SentiNEX
HomeAboutProductConsultingInsightsPricingContact
Sign InGet Started

Legal

Privacy Policy

How SentiNEX collects, uses, shares and protects personal data when you use our reputation and compliance intelligence platform.

Effective date: 1 September 2026

1. Who we are

SentiNEX is a reputation, sentiment and compliance intelligence platform for financial institutions and their regulators across Africa. This policy explains how we handle personal data.

The data controller is Zent AI Labs Ltd, Lagos, Nigeria.

For any privacy question, to reach our Data Protection Officer, or to exercise the rights in section 9, contact admin@sentinex.co. Requests sent to that address are routed to the person responsible for data protection.

2. Scope

This policy covers the SentiNEX website and the authenticated platform. It addresses two distinct kinds of data, which we treat differently throughout:

  • Account data — personal data about you, our user, created when your organisation gives you access.
  • Monitored content — publicly published material about the banks, fintechs and other institutions our customers monitor. This may incidentally contain personal data about the authors of public posts. Section 6 deals with it specifically.

3. Personal data we collect

Information you or your organisation provide

  • Your first name, last name and email address.
  • Your password, which we store only as a salted cryptographic hash. We never store or have access to your password in readable form.
  • Your role and permissions, and the institution, entity or regulator organisation you belong to.
  • Anything you submit through the platform — compliance case notes, keywords you track, report configurations — and messages you send us through the contact form.

Information we collect automatically

  • IP address and browser user-agent string, recorded against each sign-in session. We compare the user-agent on later requests to the value captured at sign-in and reject the request if it changes, which limits the usefulness of a stolen session cookie.
  • Session timestamps: when a session was created, when it was last seen, when it expires, and whether and why it was revoked.
  • A tamper-evident audit log of security- and billing-significant actions, recording the action, the affected record, the acting user, IP address and user-agent. Entries are chained by cryptographic hash so that alteration is detectable. This log exists to protect you and to meet our customers' regulatory obligations.
  • Diagnostic and error data when something breaks, which may include the URL and limited technical context.

Billing information

Subscription, invoice and transaction records for your organisation. Card details are entered directly with our payment processor and never reach or pass through our servers.

4. Why we use it, and our lawful basis

Under the Nigeria Data Protection Act 2023 we must have a lawful basis for each purpose. Ours are:

  • To provide the platform — authenticating you, maintaining sessions, showing you the data your role permits. Basis: performance of a contract.
  • To secure the platform — session pinning, CSRF and rate-limit protection, audit logging, fraud and abuse investigation. Basis: legitimate interests, and legal obligation where our customers are regulated entities.
  • To bill — managing subscriptions, trials, invoices and payments. Basis: performance of a contract, and legal obligation for tax and accounting records.
  • To communicate — invitations, password resets, email verification, security notices and service announcements. Basis: performance of a contract.
  • To support and improve — diagnosing faults and improving reliability and accuracy. Basis: legitimate interests.

We do not sell personal data, and we do not use your account data to train AI models.

5. Automated processing and AI

SentiNEX uses large language models and statistical methods to classify sentiment, extract topics and themes, detect possible fraud patterns and generate recommendations. Monitored content is sent to the AI providers listed in section 7 for this purpose.

Two things follow that we want to state plainly. First, these outputs are algorithmic estimates and can be wrong, incomplete or out of date. They are decision support, not a finding of fact, a regulatory determination, or financial advice. Second, we do not use automated processing to make decisions about you that produce legal effects or similarly significant consequences.

Where a customer acts on a SentiNEX output — for example a regulator opening a compliance case — that decision is made by that organisation, exercising its own judgement, and it is responsible for it.

6. Monitored public content

To measure how an institution is perceived, we collect material that has been published publicly about it. Sources include Nairaland, Reddit, X (Twitter), Facebook, Google News, and news and RSS feeds across African markets. For each item we typically store the URL, title, text, publication date, source, and the analysis we derive from it.

We collect this material because it concerns the institution being monitored, not because it concerns the author. But a public post can plainly contain personal data about whoever wrote it. Where it does:

  • Our basis is legitimate interests — enabling institutions and their regulators to understand consumer sentiment, detect emerging fraud and act on public complaints, which is also in the interest of the customers those institutions serve.
  • We collect only what is already publicly accessible. We do not attempt to access private accounts, private groups or restricted content, and we do not attempt to re-identify pseudonymous authors.
  • We do not use this material to build advertising or marketing profiles of individuals.
  • You can ask us to remove content that identifies you. Write to admin@sentinex.co with the URL, and see section 9.

7. Who we share data with

We share personal data only as set out below. Every provider acts on our instructions under a contract, or as an independent controller where noted.

