We collect categories of personal information (identifiers, contact details, usage data, submitted educational content) to operate and secure the platform, personalize the experience, provide support, produce aggregated metrics, and comply with our legal obligations. Sources: forms, institutional integrations, API, technical logs. Recipients: internal teams (need to know) and vendors (hosting, analytics, messaging, payment, support) under written agreements (section 5).
We do not sell your information. We do not "share" it for cross-context advertising without your explicit choice. Retention periods appear in section 8. To exercise your rights (including "Do Not Sell/Share"), see the Exercise your rights section.
1. Introduction
Nabunam inc. ("Nabunam," "we") is committed to protecting your privacy. This policy describes how we collect, use, disclose, and protect your personal information when you use our sites and services.
Collection methods: forms, integrations with your institution, API, and technological means (e.g., logs). Identification/location/profiling functions are disabled by default and activated only through your own action.
3. Purposes and legal bases
We process your information to operate and secure the platform, personalize the experience, provide support, produce aggregated measurements (not marketing without consent), and comply with our legal/contractual obligations. In the EU/UK, our legal bases include performance of a contract, legitimate interest (assessed), consent, and compliance with legal obligations.
4. Cookies & similar technologies
We use necessary cookies. Optional analytics cookies are disabled by default and only activated with your consent, which is separate from accepting this Privacy Policy and the Terms of Use.
If you consent, we use Google Analytics 4 to measure visits to public and marketing pages, such as the page viewed, approximate visit time, browser/device information and campaign parameters. We do not configure an authenticated user identifier or Google Signals, and we exclude the authenticated dashboards from this measurement. Google may process this navigation data outside Quebec or Canada under the applicable contractual and privacy safeguards. The retention period is governed by the settings of Nabunam's Google Analytics property and must be verified before Analytics is enabled in production.
You may refuse or withdraw your analytics consent at any time without losing access to the site. Withdrawal stops new analytics events and removes first-party cookies beginning with _ga where technically possible.
5. Sharing & vendors
Internal access limited to a need to know basis. We use vendors (hosting, messaging, analytics, payment, support) under written agreements requiring confidentiality, security, and destruction/return of data at the end of service. Up-to-date list: https://nabunam.com/fournisseurs.
Subject to completion of our privacy assessment and contractual review, Cloudflare may act as a network, security and content-delivery provider. It may process technical information such as IP addresses, requested URLs, protocol, hostname and security headers to protect and deliver approved services. Processing may occur outside Quebec or Canada under the applicable contractual safeguards. Contact our Privacy Officer or consult the vendor page for details. Cloudflare infrastructure security is distinct from optional Google Analytics and from Nabunam's internal MySQL audit logs.
Do not sell/share: we do not sell your information. To limit any cross-context advertising "sharing," use the button below or your browser signal (GPC).
6. International transfers
Your data may be disclosed outside your territory. Before any transfer outside Quebec, we carry out a privacy impact assessment (PIA) and enter into appropriate agreements. For EU→US transfers, we use the EU–US Data Privacy Framework when the vendor is certified, or standard contractual clauses with a supplementary assessment.
7. Security
Proportionate technical and organizational measures: encryption in transit/at rest where relevant, access control, logging, testing, hardening, backups, and an incident response plan.
8. Retention, destruction & anonymization
Retention for the period necessary to fulfill the described purposes and legal/contractual requirements. Secure destruction or irreversible anonymization under the supervision of a qualified person once the purposes are fulfilled.
9. Decisions based exclusively on automated processing
If a decision concerning you is made solely by automated processing, we will inform you and you may submit observations to a person authorized to review the decision.
10. Minors
We do not knowingly collect information from children under 14 without the consent of the holder of parental authority (except for a manifest benefit to the minor).
11. Privacy incidents
In the event of an incident presenting a risk of serious harm, we will notify the competent authority and the affected individuals and record the event in an incident register.
12. Your rights & exercising them
Depending on your place of residence, you may request: access, correction, deletion, portability, withdrawal of consent, restriction/objection, de-indexing, "Do Not Sell/Share," limiting the use of sensitive information, and appeal (USA–Virginia) in the event of refusal.
13. Governance & complaints
We publish governance policies/practices (roles, retention/destruction, training, incident management). To file a complaint, contact the Privacy Officer (details below) or the competent authority of your territory.
710-5455 Av. de Gaspé, Montréal, QC H2T 3B3, Canada
15. Regional annexes
Annex A – Quebec (Law 25)
Law 25 (reforming the Act respecting the protection of personal information in the private sector) imposes specific requirements on businesses established in Quebec or that collect personal information there. This annex explains how Nabunam complies.
1) Scope & definitions
Personal information: any information concerning a natural person that allows them to be identified directly or indirectly (including sensitive information).
Sensitive information: by its nature (medical, biometric, intimate) or because of the context of use/disclosure, it gives rise to a high expectation of privacy.
De-identified/anonymized information: measures to prevent re-identification; obligations to prevent re-identification and control uses.
2) Governance & Privacy Officer
Person in charge of the protection of personal information (Privacy Officer): the person with the highest authority is responsible by default; the delegation is published (see the "Contact" section).
Policies & practices: documented internal policies (roles, retention/destruction, incidents, subcontracting, rights, annual training); a public summary is available in this policy.
