Privacy Policy
Effective 29 July 2026. This policy explains how TREJJ Communications Limited handles personal data in TREJJ NetOps.
Our roles
TREJJ is responsible for personal data used to create accounts, secure the platform, manage billing and provide support. For subscriber and provider-customer data entered by an ISP, the ISP generally determines why the data is used and TREJJ processes it to provide the service.
Information we collect
We may collect account identity and contact information, organisation and staff records, login and multi-factor authentication events, IP addresses, device and browser information, support messages, billing references and audit events.
Provider workspaces may contain customer contact details, addresses, service plans, PPPoE or RADIUS identifiers, router identifiers, site information, voucher records, connection status and approved transaction references. Secret credentials are stored only where required and are protected separately.
How we use information
We use information to create and secure accounts, separate provider workspaces, deliver requested features, calculate usage, investigate abuse, provide support, improve reliability, keep required records and comply with lawful obligations. On TREJJ’s own website, an IP-derived country may be used to select a matching display currency; the platform stores only a short-lived country preference for this purpose.
Lawful basis
Depending on the context, processing is based on performing the service agreement, legitimate operational and security interests, compliance with law, or consent where consent is required. Providers are responsible for identifying the lawful basis for their subscriber data.
Sharing and service providers
We may use carefully selected hosting, email, security, payment or technical service providers where necessary. We do not sell personal data. We may disclose information when required by law, to protect users or the platform, or as part of a properly controlled business transfer.
A provider’s selected gateway, messaging vendor, domain provider, RADIUS service or network equipment may process information under that provider’s own account and terms.
Security
We use reasonable technical and organisational safeguards to protect account and service information. No system is risk-free, and providers must also protect their own accounts, routers and merchant credentials.
Retention
We retain data for as long as needed to provide the service, maintain security and audit records, resolve disputes and meet legal obligations. Retention varies by record type. Data may remain in protected backups for a limited recovery period after deletion from the active system.
International processing
Some service providers may process data outside the country where it was collected. Where required, TREJJ uses an approved legal basis and appropriate safeguards for cross-border transfers.
Your rights
Subject to applicable law, you may request information, access, correction, deletion, restriction, objection, portability or withdrawal of consent. Some requests must be directed to the ISP that controls the subscriber record. We may retain information where law, security or a legal claim requires it.
You may also complain to the Nigeria Data Protection Commission where the Nigeria Data Protection Act applies.
Cookies and local storage
We use essential session and security cookies to keep users signed in and protect requests. TREJJ’s own website may remember an IP-derived country for up to 30 days so prices remain in one matching currency. The interface may store a colour-theme preference on the device. Additional analytics or marketing technologies should not be enabled without an appropriate notice and consent mechanism where required.
Children
TREJJ NetOps accounts are intended for authorised business users. A provider serving schools or minors remains responsible for the notices, authority and safeguards required for that subscriber data.
Questions and changes
Submit privacy or security questions through the support-ticket system. Do not include passwords, private keys or full payment credentials. We may update this policy as the service or law changes and will publish the effective date above.