Legal & Governance

Privacy Doctrine

We believe data sovereignty matters. Here is exactly what we collect, why we collect it, how long we keep it, and your rights.

Last updated: 21 August 2026 · NDPR & GDPR Compliant

1. Who We Are (Data Controller)

The Sovereign AI Compute Platform (founder.drpcoa.com) is operated by Prince Charles Ejikeme, trading as drpcoa Enterprise, Lagos, Nigeria.

For privacy-related matters, contact: privacy@drpcoa.com or hi@drpcoa.com.

We act as the Data Controller under the Nigeria Data Protection Regulation (NDPR) 2019 and, to the extent applicable, the EU General Data Protection Regulation (GDPR).

2. Personal Data We Collect

Registration Data: Full name, email address, phone number, username, and encrypted password hash when you create a Member account.

Financial Data: Payment reference numbers, transaction amounts, and currency.

We do not store raw card numbers — all payment data is tokenised by our payment processors (Stripe, Paystack, Flutterwave).

Referral Data: Referral codes and the identity of the referring member for commission attribution.

Usage Telemetry: IP address, browser user-agent, session timestamps, page views, and API call logs for security auditing and rate limiting.

Biometric KYC Data (optional): If you elect to complete BioVault FIDO2 passkey registration, cryptographic key identifiers are stored — no raw biometric images are retained.

Communication Data: Support ticket content, VIP inbox messages, and email correspondence.

4. Data Retention

Active Accounts: Personal data is retained for the duration of your membership and for 7 years thereafter for legal compliance purposes.

Waitlist Entries: Retained for 24 months from the date of sign-up or until launch, whichever comes first.

Audit Logs: Tamper-evident audit records (hash-chained) are retained for 7 years as required for financial compliance.

Deleted Accounts: Upon account deletion, your personal identifiers are anonymised within 30 days.

Anonymised aggregate data may be retained indefinitely.

5. Third Parties & Data Sharing

We do not sell your personal data.

We share data only with: Payment Processors — Stripe (USA, SCCs apply), Paystack (Nigeria), Flutterwave (Nigeria/USA) — solely for transaction processing.

Communication Providers — Termii (SMS/OTP, Nigeria), Twilio (SMS fallback, USA), SMTP email relay — solely for transactional communications.

AI Inference Provider — AIMLAPI processes prompt text for AI responses.

Prompts are not used for model training per our data processing agreement.

No personal identifiers are sent to AIMLAPI.

Legal Authorities — We disclose data to law enforcement only when legally compelled and where disclosure is not prohibited.

6. Your Rights (GDPR/NDPR)

You have the right to: Access — Request a copy of your personal data.

Rectification — Correct inaccurate data.

Erasure — Request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements.

Portability — Receive your data in a machine-readable format.

Objection — Object to processing based on legitimate interests.

Restriction — Request that processing is restricted while a dispute is resolved.

To exercise any right, email privacy@drpcoa.com.

We will respond within 30 days.

If unsatisfied, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC) or your local supervisory authority.

7. Cookies & LocalStorage

We use essential cookies for session management and authentication.

Analytics cookies are set only with your explicit consent via our cookie banner.

LocalStorage is used to cache UI state preferences (theme, command palette history).

Please review our full Cookie & Storage Policy at /cookie-policy for complete technical details.

8. Security Measures

We implement industry-standard security: Encryption — All data in transit uses TLS 1.3.

Data at rest is encrypted using AES-256.

Password Hashing — Passwords are hashed using bcrypt with a minimum cost factor of 12.

Access Control — RBAC with 14 role tiers.

Admin actions require multi-factor authentication.

Audit Trails — Tamper-evident hash-chained audit logs record every admin action, impersonation, and financial mutation.

Bot Defence — S-Sonic Guardian passive behavioural entropy analysis on all authentication flows.

9. Policy Updates

We may update this Privacy Doctrine periodically.

Material changes will be communicated by email with at least 14 days advance notice.

The current version is always available at founder.drpcoa.com/privacy.

This doctrine was last updated on 21 August 2026.

Install Sovereign Engine
Fast, offline-ready native experience