Effective 28 July 2026

Data Use Policy

How Afialytics uses Customer Data, metadata, and AI Inputs/Outputs when providing governed analytics—complementing our Privacy Policy and Terms.

1. Purpose of this Policy

This Data Use Policy explains how we handle Customer Data inside the Service: what we process, why, what we do not do, and how responsibilities are shared with your organization. It is designed for analytics platforms where your warehouses and business metrics stay yours.

If a signed customer agreement conflicts with this Policy, the signed agreement controls for that customer.

2. Roles and responsibilities

Your organization decides what data to connect, who may access workspaces, which tables are allowed, and how dashboards are shared. For personal data inside Customer Data, your organization is typically the data controller under the Nigeria Data Protection Act, 2023.

Afialytics provides the platform and processes Customer Data on your documented instructions (through product configuration and agreements) as a data processor / data compute intermediary—except for account and operational data described in the Privacy Policy, where we act as controller.

You must ensure you have a lawful basis and any required notices or consents before processing personal data through the Service.

3. Categories of data in scope

A. Customer Data

  • Schemas, tables, and column metadata discovered from connected sources;
  • Query results and cached analytical datasets generated for your workspaces;
  • Logical models, synonyms, descriptions, and AI context you store;
  • Reports, dashboards, filters, notes, embeds, and sharing settings;
  • Prompts, clarification turns, and Outputs from Oma, OmaIQ, Oma Modeler, and related features when tied to your tenant.

B. Platform and account data

Identity, membership, billing status, product telemetry, and security logs are handled primarily under the Privacy Policy. We may use aggregated, de-identified usage metrics to improve reliability and capacity planning without identifying your end users where practicable.

4. How we use Customer Data

We use Customer Data only to:

  • Connect to sources you authorize and refresh catalogs you request;
  • Enforce workspace table access, roles, and dashboard permissions;
  • Execute and display queries, reports, and live tiles;
  • Power AI-assisted features you invoke, using the minimum context needed for the request;
  • Provide support when you grant access or share diagnostics;
  • Maintain security, tenancy isolation, abuse prevention, and service integrity;
  • Comply with law and lawful requests.

We do not use Customer Data to sell advertising, to build marketing profiles about your employees or customers, or to train generalized foundation models for other customers, unless you expressly opt in under a written agreement.

5. AI features and model providers

When you use Oma or related agents, Inputs and relevant workspace context may be sent to model providers we engage as subprocessors to generate Outputs. Those providers are bound contractually to process data for providing the feature—not to use your Customer Data for their own advertising.

You should avoid pasting secrets or unnecessary sensitive personal data into prompts. Review Outputs before operational use. AI suggestions are assistive, not a substitute for human judgment or certified reporting controls.

6. Access within your organization

Owners and admins can provision members, assign workspaces, and adjust capabilities. Dashboard editors can share boards and restrict tabs or charts. You are responsible for least-privilege configuration and for offboarding people who should no longer have access.

7. Subprocessors and infrastructure

We use vetted infrastructure and service providers (for example cloud hosting, email delivery, and AI inference) to operate the Service. They may process Customer Data or personal data only to perform services for us and must implement appropriate security measures.

We will maintain a current description of material subprocessors on request via [email protected] and will provide notice of material changes where required by customer agreements.

8. Storage location and transfers

Customer Data may be processed in regions where our primary infrastructure and subprocessors operate. Cross-border transfers of personal data are handled with NDPA-aligned safeguards described in the Privacy Policy. If you require a specific residency commitment, it must be agreed in writing.

9. Retention and deletion

Active Customer Data remains available while your organization uses the Service. After termination or a deletion request from an authorized admin, we will delete or irreversibly de-identify Customer Data from active systems within a commercially reasonable period (typically within thirty (30) to ninety (90) days), except where retention is required by law, dispute resolution, or secure backup cycles that are later purged on schedule.

You should export any Customer Data you need before closure. Cached query results and ephemeral diagnostics may expire sooner according to product design.

10. Security incidents affecting Customer Data

If we become aware of a personal data breach affecting Customer Data we process for you, we will notify your organization’s designated contacts without undue delay and provide information reasonably available to help you meet your NDPA obligations, as further described on our Security page and in customer agreements.

11. Your commitments

You agree to:

  • Connect only sources you are authorized to use;
  • Configure access so users see only data they are permitted to see;
  • Avoid using the Service as a system of record for categories of data we have not agreed to support;
  • Respond to data subject requests that relate to Customer Data you control;
  • Keep contact details for security and privacy notices current.

12. Changes

We may update this Policy by posting a revised version with a new effective date. Material changes affecting Customer Data processing will be communicated to admin contacts where appropriate.

13. Contact

Questions about this Data Use Policy: [email protected]. Security incidents: [email protected]. Legal: [email protected].