Last updated 9 August 2026
This policy explains what personal data cy‑paid collects, the purposes for which it is processed, the parties with whom it is shared, and the rights available to you. It applies to the cy‑paid website and application. Questions may be directed to the address in the Contact section below.
Account data. Your email address and the sign-in method used (email link or Google).
Content you submit. Business details, invoices and line items, clients, projects, payments, tax settings and payment account details. This data is necessary to provide the service.
Uploaded files. A business logo, where you choose to supply one, for inclusion on your invoices. Logo files are stored in a publicly accessible storage bucket under an unguessable URL, which is how they are embedded in generated PDF documents. You should not upload material to this field that must remain confidential.
API credentials. Where you generate an API key, only a hash of that key is retained. A lost key cannot be recovered and must be replaced.
Technical data. Server logs generated by our hosting provider, comprising IP address, requested URL and timestamp, retained on a short-term basis for service reliability and abuse prevention.
Account and content data are processed to perform the contract between you and cy‑paid, being the provision of the invoicing service you have requested. Technical data is processed on the basis of legitimate interests in maintaining the security, availability and integrity of the service. Where processing relies on consent, that consent may be withdrawn at any time.
cy‑paid engages the following processors. This list is exhaustive; no other party receives personal data.
Account email address, business details, invoices, clients, projects, payments and uploaded logos.
Your email address, and only if you choose to sign in with Google. No data is shared with Google if you sign in by email link.
Your email address and the contents of reminder emails addressed to you. No email is sent to your clients.
Currency codes only. No personal data, client data or invoice amounts are transmitted.
Server request logs, including IP address, requested URL and timestamp.
Personal data may also be disclosed where required by law, court order or a binding request from a competent authority.
Our service providers operate internationally, and personal data may accordingly be processed outside Nigeria and outside the European Economic Area. Such transfers are made in reliance on the standard contractual protections maintained by those providers. Data is not transferred for any purpose other than the operation of the service.
Personal data is retained for the duration of your account. On deletion of an account, the associated records are removed from the live database and expire from backups within 30 days. Server logs are retained by our hosting provider on a short-term basis and are then deleted.
Guest accounts, created without an email address, are deleted automatically thirty days after they are created unless an email address or Google identity is added to them. Deletion covers the account and every record attached to it.
Access to your data is restricted to your authenticated account. Data is transmitted over encrypted connections and stored by our providers using encryption at rest. API keys are stored only as hashes. No system can be guaranteed to be entirely secure, and you should retain your own copies of records you cannot afford to lose.
cy‑paid is operated from Nigeria and is subject to the Nigeria Data Protection Act 2023. The following rights are extended to all users irrespective of their place of residence:
Requests should be sent to hello@cy-paid.cytro.com.ng and will receive a substantive response within 30 days. If you consider that your rights have not been respected, you may lodge a complaint with the Nigeria Data Protection Commission or, where applicable, your local supervisory authority.
The service is intended for business use and is not directed at children. We do not knowingly collect personal data from any person under the age at which they can lawfully enter a contract in their jurisdiction.
This policy may be amended from time to time. The date of the current version appears at the head of this page. Where an amendment materially affects your rights, notice will be given by email in advance of the change taking effect.