Privacy Policy
How Afrisapients collects, uses, shares and retains personal data belonging to clients, experts and website visitors.
Draft — pending legal review.
This document describes how Afrisapients operates today and is published in good faith. It has not yet been reviewed by external counsel, and the final version may differ. It does not constitute legal advice.
Last updated 2026-09-01.
1. Who we are
Afrisapients operates an Africa-focused expert network. We connect organisations carrying out professional research with verified experts, and we run the compliance screening, scheduling, recording and transcription that surrounds those consultations.
Afrisapients is the controller of the personal data described in this policy. Where we act on written instructions from a client — for example when processing a brief they have submitted — we act as a processor for that limited purpose. Our registered entity details and contact routes are published on our contact page.
2. The data we collect
We collect only what the service needs. The categories below are the complete set.
- Account data: name, work email address, organisation, job title, country and password credentials (stored only as a hash by our authentication provider).
- Brief data: the research question you submit, sectors, countries, urgency, target dates and any context you choose to include.
- Expert profile data: professional history, sector and geographic coverage, languages, stated rate, CV and supporting credential documents.
- Compliance data: conflict declarations, employer-consent confirmations, restricted-topic acknowledgements and the audit record of each declaration.
- Consultation data: scheduling metadata, attendance, recordings made with consent, transcripts, AI-assisted summaries and post-call ratings.
- Payment data: amounts, currency, status and the payment provider's own references. We never see or store full card numbers.
- Technical data: IP address at the point of submission for rate limiting and abuse prevention, plus aggregate, cookieless analytics.
3. Why we process it, and on what basis
| Purpose | Lawful basis |
|---|---|
| Creating and administering accounts | Performance of a contract |
| Matching a brief to suitable experts | Performance of a contract |
| Conflict, sanctions and compliance screening | Legitimate interests, and legal obligation where applicable |
| Recording and transcribing a consultation | Consent of all participants |
| Taking payment and paying experts | Performance of a contract |
| Service emails, including brief acknowledgements and scheduling | Performance of a contract |
| Marketing emails and newsletters | Consent, withdrawable at any time |
| Rate limiting, fraud and abuse prevention | Legitimate interests in keeping the platform secure |
| Keeping an audit trail of compliance-relevant actions | Legitimate interests in a defensible research record |
5. International transfers
Afrisapients operates across African markets and our clients are frequently based elsewhere, so personal data is transferred across borders in the ordinary course of the service. Where data leaves the country in which it was collected, we rely on the receiving country's adequacy status where one exists, and otherwise on standard contractual clauses with the recipient together with a transfer risk assessment.
You can request a summary of the transfer mechanism applying to your data using the contact route below.
6. How long we keep it
| Data | Retention |
|---|---|
| Account records | For the life of the account, then 12 months |
| Briefs and shortlists | 6 years from the close of the engagement |
| Recordings | 12 months from the consultation, then deleted |
| Transcripts and summaries | 6 years from the consultation |
| Compliance declarations and audit log | 7 years, append-only |
| Payment and invoice records | As required by tax law, currently 7 years |
| Unsuccessful expert applications | 12 months, unless you ask us to keep them |
| Marketing consent records | Until withdrawn, plus 24 months |
7. Your rights
Subject to the exemptions available under the law applying to you, you may ask us to give you a copy of your personal data, correct it, delete it, restrict how we use it, transfer it to another provider, or object to processing carried out on the basis of our legitimate interests. Where we rely on consent — recordings and marketing — you may withdraw it at any time without affecting processing already carried out.
We respond to requests within one month. We may ask you to verify your identity first. If you are unhappy with our response you may complain to the data protection authority in your country.
8. Security
- All traffic is encrypted in transit, and data is encrypted at rest by our hosting provider.
- Row-level access control is enforced in the database, not only in the interface: an expert cannot read another expert's record, and a client cannot read another organisation's briefs.
- CVs, credential documents and recordings are held in private storage and reachable only through short-lived signed links.
- Compliance and audit tables are append-only. Entries cannot be edited or deleted, including by our own staff.
- Access to production data is limited to the operations team members who need it, and every state-changing action is logged with the actor's identity.
- No system is perfectly secure. We do not promise absolute security, and we will notify affected people and the relevant authority where a breach requires it.
10. Children
The platform is intended for professional use and is not directed at anyone under 18. We do not knowingly collect data about children.
11. Contacting us and changes to this policy
Data requests and privacy questions should be sent using the contact routes published on our contact page, marked for the attention of the privacy contact.
This policy was last updated on 2026-09-01. Where a change materially affects how we use your data, we will tell account holders by email before it takes effect and keep the previous version available on request.