• Home
  • GDPR Compliance Policy

GDPR Compliance Policy

Effective Date: 22 September 2026
Last Updated: 22 September 2026

1. Introduction

This GDPR Compliance Policy explains how CollabWise Academy handles personal information where the European Union General Data Protection Regulation (“EU GDPR”) or the United Kingdom General Data Protection Regulation (“UK GDPR”) applies.

CollabWise Academy operates through https://collabwiseacademy.com/ and provides expert-led webinars and professional training in AI solutions and automation, career development, professional skills, employee wellness, leadership and management, sustainability, innovation, and workplace performance.

As a Nigeria-based organization, our primary data-protection responsibilities arise under the Nigeria Data Protection Act 2023. The EU GDPR or UK GDPR may also apply in particular circumstances, including where we intentionally offer services to people in the relevant territory or carry out covered monitoring activities.

This Policy should be read together with our Privacy Policy, Cookie Policy, Data Usage Policy, and Account and Data Deletion Policy.

2. When GDPR May Apply

The EU GDPR may apply to certain processing where CollabWise Academy:

  • Offers webinars or training services to individuals located in the European Union or European Economic Area;
  • Intentionally targets individuals in those territories;
  • Accepts registrations from relevant individuals as part of such an offering;
  • Monitors covered website behaviour through applicable tracking technologies; or
  • Processes personal information on behalf of an organization that is subject to the EU GDPR.

The UK GDPR may apply separately where comparable activities involve people located in the United Kingdom. The fact that a website can be accessed internationally, or displays an international currency, does not by itself establish that every GDPR obligation applies. Applicability must be assessed according to the nature of the offering and processing activity.

Where neither the EU GDPR nor UK GDPR applies, we will still process personal information according to our Privacy Policy and applicable Nigerian data-protection requirements.

3. Our Role

For information collected directly through our website, accounts, webinar registrations, communications, and customer relationships, CollabWise Academy will generally act as the data controller. This means that we determine why and how the information is processed.

In some corporate training arrangements, an employer or sponsoring organization may determine the purpose of processing participant information. Depending on the arrangement, CollabWise Academy may act as:

  • An independent controller;
  • A joint controller; or
  • A processor acting on the organization’s documented instructions.

Where CollabWise Academy acts as a processor, the relevant organization remains responsible for providing appropriate privacy information and establishing a valid lawful basis for supplying participant data.

4. Personal Data We May Process

Depending on how you interact with us, we may process:

  • Name and contact information;
  • Account and login details;
  • Billing address;
  • Webinar registration information;
  • Attendance and completion history;
  • Organization and professional information;
  • Learning interests;
  • Questions, feedback, and survey responses;
  • Support messages and email text;
  • Webinar chat contributions;
  • Audio, video, or display name where enabled;
  • Transaction references and payment status;
  • Device, browser, IP address, and security logs;
  • Cookie identifiers and website usage information; and
  • AI-related examples or text voluntarily submitted during training.

We apply data-minimization principles and seek to collect only information reasonably necessary for the relevant purpose.

5. Lawful Bases for Processing

Where GDPR applies, we process personal information under one or more lawful bases.

Performance of a Contract

We may process information where necessary to:

  • Create and manage an account;
  • Complete a webinar registration;
  • Process a transaction;
  • Provide session access;
  • Deliver learning materials;
  • Maintain attendance records;
  • Issue a certificate; or
  • Respond to a service-related request.

Consent

We may rely on consent for:

  • Optional marketing communications;
  • Non-essential analytics or advertising cookies;
  • Certain webinar recordings or promotional uses;
  • Processing optional sensitive information; or
  • Another activity where consent is the most appropriate basis.

Consent must be freely given, specific, informed, and unambiguous. You may withdraw consent at any time without affecting processing that lawfully occurred before withdrawal.

Legitimate Interests

We may rely on legitimate interests to:

  • Secure the website and accounts;
  • Prevent fraud;
  • Improve our services;
  • Maintain appropriate business records;
  • Respond to enquiries;
  • Understand general service usage;
  • Protect our legal rights; or
  • Communicate with existing customers about closely related services where permitted.

Before relying on legitimate interests, we consider whether the processing is necessary and whether your rights and reasonable expectations outweigh our interests.

Legal Obligation

We may process or retain information where necessary to comply with accounting, regulatory, court, law-enforcement, consumer-protection, or other applicable legal obligations.

Vital Interests

In exceptional circumstances, information may be processed where necessary to protect someone’s life or physical safety.

6. Special-Category Information

We do not generally require sensitive information for ordinary webinar registration. Employee wellness discussions or participant communications could sometimes reveal information relating to health, disability, racial or ethnic origin, religious beliefs, trade-union membership, sexual orientation, or other protected categories.

