Privacy Policy
Effective: 11 July 2026 · Version: 2.0 Applies to: learn.crenc.org and all related educational services
1. Who we are
This site, learn.crenc.org, is the online learning platform of Clinical Research Education, Networking and Consultancy (CRENC), a Cameroonian non-profit dedicated to strengthening health research capacity across Africa.
For the purpose of the personal data processed through this site, CRENC is the Data Controller. Where CRENC engages service providers to process data on our instructions (for example, our hosting provider or our email service provider), those parties act as Data Processors bound by contractual confidentiality and security obligations.
Contact for privacy matters: [email protected] (please write "Data Protection" in the subject line).
2. The law that governs this policy
This policy is governed by Law No. 2024/017 of 23 December 2024 relating to Personal Data Protection in Cameroon ("the Data Protection Law"), together with:
- Law No. 2010/012 of 21 December 2010 on cybersecurity and cybercriminality;
- Law No. 2010/013 of 21 December 2010 governing electronic communications;
- any implementing decrees, regulations, and guidance issued by the Personal Data Protection Authority of Cameroon ("the Authority") once operational.
Where you access this site from outside Cameroon, we also endeavour to respect internationally recognised data-protection principles including those reflected in the EU General Data Protection Regulation (GDPR) and the Malabo Convention. Nothing in this policy is intended to reduce rights you may hold under mandatory law in your country of residence.
If any provision of this policy conflicts with mandatory law that applies to you, the mandatory law prevails and this policy shall be read to conform to it, without invalidating the remainder.
3. What personal data we collect
We collect only what we need to run the platform. The categories are:
a. Data you provide directly
- Account data — username, email address, hashed password, first and last name where you supply them, preferred language, and any profile information you choose to add.
- Enrolment and progress data — the courses you enrol in, quiz results, completion status, certificates issued.
- Newsletter data — the email address you submit to receive updates.
- Communications — the content of messages you send us and our replies.
- User-generated content — comments, forum posts, or feedback you publish on the site.
b. Data collected automatically
- Technical data — IP address, browser type and version, operating system, device type, screen resolution, referring URL, pages viewed, and the time and date of each visit.
- Cookie and similar data — see Section 9 below.
c. Data from third parties
- Sign-in providers — if you sign in via a third-party service, we receive the basic profile data that service transmits.
- Analytics providers — aggregate usage statistics that may include a limited set of identifiers.
4. Why we process your data (lawful basis)
Under the Data Protection Law we must be able to point to a lawful basis for every use of your data. Ours are:
| Purpose | Lawful basis |
|---|---|
| Creating and managing your account, delivering courses and certificates | Performance of the agreement between you and CRENC (Section 9 of the Data Protection Law) |
| Sending newsletter updates | Your prior, explicit consent — which you can withdraw at any time |
| Analysing site usage to improve content | Our legitimate interest in operating a useful platform, balanced against your rights |
| Detecting fraud and abuse, keeping the site secure | Our legitimate interest and, where applicable, legal obligation |
| Responding to lawful requests from public authorities | Compliance with a legal obligation |
| Communicating important service or safety notices | Performance of the agreement |
We do not use your personal data for automated decision-making that produces legal or similarly significant effects on you.
5. Sensitive data
The Data Protection Law defines certain categories of personal data as sensitive, including data on religion, philosophical or political opinions, trade-union activity, racial, ethnic, linguistic or regional origin, sex life, genetics, biometrics, health, and information relating to legal proceedings or criminal sanctions.
We do not knowingly collect sensitive data. If sensitive information incidentally appears in content you submit (for example, a forum post), we will treat it with additional confidentiality and will not process it beyond the display and storage strictly necessary to run the service. Please do not share sensitive information about yourself or others through this site.
6. How we share data
We do not sell or rent your personal data. We share it only in these limited situations:
- With Data Processors we have engaged — hosting, email delivery, analytics, backup, and similar services. Each is bound by a written data-processing agreement requiring confidentiality and appropriate security.
- With research partners named on a course, but only in aggregate or anonymised form unless you have separately consented to the disclosure of your identifiable data for that course.
- With public authorities where legally compelled or where necessary to protect life, safety, or the integrity of the platform.
- In connection with an organisational change — for example, if CRENC restructures or merges with another Cameroonian non-profit pursuing the same mission. Your data would remain protected by this policy or a successor at least as protective.
7. International data transfers
Some of our service providers are based outside Cameroon. Your data may be transferred to, stored in, or processed in countries whose data protection regime differs from Cameroon's — including the European Union, the United States, and other jurisdictions. Present cross-border processors include, among others, our website hosting infrastructure and our email delivery service.
