INTRODUCTION
As a responsible firm, Leap Wise LP is fully committed to the adequate protection of your privacy rights and personal data in compliance with the applicable data protection laws.
This privacy policy clearly states the categories of data we collect, process, and store, any personal information we collect from you and your rights in relation to the information when you visit our website, engage our legal or advisory services or interact with us, and further shows Leap Wise’s dedication to ensuring that any personal data we collect in respect of any of our services is handled in compliance with applicable data protection laws.
DEFINITIONS AND INTERPRETATION
- Applicable Data Protection Laws: This refers to several laws, regulations and directives on the protection of privacy and personal data, such as the Nigeria Data Protection Act, 2023, Nigeria Data Protection Act – General Application and Implementation Directive, 2025 and the General Data Protection Regulations (GDPR).
- Automated decision making: This means the usage of personal data by computer program or algorithm to make choice or judgement about an individual without any human involvement.
- Consent: means any freely given, specific, informed, and unambiguous indication, which can be by a written or oral statement or an affirmative action, of an individual’s agreement to the processing of personal data relating to him or to another individual on whose behalf he has the permission to provide such consent.
- Controller or Data Controller: means an individual, private entity, public Commission, agency or any other body who, alone or jointly with others, gives instructions on the purposes and means of processing of personal data.
- Cookies: means small text or data files stored on a user’s device by a web browser when visiting a website. The purpose of this is to help us enhance your experience while using our website by recognizing your browser, collecting analytics, and remembering your preferences (like language or login information).
- Data Subject: means a living natural person who can be identified, directly or indirectly, from personal data held or processed by an organization.
- Personal Data: means any information relating to an individual, who can be identified or is identifiable, directly or indirectly, by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, psychological, cultural, social, or economic identity of that individual.
- Processing or Process: means any operation or set of operations which is performed on personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment, combination, restriction, erasure or destruction and does not include the mere transit of data originating outside Nigeria.
- Processor or Data Processor: means an individual, private entity, public authority, or any other body, who processes personal data on behalf of or at the direction of a data controller or another data processor.
- Profiling: means any automated processing of data to evaluate, analyze, or predict personal aspects such as behavior, economic situation, location or health of a natural person.
- Sensitive Personal Data: refers to specific categories of personal information that pose higher risk to individuals and require stricter protection measures and special conditions for processing.
- Services: refers to the legal and related professional services provided by the Firm.
- Third Party: means any individual, company, regulatory body, service provider, professional adviser, or other entity, other than the Data Subject, the Firm, or persons acting under the direct authority of the Firm, that may receive, access, process, or otherwise have involvement with Personal Data in connection with the provision of the Firm’s legal, advisory, or related services.
- Website: refers to the Firm’s website, which can be accessed via this URL: https://leapwiselp.com.
SCOPE AND APPLICATION
This Privacy Policy applies to Personal Data collected by Leap Wise LP through our website, digital platforms, events, communications, and other interaction channels with us or our representatives in respect of our legal, regulatory, corporate, and startup advisory services.
In this policy, references to “we”, “us”, or “Firm” are references to Leap Wise LP, while references to “you” refers to any natural person who are our Data Subjects which can be any of the following (Partners, Prospective Employees, Employees, Prospective Clients, Clients, Vendors, or Visitors) who visit our website or any of our physical offices or interact with any of our controlled information collection links or forms.
This Privacy Policy applies to Personal Data relating to, or provided by:
- Client: any person or organisation who has engaged the Firm for the purpose of obtaining any of our services.
- Prospective Client: any person or organisation who is actively planning to engage the Firm for the purpose of obtaining legal advice, advisory services, or other services within the confine of our services.
- Employee: any person who is duly employed by the Firm to carry out any of its operation in the delivery of legal and advisory services to its clients including interns, volunteers, business support, part-time, and any other temporary or contract staff.
- Prospective Employee: any person who at the moment is undergoing the Firm’s recruitment process such as job applicants, test takers, and interviewees.
- Vendor: any person, professional, service providers, consultants, or organisation who has been engaged by the Firm to provide goods or services to support its operations and meet its business needs. This includes any prospective vendors.
- Visitor: any person who visits the Firm’s office location physically, participants in any events, webinars, workshops, consultations, and other programmes hosted by the Firm, or users of our website and other digital platforms.
- Partner: any person admitted into the Firm’s partnership.
- Any other person or organisation whose Personal Data is lawfully provided to or processed by the Firm in respect of our services or activities.
