Skip to main content

Privacy

Your information should be useful, protected and understandable.

This page explains the main types of information EEPAC handles, why they are needed and the choices available to applicants and participants.

Information we handle

Only what supports the program and its safe operation

Depending on how you use EEPAC, this can include contact details, registration answers, business-stage information, support preferences, account and cohort records, attendance, learning progress, submitted evidence, facilitator feedback, communications and limited technical security records.

Why we use it

To review registrations and deliver the program

Information is used to process registrations, communicate outcomes, create approved accounts, manage cohorts, provide learning and support, protect the service, keep an audit trail, issue completion records where applicable and produce approved aggregate program reporting.

Access and sharing

Access follows role and responsibility

Program staff see only the information needed for their authorised work. Facilitators are restricted to assigned cohorts and relevant evidence. Technical providers may process information where needed to host, secure or operate the service under the organisation’s arrangements. EEPAC is not designed to publish private business evidence or participant support details.

Security and retention

Protected records, controlled access and defined retention

The platform uses protected account access, role-based permissions, encryption for sensitive application and profile records, audit logging and private evidence storage. Records are retained according to the approved program schedule and applicable obligations, then reviewed for deletion, anonymisation or continued authorised retention.

Essential cookies may be used for sign-in, security and saved sessions. Any optional analytics or marketing technology should be described separately before it is enabled.

Your choices

Ask, correct, update or raise a concern

You can ask the program team to explain the information connected to you, correct inaccurate details, update communication preferences or direct a privacy concern to the responsible organisation. Some records may need to be retained where required for program administration, security, funding accountability or law.

Privacy contact: admin@eepac.ca

Current registration privacy notice

EEPAC Application Privacy Notice

Approved version notice-02e91adc2a0b86013062d29e

Africa Centre administers the EEPAC program and is responsible for the application information described in this notice. Questions, correction requests and privacy enquiries can be sent to admin@eepac.ca.

Scope of this notice

This notice applies when a person starts, saves, submits or follows up a EEPAC application and when the program team reviews that application. A separate participant record is created only after acceptance, secure invitation and account activation.

Information collected

The application may collect the applicant’s name, preferred name, email address, phone number, city or town, province or territory, preferred contact method, current business stage, business name, description of the business idea or activity, product or service, intended customer, first-sale experience, program goals, requested areas of support, delivery preference, accessibility or language support requests, digital-support preference, referral source and the consent choices displayed on the form. The platform also records application status, secure-link events, timestamps, staff review notes, decisions and limited technical security records needed to protect the service.

How the information is obtained

Most information is provided directly by the applicant. Authorised program staff may add review notes, decision reasons, contact outcomes and cohort-planning information. The platform may generate security and audit records when secure links, forms or administrative actions are used.

Purposes

The information is used to provide secure save-and-return registration, assess the application through human review, request clarification, communicate the decision, arrange accessibility or language support, plan appropriate delivery, issue a secure participant invitation after acceptance, prevent duplicate or unauthorised accounts, support cohort assignment, operate and secure the service, respond to enquiries and meet documented program, funding, safeguarding, dispute-resolution or legal requirements. Optional program updates are a separate choice and are not required for an application decision.

Human review and decisions

EEPAC does not use the registration form to make a solely automated acceptance decision. Authorised staff consider the submitted information against the current program purpose, capacity and documented review standard. Applicants may be asked for more information and may contact the program team about a decision or correction.

Access and service providers

Access is limited to authorised staff whose assigned role requires application review, onboarding, participant support, privacy administration, audit or technical security work. Contracted providers may process the minimum information needed to host, back up, secure or deliver the platform and its transactional email. Applicant information is not sold. Identifiable application information is not used for unrelated marketing without a separate choice or other documented authority.

Security

Application records are stored in the protected EEPAC data layer and encrypted at rest. Secure return and activation links are time-limited and stored as non-reversible token hashes. Staff access is capability-controlled, material actions are logged, and messages are designed to contain only the information needed for the relevant service step. No online service can eliminate every risk, so suspected misuse or disclosure should be reported promptly.

Retention and disposal

The operational baseline is 730 days after the application reaches its final decision or is otherwise no longer required for active administration. A shorter or longer period may apply where a documented legal, contractual, funding, safeguarding, complaint, investigation or dispute requirement applies. At the end of the approved period, records are securely deleted or de-identified through the governed retention process, subject to the organisation’s backup and legal-hold arrangements. Accepted applicants who activate an account have separate participant and learning records governed by the relevant participant controls.

Applicant choices and requests

Applicants can correct a draft through their secure return link before submission. After submission they may contact the program team to request access, correction, withdrawal or other privacy support. Identity verification may be required before protected information is released or changed. Withdrawing an application does not require the organisation to erase records that must be retained for a documented reason. Optional communication preferences can be changed without affecting the original application decision.

Changes and contact

The version shown with this notice is the version that applies to the relevant application. Material changes are published as a new version. Contact admin@eepac.ca with questions or requests.