Skip to content
← Back

Privacy Policy

Version 2.0 · Effective 14 September 2026

This policy explains what personal information Digital Learning Academy (the “Platform”) holds about you, why we hold it, who else sees it, where it is stored and what you can do about it. It is written to be read, not filed. Where the Platform does something that members would not expect, we say so here rather than leave it out.

1. Who is responsible for your information

The SADC Development Finance Resource Centre (“the Centre”, “we”, “us”) is the responsible party for the personal information described in this policy. In the language of the Botswana Data Protection Act the Centre is the data controller; in the language of POPIA it is the responsible party. The Centre is based in Gaborone, Botswana.

Legal entity
SADC Development Finance Resource Centre
Registered office
Gaborone, Botswana. [TO CONFIRM: full street address, postal address and plot number of the registered office.]
Registration
[TO CONFIRM: registration or establishment number and the instrument under which the Centre is constituted.]
Platform
Digital Learning Academy, at lms.sadc-dfrc.org

2. The law we work to

Members are spread across the SADC region and the data-protection law that applies to you depends on where you are. Rather than publish a different policy for each country, we have drafted to the strictest common standard, which in practice means the following two regimes. Meeting them satisfies the others.

  • Botswana: the Data Protection Act 18 of 2024, which came into force on 14 January 2025 and repealed the Data Protection Act of 2018. The regulator is the Information and Data Protection Commission (IDPC).
  • South Africa: the Protection of Personal Information Act 4 of 2013 (POPIA), together with the Promotion of Access to Information Act 2 of 2000 (PAIA). The regulator is the Information Regulator (South Africa).
  • Other member states with data-protection law in force include Angola, Eswatini, Lesotho, Madagascar, Malawi, Mauritius, Seychelles, Tanzania (with enforcement from April 2026), Zambia and Zimbabwe. Namibia and Mozambique have bills before their legislatures rather than law in force.
  • The SADC Model Law on Data Protection is guidance to member states, not binding law, but we have used it as a sense-check on this policy.

If the law where you live gives you a stronger right than this policy describes, that stronger right applies and you should simply ask us for it.

3. Information Officer

POPIA section 55 requires a named Information Officer, and the Botswana Act requires a responsible contact point for data-protection matters. The same person performs both roles for the Platform, and is the single address for every request, question or complaint described in this policy.

Information Officer
Bryan Mashaleng
Position
[TO CONFIRM: job title and reporting line of Bryan Mashaleng.]
Deputy Information Officer
Maipelo Stroh [TO CONFIRM: position.]
Registration with the Information Regulator
[TO CONFIRM: whether the Information Officer has been registered with the South African Information Regulator, and the registration reference.]

Until a dedicated privacy mailbox is published, every request reaches the Information Officer at SADC-DFRC@socoed.com. Put “Data protection” in the subject line and we will route it correctly. [TO CONFIRM: whether a dedicated address such as privacy@sadc-dfrc.org should be created and published here instead.]

4. What the Platform collects

This is the complete list, described in the terms the system actually uses rather than in generalities.

