Privacy Policy
What we collect, why, how long we keep it, and what you can ask us to do with it.
Last updated 29 July 2026
Who we are
CHEER MEDICS FOUNDATION is a Nigerian non-governmental organisation. We provide scholarships and mental-health support to medical students, and healthcare to elderly people who would otherwise go without.
For the purposes of the Nigeria Data Protection Act 2023 we are a data controller — we decide what personal data is collected and what happens to it. Because we operate in the health sector and will hold records for more than 200 people, we are a controller of major importance under the Act, which carries additional duties. We set out below where we meet those and where we do not yet.
We are not yet registered with the Nigeria Data Protection Commission. Registration is required of controllers of major importance and we are working through it. We are telling you because it is true, not because we are obliged to publish it.
Data protection contact
We have not yet appointed a Data Protection Officer. The Act requires one of an organisation like ours and we are recruiting for it. In the meantime everything described on this page still applies and every request reaches a real person: use the contact form and mark it “data protection”.
What we hold, and why
We hold different things about different people. This is the whole of it.
If you donate
- Your name and email address, so we can send a receipt.
- The amount, the date, and which programme you chose.
- A reference from our payment provider.
We never see or store your card details. Card payments are handled entirely by Paystack; the card number does not pass through our systems and is not on our servers. If you choose to give anonymously we still hold your name and email — we have to, to send the receipt and to account for the money — but your name appears in no public acknowledgement.
If you apply for assistance
- Your name and contact details.
- Your circumstances, in your own words.
- Information about your household income.
- Documents you upload in support.
- Where a payment is made, the details needed to make it.
This is the most personal thing most people will ever send us. It is encrypted in our database, it is visible only to the small number of staff who assess applications, and it is never used to decide anything other than the application it was sent for.
If you are a patient at one of our clinics
See Health information below. It is treated separately because it is different.
If you volunteer
- Your name, contact details and the skills you told us about.
- Your availability, the shifts you took, and the hours you logged.
- An account on this site, once your application is approved.
If you subscribe to our newsletter
- Your email address, and the date you confirmed it.
We use double opt-in: subscribing sends you an email, and nothing else is sent until you click the link in it. We do this so that nobody can sign you up to our mail. Every email carries a one-click unsubscribe link and it works immediately.
If you just read the website
- A session cookie, so that pages work.
- Server logs, which include IP addresses, kept 90 days.
We do not use advertising trackers, we do not sell anything to anyone, and we do not build profiles of visitors. See our Cookie Policy.
Health information
Where we run a clinic, we hold clinical records: dates of birth, blood type, addresses, emergency contacts, appointment notes, and the reasons people came to us.
Under the Act this is sensitive personal data, and it gets stricter handling than anything else we hold:
- It is encrypted in the database, not merely behind a password. Somebody holding a copy of our database still cannot read it.
- Only clinicians can reach it. Access is by role, and the roles are enforced by the software rather than by policy.
- Every time a record is opened, that is recorded — who opened it, which record, and when. We can tell you who has looked at yours.
- Appointment reminders say when and where and nothing clinical. A text arriving on a shared phone should not disclose why you are coming.
We will not discuss your care with anybody without your say-so — not a relative, not an employer, not a donor — unless we are required by law to do so, or somebody is at immediate risk of serious harm. If that ever happens we will tell you, unless telling you would itself create the risk.
Our lawful basis
The Act requires a specific reason, recognised in law, for every kind of processing. Ours are:
| What | Why we are allowed to |
|---|---|
| Donation records | Performing our side of the transaction, and our legal duty to keep financial records |
| Assistance applications | Your consent, given when you submit the form |
| Clinical records | Your consent, and the provision of healthcare |
| Volunteer records | Performing our agreement with you |
| Newsletter | Your consent, confirmed by clicking the link in the opt-in email |
| Website logs and session cookies | Our legitimate interest in a working, secure website |
Where the basis is consent you may withdraw it at any time and we will stop. Withdrawing consent does not undo what was lawful before you withdrew it — we cannot un-send a receipt or un-treat a patient — but it stops everything from that point.
