1 Introduction
Obi Ogbonnia Sickle Cell Foundation (OOSCF) is deeply committed to protecting your privacy.
This policy outlines how we collect, use, and safeguard personal information across all
interactions — whether you engage with us as a donor,
volunteer, partner, or website visitor.
By using our website at ooscf.com, you consent to the data practices
described in this policy. We uphold the highest standards of data protection aligned
with GDPR, CCPA, and Nigerian data protection regulations (NDPR).
2 Information We Collect
We collect only the information necessary to serve you effectively and advance our mission against sickle cell disease.
Donors
Name, email, billing address, payment details (via secure third-party gateways), and donation preferences including anonymity selections on the Virtual Donor Wall.
Volunteers
Full name, contact details, skills inventory, background check data (where legally required), and stated availability.
Partners
Organization name, designated contact person details, and the terms of any signed collaboration agreements.
Website Users
IP address, browser cookies, device metadata, and aggregated browsing behavior via analytics tools such as Google Analytics.
3 How We Use Your Information
- Process donations securely and issue tax receipts where applicable.
- Acknowledge donors on the Virtual Donor Wall — unless you select "Do Not Show My Name."
- Send updates, programme news, events, and volunteer opportunities.
- Conduct background checks for volunteers (with explicit prior consent).
- Improve website functionality, performance, and accessibility.
- Comply with our legal and regulatory obligations under applicable laws.
4 Who We Share Your Data With
Third-Party Payment Processors
Flutterwave and Paystack handle transaction data securely using industry-grade encryption. We do not store, log, or have access to your card or banking details.
Cryptocurrency Platforms
Coinbase and Binance process blockchain transactions on our behalf. Wallet addresses are pseudonymized to protect your identity.
Password Reset Emails
Your IP address is included in password reset emails for verification and security purposes only.
No other third parties receive your personal data unless compelled by applicable law or court order.
5 Embedded Content from Other Websites
Articles and pages on OOSCF.com may include embedded content — such as videos, images,
or social media widgets. This embedded content behaves exactly as if you had visited
the originating website directly. Those external sites may collect data about you,
use cookies, embed additional third-party tracking, and monitor your interactions,
particularly if you are logged into their platforms.
We recommend reviewing the privacy policies of any third-party platforms whose content appears on our website.
6 How Long We Retain Your Data
-
Comments & Metadata: Retained indefinitely to enable moderation and auto-approve follow-up comments from established users.
-
User Profiles: Registered users' personal data is stored within their profile. Users may request to edit or delete their personal information at any time (excluding usernames). Administrators can also access and manage this data where required.
-
Donation Records: Retained for a minimum of seven (7) years for financial audit and legal compliance purposes.
7 Your Rights
OOSCF fully recognises your rights regarding your personal data. You may exercise any of the following at any time:
Access & Correction
Request a full copy of your stored data or correct any inaccuracies.
Deletion
Ask us to erase your data, subject to legal or administrative holds.
Opt-Out
Unsubscribe from any communications or revoke consent at any time.
GDPR & CCPA
EU and California residents may exercise additional rights under applicable law.
To exercise any right, contact us at info@ooscf.com. We will respond within 30 days.
8 Security Measures
We implement layered security controls to protect your personal data at every stage of processing:
256-bit SSL/TLS encryption for all data transmission between your browser and our servers.
Role-based access controls strictly limiting who can view your personal information.
Regular security audits and penetration testing of all third-party vendor systems.
Two-factor authentication enforced for all administrative accounts.
Automatic data breach notification protocols aligned with GDPR Article 33 requirements.
9 International Data Transfers
As a globally engaged foundation, your data may be stored and processed in countries
outside your own. Where such transfers involve EU residents' data, we ensure
compliance with GDPR Chapter V requirements, including Standard Contractual Clauses (SCCs)
or equivalent safeguards.
By using our website and services, you acknowledge and consent to such international transfers as described herein.
10 Children's Data
OOSCF does not knowingly collect, store, or process personal data from children under
the age of 13 without verified parental or guardian consent. Our programmes that
involve minors are conducted under strict safeguarding protocols.
If you believe we have inadvertently collected data from a child, please contact us
immediately at info@ooscf.com and we will delete such data without delay.
11 Media & Location Data
If you upload images or media files to our website (as a registered contributor or
through our contact forms), please take care to avoid uploading files that contain
embedded location data (EXIF GPS metadata). Our systems do not automatically strip
this metadata, and other visitors could potentially download and extract location
information from any media files you upload.
12 Cookies & Tracking Technologies
Our website uses cookies to enhance your experience and measure site performance. By continuing to use OOSCF.com, you agree to our use of cookies as described below.
Comment Cookies
If you leave a comment, you may opt in to saving your name, email address, and website URL in cookies for your convenience. These persist for 1 year.
Login Cookies
Temporary session cookies verify browser acceptance (no personal data; expire on browser close). Standard login cookies last 2 days; screen preferences last 1 year. "Remember Me" extends login to 2 weeks. Logging out removes all login cookies immediately.
Editor Cookies
Editing or publishing content saves a lightweight cookie containing only the post ID — no personal data. Expires after 1 day.
Analytics Cookies
Google Analytics may use cookies to collect aggregated browsing behaviour data to help us improve our website. No personally identifiable information is shared with Google Analytics.
13 Where Your Data Is Sent
Visitor comments submitted through our website may be run through an automated spam
detection service (e.g., Akismet) to maintain content quality. The data processed
consists only of the comment content and associated metadata.
No other unauthorised transfers or disclosures of your personal data to external parties occur.
14 Policy Updates
We may revise this Privacy Policy from time to time to reflect changes in our
practices, legal requirements, or service offerings. All updates will be published
on this page with an updated "Last Updated" date.
Your continued use of our website following any published revision constitutes
your acceptance of the updated policy. Where changes are material, official
notification will be sent via email to all registered users, donors, volunteers,
and partners within 24 hours of publication.
✉ Contact Us
Questions, requests, or concerns about this policy? Our Data Protection team is ready to help.