At the time of collection (especially by technological means), we indicate: the purposes, the means, the categories of persons who will have access (need to know), the categories of recipients, the possibility of disclosure outside Quebec, the retention period, the rights and how to exercise them, as well as, where applicable, the use of identification, location, or profiling.
4) Default privacy settings
Our technology products/services are configured to ensure the highest level of privacy by default (e.g., profiling disabled, non-essential cookies inactive until consented to).
Clear information and the ability to enable/disable these functions; they are inactive by default.
Clear, free, informed, and specific consent for non-necessary uses.
6) Privacy impact assessments (PIAs)
Mandatory for any project to acquire, develop, or overhaul an information system/electronic service involving personal information, and before any disclosure outside Quebec.
A PIA documents risks, mitigation measures, legal basis/consent, impacts on rights, and decisions.
7) Disclosure of information outside Quebec
Before any disclosure, we carry out a specific "transfer" PIA (legal framework of the country, risks, contractual/technical/organizational measures).
Disclosure is permitted if protection is adequate and governed by a written agreement (clauses: purposes, measures, incident notification, subcontracting, audits, return/destruction).
8) Contracts with vendors (subcontractors)
A written contract requiring: confidentiality, security measures, limited purposes, prohibition on secondary use, incident notification, subcontracting register, audit, return/destruction of data at the end of service.
9) Privacy incidents
Maintaining an incident register and assessing the risk of serious harm.
Notifications to the CAI and to affected individuals if the risk is serious; mitigation measures and documentation of decisions.
10) Fully automated decisions
Information is provided when a decision concerning you is made exclusively by automated processing; you may obtain the main factors and submit observations to a person authorized to review the decision.
Portability of computerized information provided by the individual, in a structured, commonly used format (to the extent provided by law and technically possible).
Withdrawal of consent, objection/restriction where applicable.
A retention schedule by purpose; secure destruction or irreversible anonymization once the purposes are achieved.
If we use de-identified data, we apply reasonable measures to prevent any re-identification; disclosure is controlled.
13) Minors
Consent of the holder of parental authority for children under 14 (except for a clear benefit to the minor).
14) Privacy Officer contact details
See the "Contact (Privacy Officer)" section. The Privacy Officer reports to the highest authority and can be contacted for any question relating to this annex, for incidents, or for rights.
PIPEDA applies to private-sector organizations that, in Canada, collect, use, or disclose personal information in the course of commercial activities, except where a "substantially similar" provincial law applies (see below). It is built around 10 fair information principles and imposes obligations of transparency, security, and accountability.
1) Principles (operational summary)
Accountability: designate a person responsible and implement a privacy management program (policies, procedures, training, vendor oversight).
Identifying purposes: clearly state the purposes before or at the time of collection.
Valid consent: obtain meaningful consent (see §2) except for exceptions provided by law.
Limiting collection: limit to the information necessary for the identified purposes.
Limiting use/disclosure/retention: use/disclose only for the stated purposes, for an appropriate period.
Accuracy: keep information as accurate, complete, and up to date as necessary.
Safeguards: protections proportionate to sensitivity (technical, organizational, physical).
Openness: a clear policy explaining practices and contacts.
Individual access: allow access and correction upon verified request.
Challenging compliance: a mechanism to file an internal complaint and one with the competent authority.
2) "Meaningful" consent
Consent must be informed and meaningful: the individual understands the information collected, the purposes, the consequences of consenting/refusing, the parties with whom information is shared, and their rights. Present information accessibly, at the right time, and provide simple options to accept/decline non-essential uses (e.g., analytics/marketing).
3) Security breaches (real risk of significant harm) & 24-month record
Assess any security breach and determine whether there is a real risk of significant harm (RROSH).
If a RROSH exists: report to the OPC and notify affected individuals as soon as possible; notify third parties who could help reduce the risk.
Keep a record of all breaches (even without a RROSH) for at least 24 months, with the elements required by regulation.
4) Cross-border transfers & vendors
A transfer to a vendor for processing is permitted without additional consent if the purpose remains the same, subject to transparent information to the individual and contractual measures (security clauses, purpose limitation, incident notification, controlled subcontracting, return/destruction at the end of the engagement).
Clearly disclose the location of processing (country) and any residual risks; maintain reasonable diligence over subcontractors.
5) Individual rights & requests
Access & correction: respond within a reasonable time; explain refusals permitted by law; offer an internal appeal mechanism.
External complaint: the ability to file a complaint with the Office of the Privacy Commissioner of Canada (OPC) if the response is unsatisfactory.
Employment: PIPEDA covers employee information for federally regulated organizations; in AB/BC/QC, private provincial laws cover private-sector employment.
6) "Substantially similar" provincial laws
Alberta PIPA, British Columbia PIPA, and Quebec (private sector): deemed "substantially similar." For strictly intraprovincial activities in these provinces, these laws may apply instead of PIPEDA.
Health: some provinces (e.g., Ontario, N.B., N.S., N.L.) have health laws deemed similar for health information custodians.
7) Recourse & useful contacts
OPC – File a complaint: form and contact details on the official website.
Reminder: keep your breach records and compliance programs ready for inspection.
Annex C – California (CCPA/CPRA)
This annex explains Nabunam's compliance with California's CCPA law as amended by the CPRA: notice at collection, consumer rights, mandatory links, the Global Privacy Control (GPC) signal, handling of sensitive information, response timelines, and record-keeping.
