Privacy Policy

Effective Date: June 2026

FirstFive Magazine is a Christian publication focused on grooming the first five years of love, marriage, and parenting. This Data Privacy Policy, issued in compliance with the Nigeria Data Protection Act, 2023 (NDPA), the General Application and Implementation Directive (GAID) 2025, and the EU General Data Protection Regulation (GDPR), explains how we collect, use, store, share, and protect your personal data.

SECTION 1: SCOPE & APPLICABILITY
This Data Privacy Policy ("Policy", “Agreement”) applies to all users ("User", "you", or "your") who register, access, or interact with the FirstFive Magazine platform, whether through the website or any associated applications (“the platform”, “Our platform”, “FirstFive”, “FirstFive Magazine”, “Our System). This Policy does not apply to third-party platforms, websites, or services that may be linked to or from the platform. We encourage you to review the privacy policies of any external platforms you visit.

SECTION 2: DATA COLLECTION
Our system collects a range of personal and professional data. The data we collect includes, but is not limited to the below-stated:

Account Information:

  • Name
  • Email address
  • Username
  • Password credentials

Directory Information

  • Business name
  • Contact information
  • Professional credentials
  • Website and social media links

Transaction Information

  • Purchase history
  • Payment details processed by third-party payment providers

Technical Information

  • IP address
  • Browser information
  • Device information
  • Operating system
  • Usage data

SECTION 2.1: How We Collect Your Data
We collect personal data through the following means:

  • When you register on the platform, complete your profile, upload documents, or communicate with us;
  • Through cookies, analytics tools, and server logs when you use the platform;
  • Subject to the user granting access, we may import data from other professional platforms you choose to connect to the platform
  • Open academic databases, publications, and other publicly available sources

SECTION 2.2: Children’s Data
FirstFive Magazine is not directed at children under the age of 18. We do not knowingly collect personal data from minors without verifiable parental or guardian consent. Users between the ages of 13 and 17 who request our services may use the platform with the explicit prior consent of a parent or guardian. We apply appropriate age verification mechanisms and provide our privacy information in accessible language for younger users. If we become aware that personal data has been collected from a child without appropriate consent, we will promptly delete such data. If you believe a minor's data has been submitted without consent, please contact us at support@firstfive.cc.

SECTION 3: DATA USAGE
FirstFive Magazine will not use your personal data for any purpose incompatible with the purposes stated below without your prior consent
Core Platform Services

  • Analysing the profile of experts, editors and columnists to verify expertise. Information submitted for directory listings may be publicly displayed. By submitting a directory listing, you consent to publication of approved information.
  • Processing subscriptions and purchases
  • Delivering digital products
  • Managing directory listing

Platform Operations

  • Creating and managing your user account
  • Processing subscription payments
  • Providing customer support and responding to enquiries
  • Sending platform notifications and newsletters

Upgrades, Improvements and Cyber Security

  • Conducting internal analytics to improve matching accuracy
  • Monitoring for fraud, abuse, and security threats
  • Debugging and resolving technical issues

Legal and Regulatory Compliance

  • Meeting our obligations under regulatory frameworks guiding our operation of this platform
  • Responding to lawful orders from courts or regulatory authorities

SECTION 3.1: Google reCAPTCHA

This site is protected by Google reCAPTCHA, which may collect hardware and software information to determine whether or not a user is human. The use of reCAPTCHA is subject to Google's Privacy Policy and Terms of Service.


SECTION 3.2: Use of Cookies

  1. We use cookies and similar technologies to ensure the platform functions correctly and to understand how users interact with our services. By continuing to use our website, you consent to our use of cookies as described in this Policy.The categories of cookies we collect includes: Essential Cookies, required for the platform to function; Analytics Cookies, used to understand user behaviour and improve platform performance; Preference Cookies, used to remember your settings and preferences across sessions; Marketing Cookies, used to deliver relevant content or measure marketing effectiveness
  2. We obtain opt-in consent before placing any non-essential cookies. You may manage or withdraw your cookie preferences at any time through our Cookie Preference Centre. Withdrawing consent does not affect the lawfulness of prior cookie use.
  3. Disabling certain cookies may affect website functionality. We are not responsible for any technical difficulties you may face on the platform if you disable your cookies.
  4. Third parties such as Google reCAPTCHA, Stripe, Paystack and Analytics providers may place cookies on the platform. These providers maintain their own privacy practices. Google reCAPTCHA may place cookies and collect information to distinguish human users from automated activity. Users are encouraged to review the data policy on these third party platforms, as we are not responsible for any breach, damages, and such other liabilities arising from these third-party platforms.

