Privacy Policy

Privacy Policy

Africa Risk Management Advisors Limited ("ARMA", "we", "us", "our")

Effective date: 2026-06-08
Version: 1.0 (supersedes all prior versions)
Last reviewed: 2026-06-07
Canonical URL: https://africarisk.net/legal/privacy


1. About this policy

This Privacy Policy explains how ARMA collects, uses, shares, and protects personal information across all of our products and services, including:

  • The ARMA Advisory practice (client.africarisk.net and direct engagements)
  • ARMA Academy — individual CPD learner platform (academy.africarisk.net)
  • ARMA Academy Institutional — white-label academy for sponsoring institutions (institutional.africarisk.net)
  • Risk Advisor by ARMA — AI risk advisory product (riskadvisor.africarisk.net)
  • The ARMA Developer Portal — API access for integration partners (developers.africarisk.net)
  • The ARMA marketing website and any associated public pages (africarisk.net and subdomains)
  • All other ARMA services, applications, and communications

(Collectively, the "Services".)

This policy is designed to comply with:

  • Kenya Data Protection Act, 2019 (administered by the Office of the Data Protection Commissioner)
  • South Africa Protection of Personal Information Act, 2013 (POPIA)
  • Nigeria Data Protection Act, 2023
  • Ghana Data Protection Act, 2012 (Act 843)
  • EU General Data Protection Regulation (GDPR) and UK GDPR
  • California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
  • Other applicable data protection laws in jurisdictions where our users reside

Where this policy and any applicable local law conflict, the law most protective of your rights prevails for users in that jurisdiction.

We are the data controller for personal information processed through the Services, except where we act as a data processor on behalf of an institutional client (for example, when delivering a white-labelled academy programme to a client's employees, or when handling personal data on behalf of a sponsor under a written Data Processing Agreement — see Section 6.2).


2. Who we are and how to contact us

Africa Risk Management Advisors Limited
Peponi Road, Westlands
Nairobi, Kenya
Phone: +254 10 359 4400

For all privacy-related enquiries and data subject requests: dpo@africarisk.net

(The same address reaches our Data Protection Officer and the broader privacy function. Use this single inbox for all of: access requests, deletion requests, rectification, portability, complaints, breach reports, and general privacy questions.)

For other matters:

  • Advisory engagements: advisory@africarisk.net
  • Academy: academy@africarisk.net
  • General enquiries: hello@africarisk.net

We have appointed a Data Protection Officer (DPO) responsible for overseeing this policy and answering questions about it. Contact the DPO at dpo@africarisk.net.

For users in the EU/UK, our designated representative for data protection enquiries can be contacted at dpo@africarisk.net.


3. What information we collect

We collect different categories of personal information depending on which Service you use.

3.1 Information you provide directly

When you submit an Advisory engagement request or contact us

  • Name, work email, work phone, role/title
  • Institution name and (if applicable) industry, jurisdiction
  • Description of the work you need help with
  • Source of referral / how you heard about ARMA
  • Any other information you choose to include

When you become an Advisory client and engage ARMA

  • Information required to perform the engagement (regulatory frameworks in scope, deliverable requirements, point-of-contact details)
  • KYC documentation when you sign up as a sponsor, anchor, or institutional client (corporate registration, beneficial ownership, director identification, compliance attestations, authorised signatory information)
  • Engagement deliverables, working papers, and correspondence

When you enrol in ARMA Academy as an individual learner

  • Name, email, country of residence
  • Professional credentials (e.g., ACCA / ICPAK / CIMA membership number) if you elect to track CPD
  • Payment information (processed by our payment sub-processor — we do not store full card numbers)
  • Course enrolments, lesson progress, quiz answers, completion data
  • Any content you submit (capstone exercises, free-text assessment responses)

When your institution enrols you in a white-labelled Academy programme

  • The same data categories as the individual learner above, where your employer or sponsoring institution is the data controller and ARMA acts as the data processor under a written Data Processing Agreement (DPA) (see Section 6.2)

When you are an L&D administrator at a sponsoring institution and use the Institutional Portal

  • Your administrative profile (name, work email, role, institution name)
  • Records of learners you have enrolled or invited from your institution
  • Aggregated reporting on those learners' progress (configured per the DPA between ARMA and your institution)
  • Billing and subscription information for your institutional licence
  • White-label branding configuration (logos, colours, domain) you upload

When you use Risk Advisor (riskadvisor.africarisk.net)

