Privacy
Privacy Policy
This policy explains what personal information this site collects, why, who it is shared with, and the choices you have. It covers the public website, the appointment booking form, and the staff platform used by the coordination office team.
Last updated: 9 September 2026
1. Who we are
This site is operated by the owner of groatwarden.com (“we”, “us”), the data controller for the information described here. You can reach us through the Contact section of the home page.
2. What we collect
Visitors who book an appointment
The booking form asks for:
- your name, email address and phone number;
- the type of appointment, the date and time you choose, and its duration;
- the purpose of the meeting, in your own words.
We generate a booking reference and record the status of the appointment (pending, confirmed, rescheduled, completed, cancelled or missed) alongside these details.
Staff, administrators and auditors
The staff platform is invitation-only. When you register or are invited we collect your name, email address, phone number and department, and a password which is stored only as a salted hash. If you enable two-factor authentication we store the secret needed to verify your codes. Using the platform then creates work records in your name: tasks, notes, comments, messages, time entries, documents you upload, and finance, procurement and audit records you enter or approve. Security-relevant actions are written to an audit log with your account and a timestamp.
Technical information
Our hosting provider records standard request logs (IP address, browser type, pages requested, timestamps) to run and secure the service. When the site encounters an error we send an error report to our monitoring provider; these reports are configured not to include request bodies, headers or user identifiers.
3. How we use it
- To arrange, confirm, reschedule and follow up appointments, including sending you confirmation and reminder messages by email and, where enabled, WhatsApp.
- To run the staff platform: sign-in, permissions, task and appointment management, internal messaging, document handling, and finance and audit workflows.
- To keep the service secure: detecting abuse, rate-limiting sign-in attempts, keeping an audit trail of sensitive actions.
- To meet legal, accounting and audit obligations that apply to the coordination office.
We do not sell personal information, and we do not use it for advertising or profiling.
4. Google Calendar integration
An administrator may connect a Google account so that tasks created on the staff platform appear on that Google Calendar with their own reminders. This is optional and applies only to the account the administrator chooses to connect.
When a Google account is connected, the site requests these Google permissions:
- View and edit events on all your calendars (
calendar.events): used solely to create, update and remove calendar events that correspond to tasks on the platform. We do not read, store or display any other events on the calendar. - Your email address and basic sign-in (
email,openid): used only to show which Google account is connected on the integrations settings page.
The refresh token Google issues is stored server-side in the platform’s database and is never sent to a browser. The administrator can disconnect at any time from the integrations settings page, which revokes the token with Google and deletes it from our records. Access can also be removed from the Google account permissions page.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used for advertising, is not sold, is not transferred to third parties except as needed to provide the integration or to comply with law, and is not read by people except with the connected user’s consent, for security purposes, or where required by law.
5. AI writing assistance
Staff may use optional AI features to help draft emails, notes and task descriptions. The text a staff member submits to those features is sent to Anthropic, our AI provider, to generate a response, under its commercial API terms. Do not submit information into AI features that must not leave the platform.
7. How long we keep it
- Appointment bookings are kept as a record of the office’s engagements.
- Staff account details are kept while the account is active and for a reasonable period afterwards so that records they created remain attributable.
- Finance, procurement and audit records, and the audit log, are kept for as long as accounting and audit rules require.
- Error reports and request logs are kept by the respective providers for their standard, limited retention periods.
8. Security
All traffic is encrypted in transit. Passwords are stored only as salted hashes. Two-factor authentication is available to every account and required for administrators. Access to records is role-based, sign-in attempts are rate-limited, and sensitive actions are logged. No system is perfectly secure; if you believe your account has been compromised, contact us immediately.
9. Your rights
Under the Nigeria Data Protection Act 2023 you may ask us to confirm what personal information we hold about you, to correct it, to delete it, to restrict or object to its processing, or to provide it in a portable format. You may also withdraw consent where processing is based on consent, and you have the right to lodge a complaint with the Nigeria Data Protection Commission. Visitors from the European Economic Area and the United Kingdom have equivalent rights under the GDPR.
To exercise any of these rights, contact us through the home page. We may need to verify your identity before acting, and some records (for example finance and audit records) may have to be retained despite a deletion request; we will tell you if that applies.
10. Children
The site is not directed at anyone under 18 and we do not knowingly collect information from children. If you believe a child has provided us with personal information, contact us and we will remove it.
11. Changes to this policy
We will update this page when our practices change and revise the date at the top. Where a change is significant we will also notify staff through the platform.
12. Contact
Questions about this policy or your information: use the Contact section of the home page. See also our Terms of Service and Cookie Policy.