1. Who we are and scope
Create Cri8 (“CRI8”, “we”, “us” or “our”) provides creative programs, training, projects, professional services, volunteer opportunities and digital products from Nigeria. For personal data collected through mycri8.com and our related services, Create Cri8 is the data controller unless a notice says otherwise.
This policy covers visitors, customers, learners, tutors, donors, volunteers, applicants, business contacts and people shown in approved portfolio content. It does not govern third-party sites linked from our services.
2. Information we collect
- Contact and identity data: name, email address, telephone number and communications.
- Transaction and service data: orders, bookings, registrations, donation choices, currency, price, payment status, receipts, cancellation or refund records and service requirements. We do not collect or store full card numbers; an authorised payment provider handles payment details when payments are enabled.
- Application and content data: skills, motivation, portfolio links, quote requests, optional private attachments, tutor profiles, media permissions and content you submit.
- Technical and security data: IP address, request time, browser or device information, security events, session identifiers and limited server logs.
- Usage data: privacy-safe interaction events such as page or call-to-action activity. We configure analytics not to accept names, email addresses, phone numbers or free-text form content.
- Information from others: information a project partner, tutor or authorised representative provides where they are entitled to do so.
3. Why we use information and our lawful bases
- To answer enquiries and take steps you request before a contract.
- To provide and administer purchases, training, programs, services and downloads; process cancellations and refunds; and keep transaction records necessary to perform a contract.
- To assess volunteer applications and manage projects with your consent or at your request.
- To send essential service, safety, transaction and logistics messages. These are not marketing messages.
- To prevent fraud, abuse and security incidents; protect users and systems; improve reliability; and establish or defend legal claims, based on legitimate interests.
- To comply with tax, accounting, consumer-protection, law-enforcement and other legal obligations.
- To publish a tutor profile, testimonial, identifiable photograph or public donor identity only on an appropriate legal basis, including consent where required. Consent may be withdrawn for future use.
Where information is required to enter or perform a contract, not providing it may mean we cannot fulfil the request. We do not use solely automated decision-making that produces legal or similarly significant effects.
4. Sharing and processors
We disclose only what is reasonably necessary to staff and authorised contractors; Oracle Cloud for application and database hosting; Cloudflare-compatible object storage for private files; email and monitoring providers when configured; payment providers when enabled; professional advisers; and public authorities where lawfully required. Providers act under their own terms or our instructions, as applicable. We do not sell personal information.
If a partner is independently responsible for an event or service, we will identify that partner before sharing attendee or customer information.
5. International transfers
Our infrastructure or providers may process information outside Nigeria, including in the United Arab Emirates and other countries where our providers operate. We assess transfers and use contracts, security measures, consent, adequacy decisions or another lawful transfer mechanism as required by the Nigeria Data Protection Act 2023 and applicable foreign law. Contact us for information about safeguards relevant to your data.
6. Retention
- Uncompleted registration, booking and checkout records: normally up to 30 days after expiry, unless needed for security or a dispute.
- General enquiries and unsuccessful applications: normally up to 12 months after closure.
- Successful applications and service-delivery records: for the engagement plus normally up to 24 months.
- Contracts, orders, payments, receipts, refunds and accounting records: normally 7 years or the longer period required by law or an active dispute.
- Security logs: normally up to 12 months; audit records may be kept longer where necessary to protect the service.
- Public content and consent records: while published and for a reasonable period afterward to document permissions and handle claims.
These are default maximums, not promises to retain every record for the full period. We delete, anonymise or restrict data sooner when it is no longer needed, subject to legal holds, fraud prevention, backups and financial-record duties.
7. Your rights
Subject to applicable law and exemptions, you may ask us to confirm processing; access or obtain a copy; correct inaccurate data; delete data; restrict or object to processing; receive portable data; withdraw consent; and complain to a regulator. We may verify identity, clarify a request, or retain limited information where law permits or requires it.
People in Nigeria may complain to the Nigeria Data Protection Commission. If European, UK or other foreign privacy law applies, you may also complain to your local supervisory authority and exercise the rights that law provides.
Contact Create Cri8 through our contact form. Put “Privacy request”, “Refund request”, or “Legal notice” in the subject so it reaches the correct team. Do not send passwords, card details, identity documents, or other unnecessary sensitive information.
8. Children
Our general website is not directed to children under 18 and they must not purchase, donate, apply, or submit personal data without a parent or legal guardian’s involvement. A program intentionally offered to minors will use a separate age-appropriate notice, collect verifiable guardian authorisation where required and limit the data collected. Contact us if you believe a child submitted information improperly.
9. Security and incidents
We use access controls, encryption in transit, restricted private storage, malware scanning, authentication controls, logging, backups and data-minimisation measures appropriate to the risks. No system is completely secure. If a personal-data breach occurs, we will investigate, contain it and notify affected people and regulators where and within the time required by applicable law.
10. Cookies, changes and contact
See our Cookie Notice. We will post material policy changes here and change the effective date; where required, we will give additional notice or request fresh consent. The policy in force when we collected information continues to govern that processing unless law or an agreed update provides otherwise.
Contact Create Cri8 through our contact form. Put “Privacy request”, “Refund request”, or “Legal notice” in the subject so it reaches the correct team. Do not send passwords, card details, identity documents, or other unnecessary sensitive information.