Privacy
Privacy Policy
This Privacy Policy explains how Pilotestate collects, uses, shares, protects, retains, and respects rights over personal data in connection with estate operations.
Last updated: May 2, 2026
This policy is written to align with the Nigeria Data Protection Act, 2023 and NDPC privacy principles such as lawfulness, fairness, transparency, purpose limitation, data minimization, storage limitation, accuracy, security, and accountability.
Depending on the feature, Pilotestate may act as a data controller for its own business data or as a processor/service provider for estate-managed resident, visitor, gate pass, and dues information.
1. Who This Policy Covers
This policy applies to visitors to our website, estate administrators, facility managers, security personnel, residents, invited visitors, vendors, and anyone who interacts with Pilotestate through our website, forms, dashboard, support channels, payment flows, or gate pass tools.
Where an estate decides why resident or visitor information is processed, the estate may be the controller of that data. Pilotestate processes that information to provide the service and support the estate, subject to applicable law and any agreement with the estate.
2. Personal Data We May Collect
We may collect account and contact data such as name, email address, phone number, role, estate name, company name, password credentials, and support messages.
We may process estate operations data such as resident records, unit or house identifiers, dues status, payment references, receipts, visitor names, visitor phone numbers, vehicle details, QR or PIN gate pass information, check-in/check-out logs, approvals, and security notes.
We may collect technical and usage data such as IP address, device type, browser type, pages visited, form submissions, timestamps, error logs, cookies, analytics events, and approximate location derived from technical data.
We do not intentionally collect sensitive personal data unless it is necessary for a feature, required by law, or supplied by an authorized estate administrator for a legitimate estate operation.
3. Lawful Basis and Purposes
We process personal data where there is a lawful basis under applicable Nigerian data protection requirements. This may include consent, contract, legal obligation, legitimate interest, vital interest, public interest, or another lawful basis recognized by applicable law.
We use personal data to provide and secure the platform, create and manage accounts, process dues and receipts, issue and verify gate passes, support estate administration, communicate service updates, respond to enquiries, prevent fraud or misuse, maintain audit records, improve the service, and comply with legal obligations.
We limit processing to specified, explicit, and legitimate purposes and aim to avoid using data in ways that are incompatible with those purposes.
4. Data Sharing and Service Providers
We may share relevant data with estate administrators, authorized security personnel, payment processors, banks, messaging providers, email providers, hosting providers, analytics providers, support tools, professional advisers, regulators, law enforcement, or other parties where necessary to provide the service, protect rights, comply with law, or enforce our terms.
Service providers are expected to process data only for authorized purposes and apply appropriate confidentiality, security, and data protection measures.
5. Resident, Visitor, and Gate Pass Data
Resident and visitor data should be used only for estate operations such as access control, visitor verification, dues collection, resident support, security, incident review, and operational reporting.
Estates should notify residents and visitors about relevant processing, limit staff access by role, keep records accurate, and avoid collecting unnecessary information. Pilotestate provides tools to support these responsibilities, but estates remain responsible for their own lawful use of the data they control.
6. Cookies and Analytics
Our website may use cookies and similar technologies for site functionality, security, performance, preferences, and analytics. Where analytics tools such as Google Analytics are enabled, they help us understand how visitors use the website so we can improve it.
Where cookies or similar technologies involve personal data, we handle that data in line with this Privacy Policy and our Cookie Policy.
7. Data Retention
We keep personal data only for as long as reasonably necessary for the purpose it was collected, to provide the service, keep business and security records, comply with legal or accounting obligations, resolve disputes, enforce agreements, or meet estate administration requirements.
Retention periods may vary by data category. For example, payment and accounting records may need to be retained longer than website enquiry data, while visitor logs may be retained according to the estate configuration, legal need, or agreed policy.
8. Security and Integrity
We use administrative, technical, and organizational measures designed to protect personal data against unauthorized access, unlawful processing, accidental loss, destruction, damage, or data breach.
No online system is completely risk-free. Users and estates must also protect their accounts, use appropriate role permissions, update access when staff change, and report suspected incidents promptly.
9. Your Rights Under Nigerian Data Protection Law
Subject to applicable law and verification, data subjects may have rights to be informed, access their personal data, correct inaccurate data, object to processing, restrict processing, request portability, request deletion where appropriate, withdraw consent where consent is the basis of processing, complain to the Nigeria Data Protection Commission, and avoid decisions based solely on automated processing where applicable.
If your data is managed by an estate using Pilotestate, we may need to direct your request to the estate administrator or work with the estate to respond, because the estate may be the controller of that data.
10. International Transfers
Some service providers may process or store data outside Nigeria. Where cross-border transfer rules apply, we aim to use appropriate safeguards, contractual protections, adequacy considerations, consent where required, or another lawful transfer basis recognized under applicable Nigerian data protection law.
11. Children
Pilotestate is not directed to children. If children's personal data is processed because it is necessary for estate administration, the relevant estate or administrator should ensure that processing is lawful and that any required parental, guardian, or legal authority is obtained.
12. Updates to This Policy
We may update this policy to reflect product changes, legal requirements, or operational improvements. The updated date on this page shows when the latest version took effect.
13. Contact and Rights Requests
For privacy questions, data subject requests, or complaints, contact support@pilotestate.com. If your request relates to an estate account, include the estate name and enough information for us to verify and route the request appropriately.
Need help with this policy? Email support@pilotestate.com.