  • Email, name, country
  • Subscription tier (free, Pro, Enterprise)
  • Queries you submit to the AI Risk Advisor (treated as user-generated content)
  • Competency assessment responses
  • Generated learning paths and history
  • CPD activity log entries (Pro+ tiers)

When you apply to or join the ARMA Bench (consultant network)

  • Full name, professional credentials, work history, references, CV
  • Banking details (for fee payment, processed by our payment sub-processor)
  • Professional indemnity insurance details (where applicable)
  • Sample work product or anonymised case studies you elect to share
  • Onboarding-state records (your progression through the bench-onboarding workflow)
  • Sandbox engagement deliverables and review notes (used for bench admission decisions)

When you use the ARMA Developer Portal (developers.africarisk.net)

  • Developer account information (name, work email, organisation, intended use case)
  • API keys and access tokens (which you can revoke at any time)
  • API usage logs and rate-limit metrics
  • Webhook configurations and endpoint URLs
  • Sandbox / test environment data you upload
  • Integration partner contractual details

3.2 Information collected automatically

When you use any ARMA-hosted website or portal — including the public marketing site, the Academy, the Advisory client portal, the Institutional portal, the Risk Advisor product, or the Developer Portal:

  • IP address, browser type and version, device type, operating system
  • Pages visited, time on page, clickstream
  • Referring URL (e.g., LinkedIn, search engine, direct)
  • Approximate location derived from IP (country/city level only)
  • Cookies and similar tracking technologies (see Section 11)

3.3 Information from third parties

We may receive information about you from:

  • Your employer or sponsoring institution, when they enrol you in a programme
  • Sign-in providers (e.g., Google) when you choose social sign-in
  • Public professional networks (e.g., LinkedIn) when you sign up using those credentials
  • Referral partners
  • Publicly available regulatory or professional registries (for accreditation verification)
  • AML/CFT and sanctions screening services for institutional client onboarding (legal-basis: legal obligation under AML regulations)

3.4 Special category data

We do not intentionally collect special category data (racial or ethnic origin, religious beliefs, health information, sexual orientation, biometrics, etc.) through the Services. If you voluntarily include such information in free-text fields (for example, in an advisory engagement request, an AI Risk Advisor query, or a free-form assessment response), we will treat it with additional care and may seek explicit consent before processing it for any purpose other than responding to your request.

We do not knowingly process information of children under the age of 18. The Services are intended exclusively for finance and risk-management professionals.


4. How we use your information

We use your information for the following purposes, on the legal bases noted.

Purpose Legal basis (GDPR / EU) Legal basis (Kenya DPA, POPIA, NDPA equivalent)
Respond to your Advisory engagement request Performance of a contract / pre-contractual steps at your request Performance of a contract; legitimate interest
Deliver Advisory engagements you have contracted Performance of a contract Performance of a contract
Deliver Academy courses you have enrolled in Performance of a contract Performance of a contract
Manage white-label Academy delivery for sponsoring institutions Performance of a contract Performance of a contract
Issue certificates and CPD evidence Performance of a contract Performance of a contract; legitimate interest
Anchor verified certificates to a public blockchain (Polygon) for tamper-evidence Performance of a contract; legitimate interest in credential integrity Legitimate interest; consent at enrolment
Provide AI Risk Advisor responses and personalised learning paths Performance of a contract; legitimate interest in product improvement, with safeguards (Section 4.1) Performance of a contract; legitimate interest
Provide Developer Portal API access Performance of a contract; legitimate interest Performance of a contract
Monitor API usage for billing, security, and abuse prevention Performance of a contract; legitimate interest Performance of a contract
Onboard, vet, and pay bench consultants Performance of a contract; legal obligation (tax, AML) Performance of a contract; legal obligation
Send transactional communications (account, course updates, certificate delivery, billing, security alerts) Performance of a contract Performance of a contract
Send marketing communications (newsletter, course launches, programme updates) Consent (opt-in only) Consent (opt-in only)
Improve the Services, including aggregate analytics Legitimate interest, with safeguards (Section 4.1) Legitimate interest, with safeguards
Detect and prevent fraud, abuse, and security incidents Legitimate interest; legal obligation Legitimate interest; legal obligation
Comply with regulatory and legal obligations Legal obligation Legal obligation
Conduct AML/CFT and sanctions screening on sponsor and institutional client accounts Legal obligation; legitimate interest Legal obligation

We will not use your information for any purpose that is materially different from those listed above without first informing you and, where required, obtaining your consent.

