Important Notice
This Privacy Policy applies to the official website of the Emmanuel International College Alumni Association ("EICAA"). By accessing or using this website, you confirm that you have read, understood, and agree to be bound by the terms of this Policy. If you do not agree, please discontinue use of the website.
About the Emmanuel International College Alumni Association
The Emmanuel International College Alumni Association ("EICAA", "we", "us", or "our") is the official alumni body of Emmanuel International College, a co-educational private Christian secondary school located at Road G, Da Chibi Rwang Street, Opposite the Old Government House Junction, Rayfield, Jos, Plateau State, Nigeria.
The school was incorporated as Emmanuel International College Limited (RC-469425) and is operated under the auspices of El-Shaddai Covenant Ministries, founded in 1986 by Dr. James Iruobe. The College runs both Junior Secondary School (JSS 1–3) and Senior Secondary School (SSS 1–3) programmes, providing six years of qualitative Christian-based education.
The EICAA website serves as a platform for connecting alumni, sharing news and events, facilitating membership registration, and preserving the heritage and community of EIC graduates and former staff.
Scope and Application of This Policy
This Privacy Policy governs all personal data collected, processed, stored, or transmitted through the EICAA website and any associated digital platforms, including but not limited to:
- Alumni registration and membership portals
- Contact and inquiry forms
- Event registration pages
- Newsletter and communications subscriptions
- Donation or dues payment gateways
- Social media integrations and linked third-party services
This Policy applies to all users of the EICAA website, including alumni, current students, parents, former staff, and any other visitors, regardless of their location within or outside Nigeria. It applies equally where personal data is processed by automated or manual means.
Legal Framework and Regulatory Compliance
EICAA is committed to processing personal data to the highest internationally recognised standard. Our alumni community spans multiple countries across Europe, North America, and beyond, and we believe every member — wherever they are in the world — deserves the same level of protection.
Our primary data protection framework is the EU General Data Protection Regulation (GDPR), widely regarded as the world's gold standard for personal data protection. We apply GDPR principles to all data subjects regardless of their country of residence. As an organisation also based in Nigeria, we comply with the Nigeria Data Protection Act 2023 (NDPA), which was itself substantially modelled on the GDPR — meaning our GDPR-aligned practices meet or exceed NDPA requirements in virtually all respects.
- EU General Data Protection Regulation (GDPR) — Primary Standard:Governs how we collect, use, store, and protect personal data for all members and users, regardless of location.
- UK GDPR:The retained version of the EU GDPR applicable in the United Kingdom, to which we also adhere for members resident in the UK.
- Nigeria Data Protection Act 2023 (NDPA):Nigeria's primary data protection legislation, signed into law on 12 June 2023. Our GDPR-aligned practices meet and exceed NDPA requirements.
- NDPC General Application and Implementation Directive (GAID) 2025:Issued by the Nigeria Data Protection Commission on 20 March 2025, providing implementation guidance under the NDPA.
- UN Convention on the Rights of the Child (UNCRC):Informing our approach to the privacy of children and young people, complemented by the Child Rights Act 2003.
Personal Data We Collect
4.1 Data You Provide Directly
- Identity Data:Full name, maiden name, graduation year, student identification number
- Contact Data:Email address, telephone number, postal address
- Academic Data:Years of attendance, class set, academic programmes, extracurricular activities
- Professional Data:Current employer, job title, industry, professional qualifications, LinkedIn profile
- Financial Data:Payment information for membership dues or donations (processed via secure third-party processors — we do not store raw card data)
- Profile Data:Photographs, biographical information, and voluntarily submitted content
- Communications Data:Messages, queries, feedback, or correspondence sent to us
4.2 Data Collected Automatically
- IP address and approximate geographic location
- Browser type, version, and operating system
- Device type and screen resolution
- Pages visited, links clicked, and time spent on pages
- Referring URLs and search terms used to reach the site
- Session duration and frequency of visits
4.3 Data from Third Parties
- Social media platforms when you interact with our pages or use social login features
- Other alumni or members who provide your contact details in the context of alumni activities
- Emmanuel International College itself, in connection with verified alumni records
- Payment processors and financial service providers, in relation to transaction confirmations
4.4 Special Categories of Data
We do not intentionally collect special categories of sensitive personal data (such as data revealing racial or ethnic origin, religious beliefs, health information, biometric data, or political opinions). If any such data is incidentally disclosed, we will handle it with additional care and will not process it beyond the purpose for which it was disclosed, unless we have obtained your explicit consent.
