Effective: 1 April 2026 Version 1.0 GDPR Compliant NDPA 2023 Compliant International Standard

Important Notice

This Privacy Policy applies to the official website of the Emmanuel International College Alumni Association ("EICAA"). By accessing or using this website, you confirm that you have read, understood, and agree to be bound by the terms of this Policy. If you do not agree, please discontinue use of the website.

01

About the Emmanuel International College Alumni Association

The Emmanuel International College Alumni Association ("EICAA", "we", "us", or "our") is the official alumni body of Emmanuel International College, a co-educational private Christian secondary school located at Road G, Da Chibi Rwang Street, Opposite the Old Government House Junction, Rayfield, Jos, Plateau State, Nigeria.

The school was incorporated as Emmanuel International College Limited (RC-469425) and is operated under the auspices of El-Shaddai Covenant Ministries, founded in 1986 by Dr. James Iruobe. The College runs both Junior Secondary School (JSS 1–3) and Senior Secondary School (SSS 1–3) programmes, providing six years of qualitative Christian-based education.

The EICAA website serves as a platform for connecting alumni, sharing news and events, facilitating membership registration, and preserving the heritage and community of EIC graduates and former staff.

Organisation
Emmanuel International College Alumni Association (EICAA)
School Location
Road G, Da Chibi Rwang Street, Opp. Old Government House Junction, Rayfield, Jos, Plateau State, Nigeria
School Website
Regulatory Body
Nigeria Data Protection Commission (NDPC)
02

Scope and Application of This Policy

This Privacy Policy governs all personal data collected, processed, stored, or transmitted through the EICAA website and any associated digital platforms, including but not limited to:

  • Alumni registration and membership portals
  • Contact and inquiry forms
  • Event registration pages
  • Newsletter and communications subscriptions
  • Donation or dues payment gateways
  • Social media integrations and linked third-party services

This Policy applies to all users of the EICAA website, including alumni, current students, parents, former staff, and any other visitors, regardless of their location within or outside Nigeria. It applies equally where personal data is processed by automated or manual means.

04

Personal Data We Collect

4.1 Data You Provide Directly

  • Identity Data:Full name, maiden name, graduation year, student identification number
  • Contact Data:Email address, telephone number, postal address
  • Academic Data:Years of attendance, class set, academic programmes, extracurricular activities
  • Professional Data:Current employer, job title, industry, professional qualifications, LinkedIn profile
  • Financial Data:Payment information for membership dues or donations (processed via secure third-party processors — we do not store raw card data)
  • Profile Data:Photographs, biographical information, and voluntarily submitted content
  • Communications Data:Messages, queries, feedback, or correspondence sent to us

4.2 Data Collected Automatically

  • IP address and approximate geographic location
  • Browser type, version, and operating system
  • Device type and screen resolution
  • Pages visited, links clicked, and time spent on pages
  • Referring URLs and search terms used to reach the site
  • Session duration and frequency of visits

4.3 Data from Third Parties

  • Social media platforms when you interact with our pages or use social login features
  • Other alumni or members who provide your contact details in the context of alumni activities
  • Emmanuel International College itself, in connection with verified alumni records
  • Payment processors and financial service providers, in relation to transaction confirmations

4.4 Special Categories of Data

We do not intentionally collect special categories of sensitive personal data (such as data revealing racial or ethnic origin, religious beliefs, health information, biometric data, or political opinions). If any such data is incidentally disclosed, we will handle it with additional care and will not process it beyond the purpose for which it was disclosed, unless we have obtained your explicit consent.

06

Cookies and Similar Tracking Technologies

Our website uses cookies and similar technologies to enhance your browsing experience and to gather usage analytics. A cookie is a small text file placed on your device by the website when you visit.

6.1 Types of Cookies We Use

  • Strictly Necessary Cookies:Essential for the website to function correctly (e.g., maintaining your session). These cannot be disabled.
  • Functional Cookies:Allow the website to remember your preferences for a more personalised experience.
  • Analytics Cookies:Help us understand how visitors interact with the website (e.g., Google Analytics).
  • Social Media Cookies:Set by social media platform integrations; governed by the respective platform's privacy policy.