4.1 Automated decision-making and AI processing

ARMA Academy and Risk Advisor use AI models (currently provided by Anthropic and Pictory under written commercial agreements) to generate course materials, deliver AI advisory responses, and personalise learning paths.

  • No solely-automated decisions with legal or similarly significant effects are made about you. Final advisory recommendations and any decisions that may affect your professional standing are reviewed by a qualified human practitioner.
  • You may request human review of any AI-generated output that affects you by emailing dpo@africarisk.net.
  • AI sub-processors are bound by data processing agreements that prohibit them from training their models on your personal information without your explicit consent (see Section 6 for the current list).
  • Your free-text inputs to Risk Advisor, free-text assessment answers in Academy, or free-text in engagement requests are stored, used to improve YOUR experience (history, follow-up context), and may be analysed in aggregate for product improvement. They are not used to train third-party AI models.

5. How we protect your information

We implement technical and organisational measures appropriate to the risk, including:

  • Encryption in transit (TLS 1.2+) and at rest for sensitive data
  • Role-based access control with least-privilege principles
  • Multi-factor authentication for staff accounts with access to personal data
  • Audit logging of access to KYC documents and other high-sensitivity records
  • Regular security testing and dependency vulnerability scanning
  • Incident response procedures with notification commitments under Section 12
  • Cryptographic anchoring of high-integrity records (e.g., certificates) to a public blockchain for tamper-evidence — note that only one-way hashes, never personal data, are anchored on chain

No system is 100% secure. While we use reasonable measures, we cannot guarantee absolute security. If you have reason to believe your interaction with us is no longer secure, please contact dpo@africarisk.net immediately.


6. Who we share your information with

We share personal information only with the following categories of recipients.

6.1 Sub-processors (data processors acting on our instructions)

Sub-processor Purpose Location of processing
Hetzner Online GmbH Cloud hosting (compute, storage, databases) Germany / EU
Cloudflare, Inc. DNS, content delivery network, DDoS protection, video edge cache Global edge network
Anthropic, PBC AI for course generation, AI Risk Advisor responses, bench-onboarding sandbox AI drafts United States (with Standard Contractual Clauses)
Pictory AI, Inc. Video generation for course content United States (with Standard Contractual Clauses)
Resend, Inc. Transactional email delivery United States (with Standard Contractual Clauses)
Polygon Labs Public blockchain anchoring of verified certificates (one-way hashes only — no personal data on chain) Decentralised global network
Payment processor — to be named at point of payment Card and account-to-account payment processing Subject to PCI-DSS
AML/CFT and sanctions screening provider Onboarding of institutional clients (KYC/AML compliance) Subject to provider's DPA

We require each sub-processor to:

  • Process personal information only on our written instructions
  • Implement security measures at least as protective as our own
  • Notify us of any data breach within 24 hours of becoming aware
  • Permit audits or independently-verified security assessments

The current authoritative sub-processor list is maintained at https://africarisk.net/legal/subprocessors — defer to that URL as the authoritative current list; this policy lists sub-processors as of the version publication date.

6.2 Institutional clients (where ARMA acts as a processor)

When your employer or sponsoring institution enrols you in an Academy white-label programme, contracts ARMA for an Advisory engagement involving your data, or otherwise causes ARMA to process your personal data on their behalf, that institution is the data controller for your data, and ARMA acts as a processor on their behalf under a written Data Processing Agreement.

Direct your data-subject requests to your institution's data protection contact in those cases. We will support your institution in responding to your request promptly.

  • Polygon blockchain anchoring — When you complete a course and elect to receive a verifiable certificate, a one-way cryptographic hash of your certificate metadata is anchored to the Polygon blockchain. The on-chain record does not include your name, email, or any personal data — only a hash that is meaningless without the certificate file you hold. You can request that future certificates not be anchored by emailing dpo@africarisk.net before enrolment. Already-anchored hashes cannot be removed by the design of blockchain technology, but as no personal data is on chain, this does not expose you.
  • CPD body submissions — When you elect to submit your CPD evidence to a professional body (e.g., ACCA myCPD, ICPAK, CIMA), we may share the minimum data required for that submission, with your express consent at the point of submission.

