Home / Legal / Terms of Service

Terms of Service

Effective Date: 1 October 2026
Last Updated: NA
Version: 1.0

1. Introduction

These Terms of Service (“Terms”) govern your access to and use of www.amstelconsulting.ng (the “Website”) and certain services, materials and functionality made available through the Website by Amstel Tech Compliance and Consulting Limited d/b/a Amstel Consulting (“we”, “us” or “our”).

Please read these Terms carefully.

By accessing or using the Website, you agree to be bound by these Terms. If you do not agree with these Terms, you should discontinue use of the Website.

2. About Us

Amstel Consulting is a company registered in Nigeria.

Registered Office: Leisure Court Estate, Karshijikwoyi 2, Jikwoyi, Abuja, FCT.
RC Number:
DPCO Licence Number:
Email: info@amstelconsulting.ng

We provide professional services relating to data protection, privacy, governance, compliance and information management.

Our services may include:

  • Data Protection Compliance Organisation (“DPCO”) services;
  • outsourced and consulting Data Protection Officer (“DPO”) services;
  • data protection compliance audits;
  • Compliance Audit Return support;
  • privacy compliance assessments;
  • Data Protection Impact Assessments (“DPIAs”);
  • privacy governance;
  • data mapping;
  • records of processing activities;
  • policy and procedure development;
  • privacy notices;
  • data processing agreements;
  • vendor privacy assessments;
  • personal data breach response;
  • data subject rights management;
  • training and awareness;
  • regulatory liaison and support;
  • cross-border data transfer assessments; and
  • related consulting and advisory services.

3. Website Use and Professional Services

These Terms govern use of our Website and any Website functionality expressly made subject to them.

The detailed terms governing professional consulting services may be contained in a separate:

  • proposal;
  • engagement letter;
  • Master Services Agreement;
  • Statement of Work;
  • purchase order;
  • Data Processing Agreement; or
  • other written agreement.

Where there is a conflict between these Website Terms and a specifically negotiated written agreement concerning professional services, the specifically negotiated agreement will prevail in relation to those services.

4. No Engagement Merely Through Website Use

Using this Website, completing an enquiry form, requesting a quotation, sending us information or communicating with our personnel does not automatically create a professional engagement.

We reserve the right to:

  • conduct conflict checks;
  • carry out client due diligence;
  • clarify the scope of proposed work;
  • assess our capacity and professional competence;
  • determine whether an engagement may impair DPO independence;
  • require appropriate contractual documentation; and
  • accept or decline a proposed engagement.

An engagement will commence only when expressly accepted by us in accordance with the relevant contractual arrangements.

5. Client Responsibilities

Where you engage us to provide professional services, you agree, subject to the specific engagement terms, to:

  • provide complete and accurate information reasonably required for the engagement;
  • provide timely access to relevant personnel, records, systems and documentation;
  • identify relevant legal, regulatory and operational requirements known to you;
  • inform us of material changes affecting the engagement;
  • ensure that instructions provided to us are lawful;
  • maintain responsibility for management and operational decisions;
  • appropriately consider recommendations made by us;
  • obtain internal approvals required to implement recommendations;
  • maintain appropriate security over your systems and records; and
  • pay applicable fees and expenses in accordance with the agreed terms.

Unless expressly agreed otherwise, you remain responsible for determining whether and how recommendations are implemented.

6. DPCO Services

Where we are appointed to provide DPCO services, the scope of those services will be specified in the applicable engagement documentation.

Our DPCO services may include compliance auditing, assessment, training, advisory support, documentation and regulatory filing or liaison.

The client acknowledges that responsibility for organisational compliance remains with the relevant data controller or data processor and its management.

Our appointment does not transfer the client's statutory responsibilities to us.

7. DPO Services

Where we are appointed to provide outsourced or consulting DPO services, the appointment and scope of responsibility will be separately documented.

The client agrees to support the effective performance of the DPO function, including by:

  • providing appropriate access to senior management;
  • involving the DPO appropriately and in a timely manner in matters relating to personal data;
  • providing access to information necessary to perform the role;
  • providing sufficient resources;
  • respecting applicable requirements concerning DPO independence;
  • avoiding instructions that improperly interfere with independent DPO functions; and
  • identifying and managing conflicts of interest.

The precise allocation of responsibilities will be determined by applicable law and the relevant engagement agreement.

8. Accuracy of Client Information

Our professional work may depend materially upon information supplied by clients and other stakeholders.

Unless the engagement expressly requires independent verification, we may rely upon information provided to us as being complete and accurate.

We are not responsible for errors in advice, assessments or deliverables to the extent that those errors result from materially inaccurate, incomplete, misleading or withheld information supplied to us, subject to applicable law.