1) Notice at Collection
At or before collection, we provide a clear notice indicating: categories of data (including categories of sensitive personal information), purposes, whether this data is sold or shared, the retention period for each category (or the criteria used to determine it), a link to the privacy policy and, where applicable, to the sell/share opt-out page.
The notice is accessible wherever collection takes place (online, forms, phone, signage, etc.).
2) Links and preferences
Do Not Sell or Share My Personal Information: a link available in the footer/menu and in the app, allowing you to opt out of the sale and sharing (cross-context advertising).
Limit Use of My Sensitive Personal Information: a separate link where sensitive information is used beyond the limited purposes allowed (e.g., security, providing the requested service).
GPC/opt-out preference signals: when a browser sends an opt-out preference signal (e.g., GPC), we treat it as a valid request to opt out of sale/sharing for that browser/device and any associated profile.
3) Consumer rights (CA)
Access ("right to know"): categorical information and, upon verified request, specific information (preceding 12 months, unless an extension is permitted).
Deletion (with legal exceptions) and Correction of inaccurate information.
Opt-out of sale and/or sharing (cross-context advertising); non-discrimination for exercising rights.
Limitation of the use/disclosure of sensitive personal information to necessary and proportionate purposes.
Timelines: response within 45 days (a 45-day extension possible if necessary, with notice).
Verification & authorized agents: requests processed after reasonable verification; a mechanism for requests by an authorized representative.
Records: retention for at least 24 months of consumer requests and the responses provided.
4) Minors (under 16)
Opt-in required for any sale/sharing: consent of a parent/guardian for those under 13; consent of the minor for ages 13–15.
After a refusal (or absence of opt-in), we refrain from selling/sharing the data and observe a waiting period before any new consent request.
5) Vendors / service providers / third parties
Transfers to service providers/contractors are governed by contract: limited purposes, security, prohibition on sale/sharing, incident notification, return/destruction at the end of the engagement, controlled subcontracting, cooperation in responding to rights requests.
We publish the up-to-date list of vendors and locations on the page referenced in the main section.
6) How to exercise your rights (CA)
You can use: our "Exercise your rights" form (main section), the "Do Not Sell or Share" link, the "Limit Use of Sensitive PI" link, or set a GPC signal in your browser.
For online-only businesses with a direct consumer relationship, a web form and an email address may be sufficient; otherwise, at least two methods are offered.
Annex D – Colorado (CPA)
The Colorado Privacy Act (CPA) applies to entities (including certain nonprofits) that conduct business in Colorado or target Colorado residents and that: (i) control/process the data of at least 100,000 consumers/year, or (ii) control/process the data of at least 25,000 consumers and derive revenue (or a discount) from the sale of data.
1) Consumer rights
Access, portability, correction, deletion.
Opt-out of sale, targeted advertising, and profiling leading to decisions with legal or similarly significant effects.
Timelines: response within 45 days (extendable by 45 days with notice) and an internal appeal procedure in the event of refusal (response to the appeal within 45 days, extendable).
2) Opt-out & Universal Opt-Out Mechanism (UOOM)
Since July 1st, 2024, controllers must automatically recognize UOOM signals (e.g., Global Privacy Control – GPC) for sale and targeted advertising.
Provide a clear and visible opt-out link outside the policy (footer/menu) and describe it in the policy.
After an opt-out request, cease the relevant processing within 15 days.
3) Sensitive data & minors
Prior consent (opt-in) required to process sensitive data (health, biometrics, origin, beliefs, orientation, citizenship status, data of children under 13, etc.).
Developments for "minors": the SB 24-041 law strengthens protections (additional requirements for online services presenting an increased risk) — expected to take effect on October 1st, 2025.
4) Data Protection Assessments
Mandatory for any processing presenting an increased risk: targeted advertising, sale of data, profiling with significant effects, sensitive data.
A real, documented analysis (purposes, necessity, minimization, risks, mitigation measures). Must be made available to the AG on request.
5) Consent & "dark patterns"
Consent must be freely given, specific, informed, and unambiguous.
Any consent obtained through dark patterns is void: no pre-checked options, symmetrical choices, neutral wording, non-misleading flows.
6) Loyalty programs & disclosures
Transparency about benefits and the use of data that is necessary vs. optional. If sensitive data is required, justify the necessity and obtain opt-in.
7) Security, minimization & processors
Minimization, purpose limitation, security proportionate to sensitivity, required records.
Contracts with processors: limited purposes, security, controlled subcontracting, assistance with rights, return/destruction at the end of the engagement.
8) Profiling with significant effects
Provide an opt-out method before or at the time of the relevant profiling, along with clear explanations (logic, human role, data used) if the opt-out is refused in certain cases permitted by the rules.
9) Enforcement & penalties
No private right of action: enforcement by the Colorado Attorney General (AG) and District Attorneys.
Violations constitute deceptive trade practices: fines of up to $20,000 per violation (aggregate caps may apply depending on case law/statute), injunctions possible.
The mandatory "cure" period before AG action expired on January 1st, 2025.
Annex E – Virginia (VCDPA)
The Virginia Consumer Data Protection Act (VCDPA) governs organizations that conduct business in Virginia or target Virginia residents and that, in a given year, (i) control/process the data of at least 100,000 consumers, or (ii) control/process the data of at least 25,000 consumers and derive more than 50% of their gross revenue from the sale of personal data.