We may share information when required to:

  • Comply with a court order, subpoena, or other legal process
  • Comply with regulatory requirements (e.g., AML/CFT obligations)
  • Protect the rights, property, or safety of ARMA, our users, or others
  • Investigate fraud or security incidents

Where legally permitted, we will notify you in advance of any such disclosure.

6.5 Corporate transactions

If ARMA is acquired, merged, or part of any business combination, your information may be transferred to the acquiring or continuing entity. We will give you advance notice and an opportunity to object where the law permits.

6.6 We do not sell personal information

ARMA does not sell, rent, or trade personal information for monetary or other valuable consideration. This commitment applies regardless of jurisdiction.


7. International data transfers

Some of our sub-processors are located outside of Kenya, the EU, the UK, and other jurisdictions where our users reside. When personal information is transferred outside your country of residence:

  • We rely on Standard Contractual Clauses (EU/UK GDPR), adequacy decisions where they exist, or equivalent safeguards under your local law
  • We conduct transfer impact assessments for transfers to jurisdictions without adequacy decisions
  • We use technical measures (encryption, pseudonymisation) to reduce risk
  • For Kenya-resident users, all critical transfers are notified to the Office of the Data Protection Commissioner where required

For a copy of the safeguards we rely on for any specific transfer, email dpo@africarisk.net.


8. How long we keep your information

We retain personal information only as long as necessary for the purposes for which it was collected, and to comply with legal, accounting, or reporting requirements.

Data type Retention period
Account and profile data (all portals) For the duration of your account, plus 12 months after closure (or longer if legally required)
Course enrolment and progress data For the duration of your account, plus 7 years for CPD evidence retention (industry standard)
Certificate and credential data Indefinitely for the credential record itself (you may request deletion of personally-identifying records, but blockchain hash anchors are immutable by design — only the hash, never personal data, is on chain)
Advisory engagement records For the duration of the engagement plus 7 years (audit, tax, and regulatory requirements)
KYC and AML data 7 years from the end of the relationship (AML/CFT regulatory requirement)
Institutional administrator records For the duration of the institutional contract plus 7 years
Risk Advisor query history (free tier) 90 days unless you have an active Pro or Enterprise subscription
Risk Advisor query history (Pro / Enterprise tier) For the duration of your subscription plus 12 months
Bench consultant records (active) For the duration of the bench relationship
Bench consultant records (after departure) 7 years post-departure for tax and regulatory purposes; PII reduced where not needed
Developer Portal API keys and usage logs For the duration of your developer account; usage logs 24 months
Marketing communication preferences and opt-outs Indefinitely (to honour your unsubscribe choices)
Web analytics (aggregated) Up to 26 months in identifiable form, then aggregated indefinitely
Security and audit logs 12-24 months

After the retention period, we either securely delete or anonymise the data so that you can no longer be identified from it.


9. Your rights

Subject to your jurisdiction's law, you have the following rights:

Right What it means
Access You can request a copy of the personal information we hold about you
Rectification You can correct information that is inaccurate or incomplete
Erasure ("right to be forgotten") You can request deletion in defined circumstances
Restriction of processing You can ask us to pause processing in defined circumstances
Data portability You can receive your data in a structured, commonly-used, machine-readable format
Objection You can object to processing based on legitimate interest or for direct marketing
Withdraw consent Where processing is based on consent, you can withdraw it at any time (does not affect prior processing)
Not be subject to solely-automated decisions with legal or similarly significant effects (see Section 4.1)
Lodge a complaint with the supervisory authority in your jurisdiction (Section 13)

9.1 How to exercise your rights

Email dpo@africarisk.net with the heading "Data Subject Request" and:

  • The specific right you are exercising
  • Sufficient information for us to verify your identity (typically your registered email address plus one additional confirmation)
  • Where applicable, the specific data or processing activity in question

We will respond within 30 days of verifying your identity, unless your request is complex, in which case we will let you know within 30 days and respond fully within 90 days.

There is no charge for most requests. We may charge a reasonable fee or refuse to act on manifestly unfounded or excessive requests.

9.2 Authorised agent requests (California residents)

If you are a California resident, you may designate an authorised agent to make requests on your behalf. We will require proof of the agent's authority and your identity verification before acting.


