Last updated: 1 January 2025
Section 01
Introduction
Ìmọ̀dòtun AI ("the Platform", "we", "us", "our") is an academic digital preservation project operated by Ede Polytechnic, Ede, Osun State, Nigeria. This Privacy Policy explains how we collect, use, store, and protect information when you use the platform at https://imodotun-ai.aporaj.com and any associated subdomains.
By using the Platform, you agree to the practices described in this Privacy Policy. If you do not agree, please discontinue use of the Platform.
Academic context: This platform is operated as an academic project for research and public benefit. It is non-commercial, carries no advertising, and does not sell user data under any circumstances.
Section 02
Information We Collect
Information you provide directly:
- Contact form submissions — name, email address, subject, and message content when you use the contact form.
- Newsletter signup — email address only, if you choose to subscribe to platform updates.
- Admin accounts — name, institutional email address, and role, for authenticated users (platform administrators and reviewers only).
- Manuscript submissions — title, author, abstract, community of origin, and consent documentation provided with submitted materials.
Information collected automatically:
- Server logs — IP address, browser type, pages visited, and timestamps. These are standard web server logs retained for security and analytics purposes only.
- Session data — temporary session identifiers for authenticated users, stored in session cookies and cleared on logout.
We do not collect payment information, biometric data, or sensitive personal data beyond what is listed above.
Section 03
How We Use Your Information
We use the information we collect solely for the following purposes:
- To respond to your contact form submissions and enquiries
- To send platform update newsletters (only if you have opted in)
- To authenticate and manage admin user accounts
- To process manuscript submissions and coordinate consent workflows
- To monitor and improve platform security and performance
- To generate anonymised usage statistics for academic research reporting
We will never: sell your data, share it with third-party advertisers, use it for commercial profiling, or contact you for purposes unrelated to your interaction with this platform.
Section 04
Cookies & Tracking
The Platform uses only essential cookies necessary for operation:
- Session cookie — a temporary identifier for logged-in admin users. Expires when the browser is closed or the session times out (1 hour of inactivity).
- CSRF token cookie — a security token to protect form submissions against cross-site request forgery. Cleared after form submission.
We do not use advertising cookies, third-party tracking cookies, Google Analytics, Facebook Pixel, or any other external tracking services. Public visitors (non-logged-in users) receive no persistent cookies.
Section 05
Data Sharing
We do not sell, trade, or share your personal information with third parties except in the following limited circumstances:
- Institutional disclosure — Ede Polytechnic management may access anonymised platform usage statistics for academic reporting. No personally identifiable information is included in these reports.
- Legal requirement — we may disclose information if required to do so by Nigerian law, court order, or to protect the rights and safety of the platform and its users.
- Service providers — we may share minimal technical data with hosting providers (e.g. Hostinger or Namecheap) strictly for the purpose of operating the platform. These providers are contractually prohibited from using the data for any other purpose.
Manuscript content and indigenous knowledge materials are published publicly on the archive only after documented community consent has been obtained and verified. Community consent records are stored securely and are never shared publicly.
Section 06
Data Retention
- Contact messages — retained for 2 years from receipt, then permanently deleted.
- Newsletter subscriptions — retained until you unsubscribe, then immediately deleted.
- Admin account data — retained for the duration of the account and 6 months thereafter.
- Server logs — retained for 90 days, then automatically purged.
- Archived manuscript metadata — retained indefinitely as part of the academic archive. Community consent documentation is retained permanently alongside each archived item.
Section 07
Your Rights
You have the following rights regarding your personal information:
- Access — request a copy of the personal information we hold about you.
- Correction — request correction of inaccurate personal information.
- Deletion — request deletion of your personal information, subject to any legal or archival obligations.
- Objection — object to processing of your personal information in specific circumstances.
- Newsletter unsubscribe — unsubscribe from newsletters at any time by clicking the unsubscribe link in any email or contacting us directly.
To exercise any of these rights, contact us at privacy@atunra.edepoly.edu.ng. We will respond within 30 days.
Section 08
Indigenous Knowledge & Community Data
We recognise that indigenous knowledge carries unique cultural, spiritual, and communal significance that goes beyond standard data protection frameworks. Accordingly, we apply additional protections:
- No indigenous knowledge material is published without documented community consent from the originating community.
- Communities retain the right to request removal or restriction of their knowledge at any time, regardless of consent previously given.
- Traditional Knowledge (TK) labels are applied to every archived item, communicating the community's terms for access and use to all visitors.
- Community consent documentation is stored securely and separately from the public-facing archive.
- We do not permit commercial use of archived indigenous knowledge content without explicit additional consent from the originating community.
Cultural sovereignty: Communities are the ultimate owners of their knowledge. This platform acts as a custodian, not an owner, of indigenous knowledge content.
Section 09
Security
We implement appropriate technical and organisational measures to protect your information, including:
- SSL/TLS encryption for all data in transit
- Password hashing using PHP's
password_hash() with bcrypt
- CSRF tokens on all forms
- PDO prepared statements to prevent SQL injection
- Input sanitization on all user-provided data
- File upload validation and type checking
- Regular database backups
No system is completely secure. While we take every reasonable precaution, we cannot guarantee absolute security. In the event of a data breach, we will notify affected users within 72 hours where required by applicable law.
Section 10
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For significant changes, we will provide a notice on the platform homepage.
Continued use of the Platform after a change to this Policy constitutes acceptance of the updated terms.