1) Consumer rights & timelines
Access, correction, deletion, portability.
Opt-out of targeted advertising, of sale (in exchange for monetary consideration), and of profiling leading to decisions producing legal or similarly significant effects.
Response to requests: 45 days (extendable by 45 days with notice).
Appeal in the event of refusal: a simple and accessible procedure; response to the appeal within 60 days, with a written reason and information about the ability to contact the Attorney General.
2) Consent & sensitive data
Opt-in required to process sensitive data (e.g., origin, beliefs, health, biometrics, citizenship/immigration status, children's data, precise geolocation). Consent must be freely given, specific, informed, and unambiguous.
3) Notice & transparency
A clear and accessible privacy policy stating the categories and purposes, how to exercise rights and file an appeal, as well as clear and conspicuous disclosure if we sell data or engage in targeted advertising, with the opt-out method.
Non-discrimination for exercising rights.
4) Opt-out mechanisms & browser signals
The VCDPA does not require mandatory recognition of universal opt-out signals (e.g., GPC). We may, however, honor such signals as a best practice and for multi-state harmonization.
5) Data Protection Assessments
Mandatory for: targeted advertising, sale of data, risky profiling, sensitive data, and any processing presenting an increased risk. Assessments are documented and available to the Attorney General upon request.
6) Processors
Written contracts requiring: limited purposes, security, confidentiality, assistance in exercising rights, audits/assessments, controlled subcontracting, return/destruction at the end of the engagement.
7) Enforcement & penalties
Exclusive enforcement by the Attorney General; no private right of action.
30-day cure period before action: if the violation is cured and a written commitment is provided, no action is brought. In the event of no cure/relapse: injunctions and fines of up to $7,500 per violation.
8) How to exercise your rights (VA)
Use our "Exercise your rights" form (main section), or write to us. We reasonably verify your identity and accept requests from authorized representatives in accordance with VCDPA requirements.
Annex F – European Union & United Kingdom
This annex explains our compliance with the EU GDPR, the UK GDPR, and ePrivacy rules (including PECR in the UK) for users located in the EU/EEA and the United Kingdom.
1) Information provided under Articles 13/14
Identity of the controller: Nabunam inc. (contact details – see the "Contact" section).
EU/UK representative (Art. 27): if we target the EU/UK without being established there, we will appoint a representative and publish their contact details here.
DPO: if required, we will indicate the appointed DPO (or, failing that, the privacy point of contact).
Purposes & legal bases: providing the service (contract), security/fraud prevention (legitimate interest/legal obligation), support (contract/legitimate interest), non-essential analytics (consent), direct electronic marketing (consent or specific local rules), legal obligations (legal obligation).
Recipients: internal teams on a "need to know" basis, service providers (hosting, messaging, support, analytics), authorities when required by law.
Transfers: see §6.
Retention periods: see the main "Retention" section; criteria: duration of the relationship, legal obligations, limitation periods, security and audit needs.
Fully automated decisions: if applicable, we inform you, explain the overall logic, and your rights to human intervention and to contest the decision.
Source of data (if indirect): partner institution, integrations, technical vendors.
Rights: access, rectification, erasure, restriction, portability, objection (including to direct marketing), withdrawal of consent, complaint to a supervisory authority (e.g., CNIL/ICO) – see §5 and §7.
2) Legal bases (operational reminders)
Contract: account creation and management, provision of features, support.
Legitimate interest (documented balancing test): security, fraud/abuse prevention, non-intrusive improvement, internal aggregated metrics; a right to object may apply.
Consent: non-essential cookies/trackers, electronic marketing, optional sensitive data; withdrawable at any time as easily as it was given.
3) Cookies & trackers (ePrivacy/PECR)
Prior consent for any non-essential tracker (analytics/marketing). Trackers necessary for the requested service may be set without consent.
Withdrawal must be as simple as giving consent (e.g., a "Reject All"/"Accept All" button, persistent preferences, permanent access via the "Cookie preferences" link).
We do not make access to the essential service conditional on accepting non-essential cookies.
4) Direct marketing & profiling
Electronic marketing (email/SMS/push): based on prior consent (with limited national "existing customer" exceptions depending on the state). You may unsubscribe at any time.
Objection to marketing: a right to object at any time (Art. 21(2)); if you object, we stop marketing without delay.
Profiling for marketing purposes: only with tracker consent or when otherwise based on and permitted by law, with clear information and a right to object.
5) Your rights (EU/UK) & timelines
Access, rectification, erasure, restriction, portability, objection (including to marketing).
Response within 1 month (may be extended by 2 months for complexity/volume – you will be informed).
Withdrawal of consent: does not affect the lawfulness of processing carried out before withdrawal.
6) International transfers
EU → United States: we favor vendors certified under the EU-US Data Privacy Framework or use SCCs (Standard Contractual Clauses) with a transfer assessment and supplementary measures if necessary.
UK → United States: we use the UK Extension to the DPF (the "US-UK data bridge") or the UK IDTA / the UK Addendum to the EU SCCs, with a transfer impact assessment (TIA).
For other third countries: equivalent mechanisms (SCC/IDTA, binding corporate rules if applicable) plus an assessment and technical/organizational measures.