This Privacy Policy will be applicable irrespective of the medium through which personal data is collected, either through our website, email, telephone, physical correspondence, online forms, consultations, client onboarding processes, events, social media platforms, or other lawful means.
Where the Firm processes Personal Data on behalf of a client or another organisation with whom we owe strict professional and statutory obligation of confidentiality, in the capacity of a Data Processor, the collection, usage, sharing and processing of such data will be subjected to the terms of the relevant letter of engagement, applicable laws or other contractual arrangement between the parties.
This Privacy Policy is applicable to all Leap Wise LP Services accessed by you. By accessing our Website, using our Services or contacting us directly, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.
THE DATA CONTROLLER
Leap Wise is a law and technology policy advisory law firm working at the key intersection of technology, business, and law, with a focus on legal, regulatory, corporate, and strategic advisory services to individuals, businesses, startups, founders, and other organisations. The Firm is registered as a partnership under the laws of the Federal Republic of Nigeria with its principal place of business situated at Suite 1, Favour Plaza, Ovwian 330103, Delta, Nigeria.
The data controller responsible for your Personal Data processed via the website or in relation to our services is Leap Wise LP. In other words, we are primarily responsible for the data we collect and are the legal person, which, solely or jointly with others, determines the purposes and means of the processing of the personal data.
We have a Data Protection Officer (DPO) whose primary responsibility is to oversee and provide answers to questions in relation to this Privacy Policy. If you have any questions about this Privacy Policy, including any requests to exercise your legal rights, please contact the DPO using the information set out below:
- Email address: contact@leapwiselp.com
- Postal address: Suite 1, Favour Plaza, Ovwian 330103, Delta, Nigeria.
PERSONAL DATA WE COLLECT
Based on the scope of the relationship you have with us, the service we provide, and how you interact with our website and legal services, we may collect, use, store, transfer, and process different types of personal data about you, which we have categorised as follows:
Identity Data
This may include information that helps us to verify your identity in order to offer our Services to you, such as:
- Full name, title, and job title or role.
- Identification documents or numbers (e.g., passport, driving licence, company registration details), photograph.
- Employer or organisation details, where relevant.
- Any other type or form of information which is used to uniquely identify an identified/identifiable person.
Contact Data
This is the category of data that we use to contact you, such as:
- Residential or business address.
- Email address, postal address.
- Telephone numbers.
- Any other type or form of information which provides a means by which to contact an identified/identifiable person.
Financial and Transaction Data
This is the category of data for payments processing and accounting records maintenance. They include:
- Bank account details, payment records, and invoices.
- Billing contact details.
- Tax identification details, partnership equity contributions, income and salary details.
- Loan and debt information, insurance policies.
- Any other type or form of information relating to any financial transactions between an identified/identifiable person or an organisation and the Firm.
Legal and Advisory Information
This includes legal documents pertaining to your startup or company, such as:
- Contracts, agreements, applications, pleadings, corporate records.
- Regulatory filings, due diligence materials, intellectual property agreements.
- Any other information provided to us in connection with a legal or advisory matter.
Technical and Usage Data
These are data that our server automatically collects about how you access our services anytime you access our services or digital platforms. This may include:
- Information about your access to and use of our website, such as IP address, browser type and version, operating system, time zone setting, unique device identifier, log-in information, location and other device details.
- Details of how you interact with our website (e.g., pages viewed, links clicked, and other analytical data).
- Data collected through cookies and similar technologies.
- Any other information generated through your interaction with our digital platforms.
Communication and Correspondence Data
This category of data is contained in the communications between you and the Firm, such as:
- Emails, letters, messages, and enquiries.
- Telephone conversations, consultation records, meeting notes.
- Any other correspondence.
Recruitment Data
This category of data is collected when you apply for employment, internship or any other opportunities within the Firm, such as:
- Curriculum vitae (CV), education and employment history, qualifications, references, and interview notes.
- Professional memberships and regulatory information (e.g., practising certificate details).
- Any other types or forms of Personal Data processed for the purpose of completing the recruitment process.
Sensitive Personal Data
Where necessary and permitted by applicable law, we may process:
- Information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, bio-metric data, genetic data, trade union membership, health data, or information concerning a person’s sex life or sexual orientation.
- Information relating to criminal convictions, offences, or related proceedings.
We only process such data where it is necessary for the establishment, exercise, or defence of legal claims, or otherwise in accordance with applicable data protection laws, and we apply appropriate safeguards to such information in accordance with applicable data protection laws.
