Privacy Policy
How we collect, use, secure, and protect your information.
Last updated: July 31, 2026
This page is maintained by Brilliantcraft to explain our data practices. It is not legal advice, a certification, or a substitute for your own compliance review. If you need jurisdiction-specific guidance, please consult a qualified legal professional.
Introduction
Brilliantcraft ("we", "us", or "our") is a Business & Revenue Automation Agency based in Akure, Nigeria. We help businesses design, build, and operate automation systems that save time and increase revenue. This Privacy Policy explains how we collect, use, store, and protect personal and business data in the course of delivering our services.
By using our website at brilliantcraft.com.ng or engaging us to build automation for your business, you agree to the practices described in this policy.
Data We Collect
We collect information that is necessary to deliver our services:
- Contact information: names, email addresses, and phone numbers submitted through our Automation Audit forms, contact pages, or direct communication.
- Business data: information about your workflows, sales processes, customer journeys, and operational needs shared during discovery and project delivery.
- System access credentials: API keys, login details, or integration tokens required to connect your tools to the automation systems we build.
- Usage and technical data: standard website analytics such as pages visited, device type, browser, and approximate location, collected to improve our site and services.
We do not intentionally collect sensitive personal data unless you voluntarily provide it and it is required for a specific automation project.
How We Use Your Data
We use the information we collect to:
- Respond to inquiries and schedule automation audits.
- Design, build, test, and maintain automation systems for your business.
- Communicate project updates, support requests, and service-related notices.
- Improve our website, tools, and service delivery processes.
- Comply with legal obligations and protect our rights.
We only process data for the purposes described above or as otherwise agreed with you in our service agreement.
Third-Party Integrations & AI
To build and operate automation systems, we connect data across approved third-party platforms. The specific tools used depend on your project, and may include:
- Automation platforms: Zapier, Make.com, and similar workflow orchestration tools.
- CRM and marketing systems: HubSpot, Shopify, and other sales or customer-management platforms.
- Artificial intelligence models: OpenAI and other AI providers used to generate content, classify data, or power chatbot conversations.
When we build AI chatbots or assistants for your business, the data they process is governed by this policy and any specific terms in your service agreement. We configure these tools to handle end-user data responsibly and only for the purposes you authorize. We do not sell personal data to third parties.
Each third-party provider has its own privacy and security practices. We select providers with strong data protection commitments, but we encourage you to review their policies as well.
Data Security
We take the security of client data seriously. Measures we apply include:
- Storing credentials and API keys in encrypted, access-controlled environments.
- Limiting access to client systems and business logic to team members who need it for project delivery.
- Using secure communication channels and multi-factor authentication where supported.
- Regularly reviewing integrations and revoking access that is no longer needed.
No system is completely risk-free. We continuously evaluate our security practices and respond promptly to any suspected breach or vulnerability.
Compliance
We aim to handle personal data in a manner consistent with the Nigeria Data Protection Regulation (NDPR) and, where applicable, international frameworks such as the General Data Protection Regulation (GDPR) for clients based in or serving individuals in the European Economic Area.
Our commitment includes collecting only the data we need, keeping it accurate, storing it securely, retaining it only as long as necessary, and respecting your rights over your information. Specific compliance obligations may also be addressed in a separate Data Processing Agreement or service contract.
Your Rights
Depending on your location and applicable law, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate or incomplete data.
- Request deletion of your data, subject to legal or contractual obligations.
- Object to or restrict certain types of processing.
- Withdraw consent where processing is based on consent.
To exercise any of these rights, please contact us using the details below. We will respond within the timeframes required by applicable law.
Data Retention
We retain personal and business data only for as long as needed to fulfill the purposes described in this policy, maintain automation systems under active service agreements, or comply with legal requirements. When data is no longer needed, we securely delete or anonymize it.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, tools, or legal requirements. The latest version will always be posted on this page with the updated effective date.
Contact Information
If you have questions, concerns, or requests about this Privacy Policy or how we handle your data, please contact us:
Brilliantcraft
Lagos, Nigeria