Privacy Notice

Version 2.3 - Last updated Aug 28, 2026

Product: TestServes
Legal operator: BIG H MULTIDYNAMIC VENTURE
Contact: Contact Us
WhatsApp: 08083019506
Website: https://testserves.com
TestServes is a digital product operated by BIG H MULTIDYNAMIC VENTURE, a Nigerian sole proprietorship registered with the Corporate Affairs Commission under BN 7829006. Its registered principal place of business is No. 1, Awori Street, off First Gate, LASU-Isheri Road, Ojo, Lagos State, Nigeria.

PART A - WEBSITE PRIVACY NOTICE

1. About this notice

This Privacy Notice explains how TestServes processes personal data when schools, school owners, administrators, staff, students, parents or guardians, website visitors, prospective customers and support users interact with the TestServes website, school portals, applications and related services.

TestServes is a digital product operated by BIG H MULTIDYNAMIC VENTURE, a Nigerian sole proprietorship registered with the Corporate Affairs Commission under BN 7829006. Its registered principal place of business is No. 1, Awori Street, off First Gate, LASU-Isheri Road, Ojo, Lagos State, Nigeria.

Privacy enquiries may be sent to testserves.ng@gmail.com. Formal correspondence may also be sent to No. 1, Awori Street, off First Gate, LASU-Isheri Road, Ojo, Lagos State, Nigeria. The current privacy contact is the TestServes Privacy Contact, reachable through that email and the official support channels.

This Notice should be read together with the TestServes Terms of Service, Cookie Notice and any school-specific privacy information provided by a subscribing school.

2. Our roles

The organisation that decides why and how personal data is processed is a data controller. An organisation that processes personal data on a controller's documented instructions is a data processor.

For student, staff, examination, attendance, lesson, exercise, result and other school records entered into a school portal, the subscribing school will ordinarily act as the data controller and TestServes will ordinarily act as its data processor. The school determines which users are created, what school records are uploaded, how academic activities are administered and when results are released.

TestServes acts as a separate data controller for information used to administer its own website, onboarding, school-owner accounts, subscriptions, billing records, security, fraud prevention, service analytics, communications and support operations. The precise roles may depend on the processing activity and applicable law.

3. People covered by this Notice

This Notice applies to:

school proprietors, owners and authorised representatives;

school administrators, heads of department, teachers, bursars and other staff;

students and candidates, including children under 18;

parents, guardians and emergency contacts whose details are supplied;

prospective customers, website visitors and support users;

contractors, agents and authorised personnel who interact with TestServes.

4. Personal data we may process

Depending on the features used, we may process the following categories.

4.1 Identity and profile data

Names, usernames, unique identifiers, profile photographs, age or date of birth where required, gender where configured by the school, school admission or staff numbers, class, department, role and account status.

4.2 Contact and school data

Email address, telephone number, school name, school address, school branding, contact-person details, parent or guardian details and authorised support contacts.

4.3 Academic and operational data

Subjects, classes, terms, sessions, attendance, lesson notes, exercises, question banks, examination schedules, responses, scores, theory markings, results, performance records, teacher comments, approval records and relevant audit history.

4.4 Account and authentication data

Password hashes, login history, session identifiers, password-reset information, account permissions, access events and security records. TestServes should not store users' passwords in readable form.

4.5 Payment and transaction data

Subscription plan, amount, payment status, transaction reference, payer name, billing contact, invoices and refund information. Complete payment-card details are ordinarily collected and processed by the selected payment provider and should not be stored by TestServes.

4.6 Support and communications data

Messages submitted through contact forms, support tickets, live support, email, WhatsApp or other authorised channels, including attachments and records needed to investigate a request.

4.7 Device and technical data

IP address, browser type, device type, operating system, timestamps, requested pages, school subdomain, error reports, cookie or local-storage identifiers, authentication events and information reasonably needed to operate and secure the service.

4.8 Sensitive personal data

Schools should not upload sensitive personal data unless it is necessary, lawful and supported by suitable safeguards. Depending on school configuration, student records could reveal health, disability, religious or other sensitive information. TestServes must not request such information merely because it may be useful.

5. Sources of personal data

We may receive personal data directly from the individual; from a subscribing school or its authorised personnel; from a parent or guardian; from a payment, communications or identity provider; automatically from the device used to access the service; or from records created through use of TestServes.

