Privacy

Home > Privacy

AAIPA PRIVACY AND DATA-USE NOTICE

1. Who we are

This Notice is issued by the African Asset Integrity Professionals Alliance (AAIPA) owned by Asset Integrity Professionals Alliance Global (AIPAG). For the processing described here, AAIPA acts as data controller except where a contract states that AAIPA processes information only on another organisation's documented instructions.

2. Who and what this Notice covers

This Notice applies to website visitors, enquirers, membership applicants and members, inspectors, engineers, trainers and technical specialists, client representatives, Opportunity-Originating Members, Execution Partner applicants and personnel, event participants, referees, assessors, administrators and other individuals whose information is processed through AAIPA's website or portals.

It covers personal data processed through public forms, authenticated accounts, the professional directory, membership verification, the Member Project Partnership process, client requests, Execution Partner due diligence, training registration, project workspaces, communications and website security logs. Separate agreements govern confidentiality, non-circumvention, professional delivery and particular projects.

3. Information AAIPA may collect

3.1 Identity and contact information

  • Name, photograph where chosen, country, city or region, telephone/WhatsApp number, email address, preferred language and communication preferences.
  • Organisation, job title, professional role, business address and authorised-representative details.

3.2 Professional and membership information

  • CV, disciplines, experience, education, licences, qualifications, certifications and expiry dates, training records, languages, availability, geographic coverage, references, project history and membership tier/status.
  • Assessment outcomes, verification results, complaints, restrictions, suspension or disciplinary records where necessary and handled with restricted access.

3.3 Execution Partner information

  • Corporate registration, ownership and representatives; tax or regulatory records; permits; insurance; equipment and calibration information; personnel capacity; HSE and QA/QC systems; geographic coverage; references; conflicts; due-diligence and performance results.

3.4 Client, opportunity and project information

  • Client contacts, facility/site, sector, scope, assets, required codes and standards, timetable, procurement route, tender/RFQ documents, pricing assumptions, instructions and communications.
  • Opportunity provenance, identity of the Opportunity-Originating Member, relationship to the client, date/evidence of introduction, requested role or benefit and disclosure preferences.
  • Where authorised: drawings, equipment registers, inspection histories, photographs, NDT or thickness data, defect/corrosion information, shutdown plans, HSE conditions, bids, reports, certificates and project deliverables.

3.5 Website and transaction information

  • IP address, device/browser data, authentication and security logs, access/download activity, cookie choices, form history, acceptance records, document versions, payment status and communications.
  • AAIPA will not store full payment-card details where payment is handled by an approved payment provider.

4. How information is collected

  • Directly from the individual or authorised organisational representative.
  • From employers, referees, credential issuers, professional bodies, regulators, clients and public corporate/professional records during verification.
  • From Opportunity-Originating Members or clients who are authorised to identify proposed project participants or contacts.
  • Automatically through website security, authentication and consented cookie technologies.
  • From Execution Partners, project teams and clients during bidding, mobilisation, delivery, quality review and close-out.

A person submitting information about someone else will have authority or another lawful basis to do so and will direct that person to this Notice where practicable.

5. Why AAIPA uses information

PurposeAAIPA-specific use
Website and account operationProvide pages, forms and portals; authenticate users; maintain security and respond to support requests.
MembershipAssess applications; verify credentials; allocate and maintain tiers/status; administer renewal, training and member communications.
Professional directoryPublish only approved public fields; allow profile correction and manage verified status.
Capability matchingIdentify professionals and Execution Partners suited to an anonymised enquiry or opportunity.
Member Project PartnershipValidate provenance; protect the Opportunity-Originating Member; shortlist capacity; structure bidding, contracting and delivery.
Client requests and projectsClarify scope; manage controlled disclosures; support proposals, mobilisation, quality, reporting, complaints and close-out.
Execution Partner governanceConduct due diligence, conflict checks, continuing assessment, performance monitoring and corrective action.
Legal, safety and integrityPrevent fraud, impersonation, misuse and circumvention; maintain audit evidence; respond to lawful requests; protect safety and legal claims.
Training and communicationsAdminister events and essential service messages; send optional marketing only with an appropriate choice.
Aggregated insightCreate statistics that do not identify a person, client, site, opportunity or project.

6. Grounds for processing

Depending on the activity and applicable law, AAIPA may process information with consent; to take requested pre-contractual steps or perform an agreement; to meet legal, regulatory, safety, tax, accounting or professional duties; and for legitimate alliance purposes that do not improperly override individual rights.

Where explicit consent is relied on, it may be withdrawn for future processing, but withdrawal does not invalidate earlier lawful processing or override necessary legal retention.

7. Mandatory and optional information

Each form will identify mandatory fields. Without essential identity, contact, authority, verification or scope information, AAIPA may be unable to create an account, assess membership, publish a verified profile, evaluate an Execution Partner, protect opportunity provenance, respond to a client or grant project access. Marketing, optional profile fields and non-essential cookies will not be made conditions of core service unless genuinely necessary.

8. Public profiles

AAIPA will publish only fields clearly marked Public and approved for publication. Verification documents, government identification, residential address, date of birth, bank/payment details, personal rates, referee contacts, disciplinary material, private assessment notes, client lists and confidential project history will not be public by default. See the AAIPA Public Directory and Profile Publication Policy.

