Novotech Works
PILC Privacy Policy

Effective Date: July, 2026
Last Updated: July, 2026

1. Introduction

This Privacy Policy explains how Novotech Works Ltd. ("Novotech Works", "we", "us" or "our") collects, uses, stores, discloses, and otherwise processes personal data and related business information in connection with the PILC web-based purchase flow hosted on Novotech Works' website.

PILC enables organizations across Africa to purchase Asana Inc. ("Asana") software subscriptions in local currency through Novotech Works as a certified Asana Solutions Partner. Under Asana's channel-partner framework, customer use of the Asana service remains subject to Asana's subscriber terms, while payment, refunds, and other commercial terms between the customer and the channel partner are handled through the customer's agreement with the partner. The customer acknowledgment form also contemplates that Asana may share certain account information, including billing information and usage metrics, with the channel partner for support purposes.

This Privacy Policy is designed for customers in Nigeria and other African jurisdictions and is intended to support compliance with the Nigeria Data Protection Act, 2023 ("NDPA"), the earlier Nigeria Data Protection Regulation, 2019 ("NDPR") and related guidance where relevant, and the General Data Protection Regulation (GDPR) / UK GDPR where those laws apply to our processing activities. Where local law in a customer's country imposes additional or stricter privacy obligations, we will interpret and apply this Privacy Policy in a manner intended to meet those requirements.

2. Scope

This Privacy Policy applies to personal data and related business information we process when you:

  1. (a) visit or use the PILC purchase flow;
  2. (b) request quotes, place orders, or complete onboarding documents;
  3. (c) submit or sign a customer acknowledgment form or related customer agreement;
  4. (d) communicate with us about orders, renewals, support, billing, or account management;
  5. (e) receive transactional or marketing communications from us; or
  6. (f) interact with our payment and checkout partners in connection with a PILC transaction.

This Privacy Policy does not replace:

  1. (i) Asana's own privacy and service terms, which govern Asana's processing of data within the Asana platform and your use of the Asana service; or
  2. (ii) any privacy notices issued by payment providers, banks, or other third parties that process your data independently. Asana may store and process information about users, in the United States and transferred cross-border to third-party processors, with transfer mechanisms such as the Data Privacy Framework and Standard Contractual Clauses used where applicable.

3. Who We Are

Controller / Business Contact. Novotech Works is generally the data controller for personal data processed through PILC for sales, billing, onboarding, customer management, and related communications. Contact details:

Entity: Novotech Works Ltd.
Registered address: Plot 75, Block 15, Ichie Mike Ejezie Street, Lekki Phase 1
General contact email: info@novotechworks.com
Privacy contact / DPO: Kasope@novotechworks.com / Kasope Badaru
Support contact: payments@novotechworks.com

Where we process personal data strictly on behalf of another organization under a separate written arrangement, our role may differ.

4. Relationship With Asana and Payment Providers

PILC is a reseller flow. This means:

  1. (a) Novotech Works manages the customer-facing purchase, local-currency billing, onboarding, and account-management relationship.
  2. (b) Asana provides the underlying software service and remains a separate service provider with its own subscriber terms, privacy documentation, and sub-processors.
  3. (c) Payment processors and payment infrastructure providers, including Flutterwave Technology Solutions Limited ("Flutterwave"), may process payment-related data to complete transactions.

When a customer buys through any Asana channel partner, payment terms are governed by the customer's agreement with that partner, refund claims are routed through the channel partner, and Asana may suspend or terminate service if it does not receive corresponding payment from the partner. Also, customers consent to Asana sharing certain account information with the channel partner for customer service purposes.

Flutterwave's merchant agreement also requires merchants using its services to implement privacy practices aligned with the NDPR and other applicable privacy laws, maintain website privacy and refund/cancellation disclosures, and protect cardholder information.

5. Categories of Data We Collect

We may collect the following categories of personal data and business information.

Category Examples
Identity and contact data Name, job title, company name, business email address, phone number, billing contact details, account manager details
Business and account data Company legal name, domain, billing address, country, VAT/TIN or other tax details where required, user counts, subscription tier, renewal date, order records
Order and onboarding data Customer acknowledgment form details, reseller transaction details, license request details, implementation notes, support history
Payment and transaction data Payment status, transaction reference, payment channel, payer details, currency, amount, settlement metadata, refund status
Technical and device data IP address, browser type, device identifiers, operating system, time zone, session logs, page interaction data
Communications data Emails, support tickets, call notes, chat messages, meeting notes, complaint records
Marketing and preference data Subscription preferences, consent records, campaign engagement data, opt-in / opt-out status
Compliance and verification data Identity verification details, fraud screening indicators, sanctions or anti-abuse screening results where necessary
Website usage and analytics data Cookie identifiers, analytics events, referral URLs, page views, conversion events

We do not intentionally collect payment card security data that we do not need to process directly. Flutterwave's merchant terms require merchants not to store card verification value data after authorization and to notify Flutterwave of third-party providers with access to cardholder data.

