Privacy Policy

Privacy and Cookie Policy of Cromakod Academy Limited

1. Introduction

Cromakod Academy Limited ("Cromakod", "we", "us" or "our") is committed to protecting the privacy of individuals and organizations that use our services. This Privacy and Cookie Policy ("Policy") explains how we collect, use, disclose, and safeguard Personal Data in compliance with applicable laws. Cromakod is a company operating under the laws of Nigeria, and we adhere to the Nigeria Data Protection Regulation 2019 (NDPR) and its successor legislation, as well as global data protection standards modeled by the EU General Data Protection Regulation (GDPR).

This Policy is intended to meet the requirements of the NDPR while aligning with the GDPR and other major international privacy laws to ensure robust privacy protection for all data subjects worldwide. It applies to all users of our websites, products, and services globally, regardless of location. By using our services or interacting with our platforms, you acknowledge that you have read and understood this Policy. If you do not agree with any part of this Policy, please refrain from using our services.

2. Definitions

For the purposes of this Policy, the following terms have the meanings set out below:

Personal Data:

Any information relating to an identified or identifiable natural person ("Data Subject"). An identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or factors specific to the individual's physical, physiological, genetic, mental, economic, cultural, or social identity. Personal Data does not include information that has been anonymized or aggregated such that it can no longer be used to identify a specific individual.

Data Subject:

The natural person to whom Personal Data relates, whether the person is a user, customer, visitor, or any individual interacting with our services. This Policy protects the rights of all Data Subjects whose Personal Data we process. (Note: This Policy does not apply to data relating to legal entities or deceased persons, which are not considered "personal data" under NDPR and GDPR.)

Processing:

Any operation or set of operations performed on Personal Data, whether or not by automated means. Processing includes activities such as collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission or dissemination, alignment or combination, restriction, erasure, or destruction of Personal Data.

Data Controller:

The natural or legal person (alone or jointly with others) that determines the purposes and means of the processing of Personal Data. For this Policy, Cromakod acts as the Data Controller of your Personal Data.

Data Processor:

A natural or legal person or other body that processes Personal Data on behalf of the Data Controller. Data Processors (for example, service providers engaged by Cromakod) handle Personal Data only according to our instructions and are contractually obligated to protect it.

Sensitive Personal Data:

Certain categories of Personal Data that are subject to additional protections under law. This may include information about an individual's health, genetic or biometric data, sex life or sexual orientation, religious or philosophical beliefs, political opinions, trade union membership, or criminal convictions, among others (often referred to as "special categories of data" under GDPR). We generally do not collect Sensitive Personal Data unless it is necessary and we have obtained explicit consent or another lawful basis to do so, in accordance with applicable regulations.

Cookies:

Small text files or similar tracking technologies that are placed on your device when you visit websites. Cookies allow us to recognize your browser or device and collect certain information (see Section 6 below and Appendix A for details on how we use cookies and your choices).

Cromakod (or "the Company"):

Refers to Cromakod Academy Limited, a company registered in Nigeria. In this Policy, "we" or "us" means Cromakod Academy Limited as the organization responsible for Processing your Data.

NDPR:

The Nigeria Data Protection Regulation 2019, which is Nigeria's primary data protection regulation. This Policy is designed to comply with the NDPR (and any applicable successor law, such as the Nigeria Data Protection Act 2023) for data processing within Nigeria.

GDPR:

The European Union's General Data Protection Regulation (EU Regulation 2016/679). Although Cromakod operates under Nigerian jurisdiction, we align our practices with the GDPR and other international data protection standards to protect the Personal Data of individuals globally.

Interpretation:

Unless otherwise defined in this Policy, terms used herein shall have the same meaning as defined by the NDPR, GDPR, or other applicable data protection laws. In case of any conflict between definitions, the definition under the strictest applicable law will apply for the protection of the Data Subject.

3. Scope of Policy

This Policy applies to all Personal Data processed by Cromakod in the course of our business, whether collected through our websites, mobile applications, products, services, marketing activities, or any other interaction you have with us. It covers Personal Data of individuals with whom we interact, including but not limited to customers, website visitors, end-users of our products, business partners, and representatives of organizations (to the extent such data relates to an identifiable individual).

This Policy is global in scope. That means that while Cromakod is based in Nigeria, we extend the safeguards of this Policy to all individuals worldwide. We endeavor to meet the highest standards of privacy compliance, including the NDPR within Nigeria and the GDPR for individuals in the European Union, the UK Data Protection Act 2018/UK GDPR for individuals in the United Kingdom, and comparable requirements of other jurisdictions. In effect, regardless of where you are located, we will handle your Personal Data in a manner consistent with the principles outlined in this Policy.

