Privacy & Cookies Policy
Last Updated: 12 August 2026
1. Introduction
MAGE LEGAL PUBLICATIONS AND BUSINESS ADVISORY LIMITED ("MAGE," "the Company," "we," "us," or "our") is a digital publishing and business advisory company engaged in the publication and dissemination of legal, regulatory, commercial, and professional information through online platforms and electronic media, and in the provision of business development support, market insight, and general business development advisory services to organisations across various sectors.
We recognise the importance of the personal information you entrust to us and are committed to protecting it in accordance with the Nigeria Data Protection Act, 2023 ("NDPA"), the NDPA General Application and Implementation Directive, 2025 ("GAID"), and other applicable data protection laws. This Privacy Policy explains how we collect, use, disclose, transfer, retain, and protect personal data when you visit our website(s), subscribe to our publications, engage our advisory services, or otherwise interact with us.
By accessing our website, subscribing to our publications, or engaging our services, you acknowledge that you have read and understood this Privacy Policy. Your use of our services, and any dispute arising from privacy matters, is also subject to our Terms of Service, which are incorporated into this Policy by reference.
Our website and services are not directed at individuals in any jurisdiction where making such information or services available would be contrary to local law, and nothing in this Policy should be construed as legal advice specific to any individual or organisation's circumstances.
2. Definitions
Throughout this Policy:
"You" and "your" refer to visitors to our website, subscribers to our publications, newsletter recipients, advisory clients, prospective clients, and any other individual whose personal data we process.
"We," "us," and "our" refer to MAGE LEGAL PUBLICATIONS AND BUSINESS ADVISORY LIMITED.
"Services" means our publishing platforms, digital publications, newsletters, legal and regulatory updates, business development advisory services, market insight reports, and any other product, service, or engagement we provide, as may change from time to time.
"Personal Data" means any information relating to an identified or identifiable natural person.
3. Scope of This Policy
This Policy applies to personal data we collect through:
a. our website(s) and any associated digital platforms;
b. subscriptions to our publications, newsletters, and alerts;
c. engagement of our business advisory services;
d. attendance at our webinars, seminars, or events;
e. direct correspondence with us (by email, telephone, or otherwise); and;
f. any other interaction you have with us in connection with our Services.
3.1. This Policy does not apply to the content of publications we distribute (which may include information about third parties compiled from public regulatory or legal sources), except to the extent such content constitutes your personal data and is addressed separately below.
4. Age Restriction and Processing of Children’s Personal Data
4.1. Our Services are intended for a general professional and business readership. While we do not specifically target or market our Services to children, we recognise that our publications may be accessed by students and young professionals under the age of 18 in an educational or professional-development capacity.
4.2. We do not knowingly collect personal data from children under the age of 13. Where we become aware that we have inadvertently collected personal data from a child under 13 without appropriate parental or guardian consent, we will take reasonable steps to delete that data promptly.
4.3. If you are a parent or guardian and believe that a child under your care has provided us with personal data without your consent, please contact us using the details in Section 20.
5. Information We Collect
The categories of personal data we may collect depend on how you interact with us:
5.1. Identity and Contact Data. Full name, job title, employer or organisation, email address, telephone number, postal or business address.
5.2. Subscription and Publication Data. Information provided when you subscribe to our newsletters, legal updates, or publications, including your areas of professional interest, industry sector, and reading or engagement preferences (e.g., articles opened, links clicked).
5.3. Advisory Engagement Data. Where you engage our business development or advisory services, we may collect information about your organisation's business activities, sector, market position, commercial objectives, and any other information you or your organisation provides to enable us to deliver advisory support, market insight, or business development recommendations.
5.4. Billing Data. Where applicable, billing name, business address, and payment reference details necessary to invoice for subscriptions or advisory services. We do not store full payment card or bank account details; these are processed by our third-party payment processors in accordance with their own privacy and security standards.
5.5. Technical and Usage Data. Internet protocol (IP) address, browser type and version, device information, operating system, referral source, pages visited, time spent on pages, and other analytics data collected automatically when you visit our website.
5.6. Communications and Feedback Data. Records of correspondence with us, including enquiries, feedback, survey responses, and comments submitted through our website or in the course of our engagement with you.
5.7. Marketing Preferences. Your preferences regarding receipt of marketing or promotional communications from us.
5.8. Where special category data is inadvertently provided to us (for example, within correspondence or advisory materials), we will restrict its use to the purpose for which it was shared, take appropriate steps to secure it, and delete it once it is no longer necessary for that purpose.