6. How We Collect Data

We collect data:

  1. (a) directly from you, when you place an order, complete forms, contact us, or subscribe to communications;
  2. (b) from your organization, including procurement, finance, IT, or admin contacts acting on your behalf;
  3. (c) from payment processors, payment gateways, and banking rails involved in a transaction;
  4. (d) from Asana, where account, subscription, billing, or usage information is shared with us to support the reseller relationship, as contemplated by the customer acknowledgment process;
  5. (e) automatically, through cookies, server logs, pixels, and analytics tools when you use PILC; and
  6. (f) from public or third-party sources, such as corporate registries, sanctions lists, fraud-prevention databases, or professional networking sources, where permitted by law.

7. Purposes of Processing and Lawful Bases

We process personal data for the purposes below. Where the GDPR/UK GDPR applies, we rely on one or more lawful bases identified in the table.

Purpose Examples GDPR / UK GDPR Lawful Basis
Provide PILC services Process orders, validate purchases, request onboarding forms, provision licenses, manage accounts Contract; steps prior to entering a contract
Customer onboarding and account management Verify customer identity, coordinate activation, manage reseller support, liaise with Asana Contract; legitimate interests
Payments, reconciliation, refunds, and fraud prevention Process local-currency payments, verify settlement, investigate failed payments or suspected fraud Contract; legal obligation; legitimate interests
Compliance and recordkeeping Meet tax, accounting, anti-fraud, sanctions, dispute, and regulatory obligations Legal obligation; legitimate interests
Transactional communications Send payment confirmations, form reminders, activation notices, renewal notices, service messages Contract; legitimate interests
Marketing communications Send newsletters, event invitations, product updates, partner offers Consent where required; legitimate interests where permitted by law
Improve PILC and customer experience Monitor platform usage, troubleshoot issues, analyze conversion and performance Legitimate interests; consent where required for non-essential cookies
Security and incident response Detect abuse, secure systems, investigate incidents, preserve logs Legal obligation; legitimate interests
Dispute handling and legal claims Respond to complaints, enforce terms, defend legal rights Legitimate interests; legal obligation
Cross-border service delivery Coordinate with Asana and other vendors across jurisdictions Contract; legitimate interests; legal mechanisms for transfers

For customers in Nigeria, our processing is undertaken in line with lawful and fair processing principles under the NDPA and, where still relevant operationally, the NDPR framework. For customers in the EEA, UK, or Switzerland, we will identify and rely on an appropriate lawful basis under applicable data protection law.

8. Cookies, Analytics, and Similar Technologies

We may use cookies, pixels, tags, SDKs, and similar technologies on PILC for the following purposes:

  1. (a) strictly necessary cookies required for site operation, session security, fraud prevention, and checkout functionality;
  2. (b) performance and analytics cookies to understand how users navigate PILC and improve usability;
  3. (c) functional cookies to remember settings or reduce repetitive input; and
  4. (d) marketing cookies, where used, to measure campaign effectiveness and personalize communications.

Where required by law, we will request your consent before placing non-essential cookies on your device. You may also manage cookie preferences through your browser settings or any consent management tool we make available.

Asana may use analytics tools in marketing emails to measure opens and clicks, and distinguishes those practices from non-optional transactional or operational messages.

9. Communications: Transactional vs Marketing

We may send two broad categories of messages:

9.1 Transactional and Service Communications

These are messages necessary to administer your relationship with us, including:

  1. (a) order confirmations;
  2. (b) payment receipts or payment failure notices;
  3. (c) customer acknowledgment form reminders;
  4. (d) activation and provisioning notices;
  5. (e) renewal reminders;
  6. (f) support, service, or security notices; and
  7. (g) important legal, policy, or compliance notices.

You cannot opt out of essential transactional communications while you remain an active customer, except by ceasing use of the service and closing the relationship where permitted.

9.2 Marketing Communications

These may include:

  1. (a) newsletters;
  2. (b) educational content;
  3. (c) webinars and events;
  4. (d) partner or product announcements;
  5. (e) promotional campaigns; and
  6. (f) new offering updates.

