This Privacy Policy explains what information we collect, why we collect it, how we use and share it, how long we keep it, and the rights available to you under applicable data protection laws, including Kenya’s Data Protection Act and, where applicable, the GDPR.
In brief: We collect only the personal information needed to provide AAS Executive Education services, manage enrolment, communicate with participants, improve our services, meet legal obligations, and protect our systems. We apply appropriate safeguards, limit access, retain data only as necessary, and respect your privacy rights.
1. Scope and Controller
This Policy applies to the AAS Executive Education website, events, courses, digital platforms, communications and related services that link to or reference it.
The African Academy of Sciences (AAS) is the controller of personal information processed in connection with AAS Executive Education, unless a separate notice states otherwise.
2. Personal Information We Collect
- Information you provide: name, email address, telephone number, organisation, job title, professional profile, education and qualifications, application details, enquiries, feedback, newsletter preferences and payment-related information.
- Information from your organisation: where your employer or institution sponsors or manages your participation, we may receive contact, role, organisational identification and enrolment information.
- Information from use of our services: device and browser information, IP address, log data, course access records, pages viewed, enquiries submitted, approximate location, cookies and similar technologies.
- Information from other sources: publicly available professional information, partners, affiliates or third parties where lawful and relevant to the Executive Education service.
3. How and Why, We Use Personal Information
We use personal information to process applications and enrolments; provide access to courses, events and services; issue certificates; manage payments; respond to enquiries; send administrative updates; provide newsletters or promotional information where permitted; analyse and improve our services; protect against fraud, misuse and cyber threats; meet legal, regulatory, audit and contractual obligations; and produce aggregated or anonymised insights for reporting, research or service improvement.
We do not sell personal information.
4. Legal Basis for Processing
We process personal information only where there is a lawful basis. This may include your consent, performance of a contract, compliance with a legal obligation, or AAS’s legitimate interests, such as improving services, communicating with participants, protecting systems and managing programme operations. Where we rely on consent, you may withdraw it at any time.
6. International Transfers
Your personal information may be stored or processed outside your country. Where this happens, AAS will apply appropriate safeguards, such as contractual protections, transfer to jurisdictions recognised as providing adequate protection, or other measures required by applicable law.
7. Retention
We keep personal information only for as long as necessary for the purposes described in this Policy, including programme delivery, account management, legal compliance, audit, dispute resolution, reporting and legitimate business needs. When information is no longer required, we securely delete, anonymise or archive it in line with applicable law and internal retention requirements.
8. Your Data Protection Rights
Subject to applicable law, you may request access to your personal information; correction of inaccurate or incomplete information; deletion where there is no lawful reason to retain it; restriction of processing; objection to processing based on legitimate interests or direct marketing; withdrawal of consent; and a copy of your information in a structured, commonly used format.
To exercise these rights, contact the AAS Privacy Centre using the details below. We may need to verify your identity before responding and will respond within the period required by applicable law, typically within 30 days.
10. Security and Breach Notification
AAS applies technical and organisational measures designed to protect personal information against unauthorised access, loss, misuse, alteration or disclosure. These measures may include access controls, secure systems, staff awareness, vendor controls, monitoring and incident response procedures.
If a personal data breach is likely to result in risk to individuals, AAS will notify affected persons and/or the relevant data protection authority where required by law, including within applicable statutory timelines.
11. Children’s Privacy
AAS Executive Education services are intended for adults and are not directed to persons under 18. We do not knowingly collect personal information from children. If we become aware that such information has been collected without appropriate consent, we will take steps to delete it.
12. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals. If this changes, we will provide appropriate notice and safeguards.
13. Third-Party Links
Our website may link to third-party websites, platforms or services. This Policy does not apply to those third parties. We encourage you to read their privacy notices before providing personal information.
14. Changes to this Policy
We may update this Policy from time to time. Material changes will be communicated through the website or other appropriate channels where reasonably possible.