Privacy Policy SudoForce June 17, 2026

Privacy Policy

SudoForce Privacy Notice

SudoForce Privacy Notice

Effective date: 13 August 2026

This Notice explains how SudoForce Limited ("SudoForce", "we", "us" or "our") processes personal data through the SudoForce website, the SudoSIM website and platform, demo and contact forms, customer engagements, support channels and related communications. It also covers recruitment and visits to our physical premises.

It is issued under the Nigeria Data Protection Act 2023 (NDPA), the Nigeria Data Protection Act General Application and Implementation Directive 2025 (GAID), section 37 of the Constitution of the Federal Republic of Nigeria 1999 (as amended) and other applicable data protection laws.

Key terms. Personal data means information relating to an identified or identifiable natural person. Processing includes collecting, recording, organising, storing, using, disclosing, altering, restricting, deleting or otherwise handling personal data. A controller decides why and how personal data is processed; a processor handles it for a controller on documented instructions; and a data subject is the person to whom the data relates.

1. Who we are and how to contact us

SudoForce Limited provides cybersecurity services and develops and operates SudoSIM, a cyber-crisis simulation platform.

Contact itemDetails
Data controllerSudoForce Limited
AddressSuite 01, 3rd Floor Suite 1, Nusaiba Towers, Plot 117 Ahmadu Bello Way, Kado, FCT, Abuja
Privacy contact/DPOamina@sudoforce.com, Data Protection Officer
General enquirieshello@sudoforce.com
Telephone+234 806 701 7054
Websiteshttps://sudoforce.com and https://www.sudosim.io

Send a privacy request or complaint to the privacy contact above. We will acknowledge and handle it under applicable law and our internal grievance procedure.

2. When SudoForce is a controller or processor

SudoForce as controller. We decide why and how personal data is processed for our websites, demo requests, sales contacts, account administration, platform security, fraud prevention, service management, legal compliance and our own business communications.

SudoForce also acts as controller for its recruitment, premises access and CCTV, payment administration and identity or corporate verification activities.

SudoForce as processor. A customer organisation normally decides the purpose of a SudoSIM exercise, selects participants and determines how exercise results will be used. For participant details, responses, observations and other content processed only on that customer's documented instructions, the customer is the controller and SudoForce acts as its processor.

If your organisation invited you to SudoSIM, its privacy notice and internal policies also apply. Contact your organisation first for questions about why it requires an exercise or how it uses the results. We will assist the organisation with valid requests.

SudoForce remains a controller for limited records it must process for its own security, legal compliance, billing, abuse prevention and defence of legal claims, even when it otherwise provides SudoSIM as a processor.

3. Personal data we collect

  • Contact and enquiry data. Name, email address, telephone number, job title, organisation, referral source, message content, meeting details and communication history.
  • Account and identity data. Name, email, organisation, user role, account identifiers, authentication credentials, password-reset records, one-time codes, multi-factor authentication settings, session identifiers and Google account identifiers where Google sign-in is used.
  • Organisation and service data. Organisation name, industry, administrators, authorised users, service configuration, subscription or contract details, billing contacts and support records.
  • Simulation and exercise data. Exercise assignment, participant role, attendance, scenario content, injects, responses, decisions, comments, actions, communications, timestamps, facilitator notes, observations, results, readiness measures, lessons learned and after-action reports.
  • Technical and usage data. IP address, approximate location derived from IP, browser, device, operating system, referring page, pages and features used, date and time, session events, audit logs, error reports and security events.
  • Cookie and storage data. Session and security cookies, consent choices, interface preferences and similar identifiers stored in a browser or device.
  • Support and correspondence data. Information supplied in emails, calls, support requests, surveys or other communications, including attachments.
  • Commercial and legal records. Contracts, invoices, payment status, due diligence records, authorised representatives and records needed for tax, audit, compliance or legal claims.
  • Recruitment and professional data. Job-application details, curriculum vitae, education and employment history, qualifications, references, interview notes, professional memberships, right-to-work evidence and permitted background-check results.
  • Visitor and premises security data. Visitor name, organisation, host, arrival and departure times, access badge records, vehicle details, incident records and CCTV images where cameras operate.
  • Verification and due-diligence data. Identity documents or numbers, company registration records, directors, officers, beneficial owners, authorised representatives, screening results and related verification records.
  • Assessment, allegation and disciplinary data. Exercise observations, readiness or performance measures, alleged conduct, investigation context, criminal offence information or proposed disciplinary outcomes where a customer chooses to include or derive such information through SudoSIM.