Jurisdiction and Applicable Law:

Cromakod is subject to the laws of Nigeria. In practice, this Policy incorporates key principles from international data protection laws to ensure compliance and interoperability. If you are located in a jurisdiction with privacy laws offering additional protections, we will also comply with those requirements to the extent applicable. This Policy is not a substitute for any legal rights you may have under local law; rather, it is intended to transparently inform you how we safeguard your data and comply with our legal obligations globally.

Third-Party Websites:

Please note that our website or services may contain links to external websites or services operated by third parties. This Policy does not cover those third-party sites. We encourage you to review the privacy policies of any external sites or services before providing any Personal Data to them. Cromakod is not responsible for the privacy practices or content of third-party websites. (See also Section 7 on data disclosure and Section 6 on third-party cookies.)

4. Personal Data We Collect

We collect and process various categories of Personal Data depending on your interaction with us. We limit our collection to data that is relevant and necessary for the purposes described in this Policy. The types of Personal Data we may collect include:

Information You Provide Directly:

This includes data that you give us when you use our services, contact us, or otherwise interact with Cromakod. For example:

  • Contact and Identity Data: such as your name, email address, telephone number, postal address, job title, and company or organization name (if you are engaging with us on behalf of an entity).
  • Account Credentials: such as usernames, passwords, or other security information for accessing our platforms (if you register an account with us).
  • Profile Information: such as preferences, feedback, and any other Personal Data you choose to share with us (for instance, when filling out forms, responding to surveys, or participating in promotions).
  • Customer Support and Communications: any information you provide when you contact us for support or with inquiries, including the content of emails or messages, and your contact details for follow-up.

Information Collected Automatically:

When you interact with our websites or online services, we automatically collect certain data about your device and usage through cookies and similar technologies (see Section 6 and Appendix A for details). This data may include:

  • Technical Data: such as your IP address, browser type and version, device identifiers (e.g., device ID, MAC address, IMEI), operating system, network provider, and device model.
  • Usage Data: such as timestamps of visits, pages or screens viewed, features used, links clicked, content interactions, and the page you visited before navigating to our website. We may also collect crash logs and other diagnostic data to help us improve our services.
  • Cookies and Tracking Data: as further described in Section 6, we and third parties use cookies and other tracking technologies to collect information about your browsing actions and patterns. This may include data on how you navigated to and from our site, your preferences (like language settings), and your engagement with our ads or content on third-party sites.

Information from Third Parties:

We may receive Personal Data about you from third-party sources, but only where those third parties have a legal basis to share your information with us. Such data may include:

  • Third-Party Services: If you interact with our services through social media platforms or other third-party services (for example, if you log in via a social network account, or use an integration with a third-party tool), we may receive certain information from that service such as your public profile, name, contact information, or friends/contacts list, according to the authorization procedures determined by such third party.
  • Service Providers and Business Partners: We might obtain data from partners such as resellers, analytics providers, advertising networks, or payment processors. For instance, our analytics providers may supply us with aggregate demographic or preference information; our advertising partners might provide information on your interactions with our ads on other platforms.
  • Publicly Available Sources: We may also collect information from public databases, industry directories, or social network platforms if, for example, we are verifying identity or conducting due diligence as permitted by law.

We will treat any Personal Data obtained from these sources in accordance with this Policy. Where appropriate, we will inform you of the source of Personal Data we collect indirectly and ensure that any third party has confirmed that they have your consent or another lawful basis to share such Personal Data with us.

Children's Data:

Our services are generally not directed at children under the age of 18. We do not knowingly collect Personal Data from anyone under 18 without verifiable parental consent. If you are a parent or guardian and believe we might have collected Personal Data from your child without proper consent, please contact us (see Section 15), and we will take appropriate steps to investigate and address the issue, including deleting the data if required. (For minors where applicable law requires a higher age threshold or parental authorization – e.g., age 13 in some jurisdictions for certain online services – we will comply with those requirements.)

6. Cookies and Tracking Technologies

Use of Cookies:

Cromakod uses cookies and similar tracking technologies (such as web beacons, pixels, and device identifiers) on our websites and online services to provide a better user experience, for functionality, analytics, and advertising purposes. Cookies are small text files that a website saves on your computer or mobile device when you visit the site. They enable the website to remember your actions and preferences (such as login, language, and other display preferences) over a period of time, so you don't have to re-enter them whenever you come back to the site or browse from one page to another. Cookies also help us understand which pages are popular, whether users are encountering errors, and how we can improve our content and layout.

