Privacy Notice
1. Who is responsible for your information
NRS TECH VENTURES (Pty) Ltd, registration number 2026/588319/07, a private company incorporated in the Republic of South Africa and trading as AfriLearn, is the responsible party under the Protection of Personal Information Act 4 of 2013 in respect of personal information processed through the AfriLearn website and services ("AfriLearn", "we", "us"). Our address is Unit 3, Cedar Park, 24 Cedar Street, Bryanston, Johannesburg, 2191. The Information Officer is Nicolene Renske Steyn, reachable at nrstechven@proton.me; general learner questions can go to info@afrilearnai.co.za. See also the Company Information page.
2. What we collect, and what we deliberately do not
Information that stays on your device
The course stores your study state in your own browser's local storage: your first name or chosen display name, your field of study, year of study, the concern you selected at onboarding, which lessons you have opened, your quiz scores and practice activity, your session token once signed in, and the claim token described below. This is what makes the course work offline: the lessons continue to run with the connection switched off, and your work is sent to us when you are next online. Because the course now requires an account, this browser copy is a working cache rather than the only record, and the server copy described below is what restores you on another device.
Information we receive and store
- When you create an account or sign in: the name you give for your certificate, your email address, and a hashed one-time sign-in code that is valid for 10 minutes and deleted when used. We never store the code itself, and there are no passwords. An account is required before any course content, including the free module, so that your progress is recoverable.
- While you are signed in: your course progress (lessons opened, practice activity and the personalisation choices above) is saved to our servers against your account email, so that it can be restored when you sign in on another device.
- Your quiz results: for each module we record your best score, whether you passed, how many attempts you have made and the date and time of your most recent attempt. We keep these because your quizzes are marked by us rather than by your browser, so this record is what a certificate is issued against, and because the date of your last attempt is what the 48 hour interval between attempts is measured from. Your individual answers are marked and are not stored.
- When you buy the course: the name you entered for your certificate, your verified account email, and a randomly generated claim token pass through the checkout so that your certificate can be issued to the right person and linked to your account. Our payment provider sends us a payment reference number.
- When a learner is under 18: the guardian-consent process collects the parent or guardian's name and email address, and the one-time sign-in code goes to the guardian's inbox rather than the learner's. We store the guardian's name, email address, the date and time of consent, and the version of the terms consented to, as the record that POPIA sections 34 and 35 contemplate.
- At checkout: we record your separate consents (to immediate performance, and your acknowledgement of the liability clause), each with a timestamp and the terms version, because the law requires us to be able to show they were actively given.
- When a lecturer or institution arranges class access: we hold the email addresses on the class list, the class label, and the grant status, supplied to us by the lecturer for the purpose of giving those students free access.
- When a certificate is issued: we store the certificate ID, your name as it appears on the certificate, the course name, the issue date, the certificate status, the payment reference or class grant reference, your email address and the claim token.
- Technical logs: our hosting provider keeps short-lived request logs (such as IP addresses and pages requested) for security and fault diagnosis. We do not use them to profile you.
Payment card details
We never see or store your card number or banking credentials. Payment is processed by PayFast, a South African payment provider, on its own secure pages, under its own privacy policy. PayFast is an independent responsible party for the payment information you give it.
3. Why we process this information, and on what basis
| Purpose | POPIA justification |
|---|---|
| Creating and operating your account: sending one-time sign-in codes, maintaining sessions | Performance of the contract, and steps at your request prior to purchase (section 11(1)(b)) |
| Saving your course progress to your account and restoring it across devices | Performance of the contract (section 11(1)(b)) |
| Recording guardian consent for learners under 18 and sending sign-in codes to the guardian | Consent of a competent person (sections 11(1)(a), 34 and 35), and our legal obligation to be able to demonstrate it |
| Recording checkout consents (immediate performance; liability acknowledgement) | Performance of the contract and our legal obligations under ECTA and the CPA (sections 11(1)(b) and (c)) |
| Administering class access lists supplied by a lecturer or institution | Our and the students' legitimate interests in delivering sponsored access (section 11(1)(f)); performance of the contract once the student signs in |
| Processing your purchase and issuing your certificate | Performance of the contract you conclude with us when you buy the course (section 11(1)(b)) |
| Public verification of certificates (see section 4 below) | Performance of the contract, and our and your legitimate interests in credible, checkable credentials (section 11(1)(f)) |
| Emailing your certificate to you | Performance of the contract |
| Security, fraud prevention and fault diagnosis | Our legitimate interests (section 11(1)(f)) |
| Complying with tax and financial record-keeping laws | Legal obligation (section 11(1)(c)) |
Providing your name at checkout is voluntary, though without it we cannot put a name on your certificate. We do not use your information for direct marketing. If that ever changes, we will ask for your consent first, as POPIA section 69 requires.
