Nabunam
For teachersFor institutions
Pricing
Sign inTry for free

Privacy Policy

Last updated: September 4, 2025

Notice at Collection

We collect categories of personal information (identifiers, contact details, usage data, submitted educational content) to operate and secure the platform, personalize the experience, provide support, produce aggregated metrics, and comply with our legal obligations. Sources: forms, institutional integrations, API, technical logs. Recipients: internal teams (need to know) and vendors (hosting, analytics, messaging, payment, support) under written agreements (section 5).

We do not sell your information. We do not "share" it for cross-context advertising without your explicit choice. Retention periods appear in section 8. To exercise your rights (including "Do Not Sell/Share"), see the Exercise your rights section.

  1. Introduction
  2. Data collected and methods
  3. Purposes and legal bases
  4. Cookies & similar technologies
  5. Sharing & vendors
  6. International transfers
  7. Security
  8. Retention, destruction & anonymization
  9. Automated decisions
  10. Minors
  11. Privacy incidents
  12. Your rights & exercising them
  13. Governance & complaints
  14. Contact (Privacy Officer)
  15. Regional annexes

1. Introduction

Nabunam inc. ("Nabunam," "we") is committed to protecting your privacy. This policy describes how we collect, use, disclose, and protect your personal information when you use our sites and services.

2. Data collected and methods

  • Identity & contact: name, email, institution, role.
  • Usage: educational activities, preferences, technical logs, session identifiers.
  • Content provided: documents, assessments, feedback, messages.

Collection methods: forms, integrations with your institution, API, and technological means (e.g., logs). Identification/location/profiling functions are disabled by default and activated only through your own action.

3. Purposes and legal bases

We process your information to operate and secure the platform, personalize the experience, provide support, produce aggregated measurements (not marketing without consent), and comply with our legal/contractual obligations. In the EU/UK, our legal bases include performance of a contract, legitimate interest (assessed), consent, and compliance with legal obligations.

4. Cookies & similar technologies

We use necessary cookies. Optional analytics cookies are disabled by default and only activated with your consent, which is separate from accepting this Privacy Policy and the Terms of Use.

If you consent, we use Google Analytics 4 to measure visits to public and marketing pages, such as the page viewed, approximate visit time, browser/device information and campaign parameters. We do not configure an authenticated user identifier or Google Signals, and we exclude the authenticated dashboards from this measurement. Google may process this navigation data outside Quebec or Canada under the applicable contractual and privacy safeguards. The retention period is governed by the settings of Nabunam's Google Analytics property and must be verified before Analytics is enabled in production.

You may refuse or withdraw your analytics consent at any time without losing access to the site. Withdrawal stops new analytics events and removes first-party cookies beginning with _ga where technically possible.

5. Sharing & vendors

Internal access limited to a need to know basis. We use vendors (hosting, messaging, analytics, payment, support) under written agreements requiring confidentiality, security, and destruction/return of data at the end of service. Up-to-date list: https://nabunam.com/fournisseurs.

Subject to completion of our privacy assessment and contractual review, Cloudflare may act as a network, security and content-delivery provider. It may process technical information such as IP addresses, requested URLs, protocol, hostname and security headers to protect and deliver approved services. Processing may occur outside Quebec or Canada under the applicable contractual safeguards. Contact our Privacy Officer or consult the vendor page for details. Cloudflare infrastructure security is distinct from optional Google Analytics and from Nabunam's internal MySQL audit logs.

Do not sell/share: we do not sell your information. To limit any cross-context advertising "sharing," use the button below or your browser signal (GPC).

6. International transfers

Your data may be disclosed outside your territory. Before any transfer outside Quebec, we carry out a privacy impact assessment (PIA) and enter into appropriate agreements. For EU→US transfers, we use the EU–US Data Privacy Framework when the vendor is certified, or standard contractual clauses with a supplementary assessment.

7. Security

Proportionate technical and organizational measures: encryption in transit/at rest where relevant, access control, logging, testing, hardening, backups, and an incident response plan.

8. Retention, destruction & anonymization

Retention for the period necessary to fulfill the described purposes and legal/contractual requirements. Secure destruction or irreversible anonymization under the supervision of a qualified person once the purposes are fulfilled.

9. Decisions based exclusively on automated processing

If a decision concerning you is made solely by automated processing, we will inform you and you may submit observations to a person authorized to review the decision.

10. Minors

We do not knowingly collect information from children under 14 without the consent of the holder of parental authority (except for a manifest benefit to the minor).

11. Privacy incidents

In the event of an incident presenting a risk of serious harm, we will notify the competent authority and the affected individuals and record the event in an incident register.

12. Your rights & exercising them

Depending on your place of residence, you may request: access, correction, deletion, portability, withdrawal of consent, restriction/objection, de-indexing, "Do Not Sell/Share," limiting the use of sensitive information, and appeal (USA–Virginia) in the event of refusal.

Or write to us

13. Governance & complaints

We publish governance policies/practices (roles, retention/destruction, training, incident management). To file a complaint, contact the Privacy Officer (details below) or the competent authority of your territory.

14. Contact (Privacy Officer)

Éric B. Zotti – Privacy Officer

info@nabunam.com · +1 (514) 000-0000

710-5455 Av. de Gaspé, Montréal, QC H2T 3B3, Canada

15. Regional annexes

Annex A – Quebec (Law 25)

Law 25 (reforming the Act respecting the protection of personal information in the private sector) imposes specific requirements on businesses established in Quebec or that collect personal information there. This annex explains how Nabunam complies.

1) Scope & definitions

  • Personal information: any information concerning a natural person that allows them to be identified directly or indirectly (including sensitive information).
  • Sensitive information: by its nature (medical, biometric, intimate) or because of the context of use/disclosure, it gives rise to a high expectation of privacy.
  • De-identified/anonymized information: measures to prevent re-identification; obligations to prevent re-identification and control uses.

