Beta: We're currently in beta and gradually updating this landing page. Some content might be missing or incomplete.

Privacy Policy

Last updated: January 14, 2025

Product7 Technologies Limited ("Product7," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our feedback management platform and related services.

1Introduction and Scope

Product7 Technologies Limited, a company incorporated under the laws of the Federal Republic of Nigeria, operates the feedback management and customer experience platform accessible at https://product7.io and related services (collectively, the "Services").

This Privacy Policy ("Policy") describes our practices regarding the collection, processing, storage, and protection of personal data when you use our website, platform, mobile applications, and associated services. By accessing or using our Services, you acknowledge that you have read and understood this Policy.

1.1 Regulatory Framework

As a global company with African roots, we comply with:

  • Nigeria: Nigeria Data Protection Regulation (NDPR) 2019 and Nigeria Data Protection Act (NDPA) 2023
  • European Union: General Data Protection Regulation (EU) 2016/679 ("GDPR")
  • United States: California Consumer Privacy Act (CCPA), California Privacy Rights Act (CPRA), and applicable state privacy laws
  • International: Applicable data protection laws in jurisdictions where our customers operate

1.2 Incorporation by Reference

This Policy should be read in conjunction with:

  • Our Terms of Service
  • Our Cookie Policy
  • Our Data Processing Agreement for business customers

2Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person, including but not limited to names, email addresses, IP addresses, and behavioral data.
  • "Processing" means any operation performed on personal data, whether automated or manual, including collection, recording, organization, storage, adaptation, retrieval, use, disclosure, or destruction.
  • "Controller" means the entity that determines the purposes and means of processing personal data.
  • "Processor" means the entity that processes personal data on behalf of the controller.
  • "Customer Data" means personal data that our business customers submit, store, or process using our Services while acting as data controllers.
  • "Service Data" means operational and technical data we collect independently to maintain, secure, and improve our Services.
  • "User" means any individual using our Services, including end users of our customers' feedback boards.

3Data Controller Information

Data Controller: Product7 Technologies Limited

Registered Address: Lagos, Nigeria

Email: privacy@product7.io

Data Protection Contact: dpo@product7.io

4Categories of Personal Data We Process

4.1 Information You Provide Directly

When you register, subscribe, or interact with our Services, you may provide:

  • Account Information: Name, email address, company name, job title
  • Authentication Data: Passwords (hashed), SSO tokens, multi-factor authentication settings
  • Payment Information: Billing address, tax identification number (payment card details are processed solely by our PCI-DSS compliant payment processors)
  • Communication Data: Support tickets, feedback submissions, survey responses, chat messages
  • User-Generated Content: Feature requests, bug reports, comments, votes, roadmap contributions

4.2 Information We Collect Automatically

When you use our Services, we automatically collect:

  • Technical Data: IP address (for security and approximate geolocation), browser type and version, device identifiers, operating system
  • Usage Data: Pages visited, features accessed, click patterns, session duration, error logs
  • Integration Data: Information from connected third-party services (Slack, Jira, Linear, etc.) as authorized by you
  • Performance Data: Application response times, API usage, system health metrics

4.3 Information from Third Parties

We may receive information about you from:

  • Your Organization: When your employer or client provides us with your business contact information
  • Integration Partners: When you connect third-party services to Product7
  • Publicly Available Sources: Professional information from public profiles for B2B communication

4.4 Special Categories of Data

We do not intentionally collect special categories of personal data (racial or ethnic origin, political opinions, religious beliefs, health data, etc.). If such data is inadvertently provided through user-generated content, we will delete it upon discovery.