9. Professional Judgement

Data protection compliance frequently requires professional judgement based upon legislation, regulatory guidance, technological risks and factual circumstances.

Our advice represents our professional assessment based upon the information reasonably available to us at the relevant time.

Regulatory authorities, courts or other professional advisers may reach different conclusions concerning the same circumstances.

Unless expressly agreed otherwise, no professional opinion constitutes a guarantee of a particular regulatory or judicial outcome.

10. Regulatory Changes

Data protection, technology and cybersecurity regulation evolves over time.

Unless ongoing monitoring is expressly included within our engagement, advice and deliverables are based upon laws, regulations and authoritative guidance applicable or reasonably known at the time the relevant work is performed.

We are not automatically responsible for updating completed advice or deliverables following subsequent changes in law, regulatory interpretation, technology or the client's operations unless we have expressly agreed to provide ongoing support.

11. Fees and Payment

Fees for professional services will be specified in the applicable proposal, engagement letter, Statement of Work, invoice or other written agreement.

Unless otherwise agreed:

  • fees are stated exclusive of applicable taxes;
  • invoices must be paid within 14 days of issue;
  • approved out-of-pocket expenses may be charged separately;
  • work outside the agreed scope may be subject to additional fees; and
  • significant changes to scope, timing or client requirements may require revised commercial terms.

We reserve the right, subject to contractual and legal obligations, to suspend non-critical services where undisputed invoices remain materially overdue after reasonable notice.

12. Confidentiality

Each party may receive confidential information belonging to the other.

We will maintain the confidentiality of client information and will not disclose it except:

  • as necessary to provide the agreed services;
  • to personnel or subcontractors subject to appropriate confidentiality obligations;
  • with the client's authorisation;
  • where required by law or regulation;
  • where required by a competent regulator, court or public authority;
  • where necessary to establish, exercise or defend legal rights; or
  • as otherwise permitted by the applicable engagement agreement.

These obligations survive termination to the extent provided by applicable law or contract.

13. Data Protection

Each party shall comply with applicable data protection legislation in relation to personal data processed in connection with the services.

Depending upon the processing activity, Amstel Consulting may act as:

  • an independent data controller;
  • a joint controller, where expressly established;
  • a data processor acting on the client's instructions; or
  • a professional service provider processing limited information in connection with its independent legal, regulatory or professional obligations.

Where we process personal data as a processor on behalf of a client, the parties will enter into appropriate contractual arrangements where required by applicable law.

Further information concerning our processing of personal data is contained in our Privacy Statement.

14. Information Security

We maintain technical and organisational measures designed to protect personal data and confidential information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

Clients remain responsible for maintaining appropriate security over their own systems, accounts, infrastructure and information.

No electronic system can be guaranteed to be completely secure, and neither party represents that security incidents can be eliminated entirely.

15. Intellectual Property

Unless otherwise agreed in writing, all intellectual property owned by either party before an engagement remains the property of that party.

This includes our pre-existing:

  • methodologies;
  • frameworks;
  • models;
  • templates;
  • training materials;
  • assessment tools;
  • know-how;
  • processes; and
  • intellectual property.

Where we create client-specific deliverables, ownership and/or licence rights will be determined by the applicable engagement agreement.

Unless otherwise agreed, upon payment of applicable fees the client may use final client-specific deliverables internally for the purposes for which they were commissioned.

Our pre-existing methodologies, tools, know-how and underlying intellectual property remain ours.

16. Website Content

Website content, publications and general resources are provided for information and educational purposes.

They do not constitute advice tailored to a particular organisation and should be read subject to our Legal Disclaimer.

We may change, withdraw or update Website content without prior notice.

17. Acceptable Use

You must not use our Website:

  • unlawfully or fraudulently;
  • to introduce malware or harmful code;
  • to gain unauthorised access to systems or information;
  • to interfere with Website availability or security;
  • to harvest personal data unlawfully;
  • to impersonate another person or organisation;
  • to infringe intellectual property rights;
  • to transmit unlawful, defamatory or harmful material; or
  • in a manner that could damage our systems, reputation or operations.

We may restrict or terminate access where we reasonably believe these Terms have been materially breached.

18. Third-Party Services

Our Website or professional services may make use of or refer to third-party technology, platforms, software or information sources.

Unless expressly agreed otherwise, we are not responsible for the availability, operation or independent acts of third-party services outside our reasonable control.

Third-party services may be subject to separate terms and privacy notices.

19. Subcontractors and Specialists

Subject to the relevant engagement terms and applicable law, we may use appropriately qualified personnel, contractors or specialist service providers to assist in delivering services.

Where such persons receive access to confidential information or personal data, we will seek to impose appropriate contractual, confidentiality and data protection obligations.