Participants should avoid submitting sensitive information unless it is necessary. Where we intentionally process special-category information under GDPR, we will establish both a lawful basis under Article 6 and an applicable condition under Article 9, such as explicit consent or another legally permitted condition.

Employee wellness webinars do not create a medical or therapeutic relationship, and participants should not disclose detailed health records in public webinar chats.

7. AI-Related Processing

CollabWise Academy provides training about AI tools but does not currently present its website as an independent AI response-generation platform.

If you submit AI-related questions, sample prompts, or email text directly to us, we may use them to:

  • Answer your question;
  • Deliver training support;
  • Demonstrate responsible AI practices;
  • Maintain security; and
  • Improve relevant learning content.

Directly submitted correspondence may be retained for up to 24 months unless a valid deletion request applies or a longer period is required for a legal matter. Third-party AI tools demonstrated during a webinar operate under their own terms. Participants should not submit sensitive personal data, confidential employer information, passwords, or third-party data without authorization.

We do not use AI alone to make decisions that produce legal or similarly significant effects concerning account eligibility, payments, or webinar access. If we introduce an AI feature that processes user prompts, we will provide information about the provider, purposes, lawful basis, retention period, human review, and any applicable automated decision-making before or when the feature is used.

8. GDPR Data-Protection Principles

Where GDPR applies, we seek to process personal information according to the following principles:

  • Lawfulness, fairness, and transparency: Information is processed under an appropriate legal basis and in a manner individuals can reasonably understand.
  • Purpose limitation: Information is collected for specified and legitimate purposes.
  • Data minimization: We seek to collect only what is reasonably necessary.
  • Accuracy: Reasonable steps are taken to keep relevant information accurate and current.
  • Storage limitation: Information is not retained longer than reasonably necessary.
  • Integrity and confidentiality: Appropriate security measures are used.
  • Accountability: We maintain appropriate procedures and records to demonstrate responsible processing.

9. Individual Rights

Where the EU GDPR or UK GDPR applies, you may have the following rights, subject to applicable conditions and exceptions.

Right to Be Informed

You have the right to receive clear information about how and why your personal information is processed.

Right of Access

You may request confirmation of whether we process your information and obtain a copy of eligible information, together with relevant processing details.

Right to Rectification

You may ask us to correct inaccurate information or complete information that is materially incomplete.

Right to Erasure

You may request deletion where information is no longer necessary, consent has been withdrawn, an upheld objection applies, or the processing is unlawful.

This right is not absolute. Information may be retained where necessary for legal obligations, claims, fraud prevention, security, or another permitted exception.

Right to Restrict Processing

You may request restricted use of information in circumstances such as when accuracy is disputed or an objection is being assessed.

Right to Data Portability

Where processing is based on consent or contract and carried out by automated means, you may request eligible information in a structured, commonly used, and machine-readable format.

Right to Object

You may object to processing based on legitimate interests or certain public-interest grounds. You have an unconditional right to object to personal information being used for direct marketing.

Rights Concerning Automated Decisions

You may have the right not to be subject to a decision based solely on automated processing, including profiling, where the decision creates legal or similarly significant effects.

Right to Withdraw Consent

Where processing is based on consent, you may withdraw it at any time. Withdrawal does not make earlier lawful processing invalid.

Right to Complain

You may complain to the data-protection authority responsible for your country or region. UK users may contact the Information Commissioner’s Office where appropriate.

10. Exercising Your Rights

To exercise a GDPR right, contact us using the information at the end of this Policy.

Your request should include:

  • Your full name;
  • Email address connected to the account;
  • The right you wish to exercise;
  • Relevant account or webinar information; and
  • Enough detail for us to understand the request.

We may request proportionate proof of identity to prevent unauthorized access or deletion. Valid requests will normally be handled within one month. Where a request is complex or multiple requests are submitted, the response period may be extended as permitted by law. If an extension is required, we will provide appropriate notice.

Requests are generally handled without charge. A reasonable fee may be permitted where a request is manifestly unfounded, excessive, or repetitive.

11. Data Retention

We retain personal information only for as long as necessary for its stated purpose and applicable legal requirements.

Our general approach includes:

  • Keeping account data while the account is active and for a reasonable period afterward;
  • Keeping support messages and directly submitted AI-related text for up to 24 months;
  • Retaining webinar records where necessary for certificates and learning history;
  • Retaining transaction information for applicable accounting and legal periods;
  • Keeping security logs for a proportionate security period; and
  • Retaining marketing information until consent is withdrawn or you unsubscribe.

