Privacy Notice
Last updated: 24 September 2026
1. Who we are
This notice covers the TENTai portal, part of an integrated facilities and property management platform operated by TENTai. Each organisation on the platform has its own clients, tenants, vendors and staff, and its data is kept fully separated from every other organisation’s.
Using this portal — as a tenant, applicant, vendor, landlord or staff member — means your personal data is processed as described below.
Data controller: TENTai. Each client organisation’s data is controlled by TENTai under its management agreement with that client.
Data Protection Officer: Ebube Ikechwu. Contact at ebubei@tfmlconsultant.com.
2. What we collect, and why
- Identity and contact — name, email, phone number, Telegram ID. To create your account, reach you, and attribute actions to the right person.
- Tenancy application details — employment, address, next of kin, income. To assess a tenancy application, with your consent.
- Special-category information, only where a tenancy application asks for it — religion, marital status. Only with your explicit, separate consent; see section 4.
- Identity documents — uploaded ID, proof of address, employment letters. To verify who you are and support a tenancy or vendor application.
- Property photographs and video — maintenance job evidence, inspection photos. To document work carried out, including inside occupied properties.
- Financial records — payments, rent charges, service charges, payout details. To bill correctly, collect and remit money, and keep an accurate account.
- Communications — messages sent through WhatsApp, Telegram or the web portal, and your request history. To respond to what you have asked, and keep a record of what was said.
We do not collect more than the above for these purposes, and we do not sell personal data to anyone.
3. The legal basis for processing your data
- Reviewing a tenancy application — your consent, and steps taken before entering a contract.
- Running your lease, rent and service charges — performance of a contract with you.
- Managing a vendor relationship and paying vendors — performance of a contract.
- Handling maintenance requests and work orders — our legitimate interest in operating the property properly.
- Keeping an audit trail of who did what — a legal obligation, and our legitimate interest in an accountable system.
- Religion and marital status, where collected — your explicit, separate consent only. Never assumed, and never required to proceed.
4. Automated checks on your documents — what they do, and do not, decide
When you submit a tenancy application, some of the initial checks on your documents may be assisted by an automated system. Exactly what that means:
- The system may check that your documents are complete, legible, internally consistent and not duplicated. It records what it found — never a conclusion about you.
- No automated system decides, scores, ranks or recommends an outcome on your application. A member of staff always reviews your application and documents personally, and a second, independent member of staff makes the final decision. Neither may be the same person.
- Whatever a human reviewer decides, they must record their own stated reason. The automated findings inform that reason; they never replace it.
- If you believe an automated finding about your documents is wrong, you can ask the reviewing team to look again. This is built to be contestable, not final.
- Religion and marital status, where asked, are never sent to any automated system. They are seen only by the human reviewers, and only with your explicit consent.
Consent statement. By continuing with an application you will be shown a specific consent statement covering this. The exact wording you agreed to is kept on your application record, so a later change to this notice never silently changes what you consented to.
5. How long we keep your data
- A tenancy application that is rejected or withdrawn — 90 days, then your personal details are permanently removed. A record that a decision was made is kept, without your personal details, so the process remains auditable.
- An approved tenancy application — for the length of the tenancy, plus 6 years after it ends.
- Financial records (payments, rent, remittances) — retained as a permanent financial record. This cannot be deleted on request, for the same reason a bank statement cannot be un-issued, but you can always ask what is held.
- The audit trail of actions taken on your account — retained permanently, and cannot be altered by anyone, including TENTai staff.
6. Your rights
You can ask us to:
- Show you what we hold about you. Much of it is already visible to you directly — your requests, rent history, statements, payment history, or your own application while it is in progress.
- Correct inaccurate information. Some of this you can fix yourself in your profile; for the rest, ask your administrator or the Data Protection Officer.
- Delete your data. This is automatic for a rejected or withdrawn application after 90 days (section 5). For anything else, contact the Data Protection Officer; where a legal reason such as a financial record means we cannot fully delete something, we will explain that clearly rather than simply refusing.
- Withdraw consent you previously gave.
We aim to respond within 30 days, as required by the Nigeria Data Protection Act 2023. To exercise any of these rights, contact Ebube Ikechwu at ebubei@tfmlconsultant.com.
7. Who else sees your data
We use service providers to run this platform — for hosting, messaging, payments and error monitoring. They process your data only to provide that service to us, under contract, and never for their own purposes. They include our hosting and database provider, our email and messaging providers, our payment processors, and our error-monitoring provider.
Some are based outside Nigeria. Our production systems are hosted in Ireland, and transfers outside Nigeria are made under contractual clauses with each provider, as section 41 of the Nigeria Data Protection Act 2023 permits. You can ask us at ebubei@tfmlconsultant.com for the current list of providers and the safeguards that apply to each.
8. How we keep your data secure
- All data is encrypted in transit and at rest.
- Access is restricted by role — a member of staff can only see what their role and assignment require, and this is enforced by the system itself, not only by policy.
- Every action taken on your data is recorded in a permanent, tamper-evident audit trail.
- Identity documents and property photographs and video are stored privately, and are not publicly accessible by URL.
9. If something goes wrong
We keep a written procedure for handling a personal data breach, and it runs to fixed deadlines:
- Our Data Protection Officer is told immediately, without waiting for certainty about what happened.
- Where a breach is likely to result in a risk to your rights and freedoms, we notify the Nigeria Data Protection Commission within 72 hours of becoming aware of it.
- Where a breach is likely to result in a high risk to you, we tell you as well, immediately and in parallel — not after the Commission has responded.
We will tell you what happened, what data was involved, what we are doing about it, and what you can do to protect yourself.
10. Changes to this notice
We will update this notice as needed and change the date at the top. Where a change is significant, we will take reasonable steps to let you know before it takes effect.
11. Contact
Data Protection Officer: Ebube Ikechwu — contact at ebubei@tfmlconsultant.com.
For anything else, contact TENTai through the Portal. Our Terms of Service and Refund Policy sit alongside this notice.