Skip to main content

Privacy & Data Governance

Personal data should remain connected to a clear purpose, context, and responsibility.

This notice explains how Studomia LTD collects, uses, shares, protects, and retains personal data across its public website, communications, learning experiences, and institutional work.

It also explains the difference between ordinary website and relationship data, contextual learning signals, governed evidence, and institutional authority.

Data controller
Studomia LTD
Lagos, Nigeria
Effective date
12 July 2026
Privacy contact
privacy@studomia.com

At a glance

The commitments that govern our data practice.

These commitments apply across the public website and carry into more specific learning, pilot, and institutional agreements.

Purpose before collection

We collect personal data only for a defined and understandable purpose.

No sale or advertising profiling

We do not sell personal data or build behavioural advertising profiles.

No automatic authority

Website activity, enquiries, subscriptions, and declared interests do not create eligibility, readiness, priority, evidence, or institutional status.

Context-bound use

Learning-related data is interpreted only within the authorised experience or institutional context in which it was generated.

Human review and accountable decisions

AI-assisted tools may support reflection or synthesis, but they do not independently certify, rank, authorise, or declare competency.

01 · Scope

What this notice covers.

The same privacy principles apply across Studomia, but the exact data, purpose, lawful basis, and responsibility may differ by context.

Public website

Website delivery, security, privacy choices, technical diagnostics, and any optional analytics enabled in accordance with this notice.

Relationship enquiries

Institutional, pilot, partnership, sponsorship, and general enquiries submitted through the shared Contact system.

Invitations and updates

Consent-managed email communications and the topic preferences selected by subscribers.

Learning experiences and pilots

Governed participation, reflection, artifacts, contextual signals, institutional records, and any evidence formed under an authorised experience or pilot.

Institutional agreements may assign Studomia and an institution different controller or processor responsibilities. Those agreements do not replace the need for a lawful basis; they define the authorised purpose, roles, safeguards, and operational responsibilities for that engagement.

02 · Data processing

What we process, why we process it, and how long it remains.

We collect only the information reasonably necessary for the stated purpose. Please do not submit sensitive personal data through a public form unless Studomia has specifically requested and authorised it.

Public website operation

Data
Basic request, device, browser, security, and network information generated when the site is accessed.
Purpose
Deliver the website, protect its availability, prevent misuse, diagnose faults, and maintain security.
Lawful basis
Legitimate interests in operating and securing the website, and legal obligations where applicable.
Retention
Short operational periods, normally no more than 30 days unless a security incident, legal duty, or claim requires longer retention.

Relationship enquiries

Data
Name, email address, organisation, role, country, enquiry context, message or institutional question, source page, source component, source pathway, referrer, consent record, and operational follow-up information.
Purpose
Route and review institutional, pilot, partnership, sponsorship, or general enquiries and preserve appropriate relationship continuity.
Lawful basis
Steps taken at your request before a possible engagement, legitimate interests in responding to and managing enquiries, contract where applicable, and legal obligations.
Retention
While the enquiry or conversation is active, then normally up to 6 months after closure. Minimal compliance metadata may be retained for up to 24 months where needed for consent, governance, claims, or legal accountability.

Invitations and updates

Data
Name, email address, organisation where supplied, subscription context, source information, selected communication topics, preference history, consent version, and opt-in time.
Purpose
Send only the categories of Studomia communication that you selected and maintain your communication preferences.
Lawful basis
Consent.
Retention
While your subscription remains active. We aim to remove the active subscription within 30 days of unsubscribe or withdrawal, while retaining only a minimal suppression or compliance record for up to 24 months where necessary.

Governed learning experiences

Data
Participation records, reflections, artifacts, contextual signals, facilitation records, and other information defined for the authorised experience.
Purpose
Facilitate the experience, support reflection and learning, preserve context, and meet agreed governance responsibilities.
Lawful basis
Consent where required, contract, legitimate interests, legal obligations, or another lawful basis specified for the particular experience.
Retention
Defined for the experience or institutional agreement. Personal data is reviewed when the purpose ends and, where no longer required, deleted, anonymised, or reduced to the minimum necessary record.