2) Governance & Privacy Officer

  • Person in charge of the protection of personal information (Privacy Officer): the person with the highest authority is responsible by default; the delegation is published (see the "Contact" section).
  • Policies & practices: documented internal policies (roles, retention/destruction, incidents, subcontracting, rights, annual training); a public summary is available in this policy.
  • Registers: internal registers (incidents, PIAs, transfers, requests/rights).

3) Transparency at collection (mandatory notice)

At the time of collection (especially by technological means), we indicate: the purposes, the means, the categories of persons who will have access (need to know), the categories of recipients, the possibility of disclosure outside Quebec, the retention period, the rights and how to exercise them, as well as, where applicable, the use of identification, location, or profiling.

4) Default privacy settings

  • Our technology products/services are configured to ensure the highest level of privacy by default (e.g., profiling disabled, non-essential cookies inactive until consented to).

5) Identification, location & profiling technologies

  • Clear information and the ability to enable/disable these functions; they are inactive by default.
  • Clear, free, informed, and specific consent for non-necessary uses.

6) Privacy impact assessments (PIAs)

  • Mandatory for any project to acquire, develop, or overhaul an information system/electronic service involving personal information, and before any disclosure outside Quebec.
  • A PIA documents risks, mitigation measures, legal basis/consent, impacts on rights, and decisions.

7) Disclosure of information outside Quebec

  • Before any disclosure, we carry out a specific "transfer" PIA (legal framework of the country, risks, contractual/technical/organizational measures).
  • Disclosure is permitted if protection is adequate and governed by a written agreement (clauses: purposes, measures, incident notification, subcontracting, audits, return/destruction).

8) Contracts with vendors (subcontractors)

  • A written contract requiring: confidentiality, security measures, limited purposes, prohibition on secondary use, incident notification, subcontracting register, audit, return/destruction of data at the end of service.

9) Privacy incidents

  • Maintaining an incident register and assessing the risk of serious harm.
  • Notifications to the CAI and to affected individuals if the risk is serious; mitigation measures and documentation of decisions.

10) Fully automated decisions

  • Information is provided when a decision concerning you is made exclusively by automated processing; you may obtain the main factors and submit observations to a person authorized to review the decision.

11) Individual rights

  • Access/correction (statutory timeline, verified identity).
  • De-indexing/de-listing under certain conditions.
  • Portability of computerized information provided by the individual, in a structured, commonly used format (to the extent provided by law and technically possible).
  • Withdrawal of consent, objection/restriction where applicable.

To exercise your rights, use the "Exercise your rights" section.

12) Retention, destruction & anonymization

  • A retention schedule by purpose; secure destruction or irreversible anonymization once the purposes are achieved.
  • If we use de-identified data, we apply reasonable measures to prevent any re-identification; disclosure is controlled.

13) Minors

  • Consent of the holder of parental authority for children under 14 (except for a clear benefit to the minor).

14) Privacy Officer contact details

See the "Contact (Privacy Officer)" section. The Privacy Officer reports to the highest authority and can be contacted for any question relating to this annex, for incidents, or for rights.

15) Useful links (French-language resources)

  • CAI – Key changes under Law 25
  • CAI – PIA Guide (PDF)
  • Text of the law (private sector)

Annex B – Canada (outside Quebec) – PIPEDA

PIPEDA applies to private-sector organizations that, in Canada, collect, use, or disclose personal information in the course of commercial activities, except where a "substantially similar" provincial law applies (see below). It is built around 10 fair information principles and imposes obligations of transparency, security, and accountability.

1) Principles (operational summary)

  • Accountability: designate a person responsible and implement a privacy management program (policies, procedures, training, vendor oversight).
  • Identifying purposes: clearly state the purposes before or at the time of collection.
  • Valid consent: obtain meaningful consent (see §2) except for exceptions provided by law.
  • Limiting collection: limit to the information necessary for the identified purposes.
  • Limiting use/disclosure/retention: use/disclose only for the stated purposes, for an appropriate period.
  • Accuracy: keep information as accurate, complete, and up to date as necessary.
  • Safeguards: protections proportionate to sensitivity (technical, organizational, physical).
  • Openness: a clear policy explaining practices and contacts.
  • Individual access: allow access and correction upon verified request.
  • Challenging compliance: a mechanism to file an internal complaint and one with the competent authority.

2) "Meaningful" consent

Consent must be informed and meaningful: the individual understands the information collected, the purposes, the consequences of consenting/refusing, the parties with whom information is shared, and their rights. Present information accessibly, at the right time, and provide simple options to accept/decline non-essential uses (e.g., analytics/marketing).

3) Security breaches (real risk of significant harm) & 24-month record

  • Assess any security breach and determine whether there is a real risk of significant harm (RROSH).
  • If a RROSH exists: report to the OPC and notify affected individuals as soon as possible; notify third parties who could help reduce the risk.
  • Keep a record of all breaches (even without a RROSH) for at least 24 months, with the elements required by regulation.

4) Cross-border transfers & vendors

  • A transfer to a vendor for processing is permitted without additional consent if the purpose remains the same, subject to transparent information to the individual and contractual measures (security clauses, purpose limitation, incident notification, controlled subcontracting, return/destruction at the end of the engagement).
  • Clearly disclose the location of processing (country) and any residual risks; maintain reasonable diligence over subcontractors.

5) Individual rights & requests

  • Access & correction: respond within a reasonable time; explain refusals permitted by law; offer an internal appeal mechanism.
  • External complaint: the ability to file a complaint with the Office of the Privacy Commissioner of Canada (OPC) if the response is unsatisfactory.
  • Employment: PIPEDA covers employee information for federally regulated organizations; in AB/BC/QC, private provincial laws cover private-sector employment.