Where the Data Protection Law requires prior authorisation from the Authority for such transfers, we will seek it. In the meantime we rely on the following safeguards:
- Written processing agreements with each processor incorporating confidentiality, security, and processor-side data-protection commitments;
- Reasonable due diligence on the security posture of each provider;
- A preference, where equivalent alternatives exist, for providers subject to strong data-protection regimes.
Once the Authority publishes an adequacy list or additional transfer mechanisms, we will update our practices accordingly.
8. How long we keep data (retention)
We keep personal data only as long as needed for the purpose we collected it or as required by law. Our current retention periods are:
- Account data — for as long as your account is active, plus 12 months after deletion to handle disputes and legal claims, unless a longer period is required by law.
- Course-completion records and certificates — retained indefinitely as they verify credentials you may need to prove years later. You may request removal but doing so may prevent us from re-issuing your certificate.
- Newsletter data — until you unsubscribe, plus a short suppression record to make sure we honour your opt-out.
- Server and analytics logs — up to 12 months in identifiable form where our systems permit, after which they are aggregated or deleted.
- Communications with us — up to 5 years so we can track and reference prior conversations.
- Community content (forum posts, comments) — for the life of the community feature, unless you request removal.
Where deletion is not technically feasible (for example, in encrypted backups), we isolate the data and delete it in the next scheduled backup rotation.
9. Cookies and similar technologies
We use a small number of cookies. They fall into three categories:
- Essential — required to sign you in, keep you signed in, and route you to the correct language. These cannot be turned off.
- Functional — remember your preferences (language, display settings). You may clear these through your browser.
- Analytics — help us understand which pages people find useful. Where the Data Protection Law requires it, we ask for your consent before setting analytics cookies.
You can manage or clear cookies at any time through your browser settings. A dedicated cookie preferences panel will be introduced on this site; until it is live, you may email us to withdraw analytics consent.
10. Your rights
Under the Data Protection Law you have the following rights, exercisable free of charge:
- Access — obtain confirmation of whether we hold data about you, and a copy of that data;
- Rectification — correct inaccurate or incomplete data;
- Erasure ("right to be forgotten") — request deletion where the data is no longer needed, where you withdraw consent, or where processing was unlawful, subject to legal retention obligations;
- Restriction — ask us to pause processing while a concern is investigated;
- Portability — receive your data in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible;
- Objection — object at any time to processing based on our legitimate interest, and to direct-marketing communications;
- Withdraw consent — where processing is based on consent, withdraw it at any time (this does not affect the lawfulness of prior processing);
- Complain to the Authority — lodge a complaint with the Personal Data Protection Authority of Cameroon once operational, or with the supervisory authority of your country of residence.
To exercise any of these rights, email [email protected] with the subject "Data Protection request". We will respond generally within 30 days of a verifiable request, and will explain any extension if the request is complex.
11. Security and breach notification
We apply organisational and technical measures proportionate to the sensitivity of the data we hold, including:
- Encryption in transit (HTTPS across the site);
- Password hashing using industry-standard algorithms;
- Access controls that restrict staff access to what each role requires;
- Regular backups and monitoring;
- Vendor selection favouring providers with strong security postures.
No system is perfectly secure. If we become aware of a personal data breach that is likely to result in a risk to your rights, we will notify the Authority within 72 hours where feasible, and will notify affected individuals without undue delay where the risk is high.
The commitments above reflect our current standard practice; specific timing in any given incident depends on our detection capability at the time and any legal restrictions on disclosure that may apply.
12. Children and minors
The Services are intended for users aged 18 and above. If you are under 18, please use the Services only with the involvement and consent of a parent or guardian. If we learn that we have collected personal data from a person under 18 without appropriate consent, we will delete it promptly.
13. Changes to this policy
We may update this policy from time to time — for example, when the Authority issues implementing regulations, when we add or remove a service provider, or when we launch new features. Material changes will be signalled at the top of this page and, where reasonable, by an announcement or email to registered users. The "Effective" date and version number at the top of this page always reflect the current version.
14. Contact us
Clinical Research Education, Networking and Consultancy (CRENC) Rue 1.354, Nouvelle route Omnisport, P.O. Box 3787, Yaoundé, Cameroon Email (Data Protection): [email protected] — subject line "Data Protection" Phone: 00 237 243 154 601 Web: www.crenc.org
Once the Personal Data Protection Authority of Cameroon is operational, its contact details will be published on this page.
A note on this policy
This policy represents CRENC’s good-faith effort to describe how we handle personal data under Law No. 2024/017 and internationally recognised data-protection principles. We are a small Cameroonian non-profit with limited legal and technical resources, and we implement measures proportionate to those resources. Where any provision of this policy conflicts with mandatory law, the mandatory law prevails and this policy shall be read to conform to it, without invalidating the remainder.
If you find something unclear, incorrect, or in need of improvement, please write to [email protected]. We welcome the feedback.