Where a school supplies information about a person, the school is responsible for ensuring that it has an appropriate lawful basis and has given any notice required by law. TestServes remains responsible for its own duties as a processor or controller and does not exclude those duties through this statement.

6. Purposes and lawful bases

TestServes will identify an appropriate lawful basis before processing personal data. The bases relied on may include consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a public-interest task where applicable, and legitimate interests that do not override the person's rights.

Account creation and administration. Identity, contact and account data are processed to take requested steps before a contract and perform the contract.

School portals, CBT, learning and results. Identity, academic, account and technical data are processed on the School's documented instructions, under the service contract and according to the lawful basis selected by the School for the activity it controls.

Authentication and permissions. Identity, account and technical data are processed to perform the contract and pursue the legitimate interest of secure service delivery.

Subscriptions and financial records. Contact, transaction and billing data are processed to perform the contract and comply with legal obligations.

Misuse, cheating, fraud and unauthorised access. Account, technical and activity data are processed for legitimate security interests and applicable legal obligations.

Support and privacy requests. Identity, contact and support data are processed under the contract, legitimate interests and legal obligations, depending on the request.

Fault diagnosis and reliability. Technical, error and limited usage data are processed for legitimate interests, subject to necessity, proportionality and safeguards.

Optional promotions. Contact and preference data are processed on consent where consent is required.

Legal claims. Relevant account, transaction, security and communication data may be processed to comply with law or establish, exercise or defend legal claims.

Providing a privacy notice is not itself a request for consent. Where consent is legally required, TestServes or the responsible school must request it separately, clearly and before the relevant processing. Consent may not be inferred from silence, inactivity or a preselected option.

7. Students and children

TestServes is designed for schools and may process personal data relating to children under 18. Child data must be handled with heightened care.

Schools are responsible for selecting an appropriate lawful basis for the educational and administrative activities they control, providing suitable notices to students and parents or guardians, limiting access to authorised personnel and maintaining accurate account information. Where the applicable processing requires consent, explicit consent must be obtained from and verified through a parent or legal guardian in accordance with applicable law.

TestServes will support schools in meeting lawful requests relating to child data, apply access restrictions appropriate to school roles, avoid behavioural advertising directed at children, and avoid using child data for unrelated purposes. Students may not independently purchase or legally bind a school to a TestServes subscription.

Parents or guardians should ordinarily direct requests about school-controlled records to the relevant school. They may also contact TestServes where the school cannot resolve a request or where the request concerns processing controlled directly by TestServes.

8. Examination marking, analytics and artificial intelligence

Objective questions may be scored automatically according to the answers and grading settings supplied by the school. Theory or essay responses are intended to be reviewed by authorised school personnel unless the relevant feature clearly states otherwise. Schools remain responsible for checking question settings, answer keys, grading rules and result-release decisions.

Where TestServes introduces a decision based solely on automated processing that produces legal or similarly significant effects, affected users will receive appropriate information and any consent or safeguards required by law, including a reasonable method to request human review or challenge an error.

TestServes uses the Google Gemini API to assist authorised users with activities such as drafting examination questions or educational content. Information entered into the AI feature and the generated response are transmitted to Google for processing. Schools and users must not submit student names, account details, examination responses, results or unnecessary sensitive information into the AI feature.

Google's handling of Gemini API content depends on the applicable service tier, project settings and current terms. Google states that paid Gemini API prompts and responses are not used to improve its products, but it may retain limited content for safety, abuse-monitoring or enabled logging, and its services may process information on servers outside Nigeria. TestServes will configure the service to minimise retention where reasonably available and will review material changes to Google's terms.

9. Recipients and service providers

Personal data may be disclosed only where necessary and lawful to:

the relevant subscribing school and its authorised users;

hosting, database, backup and infrastructure providers;

payment providers and financial institutions;

transactional email, messaging and support providers;

security, monitoring and error-diagnostic providers;

professional advisers, auditors and licensed compliance organisations;

regulators, courts or law-enforcement bodies where disclosure is lawfully required;

a successor in connection with a lawful business reorganisation, subject to suitable safeguards.

TestServes will maintain a current subprocessor register identifying the provider, service, data involved and processing location. Providers must be engaged under appropriate written terms and given only the access reasonably necessary for their service.

10. Google Gemini processing outside Nigeria

TestServes operates from Nigeria, but its use of the Google Gemini API may involve processing on Google systems outside Nigeria. TestServes will limit information sent to Gemini to content reasonably needed to provide the AI feature and will not intentionally send identifying student records. Where personal data must be transferred, TestServes will apply a lawful transfer basis and appropriate contractual or other safeguards required by the Nigeria Data Protection Act.