5.9. We do not intentionally collect special categories of personal data (such as health, biometric, or genetic data) and ask that you do not submit such data to us unless specifically requested and necessary for a stated purpose, in which case we will process it strictly in accordance with applicable law.
6. How We Collect Your Information
a. Directly from you, when you subscribe to a publication, register on our website, request advisory services, complete a form, or otherwise correspond with us.
b. Automatically, through cookies, web beacons, and similar technologies when you visit our website (see Section 15 on Cookies).
c. From third parties, including:
i. analytics providers (e.g., Google Analytics);
ii. publicly available regulatory, corporate, or professional registers relevant to the legal, regulatory, and commercial information we publish;
iii. event organisers or co-hosts, where you register for a webinar or event we participate in; and
iv. your organisation, where a colleague provides your contact details for the purpose of arranging engagement with us (the provider of such data warrants that they have the necessary consent to do so).
7. Lawful Basis for Processing
We rely on the following lawful bases under the NDPA and applicable data protection law:
7.1. Consent: where you have given clear consent for us to process your personal data for a specific purpose (e.g., subscribing to marketing communications).
7.2. Contractual necessity: where processing is necessary to perform a contract with you or your organisation, or to take steps at your request before entering into a contract (e.g., providing advisory services you have requested).
7.3. Legitimate interests: where processing is necessary for our legitimate interests (such as improving our Services, understanding readership of our publications, and business development), provided such interests are not overridden by your rights and freedoms.
7.4. Legal obligation: where processing is necessary to comply with a legal or regulatory obligation to which we are subject.
8. How We Use Your Information
We use your personal data to:
a. provide, maintain, and improve our publications and advisory services;
b. deliver newsletters, legal and regulatory updates, and other subscribed content;
c. respond to enquiries and provide the advisory or market insight support you request;
d. personalise content and recommendations based on your professional interests;
e. conduct research, analytics, and statistical analysis to improve our Services;
f. communicate with you, including by email, telephone, or other means;
g. process billing and manage our contractual relationship with you or your organisation;
h. maintain and update our records;
i. send you service-related communications, including updates to our Services or this Policy;
j. detect, prevent, and investigate fraud, misuse, or security incidents; and
k. comply with applicable legal and regulatory obligations.
9. How We Disclose and Share Your Personal Data
9.1. We may share your personal data with:
a. Service providers Including website hosting providers, email and newsletter distribution platforms, analytics providers, and payment processors, engaged to support our operations, subject to appropriate confidentiality and data protection obligations.
b. Professional advisers. Including our auditors, insurers, and legal advisers, where necessary.
c. Regulatory and law enforcement authorities. Where required by law, legal process, or in the good-faith belief that disclosure is necessary to comply with a legal obligation or protect the rights, property, or safety of MAGE, our clients, or the public.
d. Business transferees. In the event of a merger, acquisition, restructuring, or sale of assets, subject to appropriate safeguards.
9.2. We do not sell your personal data. We may share aggregated or anonymised data (which does not identify you) with business partners, advertisers, or affiliates for analytical or business development purposes.
9.3. Where any disclosure listed above is not strictly required by law, we will only make it with your consent or where permitted under this Policy.
10. Marketing Communications
10.1. We may send you marketing content relating to our publications and advisory services where you have subscribed to receive such content, requested information from us, or otherwise provided your details for that purpose and have not opted out.
10.2. We will only share your data with third parties for their own marketing purposes where you have expressly opted in to such sharing. You may opt out of marketing communications at any time by using the unsubscribe link in our communications or by contacting us using the details in Section 20.
11. International Transfer of Data
11.1. As our Services may be accessed by, and our publications distributed to, readers and clients outside Nigeria, your personal data may be transferred to, stored, and processed in countries other than your country of residence. Any such cross-border transfer will only be made on one of the following bases, in accordance with Part VIII of the NDPA and the GAID:
a. the recipient country or territory has been the subject of an adequacy decision by the Nigeria Data Protection Commission ("NDPC");
b. the transfer is made pursuant to an approved Cross-Border Data Transfer Instrument (CBDTI), such as standard contractual clauses or binding corporate rules; or
c. another lawful basis recognised under the NDPA applies, such as your explicit consent to the transfer, or the transfer being necessary for the performance of a contract with you, or for the establishment, exercise, or defence of legal claims.
11.2. Where we rely on your consent for a specific transfer, you may withdraw that consent at any time in accordance with Section 12 below, though this will not affect transfers already carried out.