Purposes of Data Processing and Legal Bases
In accordance with the NDPA 2023 and the NDPC GAID 2025, all personal data processing must be grounded in a lawful basis:
| Purpose | Data Types | Legal Basis |
|---|---|---|
| Alumni registration & membership management | Identity, Contact, Academic | Contract / Consent |
| Processing membership dues or donations | Identity, Contact, Financial | Performance of contract |
| Sending newsletters, event invitations, and news | Identity, Contact | Consent |
| Maintaining and displaying an alumni directory | Identity, Profile, Professional | Consent |
| Organising alumni events and reunions | Identity, Contact | Legitimate interest / Consent |
| Responding to inquiries and correspondence | Identity, Contact, Communications | Legitimate interest |
| Improving website functionality and user experience | Technical / Usage | Legitimate interest |
| Ensuring website security and preventing fraud | Technical, Identity | Legitimate interest / Legal obligation |
| Complying with legal and regulatory obligations | As required by law | Legal obligation |
| Statistical and historical research | Anonymised / Aggregated | Legitimate interest |
Consistent with Section 24(1) of the NDPA and the principle of purpose limitation, we will not use your personal data for incompatible purposes without first obtaining your consent or establishing a new lawful basis.
Cookies and Similar Tracking Technologies
Our website uses cookies and similar technologies to enhance your browsing experience and to gather usage analytics. A cookie is a small text file placed on your device by the website when you visit.
6.1 Types of Cookies We Use
- Strictly Necessary Cookies:Essential for the website to function correctly (e.g., maintaining your session). These cannot be disabled.
- Functional Cookies:Allow the website to remember your preferences for a more personalised experience.
- Analytics Cookies:Help us understand how visitors interact with the website (e.g., Google Analytics).
- Social Media Cookies:Set by social media platform integrations; governed by the respective platform's privacy policy.
6.2 Managing Your Cookie Preferences
On your first visit, a cookie consent banner will allow you to accept or reject non-essential cookies. You may update your preferences at any time through your browser settings. Disabling certain cookies may affect the functionality of parts of the website.
Disclosure and Sharing of Personal Data
7.1 Within the Association
Personal data may be shared internally among authorised EICAA officers, committee members, and volunteers who require access in the performance of their functions. All such persons are bound by confidentiality obligations.
7.2 Third-Party Service Providers
We engage reputable third-party service providers as data processors, contractually obligated to process your data only on our instructions and in accordance with the GDPR and applicable data protection law. These include:
- Website hosting and cloud infrastructure providers
- Email marketing platforms and newsletter services
- Payment processors for membership dues and donations
- Event management platforms
- Analytics and website performance services
7.3 Emmanuel International College
We may share relevant alumni data with Emmanuel International College for the purpose of maintaining accurate alumni records and facilitating school-alumni engagement activities, subject to appropriate data protection agreements.
7.4 Legal Disclosures
We may disclose personal data where required by law, court order, or at the direction of a competent regulatory authority, including data protection supervisory authorities, law enforcement agencies, or other bodies with legal jurisdiction.
7.5 What We Will Never Do
- Sell your personal data to any third party
- Share your data with advertisers or commercial entities for marketing without your explicit consent
- Transfer your data to organisations that do not provide adequate data protection safeguards
International Data Transfers
EICAA is a Nigeria-based organisation, but as an alumni body with members dispersed across multiple countries, cross-border data transfer is a routine part of how we operate. We take this responsibility seriously and apply the highest international standard to all such transfers.