SECTION 4: DATA TRANSFER
We maintain the right to share your data in the certain circumstances:

  1. Service Providers (Data Processors)
    All third-party processors engaged by us are bound by Data Processing Agreements (DPAs), and are prohibited from using your data for any purpose other than providing services to us. These processors may include: Cloud hosting and infrastructure providers (e.g. AWS, Google Cloud); AI and machine learning model providers; Payment processors (who have their own PCI-DSS compliant policies); Analytics and monitoring tools
    FirstFive Magazine may contain links to external websites, or offer integrations with third-party platforms. This Policy does not govern those external platforms. We encourage you to review the privacy policies of any third-party services you use.
    Where you choose to connect a third-party account, you authorise that platform to share data with us in accordance with your settings on that platform. You may disconnect any such integration at any time through your account settings.
  2. Legal Obligations
    We may disclose your data to law enforcement, regulatory authorities, or courts where required by Nigerian law, a valid court order, or to protect the rights and safety of the platform, its users, or the public.
  3. Business Transfers
    In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity. We will notify you of any such change and ensure the receiving party maintains the same or equivalent data protection standards.
  4. Cross-Border Data Transfers
    As a digital platform with international infrastructure, your data may be transferred to and stored in countries outside your home country. In such cases, we ensure that transfers are made to countries deemed to provide adequate data protection by international regulatory frameworks. Where adequacy is not established, we put in place appropriate safeguards such as Standard Contractual Clauses, Data processing agreements, or equivalent contractual protections.

We do not sell, rent, or trade your personal data for any other purposes aside from the aforementioned. You may request details of the safeguards applied to international transfers by contacting support@firstfive.cc.

SECTION 5: DATA SECURITY

  1. We implement technical and organisational measures to protect your personal data against unauthorised access, loss, disclosure, or destruction. These measures include Encryption of data in transit (TLS/HTTPS) and at rest (AES-256); Access controls and role-based permissions for internal staff; Regular security audits and vulnerability assessments; Secure development practices and code reviews;
    Incident response and breach notification procedures
  2. Where our data processing activities are likely to result in high risk to the rights and freedoms of data subjects, we carry out a Data Protection Impact Assessment (DPIA). DPIAs help us identify and mitigate privacy risks before they materialise. Where a residual high risk remains after mitigation, we consult regulatory bodies prior to processing. Records of DPIAs are maintained and made available upon request.
  3. In the event of a personal data breach that is likely to result in risk to your rights and freedoms, we will notify you directly without undue delay. Where the breach is likely to result in high risk to you, and remains unresolved within 72 hours of becoming aware of this breach, we will notify regulatory agencies, and may delete your account.

SECTION 6: DATA RETENTION
We retain your personal data only for as long as necessary to fulfil the purposes described in this Policy, or as required by law. Your account data is retained for the duration of your active account. Upon account deletion, we will securely delete or anonymise your personal data within 30 days, except where retention is legally required, such as ongoing legal proceedings, regulatory investigation, financial reporting obligations, or dispute.

SECTION 7: YOUR RIGHTS AS A DATA SUBJECT
Under regulatory frameworks, you have certain rights with respect to your personal data. You have the right to know what data we hold about you, how it is used, and with whom it is shared. You may request deletion of your personal data, subject to legal retention obligations, and you may request that we limit how we use your data in certain circumstances. To exercise these rights or more, we request that you submit a written request to support@firstfive.cc. We will respond within 30 days, and may request identity verification before processing your request.

SECTION 8: AMENDMENTS TO THIS POLICY
We may update this Policy from time to time to reflect changes in our practices, applicable law, or regulatory guidance. When we make material changes, we will update the 'Effective Date' at the top of this document, notify you via email or a prominent notice on the platform, and where required by law, seek your renewed consent. We encourage you to review this Policy periodically. Continued use of the platform after notification of changes constitutes acceptance of the revised Policy.

SECTION 9: GOVERNING LAW & JURISDICTION
This Privacy Policy is governed by and construed in accordance with the laws of the Federal Republic of Nigeria, including but not limited to the Nigeria Data Protection Act, 2023, the Cybercrimes (Prohibition, Prevention, etc.) Act, 2015 (as amended), and the Constitution of the Federal Republic of Nigeria, 1999 (as amended). Any disputes arising in connection with this Policy shall be subject to the jurisdiction of the competent courts of Nigeria. Users in other jurisdictions also retain rights under their applicable local laws, which we respect and comply with to the extent required.

SECTION 10: CONTACT US
If you have questions, concerns, or wish to exercise your data subject rights, please contact us via support@firstfive.cc. We also have a designated Data Protection Officer responsible for overseeing our data protection strategy and compliance. You may contact us at any time with questions, requests, or concerns relating to how we handle your personal data. We are committed to resolving all privacy-related matters promptly and transparently.

This Privacy Policy was last reviewed and approved in June 2026.