1. Introduction
CadreHealth is operated by Consult For Africa Limited ("we", "us", "our"). We are committed to protecting your personal data in compliance with the Nigeria Data Protection Regulation (NDPR) 2019 and the Nigeria Data Protection Act (NDPA) 2023. This policy explains what data we collect, how we use it, and your rights.
2. Data We Collect
We collect the following categories of data:
- Account data: name, email, phone number, password (hashed), cadre, location
- Professional data: credentials, qualifications, CPD records, work history, years of experience
- Salary data: self-reported compensation, allowances, facility type (anonymized before display)
- Reviews: hospital ratings and written feedback (cadre displayed, name withheld by default)
- Assessment data: career readiness quiz responses and computed scores
- Usage data: pages visited, features used, device type (collected via standard web analytics)
3. How We Use Your Data
Your data is used to:
- Provide and improve Platform features (salary map, hospital reviews, credential tracking)
- Generate aggregated, anonymized insights for the community
- Compute your career readiness scores and personalized roadmaps
- Match you with relevant career opportunities (only with your consent)
- Send you account-related communications (verification, password reset)
- Send the CadreHealth Report newsletter (if subscribed, with easy opt-out)
4. Anonymization Guarantees
We take anonymization seriously. Salary data is aggregated into groups of at least 3 reports before being displayed. No individual salary figure is ever shown. Reviews display your cadre and employment type but not your name. We apply statistical methods to prevent re-identification in small groups.
5. Legal Basis for Processing
We process your data based on:
- Consent: you provide data voluntarily when registering, submitting reviews, and reporting salary
- Contractual necessity: to deliver the services you signed up for
- Legitimate interest: to improve the Platform and produce aggregated career intelligence
6. Data Retention
Your account data is retained for as long as your account is active. If you delete your account, personal data is removed within 30 days. Anonymized, aggregated data (salary statistics, anonymized review data) may be retained indefinitely as it cannot be linked back to you. Assessment results are retained for 24 months from the date of the assessment.
7. Third-Party Sharing
We do not sell your personal data. We may share data with:
- Service providers: hosting (Vercel), database (Supabase/Neon), email (Zoho). These providers process data on our behalf under data processing agreements.
- Employers/recruiters: only if you explicitly opt in to be visible in candidate searches
- Legal authorities: if required by law or to protect the rights and safety of our users
We never share your individual salary, review, or assessment data with employers, hospitals, or any third party.
8. Data Security
We use industry-standard security measures including encryption in transit (TLS), hashed passwords (PBKDF2 with SHA-512), secure cookies, and access controls. Our infrastructure is hosted on certified cloud platforms with SOC 2 compliance.
9. Your Rights
Under the NDPR and NDPA, you have the right to:
- Access: request a copy of your personal data
- Rectification: correct inaccurate data in your profile
- Erasure: request deletion of your account and personal data
- Objection: object to processing of your data for specific purposes
- Portability: request your data in a machine-readable format
- Withdraw consent: withdraw consent at any time for optional processing
To exercise any of these rights, contact us at platform@consultforafrica.com.
10. Cookies
We use essential cookies for authentication (session token). We do not use advertising or tracking cookies. Analytics cookies, if used, are anonymized and do not track individuals across websites.
11. Children
CadreHealth is intended for qualified healthcare professionals and students aged 16 and above. We do not knowingly collect data from children under 16.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated to registered users via email. The "Last updated" date at the top reflects the most recent revision.
13. Contact and Complaints
For privacy-related enquiries or complaints, contact our Data Protection Officer at platform@consultforafrica.com. You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).