Privacy Policy
Last updated: August 2026
Overview
FirmLyt (“we”, “us”) provides practice management software for Nigerian law firms and chambers. We process personal data to deliver the service, comply with law, and improve the product.
This policy explains what we collect, why we use it, how we protect it, and the choices you have under Nigerian data protection law.
This policy also covers analytics and error monitoring on our cloud-hosted web application (the logged-in product at app.firmlyt.com).
What we collect
Depending on how you use FirmLyt, we may process:
• Account information - name, email, phone, role at your firm, and login credentials
• Firm profile - chambers name, address, and billing contact details
• Practice data you enter - client and contact names, matter details, court dates, documents, notes, and correspondence metadata
• Technical data - IP address, device and browser type, timestamps, and logs needed to secure and operate the service
How we use your information
We use personal data only for clear purposes tied to running FirmLyt:
• Providing and maintaining your account and firm workspace
• Processing matters, clients, schedules, and documents you store in the product
• Sending service-related messages (security alerts, support replies, product updates that affect your account)
• Complying with legal obligations and responding to lawful requests
• Improving reliability, security, and usability of the platform
Retention and deletion
We keep account and practice data while your subscription is active and for a limited period afterward so you can export records or reactivate if needed.
You may request deletion of your account and associated data. We will remove it from active systems unless we must retain certain records for legal, regulatory, or legitimate business purposes (for example unresolved billing or disputes).
Product analytics (PostHog)
When you use our cloud application, we may ask for your consent to use PostHog for product analytics.
What we collect (only if you accept)
• Anonymized usage events (for example: signup steps completed, feature pages viewed, matter or client created, chamber schedule updated, subscription plan changes)
• A random analytics identifier stored in your browser (cookie/local storage)
• Your firm account ID (after sign-in) to group events for B2B activation metrics, not for individual marketing profiles
What we DO NOT send to PostHog
• Your name, email address, or phone number
• Referral or sales codes
• Client, contact, or matter names and case details
• Payment amounts or other financial details
• Raw error message text from the application
Your choice: A consent banner lets you Accept or Decline analytics. If you decline, the app works normally and no PostHog analytics cookies are set. Essential cookies for login and security are separate and required for the service.
Provider & location: PostHog is a third-party analytics provider. We configure the EU ingest host where applicable. See PostHog's privacy documentation for their processing practices.
Error monitoring (Sentry)
We use Sentry on our cloud application to detect and fix technical errors.
What Sentry receives
• Error stack traces and technical context needed to diagnose bugs
• Performance trace samples (higher sample rate in non-production environments)
What Sentry does not receive from us
• Your email or name attached to error reports
Sentry runs for operational reliability and is not gated by the analytics consent banner in the same way as PostHog, because it is used only for error and performance monitoring, not product analytics.
Cookies summary (cloud app)
| Type | Purpose | Consent required |
|---|---|---|
| Authentication | Login sessions, security | No (essential) |
| PostHog analytics | Product usage insights | Yes (Accept on banner) |
| UI preferences | e.g. sidebar state | No (functional) |
Your rights under NDPR
Under the Nigeria Data Protection Regulation (NDPR) and applicable law, you may have the right to:
• Know whether we process your personal data and receive a copy
• Correct inaccurate or incomplete data
• Request deletion where the law allows
• Restrict or object to certain processing
• Withdraw consent where processing is based on consent
• Lodge a complaint with the Nigeria Data Protection Commission (NDPC)
Contact us to exercise these rights. We will respond within the timeframes required by law and may need to verify your identity or your firm’s authority before acting on a request.
Contact
For privacy questions or to exercise your rights, email [email protected].
If you are a client of a law firm using FirmLyt, your firm is usually the data controller for matter and client records. Contact your chambers first; we can assist your firm with technical requests about data held in the product.