Privacy Policy
Last Modified: May 30, 2026 · Version 2026-05-30
This Privacy Policy describes how Clustra Technologies Ltd. ("Clustra", "we", "our", or "us") collects, uses, discloses, and protects personal information when you access our website, applications, APIs, and related services (collectively, the "Service"). It applies globally and reflects our obligations under the EU and UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and other U.S. state privacy laws, the Nigeria Data Protection Act 2023 (NDPA), and analogous frameworks across other African jurisdictions.
Plain-language summary. We collect what we need to run your workspace, keep it secure, and bill you. We encrypt your identity data at rest, we don't sell or rent it, and we don't fire analytics or marketing tracking without your opt-in. You can access, correct, export, restrict, or delete your data from your account settings or by emailing us. Children under 16 are not permitted on the Service.
1. Controller, Representatives & Contact
The data controller (or, where applicable, "business" under CCPA/CPRA and "data controller" under NDPA) for personal data processed through the Service is Clustra Technologies Ltd. Our registered postal address and company registration number are available on request from privacy@clustra.org.
Our Data Protection Officer can be reached at dpo@clustra.org.
Workspace customers as controllers. When you sign up for a workspace, Clustra acts as a data processor for the content you and your team upload (documents, calendar entries, helpdesk tickets, chat messages, mail, notes, custom database records). Your organisation is the controller for that content; this policy describes the processing we perform on your behalf and our additional processing as a controller for account, billing, and security data.
2. Information We Collect
We collect the following categories of personal data, all sourced from your interactions with the Service:
2.1 Identity & account data
- Email address — used to sign in, verify your identity, and contact you about your account. Stored encrypted at rest (AES-256-GCM envelope encryption) with a separate blind index for lookups, so the plaintext email is never present in our query path.
- First and last name — encrypted at rest under the same scheme as above.
- Password — stored only as a bcrypt hash (cost 13). We never see or store your plaintext password.
- Profile photo URL — points to a file you uploaded, hosted on Google Cloud Storage.
- Authentication metadata — auth providers linked to your account (Email/Password, Google), email verification status, two-factor (TOTP) enabled flag and (where you enable 2FA) the TOTP shared secret stored under a key management service, single-use email verification and password reset tokens (bcrypt-hashed, 10-minute expiry), login attempt counter and last failure timestamp used for brute-force lockout.
- Age confirmation timestamp — null until you confirm you are 16 or older, as required before workspace features become available.
- GDPR/NDPA control flags — processing-restriction flag and reason (Art. 18 / NDPA s. 36), list of purposes you have objected to (Art. 21 / NDPA s. 37) with timestamps.
2.2 Workspace & organisation data
- Workspace name, logo, your role (Administrator / Editor / Viewer), team membership, seat assignments, and workspace-local profile overrides (display name, photo, title, timezone, phone, birthday, start date, presence status).
- Invitations you send or receive (invitee email, role, single-use signed invite token).
- API tokens and helpdesk-portal API keys you mint for integrations. We display the token in plaintext exactly once at creation; only a SHA-256 hash and a four-character hint are stored thereafter.
- Workspace database configuration if you connect your own external database.
- Workspace ownership history and admin-initiated actions for audit purposes.
2.3 Billing & payment data
- Billing email, billing contact name, plan, subscription status, currency (USD, NGN, GHS, ZAR, KES), billing interval, seat quantity, period dates, trial-end date, and provider-side customer and invoice identifiers.
- We do not store payment card data. Payment instruments are tokenised and processed exclusively by Paystack, which is responsible for PCI-DSS compliance for that data.
2.4 Workspace content (processed on behalf of your organisation)
- Files you upload to Google Cloud Storage under your user-scoped path; 10 MiB per-file limit, MIME type allow-list enforced.
- Notes, tasks, calendar events, mail messages (including IMAP/SMTP or Google OAuth-synced mailbox content where you connect a mailbox), chat messages, helpdesk tickets and customer contact records, collaborative documents, and content you create in custom databases.
- Free-text fields that are encrypted at rest under a workspace-scoped data encryption key wrapped by our key management service.
2.5 Usage telemetry & analytics
- PostHog product analytics — page views, autocaptured interactions, and identify events containing your user ID, email, and name. These fire only after you opt in via the consent banner; opting out at any time stops further collection.
- Sentry error monitoring — server and browser stack traces, request context, and breadcrumbs. Sensitive headers (cookies, authorisation, tokens) are redacted at source, email patterns in error payloads are replaced with
[email], and the user object is truncated to an ID before transmission. Error monitoring is treated as a legitimate-interest security function and runs without separate consent. - Operational monitoring logs — HTTP method, path, status, response time, user agent, IP address, and the requesting user ID for each API call, retained for security and reliability analysis.
