ApprovalDesk← Back to home

Trust & data governance

Privacy Policy

How ApprovalDesk handles personal information when we provide and support your organisation’s managed approval-workflow instance.

Last updated 27 August 2026

1. Scope, responsible companies, and our role

This policy applies to the ApprovalDesk website, managed product instances, support services, and related business communications. ApprovalDesk is developed by OHR Systems and supported by IChannel Technologies. Both companies are registered in Nigeria.

Your organisation decides why and how request, workflow, and employee information is used in its ApprovalDesk instance. In that context, the organisation is generally the data controller and the ApprovalDesk provider identified in its service agreement acts as a data processor or service provider. OHR Systems and IChannel Technologies may each act as a controller for account, security, support, commercial, and website information they collect for their own business purposes.

2. Information we process

Depending on how your organisation configures ApprovalDesk, we may process:

  • Account and organisation details, including names, work email addresses, roles, departments, managers, and optional telephone numbers.
  • Request content, custom form answers, attachments, comments, mentions, approval decisions, conditions, delegations, deadlines, and workflow history.
  • Security and technical records, such as sign-in events, device and session information, IP-derived location signals, audit events, and delivery logs.
  • Support and commercial information, including messages, configuration details, service contacts, and order or billing records.
  • Integration data needed to deliver notifications or approved post-workflow actions through services your organisation enables.

3. Sources, purposes, and lawful bases

Information may come from you, your organisation and its administrators, other Authorised Users, customer-enabled integrations, and the devices and systems used to access the service.

We process information to provide, secure, maintain, and support ApprovalDesk; route requests to authorised people; record decisions; deliver notifications; generate reports and evidence packs; troubleshoot incidents; prevent abuse; and meet contractual or legal obligations. Where applicable, we rely on performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, or consent for a specific optional activity.

We do not sell personal information. We do not use the contents of your organisation’s requests or attachments for third-party advertising.

4. Customer control and lawful use

Your organisation controls its forms, workflows, users, permissions, integrations, and retention requirements. It is responsible for having a lawful basis to submit personal information to ApprovalDesk, giving appropriate notices to its users, and avoiding unnecessary collection of sensitive data.

Administrators can restrict sensitive fields, manage user access, review security events, and anonymise former users while preserving decision history where accountability records must remain intact.

5. Sharing and subprocessors

We disclose information only as needed to operate the service, follow your organisation’s instructions, comply with law, protect the service and its users, or complete a business transaction subject to appropriate safeguards.

Service providers may support managed hosting, email delivery, monitoring, backups, customer support, or other operational functions. Customer-enabled integrations receive only the information needed for the action your organisation configures. Those services apply their own terms and privacy practices.

6. Security

ApprovalDesk uses administrative, technical, and organisational safeguards appropriate to the service, including role-based access, encrypted connections, protected credentials, time-limited signed links, access logging, backups, and optional multi-factor controls.

No service can guarantee absolute security. Customers should configure least-privilege access, protect administrator accounts, review integrations, and promptly report suspected compromise.

7. Retention, audit records, and deletion

We retain information for as long as needed to provide the managed service, satisfy the customer’s documented requirements, resolve disputes, maintain security, and meet legal obligations. Retention periods may vary by customer configuration and service agreement.

ApprovalDesk is designed to preserve an append-only history of workflow actions. When a person has participated in a recorded business decision, account deletion may be replaced with anonymisation so the organisation can retain an accountable audit trail. Customers can request exports and agree offboarding or deletion arrangements with our team.

8. International processing

Managed infrastructure and service providers may process information outside the country where a user works. Where required, we use contractual and organisational safeguards for international transfers and discuss data-location requirements during customer onboarding.

9. Your choices and rights

Depending on applicable law, individuals may have rights to be informed; access, correct, or export their information; restrict or object to processing; withdraw consent; request deletion; and raise a complaint with the data-protection authority responsible for their location.

For information held in an organisation’s ApprovalDesk instance, contact that organisation first. We will support verified customer requests as required by our agreement and applicable law. For information controlled directly by ApprovalDesk, contact us using the details below. We may need to verify identity before completing a request.

10. Website data and cookies

Our website may use essential storage or cookies needed for security, preferences, and basic operation. If we introduce non-essential analytics or marketing technologies, we will provide any notice and choices required by applicable law.

11. Children

ApprovalDesk is a business service and is not directed to children. Organisations must not use it to collect children’s personal information unless they have an appropriate lawful basis, safeguards, and a use case agreed with us.

12. Changes and contact

We may update this policy as the product, operating model, or law changes. We will publish the revised date and provide additional notice when a material change requires it.

For product and privacy enquiries, contact OHR Systems at hello@ohrsystems.ng. For implementation and support enquiries, contact IChannel Technologies at hello@ichanneltech.com.

ApprovalDesk

Managed approval infrastructure for accountable teams.