Last reviewed: July 2026
Effective: 6 July 2026Plain English summary: We collect the minimum data needed to run your account. We never sell your data. Your client data belongs to you. You can request deletion at any time.
Ngozi CRM is operated by A-One Global Resourcing Ltd (AOGRL), a company incorporated in Mauritius (Business Registration No. C23014789). References to "we", "us", or "our" mean AOGRL.
For data protection purposes, AOGRL is the data controller for account and billing data. You (the clinic owner) are the data controller for your clients' personal data stored within the platform.
Contact: privacy@ngozi-crm.beauty
Data you enter about your own clients โ names, contact details, treatment notes, appointment history, invoices, photos โ is your data. We process it on your behalf as a data processor, not a data controller. We do not access, analyse, or share it except to provide the service.
If you submit a contact or trial request form on our website, we collect your name, email, phone, and clinic name to follow up with you about Ngozi CRM.
For users in Nigeria, we comply with the Nigeria Data Protection Regulation (NDPR) 2019 and its Implementation Framework, as administered by the National Information Technology Development Agency (NITDA). We conduct Data Protection Impact Assessments for high-risk processing and appoint a Data Protection Compliance Organisation (DPCO) as required.
For users in South Africa, we comply with the Protection of Personal Information Act 4 of 2013 (POPIA). We process personal information lawfully and only for the purposes set out in this policy. You have the right to object to processing and to lodge a complaint with the Information Regulator at inforegulator.org.za.
For users in Kenya, we comply with the Kenya Data Protection Act 2019 and the regulations thereunder. You have the right to access, correct, and delete your personal data. Complaints may be lodged with the Office of the Data Protection Commissioner (ODPC) at odpc.go.ke.
As a company incorporated in Mauritius, we are subject to the Mauritius Data Protection Act 2017. We are registered with the Data Protection Office (DPO) of Mauritius. Complaints may be directed to the Data Protection Office at dataprotection.govmu.org.
We respect applicable data protection laws in all markets where we operate, including the Ghana Data Protection Act 2012, the Senegal Law on Personal Data Protection (Law 2008-12), and the Ethiopia Personal Data Protection Proclamation. Users in these markets have equivalent rights to access, correct, and delete their data by contacting us at privacy@ngozi-crm.beauty.
Your data is stored on:
All data is encrypted in transit (TLS 1.2+) and at rest. Access is role-based โ staff members only see data belonging to their own organisation. We perform regular backups.
Payment data never touches our servers. PayPal processes all card and payment information directly under their own PCI-DSS compliance programme.
We do not sell, rent, or trade your personal data. We share it only with:
All sub-processors are bound by data processing agreements and operate under equivalent data protection standards.
NgoziCRM offers an optional Google Calendar integration that allows appointment bookings to be automatically added to your Google Calendar. This integration is entirely optional and must be explicitly authorised by you.
What we access: When you connect your Google Calendar, NgoziCRM requests the https://www.googleapis.com/auth/calendar.events scope. This allows us to:
What we do NOT do: We do not read, scan, store, analyse, or share any of your existing Google Calendar events. We only interact with events that NgoziCRM itself has created. Your personal or existing calendar data is never accessed or used.
Token storage: Your Google OAuth refresh token is encrypted at rest in our database and used solely to maintain the connection. It is never shared with third parties.
Revoking access: You can disconnect your Google Calendar at any time from NgoziCRM's Settings page, or by visiting your Google Account permissions page and removing NgoziCRM. Upon revocation, we delete your stored token within 24 hours.
Our use of Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.
When you use NgoziCRM's WhatsApp reminder and re-engagement features, your clients' phone numbers are transmitted to Meta Platforms (WhatsApp) to deliver messages on your behalf. This transmission is governed by WhatsApp's own Privacy Policy and Meta's Terms of Service. We only send WhatsApp messages to clients who have provided their phone number to your clinic โ we do not use these numbers for any other purpose. You are responsible for ensuring you have appropriate consent from your clients to contact them via WhatsApp.
Your data may be processed in the EU, UK, and USA (via our infrastructure providers). Where transfers occur outside the EEA, we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards as required by UK and EU GDPR.
Under UK GDPR, EU GDPR, and applicable data protection laws, you have the right to:
To exercise any of these rights, email privacy@ngozi-crm.beauty. We will respond within 30 days.
You also have the right to lodge a complaint with your local supervisory authority:
We use essential cookies only for session management and authentication. No advertising or tracking cookies. See our Cookie Policy for full details.
Ngozi CRM is a B2B platform for business owners. We do not knowingly collect data from anyone under 18. If you believe a minor has submitted data to us, please contact us immediately.
We will notify active users by email of any material changes at least 14 days before they take effect. The "Last reviewed" date at the top of this page reflects the most recent update.
A-One Global Resourcing Ltd (AOGRL)
Souillac, Mauritius
Email: privacy@ngozi-crm.beauty
Website: ngozi-crm.beauty