Legal — Privacy
Privacy policy
Last updated — 25 July 2026
This policy explains what personal data OurAfrica collects, why we collect it, how it is protected, and the choices you have. It is written to be read — plain language first, no fine print doing quiet work.
Who we are
OurAfrica operates the OurAfrica learning platform — the web application, the Windows desktop application, and the Android application (together, the “Platform”). We are based in Harare, Zimbabwe, and we act as the data controller for the personal data described in this policy.
What we collect
We collect only what the Platform needs to work:
- Account data — your name, email address, and password credentials, created when you register directly or sign in with Google. Authentication is handled through a managed identity service; we never store your password in plain text.
- Learning data — enrollments, lesson progress, quiz attempts and scores, notes, and the certificates you earn. This is the record your credentials are built on.
- Organization data — if you join the Platform through an employer or institution, we record that membership and your role within it.
- Billing data — subscription tier, purchase history, and invoices. Card details are processed by our payment providers and never touch our servers.
- Technical data — device type, app version, and diagnostic logs used to keep the Platform reliable.
How we use your data
- To deliver the Platform: courses, progress tracking, quizzes, and certificates.
- To let you learn offline: course content and your progress are stored on your device and synced when you reconnect.
- To issue verifiable certificates that anyone can check against our records.
- To bill subscriptions and purchases, and send receipts.
- To keep the Platform secure, diagnose faults, and improve reliability.
- To answer your support requests.
We do not sell your personal data, and we do not use it for third-party advertising.
What your organization can see
If your account is linked to an organization’s subscription, that organization’s administrators can see your enrollment status, course progress, and completion records for courses within their program — that visibility is the product they are paying for. They cannot see your personal notes, and your certificates and learning history remain yours: they stay with your account if you leave the organization.
How we protect your data
- All traffic between your device and our servers is encrypted in transit (TLS).
- Authentication uses short-lived, automatically-refreshed session tokens held in secure cookies.
- Courses downloaded for offline use are stored on your device encrypted with AES-GCM; on desktop, an offline PIN and operating-system keystore credentials protect access when you are away from the internet.
- If you use the optional AI study tools with your own provider key, that key is stored on your device — not on our servers.
- Access to production data inside OurAfrica is restricted and audited.
We align our practices with Zimbabwe’s Data Protection Act and with internationally recognized data-protection principles, including those of the GDPR and South Africa’s POPIA, for learners across the continent.
How long we keep it
Your learning record is deliberately durable: certificates and completion history are retained so they can be verified years later — if your subscription lapses, your record is paused, never wiped. Account data is kept while your account is active. Diagnostic logs are kept only as long as needed for reliability work.
Your rights
You can, at any time:
- Access a copy of the personal data we hold about you.
- Correct inaccurate profile data (most of it directly, in Settings).
- Request deletion of your account and associated personal data — noting that issued certificates carry a verification record we retain in minimal form.
- Object to or restrict specific processing.
To exercise any of these, email [email protected]. We respond within 30 days.
Changes to this policy
When this policy changes in a way that matters, we will say so in the Platform before the change takes effect — the “last updated” date at the top always reflects the current revision.