
Privacy
Home > Privacy
AAIPA PRIVACY AND DATA-USE NOTICE
1. Who we are
This Notice is issued by the African Asset Integrity Professionals Alliance (AAIPA) owned by Asset Integrity Professionals Alliance Global (AIPAG). For the processing described here, AAIPA acts as data controller except where a contract states that AAIPA processes information only on another organisation's documented instructions.
2. Who and what this Notice covers
This Notice applies to website visitors, enquirers, membership applicants and members, inspectors, engineers, trainers and technical specialists, client representatives, Opportunity-Originating Members, Execution Partner applicants and personnel, event participants, referees, assessors, administrators and other individuals whose information is processed through AAIPA's website or portals.
It covers personal data processed through public forms, authenticated accounts, the professional directory, membership verification, the Member Project Partnership process, client requests, Execution Partner due diligence, training registration, project workspaces, communications and website security logs. Separate agreements govern confidentiality, non-circumvention, professional delivery and particular projects.
3. Information AAIPA may collect
3.1 Identity and contact information
- Name, photograph where chosen, country, city or region, telephone/WhatsApp number, email address, preferred language and communication preferences.
- Organisation, job title, professional role, business address and authorised-representative details.
3.2 Professional and membership information
- CV, disciplines, experience, education, licences, qualifications, certifications and expiry dates, training records, languages, availability, geographic coverage, references, project history and membership tier/status.
- Assessment outcomes, verification results, complaints, restrictions, suspension or disciplinary records where necessary and handled with restricted access.
3.3 Execution Partner information
- Corporate registration, ownership and representatives; tax or regulatory records; permits; insurance; equipment and calibration information; personnel capacity; HSE and QA/QC systems; geographic coverage; references; conflicts; due-diligence and performance results.
3.4 Client, opportunity and project information
- Client contacts, facility/site, sector, scope, assets, required codes and standards, timetable, procurement route, tender/RFQ documents, pricing assumptions, instructions and communications.
- Opportunity provenance, identity of the Opportunity-Originating Member, relationship to the client, date/evidence of introduction, requested role or benefit and disclosure preferences.
- Where authorised: drawings, equipment registers, inspection histories, photographs, NDT or thickness data, defect/corrosion information, shutdown plans, HSE conditions, bids, reports, certificates and project deliverables.
3.5 Website and transaction information
- IP address, device/browser data, authentication and security logs, access/download activity, cookie choices, form history, acceptance records, document versions, payment status and communications.
- AAIPA will not store full payment-card details where payment is handled by an approved payment provider.
4. How information is collected
- Directly from the individual or authorised organisational representative.
- From employers, referees, credential issuers, professional bodies, regulators, clients and public corporate/professional records during verification.
- From Opportunity-Originating Members or clients who are authorised to identify proposed project participants or contacts.
- Automatically through website security, authentication and consented cookie technologies.
- From Execution Partners, project teams and clients during bidding, mobilisation, delivery, quality review and close-out.
A person submitting information about someone else will have authority or another lawful basis to do so and will direct that person to this Notice where practicable.
5. Why AAIPA uses information
| Purpose | AAIPA-specific use |
|---|---|
| Website and account operation | Provide pages, forms and portals; authenticate users; maintain security and respond to support requests. |
| Membership | Assess applications; verify credentials; allocate and maintain tiers/status; administer renewal, training and member communications. |
| Professional directory | Publish only approved public fields; allow profile correction and manage verified status. |
| Capability matching | Identify professionals and Execution Partners suited to an anonymised enquiry or opportunity. |
| Member Project Partnership | Validate provenance; protect the Opportunity-Originating Member; shortlist capacity; structure bidding, contracting and delivery. |
| Client requests and projects | Clarify scope; manage controlled disclosures; support proposals, mobilisation, quality, reporting, complaints and close-out. |
| Execution Partner governance | Conduct due diligence, conflict checks, continuing assessment, performance monitoring and corrective action. |
| Legal, safety and integrity | Prevent fraud, impersonation, misuse and circumvention; maintain audit evidence; respond to lawful requests; protect safety and legal claims. |
| Training and communications | Administer events and essential service messages; send optional marketing only with an appropriate choice. |
| Aggregated insight | Create statistics that do not identify a person, client, site, opportunity or project. |
6. Grounds for processing
Depending on the activity and applicable law, AAIPA may process information with consent; to take requested pre-contractual steps or perform an agreement; to meet legal, regulatory, safety, tax, accounting or professional duties; and for legitimate alliance purposes that do not improperly override individual rights.
Where explicit consent is relied on, it may be withdrawn for future processing, but withdrawal does not invalidate earlier lawful processing or override necessary legal retention.
7. Mandatory and optional information
Each form will identify mandatory fields. Without essential identity, contact, authority, verification or scope information, AAIPA may be unable to create an account, assess membership, publish a verified profile, evaluate an Execution Partner, protect opportunity provenance, respond to a client or grant project access. Marketing, optional profile fields and non-essential cookies will not be made conditions of core service unless genuinely necessary.
8. Public profiles
AAIPA will publish only fields clearly marked Public and approved for publication. Verification documents, government identification, residential address, date of birth, bank/payment details, personal rates, referee contacts, disciplinary material, private assessment notes, client lists and confidential project history will not be public by default. See the AAIPA Public Directory and Profile Publication Policy.