  • Account and profile: your first name, last name and display name, email address, password (stored as a hash, never in readable form), phone number, organisation and structured institution, country and country code, job title, headline, biography, skills, work history, and your profile photo. Your language preference and your three email-notification preferences are stored on the same record.
  • Your profile photo is stored inside the database: when you upload an avatar it is held as an encoded image inside the main database rather than as a separate file. That means a copy of your photo is present in every database backup, and it is removed from those backups only as the backups themselves age out. If you would prefer no photo, leave the avatar empty and the Platform shows your initials.
  • Learning records: course enrolments, cohort membership, lesson progress, completion dates, credentials earned and CPD points.
  • Video and lesson telemetry: the Platform records granular playback data per lesson: total seconds watched, the position you last scrubbed to, the lesson duration, the time of your last heartbeat while a video is open, and the time you were last active. This is what makes completion tracking and resume-where-you-left-off work, and it is detailed enough to show when and for how long you studied.
  • Assessment data: every quiz attempt is kept, including the attempt number, the score, whether you passed, the language you took it in, and the full set of answers you gave, stored as structured data. Answers are retained, not just scores, because credential integrity depends on being able to re-examine an attempt if a result is challenged.
  • Content you create: posts, comments, likes, group discussions, event registrations and RSVPs, connection requests, and the documents you upload.
  • Direct messages: the body of every direct message and group conversation is stored in our database in readable form. Messages are not end-to-end encrypted. They are protected in transit and by access controls, and they are not read as a matter of course, but a small number of authorised administrators and engineers can technically access them, and we can be compelled to produce them by a lawful order. Do not use Platform messaging for anything you would not put in a work email.
  • Sign-in with Google: if you sign in with Google we store the access token, refresh token and identity token that Google issues, together with their expiry times and the scopes granted. These are currently held in the database as ordinary text columns rather than in a separate encrypted store. They let the Platform confirm who you are; they are not used to read anything else in your Google account. You can disconnect Google at any time by writing to the Information Officer, and we will delete the stored tokens. [TO CONFIRM: target date for moving these token columns to encrypted-at-rest storage.]
  • Session and device records: each sign-in creates a session record holding your IP address, your browser user-agent string, and the session creation and expiry times.
  • Presence: so that the Platform can show who is around, we keep one rolling record per member with the time you were last seen and the IP address and user agent you were last seen from. It is overwritten as you use the Platform rather than accumulated as a history.
  • Failed sign-in attempts: when a sign-in fails we record the email address that was typed, the IP address and the user agent. This is a security control against password guessing. It means we may hold a record containing an email address belonging to someone who has no account with us, for example when a member mistypes their own address or when an attacker tries a list of addresses. We do not use these records for any purpose other than security, and we do not contact the addresses in them.
  • Consent records: when you accept the Terms of Service and this Privacy Policy we record which version you accepted and when, so that both sides can show what was agreed.

The Platform does not collect special categories of personal information such as health, biometric, religious or political data, and you should not put such information into your profile, posts or messages.

5. Where the information comes from

Most of it comes from you directly, when you register, complete your profile, take a course or post something. Some comes from your device automatically, such as your IP address and browser type. Some may come from your institution, where it nominates you for a programme and supplies your name, work email and role. If you sign in with Google, your name, email address and Google account identifier come from Google.

6. Why we process it, and on what basis

Every processing activity on the Platform rests on one of the following grounds, which exist in equivalent form in the Botswana Act and in POPIA:

  • Performance of our agreement with you: running your account, your profile, your network, your courses, your messages and your credentials. Without this processing there is no Platform.
  • Your consent: accepting the Terms and this policy at registration, choosing which notification emails to receive, and choosing to upload a photo. You can withdraw consent for the optional items at any time in Settings, or for everything by asking us to close your account.
  • Our legitimate interests, balanced against yours: keeping the Platform secure, preventing password guessing and abuse, maintaining the integrity of assessments and credentials, diagnosing faults, and understanding usage in aggregate so the service improves.
  • Compliance with a legal obligation: responding to lawful requests, keeping consent records, and notifying a regulator of a breach when the law requires it.
  • The legitimate interests of your institution, where you take part in a programme it sponsors, in knowing whether its nominees enrolled and completed.

We do not sell personal information, we do not use it for third-party advertising, and we do not profile members for marketing.

7. What other members can see

The Platform is a professional network, so parts of your profile are deliberately visible. Your name, photo, headline, job title, institution and country are visible to other signed-in members, as are the posts and comments you publish and the groups and events you join. Direct messages are visible only to their participants. Credential verification pages show the credential, the holder’s name and the issue date to anyone you share the verification link with. Your assessment answers and scores are not visible to other members. Your email address, phone number, IP address and sign-in history are never shown to other members.

8. Who we share it with

We share personal information in three situations, and no others.