6) "Substantially similar" provincial laws

  • Alberta PIPA, British Columbia PIPA, and Quebec (private sector): deemed "substantially similar." For strictly intraprovincial activities in these provinces, these laws may apply instead of PIPEDA.
  • Health: some provinces (e.g., Ontario, N.B., N.S., N.L.) have health laws deemed similar for health information custodians.

7) Recourse & useful contacts

  • OPC – File a complaint: form and contact details on the official website.
  • Reminder: keep your breach records and compliance programs ready for inspection.

Annex C – California (CCPA/CPRA)

This annex explains Nabunam's compliance with California's CCPA law as amended by the CPRA: notice at collection, consumer rights, mandatory links, the Global Privacy Control (GPC) signal, handling of sensitive information, response timelines, and record-keeping.

1) Notice at Collection

  • At or before collection, we provide a clear notice indicating: categories of data (including categories of sensitive personal information), purposes, whether this data is sold or shared, the retention period for each category (or the criteria used to determine it), a link to the privacy policy and, where applicable, to the sell/share opt-out page.
  • The notice is accessible wherever collection takes place (online, forms, phone, signage, etc.).

2) Links and preferences

  • Do Not Sell or Share My Personal Information: a link available in the footer/menu and in the app, allowing you to opt out of the sale and sharing (cross-context advertising).
  • Limit Use of My Sensitive Personal Information: a separate link where sensitive information is used beyond the limited purposes allowed (e.g., security, providing the requested service).
  • GPC/opt-out preference signals: when a browser sends an opt-out preference signal (e.g., GPC), we treat it as a valid request to opt out of sale/sharing for that browser/device and any associated profile.

3) Consumer rights (CA)

  • Access ("right to know"): categorical information and, upon verified request, specific information (preceding 12 months, unless an extension is permitted).
  • Deletion (with legal exceptions) and Correction of inaccurate information.
  • Opt-out of sale and/or sharing (cross-context advertising); non-discrimination for exercising rights.
  • Limitation of the use/disclosure of sensitive personal information to necessary and proportionate purposes.
  • Timelines: response within 45 days (a 45-day extension possible if necessary, with notice).
  • Verification & authorized agents: requests processed after reasonable verification; a mechanism for requests by an authorized representative.
  • Records: retention for at least 24 months of consumer requests and the responses provided.

4) Minors (under 16)

  • Opt-in required for any sale/sharing: consent of a parent/guardian for those under 13; consent of the minor for ages 13–15.
  • After a refusal (or absence of opt-in), we refrain from selling/sharing the data and observe a waiting period before any new consent request.

5) Vendors / service providers / third parties

  • Transfers to service providers/contractors are governed by contract: limited purposes, security, prohibition on sale/sharing, incident notification, return/destruction at the end of the engagement, controlled subcontracting, cooperation in responding to rights requests.
  • We publish the up-to-date list of vendors and locations on the page referenced in the main section.

6) How to exercise your rights (CA)

  • You can use: our "Exercise your rights" form (main section), the "Do Not Sell or Share" link, the "Limit Use of Sensitive PI" link, or set a GPC signal in your browser.
  • For online-only businesses with a direct consumer relationship, a web form and an email address may be sufficient; otherwise, at least two methods are offered.

Annex D – Colorado (CPA)

The Colorado Privacy Act (CPA) applies to entities (including certain nonprofits) that conduct business in Colorado or target Colorado residents and that: (i) control/process the data of at least 100,000 consumers/year, or (ii) control/process the data of at least 25,000 consumers and derive revenue (or a discount) from the sale of data.

1) Consumer rights

  • Access, portability, correction, deletion.
  • Opt-out of sale, targeted advertising, and profiling leading to decisions with legal or similarly significant effects.
  • Timelines: response within 45 days (extendable by 45 days with notice) and an internal appeal procedure in the event of refusal (response to the appeal within 45 days, extendable).

2) Opt-out & Universal Opt-Out Mechanism (UOOM)

  • Since July 1st, 2024, controllers must automatically recognize UOOM signals (e.g., Global Privacy Control – GPC) for sale and targeted advertising.
  • Provide a clear and visible opt-out link outside the policy (footer/menu) and describe it in the policy.
  • After an opt-out request, cease the relevant processing within 15 days.

3) Sensitive data & minors

  • Prior consent (opt-in) required to process sensitive data (health, biometrics, origin, beliefs, orientation, citizenship status, data of children under 13, etc.).
  • Developments for "minors": the SB 24-041 law strengthens protections (additional requirements for online services presenting an increased risk) — expected to take effect on October 1st, 2025.

4) Data Protection Assessments

  • Mandatory for any processing presenting an increased risk: targeted advertising, sale of data, profiling with significant effects, sensitive data.
  • A real, documented analysis (purposes, necessity, minimization, risks, mitigation measures). Must be made available to the AG on request.

5) Consent & "dark patterns"

  • Consent must be freely given, specific, informed, and unambiguous.
  • Any consent obtained through dark patterns is void: no pre-checked options, symmetrical choices, neutral wording, non-misleading flows.

6) Loyalty programs & disclosures

  • Transparency about benefits and the use of data that is necessary vs. optional. If sensitive data is required, justify the necessity and obtain opt-in.

7) Security, minimization & processors

  • Minimization, purpose limitation, security proportionate to sensitivity, required records.
  • Contracts with processors: limited purposes, security, controlled subcontracting, assistance with rights, return/destruction at the end of the engagement.

8) Profiling with significant effects

  • Provide an opt-out method before or at the time of the relevant profiling, along with clear explanations (logic, human role, data used) if the opt-out is refused in certain cases permitted by the rules.

9) Enforcement & penalties

  • No private right of action: enforcement by the Colorado Attorney General (AG) and District Attorneys.
  • Violations constitute deceptive trade practices: fines of up to $20,000 per violation (aggregate caps may apply depending on case law/statute), injunctions possible.
  • The mandatory "cure" period before AG action expired on January 1st, 2025.