Information may be deleted, anonymized, or securely restricted when it is no longer required.

12. International Data Transfers

CollabWise Academy operates from Nigeria, and information involving EU, EEA, or UK individuals may therefore be transferred outside their territory.

Where GDPR transfer restrictions apply, we will use an appropriate mechanism, which may include:

  • An applicable adequacy decision;
  • Approved Standard Contractual Clauses;
  • The UK International Data Transfer Agreement or UK Addendum;
  • Binding contractual safeguards with service providers;
  • A legally recognized certification or framework; or
  • A limited derogation expressly permitted by law.

We may also apply supplementary security measures such as encryption, restricted access, data minimization, or transfer-risk assessments where appropriate.

You may contact us to request general information about the safeguard relevant to your information.

13. Service Providers

We may use service providers for:

  • Website hosting;
  • Cloud storage;
  • Webinar delivery;
  • Payment processing;
  • Email communications;
  • Analytics;
  • Customer support;
  • Cybersecurity;
  • Backups; and
  • Professional services.

Where a provider processes personal information on our behalf, we seek to use appropriate contractual terms requiring confidentiality, security, lawful processing, assistance with rights requests, and deletion or return of information when the service ends.

Independent payment, webinar, and AI providers may act as separate controllers for certain processing. Their own privacy policies will apply to those activities.

14. Cookies and Consent

Strictly necessary cookies may be used to maintain security, login sessions, carts, registration, and checkout. Where GDPR consent requirements apply, non-essential analytics, preference, or marketing cookies will not be placed until an appropriate choice has been made. You may withdraw or modify cookie consent through the available preference tool or browser settings. Further information is provided in our Cookie Policy.

15. Marketing Communications

We may send marketing communications where we have consent or another lawful basis. You may object to direct marketing or unsubscribe at any time. After an opt-out, we may retain a limited suppression record to respect your preference. Service messages about an account, payment, webinar schedule, security concern, or policy change are not promotional and may still be sent where necessary.

16. Data Security

We use reasonable technical and organizational measures designed to protect personal information. These may include:

  • Encryption during transmission;
  • Account authentication;
  • Access restrictions;
  • Software updates;
  • Security monitoring;
  • Backups;
  • Confidentiality controls; and
  • Service-provider assessments.

Security measures are reviewed according to the nature, scope, context, and risk of the processing. No electronic system can guarantee absolute security.

17. Personal Data Breaches

If a personal-data breach occurs, we will investigate, contain, document, and assess the incident. Where GDPR applies and a breach is likely to create a risk to individuals’ rights and freedoms, we will notify the competent supervisory authority within the legally required period, which is generally 72 hours after becoming aware of the breach where feasible.

Where a breach is likely to create a high risk, affected individuals will also be informed without undue delay unless a lawful exception applies.

18. Children’s Information

CollabWise Academy’s professional learning services are primarily designed for adults. Individuals under 18 may participate only with appropriate authorization and supervision from a parent, legal guardian, school, employer, or responsible organization.

Where consent is relied upon for an online service involving a child, we will consider the applicable age and parental-authorization requirements of the relevant EU or EEA country or the United Kingdom. We do not knowingly use children’s information for behavioral advertising or unrelated profiling.

19. Data Protection by Design

When introducing a new service, system, tracking technology, or AI feature, we seek to consider privacy at an early stage.

Depending on the risk, measures may include:

  • Collecting less information;
  • Limiting access;
  • Establishing defined retention periods;
  • Selecting privacy-conscious defaults;
  • Conducting a data-protection impact assessment;
  • Reviewing service-provider contracts; and
  • Providing clear user information.

A data-protection impact assessment may be completed where processing is likely to create a high risk to individuals.

20. Records and Accountability

Where required, we maintain appropriate records concerning:

  • Processing purposes;
  • Data categories;
  • Recipient categories;
  • International transfers;
  • Retention arrangements;
  • Security controls;
  • Rights requests;
  • Breach assessments; and
  • Service-provider relationships.

We will appoint a data protection officer, EU representative, or UK representative if the applicable legal conditions require one. The absence of a named representative on this page should not be interpreted as a claim that no such obligation could arise.

21. Updates to This Policy

We may update this Policy when our services, data practices, technology, or legal responsibilities change. The revised version will be posted on the website with an updated date. Where a change materially affects existing processing, we may provide additional notice or request consent where required.

22. Contact Us

For GDPR questions, rights requests, consent withdrawal, or privacy complaints, contact:

CollabWise Academy
Email: support@collabwiseacademy.com
Address: NO 50, SANI ABACHA ROAD, KARU MARARABA, NASARAWA STATE, NIGERIA

Select your currency