ARM Ecosystem
Privacy Notice
Last updated: 4 September 2026
Who is responsible for your data?
LEGAL ENTITY NAME — TO BE SUPPLIED BY ARM is the data controller for the personal data it decides how and why to process. ARM will publish its registered legal name, address, and privacy contact here before production launch.
Privacy contact: PRIVACY CONTACT EMAIL — TO BE SUPPLIED BY ARM.
What we collect
Depending on how you use ARM, we may hold your account email, name and profile details, Bible-reading reflections, membership and community activity, project participation, donation and in-kind donation records, security and audit records, and information you provide when you contact us or use a service.
We do not need your password or payment-card number to provide ARM. Authentication is handled by Supabase, and Paystack processes payment details for payments.
Why we use it
ARM uses personal data to provide accounts and member features, keep private journals private, operate community features, administer projects and donations, prevent abuse, maintain security and audit trails, communicate service information, and meet legal or accounting obligations where applicable.
LAWFUL BASIS BY PROCESSING ACTIVITY — TO BE CONFIRMED BY ARM / COUNSEL.ARM will publish the final lawful basis for each major processing activity here rather than guessing or treating consent as the answer for everything.
Who we share it with
We use service providers only where needed to operate ARM. Current infrastructure providers include Supabase for authentication, database, storage and related services; Paystack for payment processing; and Resend for transactional email. Additional processors may be added as ARM grows and will be reflected in this notice where required.
CROSS-BORDER PROCESSING DETAILS — TO BE CONFIRMED BY ARM. ARM will document applicable transfer safeguards and processor agreements before production use.
How long we keep it
ARM follows its documented Records Retention Schedule. In general, private account content is removed when an applicable erasure request is completed, while financial, governance, audit, dispute, and other records may need to remain for legal, accounting, security, or public-accountability reasons.
The current engineering baseline includes seven years for financial/accounting evidence and certain project, partner, and dispute records, permanent governance records, twelve months for security logs, and 90 days for routine telemetry, subject to legal holds and the final advice applicable to ARM's legal entity.
FINAL LEGAL/ACCOUNTING RETENTION CONFIRMATION — TO BE SUPPLIED BY ARM.
Your rights
Subject to applicable law and any lawful retention requirement, you can ask ARM for information about your personal data, access a copy, request correction, object to or restrict certain processing, request portability, and request erasure. You may also have rights relating to automated decision-making and the right to complain to the Nigeria Data Protection Commission.
Export or erase your ARM data
Signed-in members can use the self-service data controls to download the data ARM holds about their account or request erasure. Before erasure, ARM explains what will disappear and what must remain. In particular, immutable financial and in-kind facts are preserved for accountability, but the profile that identifies the person is converted to a non-identifying erased record.
Security
ARM uses access controls, Row-Level Security, secure authentication, HTTPS, append-only financial and audit records, and other safeguards appropriate to the information we process. No online system can promise perfect security, so suspected privacy or security incidents should be reported promptly through the privacy contact above.