Annex E – Virginia (VCDPA)

The Virginia Consumer Data Protection Act (VCDPA) governs organizations that conduct business in Virginia or target Virginia residents and that, in a given year, (i) control/process the data of at least 100,000 consumers, or (ii) control/process the data of at least 25,000 consumers and derive more than 50% of their gross revenue from the sale of personal data.

1) Consumer rights & timelines

  • Access, correction, deletion, portability.
  • Opt-out of targeted advertising, of sale (in exchange for monetary consideration), and of profiling leading to decisions producing legal or similarly significant effects.
  • Response to requests: 45 days (extendable by 45 days with notice).
  • Appeal in the event of refusal: a simple and accessible procedure; response to the appeal within 60 days, with a written reason and information about the ability to contact the Attorney General.

2) Consent & sensitive data

  • Opt-in required to process sensitive data (e.g., origin, beliefs, health, biometrics, citizenship/immigration status, children's data, precise geolocation). Consent must be freely given, specific, informed, and unambiguous.

3) Notice & transparency

  • A clear and accessible privacy policy stating the categories and purposes, how to exercise rights and file an appeal, as well as clear and conspicuous disclosure if we sell data or engage in targeted advertising, with the opt-out method.
  • Non-discrimination for exercising rights.

4) Opt-out mechanisms & browser signals

  • The VCDPA does not require mandatory recognition of universal opt-out signals (e.g., GPC). We may, however, honor such signals as a best practice and for multi-state harmonization.

5) Data Protection Assessments

  • Mandatory for: targeted advertising, sale of data, risky profiling, sensitive data, and any processing presenting an increased risk. Assessments are documented and available to the Attorney General upon request.

6) Processors

  • Written contracts requiring: limited purposes, security, confidentiality, assistance in exercising rights, audits/assessments, controlled subcontracting, return/destruction at the end of the engagement.

7) Enforcement & penalties

  • Exclusive enforcement by the Attorney General; no private right of action.
  • 30-day cure period before action: if the violation is cured and a written commitment is provided, no action is brought. In the event of no cure/relapse: injunctions and fines of up to $7,500 per violation.

8) How to exercise your rights (VA)

  • Use our "Exercise your rights" form (main section), or write to us. We reasonably verify your identity and accept requests from authorized representatives in accordance with VCDPA requirements.

Annex F – European Union & United Kingdom

This annex explains our compliance with the EU GDPR, the UK GDPR, and ePrivacy rules (including PECR in the UK) for users located in the EU/EEA and the United Kingdom.

1) Information provided under Articles 13/14

  • Identity of the controller: Nabunam inc. (contact details – see the "Contact" section).
  • EU/UK representative (Art. 27): if we target the EU/UK without being established there, we will appoint a representative and publish their contact details here.
  • DPO: if required, we will indicate the appointed DPO (or, failing that, the privacy point of contact).
  • Purposes & legal bases: providing the service (contract), security/fraud prevention (legitimate interest/legal obligation), support (contract/legitimate interest), non-essential analytics (consent), direct electronic marketing (consent or specific local rules), legal obligations (legal obligation).
  • Recipients: internal teams on a "need to know" basis, service providers (hosting, messaging, support, analytics), authorities when required by law.
  • Transfers: see §6.
  • Retention periods: see the main "Retention" section; criteria: duration of the relationship, legal obligations, limitation periods, security and audit needs.
  • Fully automated decisions: if applicable, we inform you, explain the overall logic, and your rights to human intervention and to contest the decision.
  • Source of data (if indirect): partner institution, integrations, technical vendors.
  • Rights: access, rectification, erasure, restriction, portability, objection (including to direct marketing), withdrawal of consent, complaint to a supervisory authority (e.g., CNIL/ICO) – see §5 and §7.

2) Legal bases (operational reminders)

  • Contract: account creation and management, provision of features, support.
  • Legitimate interest (documented balancing test): security, fraud/abuse prevention, non-intrusive improvement, internal aggregated metrics; a right to object may apply.
  • Legal obligation: accounting retention, court orders, regulatory security.
  • Consent: non-essential cookies/trackers, electronic marketing, optional sensitive data; withdrawable at any time as easily as it was given.

3) Cookies & trackers (ePrivacy/PECR)

  • Prior consent for any non-essential tracker (analytics/marketing). Trackers necessary for the requested service may be set without consent.
  • Withdrawal must be as simple as giving consent (e.g., a "Reject All"/"Accept All" button, persistent preferences, permanent access via the "Cookie preferences" link).
  • We do not make access to the essential service conditional on accepting non-essential cookies.

4) Direct marketing & profiling

  • Electronic marketing (email/SMS/push): based on prior consent (with limited national "existing customer" exceptions depending on the state). You may unsubscribe at any time.
  • Objection to marketing: a right to object at any time (Art. 21(2)); if you object, we stop marketing without delay.
  • Profiling for marketing purposes: only with tracker consent or when otherwise based on and permitted by law, with clear information and a right to object.

5) Your rights (EU/UK) & timelines

  • Access, rectification, erasure, restriction, portability, objection (including to marketing).
  • Response within 1 month (may be extended by 2 months for complexity/volume – you will be informed).
  • Withdrawal of consent: does not affect the lawfulness of processing carried out before withdrawal.

6) International transfers

  • EU → United States: we favor vendors certified under the EU-US Data Privacy Framework or use SCCs (Standard Contractual Clauses) with a transfer assessment and supplementary measures if necessary.
  • UK → United States: we use the UK Extension to the DPF (the "US-UK data bridge") or the UK IDTA / the UK Addendum to the EU SCCs, with a transfer impact assessment (TIA).
  • For other third countries: equivalent mechanisms (SCC/IDTA, binding corporate rules if applicable) plus an assessment and technical/organizational measures.