6.2 Managing Your Cookie Preferences

On your first visit, a cookie consent banner will allow you to accept or reject non-essential cookies. You may update your preferences at any time through your browser settings. Disabling certain cookies may affect the functionality of parts of the website.

07

Disclosure and Sharing of Personal Data

7.1 Within the Association

Personal data may be shared internally among authorised EICAA officers, committee members, and volunteers who require access in the performance of their functions. All such persons are bound by confidentiality obligations.

7.2 Third-Party Service Providers

We engage reputable third-party service providers as data processors, contractually obligated to process your data only on our instructions and in accordance with the GDPR and applicable data protection law. These include:

  • Website hosting and cloud infrastructure providers
  • Email marketing platforms and newsletter services
  • Payment processors for membership dues and donations
  • Event management platforms
  • Analytics and website performance services

7.3 Emmanuel International College

We may share relevant alumni data with Emmanuel International College for the purpose of maintaining accurate alumni records and facilitating school-alumni engagement activities, subject to appropriate data protection agreements.

7.4 Legal Disclosures

We may disclose personal data where required by law, court order, or at the direction of a competent regulatory authority, including data protection supervisory authorities, law enforcement agencies, or other bodies with legal jurisdiction.

7.5 What We Will Never Do

  • Sell your personal data to any third party
  • Share your data with advertisers or commercial entities for marketing without your explicit consent
  • Transfer your data to organisations that do not provide adequate data protection safeguards
08

International Data Transfers

EICAA is a Nigeria-based organisation, but as an alumni body with members dispersed across multiple countries, cross-border data transfer is a routine part of how we operate. We take this responsibility seriously and apply the highest international standard to all such transfers.

All international transfers of personal data are governed by the GDPR framework for cross-border transfers. Where personal data is transferred to countries not recognised as providing an adequate level of protection, we ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs)as approved by the European Commission — the primary mechanism we use for transfers outside the EU/EEA
  • UK International Data Transfer Agreements (IDTAs)for transfers involving UK-resident members
  • Adequacy decisionswhere the destination country has been recognised as providing adequate protection
  • Your explicit informed consent to the specific transfer, where no other safeguard applies

Some of our service providers (such as cloud platforms or email tools) may process data on servers located in various countries. We vet all such providers to ensure they meet GDPR-equivalent standards and maintain appropriate data processing agreements with each.

09

Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law:

Data Category Retention Period
Active Membership Data Duration of membership + 5 years
Event Registration Data 3 years following the event
Financial Transaction Records 7 years (Nigerian financial regulations)
Communications and Correspondence 3 years from date of last communication
Website Usage and Technical Data Maximum 13 months
Inactive Account Data Notified after 5 years of inactivity; then archived or anonymised

Upon expiry of the applicable retention period, personal data will be securely deleted, anonymised, or archived, consistent with NDPA requirements.

10

Your Rights as a Data Subject

Under the GDPR and applicable data protection law, you have the following rights in relation to your personal data held by EICAA. These rights apply to all members regardless of country of residence:

Right to Access
Request a copy of the personal data we hold about you
Right to Rectification
Request correction of inaccurate or incomplete data
Right to Erasure
Request deletion of your data in certain circumstances
Right to Object
Object to processing based on legitimate interests
Right to Restrict
Request that we limit how we use your data
Right to Portability
Receive your data in a structured, machine-readable format
Withdraw Consent
Withdraw consent at any time without affecting prior lawful processing

10.1 How to Exercise Your Rights

Contact our Data Privacy Officer (see Section 14) with your full name, contact details, and a clear description of the right you wish to exercise. We will respond to all verified requests within 30 days of receipt. Complex or multiple requests may be extended by a further two months, of which we will notify you.

10.2 No Detriment

We will not discriminate against you, deny you services, or treat you less favourably for exercising any of your rights under this Policy.

11

Data Security

EICAA implements appropriate technical and organisational measures to protect your data against unauthorised access, accidental loss, alteration, disclosure, or destruction.

Technical Measures

  • SSL/TLS encryption (HTTPS)
  • Secure, access-controlled hosting
  • Regular security assessments
  • Firewalls and intrusion detection
  • Secure, hashed password storage
  • Regular software updates and patches

Organisational Measures

  • Role-based access controls
  • Data protection training for all staff
  • Confidentiality agreements
  • Documented Data Breach Response Plan
  • Periodic internal audits

11.3 Data Breach Notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required under the GDPR (Article 33) and applicable law. Where the breach is likely to result in high risk to you personally, we will also notify you directly without undue delay (GDPR Article 34).