2.6 Device & network metadata
- IP address, user agent, and approximate location derived from IP — used to display your active sessions, detect unfamiliar sign-ins, and rate-limit abuse.
- Session metadata (created-at, last-used-at, device/agent) stored in Redis under your user ID; idle sessions are pruned after 30 days.
- OAuth state binding nonce (see Cookies, §11).
2.7 Communications
We send transactional email — welcome and verification, password reset, account-change notifications, workspace member invitations, billing notifications, helpdesk support replies, and an account-deletion confirmation. We process the email body and recipient address for the purpose of delivering the message.
2.8 Consent records
For every consent decision (analytics, marketing, product improvement) we record the purpose, the granted/withdrawn state, the policy version in force at the time of the decision, and a timestamp. This is required to prove lawfulness of processing under GDPR Art. 7(1) and NDPA s. 26.
2.9 Categories we do not collect
We do not knowingly collect special categories of personal data (GDPR Art. 9), health information, biometric data, government identifiers, precise geolocation, or data from children under 16. If you choose to upload such data into your workspace, your organisation — not Clustra — is the controller, and you are responsible for the lawful basis to do so.
3. How We Use Your Information
We use personal data for the following specific purposes:
- Authenticating you and authorising your actions in a workspace.
- Provisioning workspaces, teams, invitations, and seat assignments.
- Processing billing, subscriptions, invoices, and refunds via Paystack.
- Delivering transactional and security-related email.
- Securing the Service: brute-force lockout, single-use refresh tokens, session revocation on sensitive changes, OAuth state binding to prevent CSRF, security event alerting, and fraud detection.
- Detecting and diagnosing software errors and performance regressions (Sentry, operational logs).
- Understanding which features are used and improving them (PostHog) — only with your consent.
- Responding to your data subject requests and meeting our regulatory obligations.
- Communicating material changes to this policy and to the Service.
4. Legal Basis for Processing
4.1 GDPR / UK GDPR — Article 6
If you are in the European Economic Area, the United Kingdom, or your processing is otherwise subject to GDPR or UK GDPR, we rely on the following legal bases:
- Contractual necessity (Art. 6(1)(b)) — account creation, authentication, workspace provisioning, billing, and delivery of the Service you signed up for.
- Legitimate interests (Art. 6(1)(f)) — security monitoring, fraud prevention, error diagnosis, abuse prevention, and protection of the Service and other users. You can object at any time using the contact details in §1.
- Legal obligation (Art. 6(1)(c)) — tax and accounting record retention, regulator requests, and responses to lawful court orders.
- Consent (Art. 6(1)(a)) — product analytics (PostHog), optional marketing communications, and any cookies or trackers that are not strictly necessary. You can withdraw consent at any time without affecting the lawfulness of prior processing.
4.2 Nigeria Data Protection Act 2023
For data subjects in Nigeria, we process personal data under the lawful bases set out in NDPA s. 25: consent, contractual necessity, compliance with a legal obligation, vital interests, public interest, and legitimate interests. We have appointed a Data Protection Officer who can be contacted at privacy@clustra.org.
4.3 Other African frameworks
Where you are located in a jurisdiction with its own data protection law — including but not limited to South Africa (POPIA), Kenya (Data Protection Act 2019), Ghana (Data Protection Act 2012), Egypt (Personal Data Protection Law 2020), Uganda, Rwanda, and Mauritius — we process your personal data on the equivalent lawful bases recognised by those frameworks and honour the rights they grant.
4.4 United States & California
Outside California, U.S. federal law does not require a specific lawful basis, but we process personal information for the disclosed business purposes set out in §3. California-specific disclosures are in §9.
5. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected:
- Account data — for the lifetime of the account. On account deletion we hard-delete identifying records and propagate erasure through our app-specific erasers, with up to 30 days for backup expiry.
- Workspace content — for the lifetime of the workspace. Removed members are soft-deleted for 30 days and then hard-deleted by the retention service.
- Authentication sessions — idle sessions are pruned nightly when
lastUsedAtexceeds the configured idle window (default 30 days). - Verification codes & password reset tokens — 10 minutes from issuance.
- Billing & transaction records — retained for 7 years to satisfy tax, accounting, and audit obligations across the jurisdictions we operate in.
- Consent records — kept for the lifetime of the account; IP, user agent, and similar contextual metadata are anonymised after 13 months by our nightly retention sweep, while the consent decisions themselves (purpose, version, timestamp) are preserved as proof of lawful processing.
- Security and audit logs — retained for up to 90 days for security event analysis, then deleted or anonymised. Audit-trail records used to demonstrate compliance are retained for as long as we are required to evidence the processing decision they document.
- Operational monitoring logs — retained for up to 30 days, then deleted.
