Last Updated: 15 May 2026
Governed by the Laws of the Republic of Zambia
1.1.1 In this Privacy Policy, unless the context otherwise requires, words importing the singular shall include the plural and vice versa, and words importing any gender shall include all genders.
1.1.2 References to any statute, regulation, or legislative provision shall include any statutory modification, amendment, or re-enactment thereof.
1.1.3 Headings are for convenience only and shall not affect the interpretation of this Policy.
"Company", "We", "Us", or "Our" refers to Brain Box, the online educational platform and tuition centre operating under the laws of the Republic of Zambia.
"Data Controller" means the natural or legal person who determines the purposes and means of the processing of Personal Data.
"Data Processor" means any natural or legal person who processes Personal Data on behalf of the Data Controller.
"Data Subject" means any living individual who is the subject of Personal Data.
"Personal Data" or "Personal Information" means any information relating to an identified or identifiable natural person, including but not limited to names, email addresses, phone numbers, physical addresses, date of birth, gender, academic records, payment information, and IP addresses.
"Platform" or "Service" refers to the Brain Box online educational platform, including all associated websites, applications, and services.
"Processing" means any operation performed on Personal Data, whether automated or not, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, erasure, or destruction.
"Student" or "User" refers to any individual who registers for and uses the Platform's educational services.
"Partner" or "Partner School/Partner" refers to educational institutions that have entered into partnership agreements with the Company.
"Administrator" or "Admin" refers to authorized representatives of Partner Schools/Partners who manage student accounts and subscriptions.
2.1.1 We collect the following Personal Identification Information:
2.2.1 We collect and process the following Academic Information:
2.3.1 We collect the following Financial Information:
2.3.2 We do NOT directly collect or store full credit card numbers, CVV codes, or banking credentials. Payment processing is handled by third-party payment processors in accordance with PCI-DSS standards.
2.4.1 We automatically collect Technical Information, including:
2.5.1 We retain records of all communications between you and the Company, including:
3.1 Direct Collection: Information you provide directly through:
3.2 Automated Collection: Information collected automatically through:
3.3 Third-Party Sources: Information received from:
4.1.1 We process your Personal Data for the following purposes:
4.2.1 We process your Personal Data on the following legal grounds:
4.2.2 Contractual Necessity: Processing is necessary for the performance of the contract between you and the Company, specifically the Terms of Service governing use of the Platform.
4.2.3 Consent: Where you have provided explicit and informed consent for specific processing activities, which may be withdrawn at any time.
4.2.4 Legal Obligation: Processing is necessary to comply with legal obligations under Zambian law, including but not limited to tax laws, data protection regulations, and educational standards.
4.2.5 Legitimate Interests: Processing is necessary for the legitimate interests pursued by the Company or third parties, provided such interests do not override your fundamental rights and freedoms.
5.1.1 We implement appropriate technical and organizational measures to protect Personal Data against:
5.1.2 Our security measures include, but are not limited to:
5.2.1 Your Personal Data is stored on secure servers which may be located within or outside the Republic of Zambia.
5.2.2 We ensure that all data storage facilities maintain security standards equivalent to or exceeding those required under Zambian law.
IMPORTANT NOTICE: While we employ robust security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of your Personal Data. You acknowledge and accept this inherent risk when using the Platform.
6.1 We retain your Personal Data only for as long as necessary to fulfill the purposes for which it was collected, including:
6.1.1 Active Accounts: Personal Data associated with active accounts is retained for the duration of the account's existence plus any applicable legal retention period.
6.1.2 Inactive Accounts: Accounts inactive for more than 24 consecutive months may be archived or deleted, subject to legal and regulatory requirements.
6.1.3 Financial Records: Transaction and payment records are retained for a minimum of seven (7) years from the date of the transaction to comply with Zambian tax and accounting regulations.
6.1.4 Academic Records: Academic performance data may be retained indefinitely for historical and statistical purposes, subject to appropriate anonymization where legally required.
6.1.5 Legal Obligations: Data may be retained beyond standard retention periods where required by law, regulation, or legal proceedings.
6.2 Upon expiry of the retention period, Personal Data will be securely deleted or anonymized in accordance with data protection best practices.
7.1.1 We may disclose your Personal Data to the following categories of third parties:
If you are enrolled through a Partner School/Partner, we share relevant academic and personal information with authorized Administrators of that school/partner to facilitate educational services.
