SC SHATTIMA COLLEGE OF HEALTH SCIENCE AND TECHNOLOGY, JALINGO TARABA STATE
Home Programmes Admissions Staff Login Students Apply Now
Home Programmes Admissions Staff Login Returning Students Apply for Admission
← Back

Privacy Policy

Mahhfaz College Portal · Operated by Mahhfaz Group

Version 1.0 · Effective date: 1 July 2026 · Last updated: 1 July 2026

1. Introduction and Scope

  1. 1.1. This Privacy Policy explains how personal data is collected, used, disclosed, retained, and protected in connection with the Mahhfaz College Portal (“the Platform”), operated by Mahhfaz Group (“Mahhfaz”, “we”, “us”, “our”), a company incorporated in the Federal Republic of Nigeria with registration number 9612441 and registered office at No. 17, Kasuwan Yelwa Street, Palace Way, Jalingo, Taraba State, Nigeria.
  2. 1.2. This Policy applies to personal data of students and applicants (some of whom may be minors), guardians and sponsors, and college staff, as well as to the account holders and billing contacts of subscribing colleges.
  3. 1.3. This Policy is issued in compliance with the Nigeria Data Protection Act 2023 (“NDPA”) and the General Application and Implementation Directive 2025 (“GAID”) issued by the Nigeria Data Protection Commission (“NDPC”). Since the GAID took effect on 19 September 2025, the NDPA and GAID together form the governing data-protection framework in Nigeria, and the former Nigeria Data Protection Regulation 2019 no longer applies. Where a data subject is protected by the EU or UK General Data Protection Regulation (“GDPR”), the additional rights in Clause 12 also apply.
  4. 1.4. This Policy is incorporated into, and should be read with, the Mahhfaz Terms of Service and the Data Processing Agreement between Mahhfaz and a college.

2. Definitions

  1. 2.1. “Personal Data” means any information relating to an identified or identifiable natural person (“Data Subject”).
  2. 2.2. “Sensitive Personal Data” means Personal Data revealing categories treated as sensitive under the NDPA. In this Platform it includes a student’s blood group and National Identification Number (NIN), and staff next-of-kin details and payroll bank details.
  3. 2.3. “Data Controller” means the party that determines the purposes and means of processing Personal Data.
  4. 2.4. “Data Processor” means the party that processes Personal Data on behalf of, and on the instructions of, a Data Controller.
  5. 2.5. “College” means a tertiary educational institution that subscribes to the Platform.
  6. 2.6. “Sub-processor” means a third party engaged to process Personal Data in connection with the Service.
  7. 2.7. “Processing” means any operation performed on Personal Data, including collection, storage, use, disclosure, transfer, and deletion.

3. Our Roles — Controller and Processor

  1. 3.1. College Data (students, applicants, guardians/sponsors, staff). For Personal Data that a College submits to or generates within the Platform about its students, applicants, guardians/sponsors, and staff: (a) the College is the Data Controller, determining why and how the data is processed; and (b) Mahhfaz is the Data Processor, processing that data only on the College’s documented instructions and as described in this Policy and the Data Processing Agreement.
  2. 3.2. Mahhfaz’s own data. For Personal Data that Mahhfaz processes for its own purposes — including a College’s account and billing contacts, settlement records, marketing-website visitors, and security/audit logs maintained for Mahhfaz’s own compliance and protection — Mahhfaz is the Data Controller.
  3. 3.3. Major-importance status. Mahhfaz is a data controller/processor of major importance under the NDPA and GAID (processing the personal data of more than 200 data subjects within a six-month period). Accordingly, Mahhfaz is registered (or in the course of registration) with the NDPC, has appointed a Data Protection Officer, and files the compliance audit returns required of such an entity.
  4. 3.4. Where Mahhfaz is a Processor, the College (as Controller) is responsible for establishing a lawful basis and for responding to Data Subjects; Mahhfaz assists as described in this Policy and in the Data Processing Agreement.