7) Security & breaches

  • Art. 32: proportionate measures (encryption, access control, logging, testing, backups, vulnerability management).
  • Breach notification: to the authority within 72 hours if there is a risk to rights and freedoms; to affected individuals if there is a high risk, along with mitigation measures.

8) DPIA & records (ROPA)

  • DPIA for high-risk processing (e.g., systematic monitoring, new technologies, sensitive data, children).
  • ROPA (records of processing activities) kept up to date for controllers and processors when required.

9) Children

  • Digital age of consent: EU 16 (member states may set 13–16); UK 13. We obtain the consent of the holder of parental authority when required.

10) Processors (Art. 28)

  • Written contracts requiring: limited purposes, confidentiality, security, controlled subcontracting, assistance with rights, audits, return/destruction at the end of the engagement.
  • List of vendors & locations: see the "Vendors" page referenced in the policy.

11) Exercising your rights & recourse

  • Use the "Exercise your rights" form (main section) or write to us ("Contact" details).
  • You may file a complaint with your local supervisory authority (e.g., CNIL in France, AEPD in Spain, Garante in Italy, ICO in the United Kingdom).

If we have not yet published the EU/UK representative or the DPO (as applicable), these contact details will appear here once appointed.

Annex G – South Africa (POPIA)

This annex describes how Nabunam complies with the Protection of Personal Information Act, 2013 ("POPIA") and the regulations/practices of the Information Regulator (South Africa).

1) Scope & principles

  • POPIA applies to responsible parties that process personal information in South Africa. The conditions for lawful processing include accountability, purpose limitation, accuracy, openness, security, and data subject participation.

2) Information Officer (IO) & registration

  • We appoint an Information Officer (and, where applicable, Deputy IOs) and register them with the Information Regulator before they carry out their functions, via the official portal. Contact details appear in our PAIA Manual and in the "Contact" section.
  • Role: compliance program, training, responses to requests/complaints, oversight of breaches and subcontracting agreements.

3) Individual rights

  • Access and correction of data; objection (including to direct marketing by electronic communications); an internal complaint mechanism and the ability to complain to the Information Regulator.

4) Security & breaches (security compromises)

  • Technical and organizational measures proportionate to sensitivity; an obligation to notify the Information Regulator and affected individuals as soon as reasonably possible in the event of a breach posing a risk; maintaining a register and using official forms when required.

5) Cross-border transfers (section 72)

  • A transfer of data to a third country is only permitted if one of the following mechanisms is in place: adequate protection at the recipient, contractual agreements guaranteeing substantially similar protections, the individual's consent, contractual necessity (performance/pre-contractual measures), or a benefit to the individual where consent cannot be obtained promptly.

6) Prior authorisation

  • Mandatory for certain processing, notably: use of unique identifiers for other purposes with cross-organization linkage; transfers to countries without adequate protection; processing of special data or children's data where not otherwise authorized.
  • The processing concerned may only begin after authorization from the Regulator (except for procedural exceptions), following the procedure in sections 57–58.

7) Operators (processors)

  • Written contractual arrangements: limited purposes, confidentiality, security, breach notification, controlled subcontracting, assistance with rights, return/destruction at the end of the engagement.

8) Direct marketing

  • Direct marketing by electronic means: compliant with POPIA and related rules (prior consent or a permitted basis, clear information on the right to object, and a simple opt-out mechanism).

9) How to exercise your rights (ZA)

  • Use our "Exercise your rights" form (main section) or write to us. You may also file a complaint with the Information Regulator if you believe your rights have not been respected.

Annex H – Nigeria (NDPA 2023)

This annex describes our compliance with the Nigeria Data Protection Act, 2023 (NDPA) and the General Application and Implementation Directives (GAID) published by the Nigeria Data Protection Commission (NDPC).

1) Scope & extraterritoriality

  • The NDPA applies to processing carried out in Nigeria, as well as to entities operating in Nigeria or targeting individuals in Nigeria, even if not established in the country.
  • The NDPC may designate data controllers/processors of major importance (DC/PMI) based on volume, data sensitivity, or economic/security impact, with additional obligations (registration, DPO, etc.).

2) Principles & legal bases

  • Principles: fairness/transparency, defined purposes, minimization, accuracy, retention limitation, security, and accountability.
  • Legal bases: consent, contract, legal obligation, vital interests, public interest/authority mandate, legitimate interest (with a balancing test).
  • Consent: active (no pre-checked boxes), clear, withdrawable as easily as given; silence/inactivity ≠ consent.

3) Transparency

  • Before collection, we provide clear information: identity/contact, legal basis and purposes, recipients, duration, rights, the right to complain to the NDPC, and the existence of automated decisions.

4) DPIA (Data Privacy Impact Assessment)

  • A DPIA is mandatory when processing is likely to result in a high risk (nature, scope, context, purposes).
  • If a high risk remains despite the measures taken, prior consultation with the NDPC.

5) Sensitive data & children

  • Processing of sensitive data only on specific grounds (e.g., explicit consent, substantial public interest provided by law, health, legal claims, etc.).
  • For a child or a person unable to legally consent: consent of a parent/guardian and reasonable age-verification mechanisms.

6) Individual rights

  • Being informed, access (copy in a common format), rectification or erasure of inaccurate/outdated data, restriction, withdrawal of consent, objection (including to direct marketing, with immediate effect), not being subject to a decision based solely on automated processing (with rights to human intervention), and portability as set out in NDPC regulations.
  • Response without undue constraint or delay; complaint routes to the NDPC and civil remedies available.

7) Subcontractors & contracts

  • Written agreements requiring: limited purposes, security measures, assistance in exercising rights, notification of any new subcontracting, return/destruction at the end of the engagement, and means of demonstrating compliance.

8) Security & violations

  • Proportionate measures (encryption, resilience, restoration, logging, etc.).
  • Notification to the NDPC within 72 hours after becoming aware of a violation likely to create a risk for individuals; notification to affected individuals without delay in the event of a high risk. Phased notification is possible if necessary; an incident register is maintained.