12

Children's Privacy

Protecting the privacy of children is a matter of particular importance to EICAA, given our close association with a secondary school whose students are primarily between the ages of 10 and 16.

In line with the GDPR and the UN Convention on the Rights of the Child (UNCRC), we define a child as any person under the age of 18 years. Our website is not directed at children under 18, and we do not knowingly collect personal data directly from minors without verified parental or guardian consent.

Where we become aware that personal data has been collected from a child without appropriate consent, we will take immediate steps to delete such data. If you believe that a child's data has been submitted to our website without proper consent, please contact us immediately.

Former students who graduated as minors and subsequently turn 18 may register as full alumni members with their own consent.

13

Third-Party Websites and Social Media

Our website may contain links to third-party websites, including the main EIC school website (www.eicjos.com.ng), social media platforms, and other external resources. These websites are governed by their own privacy policies, and EICAA accepts no responsibility or liability for their privacy practices.

When you click on such links and leave our website, we encourage you to review the privacy policy of the destination website. This Policy applies only to the EICAA website and not to any external sites.

14

Contact Us and Data Privacy Officer

If you have any questions, concerns, or complaints about this Privacy Policy or our data processing practices, or if you wish to exercise any of your rights under the GDPR or applicable data protection law, please contact our designated Data Privacy Officer:

Data Privacy Officer
Role[Name of DPO — to be appointed by the Association]
OrganisationEmmanuel International College Alumni Association (EICAA)
AddressC/O Emmanuel International College, Road G, Da Chibi Rwang Street, Opp. Old Government House Junction, Rayfield, Jos, Plateau State, Nigeria
Email[insert privacy contact email]
ResponseWithin 30 days of receipt of your request

Right to Lodge a Complaint with a Supervisory Authority

If you are not satisfied with how we handle your complaint, you have the right under the GDPR (Article 77) to lodge a complaint with a data protection supervisory authority. You may contact the authority in your country of residence or the authority where the alleged infringement occurred:

  • EU members:Your national Data Protection Authority (DPA) — a full list is available atedpb.europa.eu
  • UK members:Information Commissioner's Office (ICO) —ico.org.uk
  • Nigeria-based members:Nigeria Data Protection Commission (NDPC) —ndpc.gov.ng| [email protected]
  • All other members:The supervisory or data protection authority in your country of residence
15

Changes to This Privacy Policy

EICAA reserves the right to update or revise this Privacy Policy at any time, particularly in response to changes in applicable law, regulatory guidance, or our operating practices. Material changes will be communicated to registered members via email and announced prominently on the website.

The "Effective Date" at the top of this document indicates when the current version came into force. We encourage you to review this Policy periodically. Your continued use of the website after the posting of a revised Policy constitutes your acceptance of the updated terms. A version history log will be maintained and made available to members upon request.

16

Definitions and Glossary

Data Controller
EICAA, which determines the purposes and means of processing personal data.
Data Processor
Any third-party entity that processes personal data on behalf of EICAA under a data processing agreement.
Data Subject
Any identified or identifiable individual whose personal data is processed by EICAA — in most cases, an alumnus, member, or website visitor.
Personal Data
Any information relating to an identified or identifiable natural person, including name, email address, identification number, location data, and online identifiers.
Processing
Any operation performed on personal data, including collection, storage, use, disclosure, alteration, or deletion.
NDPA
The Nigeria Data Protection Act 2023.
NDPC
The Nigeria Data Protection Commission, the independent supervisory authority established under the NDPA.
GAID
The General Application and Implementation Directive 2025, issued by the NDPC to guide implementation of the NDPA.
Consent
A freely given, specific, informed, and unambiguous indication by a data subject of their agreement to the processing of their personal data.
Cookies
Small data files stored on a user's device by a website to remember preferences and gather analytics.
Data Breach
A security incident resulting in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
Special Categories
Sensitive personal data including racial or ethnic origin, political opinions, religious beliefs, health data, biometric data, and similar categories afforded heightened protection.