4. Where the data comes from and how we process it

  • Directly from you when you contact us, request a demo, create or use an account, participate in an exercise or communicate with us.
  • From your employer, customer organisation, organisation administrator, facilitator or a colleague who invites you to SudoSIM.
  • From an identity provider, such as Google, if you choose federated sign-in.
  • Automatically from your browser, device, cookies, local storage, platform activity and security logs.
  • From service providers, referral partners, events and lawful public sources where relevant to a business relationship.
  • From job applicants, recruiters, referees, former employers, professional bodies and lawful screening providers.
  • From premises visitors, hosts, access control systems and CCTV equipment.
  • From banks, payment providers, identity verification providers, company registries and lawful due-diligence sources.

If another person gives us your data, we require them to have authority and a valid lawful basis to do so. Where the NDPA requires us to provide information directly to you, we will do so unless a statutory exception applies.

Means of processing. We process personal data through manual and automated means, including website and platform forms, account and authentication systems, customer and facilitator inputs, hosted databases and storage, security and activity logs, reporting tools, support and business workflows, and controlled disclosures to authorised users and contracted service providers.

Accuracy. Please keep your account and contact information accurate and current. Use available profile controls or contact the privacy team to correct information. We may ask you to verify important details before they are stored in a permanent record.

5. Why we process personal data and our lawful bases

ActivityPurposeLawful basis
Websites and securityOperate the sites, deliver pages, store preferences, prevent abuse, protect systems and diagnose faults.Legitimate interests; legal obligation where applicable; consent for non-essential tracking.
Enquiries and demosRespond, arrange meetings, understand requirements and prepare a proposal.Steps requested before a contract; legitimate interests.
Accounts and accessRegister users, authenticate them, administer roles, manage sessions, support multi-factor authentication and recover accounts.Contract; legitimate interests in security.
SudoSIM deliveryCreate, run, monitor and report on exercises and provide customer-requested features.Contract. For customer-controlled exercise data, the customer's lawful basis applies and SudoForce follows documented instructions.
Support and service noticesResolve support requests and send security, availability, account or contract notices.Contract; legitimate interests; legal obligation where required.
Reliability and improvementMeasure system performance, correct defects and improve features using technical telemetry and aggregated or de-identified information.Legitimate interests; consent where a non-essential tracking technology is used. Customer content is excluded unless authorised in writing.
MarketingSend product, event or service messages and measure engagement.Consent. We do not treat silence, inactivity or a pre-ticked box as consent.
Commercial recordsManage contracts, billing, accounting, audits and supplier or customer relationships.Contract; legal obligation; legitimate interests.
Compliance and claimsMeet legal duties, respond to valid authority requests, investigate misuse and establish, exercise or defend legal claims.Legal obligation; legitimate interests; public interest where applicable.
Sensitive personal dataProcess sensitive data only when necessary, proportionate and permitted by section 30 of the NDPA.Explicit consent or another ground permitted by section 30. Customers should avoid real sensitive data in simulations.
RecruitmentReceive applications, assess suitability, communicate with candidates, obtain references and administer recruitment.Steps before an employment contract; legitimate interests; legal obligation. Use a valid added condition for sensitive or background-check data.
Visitors and CCTVManage premises access, protect people and property, and prevent or investigate security incidents.Legitimate interests in premises security; legal obligation where applicable. Provide signs and complete a DPIA where required.
PaymentsIssue invoices, receive and reconcile payments, process refunds, prevent fraud and keep accounting records.Contract; legal obligation; legitimate interests.
VerificationVerify identity, authority, corporate status and ownership and complete lawful customer, supplier or personnel checks.Steps before a contract; legal obligation; legitimate interests; consent where required.
Assessment or disciplinary useRecord or display customer-supplied observations, allegations, performance measures or investigation context in an exercise or report.The customer determines and documents the lawful basis. SudoForce processes the data only on documented instructions, except for its own security and legal records.

Where we rely on legitimate interests, we assess the purpose, necessity, reasonable expectations and impact on your rights. You may request information about that assessment. Where we rely on consent, you may revoke it at any time without affecting processing that was lawful before revocation.

6. SudoSIM exercises, analytics and AI-assisted features

SudoSIM allows customer organisations to run realistic exercises, assign roles, release injects, record participant actions and comments, add facilitator observations and produce after-action reports. Authorised administrators and facilitators within the customer organisation can access the exercise data permitted by their roles.

SudoSIM may provide AI-assisted tools for drafting scenarios or injects and for supporting exercise preparation or review. AI output is assistance, not a substitute for human judgement. Customers and facilitators remain responsible for reviewing prompts, outputs and decisions made from them.

We do not use identifiable customer exercise content to train a general-purpose model or to improve a model for other customers unless the customer gives separate written authorisation and an appropriate lawful basis exists.

SudoSIM may calculate readiness measures and display analytics. These tools support review by authorised people. We do not make a decision producing legal or similarly significant effects on a person solely through automated processing.