Types of Cookies:

We use both session cookies (which are temporary and deleted when you close your browser) and persistent cookies (which remain on your device for a set period or until you delete them). Cookies can also be categorized by their purpose. Broadly, the cookies on our services fall into the following categories: Strictly Necessary Cookies, Functional Cookies, Performance/Analytics Cookies, and Targeting/Advertising Cookies. Each of these categories is explained in detail in Appendix A: Cookie Categories and Examples of this Policy. We also indicate in the Appendix whether a given category is considered "essential" or "non-essential" under relevant laws. Generally, Strictly Necessary Cookies are essential for our site to function and do not require consent to deploy, whereas the other categories (functional, analytics, advertising) are non-essential and will only be used with your consent where required by law.

Third-Party Cookies:

Some cookies on our site are set by Cromakod (these are "first-party cookies"), and others may be set by third-party services that we use. For example, we may partner with third-party analytics providers, such as web traffic analysis services, which set cookies to collect usage information, or with third-party advertising networks that set cookies to deliver personalized ads on our behalf. We do not share Personal Data that directly identifies you with third-party advertisers or social media networks without your consent. However, if you consent to Targeting/Advertising cookies, those third parties may collect information via their cookies (such as your browsing activity or device identifiers), which could be combined with other information they hold about you for profiling or ad targeting purposes. These third-party cookies and tracking technologies are controlled by the third parties, not by Cromakod, and are subject to the third parties privacy policies. We list the categories of third-party cookies in Appendix A, but we do not list specific third-party cookie names in this Policy to keep it generalized; the specific cookies in use may change from time to time. You can manage or block third-party cookies through your browser settings.

Legal Compliance and Consent:

In jurisdictions such as the EU, UK, and others that have cookie consent requirements, Cromakod will not set non-essential cookies (e.g., analytics or advertising cookies) on your device unless and until you have given consent via our cookie banner or settings center. When you first visit our site, you will be presented with a cookie notice that allows you to accept or reject different categories of cookies (except strictly necessary cookies, which you cannot disable as they are essential for the site's operation). You can adjust your preferences at any time through the "Manage Cookies" link on our website or by updating your browser settings. We will record your cookie consent choice and honor it. Note that if you are in a jurisdiction that does not mandate prior consent for cookies (for example, some parts of the US), we may still provide you with controls to opt out of certain cookies as a matter of transparency and choice.

How to Manage or Disable Cookies:

You have the right to control how cookies are used on your devices:

  • Cookie Consent Tool: On our website, you can access a cookie management tool (often found in the footer or the initial cookie banner) to review and change your preferences. Through this tool, you can typically see the categories of cookies in use and toggle your consent on or off for each category (except strictly necessary cookies, which are always enabled).
  • Browser Settings: Most web browsers allow you to refuse new cookies, delete existing cookies, or be notified before a cookie is set. Please refer to your browser's help section for instructions on how to adjust your cookie settings.

Warning: If you disable cookies (especially strictly necessary ones) via your browser, some features of our site or services may not function properly. For example, you may not be able to log in or use certain interactive features.

Do Not Track:

Some browsers have a "Do Not Track" (DNT) feature that allows you to signal to websites that you do not want to be tracked. Our site currently does not respond to DNT signals in a uniform way, because there is not yet an established standard for how to interpret them. However, we treat DNT signals as an opt-out of targeted advertising cookies where legally required. Additionally, there are industry frameworks (such as the Global Privacy Control (GPC) signal) that allow you to broadcast an opt-out of sale/sharing for targeted advertising under U.S. state laws; to the extent such signals are detected and applicable, we will honor them as required by law.

Other Tracking Technologies:

We may use related technologies such as web beacons (also known as pixel tags or clear GIFs) in our emails or on our site. For example, we might include a pixel in marketing emails to understand if you open them or take any action. This helps us measure the effectiveness of our communications. These technologies often rely on cookies to function, so if you disable cookies, they may be less effective.

For detailed information about the specific cookies and tracking technologies we use, and examples of what they do, please refer to Appendix A: Cookie Categories and Examples at the end of this Policy.