Breach notification: to the authority within 72 hours if there is a risk to rights and freedoms; to affected individuals if there is a high risk, along with mitigation measures.
8) DPIA & records (ROPA)
DPIA for high-risk processing (e.g., systematic monitoring, new technologies, sensitive data, children).
ROPA (records of processing activities) kept up to date for controllers and processors when required.
9) Children
Digital age of consent: EU 16 (member states may set 13–16); UK 13. We obtain the consent of the holder of parental authority when required.
10) Processors (Art. 28)
Written contracts requiring: limited purposes, confidentiality, security, controlled subcontracting, assistance with rights, audits, return/destruction at the end of the engagement.
List of vendors & locations: see the "Vendors" page referenced in the policy.
11) Exercising your rights & recourse
Use the "Exercise your rights" form (main section) or write to us ("Contact" details).
You may file a complaint with your local supervisory authority (e.g., CNIL in France, AEPD in Spain, Garante in Italy, ICO in the United Kingdom).
If we have not yet published the EU/UK representative or the DPO (as applicable), these contact details will appear here once appointed.
Annex G – South Africa (POPIA)
This annex describes how Nabunam complies with the Protection of Personal Information Act, 2013 ("POPIA") and the regulations/practices of the Information Regulator (South Africa).
1) Scope & principles
POPIA applies to responsible parties that process personal information in South Africa. The conditions for lawful processing include accountability, purpose limitation, accuracy, openness, security, and data subject participation.
2) Information Officer (IO) & registration
We appoint an Information Officer (and, where applicable, Deputy IOs) and register them with the Information Regulator before they carry out their functions, via the official portal. Contact details appear in our PAIA Manual and in the "Contact" section.
Role: compliance program, training, responses to requests/complaints, oversight of breaches and subcontracting agreements.
3) Individual rights
Access and correction of data; objection (including to direct marketing by electronic communications); an internal complaint mechanism and the ability to complain to the Information Regulator.
4) Security & breaches (security compromises)
Technical and organizational measures proportionate to sensitivity; an obligation to notify the Information Regulator and affected individuals as soon as reasonably possible in the event of a breach posing a risk; maintaining a register and using official forms when required.
5) Cross-border transfers (section 72)
A transfer of data to a third country is only permitted if one of the following mechanisms is in place: adequate protection at the recipient, contractual agreements guaranteeing substantially similar protections, the individual's consent, contractual necessity (performance/pre-contractual measures), or a benefit to the individual where consent cannot be obtained promptly.
6) Prior authorisation
Mandatory for certain processing, notably: use of unique identifiers for other purposes with cross-organization linkage; transfers to countries without adequate protection; processing of special data or children's data where not otherwise authorized.
The processing concerned may only begin after authorization from the Regulator (except for procedural exceptions), following the procedure in sections 57–58.
7) Operators (processors)
Written contractual arrangements: limited purposes, confidentiality, security, breach notification, controlled subcontracting, assistance with rights, return/destruction at the end of the engagement.
8) Direct marketing
Direct marketing by electronic means: compliant with POPIA and related rules (prior consent or a permitted basis, clear information on the right to object, and a simple opt-out mechanism).
9) How to exercise your rights (ZA)
Use our "Exercise your rights" form (main section) or write to us. You may also file a complaint with the Information Regulator if you believe your rights have not been respected.
Annex H – Nigeria (NDPA 2023)
This annex describes our compliance with the Nigeria Data Protection Act, 2023 (NDPA) and the General Application and Implementation Directives (GAID) published by the Nigeria Data Protection Commission (NDPC).
1) Scope & extraterritoriality
The NDPA applies to processing carried out in Nigeria, as well as to entities operating in Nigeria or targeting individuals in Nigeria, even if not established in the country.
The NDPC may designate data controllers/processors of major importance (DC/PMI) based on volume, data sensitivity, or economic/security impact, with additional obligations (registration, DPO, etc.).
2) Principles & legal bases
Principles: fairness/transparency, defined purposes, minimization, accuracy, retention limitation, security, and accountability.
Legal bases: consent, contract, legal obligation, vital interests, public interest/authority mandate, legitimate interest (with a balancing test).
Consent: active (no pre-checked boxes), clear, withdrawable as easily as given; silence/inactivity ≠ consent.
3) Transparency
Before collection, we provide clear information: identity/contact, legal basis and purposes, recipients, duration, rights, the right to complain to the NDPC, and the existence of automated decisions.
4) DPIA (Data Privacy Impact Assessment)
A DPIA is mandatory when processing is likely to result in a high risk (nature, scope, context, purposes).
If a high risk remains despite the measures taken, prior consultation with the NDPC.
5) Sensitive data & children
Processing of sensitive data only on specific grounds (e.g., explicit consent, substantial public interest provided by law, health, legal claims, etc.).
For a child or a person unable to legally consent: consent of a parent/guardian and reasonable age-verification mechanisms.
6) Individual rights
Being informed, access (copy in a common format), rectification or erasure of inaccurate/outdated data, restriction, withdrawal of consent, objection (including to direct marketing, with immediate effect), not being subject to a decision based solely on automated processing (with rights to human intervention), and portability as set out in NDPC regulations.
Response without undue constraint or delay; complaint routes to the NDPC and civil remedies available.
7) Subcontractors & contracts
Written agreements requiring: limited purposes, security measures, assistance in exercising rights, notification of any new subcontracting, return/destruction at the end of the engagement, and means of demonstrating compliance.