4. Certificate verification is public by design
The point of an AfriLearn certificate is that anyone can check it. If a person has your certificate ID, our verification page will show them your name as it appears on the certificate, the course name, the issue date and whether the certificate is valid. Nothing else is disclosed, and the ID itself cannot be guessed from your name. Share your certificate ID with the people you want to be able to verify it.
5. Who processes information on our behalf
We use a small number of service providers as operators under POPIA section 20: Vercel (website hosting and serverless functions), Supabase (the database that stores account, progress, class access, certificate and payment records) and Resend (delivery of sign-in codes and certificate emails). Each processes information only on our instructions and under contractual confidentiality and security obligations.
6. Cross-border transfers
Our hosting and database providers store information on infrastructure outside South Africa, including in the United States and the European Union. POPIA section 72 permits this where the recipient is bound by a law or binding agreement providing substantially similar protection, or where the transfer is necessary for the performance of your contract with us. Our providers are bound by contractual data protection terms, and the transfer of your name and payment reference is necessary to deliver the service you bought. By accepting this notice you also consent to these transfers.
7. How long we keep information
- Sign-in codes: 10 minutes at most, stored only as hashes, and deleted on use or expiry.
- Account, progress and quiz records: for as long as your account is in use, and for at least 365 days after an access period ends so that a learner who buys a further access period resumes with their results intact. Deletable at your request as described under your rights below, on the understanding that deleting your quiz results removes the record a certificate would be issued against.
- Guardian consent and checkout consent records: for as long as the related account or purchase may give rise to a claim or query, and at least five years for transaction-linked consents.
- Class access lists: until the grant is revoked by the lecturer or the class arrangement ends.
- Certificate records: for as long as the verification service exists, because deleting them would silently invalidate the certificate you earned.
- Payment records: at least five years, as tax and financial legislation requires.
- Technical logs: days to weeks, per our hosting provider's standard retention.
8. Security
Certificate IDs are cryptographically signed, so forged IDs fail verification. All traffic to the site is encrypted in transit. Database access is restricted to keys held server-side, and the public can never read claim tokens, email addresses or payment references from our database. No system is perfectly secure, and POPIA section 22 obliges us to notify you and the Information Regulator if a breach of your personal information ever occurs.
9. Your rights
Under POPIA you may ask us: what personal information we hold about you (also see our PAIA Manual); to correct or delete information that is inaccurate, irrelevant, excessive, out of date or unlawfully held; and to object to processing based on legitimate interests. Deleting your account and server-stored progress is possible at your request. Deleting your certificate record is also possible, on the understanding that your certificate will then no longer verify. Write to the Information Officer at nrstechven@proton.me and we will respond within a reasonable time.
You may also complain to the Information Regulator (South Africa): Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191; POPIAComplaints@inforegulator.org.za; general enquiries enquiries@inforegulator.org.za; 010 023 5200.
10. Children: the guardian-consent process
The course is intended for tertiary level students, and POPIA sections 34 and 35 prohibit processing a child's personal information unless an authorisation applies, including the prior consent of a competent person. AfriLearn therefore operates a guardian-consent process for any learner under 18:
- An under-18 learner cannot complete sign-in or purchase alone. The learner indicates their age, provides the parent or guardian's name and email address, and the one-time verification code is sent to the guardian's email. By entering that code and confirming the guardian declaration, the competent person authorises the account, the purchase where applicable, and the processing described in this notice, and becomes the contracting party for any purchase, as clause 4 of the Terms of Service provides.
- We store the guardian's name and email address, the consent timestamp and the terms version, as the demonstrable record of that consent. We may ask for reasonable further verification of the guardian's identity or authority.
- We do not send direct marketing to anyone, and would in any event not direct electronic marketing at a child; if marketing to an under-18 account were ever introduced, the competent person's separate consent would be obtained first.
- A guardian may at any time ask what we hold about the learner, ask us to correct or delete it, or withdraw consent, by writing to the Information Officer at nrstechven@proton.me. Withdrawal does not affect processing that has already lawfully occurred, and deleting a certificate record ends its verifiability.
A short plain-language explanation for young learners appears at the top of this notice.
11. Cookies and similar technologies
We set no advertising or analytics cookies. The site uses your browser's local storage and a service worker cache for one purpose only: making the course work, offline included. These hold your study state and copies of course files on your device, under your control. The Cookie Notice describes them in full.
12. Changes to this notice
If we change this notice materially, we will update the version and date above and ask you to accept the new version before you continue using the course.
See also the Terms of Service, the Disclaimer and the PAIA Manual.