Where client approval is contractually or legally required before appointment of a particular subcontractor, we will obtain that approval.

20. Conflicts of Interest

We may perform conflict checks before and during an engagement.

If an actual or potential conflict arises, we may:

  • disclose the conflict where appropriate;
  • implement appropriate safeguards;
  • obtain relevant consent where appropriate;
  • modify the engagement; or
  • decline or terminate the affected engagement where the conflict cannot appropriately be managed.

Nothing in an engagement requires us to act in a manner inconsistent with applicable professional independence or regulatory obligations.

21. Public-Sector Clients

Where services are provided to a Ministry, Department, Agency, public institution or other government body, additional requirements may apply concerning:

  • procurement;
  • public records;
  • confidentiality;
  • information security;
  • government approvals;
  • audit;
  • statutory powers;
  • public-interest processing; and
  • regulatory obligations.

Any mandatory statutory or procurement requirement applicable to the engagement will prevail over these general Terms to the extent required by law.

22. Limitation of Liability

To the maximum extent permitted by applicable law, liability arising from professional services will be governed by the relevant engagement agreement.

Nothing in these Terms excludes or limits liability where exclusion or limitation is prohibited by law.

Neither party will be liable for indirect or consequential loss to the extent such liability may lawfully be excluded, except as otherwise agreed in the applicable engagement agreement.

Any specific financial limitation of liability for professional services should be set out in the relevant engagement agreement rather than inferred from these Website Terms.

23. Indemnities

Any indemnification obligations relating to a professional engagement will be set out expressly in the relevant engagement agreement.

Nothing in these Website Terms creates an unlimited indemnity in favour of either party.

24. Force Majeure

Neither party will be responsible for failure or delay in performing an obligation, other than an obligation to pay sums properly due, to the extent caused by circumstances outside its reasonable control.

Such circumstances may include natural disasters, major infrastructure failures, widespread telecommunications outages, civil disturbances, governmental restrictions, epidemics or other comparable events.

The affected party should take reasonable steps to mitigate the effects of the event and resume performance when reasonably practicable.

25. Suspension and Termination

We may suspend or terminate access to the Website where these Terms are materially breached or where necessary to protect the security or integrity of our systems.

Professional engagements may be terminated in accordance with the applicable engagement agreement.

Termination does not affect rights or obligations that accrued before termination.

Provisions intended by their nature to survive termination, including confidentiality, intellectual property, accrued payment obligations and applicable limitations of liability, will continue to apply.

26. Notices

Formal notices relating to professional engagements should be delivered in accordance with the applicable engagement agreement.

General Website communications may be sent to:

Amstel Tech Compliance and Consulting Limited
Email: info@amstelconsulting.ng

Data Protection Enquiries:
Email: info@amstelconsulting.ng

27. Changes to These Terms

We may update these Terms periodically. The latest version will be published on the Website together with the date on which it was last updated.

Material changes affecting an existing professional engagement will not automatically amend a separately executed agreement unless that agreement expressly provides otherwise.

28. Severability

If any provision of these Terms is held to be invalid, unlawful or unenforceable, the remaining provisions will continue in effect to the extent permitted by law.

29. No Waiver

A failure or delay in exercising a right under these Terms does not constitute a waiver of that right.

30. Entire Agreement

For use of the Website, these Terms, together with our Privacy and Data Protection Statement, Cookie Notice and Legal Disclaimer, constitute the relevant Website terms between you and us.

For professional services, the applicable engagement letter, Statement of Work, Master Services Agreement or other executed agreement may contain additional or superseding terms.

31. Governing Law

These Terms are governed by the laws of the Federal Republic of Nigeria.

Subject to any dispute-resolution procedure contained in an applicable professional services agreement, disputes relating solely to use of this Website will be subject to the jurisdiction of the competent courts of Nigeria.

32. Dispute Resolution

Before commencing formal proceedings in relation to a commercial dispute arising under these Terms, the parties should, where reasonably practicable, attempt to resolve the matter through good-faith discussions.

Professional engagement agreements may provide for additional dispute-resolution procedures, including negotiation, mediation or arbitration.

Nothing in this provision prevents either party from seeking urgent interim or protective relief where appropriate.

33. Regulatory Rights

Nothing in these Terms is intended to prevent any person from:

  • exercising a statutory data protection right;
  • submitting a complaint to the Nigeria Data Protection Commission;
  • cooperating with a competent regulator;
  • making a disclosure required by law; or
  • exercising another right that cannot lawfully be excluded by contract.

34. Contact Details

Questions concerning these Terms may be directed to:

Amstel Consulting
Email: info@amstelconsulting.ng
Website: amstelconsulting.ng

© 2026 Amstel Tech and Compliance Consulting Ltd. All rights reserved.