ALUM.
Log inGet started

Everyone

Privacy Policy

Version 1.0.0 · Effective 2026-07-13

On this page

Last updated: [DATE] Data controller (platform): [ALUM LEGAL ENTITY NAME], [REGISTERED ADDRESS] ("ALUM", "we", "us"). Data Protection Officer / privacy contact: [DPO NAME OR ROLE], [DPO EMAIL].

Plain-language summary (not legally binding): ALUM powers branded apps for organizations. This policy explains what personal data we collect, why, who can see it (including the administrators of any organization you join), how identity verification (including BVN in Nigeria) works, how long we keep data, and your rights under the Nigeria Data Protection Act 2023 (NDPA) and the EU/UK GDPR. One thing to understand up front: when you join an organization, that organization controls the data you share within it — ALUM processes that data on the organization's behalf.


1. Scope — and a Note About Branded Apps

1.1. This policy applies to the ALUM Platform: our websites, apps, APIs, and every Organization Space, including organization-branded installable apps and Organization Spaces served on an organization's own custom domain. If you are using an app carrying an organization's name and logo that is powered by ALUM, this policy applies to it.

1.2. It applies to everyone whose data we handle: Users and Members, Organization administrators, Guest Donors, event attendees, and visitors.

1.3. Organizations may publish their own supplementary privacy notices for their Space. Those supplement, and do not replace, this policy for Platform processing.

2. Our Two Roles: Controller and Processor

Understanding who is "responsible" for your data depends on the context:

ALUM as controller. We decide how and why data is processed for platform-level purposes: your ALUM account, identity verification, platform security, fraud prevention, payments infrastructure, legal compliance, platform analytics, and communications from ALUM itself.

ALUM as processor, the Organization as controller. When you interact inside an Organization Space — your membership profile, posts and comments in that Space, donations to that organization's funds, event RSVPs and attendance, dues — the Organization is the data controller and decides the purposes; ALUM processes that data on the Organization's documented instructions under a Data Processing Addendum. Requests about that data may need to be directed to, or resolved with, the Organization (see Section 12).

Where processing serves both platform-level and organization-level purposes (for example, a donation record needed for payment processing and fraud prevention), each party is a controller for its own purposes.

3. Personal Data We Collect

3.1 Users and Members

  • Account data: name, email address, phone number, password or third-party sign-in identifiers (Google, Apple), profile photo, and any profile fields you complete.
  • Identity verification data: see Section 5.
  • Membership data: organizations you join, join requests, Org Roles held, membership status changes.
  • Financial activity: donations and contributions you make (amount, fund, timestamp, payment method metadata — we do not store full card numbers; these are handled by our payment processors), withdrawal details if you receive funds, and your anonymity preference per donation.
  • Content and communications: posts, comments, messages, event RSVPs, poll or election participation, media you upload, reports you submit.
  • Support interactions: correspondence with our support team.

3.2 Organization administrators

In addition to the above: organization registration details, verification documents (certificates, governing documents, officer identity documents, proof of address), settlement bank account details, and administrative action logs.

3.3 Guest Donors (no account)

Name, email address, phone number, donation amount and target fund, payment metadata, anonymity preference, and IP/device data collected at the time of donation.

3.4 Collected automatically from everyone

IP address, device and browser type, operating system, app installation events (for organization PWAs), pages viewed, referral source, timestamps, approximate location derived from IP, crash and diagnostic data, and cookie/identifier data (see Section 10).

3.5 From third parties

Identity-verification results from licensed verification providers; payment status and anti-fraud signals from payment processors; sign-in data from Google/Apple if you use them; sanctions/watchlist screening results where legally required.

We do not intentionally collect special-category data (such as health data or, except as inherent in your chosen organizations, religious affiliation). Note: joining certain organizations (for example, a religious body) may itself reveal information about you; that membership data is controlled by the organization, processed by us under Section 2, and protected accordingly.