7. Disclosure of Personal Data (Third-Party Recipients)

Cromakod respects the confidentiality of your Personal Data. We do not sell your Personal Data to third parties for profit, and we will never share or use Personal Data for purposes that are not disclosed to you. However, we do share Personal Data with certain trusted third parties in the following circumstances, and always under applicable data protection laws:

Service Providers (Data Processors):

We share Personal Data with third-party service providers that perform services and functions on our behalf to support our interactions with you. These include:

  • IT and Hosting Providers: Companies that provide data storage, cloud hosting, infrastructure, and other IT services to ensure our platform runs securely and reliably.
  • Analytics Providers: Partners that assist us in analyzing website/app traffic and user behavior (for example, analytics platforms that process data such as IP address or user actions on our behalf).
  • Customer Support Tools: Platforms that help us manage customer inquiries, send notifications, or provide live chat services.
  • Payment Processors: If you make payments to or through us, we may use secure payment gateways or processors that will process your payment information. They are responsible for safeguarding your financial data and only use it for transaction processing.
  • Marketing and Communication Services: Third-party tools that help us send newsletters, surveys, or other messages, or organize events and registrations.

These service providers act under our instructions and are bound by contractual agreements to process Personal Data only for our purposes and in compliance with this Policy and applicable law. We require them to implement appropriate security measures to protect Personal Data and not to use it for their commercial purposes.

Within Cromakod and Affiliates:

If Cromakod Academy Limited has affiliates, subsidiaries, or parent companies (collectively, "affiliates"), we may share Personal Data within our corporate group as needed for business administration, centralized management, or to provide our services to you. Any intra-group data sharing will be consistent with the purposes stated in this Policy (for example, your data might be stored in a centralized customer database accessible by our affiliate that provides IT support). All our entities are required to follow the same data protection rules as outlined in this Policy.

Business Transfers:

If we undergo a business transaction such as a merger, acquisition by another company, reorganization, joint venture, sale of all or part of our assets, or transition of service to another provider, your Data may be transferred as part of that transaction. We will ensure that any party receiving your information as part of such a transaction is bound to respect your Data in a manner consistent with this Policy. If required by law, we will notify you and/or obtain your consent when your Personal Data is transferred in this context.

Legal Obligations and Safety:

We may disclose Personal Data to third parties (such as courts, law enforcement or government agencies, regulators, or external advisors) if we determine that such disclosure is necessary to:

  • Comply with any applicable law, regulation, legal process, or governmental request. For example, we may be required to respond to a court order or a subpoena, or to report data to the Nigeria Data Protection Commission (NDPC) or other regulatory bodies.
  • Enforce our terms of service or other agreements, or to investigate potential violations thereof.
  • Protect the rights, property, or safety of Cromakod, our users, employees, or the public. This includes exchanging information with other companies and organizations for fraud prevention, spam/malware detection, or other security concerns.

When feasible and lawful, we will notify you if we must disclose your data in response to legal process. However, in urgent or sensitive cases (e.g., responding to a lawful request in a criminal investigation or to prevent imminent harm), we may not be able to provide notice.

With Your Consent:

We will share your Personal Data with others outside of the above circumstances only when we have your explicit consent to do so. For instance, if you opt-in to a feature that involves sharing data with a third-party partner (not acting as our service provider), we will disclose your Personal Data in that context. You have the right to withdraw such consent at any time (see Section 12).

No Unmentioned Third-Party Use:

We do not grant third parties any independent right to use or disclose your Personal Data for their own purposes, except as set out above. Wherever Personal Data is shared with a third party, we take steps to ensure it will be processed in a manner consistent with this Policy and under an appropriate duty of confidentiality.

International considerations for third parties:

If any third-party recipients are located outside of Nigeria or your home jurisdiction, we will implement appropriate measures to ensure that your Personal Data remains protected (see Section 8 below regarding international data transfers).

8. International Data Transfers

Given that Cromakod serves individuals and organizations globally, the Personal Data we collect may be transferred to, stored in, or accessed from countries outside of your home country or the country where the data originated. In particular, Nigeria is our primary place of business, but we may use cloud services or other third-party processors that operate in various countries (for example, in the European Union, United Kingdom, United States, or other jurisdictions).

When we transfer Personal Data across national borders, we do so in compliance with applicable data protection laws. The laws in the destination country may be different or less protective than the laws in your country; however, we will ensure that adequate safeguards are in place to protect your information in line with this Policy.