12. Your Data Rights and Choices
12.1. Subject to applicable law, you have the right to:
a. be informed about how your personal data is processed;
b. request access to the personal data we hold about you;
c. request correction of inaccurate or incomplete personal data;
d. request erasure of your personal data, subject to applicable legal or contractual retention requirements;
e. object to processing of your personal data, including for direct marketing purposes;
f. request restriction of processing in certain circumstances;
g. request portability of your personal data in a structured, commonly used format;
h. withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal; and
i. lodge a complaint with the Nigeria Data Protection Commission ("NDPC") or other applicable supervisory authority.
12.2. Please note that where you object to certain processing or request erasure, we may be unable to continue providing some or all of our Services to you.
12.3. To exercise any of these rights, please contact us using the details in Section 20. We may need to verify your identity before responding to your request.
13. Security of Personal Data and Breach Notification
13.1. Security Measures: We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction, including encryption of data in transit (such as TLS/SSL), access controls, and staff confidentiality obligations. While we implement reasonable technical and organisational safeguards, no method of transmission or storage over the internet is entirely secure, and we cannot guarantee absolute protection against unauthorised access or disclosure that occurs despite these measures.
13.2. Breach Notification: In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Nigeria Data Protection Commission (NDPC) within seventy-two (72) hours of becoming aware of the breach, in accordance with the NDPA and the GAID. Where a breach is likely to result in a high risk to your rights and freedoms, we will also notify you without undue delay, describing the nature of the breach and the measures taken or proposed to address it.
14. Data Retention
a. We retain personal data only for as long as reasonably necessary to fulfil the purposes for which it was collected. As a general guide: subscriber and marketing data is retained for the duration of your subscription and for a reasonable period after unsubscribing to reflect your preference not to be contacted; billing and financial records are retained for the period required under applicable tax and accounting legislation; and advisory engagement records are retained for the duration of the engagement and for a reasonable period thereafter to address any related legal, regulatory, or professional obligations.
b. Where data is no longer needed for these purposes, we will securely delete, anonymise, or aggregate it.
c. We determine the appropriate retention period for any category of data by reference to the nature of the data, the purpose of processing, and applicable legal or regulatory requirements.
15. Use of Cookies and Similar Technologies
15.1. We use cookies and similar tracking technologies (such as web beacons and pixels) on our website to recognise you as a returning visitor, remember your preferences, understand how our website and publications are used, support account security and fraud prevention, and improve our Services.
15.2. The cookies we use fall broadly into the following categories:
a. Strictly necessary cookies: required for the website to function properly (e.g., enabling secure areas of the site or maintaining your session);
b. Analytics and performance cookies: used to understand how visitors interact with our website, so we can improve its content and functionality;
c. Functionality cookies: used to remember choices you make (such as language or display preferences) to provide a more personalised experience;
d. Marketing cookies: where applicable, used to understand engagement with our publications and tailor content to your professional interests.
15.3. You can control or disable cookies at any time through your browser settings. Where required by applicable law, we will request your consent before placing non-essential cookies on your device, and you may withdraw that consent at any time. Please note that disabling certain cookies may affect the functionality of our website.
15.4. For further information on the specific cookies we use, their purpose, and duration, please contact us using the details in Section 20.
16. Links to Third-Party Websites
a. Our website and publications may contain links to third-party websites, regulatory portals, or resources that are not owned or controlled by us.
b. We are not responsible for the content, privacy practices, or security of any third-party website.
c. We encourage you to review the privacy policies of any third-party site you visit.
17. Publications and Professional Disclaimer
a. Our publications are provided for general informational purposes only and do not constitute legal, regulatory, or professional advice.
b. Any personal or organisational data referenced in our publications that is drawn from public regulatory, corporate, or judicial sources is processed on the basis of our legitimate interest in reporting on matters of public legal and commercial record and in accordance with applicable law.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, Services, or legal requirements. Where changes are material, we will notify you by appropriate means (such as a notice on our website or by email). The updated Policy will take effect from the date of publication unless otherwise stated.
19. Governing Law
This Privacy Policy is governed by the laws of the Federal Republic of Nigeria. Any dispute arising in connection with this Policy shall be subject to the exclusive jurisdiction of the Nigerian courts, without prejudice to any right you may have to lodge a complaint with the Nigeria Data Protection Commission or another applicable supervisory authority.
20. Contact Us
If you have any questions, comments, or requests regarding this Privacy Policy or our data protection practices, please contact us at mage.afr@gmail.com.