Institutional pilots and operations

Data
Institutional contact information, authorised participant information, programme records, governance documentation, agreed operational records, and carefully governed evidence where applicable.
Purpose
Deliver, review, govern, and document the authorised institutional engagement.
Lawful basis
Contract, steps taken before contract, consent where required, legitimate interests, legal obligations, or another lawful basis documented for the engagement.
Retention
Defined by the institutional agreement, applicable law, safeguarding requirements, and the purpose of the engagement. Records are reviewed when the engagement ends.

Privacy, security, and legal requests

Data
Identity and contact details, request records, correspondence, verification information, security records, and complaint or incident information.
Purpose
Respond to privacy requests, investigate incidents, protect rights, demonstrate compliance, and establish or defend legal claims.
Lawful basis
Legal obligation, legitimate interests, consent where applicable, and the establishment, exercise, or defence of legal claims.
Retention
For the period necessary to resolve the request or incident and meet applicable legal, audit, or claims requirements.

Information you must provide

Required form fields are marked. Without the necessary contact information, enquiry context, or communication consent, we may be unable to route an enquiry, respond, or activate a subscription.

Information received from others

We may receive limited professional contact details from an institution, authorised partner, referral, or public professional source. Where required, we will explain the source and relevant processing when we first contact you.

03 · Learning data

A signal is not automatically evidence, and evidence is not automatically authority.

Studomia keeps these categories separate so that ordinary activity, declared interest, participation, and institutional decisions do not collapse into one hidden data process.

Website and communication data

Enquiries, subscriptions, source information, and public-site activity support routing, consent-managed follow-up, security, and service improvement. They do not create readiness, eligibility, priority, evidence, or adoption status.

Contextual learning signals

Reflections, artifacts, participation records, and other observations may help make learning visible inside an authorised experience. They remain contextual and must not be treated as conclusions on their own.

Governed evidence

Evidence is formed only through authorised, purpose-bound synthesis and review. The applicable experience or institutional agreement defines who may interpret it, for what purpose, and with what safeguards.

Institutional authority

Decisions about certification, competency, continuation, access, adoption, or institutional status remain with the authorised human and institutional actors. Studomia technology does not create that authority.

04 · Recipients and transfers

Who may process personal data on our behalf.

We use service providers only for defined operational purposes and require appropriate confidentiality, security, and data-protection responsibilities.

Categories of recipients

  • Website hosting and infrastructure providers
  • Relationship-management service providers
  • Email communication service providers
  • Security and diagnostic service providers
  • Authorised institutional delivery partners
  • Professional advisers and public authorities where legally required

International transfers

Some service providers or authorised collaborators may process information outside Nigeria or your country. Where required, Studomia uses recognised transfer mechanisms, contractual protections, risk assessment, access controls, and other appropriate safeguards.

You may request more information about the relevant recipient categories and transfer safeguards through the privacy contact below.

Studomia does not sell personal data, provide it to data brokers, or disclose it for behavioural advertising.

05 · Website technologies

Cookies, local storage, analytics, and diagnostics.

Our public website should remain an orientation surface, not a surveillance surface.

Strictly necessary technology

We may use essential cookies, local storage, server logs, or equivalent technologies where necessary for security, network delivery, forms, privacy preferences, accessibility, and core website functionality.

Optional analytics

Optional public-site analytics are not active at the effective date of this notice. Before enabling them, Studomia will implement a privacy-preference control and limit collection to route-level and aggregated information needed to understand whether the website is helping visitors orient themselves.

We will not send names, email addresses, organisations, message content, submission identifiers, consent answers, or free-text responses to analytics.

No advertising tracking

We do not use advertising pixels, cross-site tracking, behavioural advertising profiles, or third-party marketing surveillance.

06 · Retention

Personal data is kept only for the period connected to its authorised purpose.

When the purpose ends, we delete, anonymise, or reduce the information to the minimum necessary record, unless law, safeguarding, an active dispute, or another documented lawful purpose requires longer retention.

Relationship enquiry content

Active conversation plus up to 6 months after closure

Delete, anonymise, or reduce to the minimum necessary compliance record.