  • Your own organisation. Administrators at your institution or regulator can see your account details, role and activity. Regulator users can see data about the institutions in their jurisdiction.
  • Anthropic and OpenAI (United States) — AI analysis of monitored content, as described in section 5.
  • Firecrawl — retrieval and extraction of public web content.
  • Paystack (Nigeria) — payment processing. Paystack handles card data as an independent controller under its own privacy policy.
  • Resend — delivery of transactional email such as invitations and password resets.
  • Sentry — error and performance monitoring.
  • Vercel and Fly.io (United States) — application hosting, file storage and background processing.
  • Our database and cache providers — managed PostgreSQL and Redis hosting.
  • Professional advisers, authorities and acquirers — where we are legally required to disclose, need to establish or defend legal claims, or in connection with a merger or acquisition.

8. International transfers

We are based in Nigeria, but several providers above process data in the United States and elsewhere. That means personal data may be transferred outside Nigeria to countries whose data protection laws differ from Nigerian law.

Where we make such a transfer we rely on the mechanisms permitted by the NDPA 2023 — principally contractual safeguards with each provider, including standard data protection clauses. You can ask us for details of the safeguards applying to a specific transfer.

9. Your rights

Subject to the conditions in applicable law, you have the right to:

  • Be informed about how we use your personal data — which is the purpose of this policy.
  • Request access to a copy of the personal data we hold about you.
  • Have inaccurate or incomplete data corrected.
  • Request deletion of your personal data.
  • Restrict or object to our processing, including processing based on legitimate interests.
  • Receive your data in a portable, machine-readable format.
  • Withdraw consent at any time, where we rely on consent.

To exercise any of these, contact admin@sentinex.co. We will respond within the period required by law. We may ask you to verify your identity first, and we will explain our reasoning if we cannot fully meet a request.

Two limits worth flagging honestly. Audit-log entries are deliberately tamper-evident and are retained to meet regulatory and security obligations, so we may be unable to delete them on request. And if your access was created by your employer, some requests are properly directed to that organisation, which decides who may use the platform — we will tell you when that applies and help you route the request.

If you are unhappy with our response, you may lodge a complaint with the Nigeria Data Protection Commission (NDPC), or with your local supervisory authority.

10. How long we keep data

  • Sign-in sessions expire automatically 24 hours after creation. Expired and revoked session records are pruned thereafter.
  • Records of which URLs the pipeline has already processed are deleted after 180 days.
  • Account data is retained while your organisation’s account is active, and then for 90 days after closure so access can be restored if the account is reinstated. After that it is deleted or irreversibly anonymised.
  • Audit and billing records are kept for 6 years, reflecting Nigerian statutory accounting and company record-keeping requirements, and our customers’ own regulatory obligations.
  • Monitored content and the analytics derived from it are retained for 24 months to support trend and historical reporting, after which source content is deleted and only aggregated statistics are kept.

11. Security

We take security seriously and it shapes how the platform is built. Measures include encryption in transit, password hashing, HTTP-only session cookies, session pinning to the signing-in browser, CSRF protection on state-changing requests, a strict Content Security Policy, role-based access control with per-entity scoping, rate limiting, guards against server-side request forgery on outbound fetches, and a tamper-evident audit log.

No system is perfectly secure, and we will not claim otherwise. If we suffer a breach affecting your personal data we will notify you and the NDPC as required by law. If you believe you have found a vulnerability, please report it to admin@sentinex.co.

12. Cookies

We use only the cookies needed to make the platform work and keep it secure. We do not use advertising cookies and we do not track you across other websites.

  • Session cookie (authjs.session-token, or __Secure-authjs.session-token over HTTPS) — keeps you signed in. HTTP-only, so it cannot be read by JavaScript. Expires after 24 hours.
  • CSRF token (sentinex-csrf) — protects against cross-site request forgery. Readable by our own scripts by design, so they can echo it back on submission.

Blocking these cookies will prevent you from signing in. Error monitoring may also set limited technical identifiers for diagnostics.

13. Children

SentiNEX is a business platform, not intended for children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us data, contact us and we will delete it.

14. Changes to this policy

We may update this policy as the platform and the law change. We will revise the effective date above and, for changes that materially affect your rights, notify you by email or in the platform before they take effect.

See also our Terms of Service.

SentiNEX

Transforming digital noise into clarity through data-driven insights.

Platform

  • Product
  • Consulting
  • Insights

Company

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

Contact

  • admin@sentinex.co
  • Lagos, Nigeria
  • Mon - Fri, 9am - 5pm WAT

© 2026 SentiNEX. All rights reserved.

PrivacyTerms