All international transfers of personal data are governed by the GDPR framework for cross-border transfers. Where personal data is transferred to countries not recognised as providing an adequate level of protection, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs)as approved by the European Commission — the primary mechanism we use for transfers outside the EU/EEA
- UK International Data Transfer Agreements (IDTAs)for transfers involving UK-resident members
- Adequacy decisionswhere the destination country has been recognised as providing adequate protection
- Your explicit informed consent to the specific transfer, where no other safeguard applies
Some of our service providers (such as cloud platforms or email tools) may process data on servers located in various countries. We vet all such providers to ensure they meet GDPR-equivalent standards and maintain appropriate data processing agreements with each.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:
| Data Category | Retention Period |
|---|---|
| Active Membership Data | Duration of membership + 5 years |
| Event Registration Data | 3 years following the event |
| Financial Transaction Records | 7 years (Nigerian financial regulations) |
| Communications and Correspondence | 3 years from date of last communication |
| Website Usage and Technical Data | Maximum 13 months |
| Inactive Account Data | Notified after 5 years of inactivity; then archived or anonymised |
Upon expiry of the applicable retention period, personal data will be securely deleted, anonymised, or archived, consistent with NDPA requirements.
Your Rights as a Data Subject
Under the GDPR and applicable data protection law, you have the following rights in relation to your personal data held by EICAA. These rights apply to all members regardless of country of residence:
10.1 How to Exercise Your Rights
Contact our Data Privacy Officer (see Section 14) with your full name, contact details, and a clear description of the right you wish to exercise. We will respond to all verified requests within 30 days of receipt. Complex or multiple requests may be extended by a further two months, of which we will notify you.
10.2 No Detriment
We will not discriminate against you, deny you services, or treat you less favourably for exercising any of your rights under this Policy.
Data Security
EICAA implements appropriate technical and organisational measures to protect your data against unauthorised access, accidental loss, alteration, disclosure, or destruction.
Technical Measures
- SSL/TLS encryption (HTTPS)
- Secure, access-controlled hosting
- Regular security assessments
- Firewalls and intrusion detection
- Secure, hashed password storage
- Regular software updates and patches
Organisational Measures
- Role-based access controls
- Data protection training for all staff
- Confidentiality agreements
- Documented Data Breach Response Plan
- Periodic internal audits
11.3 Data Breach Notification
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required under the GDPR (Article 33) and applicable law. Where the breach is likely to result in high risk to you personally, we will also notify you directly without undue delay (GDPR Article 34).
Children's Privacy
Protecting the privacy of children is a matter of particular importance to EICAA, given our close association with a secondary school whose students are primarily between the ages of 10 and 16.
In line with the GDPR and the UN Convention on the Rights of the Child (UNCRC), we define a child as any person under the age of 18 years. Our website is not directed at children under 18, and we do not knowingly collect personal data directly from minors without verified parental or guardian consent.
Where we become aware that personal data has been collected from a child without appropriate consent, we will take immediate steps to delete such data. If you believe that a child's data has been submitted to our website without proper consent, please contact us immediately.
Former students who graduated as minors and subsequently turn 18 may register as full alumni members with their own consent.
Third-Party Websites and Social Media
Our website may contain links to third-party websites, including the main EIC school website (www.eicjos.com.ng), social media platforms, and other external resources. These websites are governed by their own privacy policies, and EICAA accepts no responsibility or liability for their privacy practices.
When you click on such links and leave our website, we encourage you to review the privacy policy of the destination website. This Policy applies only to the EICAA website and not to any external sites.
Contact Us and Data Privacy Officer
If you have any questions, concerns, or complaints about this Privacy Policy or our data processing practices, or if you wish to exercise any of your rights under the GDPR or applicable data protection law, please contact our designated Data Privacy Officer:
Right to Lodge a Complaint with a Supervisory Authority
If you are not satisfied with how we handle your complaint, you have the right under the GDPR (Article 77) to lodge a complaint with a data protection supervisory authority. You may contact the authority in your country of residence or the authority where the alleged infringement occurred:
- EU members:Your national Data Protection Authority (DPA) — a full list is available atedpb.europa.eu
- UK members:Information Commissioner's Office (ICO) —ico.org.uk
- Nigeria-based members:Nigeria Data Protection Commission (NDPC) —ndpc.gov.ng| [email protected]
- All other members:The supervisory or data protection authority in your country of residence
Changes to This Privacy Policy
EICAA reserves the right to update or revise this Privacy Policy at any time, particularly in response to changes in applicable law, regulatory guidance, or our operating practices. Material changes will be communicated to registered members via email and announced prominently on the website.
The "Effective Date" at the top of this document indicates when the current version came into force. We encourage you to review this Policy periodically. Your continued use of the website after the posting of a revised Policy constitutes your acceptance of the updated terms. A version history log will be maintained and made available to members upon request.