Minimal enquiry audit record

Up to 24 months after closure

Retain only limited metadata needed for consent, governance, claims, or legal accountability.

Active communication subscription

Until unsubscribe or withdrawal

Stop active communications and remove the active subscription within the operational deletion period.

Suppression or consent record

Up to 24 months after withdrawal

Retain only what is necessary to respect the unsubscribe request and demonstrate compliance.

Website and security logs

Normally no more than 30 days

Delete automatically unless required for an active incident, legal duty, or claim.

Institutional or pilot records

As defined by the agreement and applicable law

Review at closure and delete, anonymise, archive, or reduce according to the authorised purpose.

Irreversibly anonymised outputs

May be retained for longer-term research or institutional learning

Retain only where the information is no longer personal data and re-identification is not reasonably possible.

07 · Safeguarded participation

Children, young people, and higher-risk contexts require additional safeguards.

The open public Contact and Invitations & Updates routes are not designed to collect children’s learning records or sensitive personal data.

Where a child or young person participates in a Studomia experience, participation must occur through an authorised and safeguarded context. Age-appropriate information, institutional responsibility, consent or authorisation, and applicable child-protection measures are established before processing begins.

Children’s data is not used for advertising, hidden profiling, unrelated ranking, or automatic eligibility decisions. Higher-risk processing, new technology, sensitive data, or large-scale monitoring is subject to additional assessment, including a data privacy impact assessment where required.

08 · AI and automated decisions

AI may assist authorised work, but it does not independently exercise judgment or authority.

Studomia does not use website enquiries, communication preferences, declared interests, or public-site activity to make solely automated decisions about participation, eligibility, readiness, priority, institutional status, pilot access, competency, or progression.

Inside a defined learning or institutional context, AI-assisted processing may support authorised reflection, organisation, synthesis, or analysis. It remains subject to documented purpose, applicable consent, data minimisation, human review, and institutional governance.

AI-assisted outputs do not independently certify, rank, evaluate, or declare competency, and they do not replace the responsibility of authorised human or institutional decision-makers.

09 · Security and incidents

We use administrative, technical, and organisational safeguards proportionate to the processing.

Safeguards may include

  • Encrypted transmission
  • Restricted and role-based access
  • Purpose-limited service-provider access
  • Access review and account security
  • Data minimisation and deletion controls
  • Incident response and governance documentation

Personal data breaches

We investigate suspected personal-data incidents and notify the Nigeria Data Protection Commission, affected individuals, institutions, or other authorities where applicable law requires notification.

No security measure can guarantee absolute protection, but safeguards are reviewed as the website and institutional activity evolve.

10 · Your rights

You may ask questions, exercise applicable rights, or challenge how your personal data is handled.

Rights vary by jurisdiction and may be limited where another legal duty or the rights of another person applies.

  1. 01

    Ask whether we process your personal data and request access to it.

  2. 02

    Request correction of inaccurate or incomplete personal data.

  3. 03

    Request deletion where the data is no longer required or another legal ground applies.

  4. 04

    Request restriction of processing in applicable circumstances.

  5. 05

    Object to processing based on legitimate interests or to direct communication.

  6. 06

    Withdraw consent at any time where consent is the lawful basis.

  7. 07

    Request data portability where the right applies.

  8. 08

    Ask for information about relevant international-transfer safeguards.

  9. 09

    Lodge a complaint with the Nigeria Data Protection Commission or another competent supervisory authority.

  10. 10

    Not be subject to a solely automated decision that produces legal or similarly significant effects, except where lawfully permitted and appropriately safeguarded.

How to make a request

Email privacy@studomia.com and describe the request. We may ask for proportionate information to verify identity and protect the rights of other people.

Complaints

You may lodge a complaint with the Nigeria Data Protection Commission or, where applicable, the supervisory authority in the country where you live or work.

Nigeria Data Protection Commission

Privacy contact

Ask a privacy question or exercise a data-protection right.

Studomia LTD, Lagos, Nigeria. Requests are reviewed under documented governance procedures and applicable data-protection law.

privacy@studomia.com