9) Cross-border transfers

  • Transfers to a third country only if the recipient is subject to adequate protection (law, BCRs, contractual clauses, code of conduct, certification) or if a legal exception applies (consent, contract, public interest, legal claims, vital interests, etc.).
  • Documentation of the transfer's basis; the NDPC may impose additional restrictions for certain categories of data.

10) Registration, DPO & training

  • DC/PMI and DP/PMI entities must register with the NDPC, appoint a competent DPO, and implement a compliance program (policies, initial then annual training, rights procedures, etc.).

11) Enforcement & penalties

  • The NDPC may order corrective measures, compensation, disgorgement of profits, penalties:
  • Maximum "Higher" tier (DC/PMI): ₦10,000,000 or 2 % of annual revenue (whichever is greater). Standard (others): ₦2,000,000 or 2 % of revenue.
  • Failure to comply with an enforcement order: a fine up to the above maximums and/or imprisonment of up to 1 year (depending on the case).

12) How to exercise your rights (NG)

  • Use the "Exercise your rights" form (main section) or write to us. You may also file a complaint with the NDPC if necessary.

Annex I – Kenya (Data Protection Act 2019)

This annex describes our compliance with Kenya's Data Protection Act, 2019 (DPA) and its regulations, under the supervision of the Office of the Data Protection Commissioner (ODPC).

1) Scope & authority

  • The DPA applies to the processing of personal data in Kenya and to processing targeting individuals located in Kenya, even by organizations not established locally.
  • The competent authority is the ODPC (inspections, guidance, complaints, sanctions).

2) Registration with the ODPC

  • Mandatory registration of data controllers and data processors under the Registration Regulations 2021. Organizations not established locally but processing the data of Kenyan residents must also register.
  • Registration covers information about activities, data categories, purposes, and security measures.

3) Principles & legal bases

  • Principles: lawfulness, fairness/transparency, purpose limitation, minimization, accuracy, retention limitation, integrity/confidentiality, accountability.
  • Legal bases: consent, contract, legal obligation, vital interests, public interest/authority mandate, legitimate interest (with a balancing test).

4) DPIA (Data Privacy Impact Assessment)

  • Mandatory for processing likely to result in a high risk (nature, scope, context, purposes – e.g., new technologies, systematic monitoring, sensitive data, children).
  • If a high risk remains, prior consultation with the ODPC.

5) Individual rights

  • Being informed, access, rectification, erasure, objection (incl. direct marketing), and restriction (in prescribed cases). Exercised upon verified identity, with a response without undue delay.
  • A complaint may be filed with the ODPC if unsatisfied.

6) Security & violations

  • Proportionate technical/organizational measures (encryption, access control, logging, testing, continuity).
  • Notification to the ODPC of a violation within 72 hours of becoming aware of it (and to affected individuals without delay in the event of a high risk), with an incident register maintained.

7) Cross-border transfers

  • Transfer permitted to countries/entities offering adequate protection or with appropriate safeguards (e.g., contractual clauses, internal rules, codes/certifications).
  • Absent adequacy/safeguards/necessity, explicit consent is required (with risk information). Special requirements apply to sensitive data.

8) Processors

  • Written contracts requiring: limited purposes, confidentiality, security, controlled subcontracting, assistance with rights, breach notification, return/destruction at the end of the engagement.

9) Children

  • Processing of data of a child (under 18): consent of a parent/guardian and reasonable age verification where required; a DPIA where the risk is high.

10) Enforcement & penalties

  • Corrective measures (warnings, orders), and administrative fines of up to KES 5,000,000 or 1 % of annual revenue in Kenya (whichever is lower), as well as other remedies provided by law.

11) Exercising your rights (KE)

  • Use our "Exercise your rights" form (main section) or write to us. You may also file a complaint with the ODPC.

Annex J – Morocco (Law 09-08)

This annex explains our compliance with Law No. 09-08 on the protection of individuals with regard to the processing of personal data, and its implementing decree. The competent authority is the CNDP (National Commission for the Control of the Protection of Personal Data).

1) Scope & authority

  • Law 09-08 applies to processing carried out in Morocco and to processing targeting individuals in Morocco (including via means located in Morocco).
  • The supervisory authority is the CNDP, responsible for ensuring compliance with the law and issuing receipts/authorizations.

2) CNDP formalities (declaration & authorization)

  • Prior declaration: all processing (except statutory exceptions) must be declared to the CNDP before implementation.
  • Prior authorization (examples): processing of sensitive data (health, opinions, religion, union membership, origin, biometrics/genetics), reuse for different purposes, processing of genetic data (outside care provided by health personnel), etc.
  • The receipt/authorization number may be published in our notices (e.g., "This processing has been authorized by the CNDP under ref. …").

3) International transfers

  • Transfer permitted to a country on the CNDP list (sufficient level of protection) or under conditions (explicit consent, contractual necessity, protection of life/public interest, adequate contractual safeguards, etc.).
  • In practice, the CNDP may require authorization for any transfer: we file the request and attach the safeguards (clauses/BCRs, technical measures).

4) Individual rights

  • Access to one's data, correction of inaccurate/incomplete data, and objection on legitimate grounds (including objection to direct marketing).
  • Procedures: via our "Exercise your rights" section (form/email); a complaint may be filed with the CNDP.

5) Security & confidentiality

  • Technical/organizational measures proportionate to sensitivity: access control, encryption where relevant, logging, testing, business continuity.
  • Contractual oversight of subcontractors: limited purposes, security, confidentiality, controlled subcontracting, assistance with rights, return/destruction at the end of the engagement.

6) Video surveillance (where applicable)

  • Installation subject to prior declaration (CNDP template). For purposes other than the security of property and persons, authorization is required.
  • Information notices, a limited retention period, access restricted to authorized persons.

