Legal

Privacy policy.

What we collect about you and your learners, why we collect it, who else sees it, and how to get it back or get rid of it. Written to be read, not to be survived.

Effective 9 August 2026 · Last revised 9 August 2026

1. Who we are and what this covers

This policy explains how Elitesgen Academy collects, uses and protects personal information across three places: this website (egenacademy.com and its program and school subdomains), the Egen Academy app used by learners and their parents or guardians, and the Egen Academy Team app used by our instructors and coordinators.
It is written to align with the Nigeria Data Protection Act 2023 and the Nigeria Data Protection Regulation.
The data controller for the information described here is Elitesgen Egen Limited (RC 8151916), of Magodo, Lagos, Nigeria, trading as Elitesgen Academy.

2. Information you give us

Account and contact details. When you create an account we collect a salutation, your first and last name, email address, Nigerian phone number, date of birth and a password. You may also give us a referral code. If you edit your profile you can add a home address (street, local government area, state and postcode), and a profile photo and cover photo.
You must be 18 or older to create an account for yourself. If you enter a date of birth under 18 during sign-up, the app stops and asks for a parent or guardian instead, and clears the details you had entered.
Learner details. Parents and guardians add the children and dependants in their care. For each one we collect a first and last name, the relationship to you, and optionally a date of birth, a phone number, the program they are joining and their starting level. If you choose to give a child their own login, we also collect an email address and password for them.
Enrolment and registration details. When you enrol, we collect the program, session plan and venue you choose, and the answers to any registration questions the program asks. Some registration forms accept file uploads, and some accept a payment receipt image.
Health and emergency information. See section 3, which covers this separately because it deserves to be read on its own.
Things you send us. Messages you send through our contact and enquiry forms, and anything you tell us when you contact support.

3. Health and emergency information about learners

Read this one

We ask for medical information about learners, and most of our learners are children. This section says plainly what we collect, who can see it, and how to have it removed.

What we collect. Medical conditions, known allergies, an emergency contact name, phone number and relationship, and whatever you write in a free-text box that asks for anything else we should know about, which gives allergies and injuries as examples. Where a program runs its own registration form, that form can also ask for current medications and for a doctor's name and number. Our own enrolment forms do not ask for those.
Where it is collected. Three places: the enrolment flow on this website and in the family app, the profile screen (medical conditions only, and only for a learner editing their own profile), and a program's own registration form, which has medical and emergency-contact sections its operator configures.
Who can see it. The learner, their parent or guardian, and the instructors and coordinators assigned to their program, who see it in a Contact and Medical section on the learner's record in the team app. That is the point of collecting it: a coach in the water needs to know about a learner's asthma or nut allergy before an incident, not after. There is no separate approval step for staff to view it beyond their assignment to that program.
Why we are allowed to hold it. We rely on the enrolment contract you enter into with us, and on the protection of vital interests where information is needed to respond to a medical emergency during a session.
How to change or remove it. Edit it in the app, or email support@egenacademy.com and we will update or clear it. If you clear it, staff will no longer see anything, so tell your coordinator if there is something they still need to know verbally.
How it is stored. In our main database, protected by access controls that limit each record to the programs it belongs to. It is not encrypted in a separate vault, it is not used for analytics, and it is not included in the staff-facing roster exports.

4. Photos, video and audio

Profile and cover photos. You choose these yourself, from your camera or photo library.
Performance video and audio of learners. Instructors using the team app can record video, with sound, of a learner during a session as part of assessment and coaching feedback. The recording is filed against that learner and appears in the Gallery in the family app, where the learner and their guardian can watch it and save it to their own device.
You can tell us not to record a particular learner. Speak to your coordinator or email us, naming the learner, and we will pass it to the coaches working with them and stop. You do not have to give a reason, it does not affect their place in the program, and you can ask us to delete recordings already made at the same time.
The address for that is support@egenacademy.com.
Attachments. Photos and documents can be attached to messages. Messaging is switched off in the current release of both apps, so no message attachments are being collected today. See section 7.
Where media is kept. Photos, videos and attachments are stored with Cloudflare (R2 object storage). Private files are never served from a public address; the apps request a short-lived link that expires after fifteen minutes.

5. Payments

Payments are processed by Paystack, a licensed Nigerian payment provider. When you pay, the app opens Paystack's own checkout page in a secure in-app browser. Card numbers, expiry dates and security codes are entered there, on Paystack's page. They are never entered in our apps and our systems never receive them.
What we do keep. The payment amount and reference, whether it succeeded, and what it was for. If you save a card for next time, we keep the card brand, the last four digits, the expiry month and year, any nickname you give it, and a reusable token issued by Paystack. That token can only be used to charge your card through Paystack; it is not a card number.
For bank transfers made through the public registration flow, we keep the account details shown to you and any payment receipt you upload.
Deleting your account deletes our copy of your saved cards, and we then ask Paystack to revoke the tokens. If that request to Paystack fails, the deletion still goes through, so tell us or tell your bank if you want to be certain a saved card can never be charged again.