  • Your institution. Where you take part in a programme sponsored by your employer or by a member development finance institution, we report enrolment, progress and completion status to that institution. We do not share your messages, your posts or your individual assessment answers with it.
  • Our service providers. The suppliers listed in the table below process data on our behalf under contract and may not use it for their own purposes.
  • Legal requirements. Where disclosure is required by law, by a court, or by a competent authority. Where we are allowed to tell you, we will.
Sub-processors
ProviderWhat it does for usWhereWhat it can see
Hetzner Online GmbHHosting of the servers and databases that run the PlatformHelsinki, Finland (European Union)All Platform data at rest, including profiles, learning records, messages and backups
Cloudflare, Inc.Content delivery, protection against attack, and R2 object storage for course mediaGlobal edge network; R2 bucket region [TO CONFIRM.]IP addresses and request metadata for every page you load, plus stored course media files
Sentry (Functional Software, Inc.)Error monitoring, performance tracing and session replay. See the note below the table.European Union (Sentry EU data region)Error diagnostics, the URL you were on, browser and IP, and a masked recording of the screen when an error occurs
Google (Google Ireland Limited / Google LLC)Sign in with Google, for members who choose itIreland and the United StatesThe fact that you signed in, your Google account identifier, name and email address
Transactional email relayDelivery of service email: verification, password reset, course and event noticesJohannesburg, South Africa [TO CONFIRM: registered name of the relay operator.]Your name, your email address and the content of the service emails we send you
Anthropic PBCTranslation. When you press “See translation” on a post, comment or institution description, that text is sent to Anthropic to be translated into your chosen language, and the translation is stored so that the next person to ask does not send it again. Translation happens only when somebody asks for it: nothing is sent automatically, and nothing you write is sent because you wrote it. An AI assistant service is also deployed in the Platform stack but is not connected to any member-facing feature, so nothing is sent to it.United StatesThe text a reader asks to have translated, and the language they want it in. No name, email or account identifier accompanies it.
UnsplashDecorative photography on catalogue and resource pages, loaded directly by your browserUnited StatesYour IP address and browser details, because your browser fetches the image from them
flagcdn.comCountry flag images in member and institution listings, loaded directly by your browser[TO CONFIRM: operating company and country for flagcdn.com.]Your IP address and browser details, because your browser fetches the image from them

Sentry session replay, in plain terms. When the Platform hits an error, Sentry can record a reconstruction of what was on your screen so engineers can see what went wrong. This is limited in three ways: it runs only on errors and only on about a quarter of them, all text is masked before it leaves your browser, and images and video are blocked. It is not a general recording of your activity, and normal sessions without an error are not recorded. We have enabled masking specifically because the Platform displays message bodies, member names and email addresses.

A note on analytics, to be accurate rather than reassuring. The Platform’s code includes a product-analytics library (PostHog), but no key is configured for it, so it does not load and no analytics events are being collected. If we ever turn it on we will update this policy and the Cookie Policy before doing so. The previous version of this policy described our analytics as first-party; that was not correct and has been removed.

Search (Meilisearch), caching (Redis) and the content management system (Strapi) run on the Centre’s own servers and are not third parties.

9. Sending information across borders

The Platform is hosted in the European Union. Members are in Botswana, South Africa and the other SADC member states. Your information therefore leaves your country every time you use the Platform, and comes back to your screen the same way. Both the Botswana Act and POPIA allow this where safeguards are in place, and these are ours:

  • the European Union provides a level of data protection that is recognised internationally as adequate, and the hosting contract binds the provider to it;
  • all traffic between your device and the Platform is encrypted in transit, and backups are encrypted;
  • each sub-processor listed above is engaged under a written contract that restricts it to processing on our instructions [TO CONFIRM: that a signed data processing agreement is on file for each provider in the table, and that standard contractual clauses are in place where the provider is in the United States];
  • the Centre remains responsible to you for what these providers do with your information.

If you object to your information being hosted in the European Union, the Platform cannot be provided to you, and you should tell us so that we can close your account.

10. How long we keep it

Each category of data has its own period, set out in full in the Data Retention Schedule. In summary: account and profile data is kept while your account is open and for a short wind-down period afterwards; learning records are kept for several years so that progress and CPD can be evidenced; credential records are kept long term so that certificates already issued remain verifiable; and security logs are kept for months, not years.