10. Sensitive personal information disclosure (US state laws)

For users in California and other US states with similar laws:

  • ARMA does not sell or share personal information for cross-context behavioural advertising
  • ARMA does not use sensitive personal information for any purpose other than what is necessary to provide the Services
  • You have the right to limit the use of sensitive personal information — exercise this right by emailing dpo@africarisk.net

11. Cookies and tracking technologies

We use cookies and similar technologies for:

  • Strictly necessary cookies — session management, authentication, security (always on; cannot be disabled)
  • Functional cookies — remembering your preferences (you can disable)
  • Analytics cookies — Google Analytics 4 for aggregated usage statistics (you can disable; we honour Global Privacy Control signals)
  • Performance and error monitoring cookies — to detect and diagnose issues (you can disable)

We do not use third-party advertising cookies or cross-site tracking for ad targeting.

Our cookie banner allows you to consent or decline non-essential cookies. You can change your preferences at any time via the "Cookie Preferences" link in the footer of our websites.

Do Not Track and Global Privacy Control (GPC) — we honour GPC signals as a valid opt-out under California law.


12. Data breaches

In the unlikely event of a personal data breach that is likely to result in a risk to your rights and freedoms:

  • We will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where required by law
  • We will notify you without undue delay when the breach is likely to result in high risk to you
  • Our notification will describe the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures we have taken or propose to take to address the breach

13. Supervisory authorities and complaints

You have the right to lodge a complaint with your jurisdiction's data protection authority. Examples:

We encourage you to contact us first at dpo@africarisk.net so we can address your concerns directly.


14. Changes to this policy

We may update this policy from time to time. When we make material changes:

  • We will update the "Effective date" and "Version" at the top
  • We will notify registered users by email at least 14 days before the changes take effect
  • For non-material changes (typos, clarifications), we will update the "Last reviewed" date without a separate notification
  • We will maintain a public version history at https://africarisk.net/legal/privacy/history

Continuing to use the Services after the effective date of a revised policy constitutes your acknowledgement of the changes. If you do not agree to the changes, you may close your account and stop using the Services.


15. Specific addenda for institutional clients

When ARMA acts as a data processor on behalf of an institutional client (white-label Academy programmes, custom advisory engagements involving the client's employees, institutional Risk Advisor seat licences, or any other arrangement under which ARMA processes the client's data subjects' information), a separate Data Processing Agreement (DPA) governs that relationship and prevails over this policy where the two address the same matter.

Institutional clients can request our standard DPA template, including Standard Contractual Clauses for international transfers, by emailing legal@africarisk.net.


16. Children

ARMA's Services are intended exclusively for finance and risk-management professionals aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, please contact dpo@africarisk.net and we will delete the information immediately.


17. Specific provisions for the ARMA Developer Portal

Developers and integration partners accessing ARMA APIs via the Developer Portal agree to additional terms:

  • API keys and access tokens are confidential to your organisation; you are responsible for protecting them
  • API usage is logged for security, billing, abuse-prevention, and capacity-planning purposes
  • Developer agreements may impose additional obligations on you when you process personal data of ARMA users or your end-users via our APIs — in such cases, you may act as a data controller, processor, or joint controller, and a separate DPA will define the relationship
  • Sandbox / test environment data may include synthetic personal data; do not use production personal data in sandbox environments

18. Specific provisions for the ARMA Bench (consultant network)

Bench consultants who join ARMA's anonymized consultant network are subject to additional privacy provisions documented in the bench engagement agreement. Of particular note:

  • ARMA's "disintermediation guardrail" means your name will not be exposed to clients on any client-facing surface — only your role and qualifications are presented
  • Banking information for fee payment is processed only by our payment sub-processor and is not retained in our application databases beyond what is necessary for tax / regulatory record-keeping
  • Sandbox engagement deliverables and review notes are used internally for bench admission decisions; you have the right to request a copy of these records

Contact

For any privacy-related question, request, or complaint:

Email: dpo@africarisk.net
Post: Data Protection Officer, Africa Risk Management Advisors Limited, Peponi Road, Westlands, Nairobi, Kenya


End of policy


Document control

Version Date Author Approver Summary
1.0 2026-06-07 Cowork (acting Head of Compliance) Kefa Nyakundi (Managing Partner) — pending Initial version superseding all prior policies. Covers all six ARMA product surfaces (Advisory, Academy individual, Academy institutional, Risk Advisor, Developer Portal, marketing site). Multi-jurisdictional compliance: Kenya DPA, POPIA, NDPA, Ghana DPA, GDPR, UK GDPR, CCPA. Sub-processor list current as of effective date.

Next scheduled review: 2026-12-07 (6-month cadence)