5Legal Bases for Processing

We process personal data only when we have a valid legal basis:

5.1 Contract Performance

  • Providing and maintaining your account
  • Processing transactions and billing
  • Delivering core platform functionality
  • Responding to support requests

5.2 Legitimate Interests

We rely on legitimate interests for:

  • Improving Service performance and user experience
  • Preventing fraud and ensuring platform security
  • Sending service-related communications
  • Aggregated analytics and product development
  • Enforcing our Terms of Service

5.3 Legal Obligations

  • Complying with Nigerian tax and accounting requirements
  • Responding to lawful requests from authorities
  • Maintaining records as required by law

5.4 Consent

  • Marketing communications (you may withdraw consent at any time)
  • Optional features requiring additional data processing
  • Non-essential cookies and analytics tools

6Purposes of Processing

6.1 Service Delivery

  • Create and manage user accounts
  • Facilitate feedback collection and management
  • Enable voting, commenting, and collaboration features
  • Provide customer support and help center functionality
  • Process and display product roadmaps and changelogs

6.2 Platform Operations

  • Authenticate users and manage access controls
  • Process payments and maintain billing records
  • Send transactional emails and in-app notifications
  • Integrate with third-party tools and services
  • Generate reports and analytics for customers

6.3 Security and Compliance

  • Detect and prevent fraudulent activities
  • Monitor for abuse and Terms of Service violations
  • Respond to legal requests and protect our legal rights
  • Maintain audit logs for security purposes

7Data Retention

We retain personal data only for as long as necessary to fulfill the purposes outlined in this Policy or as required by law:

Data CategoryRetention PeriodJustification
Active Account DataDuration of account + 30 daysService provision
Deleted Account Data90 days after deletionRecovery period
Payment Records7 yearsTax and accounting law
Security Logs1 yearSecurity requirements
Support Tickets2 years after resolutionService improvement

8Data Sharing and Disclosure

8.1 We Do Not Sell Personal Data

We do not sell, rent, or trade your personal data to third parties for their marketing purposes. This applies globally, including under the California Consumer Privacy Act (CCPA).

8.2 Service Providers and Sub-processors

We share personal data with carefully selected service providers who assist us in operating our Services. All sub-processors are bound by contractual obligations consistent with GDPR, NDPR, and CCPA requirements.

8.3 Legal Disclosures

We may disclose personal data when required by law or when we believe in good faith that disclosure is necessary to:

  • Comply with legal obligations, court orders, or government requests
  • Protect and defend our rights or property
  • Prevent fraud or protect against security threats
  • Protect the safety of any person

8.4 Business Transfers

If Product7 undergoes a merger, acquisition, or sale of assets, personal data may be transferred as part of the transaction. We will notify you via email and prominent notice on our Services before your personal data becomes subject to a different privacy policy.

9International Data Transfers

9.1 Primary Data Location

We store and process data on secure cloud infrastructure. Our primary servers are located in regions that ensure optimal performance and compliance for our global user base.

9.2 Cross-Border Transfers

When we transfer personal data internationally, we ensure appropriate safeguards:

  • For EU Users: We use Standard Contractual Clauses (SCCs) approved by the European Commission
  • For Nigerian Users: We comply with NDPR requirements for cross-border transfers
  • For US Users: We implement appropriate contractual and technical safeguards

9.3 Adequacy and Safeguards

We conduct transfer impact assessments for all international data transfers to ensure that the level of protection is not undermined regardless of where data is processed.

10Data Security

10.1 Technical Measures

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
  • Multi-factor authentication for administrative access
  • Regular security updates and patch management
  • Web Application Firewall (WAF) and DDoS protection
  • Secure development practices and code reviews
  • Regular penetration testing and vulnerability assessments

10.2 Organizational Measures

  • Access controls based on least privilege principle
  • Confidentiality agreements with all staff
  • Regular security training for employees
  • Incident response procedures
  • Business continuity and disaster recovery planning

10.3 Data Breach Response

In the event of a personal data breach, we will:

  • Notify relevant supervisory authorities within 72 hours (where required)
  • Notify affected data subjects without undue delay if the breach poses high risk
  • Document all breaches in our internal register
  • Take immediate steps to mitigate harm and prevent recurrence

