Last updated: May 1, 2026
1. Data Encryption
We implement industry-standard encryption to protect your data:
- In Transit: All data transmitted between your device and our servers is encrypted in transit using TLS (Transport Layer Security) 1.2 or higher
- At Rest: Personal data is encrypted at rest by our infrastructure providers (e.g., Supabase, which stores data on AES-256-encrypted volumes)
- Backups: Backup data is encrypted by our database provider
2. Access Controls
We maintain strict access controls to prevent unauthorized access:
- Role-based access control (RBAC) for all users
- Principle of least privilege - users only have access to necessary data
- Regular access reviews and audits
- Automatic session timeout after inactivity
3. Authentication Security
- Strong password policies (minimum 8 characters, complexity requirements)
- Password hashing using bcrypt (industry standard)
- Session tokens with secure, random generation
4. Security Headers
We implement modern security headers to protect against common web vulnerabilities:
- Content Security Policy (CSP) to prevent XSS and data injection attacks
- Strict-Transport-Security (HSTS) to enforce HTTPS connections
- X-Frame-Options to prevent clickjacking attacks
- X-Content-Type-Options to prevent MIME type sniffing
5. Network Security
- DDoS protection through our hosting provider
- Secure API endpoints with rate limiting
- Regular platform security updates
6. Data Backup and Recovery
- Our database provider (Supabase) performs regular automated backups
- Backup data is encrypted at rest
- Recovery procedures are in place to restore service in the event of data loss
7. Incident Response
In the event of a data breach or security incident:
- We will notify the Nigeria Data Protection Commission (NDPC) within 72 hours of becoming aware of a breach, and affected data subjects without undue delay, as required by the Nigeria Data Protection Act (NDPA) 2023
- We will investigate the incident and take appropriate remedial action
- We will document findings and implement measures to prevent recurrence
8. Physical Security
We do not operate our own data centres. Our platform runs on infrastructure from established providers (Supabase and Vercel), whose data centres maintain physical security controls, including:
- Controlled facility access and on-site security
- Surveillance and monitoring
- Environmental controls (fire suppression, climate control)
- Redundant power and network connectivity
9. Third-Party Security
- We use reputable service providers — Vercel (hosting), Supabase (database & authentication), Paystack (payments), and our email providers
- Data Processing Agreements (DPAs) are in place with our key vendors
- All third-party services are contractually obligated to protect your data
10. Compliance
Eduysle is committed to maintaining compliance with:
- NDPA 2023: Nigeria Data Protection Act (and its GAID 2025)
- GDPR: EU General Data Protection Regulation, where we process personal data of individuals in the EU/EEA
- PCI DSS: Payment Card Industry Data Security Standard (via our payment processors)
11. User Security Responsibilities
You play an important role in keeping your account secure:
- Use a strong, unique password for your Eduysle account
- Never share your login credentials
- Log out after each session, especially on shared devices
- Report suspicious activity immediately to hello@eduysle.com
12. Responsible Disclosure
We welcome responsible disclosure of security vulnerabilities. Please report security issues to hello@eduysle.com. We will investigate all reports and respond promptly. We do not pursue legal action against researchers who follow responsible disclosure practices.
13. Security Updates
We regularly review and update our security practices, and will notify users of significant security changes through platform notifications and email communications.
Contact Us
Email: hello@eduysle.com
Phone: +234 706 172 6605
Address: Trinity Mall, 79 Obafemi Awolowo Way, Ikeja, Lagos State 100271, Nigeria