7) Sanctions & compliance

  • Refusal to grant access/correction/objection may be sanctioned by a fine (ranges set by law). Other breaches (e.g., an undeclared/unauthorized transfer) may be subject to CNDP action.

8) Exercise your rights (MA)

  • Use our "Exercise your rights" form (main section) or write to us. You may also contact the CNDP if necessary.

Annex K – Rwanda (Law n°058/2021)

  • Scope & extraterritoriality: applies to controllers/processors established in Rwanda or outside the country that process the data of individuals located in Rwanda.
  • Mandatory registration (NCSA – Data Protection Office): every controller/processor must register with the supervisory authority before processing data (including foreign entities targeting individuals in Rwanda). A certificate is issued after the file is reviewed.
  • Data Protection Officer (DPO): appointment required where processing is carried out by a legal entity (public/private, across jurisdictions), or in the event of large-scale regular and systematic monitoring, or large-scale processing of special categories/convictions data. An internal or external DPO is possible; a group DPO is permitted; contact details are published and communicated to the authority.
  • Records & logging: maintaining a record of activities (purposes, categories, recipients, transfers outside Rwanda, durations) and logging operations (collection, access, disclosure/transfer, modification, erasure).
  • Legal bases: consent, contract, legal obligation, vital interests, public interest/authority mandate, duty of a public body, legitimate interest, authorized research.
  • Breach notification:
    • notification to the authority within 48 hours of discovery;
    • a detailed report to be submitted within 72 hours (nature, volume, DPO contact, measures, plan to inform individuals);
    • informing individuals "after becoming aware" if the risk is high (exemptions possible where adequate measures are in place).
  • Data storage: storage in Rwanda by default. Storage outside Rwanda requires a certificate authorizing it.
  • Transfers outside Rwanda:
    • authorization from the authority upon proof of appropriate safeguards or in prescribed cases (consent, contract, public interest, defense of rights, vital interests, limited legitimate interests, international instruments);
    • a written contract imposed on the recipient; the authority may suspend/prohibit a transfer.
  • Individual rights (indicative timelines: response within 30 days, appeal to the authority within 30 days, authority decision within 60 days):
    • information & access (copy, origin, recipients, transfers);
    • withdrawal of consent (as easy as giving it);
    • objection (including to direct marketing/profiling), restriction;
    • rectification and erasure (exceptions: public interest, research, legal obligation, legal claims);
    • portability;
    • not being subject to a decision based solely on automated processing producing legal/significant effects (except with consent, contract, or legal basis);
    • representation and designation of an heir for certain data-related prerogatives;
    • children: consent of the holder of parental authority (under 16), except for vital interests.
  • Security: proportionate technical/organizational measures; risk identification, regular verification, updated backups.
  • Sanctions:
    • Administrative: a fine of 2–5 million RWF or 1% of worldwide revenue (for certain violations: failure to register/appoint a DPO, failure to notify/report a violation, etc.).
    • Criminal: imprisonment and fines (e.g., unlawful sale, sensitive data, etc.); for a legal entity, up to 5% of revenue for the preceding fiscal year.
  • Supervisory authority: the National Cyber Security Authority – Data Protection & Privacy Office (NCSA/DPO): registration, breach notification forms, guidance.

Annex L – Egypt (Law No. 151 of 2020)

This annex summarizes the requirements of the Personal Data Protection Law No. 151/2020 (PDPL), under the supervision of the Personal Data Protection Center (an authority under the Ministry of Communications & Information Technology).

1) Scope & extraterritoriality

  • The law applies to electronic processing (in whole or in part) of the personal data of natural persons.
  • Controllers/processors located outside Egypt that target individuals in Egypt must appoint a local representative as set out in the implementing regulations.

2) Individual rights

  • Information & access (including a copy), withdrawal of consent, rectification/update/erasure, restriction, objection if rights/freedoms are affected, breach notifications.
  • Response time for requests: 6 business days (silence = refusal; right to complain to the Center).

3) Legal bases & principles

  • Explicit consent (by default), or contract, legal obligation/court order, legitimate interest (without affecting fundamental rights and freedoms).
  • Collection for legitimate and declared purposes; accuracy; security; no retention beyond what is necessary.

4) Data Protection Officer (DPO)

  • Mandatory appointment (any legal entity acting as a controller/processor) and registration of the DPO with the Center's registry; publication of the appointment.
  • Duties: overseeing compliance, regular audits, point of contact with the Center, handling requests/complaints, maintaining records, training.

5) Data breaches (notifications)

  • Notify the Center within 72 hours of becoming aware (immediately if national security is involved), plus technical information/measures.
  • Inform affected individuals within 3 business days following notification.

6) International transfers & storage

  • Principle: a license/authorization from the Center is required for transfers, with an adequate level of protection required at the recipient.
  • Exceptions are possible (e.g., explicit consent, healthcare, exercise/defense of legal claims, a contract for the individual's benefit, judicial cooperation, public interest, financial transfers, international agreements).

7) Sensitive personal data

  • A license from the Center is required to collect/process/transfer sensitive data, plus explicit written consent (and parental consent for children, if applicable).
  • Enhanced security measures overseen by the DPO.

8) Direct electronic marketing

  • Prohibited without prior consent; clear identification of the sender; a simple opt-out mechanism; proof of consent/non-objection kept for 3 years after the last message sent.

9) Licenses, permits & accreditations

  • The Center issues licenses/permits for: processing/storage, cross-border transfers, direct marketing, sensitive data, certain video surveillance systems, and advisory accreditations.
  • Indicative review period: 90 days from a complete file (otherwise deemed rejected); fee caps set by law.

10) Security & records

  • Appropriate technical/organizational measures; logging of operations; a register of activities (categories, recipients, transfers, measures, erasure).