Where ALUM acts as controller, we rely on the following legal bases under GDPR Art. 6 and the corresponding lawful bases under the NDPA:

PurposeExamplesLegal basis
Providing the PlatformAccount creation, hosting Organization Spaces, delivering Modules, processing donations, generating branded PWAsContract (ToS); legitimate interests for Guest Donor transaction handling
Identity verificationBVN/ID verification of Users; organization verificationLegal obligation (KYC/AML where applicable); contract; legitimate interests in platform integrity
Payments and settlementTransmitting payment data to processors, settlement, refunds, chargeback handlingContract; legal obligation
Safety, security, fraud preventionMonitoring for fraud and abuse, enforcing caps, investigating reports, securing accountsLegitimate interests; legal obligation
Legal complianceTax, accounting, responses to lawful requests, sanctions screeningLegal obligation
CommunicationsService notifications (transactional — always sent); ALUM product news and marketing (only with your consent or as permitted by law, always with opt-out)Contract; consent; legitimate interests
Analytics and improvementAggregated usage statistics, feature performance, debuggingLegitimate interests; consent where required for non-essential cookies
New ModulesDelivering future features under the functional framework of the ToSSame bases as the corresponding function above; any new purpose will be notified and, where required, consented

Where we rely on legitimate interests, we have balanced them against your rights and will provide details of our assessment on request. Where processing is on the Organization's behalf, the Organization is responsible for its lawful basis.

5. Identity Verification and BVN — Special Handling

5.1. In Nigeria, upgrading to Verified User (required to create organizations, hold administrative roles, or create personal funds) involves verification of your Bank Verification Number (BVN).

5.2. How it works: you submit your BVN and required matching details; we transmit them over encrypted channels to a licensed identity-verification provider, which validates them against authorized records and returns a match result and the verification attributes permitted by applicable rules.

5.3. We treat BVN and identity documents as high-sensitivity data: encrypted in transit and at rest, access restricted to the minimum necessary personnel and systems, never displayed to Organizations or other Users, never used for marketing, and never sold.

5.4. We retain verification records only as long as needed for the purposes in Section 4 and applicable KYC/AML retention laws (see Section 13). Comparable safeguards apply to any government-ID verification used in other jurisdictions.

6. Who Can See Your Data — Especially Organizations

This is the most important section to read.

6.1. Organization administrators. When you join an Organization, its authorized role-holders can see, within their permissions: your membership profile, membership status, your posts and comments in that Space, your event RSVPs and attendance in that Space, and — for financial role-holders — donation records to that Organization's funds. They cannot see your activity in other Organizations, your BVN or identity documents, or your ALUM account security details.

6.2. Anonymous donations. Choosing anonymity hides your name from public and general member-facing donor lists. Your identity remains in our records and those of our payment processors, and may be accessible to the receiving Organization's authorized financial administrators strictly for legal, accounting, refund, or fraud-prevention purposes. Anonymity is a display control, not invisibility.

6.3. Other Members and the public. Content you post in an Organization Space is visible according to that Space's settings (member-only or public). Public funds and their public donor lists are visible to anyone.

6.4. Service providers (our processors): payment processors, identity-verification providers, cloud hosting and storage, email/SMS/push delivery, analytics, and customer-support tooling — each bound by contract to process data only on our instructions. A current list of sub-processors is available at [LINK / on request].

6.5. Legal and safety disclosures: to comply with law, enforce our terms, or protect the rights, property, or safety of Users, Organizations, ALUM, or the public — including disclosures to law enforcement, regulators, courts, and financial-crime authorities.

6.6. Corporate transactions: in a merger, acquisition, or asset sale, data may transfer to the successor subject to this policy, with notice to you.

6.7. We do not sell personal data, and we do not share it with third parties for their own advertising.

7. Guest Donors

If you donate without an account, we process your name, contact details, and payment data to execute the donation, issue receipts, handle refunds and disputes, prevent fraud, and meet legal obligations. The receiving Organization receives your donor details (subject to your anonymity choice, per Section 6.2) and is the controller of its own donor records. You have the same data rights described in Section 12.

8. International Data Transfers

8.1. Our infrastructure and providers may store or process data in countries other than yours, including countries not deemed to provide adequate protection.

8.2. Where data protected by the GDPR or NDPA is transferred internationally, we implement appropriate safeguards: adequacy decisions where available; the EU Standard Contractual Clauses (and UK Addendum) with supplementary measures where needed; and, for transfers subject to the NDPA, transfers consistent with the NDPA's cross-border provisions and any instruments approved by the Nigeria Data Protection Commission (NDPC).