HOW WE COLLECT PERSONAL DATA
Information You Provide Directly
We may collect Personal Data that you voluntarily provide to us when you:
- Engage any of our services.
- Contact our customer support team to request or make enquiries about any of our services.
- Communicate with us via telephone, email and other channels.
- Register for or attend any of our events, workshops, webinars, consultations or other programmes.
- Provide documents or information for the purposes of legal advice, due diligence, regulatory compliance, transactions or other professional engagements.
- Apply for employment, internships or other opportunities with the Firm.
Information Collected Automatically
We may automatically collect certain technical and usage information through cookies, log files, analytics tools, and similar technologies when you use or access our website and other digital platforms.
Information from Publicly Available Sources
Where necessary for legitimate and lawful purposes such as for legal research, regulatory compliance, due diligence, conflict checks, or the provision of advisory services, we may collect Personal Data from publicly available sources, including government or regulatory databases, corporate registries, court records, professional directories, publicly accessible websites, and other lawful sources.
PURPOSES AND LEGAL BASIS FOR PROCESSING
We process Personal Data only where we have a lawful basis to do so under applicable data protection laws and also for specific business purposes based on the nature of our relationship with you and the services we provide, in a manner that is consistent with applicable data protection laws. The lawful basis upon which we can process your data as provided for under applicable data protection laws includes:
- Consent: where you have freely, knowingly and specifically given us and not withdrawn the consent for the specific purpose or purposes for which your personal data is to be processed.
- Contractual Obligation: where the processing of your personal data is necessary for the performance of a contract to which you are a party or in order to take steps at your request prior to entering into a contract.
- Legal Obligation: where the processing of your personal data is necessary for us to perform an obligation under applicable law or relevant regulatory body to which we are subject.
- Legitimate Interest: where the processing of your personal data is necessary for the purposes of our legitimate interests such as improving our Services or ensuring our IT security, or those of a third party, provided that such interests are not overridden by your interests, fundamental rights and freedoms which require protection of personal data, where our interests are incompatible with other lawful basis of processing or where you would not have a reasonable expectation that your personal data would be processed in the manner envisaged.
- Vital Interest: where the processing of your personal data is necessary to protect your vital interests or those of another person.
- Public Interest: where the processing of your personal data is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us.
The reasons set out above represent the general position as to the purposes for which data may be used as provided for under applicable data protection laws. However, the specific position in relation to your personal data is that we may use it for the following business purposes:
- To provide legal, regulatory, corporate, commercial, and startup advisory services. These could include legal consultations, drafting and reviewing documents, negotiations, due diligence, regulatory advice, and representation where applicable;
- To provide news and information services or updates, respond to enquiries, communicate about ongoing matters, schedule consultations, and otherwise communicate with you in relation to our services;
- To conduct conflict checks, verify identities and undertake necessary due diligence when on-boarding a new Client;
- To send newsletters, legal updates, publications, invitations, information about our services, and other communications that may be relevant to you where permitted by applicable law;
- To enter into, perform, manage, and enforce any contractual arrangements;
- To assess applications for recruitment processes, communicate with applicants, and manage prospective and existing employment relationships;
- To analyze how you use our website, using data analytics to improve our website operation, Services, user experiences and to optimise service delivery;
- To exercise, protect and defend our legal rights, interests, or claims in respect of any disputes, investigations, proceedings, or other legal matters.
NOTE: Where the legal basis for processing your personal data is your consent, you have the right to withdraw that consent at any time. You can withdraw your consent by contacting us at leapwiselp@gmail.com. However, withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal.
DISCLOSURE AND SHARING OF PERSONAL DATA
We may engage trusted third-party service providers to support the delivery of our Services, therefore where necessary we may share your personal data with them. We will not share your personal data with any third party except as stated in this policy, or where required to do so by law, or with your prior consent. Below are the categories of third party that we may share your Personal Data with:
- Courts and Tribunals: where we engage courts, tribunals or other dispute resolution channels in performing our dispute resolution services, we may be required to share your personal data with them.
- Compliance Organisations: in performing our compliance obligation we may be required to share your personal data with regulators, law enforcement agencies, auditors, and government agencies that we are subject to.
- Suppliers and Service Providers: in rendering any of our services to you, we may engage service providers to whom we outsource certain support services such as document production, secretarial and translation services, photocopying, and other document management services.
- Professional Advisers and Consultants: we may engage external lawyers, local counsel, and technology service providers such as data room providers and/or expert witnesses who may support us in the course of the services we provide to clients.
