VestraVESTRA.

Privacy Policy

Last updated: 18 August 2026

1. Who we are

Vestra ("Vestra", "we", "us", "our") is a free tech-education platform operated by the Anti-Social Vices Club of RALEBC . This Privacy Policy explains what personal data we collect from users of the Vestra platform ("you", "learners"), why we collect it, how it is used and protected, and the rights you have over it under the Nigeria Data Protection Act, 2023 ("NDPA") and its implementing regulations.

2. What personal data we collect

We collect the following categories of personal data:

  • Account data: your full name, email address, and password (stored only as a salted cryptographic hash — we never store or can retrieve your plain-text password).
  • Optional profile data: a phone number, if you choose to provide one.
  • Learning activity data: the courses and tracks you enrol in, modules you complete, quiz results, and certificates issued to you.
  • Account security data: password-reset requests and admin invitations are tracked using a hashed, time-limited token — never the raw token itself.
  • Technical data: a session cookie that keeps you signed in (see our Cookie Policy), and standard server logs (e.g. IP address, browser type, timestamps) generated automatically by our hosting infrastructure.

We do not knowingly collect sensitive personal data (such as health, biometric, or financial information), and we do not currently use any advertising, analytics, or third-party tracking tools on the platform.

3. Why we process your data, and our lawful basis

  • To provide the service — creating and maintaining your account, tracking your progress, and issuing certificates. Lawful basis: performance of a contract with you (our Terms of Use).
  • To keep your account secure — password hashing, password-reset flows, and detecting misuse. Lawful basis: legitimate interest in keeping the platform and your account secure.
  • To communicate with you — transactional emails such as password resets and admin invitations. Lawful basis: performance of a contract / legitimate interest.
  • To administer the platform — admins reviewing content and, where applicable, an internal audit log of admin actions (this does not apply to learner accounts). Lawful basis: legitimate interest.

Where we rely on your consent for any future processing (for example, optional marketing communications), you may withdraw that consent at any time.

4. Who we share your data with

We do not sell your personal data. We share it only with the following categories of data processors, strictly to operate the platform:

  • Database hosting, which stores your account and learning-activity data.
  • Application hosting — which runs the Vestra application.
  • Transactional email — used only to send account-related emails (password resets, admin invitations).

Where any of these providers process data outside Nigeria, we take reasonable steps to ensure an adequate level of protection is in place, consistent with the NDPA's cross-border data transfer requirements. We do not share your data with advertisers or data brokers.

5. How long we keep your data

We retain your account and learning-activity data for as long as your account remains active. Password-reset and admin-invite tokens automatically expire and are deleted shortly after issuance. If you ask us to delete your account (see Section 6), we will delete or anonymise your personal data within a reasonable period, except where we are legally required to retain certain records for longer.

6. Your rights under the NDPA

Subject to applicable law, you have the right to:

  • Access the personal data we hold about you.
  • Correct (rectify) inaccurate or incomplete data.
  • Erase your personal data ("right to be forgotten"), including deleting your account.
  • Restrict or object to certain processing of your data.
  • Request a copy of your data in a portable format.
  • Withdraw consent at any time, where processing is based on consent.
  • Lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe your data has been mishandled.

To exercise any of these rights, contact us at ralebcasvc@gmail.com. We will respond within the timeframe required by the NDPA.

7. How we protect your data

Vestra applies the following security measures as a baseline:

  • Passwords are hashed (never stored in plain text) before being saved.
  • Password-reset and admin-invite links use single-use, hashed, time-limited tokens.
  • Admin-only areas of the platform are gated by role-based access control.
  • Data in transit is encrypted via HTTPS/TLS.

No system is 100% secure, but we take reasonable, industry-standard steps to protect your data against unauthorised access, alteration, disclosure, or destruction, in line with the NDPA's security-of-processing requirements. In the event of a data breach affecting your personal data, we will notify the NDPC and affected users as required by the NDPA.

8. Children's privacy

Vestra is intended for learners aged 13+ and above. We do not knowingly collect personal data from children below this age without appropriate parental/guardian consent as required by the NDPA. If you believe a child has provided us with personal data without such consent, please contact us so we can remove it.

9. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date above and, where appropriate, notify you directly.

10. Contact us

If you have questions about this Privacy Policy or how your data is handled, contact us at ralebcasvc@gmail.com.