Notification to the NDPC within 72 hours after becoming aware of a violation likely to create a risk for individuals; notification to affected individuals without delay in the event of a high risk. Phased notification is possible if necessary; an incident register is maintained.
9) Cross-border transfers
Transfers to a third country only if the recipient is subject to adequate protection (law, BCRs, contractual clauses, code of conduct, certification) or if a legal exception applies (consent, contract, public interest, legal claims, vital interests, etc.).
Documentation of the transfer's basis; the NDPC may impose additional restrictions for certain categories of data.
10) Registration, DPO & training
DC/PMI and DP/PMI entities must register with the NDPC, appoint a competent DPO, and implement a compliance program (policies, initial then annual training, rights procedures, etc.).
11) Enforcement & penalties
The NDPC may order corrective measures, compensation, disgorgement of profits, penalties:
Maximum "Higher" tier (DC/PMI): ₦10,000,000 or 2 % of annual revenue (whichever is greater). Standard (others): ₦2,000,000 or 2 % of revenue.
Failure to comply with an enforcement order: a fine up to the above maximums and/or imprisonment of up to 1 year (depending on the case).
12) How to exercise your rights (NG)
Use the "Exercise your rights" form (main section) or write to us. You may also file a complaint with the NDPC if necessary.
Annex I – Kenya (Data Protection Act 2019)
This annex describes our compliance with Kenya's Data Protection Act, 2019 (DPA) and its regulations, under the supervision of the Office of the Data Protection Commissioner (ODPC).
1) Scope & authority
The DPA applies to the processing of personal data in Kenya and to processing targeting individuals located in Kenya, even by organizations not established locally.
The competent authority is the ODPC (inspections, guidance, complaints, sanctions).
2) Registration with the ODPC
Mandatory registration of data controllers and data processors under the Registration Regulations 2021. Organizations not established locally but processing the data of Kenyan residents must also register.
Registration covers information about activities, data categories, purposes, and security measures.
Legal bases: consent, contract, legal obligation, vital interests, public interest/authority mandate, legitimate interest (with a balancing test).
4) DPIA (Data Privacy Impact Assessment)
Mandatory for processing likely to result in a high risk (nature, scope, context, purposes – e.g., new technologies, systematic monitoring, sensitive data, children).
If a high risk remains, prior consultation with the ODPC.
5) Individual rights
Being informed, access, rectification, erasure, objection (incl. direct marketing), and restriction (in prescribed cases). Exercised upon verified identity, with a response without undue delay.
A complaint may be filed with the ODPC if unsatisfied.
Notification to the ODPC of a violation within 72 hours of becoming aware of it (and to affected individuals without delay in the event of a high risk), with an incident register maintained.
7) Cross-border transfers
Transfer permitted to countries/entities offering adequate protection or with appropriate safeguards (e.g., contractual clauses, internal rules, codes/certifications).
Absent adequacy/safeguards/necessity, explicit consent is required (with risk information). Special requirements apply to sensitive data.
8) Processors
Written contracts requiring: limited purposes, confidentiality, security, controlled subcontracting, assistance with rights, breach notification, return/destruction at the end of the engagement.
9) Children
Processing of data of a child (under 18): consent of a parent/guardian and reasonable age verification where required; a DPIA where the risk is high.
10) Enforcement & penalties
Corrective measures (warnings, orders), and administrative fines of up to KES 5,000,000 or 1 % of annual revenue in Kenya (whichever is lower), as well as other remedies provided by law.
11) Exercising your rights (KE)
Use our "Exercise your rights" form (main section) or write to us. You may also file a complaint with the ODPC.
Annex J – Morocco (Law 09-08)
This annex explains our compliance with Law No. 09-08 on the protection of individuals with regard to the processing of personal data, and its implementing decree. The competent authority is the CNDP (National Commission for the Control of the Protection of Personal Data).
1) Scope & authority
Law 09-08 applies to processing carried out in Morocco and to processing targeting individuals in Morocco (including via means located in Morocco).
The supervisory authority is the CNDP, responsible for ensuring compliance with the law and issuing receipts/authorizations.
2) CNDP formalities (declaration & authorization)
Prior declaration: all processing (except statutory exceptions) must be declared to the CNDP before implementation.
Prior authorization (examples): processing of sensitive data (health, opinions, religion, union membership, origin, biometrics/genetics), reuse for different purposes, processing of genetic data (outside care provided by health personnel), etc.
The receipt/authorization number may be published in our notices (e.g., "This processing has been authorized by the CNDP under ref. …").
3) International transfers
Transfer permitted to a country on the CNDP list (sufficient level of protection) or under conditions (explicit consent, contractual necessity, protection of life/public interest, adequate contractual safeguards, etc.).
In practice, the CNDP may require authorization for any transfer: we file the request and attach the safeguards (clauses/BCRs, technical measures).
4) Individual rights
Access to one's data, correction of inaccurate/incomplete data, and objection on legitimate grounds (including objection to direct marketing).
Procedures: via our "Exercise your rights" section (form/email); a complaint may be filed with the CNDP.
5) Security & confidentiality
Technical/organizational measures proportionate to sensitivity: access control, encryption where relevant, logging, testing, business continuity.