Transfers out of Nigeria:

For Personal Data originating from Nigeria, the NDPR (and NDPA 2023) imposes conditions on international transfers. We will only transfer such data to a third country if one of the following applies:

  • The destination country has been officially deemed by Nigerian authorities to have an adequate level of protection for Personal Data.
  • The receiving party is bound by standard contractual clauses, binding corporate rules, codes of conduct, or certification mechanisms that ensure an adequate level of data protection. In practice, this means we may rely on GDPR-approved Standard Contractual Clauses (SCCs) or other approved agreements to contractually require that your data receive a level of protection comparable to that under Nigerian law.
  • The transfer is otherwise allowed by law, for example:
    • You have explicitly consented to the proposed transfer after being informed of any potential risks.
    • The transfer is necessary for the performance of a contract between you and us (or for pre-contractual steps at your request), or for the conclusion or performance of a contract in your interest between us and a third party (for instance, if we need to route data through an international service provider to deliver a service you requested).
    • The transfer is necessary for the establishment, exercise, or defense of legal claims.
    • The transfer is necessary to protect vital interests of you or others (e.g., in an emergency).
    • The transfer is part of our compliance with an international agreement or for important reasons of public interest (rare scenarios).

In all cases, we document the basis for transfer and ensure that appropriate safeguards are applied.

Transfers from the EU/UK or Other Countries:

Similarly, if we transfer Personal Data from the European Economic Area (EEA), the United Kingdom, or other regions with data transfer restrictions, we will ensure such transfers comply with the GDPR/UK GDPR and local laws. This typically means:

  • Transferring data only to countries that have been deemed adequate by the European Commission or UK authorities, or
  • Implementing Standard Contractual Clauses or other lawful transfer mechanisms (such as binding corporate rules, or relying on exceptions where appropriate) to safeguard the data.

We also perform, where required, a transfer impact assessment to evaluate if additional security measures are needed to handle any unique risks of transferring to certain countries.

Your Acknowledgment:

By using our services or submitting your Personal Data to us, you understand that your Personal Data may be transferred internationally as described above. Regardless of where your data is transferred, stored, or processed, we will take steps to ensure that your data is treated securely and in accordance with this Policy and applicable laws.

If you have questions about our international data transfer practices or wish to obtain a copy of the relevant safeguards (such as excerpts of contractual clauses) in place, you may contact us (see Section 15).

9. Data Security Measures

Cromakod takes the security of Personal Data seriously. We implement and maintain appropriate technical and organizational security measures to protect your Personal Data from unauthorized access, accidental loss, misuse, alteration, destruction, or disclosure. These measures are designed to provide a level of security appropriate to the risk of processing your Personal Data. They include, but are not limited to:

Access Controls:

We limit access to Personal Data to employees, contractors, and agents who have a "need-to-know" that data for their role. Those with access are subject to strict confidentiality obligations. We use authentication and authorization mechanisms to ensure only authorized personnel can access systems storing Personal Data.

Encryption and Pseudonymization:

Where appropriate, we use encryption to protect sensitive Personal Data, both in transit (e.g., SSL/TLS encryption for data transmitted between your device and our websites) and at rest. For certain data, we may employ hashing, pseudonymization, or anonymization techniques to reduce the risk to individuals in case of a data incident.

Network and Application Security:

We protect our IT infrastructure with firewalls, intrusion detection systems, and anti-malware tools to guard against external threats. Our websites and applications are developed following security best practices (for example, protection against SQL injection, XSS, and other vulnerabilities) and we regularly update our software and systems to address security patches. We also conduct periodic vulnerability assessments and penetration testing through internal or third-party experts.

Monitoring and Logging:

We monitor our systems for potential vulnerabilities and attacks. Access to Personal Data and key actions are logged where feasible, and logs are reviewed for anomalies. This helps us detect and respond to suspicious activities.

Training and Policies:

We ensure that our staff are trained in data protection and information security practices. Cromakod has internal policies and incident response plans that guide our personnel on how to handle Personal Data and how to report and respond to security incidents or potential data breaches.

Vendor Due Diligence:

When we engage third-party service providers (Section 7), we evaluate their security practices. We require that our Data Processors implement adequate security measures to protect Personal Data, and we include appropriate data protection and security requirements in our contracts with them.

While we strive to protect your Personal Data, no security measures are infallible. The transmission of information via the internet is not completely secure, and we cannot guarantee absolute security of data, especially data transmitted to our website. However, we are committed to taking all steps required by law and following best practices to protect your information. In the unfortunate event that we identify a security compromise involving your Personal Data, we will act promptly as described in Section 13 (Data Breach Response).

You also play a role in data security. We encourage you to use unique and strong passwords for any accounts you have with us, keep your login credentials confidential, and notify us immediately if you suspect any unauthorized access to your account or Personal Data.

10. Data Retention

Cromakod

Cromakod will retain your Personal Data only for as long as is necessary to fulfill the purposes for which it was collected, as outlined in this Policy, unless a longer retention period is required or permitted by law. We maintain data retention schedules that set time limits for deletion or anonymization of data, taking into account the following criteria:

Duration of Use:

We keep Personal Data for the period during which we have an ongoing relationship with you (e.g., for as long as you maintain an account with us or use our services). For example, if you are a registered user, we will keep your account information while your account is active or as needed to provide you with services.

