This Data Processing Agreement ("DPA") applies where an institution ("Institution") nominates, sponsors or enrols participants in a Platinum ResearchTech Academy cohort and Platinum Edu-Tech Consult Nigeria Ltd (RC 7110229) ("Platinum") processes personal data on the Institution's behalf.
It forms part of the Master Service Agreement or cohort agreement between the parties. Where Platinum deals directly with an individual participant rather than through an institution, Platinum acts as controller and our Privacy Policy applies instead.
1. Roles
For participant lists, nominations, attendance reporting and performance reporting supplied to or produced for the Institution, the Institution is the controller and Platinum is the processor.
For credential issuance, credential verification, platform security and Platinum's own record-keeping obligations, Platinum acts as controller, because Platinum must stand behind the credentials it issues.
2. Subject matter and duration
- Subject matter: delivery of Academy training, assessment, attendance tracking, reporting and certification.
- Duration: for the term of the cohort engagement, plus the limited retention period set out below.
- Categories of data subject: nominated participants, and Institution staff acting as coordinators or instructors.
- Categories of personal data: name, institutional email, phone number, department and role, attendance records, submissions and marks, credential records.
- No special-category data is requested or required. Please do not send health, biometric or similar data to us.
3. Platinum's obligations as processor
- Process personal data only on the Institution's documented instructions and for the purposes of the engagement.
- Not use participant data for marketing or for training third-party AI models on identifiable content.
- Keep personnel with access bound to confidentiality, and limit access to those who need it.
- Apply the technical and organisational measures described in section 5.
- Assist the Institution with data-subject requests, impact assessments and regulator enquiries, at reasonable cost for substantial work.
- Notify the Institution without undue delay, and in any case within 72 hours of becoming aware, of a personal-data breach affecting Institution data, with the information available at the time.
4. Institution's obligations as controller
- Ensure it has a lawful basis to nominate participants and to share their contact details with Platinum.
- Inform participants that their attendance, submissions and results will be processed and reported back to the Institution.
- Send accurate participant data, and tell us of corrections and withdrawals promptly.
- Keep any register, report or export Platinum provides secure once it leaves our platform.
5. Security measures
- Role-based access control enforced at the data layer, so a learner cannot read another learner's records and an instructor sees only assigned cohorts.
- Encryption of data in transit; storage of uploaded files behind short-lived signed links.
- Separation of administrative capabilities from ordinary accounts, including for certificate numbering.
- Audit logging of attendance changes and of administrative decisions on admission and marking.
- Regular platform and dependency security scanning, with fixes prioritised by severity.
6. Sub-processors
Platinum uses sub-processors for cloud hosting, managed database and file storage, AI-assisted marking, and email delivery. Each is bound to obligations no less protective than those in this DPA.
Platinum will maintain a current list of sub-processors and give the Institution reasonable notice before adding a new one that processes Institution data. The Institution may object on reasonable data-protection grounds; if the objection cannot be resolved, either party may terminate the affected part of the engagement without penalty.
7. International transfers
Where a sub-processor operates outside Nigeria, Platinum relies on contractual commitments to standards consistent with the Nigeria Data Protection Act framework, and will provide details on request.
8. Audit and assurance
On reasonable written notice and no more than once a year (unless a breach or regulator requires otherwise), Platinum will answer a written security questionnaire and provide available assurance documentation. On-site audits are by agreement and at the Institution's cost.
9. Return and deletion
Within 60 days of the end of the engagement, Platinum will return or delete Institution personal data processed as processor, except where retention is required by law or is necessary to keep issued credentials verifiable.
Credential records retained by Platinum as controller are limited to the minimum needed for verification.
10. Liability and precedence
Liability under this DPA is subject to the limits in the Master Service Agreement or cohort agreement between the parties. Where this DPA conflicts with those terms on data protection, this DPA prevails.
To request a signed copy of this DPA on institutional letterhead, contact info@platinumedutechconsult.com.
Still being finalised
These points are being confirmed internally and will be published in the next version of this document. Everything else above applies today.
- • Named sub-processor list and hosting regions for the annex.
- • Whether a signed counterpart is required per institution or a click-through DPA is acceptable.
- • Any institution-specific security or residency commitments.
Questions about this document? info@platinumedutechconsult.com