Privacy Policy

This Privacy Policy explains how OccuHealth Solutions (“we”, “us”, or “our”) collects, uses, stores, and protects your personal data when you visit our website at occuhealthng.com, purchase and access our online courses, or engage with our services. We are committed to protecting your privacy in accordance with the Nigeria Data Protection Act 2023 (NDPA) and the Nigeria Data Protection Commission General Application and Implementation Directive (GAID) 2025, which together constitute the current governing framework for data protection in Nigeria.

By using our website or purchasing a course, you agree to the practices described in this policy.

What Personal Data We Collect

We collect the following categories of personal data:

Personal Identification Information

  • •    Full name
  • •    Email address
  • •    Phone number (where provided)
  • •    Organisation or employer name (where provided)

Payment Information

  • •    Payment card details (processed securely by Paystack or Stripe — we do not store card details on our servers)
  • •    Billing address
  • •    Transaction records

Course and Learning Data

  • •    Course enrolment and purchase history
  • •    Course progress and completion data
  • •    Assessment scores and certificates issued

Technical and Usage Data

  • •    IP address
  • •    Browser type and version
  • •    Device information
  • •    Pages visited and time spent on the site
  • •    Referring website or source

Why We Collect It and How It Is Used

We collect and use your personal data for the following purposes:

  • •    To process your course purchase and provide access to course materials
  • •    To communicate with you about your enrolment, including confirmation emails and course access details
  • •    To track your course progress and issue certificates of completion
  • •    To send relevant updates about new courses, services, or offers from OccuHealth Solutions (you may opt out at any time)
  • •    To respond to enquiries, complaints, or support requests
  • •    To improve our website, courses, and services through usage analytics
  • •    To meet our legal and regulatory obligations

Who We Share Your Data With

We do not sell your personal data. We share it only with trusted third-party service providers necessary to deliver our services, as set out below. All third-party processors are engaged under written Data Processing Agreements as required by the NDPA, which legally bind them to handle your data securely, support data subject rights, and comply with applicable Nigerian data protection law.

  • •    Payment processing: Paystack and/or Stripe
  • •    Customer relationship management: FluentCRM
  • •    Website analytics: Google Analytics
  • •    Learning management system (LMS): LearnDash 
  • •    Paystack and/or Stripe : Payment processing platforms that handle transactions securely on our behalf. Each operates under Data Processing Agreements and applicable data protection standards.
  • •    FluentCRM: Our customer relationship management system, used to manage course communications and email marketing. 
  • •    Google Analytics: Used to understand how visitors use our website through anonymised usage data. You can opt out via the Google Analytics Opt-Out browser add-on.
  • •    LearnDash (LMS): Our learning management system provider, used to host and deliver course content.

How Long We Retain Your Data

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, in accordance with the data minimisation and storage limitation principles under Section 24 of the Nigeria Data Protection Act 2023. The retention periods below reflect OccuHealth Solutions’ internal data retention policy; where specific periods are prescribed by other applicable Nigerian law (such as financial record-keeping obligations), we comply with those requirements.

Account & enrolment data

3 years after your last interaction with us

Payment & transaction records

7 years, in line with Nigerian financial and tax record-keeping obligations

Course completion & certificates

5 years to support verification and audit requests

Marketing data

Until you withdraw consent or opt out, whichever is earlier

Technical & analytics data

Up to 12 months, retained in aggregated or anonymised form where possible

Where personal data is no longer required for any lawful purpose, it will be securely deleted or irreversibly anonymised.

Your Rights Under the NDPA

As a data subject under the Nigeria Data Protection Act 2023, you have the following rights under Part VI of the Act. To exercise any of these rights, please contact us using the details in Section 7. We will respond without undue delay and within any timeframes specified by the NDPC.

Right of Access (Section 34)

You may request confirmation of whether we process your personal data and obtain a copy of that data, together with information about how it is processed.

Right to Rectification

You may request that inaccurate or incomplete personal data be corrected without undue delay.

Right to Erasure

You may request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, or where there is no continuing lawful basis for processing, subject to any legal retention obligations.