HOW WE PROTECT YOUR DATA
Leap Wise is committed to safeguarding your Personal Data and maintaining its confidentiality and integrity. We therefore take reasonable steps and put several physical, electronic, and managerial security procedures in place to maintain the safety of your Personal Data. Also, we follow industry best practices to protect your information from unauthorized access, disclosure, modification, and accidental loss. Our security measures include:
- Access Control: we limit access to your Personal Data to authorized personnel only, such as employees, agents, contractors and other third parties on a need-to-know basis who are subject to strict confidentiality obligations.
- User Authentication: we make use of strong user authentication methods to ensure that only authorized users have access to your account and Personal Data.
- Encryption: in the process of transmitting Personal Data between your device and our database we make use of encryption techniques to protect the data being transmitted. This ensures that your Personal Data remains confidential during transit.
- Incident Response Plan: we have put in place procedures to deal with any suspected Personal Data breach or security incidents and will notify you, NDPC and other appropriate authorities of the occurrence of a Personal Data breach where we are legally required to do so.
CROSS-BORDER TRANSFER OF PERSONAL DATA
In the course of rendering our services to you, we may transfer, store, or process your Personal Data outside Nigeria, including where we engage service providers, professionals, or technology providers located in other jurisdictions. We may transfer, store or process your data outside of Nigeria for the following reasons:
- Providing or offering any of our services;
- Engaging third party outside Nigeria;
- Where we make use of cloud-based storage, document management, email, communication, cybersecurity, or other technology services whose infrastructure or service providers are located outside Nigeria.
When we transfer Personal Data out of Nigeria, we only do so in the following circumstances:
- Where you have granted and not withdrawn consent to such transfer after having been informed of the possible risks of such transfers for the Data Subject due to the absence of adequate protections;
- Where transfer is necessary for the performance of a contract to which you are a party or in order to take steps at your request, prior to entering into a contract;
- Where transfer is for your sole benefit and (i) it is not reasonably practicable to obtain your consent to that transfer, and (ii) if it were reasonably practicable to obtain such consent, you would likely give it;
- Where transfer is necessary for important reasons of public interest;
- Where transfer is necessary for the establishment, exercise, or defence of legal claims; or transfer is necessary to protect your vital interests or of other persons, where you are physically or legally incapable of giving consent.
Whenever we have to transfer or transmit your Personal Data internationally, we will take reasonable steps to ensure your Personal Data is handled securely in compliance with the Applicable Data Protection Law. We will ensure that your Personal Data is sent only to countries that have been deemed to provide an adequate level of protection for Personal Data by NDPC, and where the country may not have an adequate level of data protection, we will ensure that appropriate safeguards are in place to protect your Personal Data.
We may also use such data transfer mechanisms which are available to us under the Applicable Data Protection Laws, and which are adequate to ensure appropriate safeguards for your Personal Data, or other data transfer mechanisms stipulated by the law.
DATA RETENTION
We and any other third party that we share your information with to carry out Services on our behalf will only retain your Personal Data as long as we keep offering our services to you and for no longer than is necessary to achieve the purposes as stated in this privacy policy for which it was collected, and in accordance with Applicable Data Protection Laws.
We may also retain some Personal Data after your relationship with us has ended, but such retention period will be determined by the following criteria:
- if we have a legal obligation to retain Personal Data for a defined period, e.g. some laws and regulations mandate that some Personal Data must be retained for a specific period (e.g., tax requirements);
- if we have to evidence compliance with our legal and regulatory obligations; and/or
- if we have to withhold destruction because of ongoing litigation, a court order or an investigation by law enforcement agencies or our regulators.
When we no longer have a legal basis to keep your information, we either remove it from our systems or depersonalise it so that we can’t identify you.
YOUR RIGHTS AS A DATA SUBJECT
Under Applicable Data Protection Law, you have a number of rights as a data subject in relation to the processing, storage and usage of your personal data, and Leap Wise has put procedures in place to ensure that we can facilitate any request made by an individual in the exercise of their rights under applicable data protection law. These rights include:
- Right to be informed: you have the legal right to be informed about how we collect, process and use your personal data.
- Right to erasure: you have the right to ask us to delete or remove Personal Data based on any of the following conditions:
- where there is no good reason for us continuing to process it;
- where you have successfully exercised your right to object to processing;
- where we may have processed your information unlawfully or where we are required to erase your Personal Data to comply with applicable laws.
NOTE: we may however not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
- Right of access: you have the right to access your personal data and supplementary information in order to be fully aware of and verify the lawfulness of the processing.