9. Who may receive information

  • Authorised AAIPA administrators, assessors and country representatives with role-based access.
  • Shortlisted members and Execution Partners, initially through anonymised briefs and later only through controlled disclosure.
  • Clients and client-approved project personnel receiving relevant capability, bid or delivery information.
  • Credential issuers, referees, professional bodies, regulators or public registers used for proportionate verification.
  • Contracted hosting, storage, email, form, identity, security, analytics, payment or support providers operating under written restrictions.
  • Professional advisers, insurers, auditors, law-enforcement bodies, courts or regulators where legally justified.

AAIPA does not sell personal data, member contact lists, client enquiries or project leads. Directory information may not be harvested or used for mass solicitation.

10. Controlled project disclosure

Client identity, tender documents and Project Restricted information are not ordinary directory data. AAIPA will disclose them only to approved recipients, for a defined purpose, after conflict checks and acceptance of the applicable project-specific confidentiality and client-protection undertaking. The portal will log the recipient, document/version, purpose and time of access.

11. Cross-border processing

AAIPA may operate across Ghana, Nigeria, Liberia and additional countries. Authorised personnel or providers in another country may therefore access information. Before enabling such access, AAIPA will assess the destination, purpose, recipient, safeguards, client contract and applicable local law. Personal data originating from another jurisdiction and processed in Ghana will receive the protection required by applicable law, including the foreign-law consideration required by Act 843. Regulated, critical-infrastructure, export-controlled or security-sensitive project information requires a separate review.

12. Retention

AAIPA retains information only for as long as needed for the stated purpose and applicable legal, contractual, audit, insurance, professional or dispute obligations. Operational defaults will be documented in an internal retention schedule.

RecordIndicative retention position
Incomplete accountDelete or anonymise after 90 days following notice, unless security or dispute needs justify retention.
Rejected membership/partner applicationNormally 12 months after final decision, subject to complaints, fraud concerns or legal hold.
Active profileFor the active relationship, reviewed at least annually; remove unnecessary information after exit.
Verification copyDelete once verification and challenge needs end where the result can be retained instead.
Closed, unaccepted enquiry/opportunityNormally 12 months, subject to provenance, dispute, legal or client requirements.
Project/tender materialContractual, limitation, audit, insurance and regulatory period; client instructions apply where stricter.
Security/access logsNormally at least 12 months; longer for restricted projects where proportionate.
Marketing choiceEvidence while relied upon; minimal suppression record after opt-out.

13. Security

  • Unique accounts, least privilege, project-based permissions and multi-factor authentication for privileged roles.
  • Encryption in transit and appropriate protection at rest and in backups.
  • Separation of public profiles, verification documents, opportunity provenance and project workspaces.
  • Logging of sign-in, role changes, approvals, restricted access/downloads and administrator actions.
  • Supplier due diligence, written processor restrictions, malware protection, patching, backup and recovery testing.
  • Incident response, evidence preservation, containment, legal assessment and required notifications.

No security method is perfect. Users will protect their credentials and promptly report suspected unauthorised access to support@aaipaafrica.com.

14. Individual rights and choices

  • Ask whether AAIPA holds personal data and request access in an understandable form.
  • Ask for correction or deletion of inaccurate, irrelevant, excessive, out-of-date, incomplete or misleading information.
  • Object to direct marketing and withdraw optional marketing consent.
  • Ask AAIPA to stop or restrict processing likely to cause unwarranted damage or distress, subject to lawful grounds.
  • Ask who has received or previously accessed the information where the applicable law provides.
  • Complain to AAIPA and, where applicable, the Ghana Data Protection Commission or another competent regulator.

AAIPA may verify identity, protect the rights and confidentiality of others, and retain information required by law, contract, safety, professional accountability or legal claims. Requests may be sent to support@aaipaafrica.com.

15. Children

AAIPA's membership, professional and Execution Partner services are intended for adults and authorised organisational representatives. AAIPA does not knowingly invite children to create professional accounts. Event pages involving minors require a separate child-data and guardian-consent assessment.

16. Automated decisions and AI

AAIPA will not make a decision with significant membership, disciplinary, partner-approval or project-allocation effects solely through automated processing without appropriate human review. Users may not upload Project Restricted or confidential portal content into public AI systems unless the information owner and AAIPA have expressly approved the tool and safeguards.

17. Changes to this Notice

AAIPA may update this Notice when its services, countries, technologies or legal duties change. The website will identify the version and effective date. Material changes affecting registered users will be communicated and, where necessary, require renewed acknowledgement or consent.

18. Contact and complaints

Privacy requests, incidents and general website support: support@aaipaafrica.com. Postal contact: IF 53 BlayEsthers' Place, Padmore Street, Community One, Tema, Ghana. If a concern remains unresolved, an individual may contact the Ghana Data Protection Commission through its official channels or another competent regulator.

Primary references: Ghana Data Protection Act, 2012 (Act 843); Ghana Data Protection Commission organisational guidance; and, for accessibility, W3C Web Content Accessibility Guidelines (WCAG) 2.2. References do not convert draft legislation or non-Ghana standards into applicable Ghanaian law.