Legal
Privacy Policy
Your privacy matters to us. This policy explains how the Community of Practice collects, uses, and protects your personal information.
Last updated: April 5, 2026
🏛️ 1. Who We Are
The Community of Practice is an online platform operated by the African Population and Health Research Center (APHRC), a premier research institution generating evidence to drive policy action to improve the health and well-being of people in Africa.
This platform enables researchers, practitioners, and thought leaders to collaborate, share knowledge, and engage in discussions that advance research and evidence-based policy across the continent.
Data Controller: African Population and Health Research Center (APHRC), APHRC Campus, Manga Close, off Kirawa Road, Kitisuru, P.O. Box 10787-00100, Nairobi, Kenya.
📋 2. Information We Collect
Account Information
When you register for the platform, we collect:
- Full name and display name
- Email address
- Password (stored in encrypted form)
- Profile photo (optional)
Profile Information
You may voluntarily provide additional details through your profile, including:
- Professional title, institution, and department
- Research interests and areas of expertise
- Biographical information
- Location and country
- Professional links and social media profiles
Platform Activity
As you use the platform, we automatically collect:
- Forum posts, topic discussions, and replies you create
- Groups you join and your activity within them
- Upvotes, comments, and other engagement actions
- Direct messages exchanged with other members
- Notification preferences and subscription settings
Technical Data
We automatically collect certain technical information when you visit the platform:
- IP address and approximate location
- Browser type, version, and operating system
- Pages visited, time spent, and navigation patterns
- Referring website or link source
- Device type and screen resolution
⚙️ 3. How We Use Your Information
We use the information we collect to:
- Operate the platform — create and manage your account, enable participation in groups and forums, and facilitate collaboration between members
- Communicate with you — send email notifications about replies, mentions, group activity, and weekly digest summaries based on your preferences
- Personalize your experience — display relevant content, recommend communities, and show your contributions to other members
- Maintain security — detect and prevent spam, abuse, unauthorized access, and other harmful activity
- Improve the platform — analyze usage patterns to enhance features, fix issues, and develop new functionality
- Recognize contributions — track engagement points and display leaderboards to encourage participation
We will never sell your personal information to third parties or use it for purposes unrelated to the platform without your explicit consent.
⚖️ 4. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Consent — When you register an account and agree to this policy, you consent to the processing described herein. You can withdraw consent at any time.
- Contract performance — Processing necessary to provide the platform services you signed up for, including account management and community features.
- Legitimate interests — Improving platform security, analyzing usage to enhance the user experience, and preventing abuse, where these interests are not overridden by your rights.
- Legal obligations — Where we are required to retain or disclose data to comply with applicable laws.
🤝 5. Information Sharing
We share your information only in the following circumstances:
- Public profile and contributions — Your display name, profile photo, bio, and public posts are visible to other platform members. Content posted in groups is visible to group members.
- Hidden groups — Content and membership in hidden groups is only visible to members of that group. Non-members cannot see, search, or access hidden group content.
- Service providers — We use trusted third-party services for email delivery (e.g., SendGrid), hosting, and analytics. These providers are contractually bound to protect your data.
- APHRC research — Aggregated, anonymized usage statistics may be used by APHRC for research about online academic collaboration. No personally identifiable information is included.
- Legal requirements — We may disclose information if required by law, court order, or governmental regulation, or to protect the safety and rights of our users and the public.
Private messages are only visible to the sender and recipient(s). Platform administrators do not access private messages except when investigating reported abuse.
🍪 6. Cookies & Tracking
We use cookies and similar technologies to keep the platform running smoothly:
- Essential cookies — Required for login sessions, security tokens, and basic platform functionality. These cannot be disabled.
- Preference cookies — Remember your settings, notification preferences, and display choices.
- Analytics cookies — Help us understand how members use the platform so we can improve it. This data is aggregated and anonymized.
We do not use advertising cookies or third-party tracking for marketing purposes. Your browsing activity on this platform is never shared with advertisers.
You can manage cookies through your browser settings. Note that disabling essential cookies may prevent you from using the platform.
🗄️ 7. Data Retention
We retain your data for as long as your account is active and as needed to provide platform services:
- Account data — Retained until you delete your account or request deletion
- Forum posts and replies — Retained to preserve discussion integrity, even after account deletion (attributed to "Deleted User")
- Private messages — Deleted when both parties delete their accounts
- Technical logs — IP addresses and access logs are retained for up to 12 months for security purposes, then automatically purged
- Email notification records — Delivery records retained for 90 days
When you delete your account, your personal profile data, email address, and group memberships are permanently removed. Some content you contributed (forum posts, replies) may be retained in anonymized form to preserve the coherence of community discussions.
🔒 8. Data Security
We take the protection of your data seriously and implement appropriate technical and organizational measures:
- Passwords are hashed using industry-standard algorithms and are never stored in plain text
- All data in transit is encrypted using HTTPS/TLS
- Access to user data is restricted to authorized personnel on a need-to-know basis
- Regular security reviews and updates are performed on the platform
- Hidden group content is enforced at the database level — non-members cannot access it through any means
While we strive to protect your data, no method of electronic transmission or storage is 100% secure. We encourage you to use a strong, unique password and to keep your login credentials confidential.
✊ 9. Your Rights
You have the following rights regarding your personal data:
- Access — You can view all personal data we hold about you through your profile page. You can also export a copy of your data from Settings > Data & Account.
- Correction — You can update or correct your profile information at any time via Edit Profile.
- Deletion — You can delete your account from Settings > Data & Account. This permanently removes your personal information.
- Restrict processing — You can adjust your notification, digest, and privacy preferences in Settings to control how your data is used.
- Withdraw consent — You can withdraw consent for optional data processing at any time. This does not affect the lawfulness of processing performed before withdrawal.
- Portability — You can export your data in a machine-readable format (JSON) from your account settings.
- Complain — If you believe your data rights have been violated, you may lodge a complaint with the Office of the Data Protection Commissioner of Kenya or the relevant authority in your jurisdiction.
👶 10. Children's Privacy
This platform is designed for researchers, practitioners, and professionals and is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that a child under 18 has registered, we will take steps to delete their account and associated data.
📝 11. Policy Changes
We may update this privacy policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make significant changes:
- We will update the "Last updated" date at the top of this page
- For material changes, we will notify registered members via email or an in-platform notification
- Continued use of the platform after changes take effect constitutes acceptance of the updated policy