DATA POLICY

Effective Date: November 14, 2026
Last Updated: November 14, 2026
Version: 1.0
01

INTRODUCTION

TertiaSync ("TertiaSync," "we," "our," or "us") respects your privacy and is committed to responsible handling of personal data.

This Data Policy explains what personal data TertiaSync collects, how we use it, how it may be shared, how we protect it, how long it is retained, and the rights available to users under applicable data-protection law, including the Nigeria Data Protection Act 2023 (NDPA).

TertiaSync is currently designed for undergraduate students enrolled at Nigerian tertiary institutions.

Where applicable law requires consent for a particular processing activity, TertiaSync will request consent through an appropriate mechanism. Where another lawful basis applies, processing may be carried out on that basis.

02

DATA WE COLLECT

The information TertiaSync collects depends on how you use the Platform and what information you choose to provide.

Account Information

When creating an account, TertiaSync may collect information such as:

Full name
Email address
Password/authentication credentials
Institution
Faculty
Department
Academic level
Optional Profile Information

Users may voluntarily add additional information to their profile, including:

Phone number
Matriculation number

Phone number and matriculation number are optional and are not required to create a TertiaSync account.

TertiaSync does not represent that a matriculation number is institutionally verified merely because a user enters one into their profile.

We use account and profile information to:

create and manage accounts;
authenticate users;
personalize the Platform;
provide relevant academic resources;
organize resources according to institution, faculty, department, or level;
provide relevant account communications; and
maintain Platform security and integrity.

Academic Information

Depending on the features used, TertiaSync may process information entered into academic tools, including:

courses;
grades or scores;
credit units;
semester information;
schedules;
examination dates; and
other academic information entered by the user.

This information is used to provide academic organization and calculation features such as CGPA calculations, scheduling, and relevant reminders.

TertiaSync does not represent calculations generated by the Platform as official institutional academic records.

Contributions and Uploaded Materials

When you submit an academic contribution, TertiaSync may process:

uploaded files;
title and description;
course information;
institution, faculty, department, level, and session information;
submission date;
moderation status;
contribution-related records; and
Aura Points associated with approved contributions.

This information is used to review, moderate, organize, maintain, and publish approved academic resources and administer the contribution system.

Technical and Usage Information

TertiaSync may process technical or usage information necessary to operate and secure the Platform, including, where available:

IP address;
browser information;
device information;
operating system;
timestamps;
pages or features accessed;
error information; and
security-related events.

This information may be used for:

security;
abuse and fraud prevention;
troubleshooting;
performance and reliability;
maintaining Platform functionality; and
understanding general Platform usage.

Communications

If you contact TertiaSync through email, support channels, reports, or other communication methods, we may process the information contained in those communications to respond to you, provide support, investigate reports, handle complaints, and address account or security matters.

03

PASSWORDS AND AUTHENTICATION

TertiaSync does not intentionally store user passwords in plain text.

Where passwords are used, appropriate authentication and credential-protection mechanisms are applied.

Users are responsible for protecting their account credentials and should not share their passwords with others.

04

HOW WE USE PERSONAL DATA

Depending on the circumstances, TertiaSync may process personal data to:

provide and operate the Platform;
create and manage accounts;
authenticate users;
personalize academic resources and features;
provide CGPA and academic organization tools;
operate the contribution and moderation system;
administer Aura Points;
send relevant account or Platform communications;
maintain security;
detect and prevent abuse;
investigate violations;
respond to support requests;
comply with legal obligations;
establish, exercise, or defend legal claims; and
maintain, secure, and improve the Platform.

TertiaSync will not intentionally process personal data for purposes incompatible with the purpose for which it was collected without an appropriate legal basis or notice where required.

05

THIRD-PARTY SERVICE PROVIDERS AND DATA SHARING

TertiaSync does not sell or rent users' personal data to advertisers or data brokers.

TertiaSync may use third-party service providers and infrastructure providers necessary to operate the Platform.

Depending on the services actually used by TertiaSync, these may include:

Supabase

Database infrastructure, authentication, and related backend services.

Vercel

Platform hosting and deployment infrastructure.

Domain Registrar

TertiaSync may use a third-party domain registrar to register and manage its domain name. Such a provider may process information associated with the TertiaSync account and domain registration.

Other Infrastructure and Technology Providers

TertiaSync may use other providers for services such as email delivery, security, analytics, monitoring, storage, or other technical functionality where necessary to operate the Platform.

TertiaSync will not list a provider as an active data processor merely because we may use that provider in the future.

Where third parties process personal data on TertiaSync's behalf, TertiaSync will take appropriate steps to establish relevant safeguards as required by applicable law.

Payment Providers

The November 14, 2026 MVP does not offer Premium subscriptions or paid plans.

If paid services are introduced later, the applicable payment providers and relevant data-processing practices will be reflected in an updated Data Policy where appropriate.

06

ACCESS CONTROLS AND DATA SECURITY

TertiaSync uses reasonable technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, disclosure, or destruction.

These measures may include:

secure password authentication mechanisms;
encryption during transmission;
database access controls;
Row Level Security (RLS), where implemented;
role-based access control (RBAC);
restricted administrative access;
security monitoring and controls; and
appropriate maintenance and security practices.