Purpose Fulfillment:

We retain data as needed to achieve the purposes for which it was collected. For instance, if you provided your email to receive a newsletter, we will retain that email until you unsubscribe or the newsletter program ends. If we collected data for improving our services, we may keep that data (possibly in aggregated form) for the time necessary to complete the analysis.

Consent and Opt-Out:

For data processed based on your consent, we may delete the data sooner if you withdraw consent. For example, if you consented to marketing emails and later opt out, we will remove you from our marketing list promptly (but may keep a record of your opt-out request indefinitely to ensure we respect your no-contact preference).

Legal Obligations:

We may need to retain certain data to comply with legal and regulatory obligations. For example, financial and transaction records may be kept for several years to satisfy tax or accounting laws. Likewise, under NDPR/NDPA and other laws, we might need to retain records of consent, privacy requests, and how we responded, to demonstrate compliance.

Disputes and Enforcement:

If we are involved in a dispute with you or have to enforce our agreements, we will retain relevant data for the duration of the dispute and for a period allowed or required by law after its resolution, in case we need to respond to legal claims or regulatory inquiries. This is aligned with our legitimate interest in establishing or defending legal claims.

When Personal Data is no longer needed for the above purposes, or when retention is no longer legally required, we will securely erase, anonymize, or pseudonymize the data. For example, we may permanently delete or render Personal Data irrecoverable on our systems. In some cases, if data has been stored in backups or archives, it may not be immediately removed from those systems, but we continue to safeguard it until deletion is possible.

Data Minimization:

Throughout retention, we actively minimize the data we hold. Wherever feasible, we prefer to use aggregate or de-identified data (which is not considered Personal Data) for analytics or long-term research, rather than maintaining identifiable Personal Data.

If you have questions about our specific data retention periods for certain types of Personal Data, you may contact us (see Section 15). Please note that in responding, we must balance transparency with security (for instance, we will not reveal details that could help someone maliciously infer how to evade data deletion processes).

11. Data Subject Rights

Under the NDPR, GDPR, and other data protection laws, data subjects have a range of rights regarding their Personal Data. Cromakod is committed to respecting these rights and has processes in place to enable you to exercise them. The exact rights available to you depend on your jurisdiction and the legal basis for processing, but we extend core rights to all users wherever feasible. Your key rights include:

Right to Be Informed:

You have the right to be provided with clear, transparent information about how your Personal Data is processed. This Policy is one of the ways we fulfill this right. We aim to be transparent about our data practices at the time of data collection and whenever there are significant changes.

Right of Access:

You have the right to access the Personal Data we hold about you and to obtain a copy of that data, as well as information about how we process it. This is sometimes called a "Data Subject Access Request." Upon verification of your identity, we will provide you with the relevant data and details, such as the purposes of processing, the categories of data, the recipients (or categories of recipients) to whom the data has been disclosed, and the envisaged retention period.

Right to Rectification:

If any of your Personal Data we hold is inaccurate or incomplete, you have the right to request that we correct or update it. We encourage you to keep your information up-to-date and will make rectifications promptly as required by law.

Right to Erasure:

Also known as the "Right to be Forgotten," this allows you to request that we delete your Personal Data in certain circumstances. This right is not absolute, but we will erase your data upon request if:

  • the data is no longer necessary for the purposes it was collected;
  • you withdraw consent (if the processing was based on consent) and no other legal basis exists;
  • you object to processing (see below) and we have no overriding legitimate grounds to continue;
  • the data was processed unlawfully; or
  • erasure is required to comply with a legal obligation.

Please note we might refuse the erasure request if an exemption applies, for example, if retaining the data is necessary for exercising the right of freedom of expression, compliance with a legal obligation, or the establishment or defense of legal claims.

Right to Restrict Processing:

You have the right to request that we limit the processing of your Personal Data under certain conditions. For example, you can ask for restriction if you contest the accuracy of the data (for a period allowing us to verify it), or if the processing is unlawful but you oppose erasure and prefer restriction, or if we no longer need the data but you need us to keep it for legal claims, or if you have objected to processing (pending verification of overriding grounds). When processing is restricted, such data will be marked and, apart from storage, only processed for certain things like legal claims or with your consent.

Right to Object:

You have the right to object to certain types of processing of your Personal Data at any time, on grounds relating to your particular situation.

Direct Marketing: You can always object to processing of your Personal Data for direct marketing purposes, and if you do, we will stop processing your data for that purpose immediately.

