Currently Empty: ₦0.00
Privacy Policy
Your data,
Your data,
and exactly what we do with it.
No dark patterns, no buried clauses, no selling your information to anyone. This is a plain-English account of what we collect, why, how long we keep it and how to make us stop. Written to satisfy the strictest law that applies to you, not the most convenient one.
Last updated 8 September 2026
Greenlearners Technologies · RC 7987848
Applies worldwide
01Who we are and how to reach us
We are a Nigerian company and, for the data described here, the one responsible for it. Real contact details are below, and a person answers.
Greenlearners Technologies ("we", "us", "our") is a marketing and business growth company registered in Nigeria under RC 7987848, with its registered office at 21 Fakorede Street, Orogun, Ibadan, Oyo State, Nigeria.
For the personal data described in this notice, we are the data controller. Where we handle personal data inside a client's own systems as part of a paid engagement, we act as a data processor on that client's written instructions. Section 13 explains the difference and what governs it.
Data protection contact
Questions about this notice, or about how we handle your information, come to us directly. We answer every one.
Phone & WhatsApp+234 802 258 1304
Registered office21 Fakorede Street, Orogun, Ibadan, Oyo State, Nigeria
Response timeWithin 30 days, usually far sooner
02The laws this notice is built on
We follow Nigerian, UK, EU, US, Canadian, Australian and New Zealand privacy law, and apply whichever gives you the most protection.
We serve clients across several jurisdictions, so this notice is written to satisfy the strictest of them rather than the most convenient. Depending on where you are, one or more of the following applies to you:
- Nigeria — the Nigeria Data Protection Act 2023 (NDPA) and the NDPC General Application and Implementation Directive 2025 (GAID), enforced by the Nigeria Data Protection Commission.
- United Kingdom — the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (PECR), enforced by the Information Commissioner's Office.
- European Union, Ireland and the Netherlands — the EU General Data Protection Regulation (GDPR) 2016/679 and the ePrivacy Directive as implemented locally.
- United States — the California Consumer Privacy Act as amended by the CPRA, comparable state privacy laws, and the CAN-SPAM Act 2003 for commercial email.
- Canada — the Personal Information Protection and Electronic Documents Act (PIPEDA) and Canada's Anti-Spam Legislation (CASL).
- Australia and New Zealand — the Privacy Act 1988 with the Australian Privacy Principles, the Spam Act 2003, and the New Zealand Privacy Act 2020.
Where two laws conflict, we apply the standard that gives you more protection, not less.
03What we collect
What you send us, what your browser tells us automatically, and a little public research on prospective clients. Nothing sensitive.
Information you give us
- Contact and enquiry data — your name, email address, phone number, country, company name, website or social profiles, and anything you choose to write in a message, form or WhatsApp conversation.
- Engagement data — the information needed to scope and deliver work: your objectives, budget range, target audience and, once engaged, access credentials you grant us to your own platforms.
- Course and training data — your registration details and progress if you enrol in one of our free courses.
- Billing data — invoicing details. We do not collect or store full card numbers; payments are handled by regulated payment providers.
Information collected automatically
- Device and usage data — IP address, browser type, operating system, referring page, pages viewed, time on page and approximate location derived from IP.
- Cookies and similar technologies — described in section 5.
Information from other sources
- Advertising and analytics platforms — aggregated campaign and audience data from Google, Meta, LinkedIn and TikTok.
- Publicly available sources — company websites, LinkedIn and business directories, used only to research a prospective client we are already in contact with.
We do not knowingly collect sensitive personal data such as health, biometric, genetic, religious or political information, and we ask you not to send it to us. If it reaches us unsolicited, we delete it.
04Why we use it, and our lawful basis
Eight uses, each with the legal ground it rests on. Marketing runs on consent, and you can pull it any time.
Under the NDPA, UK GDPR and EU GDPR we must have a lawful basis for every use of your personal data. Here is ours, in plain terms.
Swipe to see all columns
| What we do | Why | Lawful basis |
|---|---|---|
| Reply to your enquiry | To answer you and, where you ask for it, prepare a free growth audit | Steps taken at your request before entering a contract; legitimate interests |
| Deliver services under contract | To perform the engagement you have signed | Performance of a contract |
| Send marketing emails | To share growth advice, offers and new courses | Your consent, withdrawable at any time |
| Analytics and site improvement | To understand what works and fix what does not | Consent for non-essential cookies; legitimate interests for aggregate analysis |
| Advertising and remarketing | To reach people likely to need our services | Your consent for tracking cookies and pixels |
| Invoicing, tax and accounting | To bill you and meet statutory record-keeping duties | Legal obligation |
| Security and fraud prevention | To protect the site, our clients and ourselves | Legitimate interests |
| Publishing a client result or testimonial | To show what our work produced | Written permission from that client |
Where we rely on legitimate interests, we have balanced those interests against your rights and concluded our use is limited, expected and not intrusive. You can object at any time using the contact details in section 1.
