Page

Privacy Policy

What personal data we collect and why we collect it

1. Comments: When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

2. Contact forms: When you submit a message through our contact form, we collect your name, email address, and any other information you voluntarily provide in the message field. We retain contact form submissions for six months for customer service purposes. We do not use the information submitted through contact forms for marketing purposes unless you have given separate consent.

3. Newsletter sign-up: If you subscribe to our newsletter, we collect your name and email address. You can withdraw your consent at any time by clicking the “unsubscribe” link in any newsletter or by contacting us at info@estoniafoundation.ng.

4. Donations: When you make a donation via our website, we collect your name, email address, phone number (optional), and donation amount. Payment card details are not stored on our servers – they are handled securely by our payment processors .We keep donation records for ten years to comply with Nigerian financial and tax obligations.

Cookies

Our website uses cookies to improve your experience. By continuing to browse, you consent to the use of cookies, but you may manage your preferences through your browser settings or our cookie consent banner.

Who we share your data with

We do not sell, trade, or otherwise transfer your personal data to third parties except as described below:

  • Payment processors: To process donations, we share necessary transaction data (name, email, amount) with Paystack (privacy policy: https://paystack.com/privacy) and/or Flutterwave (privacy policy: https://flutterwave.com/privacy-policy). No card details are stored by us.
  • Email marketing platform: Newsletter subscriptions are managed through Mailchimp (privacy policy: https://mailchimp.com/legal/privacy/). Your name and email are stored on Mailchimp’s servers.
  • Analytics provider: Google Analytics (privacy policy: https://policies.google.com/privacy). Data is shared as described in the Cookies section.
  • Hosting provider: Our website is hosted by [Hosting Company Name], who may process server logs containing IP addresses. We have a Data Processing Agreement in place to ensure compliance with the Nigeria Data Protection Regulation (NDPR).
  • Legal obligations: We may disclose information if required by law or in response to valid requests by public authorities (e.g., a court or government agency).

We do not share your data with any other third parties for their own marketing purposes.


How long we retain your data

  • Comments: Comments and their metadata are retained indefinitely unless you request deletion.
  • Contact form entries: Retained for 7 months.
  • Newsletter subscriptions: Kept until you unsubscribe or withdraw consent.
  • Donation records: Retained for 10 years to comply with statutory record-keeping requirements.
  • Analytics data: Retained for 26 months.

What rights you have over your data

Under the Nigeria Data Protection Regulation (NDPR), you have the following rights regarding your personal data:

  • Right to access – You may request a copy of the personal data we hold about you.
  • Right to rectification – You may ask us to correct any inaccurate or incomplete data.
  • Right to erasure – You may request that we delete your personal data under certain conditions.
  • Right to restrict processing – You may ask us to limit the way we process your data.
  • Right to data portability – You can request that we transfer your data to another organisation, or to you, in a structured, commonly used format.
  • Right to object – You may object to processing based on legitimate interests, and you have an absolute right to object to direct marketing.
  • Right not to be subject to automated decision-making – We do not carry out any automated decision-making, but you retain the right to be informed if that changes.

Where your data is sent

Some of the third-party services we use (Google Analytics, Mailchimp, payment processors) may transfer and process your data outside Nigeria, including in the United States and the European Union.

We ensure that any cross-border transfer of personal data is carried out in accordance with the NDPR. Safeguards include:

  • Standard contractual clauses approved by NITDA or other relevant authorities,
  • Binding corporate rules, where applicable,
  • Ensuring the destination country provides an adequate level of protection,
  • Obtaining your explicit consent where required.

By using our website and services, you consent to the transfer of your data as described.


Contact information

For privacy-specific concerns or to exercise your data rights, please contact our Data Protection Officer:

Data Protection Officer (DPO)
Estonia Foundation
[Insert physical address]
Email: dpo@estoniafoundation.ng

You may also contact us generally at info@estoniafoundation.ng.


Additional information

What data breach procedures we have in place

In the event of a personal data breach, we have internal reporting and escalation procedures.
Should a breach occur that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and report the breach to NITDA within 72 hours of becoming aware of it, in line with NDPR requirements.

Industry regulatory disclosure requirements

Estonia Foundation is not part of a specifically regulated industry imposing additional privacy disclosure obligations beyond those already described.