Legal
Privacy Policy
Last updated
1. What we collect
We collect information you give us directly and information generated by your use of the platform.
Account & profile data
- Email address and secure password
- Display name, profile photo, bio, and country of origin
- Current city, languages spoken, and interest tags
Activity data
- Forum posts, replies, and upvotes you create
- Events you create or RSVP to
- Groups you join or create
- Notifications sent to your account
Technical data
- IP address and approximate location (country/city level)
- Browser type, device type, and operating system
- Session tokens stored in HTTP-only cookies
- Basic access logs retained by our infrastructure provider
We do not collect payment card details. We do not use advertising trackers or sell your data to third parties.
2. Why we collect it
We process your data on the following legal bases:
Performance of a contract
To create and maintain your account, display your profile, and deliver the core features of the platform (posts, events, groups, notifications).
Legitimate interests
To detect abuse, prevent fraud, moderate reported content, send transactional emails (RSVP confirmations, event reminders, reply notifications), and improve the platform based on aggregated usage patterns.
Consent
Where we ask for optional email preferences (marketing updates or announcements), we rely on your explicit consent. You may withdraw consent at any time from your profile settings.
Legal obligation
To comply with applicable laws, including responding to lawful requests from public authorities.
3. Data retention
We retain your data for as long as your account is active or as needed to provide the service.
- Account and profile data: retained until you delete your account
- Forum posts and replies: retained until you or a moderator removes them
- Event RSVPs: retained for 12 months after the event date
- Notification records: deleted after 90 days
- Access logs: deleted after 30 days
- Deleted account data: anonymised within 30 days of deletion request
When you delete your account, your profile is anonymised and identifying fields (display name, email, avatar, bio) are cleared. Community content (posts, replies) is attributed to “[deleted user]” unless you request full removal.
4. Your rights
If you are in the European Economic Area (EEA) or the United Kingdom, you have the following rights under the GDPR / UK GDPR:
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate or incomplete data
- Erasure — ask us to delete your personal data ("right to be forgotten")
- Restriction — ask us to pause processing your data in certain circumstances
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interests
- Withdraw consent — for any processing based on your consent, at any time
To exercise any of these rights, email us at privacy@africonnect.app. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
5. Contact us
If you have any questions about this policy or how we handle your data, please reach out:
We may update this policy from time to time. Material changes will be announced via an in-app notification. Continued use of AfriConnect after the effective date constitutes acceptance of the updated policy.