- Right to rectification: where your data is misleading, inaccurate or incomplete, you have the right to have it corrected or completed.
- Right to restrict processing: you have the right to request the restriction or suppression of the processing of your personal data where:
- you want us to establish the accuracy of your Personal Data;
- the extent of our use of your Personal Data is unlawful but you do not want us to erase it;
- you need us to hold the Personal Data even if we no longer require it as you need it to establish, exercise or defend legal claims;
- you have objected to our use of your Personal Data, but we need to verify whether we have an overriding legitimate basis to use it.
- Right to object to processing: you have the right to object to the processing of your personal data in certain circumstances, which include:
- you do not want us to process your Personal Data;
- your data is processed for direct marketing purposes — you shall have the right to object, at any time, to such processing, to the extent that it is related to such direct marketing.
- Right to request the transfer: you have the right to request the transfer of your Personal Data to you or to a third party of your choice.
- Right to withdraw consent: where we are relying on consent to process your personal data, you have the right to withdraw consent to the processing of such data at any time. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent, and we may not be able to provide certain products or Services to you where you have withdrawn your consent.
- Right to data portability: you have the right to collect and reuse your personal data for your own purposes across different services. It allows you to move, copy, or transfer personal data easily from one data controller to another in a safe and secure way, without affecting its usability.
- Rights in relation to automated decision making: you have the right not to be subject to a decision that is solely based on automated processing of personal data by computer program without any human involvement, including profiling, which produces legal or similar significant effects concerning you.
- Right to lodge complaint with relevant regulatory bodies: where you believe that we have handled, stored, processed or used your Personal Data in a manner that is not lawful, fair, or transparent, or that your data protection rights have otherwise been infringed, you have the right to lodge a complaint at any time with relevant data protection regulatory bodies.
AUTOMATED DECISION MAKING
We do not use your personal data to make decisions that are based solely on automated processing (including profiling) which produce legal effects concerning you or similarly significantly affect you, unless under the following circumstances:
- The decision is necessary as part of a contract that we have with you;
- We have your explicit consent;
- We are required by law to use the technology.
CHILDREN’S DATA
Our services and website are not generally directed at children, therefore we do not knowingly collect or process children’s Personal Data for purposes unrelated to the provision of our services or the lawful conduct of our business.
In a situation where Personal Data relating to a child is necessary for the purpose of offering any of our services, we collect such information through their guardian or where the law permits, and due to the high risk associated with the processing of children’s Personal Data we put appropriate safeguard measures in place.
Where you have any belief that a child has provided Personal Data to us without the appropriate authorisation or where such processing is not otherwise permitted by law, please contact us using the details provided in the “Contact Us” section of this Privacy Policy so that we can investigate and discontinue such data processing activities.
COOKIES AND SIMILAR TECHNOLOGIES
We use Cookies to identify the areas of our Website that you have visited and to enhance the performance and functionality of our Website, but they are non-essential to the use of our Website.
Some browsers may automatically accept Cookies, while others can be adjusted to reject Cookies or notify you when a website intends to place a Cookie on your computer. Hence, depending on your Cookie management settings and preferences, we may store Cookies on your device when you visit our website. But when you disable Cookies, you may not be able to access some functionality on our Website correctly or at all.
Where we use Cookies, we do not collect Personal Data or use information gathered for tracking purposes except with your permission.
For more information about the Cookies we employ and instructions on modifying your Cookie preferences, please refer to our Cookies Policy.
CHANGES TO THIS PRIVACY POLICY
We continually assess our data protection practices to ensure your data rights are guaranteed, therefore our data protection practices are subject to changes, and based on these changes or changes in applicable data protection law and our services, we reserve the right to update or modify this Privacy Policy to reflect such changes. In the event of an amendment to this Privacy Policy, the ‘Last Updated’ date of this Privacy Policy shall be indicative of any update. We will notify you of any material changes by posting the updated Policy on our platform or by other means of communication, where appropriate. Any modifications shall be effective immediately upon posting the updated Privacy Policy on the Website; therefore, we encourage you to occasionally check this policy to ensure you are aware of the most recent version that will apply each time you access this website.
CONTACT US AND GRIEVANCE REDRESS
If you wish to exercise any of the rights set out above or have any complaints about our use, storage or processing of your personal data, please contact us via:
- Address: Suite 1, Favour Plaza, Ovwian 330103, Delta, Nigeria.
- Email address: contact@leapwiselp.com
- Phone Number: +234 803 864 1566