TertiaSync's role-based access controls may restrict administrative or role-specific functionality according to authorized permissions.

For example, authorized representative functionality may provide certain users with capabilities that ordinary users do not have.

No online service can guarantee absolute security. Users are also responsible for taking reasonable steps to protect their accounts and devices.

07

DATA RETENTION

TertiaSync aims to retain personal data only for as long as reasonably necessary for the purposes for which it was collected, subject to applicable legal or operational requirements.

Account and Profile Data

Personal data associated with a user's account, including optional profile information such as phone number and matriculation number, will be deleted when the user deletes their account, subject to limited technical, legal, security, or other circumstances where retention is required or reasonably necessary.

Academic Information

Academic information entered into personal academic tools will be deleted with the user's account, subject to applicable technical or legal limitations.

Contribution Records

Information necessary to maintain the integrity of the contribution system may be handled separately from ordinary account information.

Approved Contributions

Approved academic materials do not automatically disappear from the TertiaSync Archive when the contributor deletes their account.

An approved contribution may remain available because it forms part of TertiaSync's academic resource archive.

However, the contributor's personal account information will not remain attached to the contribution merely because the contribution remains available.

An approved contribution may be removed where:

required by law;
a valid copyright or other rights complaint requires removal;
it violates TertiaSync policies;
it is fraudulent, harmful, or inappropriate;
removal is necessary to protect users or TertiaSync; or
TertiaSync otherwise determines removal is appropriate.
08

ACCOUNT DELETION

Users may request deletion of their TertiaSync account through the available account settings or designated support channel.

When an account is deleted, TertiaSync will delete personal data associated with that account in accordance with this Policy and applicable law.

Deleting an account does not automatically delete approved academic contributions that have already been published in the Archive.

Approved contributions are treated separately from the user's personal account data.

TertiaSync may retain limited information where necessary for legal compliance, security, fraud prevention, dispute resolution, enforcement of rights, or protection of the Platform and its users.

09

COOKIES, LOCAL STORAGE AND SIMILAR TECHNOLOGIES

TertiaSync may use cookies, local storage, or similar technologies to support Platform functionality.

These may be used for:

Authentication and Sessions

Maintaining login sessions and helping protect accounts.

Preferences

Remembering settings such as interface preferences where applicable.

Security

Supporting detection and prevention of suspicious activity.

Analytics

Where analytics tools are implemented, they may help TertiaSync understand general Platform usage and improve performance.

The specific technologies and retention periods may change as TertiaSync develops.

Users may manage or delete cookies and local storage through their browser or device settings. Disabling certain technologies may affect Platform functionality.

10

YOUR DATA PROTECTION RIGHTS

Subject to applicable law and relevant limitations, users may have rights including:

Right of Access

Request information about personal data TertiaSync processes about you.

Right to Rectification

Request correction of inaccurate or incomplete personal data.

Right to Erasure

Request deletion of personal data in appropriate circumstances.

Right to Restriction

Request restriction of certain processing where applicable.

Right to Data Portability

Request personal data in a portable format where applicable.

Right to Object

Object to certain forms of processing where applicable.

Right to Withdraw Consent

Where processing is based on consent, withdraw consent subject to applicable limitations.

Exercising a data-protection right does not necessarily require TertiaSync to remove an approved academic contribution from the Archive where the contribution is retained separately from the user's personal data and there is a lawful basis for retaining it.

To exercise a data-protection right, contact:

tertiasync@gmail.com

TertiaSync may reasonably verify the identity of a requester before processing a request. Requests will be handled within the period required by applicable law.

11

AGE AND ELIGIBILITY

TertiaSync is currently designed for undergraduate students enrolled at Nigerian tertiary institutions.

TertiaSync does not intentionally seek to collect personal data from individuals who are not eligible to use the Platform.

Where TertiaSync becomes aware that an ineligible individual has created an account, appropriate action may be taken in accordance with applicable law and the Terms of Use.

12

INTERNATIONAL DATA PROCESSING

Some third-party infrastructure or technology providers used by TertiaSync may process or store information outside Nigeria.

Where personal data is transferred or made accessible outside Nigeria, TertiaSync will take appropriate steps required by applicable Nigerian data-protection law.

The location of third-party infrastructure may change as TertiaSync develops.

13

DATA BREACHES AND SECURITY INCIDENTS

If TertiaSync becomes aware of a personal-data breach or security incident requiring action under applicable law, TertiaSync will take appropriate steps to investigate, mitigate, document, and report the incident as required.

Where notification to affected users or an appropriate authority is legally required, TertiaSync will provide such notification in accordance with applicable requirements.

14

CHANGES TO THIS POLICY

TertiaSync may update this Data Policy when necessary to reflect changes to:

the Platform;
data-processing practices;
technology;
security measures;
legal or regulatory requirements; or
other relevant circumstances.

Material changes may be communicated through the Platform or another appropriate channel.

The Last Updated date will be changed when this Policy is revised.

15

CONTACT AND PRIVACY REQUESTS

For privacy questions, data requests, complaints, or concerns:

Location:Ogbomoso, Oyo State, Nigeria

© 2026 TertiaSync. All Rights Reserved.

TertiaSync — The Centralized Academic Operating System
Built in Ogbomoso, Nigeria.