prospect relationship management (CRM) | Identity, contact, communications | Legitimate interests; consent (where required) | Controller |
| Sales & business development | Identity, contact, professional | Legitimate interests; consent | Controller |
| Marketing communications | Contact, marketing preferences | Consent; legitimate interests (existing clients) | Controller |
| Support & communications handling | Communications, account, technical | Contract; legitimate interests | Controller |
| Recruitment | Recruitment, identity, contact, professional | Consent; steps prior to a contract; legitimate interests | Controller |
| Billing, payments, accounting | Transaction, identity, contact | Contract; legal obligation | Controller |
| Security, fraud prevention, network integrity | Technical, logs, identity | Legitimate interests; legal obligation | Controller |
| Website analytics & improvement | Technical, usage | Consent (non-essential cookies); legitimate interests | Controller |
| Legal & regulatory compliance | As required | Legal obligation | Controller |
| Delivery of outsourcing services (client customer data) | As instructed by the Client | Determined by the Client (Controller) | Processor / Subprocessor |
| AI-assisted support / automation (where used) | As scoped in the SOW/DPA | Determined by role; per SOW/DPA | Depends on activity |
We rely, as applicable, on: consent (a clear affirmative choice, which you may withdraw); performance of a contract (or steps before entering one); compliance with a legal obligation; our legitimate interests (or those of a third party), balanced against your rights; protection of vital interests; and performance of a task in the public interest, in the limited circumstances these apply. Under the NDPA and GDPR these bases are broadly comparable; where consent is the basis, we do not bundle it or rely on pre-ticked boxes.
We share Personal Data only where necessary, with appropriate safeguards, with categories including: our Clients (where relevant to a relationship); our employees and contractors on a need-to-know basis; Affiliates; vendors and service providers (for example cloud hosting, CRM, communications, payment and analytics providers); approved AI providers (where used, as Subprocessors); professional advisers (legal, accounting, audit); regulators, courts and law enforcement where legally required; and parties to a corporate transaction (for example a merger, acquisition or financing), subject to confidentiality.
We do not sell Personal Data. We also do not "sell" or "share" Personal Data as those terms are defined under the CCPA/CPRA.
Our Website uses cookies and similar technologies for essential operation, and (with consent where required) for functionality, analytics and marketing. You can manage your preferences through our consent tool and browser settings. Full detail is in our Cookie Policy (Document 3).
We implement reasonable technical and organisational measures designed to protect Personal Data against unauthorised or unlawful Processing and accidental loss, destruction or damage. These may include access control and least-privilege, authentication controls, encryption where appropriate, personnel confidentiality and training, monitoring and logging, incident response, back-up and recovery, vendor management, and secure disposal. No system is completely secure; we do not claim that our measures are impenetrable. We describe controls at a level that does not expose sensitive security detail.
| Category | Proposed retention driver |
|---|---|
| Client & contract records | Duration of relationship + limitation/statutory period |
| Client Customer data (as Processor) | Per Client instruction / DPA; deleted or returned on termination |
| Communications & support records | As needed for the relationship + a defined period |
| Billing & accounting records | Statutory tax/accounting retention period |
| Recruitment (unsuccessful applicants) | Short defined period unless consent to keep on file |
| Security & system logs | Defined security period |
| Marketing data | Until consent withdrawn / opt-out + suppression record |
| Cookies | Per Cookie Policy; session or defined lifespan |
You can ask us to delete Personal Data we hold about you as a Controller. We will (1) acknowledge the request, (2) verify your identity, (3) review the data and any legal reasons to retain it, (4) apply any lawful exceptions (for example legal, tax or dispute-related holds), (5) delete or anonymise the remaining data within the applicable timeframe, (6) notify relevant Subprocessors where appropriate, and (7) confirm completion. For data we process on a Client's behalf, deletion requests are directed to and handled by the Client as Controller.
Requests: info@compliance.airsenseinc.com.
Outsourced customer, growth and operations teams for startups serving Africa, the UK, Europe and the US. Based in Lagos, Nigeria.
Book a consultation →