11) Penalties

  • Administrative (warning, suspension/revocation of license, publication of breaches) and criminal (substantial fines; imprisonment in certain cases).
  • Examples: unlawful refusal of a right (up to EGP 1 million), breach of key obligations (up to EGP 3 million), DPO non-compliance (up to EGP 2 million), sensitive data or unlawful cross-border transfers (up to EGP 5 million and/or imprisonment).

12) Exercise your rights (Egypt)

  • Use our "Exercise your rights" form or write to us ("Contact" details). If unsatisfied, you may file a complaint with the Center.

Annex M – Ghana (Data Protection Act 2012)

This annex summarizes our commitments under Ghana's Data Protection Act, 2012 (Act 843), under the supervision of the Data Protection Commission (DPC).

1) Scope & authority

  • The law applies to controllers who process data in Ghana, and to entities that use means/agents in Ghana to process data (including where the data originates in whole or in part from Ghana).
  • Authority: the Data Protection Commission (DPC).

2) Mandatory registration

  • Every data controller must register with the DPC before processing data, and renew the registration every 2 years.
  • Registration information includes: activities/purposes, data categories, security measures and — where applicable — the countries to which transfers are contemplated.

3) Principles & legal bases

  • Principles: lawfulness, minimality, defined purposes, quality/accuracy, openness, security, data subject participation.
  • Legal bases: consent, contract, legal obligation, vital interests, public interest/authority mandate, legitimate interest. A right to object to processing.

4) Subcontractors & contracts

  • Processing by a data processor only with the controller's authorization/knowledge, confidentiality, and a written contract imposing security measures and notification obligations.

5) Security & violations

  • Reasonable technical/organizational measures: risk analysis, backups, regular checks, continuous updates.
  • In the event of a security breach (unauthorized access/acquisition), notification as soon as reasonably possible to the DPC and to affected individuals; restoring system integrity and, if necessary, publicity on the DPC's instruction.

6) Individual rights

  • Information & access (including source and recipients), rectification, and erasure/destruction of inaccurate, outdated, excessive, or unlawful data.
  • Preventing processing that causes unwarranted harm; opt-out of direct marketing (without prior consent); rights relating to automated decisions; compensation in the event of a breach.

7) Cross-border transfers

  • Transfers possible under appropriate safeguards (contracts, security measures), and to be declared at registration (relevant countries).
  • Where data of foreign individuals is sent to Ghana for processing, we ensure compliance with the applicable law of the country of origin.

8) Internal oversight

  • Appointment of a Data Protection Supervisor where required or recommended by the DPC; overseeing the compliance program, records, and training.

9) Enforcement & penalties

  • Processing without registration or non-compliance with requirements: offenses subject to fines (penalty units) and/or imprisonment depending on severity; the DPC may order corrective measures.

10) Exercise your rights (Ghana)

  • Use our "Exercise your rights" form (main section) or write to us. You may also contact the DPC if necessary.

Annex N – Tunisia (Law n°2004-63)

This annex explains our compliance with Organic Law No. 2004-63 of July 27, 2004 and its implementing texts, under the supervision of the National Authority for the Protection of Personal Data (INPDP).

1) Scope & authority

  • The law applies to processing carried out in Tunisia (public/private sector). Competent authority: the INPDP (oversight, opinions/authorizations, recommendations).

2) Prior procedures

  • Prior declaration to the INPDP before any processing (tacit acceptance if there is no objection within the statutory period).
  • Prior authorization required for certain categories/processing (see §3) and in cases provided for by law/decrees.

3) Sensitive data & specific cases

  • Sensitive categories (racial/genetic origin, religious beliefs, political/philosophical/union opinions, etc.): INPDP authorization mandatory (outside the specific regime for health data).
  • Health data: a dedicated regime (Chapter V) with authorization and enhanced measures set by the INPDP.
  • Video surveillance: subject to prior INPDP authorization.

4) Principles & lawful basis

  • Lawful, defined, and explicit purposes, minimization, accuracy/updating, security/confidentiality, purpose limitation.
  • Consent: express and written except in prescribed cases (vital interest, legal basis, properly framed scientific research, etc.). It is prohibited to unduly condition a service on acceptance of unnecessary uses.
  • Advertising/marketing: use prohibited without express and specific consent (opt-in).

5) Individual rights

  • Information before processing (categories, purposes, recipients, etc.).
  • Access (including a copy), rectification/erasure, restriction (in prescribed cases), objection (including to marketing), and challenging automated decisions with significant effects.

6) Disclosure & international transfers

  • Disclosure to third parties: governed and limited to the stated purposes, with safeguards and, where applicable, agreement/authorization.
  • Transfer abroad: INPDP authorization mandatory before any transfer (including to countries deemed adequate under administrative practice), with information on the destination country, purposes, duration, and security measures.

7) Security & incidents

  • Proportionate technical/organizational measures (access control, logging, backups, confidentiality).
  • The law does not formally provide for a legal procedure for breach notification; we apply best practices and INPDP recommendations.

8) Subcontractors

  • Written contracts requiring: limited purposes, security/confidentiality, controlled subcontracting, assistance in exercising rights, return/destruction at the end of the engagement.

9) Exercise your rights (Tunisia)

  • Use the "Exercise your rights" form (main section) or write to us. You may also contact the INPDP if unsatisfied.
← Back to home
Nabunam

An AI-assisted teaching and learning platform.

Product and solutions

  • For teachers
  • For institutions
  • Pricing
  • Nabunam Academy

Resources and company

  • Resources
  • Free tools
  • Blog
  • Support
  • About us
  • Contact
  • Login

Trust and legal

  • Privacy Policy
  • Terms of Use
  • Security and compliance
  • Vendors
Nabunam inc.5455, av. de Gaspé, suite 710, Montréal, QC H2T 3B3info@nabunam.com

© 2026 Nabunam inc. All rights reserved.

Your privacy choices

Necessary cookies are always active. With your permission, Google Analytics helps us measure use of our public website. Privacy Policy