05Cookies and tracking
Only strictly necessary cookies run without asking. Analytics and advertising cookies wait for your consent.
Our website uses cookies and similar technologies. Strictly necessary cookies keep the site working and do not require consent. Everything else does.
- Strictly necessary — security, load balancing and remembering your cookie choice.
- Analytics — Google Analytics 4, to measure traffic and behaviour in aggregate.
- Advertising — Meta Pixel, Google Ads and LinkedIn tags, used for measurement and remarketing.
- Functional — embedded content such as YouTube (served in privacy-enhanced mode) and Google Maps.
Under PECR in the UK and the ePrivacy rules in the EU, non-essential cookies are only set after you consent. You can withdraw consent at any time through your browser settings or our cookie controls, and you can block cookies entirely without losing access to the site's content.
Do Not Track and Global Privacy Control: where your browser sends a recognised opt-out signal, we treat it as an opt-out of sale or sharing for California residents.
06Marketing, and how to stop it
We only email people who opted in, every message has a working unsubscribe, and we have never sold anyone's data.
We only send marketing to people who asked for it. Every email carries a one-click unsubscribe, and we act on it immediately rather than "within ten days".
- Consent — you opt in on a form, at a webinar, or when enrolling in a course. Pre-ticked boxes are never used.
- Existing clients — where the law permits, we may email you about services similar to those you already bought. You can opt out of this the same way.
- WhatsApp — we reply to conversations you start. We do not add you to broadcast lists without your agreement.
- No selling — we have never sold, rented or traded personal data, and we never will.
To stop everything at once, email contact@greenlearnerstechnologies.com with "unsubscribe" in the subject line.
07Who we share it with
A short list of service providers, each under a written agreement. Regulators only when the law compels us.
We share personal data only with service providers who need it to help us operate, and only under written terms that bind them to protect it. We do not sell it.
- Email and forms — SendPulse, for our subscription forms and email delivery.
- Analytics and advertising — Google (Analytics, Ads, Search Console), Meta, LinkedIn, TikTok.
- Hosting and infrastructure — our hosting provider and content delivery network.
- Messaging — WhatsApp, operated by Meta, when you message us there.
- Professional advisers — accountants and lawyers, bound by professional confidentiality.
- Authorities — only where we are legally required, and we will tell you unless the law forbids it.
Each provider processes data under our instructions, under a data processing agreement, and for no purpose of their own beyond what their own terms disclose to you.
08Sending data across borders
Your data may be processed abroad. When it is, we use adequacy decisions, standard contractual clauses or the NDPA transfer rules.
We are based in Nigeria and our providers operate globally, so your data may be processed outside your country. When that happens we rely on one of the following:
- An adequacy decision covering the destination country;
- Standard Contractual Clauses (or the UK International Data Transfer Addendum) with the provider;
- The transfer conditions in section 41 of the NDPA, including your explicit consent where relied on; or
- Necessity for the performance of a contract you have entered into.
Where a transfer carries residual risk, we apply additional safeguards such as encryption in transit and at rest, and minimise what is transferred in the first place.
09How long we keep it
Enquiries 24 months, client records 7 years, marketing until you unsubscribe. Then deleted or anonymised for good.
Swipe to see all columns
| Data | Kept for | Why |
|---|---|---|
| Enquiries that do not become clients | 24 months | So we can pick up a conversation you restart |
| Client records and deliverables | 7 years after the engagement ends | Tax, accounting and limitation periods |
| Marketing subscribers | Until you unsubscribe, plus 12 months | To honour your opt-out and prove we did |
| Course accounts | While active, plus 24 months | To reissue certificates and support alumni |
| Website analytics | 14 months | Platform default retention |
| Invoices and financial records | 7 years | Nigerian and international tax law |
When a period ends we delete or irreversibly anonymise the data. Backups are overwritten on a rolling cycle, so a deleted record may persist in backup for a short additional period before it is permanently gone.
10How we protect it
Encryption everywhere, individual accounts with multi-factor authentication, and we never take a client's customer data into our systems.
- Encryption in transit (HTTPS/TLS) across the entire website, including every form.
- Access on a need-to-know basis only, with individual accounts and multi-factor authentication on every critical platform.
- No shared logins. We never export a client's customer data out of that client's own systems.
- Written confidentiality obligations for everyone on the team and every contractor.
- Regular review of the providers we use, and removal of any that fall short.