If a customer uses exercise data, observations, allegations or readiness measures for employment, access, investigation or disciplinary purposes, that customer must provide an appropriate notice, document its lawful basis, complete any required DPIA, limit access and ensure meaningful human review. SudoForce does not decide the employment or disciplinary outcome.

Do not upload real incident records, credentials, security secrets, classified material or sensitive personal data to a simulation unless your organisation has authorised that use and confirmed the lawful basis, necessity, safeguards and contractual scope. Use fictional, masked or de-identified data where possible.

7. Who receives personal data

  • Your organisation. Authorised administrators, facilitators, reviewers and other users can access data according to their roles and the exercise configuration.
  • Technology service providers. Hosting, content delivery, database, storage, backup, authentication, email, monitoring, customer support, security and AI providers process data under contract and only for the agreed service.
  • Visible public site providers. SudoSIM uses Vercel for website delivery. Google services may be used for scheduling, Google sign-in and reCAPTCHA on SudoForce forms.
  • Professional advisers. Lawyers, auditors, insurers, accountants and consultants may receive data where needed and subject to confidentiality duties.
  • Authorities and legal recipients. We may disclose data where a valid law, court order or regulatory requirement applies, or where necessary to protect rights, safety and systems.
  • Corporate transaction recipients. A genuine buyer, investor, lender or successor may receive limited data under confidentiality controls during a merger, financing, restructuring or sale.
  • Recruitment recipients. Recruiters, referees, former employers, professional bodies, screening providers and authorised hiring personnel may receive or provide limited applicant information.
  • Premises security recipients. Authorised security personnel, building management, CCTV or access control providers, emergency services and lawful authorities may receive visitor or incident information.
  • Payment and verification recipients. Banks, payment processors, auditors, identity verification providers and lawful registry or screening services may receive the data needed for their assigned function.

We do not sell personal data.

8. International transfers

Some service providers or authorised recipients may process data outside Nigeria. Before a transfer, we assess the destination, recipient and safeguards and use a mechanism permitted by Part VIII of the NDPA and the GAID, such as an adequate protection framework, binding corporate rules, contractual clauses, a certification mechanism or another statutory condition.

Before transferring personal data to a country for which the Nigeria Data Protection Commission has not made an adequacy decision, we obtain the data subject's specific and informed consent where the GAID requires it, unless an applicable statutory exemption lawfully permits the transfer. We explain the destination, purpose and material risks before requesting consent.

You may contact us for information about the safeguards applicable to your data.

9. Retention and deletion

We keep personal data only for as long as needed for the stated purpose, the customer contract, security, a legal duty or a legal claim.

Data categoryRetention rule
Demo requests and pre-contract sales enquiriesDelete within 6 months if the proposed contract does not materialise, unless a documented ground supports archiving for a future legal claim. If a contract begins, apply the relevant customer and contract schedule.
Marketing contactsUntil consent is revoked or after 24 months without meaningful engagement; retain a minimal suppression record to respect an opt-out.
Account and profile dataFor the account term and up to 90 days after closure, subject to security and legal records.
Customer simulation dataCustomer-configured period or contract term; if neither states a period, 12 months after the exercise. Delete active copies within 90 days after contract end.
Security and audit logs12 months, extended only for an active investigation or legal duty.
Support records3 years after closure.
Contracts, invoices and required compliance records6 years after the relationship ends, or longer where a law or claim requires.
BackupsOverwritten or rendered inaccessible within 90 days after deletion from active systems, unless isolated for security or legal reasons.
Unsuccessful recruitmentDelete within 6 months after the recruitment process ends unless the applicant gives separate consent to a stated talent pool period or retention is needed for a legal claim.
Visitor logs and CCTVVisitor logs for 6 months and CCTV for 30 days, unless an incident, investigation or legal duty requires a longer period.
Payment and due-diligence records6 years after the relevant transaction or relationship ends, or the longer period required by an applicable law or claim.
Assessment, allegation or disciplinary dataUse the customer-configured simulation period or the controlling contract; preserve longer only on the controller's documented lawful instruction or for an applicable legal duty or claim.

At the end of the retention period, we delete, anonymise or securely isolate the data. A deletion request may be refused or limited where retention is required by law, necessary for a claim or subject to another lawful exception. We will explain the basis where the law permits.

10. Cookies and similar technologies

We use cookies, local storage and similar technologies for site and platform operation. Necessary technologies support security, authentication, session management, load delivery, accessibility and preference storage. Where permitted by law, necessary technologies operate without an opt-in because the requested service cannot function reliably without them.

Optional analytics, advertising or other tracking technologies will not operate until you make an affirmative choice. The banner must provide equally clear "Accept optional" and "Reject optional" controls and a settings option. You can change your choice at any time through a persistent cookie settings link.

