Skip to content
Afrisapients — connected African expertiseAfrisapients home
Legal

Privacy Policy

How Afrisapients collects, uses, shares and retains personal data belonging to clients, experts and website visitors.

Draft — pending legal review.

This document describes how Afrisapients operates today and is published in good faith. It has not yet been reviewed by external counsel, and the final version may differ. It does not constitute legal advice.

Last updated 2026-09-01.

1. Who we are

Afrisapients operates an Africa-focused expert network. We connect organisations carrying out professional research with verified experts, and we run the compliance screening, scheduling, recording and transcription that surrounds those consultations.

Afrisapients is the controller of the personal data described in this policy. Where we act on written instructions from a client — for example when processing a brief they have submitted — we act as a processor for that limited purpose. Our registered entity details and contact routes are published on our contact page.

2. The data we collect

We collect only what the service needs. The categories below are the complete set.

  • Account data: name, work email address, organisation, job title, country and password credentials (stored only as a hash by our authentication provider).
  • Brief data: the research question you submit, sectors, countries, urgency, target dates and any context you choose to include.
  • Expert profile data: professional history, sector and geographic coverage, languages, stated rate, CV and supporting credential documents.
  • Compliance data: conflict declarations, employer-consent confirmations, restricted-topic acknowledgements and the audit record of each declaration.
  • Consultation data: scheduling metadata, attendance, recordings made with consent, transcripts, AI-assisted summaries and post-call ratings.
  • Payment data: amounts, currency, status and the payment provider's own references. We never see or store full card numbers.
  • Technical data: IP address at the point of submission for rate limiting and abuse prevention, plus aggregate, cookieless analytics.

3. Why we process it, and on what basis

Processing purposes and the lawful basis relied upon for each
PurposeLawful basis
Creating and administering accountsPerformance of a contract
Matching a brief to suitable expertsPerformance of a contract
Conflict, sanctions and compliance screeningLegitimate interests, and legal obligation where applicable
Recording and transcribing a consultationConsent of all participants
Taking payment and paying expertsPerformance of a contract
Service emails, including brief acknowledgements and schedulingPerformance of a contract
Marketing emails and newslettersConsent, withdrawable at any time
Rate limiting, fraud and abuse preventionLegitimate interests in keeping the platform secure
Keeping an audit trail of compliance-relevant actionsLegitimate interests in a defensible research record

4. Who we share it with

We do not sell personal data and we do not share it for third-party advertising. We share it with the following categories of recipient, each under a written processing agreement and only to the extent needed:

  • Clients receive expert profiles on a shortlist, and the transcript and summary of consultations they have paid for.
  • Experts receive the brief context needed to judge whether they can help, and the identity of the client where the client has agreed to be named.
  • Infrastructure and database hosting providers, who store the data at rest.
  • Email delivery, video conferencing, transcription and payment providers, each processing only the data their function requires.
  • Professional advisers, auditors and regulators where we are required or permitted to disclose.

5. International transfers

Afrisapients operates across African markets and our clients are frequently based elsewhere, so personal data is transferred across borders in the ordinary course of the service. Where data leaves the country in which it was collected, we rely on the receiving country's adequacy status where one exists, and otherwise on standard contractual clauses with the recipient together with a transfer risk assessment.

You can request a summary of the transfer mechanism applying to your data using the contact route below.

6. How long we keep it

Retention periods by data category
DataRetention
Account recordsFor the life of the account, then 12 months
Briefs and shortlists6 years from the close of the engagement
Recordings12 months from the consultation, then deleted
Transcripts and summaries6 years from the consultation
Compliance declarations and audit log7 years, append-only
Payment and invoice recordsAs required by tax law, currently 7 years
Unsuccessful expert applications12 months, unless you ask us to keep them
Marketing consent recordsUntil withdrawn, plus 24 months

7. Your rights

Subject to the exemptions available under the law applying to you, you may ask us to give you a copy of your personal data, correct it, delete it, restrict how we use it, transfer it to another provider, or object to processing carried out on the basis of our legitimate interests. Where we rely on consent — recordings and marketing — you may withdraw it at any time without affecting processing already carried out.

We respond to requests within one month. We may ask you to verify your identity first. If you are unhappy with our response you may complain to the data protection authority in your country.

8. Security

  • All traffic is encrypted in transit, and data is encrypted at rest by our hosting provider.
  • Row-level access control is enforced in the database, not only in the interface: an expert cannot read another expert's record, and a client cannot read another organisation's briefs.
  • CVs, credential documents and recordings are held in private storage and reachable only through short-lived signed links.
  • Compliance and audit tables are append-only. Entries cannot be edited or deleted, including by our own staff.
  • Access to production data is limited to the operations team members who need it, and every state-changing action is logged with the actor's identity.
  • No system is perfectly secure. We do not promise absolute security, and we will notify affected people and the relevant authority where a breach requires it.

9. Cookies and analytics

We use a small number of strictly necessary cookies and a cookieless analytics tool. No advertising or cross-site tracking cookies are set. The detail is in our Cookie Policy.

10. Children

The platform is intended for professional use and is not directed at anyone under 18. We do not knowingly collect data about children.

11. Contacting us and changes to this policy

Data requests and privacy questions should be sent using the contact routes published on our contact page, marked for the attention of the privacy contact.

This policy was last updated on 2026-09-01. Where a change materially affects how we use your data, we will tell account holders by email before it takes effect and keep the previous version available on request.