Right to Restriction of Processing

You have the right to request that we limit the processing of your personal data in certain circumstances, such as where you contest its accuracy or object to its processing.

Right to Object (Section 36)

You may object to the processing of your personal data, where processing is based on legitimate interests or for direct marketing purposes. Where you object to direct marketing, we will cease processing for that purpose immediately.

Right to Data Portability (Section 38)

Where processing is based on consent or contract and carried out by automated means, you may request your personal data in a structured, commonly used, machine-readable format, and request that it be transmitted to another data controller where technically feasible.

Right to Withdraw Consent (Section 35)

Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal. You may withdraw consent as easily as it was given.

Right Regarding Automated Decision-Making (Section 37)

You have the right not to be subject to a decision based solely on automated processing; including profiling that produces legal effects or significantly affects you, without meaningful human review. Where we use automated processing, you have the right to request human review, to express your view, and to contest the decision.

Right to Lodge a Complaint

You have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe your data protection rights have been violated. See Section 7 for NDPC contact details.

We will respond to all data subject rights requests without undue delay. This is OccuHealth Solutions’ own service commitment. The NDPA does not prescribe a fixed response window but requires timely fulfilment. If your request is complex, we may extend our response time and will notify you accordingly.

Cookie Policy

Our website uses cookies and similar tracking technologies to support site functionality, analytics, and personalisation. Cookies are small text files stored on your device when you visit our site.
 
In accordance with Article 19 of the NDPC General Application and Implementation Directive (GAID) 2025, we obtain your explicit opt-in consent before activating any non-essential cookies. When you first visit our website, a cookie consent banner will be displayed. Non-essential cookies will only be activated after you have given your active consent, no pre-ticked boxes or implied consent is used.

Types of Cookies We Use

Strictly Necessary Cookies

Essential for the website to function (session management, security). These do not require consent and cannot be disabled.

Analytics Cookies

Used by Google Analytics to collect anonymised data about how visitors use the site. Only activated with your consent.

Functional Cookies

Used to remember your preferences and settings. Only activated with your consent.

Marketing Cookies

Used to measure the effectiveness of communications. Only activated where you have given explicit opt-in consent.

Managing Your Cookie Preferences

You may withdraw your consent to non-essential cookies at any time by adjusting your preferences via the cookie settings available on our website, or by adjusting your browser settings to block or delete cookies. Please note that disabling certain cookies may affect the functionality of our site. You may also prevent Google Analytics tracking via the Google Analytics Opt-Out Browser Add-on.

Data Breach Notification

OccuHealth Solutions has implemented appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure. In the event of a personal data breach, we will act in accordance with our obligations under Section 40 of the Nigeria Data Protection Act 2023:

  • •    We will notify the Nigeria Data Protection Commission (NDPC) within 72 hours of becoming aware of a breach that is likely to pose a risk to the rights and freedoms of data subjects.
  • •    Where the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay, using plain and clear language, and will include advice on steps you can take to reduce possible harm.
  • •    We maintain a breach register recording all incidents, their causes, and remedial actions taken.

Cross-Border Data Transfers

Some of our third-party service providers (including Stripe and Google Analytics) may process your personal data outside Nigeria. Where personal data is transferred outside Nigeria, we ensure that such transfers are made only in accordance with Section 41 of the NDPA, either to countries providing an adequate level of data protection, or under appropriate safeguards including Data Processing Agreements incorporating standard contractual clauses approved by the NDPC.

How to Contact Us With a Data Concern

If you have any questions about this Privacy Policy, wish to exercise your data rights, or have a concern about how we have handled your personal data, please contact us:

Organisation

OccuHealth Solutions

Email

services@occuhealthng.com

If you are not satisfied with our response, you have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC):

Regulator

Nigeria Data Protection Commission (NDPC)

Website

www.ndpc.gov.ng

This Privacy Policy may be updated periodically to reflect changes in our practices or applicable law. We will notify you of material changes by posting the updated policy on our website with a revised effective date.

Not sure where to start?

Every organisation’s occupational health needs are different. If you are not certain which services are most relevant to your business, we are happy to start with a conversation. Get in touch and we will help you identify the right priorities.