Trust & Compliance

Organisations trust My Centre Office (“MyCo”) with the personal data of their members, customers and supporters. This page explains who we are, where that data is held, how it is protected, who can access it, and what we are accountable for. It is written to be read by anyone who needs to understand our security and data handling, whether you are a customer, a prospective customer, a data protection officer, or carrying out a due diligence review on our behalf of your organisation.

The single most important point: the data your organisation holds in MyCo belongs to your organisation. You are the Data Controller. We are the Data Processor. We process that data only to deliver the service to you, only on your instructions, and never for our own purposes. We do not sell it, and we do not share it with anyone beyond the service providers listed in section 7.
1. Who we are MyCo is the platform. It is operated by two related companies, and you will see both names on our certificates and registrations. They are one business.
Entity Role Holds
My Centre Office Ltd
United Kingdom, company number 07719756
UK operating entity and the contracting party for the MyCo platform Cyber Essentials certification and registration with the UK Information Commissioner’s Office
MyCo Digital Solutions Limited
Group entity covering our operations and customers in Nigeria Registration with the Nigeria Data Protection Commission and our annual compliance audit filing under the Nigeria Data Protection Act 2023
If you are contracting with us and need this reflected in a specific way for your own records, contact us and we will confirm it in writing.
2. Where your data is held All MyCo platform data is hosted on servers in the United Kingdom. Our technical measures include:
  • SSL/TLS encryption for all data in transit
  • Encrypted password storage
  • Automatic blocking of suspected unauthorised access
  • Secure data centre facilities operated by our hosting partner
  • Role based access controls, so your team members only see what you allow them to see
Emails and text messages sent from MyCo are routed through our delivery partners. Message history is held on their systems for delivery tracking and is deleted when an account is closed.
3. Cyber Essentials certification MyCo is Cyber Essentials certified, assessed by IASME against the scheme’s requirements, with a scope covering our whole organisation. We hold a current certificate at all times and recertify annually. Certification confirms that we have implemented:
  • Secure configuration of systems and servers
  • Access control and user authentication
  • Protection against common malware and threats
  • Patch management and vulnerability management
We will provide a copy of our current certificate on request. Every Cyber Essentials certificate carries a QR code and certificate number that allow you to verify it independently with the certification body, so you do not have to take our word for it.
4. Regulatory registration We are registered and maintain our filings with:
  • UK Information Commissioner’s Office (ICO), under UK GDPR
  • Nigeria Data Protection Commission (NDPC), under the Nigeria Data Protection Act 2023, including the annual statutory compliance audit return
Both registrations are renewed on their normal cycle and kept current. Copies of the latest certificates and acknowledgements are available on request.
5. Payment security (PCI DSS SAQ A) All card payments taken through MyCo are handled exclusively by PCI DSS certified payment service providers: Paystack, Flutterwave and Stripe.
  • Customers enter card details directly on the provider’s hosted checkout page
  • MyCo never stores, processes or transmits cardholder data
  • Platform fees are applied automatically using split payments where applicable
Because card data never touches MyCo systems, the platform qualifies for PCI DSS SAQ A (Self Assessment Questionnaire, Type A), the lowest scope for PCI DSS compliance. Our SAQ A attestation is available on request.
6. Your data belongs to you Under our Data Processing Agreement, your organisation is the Data Controller and MyCo is the Processor. That means, in practice:
  • We process your members’ data only on your documented instructions, and only to deliver the service you have subscribed to
  • We never use your data for any other purpose, and we never sell it
  • You can export or request deletion of your data at any time
  • When your account is closed, your data is deleted, unless the law requires us to retain something, in which case we tell you
  • We release data exports only to verified, authorised representatives of your organisation, through channels officially associated with you. We do not transfer member data to third party platforms or domains without written authorisation from your designated officers
Everyone at MyCo who is authorised to handle personal data is bound by confidentiality obligations, and we maintain records of the processing we carry out on your behalf.
7. Service providers we rely on We share data only with the providers needed to deliver the service. Each is bound by data protection obligations equivalent to those in our own agreement with you.
Provider Location Purpose
Webhosting UKUnited KingdomServer hosting
SendgridUnited StatesEmail delivery
Voodoo SMSUnited KingdomSMS delivery, UK
KudismsNigeriaSMS delivery, Nigeria
StripeUnited StatesPayment processing
PaystackNigeriaPayment processing
FlutterwaveNigeriaPayment processing
KorapayNigeriaPayment processing
Anthropic PBCUnited StatesBusiness insights, aggregated and anonymised data only, see section 8
Where data is transferred outside the United Kingdom and the European Economic Area, we put appropriate safeguards in place in line with UK GDPR, including Standard Contractual Clauses where applicable. Transfers involving Nigeria are handled in accordance with the Nigeria Data Protection Act 2023. We notify you before this list changes, so that you have the opportunity to object.
8. Artificial intelligence features Maia, our built in business assistant, produces weekly advisory insights on your dashboard and, where you configure it, by email to people you nominate. To generate these insights we send aggregated, anonymised figures only: totals and counts such as revenue, contact numbers, invoice summaries and engagement statistics.
No personally identifiable information is ever sent. No names, no email addresses, no phone numbers, no dates of birth, and no other personal data relating to your contacts or users.
Insights are advisory and should not be treated as professional financial, legal or business advice. If you would prefer this feature switched off for your account, tell us and we will disable it.
9. If something goes wrong We are contractually committed to notifying you of any personal data breach without undue delay and no later than 72 hours after becoming aware of it. Our notification tells you what happened, the categories and approximate number of people affected, the likely consequences, and the steps we are taking. We maintain documented procedures for breach detection, containment and notification.
10. Individual rights and requests We support you in meeting your obligations to the people whose data you hold, including:
  • Subject Access Requests
  • Rectification of inaccurate data
  • Erasure and restriction of processing
  • Objection to processing
  • Data portability, including export in a portable format
  • Data retention and deletion schedules
You also have the right to request information demonstrating our compliance with our agreement with you. We provide reasonable assistance and documentation to support that.
11. What remains your responsibility As the Data Controller, your organisation retains responsibility for:
  • Having a lawful basis for the data you collect, and informing people as required
  • Giving us lawful and clear instructions for processing
  • Keeping the data you hold accurate and up to date
  • Managing your own users, access levels and internal security practices
12. Documents Published: Available on request, normally within two working days:
  • Current Cyber Essentials certificate
  • ICO registration certificate
  • NDPC registration and compliance audit filing acknowledgement
  • PCI DSS SAQ A attestation
  • Responses to your own security or supplier assurance questionnaire
13. Talk to us If you have a question this page does not answer, or you need documentation for a due diligence review, contact hello@mycentreoffice.com. We are happy to speak directly with whoever is responsible for data protection in your organisation.

We review this page whenever our certifications, registrations or service providers change, so that what you read here reflects our current position.