The SudoForce contact form uses Google reCAPTCHA to detect automated abuse. Google may receive device, browser, interaction and IP address data for that purpose. SudoSIM stores an interface appearance preference and uses account session technologies when a user signs in.

Browser controls can block cookies, but blocking necessary technologies may stop account login or other requested functions.

11. Security

We use risk-based technical and organisational safeguards intended to protect confidentiality, integrity and availability. Measures may include access controls, least privilege permissions, multi-factor authentication, encryption, secure development and change controls, logging, monitoring, backups, vendor review, personnel training, incident response and periodic testing.

No service can guarantee absolute security. Users must protect credentials, use approved access methods and promptly report suspected compromise.

12. Your rights

Subject to applicable conditions and exceptions, you may:

  • be informed about the processing of your personal data;
  • ask whether we process your data and obtain access to it and related information;
  • request correction of inaccurate, incomplete, out-of-date or misleading data;
  • request erasure where the data is no longer needed or no lawful basis remains;
  • request restriction of processing in the circumstances allowed by law;
  • object to processing based on legitimate interests and object at any time to direct marketing;
  • revoke consent at any time where consent is the basis of processing;
  • receive qualifying data in a structured, commonly used and machine-readable form and request transfer where technically feasible;
  • request human intervention, express your view and contest a qualifying automated decision; and
  • lodge a complaint with the Nigeria Data Protection Commission or seek judicial redress.

To exercise a right, contact amina@sudoforce.com. State the account, organisation or exercise concerned and the right you wish to exercise. We may request proportionate information to verify identity and authority. We will respond within the period required by applicable law and explain any lawful refusal or extension.

If SudoForce processes the relevant data only for a customer organisation, we may send the request to that organisation or ask you to contact it directly. We will assist it as required by contract and law.

13. Direct marketing

We send promotional messages only where valid consent exists. Marketing consent is separate from access to a demo or service, and refusal will not affect a requested service. Each marketing message will provide an unsubscribe method. You may also revoke consent through the privacy contact. We may retain a minimal suppression record so we do not add you again by mistake.

14. Children and sensitive personal data

Our websites and SudoSIM are business services and are not directed to persons under 18. A customer must not invite a child or a person lacking legal capacity without prior written agreement, a valid legal basis and the safeguards required by the NDPA. If we learn that data was collected contrary to this rule, we will restrict or delete it as appropriate.

SudoSIM does not require real health, biometric, genetic, race or ethnic origin, religious belief, sex life, political affiliation or trade union data for an ordinary exercise. Customers should use fictional or de-identified scenario data. Where sensitive data is genuinely necessary, the controller must document a section 30 ground, minimise the data and apply added safeguards.

Criminal offence, allegation, disciplinary, identity-document, financial and CCTV information must be strictly limited, access-controlled and covered by a documented lawful basis and risk assessment. The customer controller remains responsible for any employment, investigation or disciplinary use of SudoSIM information.

15. Personal data breaches

We maintain procedures to detect, assess and respond to personal data breaches. Where required, we will notify the Nigeria Data Protection Commission without undue delay and, where feasible, within 72 hours after becoming aware of a breach likely to create a risk to individuals. Where a breach is likely to create a high risk, we will communicate with affected individuals immediately after becoming aware, using clear language and practical mitigation advice.

When SudoForce acts as processor, it will notify the customer controller without undue delay and provide information reasonably needed for the customer's response.

16. If you do not provide requested data

Fields marked as required are needed to respond to an enquiry, arrange a demo, create or secure an account, or provide a contracted service. If you do not provide them, we may be unable to complete that action. Optional fields, such as a demo-request telephone number or referral source, may be left blank unless the form states otherwise.

If you do not provide information required for recruitment, premises access, payment or lawful verification, we may be unable to assess an application, admit you to a restricted location, complete a transaction or enter or continue the relevant relationship. We will identify optional fields at the point of collection.

17. Third-party links and services

Our sites may link to external services, including scheduling platforms and social networks. The external operator controls its own processing when you leave our service or interact directly with it. Review that operator's privacy notice before providing data.

18. Changes to this Notice

We may update this Notice when our services, providers or legal duties change. We will post the revised version on both websites, change the effective date and provide a more prominent notice where a change materially affects your rights or the use of your data. Where a new purpose requires consent, we will request consent before that processing begins.

19. Complaints and regulatory contact

Please first send a complaint to amina@sudoforce.com so we can investigate and provide an internal remedy. This does not limit your right to complain directly to the Nigeria Data Protection Commission or to seek relief in court.

ItemDetails
RegulatorNigeria Data Protection Commission
AddressNo. 12 Dr Clement Isong Street, Asokoro, Abuja, Nigeria
Emailinfo@ndpc.gov.ng
Telephone+234 (0) 916 061 5551
Websitehttps://ndpc.gov.ng
Scroll to Top