Where required by law, we will send marketing only on the basis of opt-in consent. Where local law permits legitimate-interest marketing to business contacts, we will still provide a clear unsubscribe mechanism.

You may opt out at any time by:

  1. (a) clicking the unsubscribe link in a marketing email;
  2. (b) changing communication preferences through available account settings; or
  3. (c) contacting us using the details in this Privacy Policy.

Opting out of marketing does not stop transactional or service-related communications.

10. Payment Processing

Payments made through PILC may be processed by Flutterwave, banks, card schemes, and other payment infrastructure providers engaged in the transaction chain.

To complete and secure payments, these providers may process:

  1. (a) payer identity and contact details;
  2. (b) transaction references;
  3. (c) amount and currency;
  4. (d) payment method data;
  5. (e) fraud and risk signals; and
  6. (f) settlement or refund information.

Flutterwave's merchant terms require merchants to maintain appropriate privacy practices, implement security measures, display privacy and refund/cancellation information on their websites, and protect cardholder data in accordance with applicable standards.

We are not responsible for the independent privacy practices of third-party payment providers acting as separate controllers. You should review their privacy notices where relevant.

11. Disclosure of Data

We may disclose personal data and related business information to:

  1. (a) Asana, where necessary to submit orders, manage subscriptions, coordinate activation, provide support, or handle renewals;
  2. (b) payment processors and financial institutions, to process transactions;
  3. (c) IT, hosting, analytics, CRM, communications, and support vendors that help us operate PILC;
  4. (d) professional advisers, such as lawyers, auditors, insurers, and accountants;
  5. (e) regulators, tax authorities, law enforcement, or courts, where required by law;
  6. (f) affiliates or contractors supporting our operations under confidentiality and data protection obligations; and
  7. (g) a buyer, investor, or successor entity in connection with a merger, restructuring, financing, acquisition, or sale of business assets, subject to appropriate safeguards.

Asana publicly states that it uses third-party sub-processors and affiliates to help provide its services, including cloud infrastructure, analytics, customer support, and feature-specific providers, and that customer information may be transferred to the United States and other jurisdictions.

12. Processors and Sub-processors

We use service providers that process data on our behalf. Depending on the services enabled, these may include providers in the following categories:

Category Typical Role
Payment processors Payment acceptance, fraud screening, settlement, refund support
Cloud hosting providers Infrastructure, hosting, backup, disaster recovery
Communications platforms Email delivery, support desk, messaging
Analytics providers Usage analytics, performance monitoring, conversion analysis
Security providers Monitoring, logging, endpoint protection, fraud and abuse detection
Document and workflow tools Electronic forms, document storage, approval workflows
Professional service providers Legal, audit, accounting, consulting support

We require processors to process data only on documented instructions, apply appropriate security measures, and maintain confidentiality.

Where applicable, we may make available a current list of material sub-processors on request or through our website.

13. International and Cross-Border Transfers

Because PILC serves customers across Africa and interacts with global providers, personal data may be transferred to and processed in countries outside the country where it was collected, including the United States and other jurisdictions where our vendors or partners operate.

This is particularly relevant because:

  1. (a) Asana is a US-based provider and states that some information is stored in, and transferred to, the United States, with cross-border transfers to third-party processors also occurring.
  2. (b) Asana's data processing documentation states that, where applicable, it relies on the EU-US Data Privacy Framework, the UK Extension, the Swiss-US Data Privacy Framework, and Standard Contractual Clauses or other lawful transfer mechanisms.
  3. (c) Flutterwave's merchant terms contemplate compliance with Nigerian privacy law and PCI-DSS obligations relevant to payment-related data protection.

When we transfer personal data internationally, we aim to use appropriate safeguards, which may include:

  1. (i) adequacy decisions;
  2. (ii) contractual transfer clauses;
  3. (iii) vendor certifications or recognized transfer frameworks;
  4. (iv) intra-group data transfer arrangements;
  5. (v) risk assessments and supplementary technical or organizational measures; and
  6. (vi) obtaining consent where required and appropriate.

If you are located in a jurisdiction with transfer restrictions, you may contact us for more information about the safeguards we use.

14. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to:

  1. (a) complete transactions and onboarding;
  2. (b) manage subscriptions and renewals;
  3. (c) maintain customer and financial records;
  4. (d) resolve disputes and complaints;
  5. (e) comply with tax, accounting, audit, and legal obligations; and
  6. (f) establish, exercise, or defend legal claims.