Contractual oversight of subcontractors: limited purposes, security, confidentiality, controlled subcontracting, assistance with rights, return/destruction at the end of the engagement.
6) Video surveillance (where applicable)
Installation subject to prior declaration (CNDP template). For purposes other than the security of property and persons, authorization is required.
Information notices, a limited retention period, access restricted to authorized persons.
7) Sanctions & compliance
Refusal to grant access/correction/objection may be sanctioned by a fine (ranges set by law). Other breaches (e.g., an undeclared/unauthorized transfer) may be subject to CNDP action.
8) Exercise your rights (MA)
Use our "Exercise your rights" form (main section) or write to us. You may also contact the CNDP if necessary.
Annex K – Rwanda (Law n°058/2021)
Scope & extraterritoriality: applies to controllers/processors established in Rwanda or outside the country that process the data of individuals located in Rwanda.
Mandatory registration (NCSA – Data Protection Office): every controller/processor must register with the supervisory authority before processing data (including foreign entities targeting individuals in Rwanda). A certificate is issued after the file is reviewed.
Data Protection Officer (DPO): appointment required where processing is carried out by a legal entity (public/private, across jurisdictions), or in the event of large-scale regular and systematic monitoring, or large-scale processing of special categories/convictions data. An internal or external DPO is possible; a group DPO is permitted; contact details are published and communicated to the authority.
Records & logging: maintaining a record of activities (purposes, categories, recipients, transfers outside Rwanda, durations) and logging operations (collection, access, disclosure/transfer, modification, erasure).
Legal bases: consent, contract, legal obligation, vital interests, public interest/authority mandate, duty of a public body, legitimate interest, authorized research.
Breach notification:
notification to the authority within 48 hours of discovery;
a detailed report to be submitted within 72 hours (nature, volume, DPO contact, measures, plan to inform individuals);
informing individuals "after becoming aware" if the risk is high (exemptions possible where adequate measures are in place).
Data storage: storage in Rwanda by default. Storage outside Rwanda requires a certificate authorizing it.
Transfers outside Rwanda:
authorization from the authority upon proof of appropriate safeguards or in prescribed cases (consent, contract, public interest, defense of rights, vital interests, limited legitimate interests, international instruments);
a written contract imposed on the recipient; the authority may suspend/prohibit a transfer.
Individual rights (indicative timelines: response within 30 days, appeal to the authority within 30 days, authority decision within 60 days):
information & access (copy, origin, recipients, transfers);
withdrawal of consent (as easy as giving it);
objection (including to direct marketing/profiling), restriction;
rectification and erasure (exceptions: public interest, research, legal obligation, legal claims);
portability;
not being subject to a decision based solely on automated processing producing legal/significant effects (except with consent, contract, or legal basis);
representation and designation of an heir for certain data-related prerogatives;
children: consent of the holder of parental authority (under 16), except for vital interests.
Administrative: a fine of 2–5 million RWF or 1% of worldwide revenue (for certain violations: failure to register/appoint a DPO, failure to notify/report a violation, etc.).
Criminal: imprisonment and fines (e.g., unlawful sale, sensitive data, etc.); for a legal entity, up to 5% of revenue for the preceding fiscal year.
Supervisory authority: the National Cyber Security Authority – Data Protection & Privacy Office (NCSA/DPO): registration, breach notification forms, guidance.
Annex L – Egypt (Law No. 151 of 2020)
This annex summarizes the requirements of the Personal Data Protection Law No. 151/2020 (PDPL), under the supervision of the Personal Data Protection Center (an authority under the Ministry of Communications & Information Technology).
1) Scope & extraterritoriality
The law applies to electronic processing (in whole or in part) of the personal data of natural persons.
Controllers/processors located outside Egypt that target individuals in Egypt must appoint a local representative as set out in the implementing regulations.
2) Individual rights
Information & access (including a copy), withdrawal of consent, rectification/update/erasure, restriction, objection if rights/freedoms are affected, breach notifications.
Response time for requests: 6 business days (silence = refusal; right to complain to the Center).
3) Legal bases & principles
Explicit consent (by default), or contract, legal obligation/court order, legitimate interest (without affecting fundamental rights and freedoms).
Collection for legitimate and declared purposes; accuracy; security; no retention beyond what is necessary.
4) Data Protection Officer (DPO)
Mandatory appointment (any legal entity acting as a controller/processor) and registration of the DPO with the Center's registry; publication of the appointment.
Duties: overseeing compliance, regular audits, point of contact with the Center, handling requests/complaints, maintaining records, training.
5) Data breaches (notifications)
Notify the Center within 72 hours of becoming aware (immediately if national security is involved), plus technical information/measures.
Inform affected individuals within 3 business days following notification.
6) International transfers & storage
Principle: a license/authorization from the Center is required for transfers, with an adequate level of protection required at the recipient.
Exceptions are possible (e.g., explicit consent, healthcare, exercise/defense of legal claims, a contract for the individual's benefit, judicial cooperation, public interest, financial transfers, international agreements).
7) Sensitive personal data
A license from the Center is required to collect/process/transfer sensitive data, plus explicit written consent (and parental consent for children, if applicable).
Enhanced security measures overseen by the DPO.
8) Direct electronic marketing
Prohibited without prior consent; clear identification of the sender; a simple opt-out mechanism; proof of consent/non-objection kept for 3 years after the last message sent.