We engage third-party service providers to perform functions on our behalf, including:
We may disclose Personal Data to law enforcement agencies, regulatory bodies, courts, and other governmental authorities when:
In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy, your Personal Data may be transferred to the successor entity, subject to the same privacy protections.
7.2.1 We do NOT sell, rent, or trade your Personal Data to third parties for marketing purposes.
7.2.2 All third-party service providers are contractually bound to:
8.1 Your Personal Data may be transferred to, stored, and processed in countries outside the Republic of Zambia where our service providers maintain facilities.
8.2 When transferring Personal Data internationally, we ensure adequate safeguards are in place, including:
8.3 By using the Platform, you acknowledge and consent to the international transfer of your Personal Data as described herein.
9.1.1 Subject to applicable law, you have the following rights regarding your Personal Data:
You have the right to request confirmation of whether we process your Personal Data and to obtain a copy of such data, along with information about how it is processed.
You have the right to request correction of inaccurate Personal Data and completion of incomplete data.
You have the right to request deletion of your Personal Data where:
You have the right to request restriction of processing where:
You have the right to receive your Personal Data in a structured, commonly used, and machine-readable format and to transmit that data to another controller where technically feasible.
You have the right to object to processing of your Personal Data based on legitimate interests or for direct marketing purposes.
Where processing is based on consent, you have the right to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
You have the right to lodge a complaint with the Zambia Information and Communications Technology Authority (ZICTA) or other relevant supervisory authority if you believe your data protection rights have been violated.
9.2.1 To exercise any of the above rights, please contact us using the contact information provided in Section 15.
9.2.2 We will respond to your request within thirty (30) days of receipt, or such other period as required by applicable law.
9.2.3 We may require verification of your identity before processing requests to ensure data security.
9.2.4 Some rights may be subject to limitations under Zambian law, particularly where processing is necessary for legal compliance or the establishment, exercise, or defense of legal claims.
10.1 We use cookies and similar tracking technologies to enhance your experience on the Platform.
Required for the Platform to function properly, including authentication and security features.
Collect information about how you use the Platform to help us improve functionality and performance.
Remember your preferences and personalize your experience.
Help us understand user behavior and measure the effectiveness of our services.
10.3 You can control cookie preferences through your browser settings. However, disabling certain cookies may limit your ability to use some features of the Platform.
10.4 We do not use cookies for third-party advertising purposes.
11.1 The Platform may contain links to third-party websites, applications, or services not operated by us.
11.2 We are not responsible for the privacy practices of third-party services. We encourage you to review their privacy policies before providing any Personal Data.
11.3 This Privacy Policy applies solely to Personal Data collected by the Company through the Platform.
12.1 The Platform is intended for use by individuals aged 18 years and older.
12.2 We do not knowingly collect Personal Data from individuals under the age of 18 without appropriate parental or guardian consent.
12.3 If we become aware that we have inadvertently collected Personal Data from an individual under 18 without proper consent, we will take steps to delete such information promptly.
12.4 Students under 18 may only use the Platform through registration by a Partner School/Partner Administrator or with verifiable parental/guardian consent.
13.1 We reserve the right to modify, amend, or update this Privacy Policy at any time to reflect changes in our practices, legal requirements, or operational needs.
13.2 Material changes to this Privacy Policy will be communicated through:
13.3 Continued use of the Platform after notification of changes constitutes acceptance of the updated Privacy Policy.
13.4 If you do not agree with changes to this Privacy Policy, you must cease using the Platform and may request deletion of your account and Personal Data, subject to legal retention obligations.
14.1 This Privacy Policy shall be governed by and construed in accordance with the laws of the Republic of Zambia, including but not limited to:
14.2 Any dispute arising out of or in connection with this Privacy Policy, including any question regarding its existence, validity, interpretation, or termination, shall be subject to the exclusive jurisdiction of the courts of the Republic of Zambia.
14.3 The parties irrevocably submit to the jurisdiction of the Zambian courts for the resolution of any such disputes.
Data Controller: Brain Box
Registered Address: [To be completed with actual registered address in Zambia]
Email: privacy@brainbox.zm
Phone: [To be completed with contact number]
Data Protection Officer (if applicable):
For privacy-related inquiries, complaints, or to exercise your data subject rights, please contact us using the information above. We will respond to all requests in accordance with applicable law.
Supervisory Authority:
Zambia Information and Communications Technology Authority (ZICTA)
Email: info@zicta.zm
Website: www.zicta.zm
By using the Brain Box Platform, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.
Back to Home