11. Security

What we do:

  • all traffic is encrypted in transit using TLS;
  • passwords are stored as hashes and cannot be read back, by us or by anyone else;
  • staff access is limited by role to what the role requires, and administrative access is restricted to a small number of people;
  • failed sign-in attempts are recorded and monitored;
  • backups are encrypted, and the servers sit behind a protected network edge.

What we want you to know is not yet in place:

  • direct messages are stored in readable form and are not end-to-end encrypted;
  • Google sign-in tokens are held in ordinary database columns rather than in a dedicated encrypted store;
  • there is no self-service data export and no self-service account deletion, so those requests are handled manually by the Information Officer.

No system is perfectly secure. If a breach affects your personal information we will notify you and the relevant regulator as the law requires, without undue delay, and we will tell you what happened, what we are doing about it and what you should do.

12. Your rights, and how to use them

Subject to the law that applies to you, you have the right to:

  • be told what personal information we hold about you and why;
  • get a copy of it;
  • have inaccurate or incomplete information corrected, which for most profile fields you can do yourself in Settings;
  • have information deleted, subject to the retention rules that apply to credentials and to records we must keep by law;
  • object to processing based on legitimate interest, and ask us to restrict processing while an objection is considered;
  • receive the information you gave us in a portable, machine-readable format;
  • withdraw consent where processing rests on consent, without affecting what was done before you withdrew it;
  • complain to a data-protection authority, without going through us first.

There is no button for any of this yet, and we would rather say so than imply otherwise. Every request is handled by hand. Email the Information Officer at SADC-DFRC@socoed.com, say which right you are exercising, and tell us the email address on your account so we can find it.

We acknowledge within 5 working days and respond substantively within 30 calendar days. If a request is complex we may need longer, in which case we will tell you before the 30 days are up, explain why, and give you a date. There is no charge for a first request; we may charge a reasonable fee for repeated or clearly excessive requests, and we will tell you the amount before doing any work. Where we refuse, we will say why and tell you how to challenge it.

We will ask you to confirm your identity before releasing or deleting anything, normally by replying from the email address on the account. This protects you from someone else making a request in your name.

13. Complaints

Please come to us first, because most things are quicker to fix directly. But you do not have to, and you can go to a regulator at any time.

  • Botswana: the Information and Data Protection Commission (IDPC), the authority established under the Data Protection Act 18 of 2024. [TO CONFIRM: current postal address, telephone number, email address and complaint portal for the IDPC, verified at the date of publication.]
  • South Africa: the Information Regulator (South Africa), JD House, 27 Stiemens Street, Braamfontein, Johannesburg. General enquiries: enquiries@inforegulator.org.za. POPIA complaints: POPIAComplaints@inforegulator.org.za. Telephone: +27 10 023 5200. [TO CONFIRM: verify these details against inforegulator.org.za at the date of publication.]
  • Elsewhere in SADC: the data-protection authority of the country where you live or work, where one has been established.

14. Cookies and what your browser stores

The Platform sets three cookies and stores two small preferences in your browser. They are listed individually, with their purpose and lifetime, in the Cookie Policy. No advertising or cross-site tracking cookies are set.

15. Children

The Platform is built for working professionals in the development finance sector and is not directed at children. Accounts are for people aged 18 and over, and we do not knowingly collect personal information from anyone under 18. If you believe a child has an account, tell the Information Officer and we will remove it.

16. Automated decisions

The Platform does not make decisions about you by automated means that have legal or similarly significant effects. Quiz scoring is automated, but a credential is awarded against published pass criteria, the result can be reviewed by a person on request, and an appeal is dealt with under the Acceptable Use and Community Guidelines.

17. Changes to this policy

We may update this policy. The current version and its effective date are shown at the foot of this page and come from the same source the Platform uses to record your acceptance, so the two can never disagree. For material changes we will notify you on the Platform before they take effect and, where the law requires it, ask you to accept the new version.

18. Contact

Privacy questions, access requests and complaints: SADC-DFRC@socoed.com

Version 2.0 · Effective 14 September 2026