9) Licenses, permits & accreditations
The Center issues licenses/permits for: processing/storage, cross-border transfers, direct marketing, sensitive data, certain video surveillance systems, and advisory accreditations.
Indicative review period: 90 days from a complete file (otherwise deemed rejected); fee caps set by law.
10) Security & records
Appropriate technical/organizational measures; logging of operations; a register of activities (categories, recipients, transfers, measures, erasure).
11) Penalties
Administrative (warning, suspension/revocation of license, publication of breaches) and criminal (substantial fines; imprisonment in certain cases).
Examples: unlawful refusal of a right (up to EGP 1 million), breach of key obligations (up to EGP 3 million), DPO non-compliance (up to EGP 2 million), sensitive data or unlawful cross-border transfers (up to EGP 5 million and/or imprisonment).
12) Exercise your rights (Egypt)
Use our "Exercise your rights" form or write to us ("Contact" details). If unsatisfied, you may file a complaint with the Center.
Annex M – Ghana (Data Protection Act 2012)
This annex summarizes our commitments under Ghana's Data Protection Act, 2012 (Act 843), under the supervision of the Data Protection Commission (DPC).
1) Scope & authority
The law applies to controllers who process data in Ghana, and to entities that use means/agents in Ghana to process data (including where the data originates in whole or in part from Ghana).
Authority: the Data Protection Commission (DPC).
2) Mandatory registration
Every data controller must register with the DPC before processing data, and renew the registration every 2 years.
Registration information includes: activities/purposes, data categories, security measures and — where applicable — the countries to which transfers are contemplated.
3) Principles & legal bases
Principles: lawfulness, minimality, defined purposes, quality/accuracy, openness, security, data subject participation.
Legal bases: consent, contract, legal obligation, vital interests, public interest/authority mandate, legitimate interest. A right to object to processing.
4) Subcontractors & contracts
Processing by a data processor only with the controller's authorization/knowledge, confidentiality, and a written contract imposing security measures and notification obligations.
In the event of a security breach (unauthorized access/acquisition), notification as soon as reasonably possible to the DPC and to affected individuals; restoring system integrity and, if necessary, publicity on the DPC's instruction.
6) Individual rights
Information & access (including source and recipients), rectification, and erasure/destruction of inaccurate, outdated, excessive, or unlawful data.
Preventing processing that causes unwarranted harm; opt-out of direct marketing (without prior consent); rights relating to automated decisions; compensation in the event of a breach.
7) Cross-border transfers
Transfers possible under appropriate safeguards (contracts, security measures), and to be declared at registration (relevant countries).
Where data of foreign individuals is sent to Ghana for processing, we ensure compliance with the applicable law of the country of origin.
8) Internal oversight
Appointment of a Data Protection Supervisor where required or recommended by the DPC; overseeing the compliance program, records, and training.
9) Enforcement & penalties
Processing without registration or non-compliance with requirements: offenses subject to fines (penalty units) and/or imprisonment depending on severity; the DPC may order corrective measures.
10) Exercise your rights (Ghana)
Use our "Exercise your rights" form (main section) or write to us. You may also contact the DPC if necessary.
Annex N – Tunisia (Law n°2004-63)
This annex explains our compliance with Organic Law No. 2004-63 of July 27, 2004 and its implementing texts, under the supervision of the National Authority for the Protection of Personal Data (INPDP).
1) Scope & authority
The law applies to processing carried out in Tunisia (public/private sector). Competent authority: the INPDP (oversight, opinions/authorizations, recommendations).
2) Prior procedures
Prior declaration to the INPDP before any processing (tacit acceptance if there is no objection within the statutory period).
Prior authorization required for certain categories/processing (see §3) and in cases provided for by law/decrees.
3) Sensitive data & specific cases
Sensitive categories (racial/genetic origin, religious beliefs, political/philosophical/union opinions, etc.): INPDP authorization mandatory (outside the specific regime for health data).
Health data: a dedicated regime (Chapter V) with authorization and enhanced measures set by the INPDP.
Video surveillance: subject to prior INPDP authorization.
4) Principles & lawful basis
Lawful, defined, and explicit purposes, minimization, accuracy/updating, security/confidentiality, purpose limitation.
Consent: express and written except in prescribed cases (vital interest, legal basis, properly framed scientific research, etc.). It is prohibited to unduly condition a service on acceptance of unnecessary uses.
Advertising/marketing: use prohibited without express and specific consent (opt-in).
5) Individual rights
Information before processing (categories, purposes, recipients, etc.).
Access (including a copy), rectification/erasure, restriction (in prescribed cases), objection (including to marketing), and challenging automated decisions with significant effects.
6) Disclosure & international transfers
Disclosure to third parties: governed and limited to the stated purposes, with safeguards and, where applicable, agreement/authorization.
Transfer abroad: INPDP authorization mandatory before any transfer (including to countries deemed adequate under administrative practice), with information on the destination country, purposes, duration, and security measures.
The law does not formally provide for a legal procedure for breach notification; we apply best practices and INPDP recommendations.
8) Subcontractors
Written contracts requiring: limited purposes, security/confidentiality, controlled subcontracting, assistance in exercising rights, return/destruction at the end of the engagement.
9) Exercise your rights (Tunisia)
Use the "Exercise your rights" form (main section) or write to us. You may also contact the INPDP if unsatisfied.