Who else sees it
We share personal data with these, and no others:
| Who | What they get | Why |
|---|---|---|
| Paystack | Your name, email and the amount | To take the payment. A licensed Nigerian payment processor. |
| Our email provider | Your email address and the message | To deliver receipts, replies and newsletters. |
| Our hosting provider | Everything, as the machine it runs on | To run the website. |
| Our backup storage | An encrypted archive | So a failure does not lose your records. The archive is encrypted before it leaves our server. |
We do not sell personal data. We do not share it with advertisers. We do not give donor lists to anyone. We may be required to disclose information by a court or by law, and if that happens we will tell you unless we are forbidden from doing so.
How it is protected
- The whole site is served over HTTPS.
- Sensitive fields are encrypted in the database, including everything clinical.
- Session records are encrypted, because they sit in the same database.
- Staff accounts that can reach money, awards or patient records must use two-factor authentication. This is enforced, not encouraged.
- Every consequential action is written to an audit trail.
- Backups are encrypted before they leave our server and are stored off it.
- There is no public sign-up. Staff accounts are created by an administrator.
No system is perfectly secure and we will not claim otherwise. What we can say is that these are real controls, in place now, rather than intentions.
How long we keep it
| What | How long |
|---|---|
| Donation and financial records | 7 years |
| Clinical records | 7 years after the last contact |
| Assistance applications that were granted | 3 years |
| Assistance applications that were not granted | 1 year |
| Volunteer records | 3 years after you stop volunteering |
| Newsletter subscription | Until you unsubscribe |
| Website server logs | 90 days |
Your rights
Under the Act you can ask us to:
- Show you what we hold about you.
- Correct it if it is wrong.
- Delete it, where we are not required to keep it.
- Stop or limit what we are doing with it.
- Give you a copy in a form you can take elsewhere.
- Withdraw consent you previously gave.
Ask through the contact form. It is free, and we will respond within 30 days. If we cannot do what you asked, we will tell you why in plain language rather than citing a section number at you.
If you are not satisfied with how we handled it you can complain to the Nigeria Data Protection Commission. You do not have to come to us first, though we would rather you did — see our complaints procedure.
Children
This website is not intended for children and we do not knowingly collect information from anyone under 18 through it.
Our clinics may treat children, and where they do we act on the consent of a parent or guardian and hold the record under the same protections set out above. If you believe we hold information about a child that we should not, tell us and we will remove it.
Data leaving Nigeria
Some services we depend on are outside Nigeria: our backup storage and our error-monitoring service may hold data abroad. The Act allows this where there are adequate safeguards, and ours are that the backup archive is encrypted before it leaves our server — the storage provider holds a file it cannot read — and that error reports are stripped of personal information before they are sent.
If you donate from outside Nigeria, your payment is processed by Paystack and your card issuer, and their own terms apply to that transaction.
If something goes wrong
If personal data we hold is lost, stolen or exposed, the Act requires us to notify the Nigeria Data Protection Commission within 72 hours of becoming aware of it. Where the breach is likely to put you at real risk we must also tell you directly, without undue delay.
We will do both. We will tell you what happened, what it means for you, and what we are doing about it — in plain language, promptly, and without waiting until we have a comfortable account of it.
What we have not finished
Most privacy policies describe an ideal. These are the places where ours does not yet match, as at the date at the top of this page:
- We have not appointed a Data Protection Officer.
- We have not completed registration with the Nigeria Data Protection Commission.
- We have not yet rehearsed a restore from backup. Backups are taken and encrypted; we have not proved we can bring one back.
We would rather publish this than a policy that reads as though everything is finished. If any of it matters to a decision you are making, ask us and we will tell you where we have got to.
Changes to this policy
When we change this page we will change the date at the top. If a change materially affects what we do with information we already hold, we will tell the people affected directly rather than relying on them to re-read it.
Questions about this page
Write to us through the contact form or at info@cheermedics.org. We answer every message about privacy, safeguarding or a complaint — those are not marketing enquiries and they are not treated as such.