Version 2.0 · Effective 14 September 2026
This policy explains what personal information Digital Learning Academy (the “Platform”) holds about you, why we hold it, who else sees it, where it is stored and what you can do about it. It is written to be read, not filed. Where the Platform does something that members would not expect, we say so here rather than leave it out.
The SADC Development Finance Resource Centre (“the Centre”, “we”, “us”) is the responsible party for the personal information described in this policy. In the language of the Botswana Data Protection Act the Centre is the data controller; in the language of POPIA it is the responsible party. The Centre is based in Gaborone, Botswana.
Members are spread across the SADC region and the data-protection law that applies to you depends on where you are. Rather than publish a different policy for each country, we have drafted to the strictest common standard, which in practice means the following two regimes. Meeting them satisfies the others.
If the law where you live gives you a stronger right than this policy describes, that stronger right applies and you should simply ask us for it.
POPIA section 55 requires a named Information Officer, and the Botswana Act requires a responsible contact point for data-protection matters. The same person performs both roles for the Platform, and is the single address for every request, question or complaint described in this policy.
Until a dedicated privacy mailbox is published, every request reaches the Information Officer at SADC-DFRC@socoed.com. Put “Data protection” in the subject line and we will route it correctly. [TO CONFIRM: whether a dedicated address such as privacy@sadc-dfrc.org should be created and published here instead.]
This is the complete list, described in the terms the system actually uses rather than in generalities.
The Platform does not collect special categories of personal information such as health, biometric, religious or political data, and you should not put such information into your profile, posts or messages.
Most of it comes from you directly, when you register, complete your profile, take a course or post something. Some comes from your device automatically, such as your IP address and browser type. Some may come from your institution, where it nominates you for a programme and supplies your name, work email and role. If you sign in with Google, your name, email address and Google account identifier come from Google.
Every processing activity on the Platform rests on one of the following grounds, which exist in equivalent form in the Botswana Act and in POPIA:
We do not sell personal information, we do not use it for third-party advertising, and we do not profile members for marketing.
The Platform is a professional network, so parts of your profile are deliberately visible. Your name, photo, headline, job title, institution and country are visible to other signed-in members, as are the posts and comments you publish and the groups and events you join. Direct messages are visible only to their participants. Credential verification pages show the credential, the holder’s name and the issue date to anyone you share the verification link with. Your assessment answers and scores are not visible to other members. Your email address, phone number, IP address and sign-in history are never shown to other members.
We share personal information in three situations, and no others.
| Provider | What it does for us | Where | What it can see |
|---|---|---|---|
| Hetzner Online GmbH | Hosting of the servers and databases that run the Platform | Helsinki, Finland (European Union) | All Platform data at rest, including profiles, learning records, messages and backups |
| Cloudflare, Inc. | Content delivery, protection against attack, and R2 object storage for course media | Global edge network; R2 bucket region [TO CONFIRM.] | IP addresses and request metadata for every page you load, plus stored course media files |
| Sentry (Functional Software, Inc.) | Error monitoring, performance tracing and session replay. See the note below the table. | European Union (Sentry EU data region) | Error diagnostics, the URL you were on, browser and IP, and a masked recording of the screen when an error occurs |
| Google (Google Ireland Limited / Google LLC) | Sign in with Google, for members who choose it | Ireland and the United States | The fact that you signed in, your Google account identifier, name and email address |
| Transactional email relay | Delivery of service email: verification, password reset, course and event notices | Johannesburg, South Africa [TO CONFIRM: registered name of the relay operator.] | Your name, your email address and the content of the service emails we send you |
| Anthropic PBC | Translation. When you press “See translation” on a post, comment or institution description, that text is sent to Anthropic to be translated into your chosen language, and the translation is stored so that the next person to ask does not send it again. Translation happens only when somebody asks for it: nothing is sent automatically, and nothing you write is sent because you wrote it. An AI assistant service is also deployed in the Platform stack but is not connected to any member-facing feature, so nothing is sent to it. | United States | The text a reader asks to have translated, and the language they want it in. No name, email or account identifier accompanies it. |
| Unsplash | Decorative photography on catalogue and resource pages, loaded directly by your browser | United States | Your IP address and browser details, because your browser fetches the image from them |
| flagcdn.com | Country flag images in member and institution listings, loaded directly by your browser | [TO CONFIRM: operating company and country for flagcdn.com.] | Your IP address and browser details, because your browser fetches the image from them |
Sentry session replay, in plain terms. When the Platform hits an error, Sentry can record a reconstruction of what was on your screen so engineers can see what went wrong. This is limited in three ways: it runs only on errors and only on about a quarter of them, all text is masked before it leaves your browser, and images and video are blocked. It is not a general recording of your activity, and normal sessions without an error are not recorded. We have enabled masking specifically because the Platform displays message bodies, member names and email addresses.
