Compliance
Our approach to regulation, data protection, and the standards we hold client infrastructure to.
Compliance
Nova X Solutions builds enterprise-grade digital infrastructure for institutions and scaling organizations, including clients in regulated sectors such as FinTech and HealthTech. Compliance is treated as a design requirement, embedded at the start of every engagement rather than bolted on at the end.
This page describes how we approach regulatory compliance and data protection for our own systems, and how we support clients in meeting their obligations. It is a general statement of practice and does not constitute legal advice or a warranty of any specific certification.
We align our practices with recognized frameworks and applicable law. Where a client engagement requires a specific certification, attestation, or audit, we confirm scope and evidence in the applicable contract or statement of work.
1. Data Protection & Privacy
We handle personal data in line with our Privacy Policy and applicable data-protection law, including the Nigeria Data Protection Act 2023 (NDPA) for our home jurisdiction and the EU/UK General Data Protection Regulation (GDPR) where we process the data of individuals in those regions.
- Personal data is collected only for defined, lawful purposes and retained no longer than necessary.
- Individuals may exercise their data-subject rights (access, correction, deletion, and objection) as described in our Privacy Policy.
- Where a security incident constitutes a reportable personal-data breach, we notify the Nigeria Data Protection Commission (NDPC) within 72 hours of becoming aware, as set out in our Security Policy.
2. Frameworks We Align With
Our engineering and operational practices are informed by widely adopted security and privacy frameworks. We reference these as guidance for control design; alignment is not a claim of formal certification unless stated in a specific client agreement.
- OWASP secure-development guidance for application security.
- ISO/IEC 27001 principles for information-security management.
- SOC 2 Trust Services Criteria (security, availability, confidentiality) as a control-design reference.
- Sector-specific requirements (for example, payment-data and health-data handling) scoped per engagement.
3. Supporting Client Compliance
For clients in regulated industries, we design systems to support — not undermine — their compliance obligations:
- Data-residency and data-flow requirements are identified during discovery and reflected in the architecture.
- Access controls, audit logging, and retention policies are built to produce the evidence auditors expect.
- Sub-processors and third-party integrations are evaluated for their security and data-handling posture before adoption, consistent with our Security Policy.
- Data-processing responsibilities are defined contractually via a Data Processing Agreement (DPA) where Nova X processes personal data on a client’s behalf.
4. Acceptable Use
Use of our Website and services is subject to our Acceptable Use Policy and Terms of Service. We reserve the right to suspend access where use violates applicable law or those policies.
5. What We Do Not Guarantee
Compliance is a continuous, shared responsibility. While we apply recognized frameworks and applicable law, alignment with a framework is not the same as a formal certification, and we do not warrant that any system is compliant with every regulation applicable to a client’s specific business. Regulatory obligations ultimately rest with the organization deploying the system, and clients should obtain independent legal advice for their circumstances.
6. Contact
Nova X Solutions
Email: info@novaxhq.com
Subject: [Compliance] — Brief Description
Website: www.novaxhq.com
Location: Abuja, FCT, Nigeria