11Your Rights

Depending on your location, you may have the following rights regarding your personal data:

11.1 Rights Under GDPR (EU/EEA Users)

  • Right of Access: Request confirmation and a copy of your personal data
  • Right to Rectification: Request correction of inaccurate data
  • Right to Erasure: Request deletion of your data ("right to be forgotten")
  • Right to Restriction: Request limitation of processing
  • Right to Data Portability: Receive your data in a portable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time

11.2 Rights Under NDPR/NDPA (Nigerian Users)

  • Right to be informed about data collection and processing
  • Right to access your personal data
  • Right to rectification of inaccurate data
  • Right to withdraw consent
  • Right to object to processing
  • Right to data portability
  • Right to complain to the Nigeria Data Protection Commission (NDPC)

11.3 Rights Under CCPA/CPRA (California Users)

  • Right to Know: Request disclosure of personal information collected
  • Right to Delete: Request deletion of personal information
  • Right to Correct: Request correction of inaccurate information
  • Right to Opt-Out: Opt-out of sale or sharing of personal information
  • Right to Non-Discrimination: Not be discriminated against for exercising rights

11.4 How to Exercise Your Rights

To exercise any of these rights, please contact us at privacy@product7.io. We will respond within 30 days (or as required by applicable law).

12Cookies and Tracking Technologies

12.1 Types of Cookies We Use

  • Essential Cookies: Required for core functionality (authentication, security)
  • Analytics Cookies: Help us understand Service usage (with consent)
  • Preference Cookies: Remember your settings and preferences

12.2 Cookie Management

You can manage your cookie preferences through:

  • Our Cookie Settings panel
  • Your browser settings
  • Browser extensions that block tracking

12.3 Do Not Track

We respect browser "Do Not Track" signals and Global Privacy Control (GPC) settings by automatically disabling non-essential cookies when detected.

13Children's Privacy

Our Services are not intended for individuals under 16 years of age (or 13 in jurisdictions where permitted). We do not knowingly collect personal data from children. If we discover that we have inadvertently collected such data, we will promptly delete it.

Parents or guardians who believe we may have collected information from their child should contact us immediately at privacy@product7.io.

14Third-Party Links and Integrations

Our Services may contain links to third-party websites and integrate with third-party services (Slack, Jira, Linear, etc.). We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing personal data.

15Updates to This Policy

We may update this Policy to reflect changes in our practices, legal requirements, or Service features. We will notify you of material changes through email and prominent notice on our Services.

For material changes that affect your rights, we will provide at least 30 days' advance notice. Your continued use of our Services after changes take effect constitutes acceptance of the updated Policy.

16Contact Information and Complaints

16.1 Contact Us

General Privacy Inquiries: privacy@product7.io

Data Protection Officer: dpo@product7.io

Support: support@product7.io

16.2 Supervisory Authorities

If you are not satisfied with our response, you have the right to lodge a complaint with a supervisory authority:

  • Nigeria: Nigeria Data Protection Commission (NDPC) - ndpc.gov.ng
  • EU: Your local Data Protection Authority
  • California: California Attorney General - oag.ca.gov

17Additional Disclosures

17.1 California Residents

Under the CCPA/CPRA, California residents have specific rights regarding their personal information. We do not sell personal information. For the categories of personal information we collect and our business purposes, please see Sections 4 and 6 above.

17.2 European Economic Area Residents

If you are located in the EEA, your personal data is protected under GDPR. Product7 Technologies Limited acts as the data controller. For international transfers, we rely on Standard Contractual Clauses.

17.3 Nigerian Residents

Your personal data is protected under the Nigeria Data Protection Act 2023 and NDPR 2019. You have the right to lodge complaints with the Nigeria Data Protection Commission.

Questions? If you have any questions about this Privacy Policy or our data practices, please don't hesitate to contact us at privacy@product7.io. We're committed to transparency and protecting your privacy.