8.3. You may request a copy of the relevant safeguards via [DPO EMAIL].

9. Security

We apply technical and organizational measures appropriate to the risk, including encryption in transit (TLS) and at rest for sensitive data, role-based access controls, network isolation, logging and monitoring, vendor due diligence, and staff confidentiality obligations. No system is perfectly secure; if a breach occurs that is likely to result in a risk to your rights, we will notify the competent authority (including the NDPC and/or relevant GDPR supervisory authority) and, where required, affected individuals, within legally mandated timeframes.

10. Cookies and Similar Technologies

We use strictly necessary cookies (authentication, security, load balancing) and, with your consent where required, functional and analytics cookies. Organization PWAs use local storage and service workers to enable installation and offline behavior. Details, and controls for non-essential cookies, are in our [Cookie Policy / cookie banner].

11. Automated Decision-Making

We use automated systems for fraud detection and security (for example, flagging suspicious donations or withdrawal patterns). Where an automated decision would produce legal or similarly significant effects (such as blocking a withdrawal), a human reviews the decision on request, and you may contest it via [SUPPORT EMAIL]. We do not use automated decision-making for profiling unrelated to security and compliance.

12. Your Rights

12.1. Subject to legal conditions and exemptions, you have the right to: access your data; rectify inaccurate data; erase data; restrict or object to processing (including an absolute right to object to direct marketing); data portability; withdraw consent at any time (without affecting prior processing); and not be subject to solely automated decisions with legal or similarly significant effects. These rights arise under the GDPR and the NDPA 2023 alike.

12.2. How to exercise them: in-app settings (profile edits, marketing preferences, account deletion) or by contacting [DPO EMAIL]. We respond within one month (GDPR) or the NDPA's applicable period, extendable where permitted. We may need to verify your identity first.

12.3. Requests involving Organization Data. Where your request concerns data controlled by an Organization (for example, deleting your posts within an Organization Space or your record in an organization's donor list), we will either route the request to that Organization or direct you to it, and assist the Organization as its processor. The Organization is responsible for responding as controller.

12.4. Complaints. You may complain to a supervisory authority: in Nigeria, the Nigeria Data Protection Commission (NDPC); in the EU/UK, your local data-protection authority or the [UK ICO]. We would appreciate the chance to address your concern first via [DPO EMAIL].

13. Retention

We keep personal data only as long as needed for the purposes collected, then delete or irreversibly anonymize it. Indicative periods:

  • Account data: life of the account, plus up to [90] days after deletion for recovery and integrity checks.
  • Identity-verification records (including BVN verification results): duration of the account plus the period required by applicable KYC/AML and financial-record laws (typically [5] years after the relationship ends, per jurisdiction).
  • Transaction and donation records: [6–7] years or as required by tax, accounting, and financial regulations.
  • Content in Organization Spaces: retained per the controlling Organization's instructions; deleted or returned per the DPA when an Organization leaves the Platform.
  • Logs and security data: typically [12–24] months.
  • Marketing preferences and suppression lists: as long as needed to honor your choices.

When you leave an Organization: your forward access ends; historical records the Organization must retain (donations, attendance, governance records) remain under its control. When you delete your account: we delete or anonymize controller data per the periods above; records we must keep by law are retained in restricted form; Content you posted in Organization Spaces is handled per the Organization's instructions, and we will pass on your deletion request.

14. Children

The Platform is not directed at children under 18 (or the applicable age of digital consent). We do not knowingly collect children's data without verifiable parental or guardian consent where such participation is lawfully enabled by an Organization. If you believe a child has provided data without consent, contact [DPO EMAIL] and we will act promptly.

15. Changes to This Policy

We will post any changes here and update the date above. For material changes, we will give notice by email or in-app notification at least [30] days before they take effect, where feasible. Continued use after the effective date constitutes acknowledgment; where a change requires consent, we will seek it.

16. Contact

[ALUM LEGAL ENTITY NAME] [REGISTERED ADDRESS] Data Protection Officer: [DPO NAME/EMAIL] General privacy queries: [PRIVACY EMAIL] [If applicable: EU/UK representative under GDPR Art. 27: [NAME, ADDRESS]]

Questions about these documents? Contact legal@alumweb.org.