6. Sharing & Sub-Processors
We do not sell or rent personal data. We share personal data only with the following categories of sub-processors, each engaged under a written data processing agreement with appropriate confidentiality and security obligations:
- Hosting & infrastructure — Vercel (web hosting), DigitalOcean (server hosting), MongoDB Atlas (global user and workspace data), managed PostgreSQL (per-feature application databases), Redis (sessions, OAuth state, cache), Google Cloud Storage (uploaded files).
- Identity & secrets — Google OAuth (sign-in only; we never store Google refresh tokens), Infisical (key management for the 2FA TOTP secrets and per-workspace data encryption keys).
- Payments — Paystack handles all payment instrument tokenisation, subscription management, and invoices. Clustra stores only Paystack customer and invoice identifiers and non-instrument billing metadata.
- Error monitoring & product analytics — Sentry (error monitoring; redactions applied at source) and PostHog (product analytics; fires only with explicit consent).
- Internal security alerting — security events (failed-login spikes, bulk data exports, member removals, GDPR-deadline breaches) are posted to a private Slack channel monitored by our security team. The payload is limited to the event type and the scoping identifier (IP, user ID, or workspace ID) needed to triage the alert.
- Government authorities and lawful requests — when legally compelled and only to the extent required, after challenging overbroad requests where possible.
A current list of sub-processors with their locations and the categories of data they process is available on request from privacy@clustra.org.
7. Security Measures
We apply technical and organisational measures designed to protect personal data, including:
- AES-256-GCM envelope encryption at rest for identity PII (email, first name, last name) with wrapped keys held in our key management service.
- Per-workspace data encryption keys for free-text content; rotating a workspace key crypto-shreds the searchable encrypted fields in that workspace.
- Blind indexing of email so we can authenticate without holding plaintext on the query path.
- Bcrypt password hashing at cost 13; timing-neutral comparison against a dummy hash on unknown accounts to mask user enumeration.
- Single-use refresh tokens; a second use triggers full session revocation on the assumption of compromise.
- OAuth state binding via an
HttpOnly,Secure,SameSite=Laxcookie with a 10-minute lifetime to prevent CSRF on the OAuth callback. - TLS 1.2+ in transit, HSTS preload, and a Content Security Policy on all properties.
- Brute-force lockout (5 failures = 15 minutes), session revocation on any sensitive change (password update, 2FA toggle, provider link/unlink), and optional two-factor authentication for all accounts.
- Sentry payload redaction (cookies, tokens, secrets) before transmission.
- Least-privilege access controls and audit logging for administrative actions.
No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (GDPR Art. 33) and, where the risk is high, notify affected individuals without undue delay (Art. 34). Equivalent breach-notification obligations under NDPA s. 40 and U.S. state breach-notification laws are also honoured.
8. Your Rights
8.1 GDPR / UK GDPR & NDPA
Subject to verification of your identity, you have the right to:
- Access the personal data we hold about you (GDPR Art. 15 / NDPA s. 34).
- Have inaccurate data corrected (Art. 16 / NDPA s. 35).
- Request erasure of your data (Art. 17 / NDPA s. 34(1)(d)). Our DSAR engine supports two modes: anonymise (zero PII while preserving content for audit and legal holds) and delete (hard delete across all stores).
- Restrict processing in specific circumstances (Art. 18 / NDPA s. 36).
- Receive your data in a portable, machine-readable format (Art. 20 / NDPA s. 38).
- Object to processing based on legitimate interest, including profiling (Art. 21 / NDPA s. 37).
- Withdraw consent at any time.
8.2 California (CCPA/CPRA)
California residents have, in addition, the right to:
- Know what categories and specific pieces of personal information we have collected, the sources, the business purposes, and the categories of recipients.
- Delete personal information, subject to statutory exceptions.
- Correct inaccurate personal information.
- Opt out of the "sale" or "sharing" of personal information. Clustra does not sell personal information and does not share it for cross-context behavioural advertising as those terms are defined in the CPRA.
- Limit the use and disclosure of sensitive personal information. We do not use sensitive personal information for purposes that would trigger this right.
- Be free from retaliation for exercising any CCPA/CPRA right.
You may also designate an authorised agent to make a request on your behalf (Cal. Civ. Code § 1798.135). California residents under 16 cannot use the Service.
8.3 Other U.S. states
Residents of states with comprehensive privacy laws — including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), and others — have substantially equivalent rights to access, correct, delete, port, and opt out of targeted advertising, sale of personal data, and certain profiling. We honour those rights using the same process as below.
8.4 How to exercise your rights
Authenticated users can exercise these rights directly from the account settings page, which calls our data subject request API. You may also email privacy@clustra.org. We respond within 30 days (GDPR Art. 12(3), NDPA s. 34(2)) and within 45 days under U.S. state laws, with one extension available where the law permits and we notify you in advance.