Legitimate Interests: If we are processing your data on the basis of our legitimate interests (or those of a third party), you also have the right to object to that processing. In such a case, we will cease processing unless we have compelling legitimate grounds that override your interests, rights, and freedoms, or unless we need to continue processing for the establishment, exercise, or defense of legal claims. (We have noted in Section 5 which purposes rely on legitimate interests.)

Right to Withdraw Consent:

Where we rely on your consent to process Personal Data (for example, for sending marketing emails or for using certain cookies), you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing based on consent before its withdrawal. Once you withdraw consent, we will stop the specific processing that was based on consent. (If you withdraw consent for cookies, see instructions in Section 6; if for marketing emails, see Section 12 below.)

Right to Data Portability:

For Personal Data that you have provided to us and is processed by automated means under the legal basis of consent or contract, you have the right to request a copy in a structured, commonly used, machine-readable format (for example, CSV or JSON). You also have the right to ask that we transmit this data directly to another data controller, where technically feasible. This right facilitates moving your data to other service providers, if desired.

Rights related to Automated Decision-Making:

If we make a decision about you that is solely based on automated processing (e.g., algorithms) which produces legal effects or similarly significant effects, you have the right not to be subject to such a decision, except in certain permitted cases. In practice, Cromakod does not carry out purely automated decisions with legal or significant effects without human involvement. If we ever do, you will be informed and given the right to contest the decision, express your point of view, and require human intervention. Examples of automated decisions could include credit scoring or algorithmic hiring, which we currently do not perform.

Right to Lodge a Complaint:

If you believe that we have infringed your data protection rights or are processing your Personal Data unlawfully, you have the right to lodge a complaint with a supervisory authority.

  • Nigeria: You can file a complaint with the Nigeria Data Protection Commission (NDPC) or its authorized agency (formerly NITDA under NDPR).
  • European Union: You may contact the data protection authority in the EU member state of your residence, place of work, or where the issue arose.
  • United Kingdom: You can reach out to the UK Information Commissioner's Office (ICO).
  • Other Regions: If you reside in another country with a data protection regulator, you can contact that regulator. We would appreciate the chance to address your concerns directly before you approach a regulator, so we encourage you to contact us first, but you are entitled to contact the authority at any time.

Exercising Your Rights:

You may contact us at any time to exercise the above rights (see Section 15 for contact details). To protect your privacy, we will verify your identity (for example, by requiring you to provide information to confirm it's you) before fulfilling your request. In general, there is no fee to exercise your rights; however, if a request is manifestly unfounded or excessive (e.g., repetitive), we may charge a reasonable fee or refuse to act on it (as permitted by law). We will respond to legitimate requests as soon as possible, and in any event within the timeframe required by law (NDPR specifies a timely response; GDPR generally requires within one month, extendable by two more months if necessary with notice).

Please note that some rights may be limited if fulfilling them would adversely affect the rights and freedoms of others. For example, if a request for access would reveal Personal Data about another person, we might need to redact certain information. Additionally, certain Personal Data may be exempt from such requests under local law (such as data involved in ongoing investigations, or data held for legal compliance).

Cromakod will make every effort to accommodate your rights request. If we cannot fulfill your request, we will provide you with an explanation, subject to any legal restrictions.

13. Data Breach Response and Notification

Despite our robust security measures (as described in Section 9), Cromakod acknowledges that data breaches can occur. A "Personal Data Breach" is generally defined as a security incident leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data. We have put in place a detailed Data Breach Response Plan to handle such incidents swiftly and effectively, in order to minimize harm and comply with our legal obligations.

Breach Response Measures:

In the event of a suspected or confirmed data breach, we will:

  • Immediately Investigate: Our security team will activate incident response procedures to contain the breach, secure our systems, and investigate the scope, cause, and impact of the incident. We will work diligently to identify what data was affected, which individuals may be impacted, and the steps needed to remediate the situation.
  • Mitigation: We will take appropriate measures to mitigate any potential harm to individuals. This might include isolating affected systems, changing access credentials, restoring data from clean backups, patching vulnerabilities, and cooperating with law enforcement if a crime is suspected. Our goal is to prevent any further unauthorized access or data loss as soon as possible after discovery of the breach.

