Legal
Information Security
How we protect the confidentiality, integrity and availability of information entrusted to the Group.
- Effective
- 6 August 2026
- Entity
- IIMG
- Registration
- RC 9586872
- Governing law
- Nigeria
Our commitment
Information is an important business asset. IDEAS IN MOTION GROUP LIMITED maintains administrative, organisational and technical safeguards intended to preserve the confidentiality, integrity and availability of information entrusted to the Group.
Security considerations form part of the planning, development and operation of the Group’s digital platforms and corporate systems, rather than being applied afterwards.
Security principles
Our security practices are designed to:
- protect confidential information;
- reduce operational risk;
- preserve business continuity;
- support secure technology infrastructure;
- safeguard intellectual property;
- strengthen resilience against cyber threats;
- encourage responsible information handling throughout the organisation.
Technical measures
- All connections to our websites and applications are encrypted in transit using TLS.
- Data at rest is held on access-controlled infrastructure operated by established providers.
- Administrative access requires individual authentication and is granted only where there is a legitimate business need.
- Our public websites are served with a strict content security policy and standard browser security headers.
- Systems are monitored, and software and dependencies are updated routinely.
- Payment card details are never stored on our systems. Card payments are handled entirely by our licensed payment providers.
Access management
Access to sensitive information is limited according to legitimate business responsibilities. Authentication procedures and access controls are applied to reduce the risk of unauthorised disclosure, and access is reviewed when roles change.
Incident management
Where a security incident is identified, we investigate, contain the risk, restore affected services and implement improvements intended to reduce the likelihood of recurrence.
Where a personal data breach is likely to result in a risk to the rights and freedoms of individuals, we notify the Nigeria Data Protection Commission within 72 hours of becoming aware of it, as required by the Nigeria Data Protection Act 2023, and we notify affected individuals without undue delay where the risk to them is high.
Reporting a vulnerability
If you believe you have found a security vulnerability in one of our websites or apps, please report it to legal@ideasinmotiongroup.com with enough detail for us to reproduce it.
We will acknowledge your report, keep you informed while we investigate, and we will not pursue action against anyone who reports an issue in good faith, gives us reasonable time to fix it, and does not access, alter or delete data belonging to other people.
Continuous improvement
Information security is an ongoing process rather than a one-time exercise. Policies, procedures and technical safeguards are reviewed periodically in response to technological developments, operational experience, regulatory change and evolving risks.
Shared responsibility
Protecting information requires cooperation at every level of the organisation. Employees, contractors, technology providers and business partners are expected to exercise appropriate care in handling information made available through or on behalf of the Group.
Related documents
See our Privacy Policy for how personal data is handled, and our Governance & Ethics statement for the wider control environment.
Who we are
IDEAS IN MOTION GROUP LIMITED is a company registered in Nigeria under registration number 9586872, with its registered office at Suite 063, Mabushi Ultra-Modern Mall, Katampe Road, Off Ahmadu Bello Way, Jahi, Abuja, FCT, Nigeria.
- Data Protection Officer
- Dr Ugo Emenalo — ugo.emenalo@ideasinmotiongroup.com
- Privacy enquiries
- privacy@ideasinmotiongroup.com
- Legal enquiries
- legal@ideasinmotiongroup.com
- Telephone
- +234 907 777 3225
