Security, privacy, and how we handle your data.
Maintained by Patrick Enwerem Limited (PEL). For our regulatory posture; NDPA 2023, NITDA, AI Ethics, ISO/IEC 27001 alignment; see the Trust & Compliance hub.
About this page
This Trust Center is maintained by Patrick Enwerem Limited (PEL) to answer common security and privacy questions about penwerem.com and the PEL client portal. It describes the practices we currently operate; it is editable project content and is not an independent certification or audit attestation.
For deeper governance materials; NDPA 2023 alignment, NITDA registration, AI ethics, and our shared-responsibility model; see the Trust & Compliance hub.
Access & authentication
Public site pages on penwerem.com are open to anyone. The PEL client portal (app.penwerem.com) is gated by authentication; sign-in sessions are scoped per user.
Administrative and staff actions require an elevated role on the backend. Role checks are enforced server-side, not in browser code, and protected data is filtered by row-level security policies in our database.
Platform & hosting
The marketing site is deployed on Cloudflare's edge network. Application data and authentication run on Supabase, which uses managed Postgres with row-level security as the system of record.
Transport is encrypted in transit with TLS. Database storage encryption at rest is provided by the managed platform. PEL does not operate self-hosted database servers for this site.
Data we collect
Brief submissions and contact forms: the name, email, company, phone, message and any optional context fields you choose to enter. We use this strictly to respond to your inquiry and to schedule a strategy session.
Client portal usage: account profile, role, and the project/engagement records associated with your organisation. Portal data is visible only to your account and authorised PEL staff under role-based access controls.
We do not sell personal data and we do not use brief or portal content to train third-party AI models.
Subprocessors & integrations
Email delivery (transactional notifications and confirmations) is handled through Resend. Scheduling for strategy sessions is provided by Calendly when you book a meeting. Application database is provided by Supabase; the public site is served via Cloudflare.
These providers only receive the minimum data required to deliver their function (e.g. your email address for a confirmation email).
Retention & deletion
Brief and contact submissions are retained for the duration of the prospect or engagement lifecycle, plus a reasonable period for record-keeping and legal/regulatory obligations.
You can request deletion of personal data we hold about you by emailing info@penwerem.com. We will confirm receipt and complete the request subject to applicable Nigerian Data Protection Act (NDPA) 2023 obligations.
Your privacy rights
Under the NDPA 2023, you may request access to, correction of, or deletion of personal data we hold about you, and you may withdraw consent for marketing communications at any time using the unsubscribe link in any email we send.
Privacy requests can be sent to info@penwerem.com. We will respond within the timelines required by applicable law.
Security & incident contact
If you believe you have discovered a security vulnerability affecting penwerem.com, the PEL client portal, or any PEL-operated service, please report it privately to info@penwerem.com with the subject line 'Security report'. Please include steps to reproduce and avoid accessing data that is not your own.
We will acknowledge receipt, investigate, and coordinate remediation. Please do not publicly disclose details until we have had a reasonable opportunity to address the issue.
Questions about security or privacy? Reach us at info@penwerem.com.
Submit a brief →