11. Retention and deletion

TestServes keeps personal data only for as long as reasonably necessary for the stated purpose, the school contract, security, dispute resolution and applicable legal obligations. The normal post-deactivation or post-deletion retention period is two months.

School portal and academic records: retained while the school portal is active. After a school is deactivated or deleted, the data is normally retained for two months so that the school can contact support to request access or recovery. It is then deleted or irreversibly de-identified, subject to a documented legal hold or other legal requirement.

Account and permission records: retained for the account life and normally deleted or de-identified within two months after valid closure, subject to necessary security and legal records.

Incomplete onboarding: deleted after two months of inactivity unless a documented lawful reason requires retention.

Support and live-support records: normally retained for two months after the matter is closed, followed by deletion or de-identification unless needed for an active dispute, fraud investigation or legal requirement.

Security and access logs: normally retained for two months, extended only where necessary for an active investigation, security incident or legal requirement.

Transactions, invoices and accounting: retained for the period required by Nigerian tax and accounting law, then securely deleted.

Marketing preferences: retained until withdrawal or obsolescence, with only the suppression record needed to honour an opt-out kept afterwards.

Backups: copies containing deactivated or deleted school data are allowed to expire through the backup lifecycle within the same two-month period, unless preservation is legally required.

Data subject requests do not always require immediate deletion. Information may be retained where necessary to comply with law, resolve disputes, preserve examination integrity, protect other persons' rights or establish and defend legal claims. Data that no longer needs to identify a person may be irreversibly de-identified.

12. Security

TestServes will use technical and organisational measures appropriate to the nature, volume and risk of the data processed. Measures may include HTTPS encryption in transit, password hashing, role-based permissions, tenant or school separation, least-privilege access, secure configuration, vulnerability remediation, backups, logging, incident response, staff confidentiality obligations and periodic reviews.

This Notice does not guarantee absolute security. Only controls verified as operating in production should be represented publicly. Users must protect their credentials, use authorised devices where possible and promptly report suspected compromise.

13. Data breaches

TestServes will document and assess suspected personal-data breaches. Where a breach is likely to create a risk to individuals' rights and freedoms and TestServes is the controller, TestServes will notify the NDPC within 72 hours after becoming aware, where required. Where a breach is likely to create high risk, affected persons will be notified without undue delay or immediately as required by applicable guidance. Where TestServes acts as a processor, it will notify the responsible school without undue delay and provide reasonable assistance.

Suspected privacy or security incidents should be reported to testserves.ng@gmail.com, the TestServes contact form or official WhatsApp support on 08083019506.

14. Individual rights

Subject to applicable limitations, a person may have the right to:

receive information about processing;

request access to personal data;

request correction of inaccurate or incomplete information;

request deletion where the legal conditions are met;

withdraw consent without affecting earlier lawful processing;

object to processing based on legitimate interests or direct marketing;

request restriction of processing in appropriate circumstances;

receive eligible information in a portable format;

challenge certain decisions based solely on automated processing;

lodge a complaint with the NDPC; and

seek other remedies available under Nigerian law.

Requests may be submitted to testserves.ng@gmail.com, the TestServes contact form or official WhatsApp support on 08083019506. TestServes may request proportionate information to verify identity and authority. Where TestServes processes the information only for a school, the request may be referred to that school and TestServes will provide reasonable assistance. Requests will not be refused merely because the requester did not use a particular form.

15. Complaints

Privacy concerns should first be sent to testserves.ng@gmail.com with enough information to investigate. This internal step does not prevent a person from complaining directly to the Nigeria Data Protection Commission or seeking a remedy through a competent court.

NDPC contact details should be checked immediately before publication. Current information is available at https://ndpc.gov.ng.

16. Cookies and website storage

TestServes uses cookies and similar storage as described in the Cookie Notice. Essential technologies may be required for authentication, security, session continuity, CSRF protection, preferences and school-portal routing. Non-essential analytics, advertising or profiling technologies will not be activated before any consent legally required has been obtained.

17. Changes to this Notice

TestServes may update this Notice when its services, providers or legal duties change. The updated version will display a new date. Material changes will be communicated through the website, account notice or other appropriate channel before or when they take effect. Where a change requires new consent, the relevant processing will not begin until valid consent is obtained.

WA