9. Who may receive information
- Authorised AAIPA administrators, assessors and country representatives with role-based access.
- Shortlisted members and Execution Partners, initially through anonymised briefs and later only through controlled disclosure.
- Clients and client-approved project personnel receiving relevant capability, bid or delivery information.
- Credential issuers, referees, professional bodies, regulators or public registers used for proportionate verification.
- Contracted hosting, storage, email, form, identity, security, analytics, payment or support providers operating under written restrictions.
- Professional advisers, insurers, auditors, law-enforcement bodies, courts or regulators where legally justified.
AAIPA does not sell personal data, member contact lists, client enquiries or project leads. Directory information may not be harvested or used for mass solicitation.
10. Controlled project disclosure
Client identity, tender documents and Project Restricted information are not ordinary directory data. AAIPA will disclose them only to approved recipients, for a defined purpose, after conflict checks and acceptance of the applicable project-specific confidentiality and client-protection undertaking. The portal will log the recipient, document/version, purpose and time of access.
11. Cross-border processing
AAIPA may operate across Ghana, Nigeria, Liberia and additional countries. Authorised personnel or providers in another country may therefore access information. Before enabling such access, AAIPA will assess the destination, purpose, recipient, safeguards, client contract and applicable local law. Personal data originating from another jurisdiction and processed in Ghana will receive the protection required by applicable law, including the foreign-law consideration required by Act 843. Regulated, critical-infrastructure, export-controlled or security-sensitive project information requires a separate review.
12. Retention
AAIPA retains information only for as long as needed for the stated purpose and applicable legal, contractual, audit, insurance, professional or dispute obligations. Operational defaults will be documented in an internal retention schedule.
| Record | Indicative retention position |
|---|---|
| Incomplete account | Delete or anonymise after 90 days following notice, unless security or dispute needs justify retention. |
| Rejected membership/partner application | Normally 12 months after final decision, subject to complaints, fraud concerns or legal hold. |
| Active profile | For the active relationship, reviewed at least annually; remove unnecessary information after exit. |
| Verification copy | Delete once verification and challenge needs end where the result can be retained instead. |
| Closed, unaccepted enquiry/opportunity | Normally 12 months, subject to provenance, dispute, legal or client requirements. |
| Project/tender material | Contractual, limitation, audit, insurance and regulatory period; client instructions apply where stricter. |
| Security/access logs | Normally at least 12 months; longer for restricted projects where proportionate. |
| Marketing choice | Evidence while relied upon; minimal suppression record after opt-out. |
13. Security
- Unique accounts, least privilege, project-based permissions and multi-factor authentication for privileged roles.
- Encryption in transit and appropriate protection at rest and in backups.
- Separation of public profiles, verification documents, opportunity provenance and project workspaces.
- Logging of sign-in, role changes, approvals, restricted access/downloads and administrator actions.
- Supplier due diligence, written processor restrictions, malware protection, patching, backup and recovery testing.
- Incident response, evidence preservation, containment, legal assessment and required notifications.
No security method is perfect. Users will protect their credentials and promptly report suspected unauthorised access to support@aaipaafrica.com.
14. Individual rights and choices
- Ask whether AAIPA holds personal data and request access in an understandable form.
- Ask for correction or deletion of inaccurate, irrelevant, excessive, out-of-date, incomplete or misleading information.
- Object to direct marketing and withdraw optional marketing consent.
- Ask AAIPA to stop or restrict processing likely to cause unwarranted damage or distress, subject to lawful grounds.
- Ask who has received or previously accessed the information where the applicable law provides.
- Complain to AAIPA and, where applicable, the Ghana Data Protection Commission or another competent regulator.
AAIPA may verify identity, protect the rights and confidentiality of others, and retain information required by law, contract, safety, professional accountability or legal claims. Requests may be sent to support@aaipaafrica.com.
15. Children
AAIPA's membership, professional and Execution Partner services are intended for adults and authorised organisational representatives. AAIPA does not knowingly invite children to create professional accounts. Event pages involving minors require a separate child-data and guardian-consent assessment.
16. Automated decisions and AI
AAIPA will not make a decision with significant membership, disciplinary, partner-approval or project-allocation effects solely through automated processing without appropriate human review. Users may not upload Project Restricted or confidential portal content into public AI systems unless the information owner and AAIPA have expressly approved the tool and safeguards.
17. Changes to this Notice
AAIPA may update this Notice when its services, countries, technologies or legal duties change. The website will identify the version and effective date. Material changes affecting registered users will be communicated and, where necessary, require renewed acknowledgement or consent.
18. Contact and complaints
Privacy requests, incidents and general website support: support@aaipaafrica.com. Postal contact: IF 53 BlayEsthers' Place, Padmore Street, Community One, Tema, Ghana. If a concern remains unresolved, an individual may contact the Ghana Data Protection Commission through its official channels or another competent regulator.
Primary references: Ghana Data Protection Act, 2012 (Act 843); Ghana Data Protection Commission organisational guidance; and, for accessibility, W3C Web Content Accessibility Guidelines (WCAG) 2.2. References do not convert draft legislation or non-Ghana standards into applicable Ghanaian law.