No system is perfectly secure and anyone who claims otherwise is selling something. What we commit to is proportionate, current safeguards and honest, prompt notification if something goes wrong.
11Your rights
Access, correction, deletion, portability, objection and withdrawal of consent. Free, and answered within 30 days.
Wherever you are, you can exercise the following with us. We do not charge for this, and we do not make it difficult.
- Access — a copy of the personal data we hold about you.
- Rectification — correction of anything inaccurate or incomplete.
- Erasure — deletion, where we have no overriding legal reason to keep it.
- Restriction — ask us to pause processing while a dispute is resolved.
- Objection — object to processing based on legitimate interests, and to direct marketing at any time, absolutely.
- Portability — receive your data in a structured, machine-readable format.
- Withdraw consent — at any time, without affecting what was lawful before you withdrew it.
- Automated decisions — we do not make decisions producing legal or similarly significant effects about you by automated means alone.
If you are in California
You also have the right to know what is collected and disclosed, to delete, to correct, to opt out of "sale" or "sharing" (we do neither), to limit use of sensitive personal information, and not to be discriminated against for exercising any of these. An authorised agent may act for you with written proof.
How to exercise them
Email contact@greenlearnerstechnologies.com. We respond within 30 days for NDPA, UK and EU requests and within 45 days for CCPA requests, and we will tell you if we need an extension and why. We may ask for proof of identity, but only what is proportionate.
12Children
Our services are for adults and businesses. If a child's data reaches us, we delete it.
Our services and this website are directed at businesses and adults. We do not knowingly collect personal data from anyone under 18 in Nigeria, or under the applicable age of digital consent in their jurisdiction (13 to 16 across the UK, EU and USA).
If you believe a child has given us personal data, contact us and we will delete it promptly. Our free courses are open to adult learners; where a minor enrols, verifiable parental or guardian consent is required.
13When we handle data for a client
Inside your accounts you are the controller and we are your processor. Your accounts, pixels and data stay in your name.
During a paid engagement we often work inside systems that belong to you: your ad accounts, your analytics, your CRM, your email platform. In that context you are the controller and we are your processor.
- We act only on your documented instructions.
- Your accounts, pixels, audiences, domains and content stay in your name. We use delegated access, never shared passwords.
- We do not export your customer lists to our own systems.
- We will sign your Data Processing Agreement before touching an account. If you do not have one, we provide ours.
- On termination we return or delete what we hold and hand back access, on your instruction.
Your own privacy notice, not ours, governs how your customers' data may be used.
14If something goes wrong
If a breach puts you at risk, we notify the NDPC within 72 hours and tell you directly, plainly and quickly.
If a personal data breach occurs and it is likely to result in a risk to your rights and freedoms, we will:
- Notify the Nigeria Data Protection Commission within 72 hours of becoming aware, as required by section 40 of the NDPA, and the ICO or relevant EU supervisory authority where UK or EU data is involved;
- Notify you directly and without undue delay where the risk to you is high;
- Tell you what happened, what data was affected, what we are doing about it and what you should do; and
- Record the incident and what we changed so it does not happen twice.
15Complaints
Come to us first. If we cannot resolve it, here is your regulator in every country we serve.
Come to us first. Most concerns are a misunderstanding we can resolve the same day. If you are not satisfied, you can complain to your regulator:
- Nigeria — Nigeria Data Protection Commission (NDPC), ndpc.gov.ng
- United Kingdom — Information Commissioner's Office (ICO), ico.org.uk
- Ireland — Data Protection Commission; Netherlands — Autoriteit Persoonsgegevens; or the supervisory authority in your EU member state
- Canada — Office of the Privacy Commissioner; Australia — OAIC; New Zealand — Office of the Privacy Commissioner
- California — California Privacy Protection Agency or the Attorney General
Exercising a right or making a complaint never affects the service you receive from us.
16Changes to this notice
We update this notice when things change, and we tell you before material changes take effect.
We update this notice when our practices, our providers or the law change. The "last updated" date at the top always reflects the current version.
If a change materially affects your rights or how we use your data, we will tell you directly by email or a prominent notice on this site before it takes effect, rather than quietly editing the page.
Also worth reading
The rest of
The rest of
the small print.
LegalTerms and ConditionsThe agreement that governs our services, fees, guarantee and liability.Read the termsLegalDisclaimerWhat our results, testimonials and free content do and do not promise.Read the disclaimerTalk to usContact usQuestions about your data? Ask a person and get an answer in minutes.Message usCompanyAbout Greenlearners TechnologiesWho we are, how we work and why clients stay year after year.About usHow it worksOur growth systemThe six stages we run for every client, and why the order matters.See the systemPricingBusiness growth packagesFour levels, one system, and the growth guarantee in writing.See pricing