6. Location

Egen Academy does not collect location.The released version of the family app has location removed at build time: the permission strings are stripped from the iOS build, the Android location permissions are blocked, and precise location is removed from the app's iOS privacy manifest. The app cannot ask for your location, and there is a test in the codebase that fails if that ever changes.
Egen Academy Team collects location at clock-in. When a staff member clocks in or out of a shift, the app records where they are at that moment, to confirm the shift was worked on site. This is foreground only: it happens while the person is actively using the clock-in screen, and neither app ever requests background location.

7. Messages

One-to-one messaging is switched off in the current release of both apps. It was held back deliberately rather than shipped unmoderated. So today we do not collect message content, attachments, read receipts, typing indicators or online status from either app.
If we turn messaging on in a future release, we will update this policy before it reaches you. Announcements and updates we send you are separate and do work today; those are one-way and we do not collect a reply.

8. Information we collect automatically

Notifications. If you allow notifications, we store a push token for your device, which platform it is (iOS or Android), and which of our apps it belongs to. It is deleted when you sign out. The token is issued by Expo, whose push service delivers through Apple and Google.
Crash and error reports. Both apps and our servers send crash and error reports to Sentry so we can fix faults. We configure Sentry not to send personal information: names, email addresses, usernames, phone numbers and IP addresses are removed before a report leaves your device, along with passwords, tokens, one-time codes, card and identity numbers. A report that cannot be cleaned is discarded rather than sent.
An opaque account identifier is kept on those reports, because knowing that one person hit the same crash five times rather than five people hitting it once is what makes a crash fixable. It is a random identifier and means nothing without our database.
Crash reports are not collected in internal development builds, and neither app records your screen or takes screenshots.
Website analytics. This website uses PostHog to understand which pages people visit, and Vercel Analytics and Speed Insights to measure page performance. Analytics requests are routed through our own domain. The mobile apps contain no analytics or advertising software at all, and neither app tracks you across other companies' apps or websites.

9. What is stored on your own device

Some information stays on your phone or computer rather than being sent to us:
  • Your sign-in tokens and a copy of your profile, held in your device's encrypted storage so you stay signed in.
  • A cached copy of recently loaded screens, so the apps work when your connection drops.
  • Work you have not finished uploading, such as an offline registration submission or a queued assessment, held until it uploads.
  • A part-finished sign-up, including the name, email, phone number and date of birth you had entered, held so you can pick up where you left off. This one is not in encrypted storage, and it is cleared when you finish signing up.
  • On this website, a part-finished enrolment, including learner names, dates of birth and any medical notes you typed. It is stored only in your own browser, expires after seven days, is cleared when you complete the enrolment, and there is a visible control to clear it yourself. Use that control if you are on a shared or public computer.
Signing out of the apps clears the stored session.

10. How we use information

We use personal information to:
  • run your account and the programs you or your learners are enrolled in;
  • schedule sessions, take attendance, record assessments and issue certificates;
  • keep learners safe during sessions, including acting on medical and emergency information;
  • take payment and keep the financial records the law requires us to keep;
  • send you confirmations, reminders, schedule changes and announcements;
  • answer you when you contact us;
  • keep accounts secure and prevent fraud and unauthorised access; and
  • find and fix faults in our apps and website.
We do not sell personal information, and we do not use it to build advertising profiles.

11. Our lawful bases

Under the Nigeria Data Protection Act we rely on:
  • Contract, to deliver the programs you enrol in, take payment and run your account;
  • Legal obligation, to meet tax, accounting and record-keeping requirements;
  • Vital interests, where health or emergency information is needed to respond to an incident during a session;
  • Legitimate interests, for security, fraud prevention, fixing faults and improving what we offer; and
  • Consent, for optional things you switch on yourself, such as notifications, SMS updates and access to your camera or photo library. You can withdraw consent at any time in your device settings or in the app.
Where a learner is a child, their parent or guardian is the person who enters into the enrolment contract with us, makes the optional choices listed above, and exercises these rights on the child's behalf.

12. Who we share information with

We share personal information only with the companies that help us run the service, each under contract and each limited to the job we give them:
  • Paystack, for payments and saved-card tokens.
  • Brevo, for the emails we send you.
  • Africa's Talking, for SMS messages, where SMS is switched on.
  • Meta, for WhatsApp messages, where you have chosen to receive them on WhatsApp.
  • Cloudflare, for storing photos, videos, attachments and files.
  • Expo, Apple and Google, for delivering push notifications to your device.
  • Sentry, for crash and error reports, with personal information removed as described in section 8.
  • PostHog and Vercel, for website analytics and performance measurement on egenacademy.com.
  • An identity verification provider, only where an organisation, partner or facility account requires identity checks. Families enrolling in programs are not asked to verify identity.
We also share information where the law requires it, where a court orders it, or where it is necessary to protect someone from harm.
If a program is run in partnership with a school or an organisation, we share with that partner what it needs to administer its own participants.

13. Where information is held

Our systems are hosted with providers outside Nigeria, and several of the companies in section 12 process information outside Nigeria. Where information leaves Nigeria we rely on the safeguards the Nigeria Data Protection Act permits, normally contractual protections with the provider that hold them to an equivalent standard.

