Protecting data across every collaboration and platform
This policy outlines how Eminify collects, uses, and protects personal information shared during discovery, delivery, and support. It applies to all clients, prospects, vendors, and website visitors.
Who we are
Eminify is a digital product and engineering studio operating globally from the United States and Nigeria. We deliver product strategy, design, engineering, and automation services for clients across regulated and emerging industries.
This Privacy Policy explains how we collect, use, and safeguard information related to inquiries, engagements, and ongoing platform operations.
Data we collect
We collect personal and business information that you voluntarily provide when contacting us, subscribing to updates, or participating in product engagements.
- Contact details such as name, email address, phone number, and company information
- Project context including goals, timelines, technology preferences, and documentation
- Usage information from our websites, portals, and support tools collected via analytics cookies and session logs
- Credentials or API keys shared for integration purposes, stored only within secure secrets management systems
How we use information
We process data solely to deliver contracted services, support platform operations, and maintain transparent communication with stakeholders.
- Responding to inquiries, proposals, and support requests
- Configuring project environments, automation workflows, and integrations
- Monitoring quality, security incidents, and performance of deployed features
- Sharing progress updates, billing details, and strategic recommendations
- Improving our internal delivery playbooks and automation models using anonymized learnings
Legal bases for processing
We rely on one or more of the following legal grounds depending on the engagement and geography: (a) consent, (b) performance of a contract, (c) legitimate business interests balanced with privacy rights, and (d) compliance with legal obligations such as taxation and regulatory reporting.
Sharing with third parties
We do not sell personal data. We may share information with vetted subprocessors strictly necessary for delivery—such as cloud infrastructure providers, analytics platforms, communications tools, or specialist partners—with contractual guarantees on confidentiality, data handling, and breach notification.
Where clients request integrations with their own vendors, we process data under their direction and adhere to any security checks or vendor onboarding workflows they define.
International data transfers
Project teams may span multiple regions. When personal data moves across borders, we implement safeguards such as Standard Contractual Clauses, NDPR-compliant agreements, and encryption-in-transit protection to meet GDPR, CCPA, and other applicable regulations.
Data retention
We retain project records only for as long as they are required to deliver the engagement, satisfy contractual obligations, or comply with law. Backup archives are purged on a scheduled basis, and credentials shared for development are removed immediately after project completion or revocation requests.
Security practices
Our security posture includes access controls, environment segregation, encrypted storage, and auditing of privileged activity. Security incidents are documented, triaged, and communicated to affected stakeholders in line with our incident response policy.
You are responsible for safeguarding credentials issued to your team. Please notify us immediately if a compromise is suspected so we can coordinate remediation.
Your rights
Depending on your jurisdiction, you may request access to, correction of, or deletion of personal data we hold. You may also object to processing, request portability, or withdraw consent where processing is based on consent.
Submit requests to the contact details below, and we will respond within thirty (30) days. For identity verification, we may request additional information before fulfilling requests.
Children's data
Our services are designed for business stakeholders and are not directed to children under the age of sixteen (16). We do not knowingly collect personal data from children. If you believe a minor has provided information, contact us so we can delete it promptly.
Policy updates
We may update this Privacy Policy to reflect new regulations, security practices, or service offerings. The effective date will be revised accordingly, and significant changes will be communicated through our standard client channels.
Primary contact
privacy[AT]eminify.com
Email us to exercise your data rights, request a data processing agreement, or report a security concern.
Mailing address
Eminify Legal & Compliance
4283 Express Lane, Suite 591-660
Sarasota, Florida, USA 34249
For EU or Nigerian data subject requests, we coordinate with regional representatives to ensure timely responses under GDPR and NDPR.
Effective date: 2025 · Reviewed quarterly