9. Right to Lodge a Complaint
If you believe we have not handled your personal data lawfully, you have the right to lodge a complaint with your local supervisory authority:
- EEA residents — find your authority via the European Data Protection Board members list (opens in new tab).
- United Kingdom — the Information Commissioner's Office (ICO) (opens in new tab).
- Nigeria — the Nigeria Data Protection Commission (NDPC) (opens in new tab).
- California — the California Privacy Protection Agency (CPPA) and the California Attorney General.
- Other jurisdictions — the data protection regulator in your country of residence.
You may also seek judicial redress where the law permits.
10. International Data Transfers
Personal data we process may be transferred to and stored in countries other than your country of residence, including the United States, the European Union, and other markets in which our sub-processors operate. Where we transfer personal data out of the EEA, the UK, Switzerland, or Nigeria to a country without an adequacy decision, we rely on:
- The European Commission's Standard Contractual Clauses (2021 modules) and, where applicable, the UK International Data Transfer Addendum or UK IDTA.
- The EU–U.S. Data Privacy Framework and its UK Extension and Swiss–U.S. Framework where the recipient is self-certified.
- Approved transfer mechanisms recognised under NDPA s. 41 and equivalent provisions in other African jurisdictions.
- Supplementary technical measures (encryption at rest and in transit, blind indexing, key segregation) to address the risks identified in our transfer impact assessments.
A copy of the safeguards in place for a specific transfer is available on request.
11. Cookies & Local Storage
We use the minimum set of cookies and browser storage needed to run the Service:
- Authentication session cookies (essential) — set by NextAuth and our auth handlers so you remain signed in.
HttpOnly,Secure,SameSite; lifetime tied to your refresh-token policy. - OAuth state binding cookie (essential) —
__Host-oauth-state-bindingin production (oroauth-state-bindingin development). Single-use CSRF nonce,HttpOnly,SameSite=Lax,Securein production, 10-minute lifetime. - Consent decision (essential, browser local storage) — records which policy version you decided under and which optional purposes you granted or refused.
- Product analytics cookies (optional) — set by the PostHog SDK after you opt in to analytics. Withdrawing consent stops further collection and clears the SDK state.
Essential cookies do not require consent under GDPR and the ePrivacy Directive. All non-essential cookies and trackers are opt-in. You can change your choices at any time from the cookie banner or your account settings. When the policy version recorded against your consent no longer matches the current version, we re-prompt you, as required for material changes under GDPR Art. 7(3).
12. Children's Privacy
Clustra is intended for users 16 years of age and older and is not directed to children. We do not knowingly collect personal data from individuals under 16. New users authenticated via OAuth must confirm they are at least 16 before workspace features become available. If we learn that we have collected personal data from a child under 16 (or under 13 where the U.S. Children's Online Privacy Protection Act applies), we will delete it as soon as practicable. Contact privacy@clustra.org if you believe a child has provided us with personal data.
13. Workspace Customers & Our Role as Processor
When a workspace administrator invites you and you accept, that administrator's organisation is the controller for the content you and your colleagues create in that workspace. As a processor we:
- Only process workspace content on documented instructions from the controller (typically the terms of our Data Processing Agreement).
- Ensure people authorised to access personal data are bound to confidentiality.
- Assist the controller with data subject requests and breach notification.
- Delete or return personal data after the end of the services, subject to legal-hold and audit requirements.
- Make available the information necessary to demonstrate compliance.
If you are a workspace user with a request about content held in your workspace, please direct it to your workspace administrator. We will forward any such request we receive directly to the responsible workspace administrator.
14. No Sale or Sharing of Personal Data
Clustra does not sell personal data, and does not share personal data for cross-context behavioural advertising, as those terms are defined under CCPA/CPRA. We do not use personal data for advertising, do not allow advertising networks on the Service, and do not exchange personal data for monetary or other valuable consideration.
15. Third-Party Links
The Service may link to or integrate with third-party websites and services (including Google, Paystack, and the integrations you connect from within your workspace). Their privacy practices are governed by their own policies, which we encourage you to review. We are not responsible for the privacy practices of those third parties.
16. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated to you by email and via an in-app notice and, where the change is material under GDPR Art. 7(3) or NDPA s. 26, your existing consent decisions will be invalidated and we will re-prompt you. The version, effective date, and a content hash of each policy revision are recorded alongside your consent records so you can verify what you agreed to at any point in time. The current version is shown at the top of this page.
17. Governing Law & Forum
This Privacy Policy is governed by the laws of the Federal Republic of Nigeria. Any dispute arising out of or in connection with this policy shall be subject to the exclusive jurisdiction of the courts of Lagos, Nigeria.
18. Contact Us
General privacy questions: privacy@clustra.org.
Data Protection Officer: dpo@clustra.org.
Postal address and company registration number are available on request.
This Privacy Policy is provided for informational purposes and does not constitute legal advice.