A note on analytics, to be accurate rather than reassuring. The Platform’s code includes a product-analytics library (PostHog), but no key is configured for it, so it does not load and no analytics events are being collected. If we ever turn it on we will update this policy and the Cookie Policy before doing so. The previous version of this policy described our analytics as first-party; that was not correct and has been removed.
Search (Meilisearch), caching (Redis) and the content management system (Strapi) run on the Centre’s own servers and are not third parties.
The Platform is hosted in the European Union. Members are in Botswana, South Africa and the other SADC member states. Your information therefore leaves your country every time you use the Platform, and comes back to your screen the same way. Both the Botswana Act and POPIA allow this where safeguards are in place, and these are ours:
If you object to your information being hosted in the European Union, the Platform cannot be provided to you, and you should tell us so that we can close your account.
Each category of data has its own period, set out in full in the Data Retention Schedule. In summary: account and profile data is kept while your account is open and for a short wind-down period afterwards; learning records are kept for several years so that progress and CPD can be evidenced; credential records are kept long term so that certificates already issued remain verifiable; and security logs are kept for months, not years.
What we do:
What we want you to know is not yet in place:
No system is perfectly secure. If a breach affects your personal information we will notify you and the relevant regulator as the law requires, without undue delay, and we will tell you what happened, what we are doing about it and what you should do.
Subject to the law that applies to you, you have the right to:
There is no button for any of this yet, and we would rather say so than imply otherwise. Every request is handled by hand. Email the Information Officer at SADC-DFRC@socoed.com, say which right you are exercising, and tell us the email address on your account so we can find it.
We acknowledge within 5 working days and respond substantively within 30 calendar days. If a request is complex we may need longer, in which case we will tell you before the 30 days are up, explain why, and give you a date. There is no charge for a first request; we may charge a reasonable fee for repeated or clearly excessive requests, and we will tell you the amount before doing any work. Where we refuse, we will say why and tell you how to challenge it.
We will ask you to confirm your identity before releasing or deleting anything, normally by replying from the email address on the account. This protects you from someone else making a request in your name.
Please come to us first, because most things are quicker to fix directly. But you do not have to, and you can go to a regulator at any time.
The Platform sets three cookies and stores two small preferences in your browser. They are listed individually, with their purpose and lifetime, in the Cookie Policy. No advertising or cross-site tracking cookies are set.
The Platform is built for working professionals in the development finance sector and is not directed at children. Accounts are for people aged 18 and over, and we do not knowingly collect personal information from anyone under 18. If you believe a child has an account, tell the Information Officer and we will remove it.
The Platform does not make decisions about you by automated means that have legal or similarly significant effects. Quiz scoring is automated, but a credential is awarded against published pass criteria, the result can be reviewed by a person on request, and an appeal is dealt with under the Acceptable Use and Community Guidelines.
We may update this policy. The current version and its effective date are shown at the foot of this page and come from the same source the Platform uses to record your acceptance, so the two can never disagree. For material changes we will notify you on the Platform before they take effect and, where the law requires it, ask you to accept the new version.
Privacy questions, access requests and complaints: SADC-DFRC@socoed.com
Version 2.0 · Effective 14 September 2026