Privacy Policy
Last updated: 28 August 2026
This policy explains what personal data Citadel handles, why, and what rights you have over it. It covers the Citadel web, desktop and mobile applications and the citadelpro.io website.
1. Who we are
Citadel is operated by Nexa Labs Ltd (“Nexa Labs”, “we”, “us”), a company registered in Ghana. Our registered address and company number are set out at the end of this policy.
2. Two different roles, and why it matters
Citadel handles two kinds of personal data, and our responsibilities differ between them. This distinction runs through the whole policy.
| Kind of data | Example | Our role |
|---|---|---|
| Account data | The name, email address and sign-in details of the person using Citadel; billing contacts; support correspondence; how the product is used | We are the controller. We decide why and how it is handled, and this policy governs it. |
| Customer data | Everything an organisation puts into Citadel: their employees, customers, invoices, documents, calendars | We are a processor. The organisation decides why and how it is handled; we act on their instructions under our agreement with them. |
If your employer uses Citadel and you want to know what they hold about you, ask them: they control that data, not us. We will help them respond, but we cannot disclose or delete their records on your request alone.
3. What we collect as controller
- Identity and contact. Name, work email, organisation, job title, and profile photo if you add one.
- Authentication. Passwords are stored only as salted hashes; we never hold your password. Two-factor secrets and session tokens where enabled.
- Billing. Company details and subscription records. Card details are handled by our payment providers and never reach our servers.
- Usage and diagnostics. Pages visited, features used, device and browser type, IP address, and error reports, used to keep the service working and to decide what to build.
- Support. Anything you send us when you ask for help.
4. Data from Google APIs
If you connect a Google account to Citadel, we access a narrow slice of your Google data. We ask for the least access that makes the feature work.
| What we access | Why |
|---|---|
Your calendar’s busy periods (calendar.readonly) | So Citadel never offers somebody a meeting time when you are already booked. We request free/busy information, which returns blocks of occupied time without the titles, attendees, locations or descriptions of those meetings. |
Creating and removing events (calendar.events) | So a meeting booked through Citadel appears on your real calendar, and disappears from it if the booking is cancelled. We only create, update and delete events Citadel itself booked. |
Your Google account email address (userinfo.email) | So you can see which account is connected and disconnect the right one. |
Limited use
Citadel’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, we do not:
- sell, rent or trade Google user data;
- use it for advertising, or transfer it to advertising platforms or data brokers;
- use it to train generalised artificial intelligence or machine learning models;
- allow humans to read it, except where you explicitly ask us to for support, where it is necessary for security or to comply with the law, or where the data has been aggregated and anonymised.
Storing and removing it
We store the access and refresh tokens that let us reach your calendar. They are encrypted at rest and are only decrypted at the moment they are used. We do not keep a copy of your calendar: busy times are fetched when needed and used to answer a single availability question.
You can disconnect at any time in Citadel, which deletes the stored tokens immediately. You can also revoke access from your Google account permissions page, which takes effect at once regardless of anything we do.
5. Why we use account data
- To provide the service. Signing you in, showing you your organisation’s data, sending notifications you asked for.
- To keep it secure. Detecting suspicious sign-ins, preventing abuse, keeping audit trails.
- To bill. Managing subscriptions and invoices.
- To support and improve. Answering your questions and understanding which features are used.
- To comply. Meeting our legal and regulatory obligations.
Where the law requires a lawful basis, ours is performance of our contract with you or your organisation, our legitimate interests in running and securing the service, your consent where we ask for it (such as connecting a Google account), and compliance with legal obligations.
6. Who we share it with
We do not sell personal data. We share it only with:
- Your organisation. If you use Citadel through an employer, its administrators can see your account and activity within it.
- Service providers who help us run Citadel: hosting, email delivery, error monitoring, payment processing. They act on our instructions and may not use the data for their own purposes.
- Authorities, where we are legally required to, and where we may lawfully tell you, we will.
- A buyer, if the business is sold or merged, subject to this policy continuing to apply.
7. International transfers
Citadel is operated from Ghana, and our infrastructure providers may process data in other countries. Where data leaves the country it was collected in, we rely on appropriate safeguards with those providers.
8. How long we keep it
- Account data: while your account is active, and for a limited period afterwards so an account closed by mistake can be restored.
- Google tokens: until you disconnect, then deleted immediately.
- Billing records: for as long as tax and accounting law requires.
- Diagnostics and logs: for a short period, then deleted or anonymised.
- Customer data: per our agreement with the organisation; on termination it is exported or deleted on their instruction.
9. Security
We encrypt data in transit and encrypt particularly sensitive values, including calendar and payment credentials, at rest. Access to production systems is limited to staff who need it and is logged. No system is perfectly secure, and we do not claim otherwise, but we will tell you and the relevant authority without undue delay if a breach affects your data.
10. Your rights
Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to how we use it, take it elsewhere in a portable form, and withdraw consent at any time.
Contact us using the details below and we will respond within the time the law allows. If you are unhappy with our response you may complain to your data protection authority; in Ghana, that is the Data Protection Commission.
11. Children
Citadel is business software and is not directed at children. We do not knowingly collect data from anyone under 18, and will delete it if we learn we have.
12. Changes
We will update this policy as the product changes. The date at the top always reflects the current version, and we will tell you in advance about changes that materially affect your rights.
13. Contact
Nexa Labs Ltd
Email: privacy@citadelpro.io