14. How long we keep information

We keep the records that make up your account and your learners' history for as long as the account is open, and for as long as we need them to deliver the service. We do not run a fixed countdown on enrolment, attendance, assessment or certificate records: they are what a program is, and a certificate has to stay verifiable. Closing your account is what removes your personal details from those records, and the delete account page sets out exactly what that reaches and what it does not.
Some things are deleted automatically, on a timer, whether you ask or not:
  • Password reset links, after 30 days. Emailed one-time codes, after a day.
  • The queue rows that record us sending you an email or an SMS, after 7 days once the message has gone. A message that failed for good is kept instead, so we can find out why.
  • Files uploaded but never attached to the record they belonged to: after 24 hours if the upload never finished, or after 7 days if it finished but the record it was meant for was still waiting to sync from someone's phone. For the incident and routine logs our staff file, both our record of the file and the stored file itself are deleted. A file that did get attached is never swept, because at that point it is part of the safety record.
  • The technical rows that log an upload happening, after 48 hours.
  • Where messaging is switched on, the note of when an account was last active, after 60 days.
  • An account that was created and then never used, with no learner, no enrolment and no connection to anyone else, is deactivated after 30 days. Deactivated, not deleted: it stops working, and it stays on record.
That list is what the system enforces by itself. It is not a full retention schedule, and we would rather say so than imply a countdown exists on records where it does not.
We keep payment, order and invoice records for six years after an account closes, because tax and accounting law requires it. We keep employment records for staff for the period employment law requires. We keep our security audit log, which exists precisely so that a record of who did what survives.
Messages sent inside the service are not on a deletion timer at all. Messaging is switched off in the current release, so there is nothing being collected today, but if we switch it on we will set a retention period and say so here before it reaches you.

15. Closing your account

You can close your account yourself, in either app: Menu, then Privacy & Data, then Delete my account. It happens immediately and cannot be undone. The full detail of what is removed and what is kept, and how to ask us to do it if you cannot use the app, is on the delete account page.
In short: your name, contact details, date of birth and home address are erased, the photos are removed from your account, your password is destroyed, you are signed out everywhere, our copy of your saved cards is deleted, and your email address is freed so it can be used again. Your enrolment, attendance, assessment and certificate history remains, with your name and contact details taken off it. Financial records, identity-check records and our audit log remain, as described on the delete account page.
Two things to be aware of. Messages you have already sent to another person stay in that conversation, in the same way an email you sent stays in the recipient's inbox. And deleting your own account does not delete the profiles of children in your care: tell us if you want those removed too, and we will do it.

16. Your rights

Under the Nigeria Data Protection Act you have the right to:
  • ask what personal information we hold about you and get a copy of it;
  • have inaccurate or incomplete information corrected;
  • have your information deleted, subject to the records we must keep by law;
  • object to particular uses of your information, and withdraw consent where we relied on it;
  • ask us to restrict how we use your information while a dispute is resolved; and
  • complain to the Nigeria Data Protection Commission.
Most of this you can do yourself in the app. For anything else, email support@egenacademy.com from the address on your account so we can confirm it is you. We handle these requests by hand rather than through an automated download, and we respond within 30 days. If you are asking on behalf of a child in your care, say so and tell us which learner.
Staff accounts work differently. An instructor or coordinator account is created and closed by the academy, so if you want yours closed, ask your coordinator or email us and we will handle it. Employment records we are required to keep are retained regardless.

17. Children

Our programs are for children, teenagers and adults, and most of our learners are under 18. That shapes how the service is built.
  • Nobody under 18 can create their own account. Sign-up asks for a date of birth and stops if the person is a minor, directing them to a parent or guardian.
  • A child is added by their parent or guardian, who decides what we are told about them.
  • A guardian may give a child their own login to see their own schedule and progress. The guardian still controls the profile.
  • Learner profiles are not searchable or discoverable by other users.
  • Messaging between users is switched off, so there is no open channel to a child in the app.
A parent or guardian can see, correct or delete anything we hold about a child in their care, in the app or by emailing support@egenacademy.com. If you believe we hold information about a child that was given to us by someone with no authority to give it, tell us and we will remove it.

18. Security

We protect information with encrypted connections, role-based access limited to the programs a member of staff works on, tenant isolation in the database, an audit log of administrative actions, and encrypted storage for your session on your own device.
No system is perfectly secure. If a breach occurs that meets the notification threshold under the Nigeria Data Protection Act, we will notify the Nigeria Data Protection Commission and the people affected, within the time the law requires.

19. Changes to this policy

We update this policy when the service changes or the law does. If a change is material, we will tell you in the app or by email before it takes effect. The revision date at the top of this page always shows the current version.

20. Contact us

Privacy questions and requests: support@egenacademy.com. Anything else: support@egenacademy.com or the contact page.
We have not designated a Data Protection Officer. Data-protection questions, access requests and any other right under the Nigeria Data Protection Act go to the address above, and a person answers them.
You can also complain to the Nigeria Data Protection Commission if you believe we have handled your information wrongly.