Notification to Authorities:

If the breach is likely to result in a risk to the rights and freedoms of data subjects, Cromakod will notify the appropriate Data Protection Authority within the timeframe required by law. Under the NDPR (as reinforced by the Nigeria Data Protection Act 2023) and GDPR, this is typically within 72 hours of becoming aware of the breach, unless a delay is justified (for example, if the breach is unlikely to pose any risk, notification might not be required). In Nigeria, the relevant authority is the Nigeria Data Protection Commission (NDPC). In the EU, it would be the supervisory authority in the member state of our establishment or the affected users. Our breach report to authorities will include information required by law, such as the nature of the breach, categories and approximate number of affected individuals and records, likely consequences, and measures taken or proposed to address the breach.

Notification to Data Subjects:

If a data breach is likely to result in a high risk to your rights and freedoms (for example, risk of fraud, financial loss, identity theft, or significant confidentiality breach), we will also inform you, the affected Data Subject(s), without undue delay. We will do so as soon as feasible after determining that such risk exists, and in a manner that is clear and communicates the nature of the breach and any recommended steps for you to protect yourself. For instance, we might advise you to reset your password and monitor your accounts for suspicious activity, if relevant. We may contact you through the email address on file, via our website, or by other direct communication channels that we have established with you. If direct communication would involve disproportionate effort (e.g., if we don't have contact info for all affected individuals), we may use public communication (such as a notice on our website) to reach affected users efficiently, as permitted by law.

Exceptions:

In certain cases, we might not notify individuals if:

  • we have implemented subsequent measures that ensure the high risk to your rights is no longer likely to materialize (for example, if we quickly secure the data such that any stolen data is rendered unusable via encryption), or
  • notification would require disproportionate effort (as noted, we would then use alternative means to inform everyone, like public announcements), or
  • it would hinder a law enforcement investigation (in which case, notification may be delayed upon request of authorities). We will adhere to guidance from relevant authorities in these scenarios.

Documentation:

We will document all data breaches, regardless of severity, including the facts relating to the breach, its effects, and the remedial actions taken. This documentation may be requested by regulators to verify our compliance with breach notification duties.

User Responsibilities:

We also encourage you to remain vigilant for any suspicious activity. If you suspect that your Personal Data has been compromised in connection with Cromakod, please notify us immediately (see Section 15 for how to contact us). Prompt notification can help us take measures to investigate and mitigate any potential breach.

Commitment:

Our goal is to be fully transparent in the unfortunate event of a data breach and to protect our users' interests in any such scenario. We treat data breaches with utmost seriousness as part of our commitment to data security and privacy.

14. Changes to this Policy

We may update or revise this Privacy and Cookie Policy from time to time to reflect changes in our practices, to keep up with legal requirements, or for other operational reasons. When we make changes, we will update the "Last Updated" date at the top of this Policy. If the changes are significant, we will provide a more prominent notice (such as by posting a notice on our website's homepage or alerting you through email or an in-service notification).

We encourage you to review this Policy periodically to stay informed about how we are protecting your Personal Data. Your continued use of our services after any modifications to this Policy will constitute your acknowledgment of the changes and your agreement to be bound by the updated Policy, to the extent permitted by law. If we seek to apply the changes to purposes or processing conditions for which we previously required your consent, we will obtain your consent for the new purposes or conditions as needed.

If you do not agree with aspects of the updated Policy, you have the right to discontinue use of our services and may exercise your rights as described in Section 11 and Section 12, such as deleting your account or data.

For any material changes, especially those that involve new uses of Personal Data that were not originally disclosed when your data was collected, we will endeavor to notify you in advance and, where required by law, obtain your consent or allow you the opportunity to opt in or out.

15. Contact Information

Cromakod Academy Limited is the Data Controller responsible for the processing of your Personal Data as described in this Policy. If you have any questions, concerns, or requests regarding this Policy or our data practices, please contact us as follows:

Email: info@Cromakod.ng

Postal Address: Cromakod Academy LTD., No. 268 Lawan Dambazau Link, Gandu New Layout, Kano State, Nigeria.

Attn: Legal Compliance Officer

We will respond to inquiries or requests as soon as reasonably possible, and in any event within any timeframes required by law. If you are contacting us to exercise a specific data subject right, please refer to Section 11 and provide enough information for us to verify your identity and understand the scope of your request.

If you have an unresolved privacy or data use concern that we have not addressed satisfactorily, you may also contact your local data protection authority (as noted in Section 11 under "Right to Lodge a Complaint").

Cromakod Academy Limited is dedicated to safeguarding Personal Data and upholding privacy rights. This Policy reflects our commitment to transparency and accountability in how we handle your information.

For more information or to see updates to this Policy, please visit our website or reach out to our team.

Thank you for trusting Cromakod with your data.

logo

Our mission is to provide accessible, expert-led courses that propel your aspirations in the tech world.

Connect with us

© 2025 Cromakod. All rights reserved