Retention periods may vary by data type and jurisdiction. Below is a general guide:

Data Type Typical Retention Approach
Order, contract, and billing records Retained for the contract term and a reasonable post-termination period required for tax, audit, and dispute purposes
Support and communications records Retained while relevant to the relationship and for a reasonable period afterward
Marketing consent records Retained while consent remains relevant and for evidence of compliance
Security logs Retained for security, fraud prevention, and incident investigation needs
KYC / compliance records Retained as required by applicable law or compliance obligations

Where retention is no longer necessary, we will delete, anonymize, or securely archive the data in accordance with applicable law.

15. Security

We implement reasonable technical, organizational, and administrative measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, or misuse.

These measures may include:

  1. (a) access controls and role-based permissions;
  2. (b) encryption in transit and, where appropriate, at rest;
  3. (c) password and authentication controls;
  4. (d) logging and monitoring;
  5. (e) vendor due diligence;
  6. (f) secure backup and recovery procedures;
  7. (g) confidentiality obligations for personnel and contractors; and
  8. (h) incident response processes.

Despite our efforts, no system is completely secure, and we cannot guarantee absolute security.

16. Customer Responsibilities

Where your organization purchases Asana licenses through PILC, you are responsible for:

  1. (a) ensuring that information provided to us is accurate and up to date;
  2. (b) obtaining any necessary notices and consents from your personnel or authorized users;
  3. (c) configuring and using Asana and related services appropriately for your risk profile;
  4. (d) safeguarding your credentials and internal systems; and
  5. (e) ensuring that any data you submit through PILC or Asana is lawful to share.

The customer determines the categories of personal data it submits to the service and is responsible for secure and appropriate use of the service.

17. Data Subject Rights

Depending on your location and applicable law, you may have the right to:

  1. (a) request confirmation of whether we process your personal data;
  2. (b) request access to your personal data;
  3. (c) request correction of inaccurate or incomplete data;
  4. (d) request deletion or erasure of data in certain circumstances;
  5. (e) object to or restrict certain processing;
  6. (f) withdraw consent where processing is based on consent;
  7. (g) request portability of data where applicable;
  8. (h) complain to a regulator or supervisory authority; and
  9. (i) request information about cross-border transfers and safeguards.

If we receive a rights request relating primarily to data controlled by Asana or another third party, we may redirect you to that party where appropriate or assist in routing the request.

To exercise your rights, contact: info@novotechworks.com

We may need to verify your identity before acting on a request.

18. Complaints

If you have concerns about how we process your personal data, please contact us first to enable us to investigate and try to resolve the matter promptly.

Privacy complaints contact: Kasope Badaru
Email: info@novotechworks.com
Phone: +234 916 277 3336
Address: Plot 75, Block 15, Ichie Mike Ejezie Street, Lekki Phase 1

If you are in Nigeria, you may also have the right to complain to the Nigeria Data Protection Commission. If you are in another jurisdiction with a data protection authority, you may complain to the relevant supervisory authority in your place of residence, work, or the place of the alleged infringement.

19. Multi-Country African Customer Considerations

Because PILC is intended for organizations across multiple African jurisdictions:

  1. (a) local privacy, consumer protection, tax, e-commerce, and electronic communications laws may also apply;
  2. (b) some countries may restrict certain outbound data transfers or require local disclosures;
  3. (c) contract, recordkeeping, and complaint-handling requirements may vary by country;
  4. (d) payment routing may involve local banks, card schemes, and regulated intermediaries; and
  5. (e) we may issue country-specific supplements or additional notices where required.

If a mandatory local law provides stronger protections than this Privacy Policy, we will apply the stronger protection to the extent required.

20. Children

PILC is intended for business customers and is not directed to children. We do not knowingly collect personal data from children in connection with PILC.

21. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  1. (a) legal or regulatory changes;
  2. (b) changes to PILC functionality;
  3. (c) new vendors, processors, or partners;
  4. (d) changes in our business operations; or
  5. (e) security, compliance, or product improvements.

Where required, we will provide notice of material changes by posting the updated version on our website, updating the "Last Updated" date, or notifying customers through appropriate channels.

22. Contact Us

For questions, requests, or complaints about this Privacy Policy or our privacy practices, contact:

Novotech Works Ltd
Plot 75, Block 15, Ichie Mike Ejezie Street, Lekki Phase 1
Email: info@novotechworks.com | Kasope@novotechworks.com | payments@novotechworks.com
Phone: +234 916 277 3336