4. Personal Data We Collect

  1. 4.1. Student and applicant data: full name; date of birth; gender; blood group; National Identification Number (NIN); passport photograph; admission/registration number; department, programme, and level; uploaded documents (for example O’level results, birth certificate, indigene letter); guardian and sponsor details; attendance records; examination scores and results.
  2. 4.2. Guardian/sponsor data: names; relationship; phone numbers; email addresses; addresses.
  3. 4.3. Staff data: names; email addresses; phone numbers; staff ID; department; next-of-kin details; passport photograph; bank account number (for payroll); payslips; qualifications; leave and attendance records.
  4. 4.4. Technical and log data: activity and audit logs, including IP addresses; message-delivery logs (for example email delivery status).
  5. 4.5. Account and billing data (Mahhfaz as Controller): College account details, authorised administrator identities, settlement subaccount details, and transaction/Commission records.
  6. 4.6. Payment data: Mahhfaz does not collect or store full card numbers, card verification values (CVV), or card PINs. All card data is collected and processed by Paystack. Mahhfaz receives only transaction references and settlement information. See Clause 8.

5. Sensitive Personal Data

  1. 5.1. The Platform processes Sensitive Personal Data, in particular the blood group and National Identification Number of students, and the next-of-kin and payroll bank details of staff.
  2. 5.2. Sensitive Personal Data is processed only where a valid lawful basis and any additional condition required by the NDPA are satisfied — for example, explicit consent, the protection of the vital interests of the Data Subject (such as the use of a student’s blood group in a medical emergency), or the performance of a contract (such as the use of staff bank details for payroll). Access is restricted to authorised roles (for example, the bursar/accountant for payroll data, and the registrar or head of department for student records).
  3. 5.3. Passport photographs. Passport photographs are collected and used for identification within the Platform (for example on student and staff profiles). They are not used to uniquely identify a person by automated biometric means and are therefore not processed as biometric data; they are nonetheless protected as Personal Data.

6. Minors’ Data and Consent

  1. 6.1. Under the NDPA, a child is any person below the age of 18. Where the Platform processes the Personal Data of a Data Subject who is a minor, Mahhfaz recognises the heightened protection this requires.
  2. 6.2. Where the NDPA requires consent as the lawful basis for processing a minor’s Personal Data, the College (as Controller) is responsible for obtaining and recording the consent of the minor’s parent or legal guardian holding parental responsibility, and for verifying that consent. Verification may be achieved by presentation of a government-approved identification document or another appropriate method, taking available technology into account.
  3. 6.3. Mahhfaz provides functionality to help Colleges capture and record such consent but does not itself determine when consent is required or verify parental responsibility on the College’s behalf.

7. Purposes and Lawful Bases

  1. 7.1. Personal Data is processed for the following purposes:
    1. (a) providing college-management functionality (admissions/applicants, student records, academics, attendance, examinations and results, library, transport, staff administration, and payroll);
    2. (b) processing school-fee and application-fee payments and effecting split settlement;
    3. (c) sending administrative and transactional communications by email and, where enabled, SMS;
    4. (d) securing the Platform, maintaining audit logs, and preventing fraud and abuse;
    5. (e) providing support and improving the Service; and
    6. (f) complying with legal and regulatory obligations.
  2. 7.2. Lawful bases (NDPA section 25 and related provisions). Depending on the processing, the lawful basis may be: performance of a contract; consent (including parental/guardian consent for minors); compliance with a legal obligation; protection of vital interests (for example, use of a student’s blood group in a medical emergency); or legitimate interests, where not overridden by the Data Subject’s rights.
  3. 7.3. Where Mahhfaz is a Processor, the College determines and documents the lawful basis for College Data. Where Mahhfaz is a Controller (Clause 3.2), Mahhfaz relies on performance of its contract with the College, its legitimate interests in securing and administering the Platform, and, for direct marketing, consent where required by the GAID.

8. Payment Data and Paystack

  1. 8.1. Online payments are processed by Paystack Payments Limited. When a payer makes a payment, card and payment-instrument data is collected and processed directly by Paystack under Paystack’s own privacy policy and its PCI-DSS-compliant environment.
  2. 8.2. Mahhfaz does not receive or store full card numbers, CVV, or PINs. Mahhfaz receives transaction references, amounts, status, and settlement details necessary to reconcile payments and effect split settlement to the College’s subaccount and Mahhfaz’s Commission.
  3. 8.3. Payers should review Paystack’s privacy policy for information on how Paystack processes their payment data.

9. Sub-processors and Third-Party Recipients

9.1. Mahhfaz engages the following Sub-processors to provide the Service. Each is engaged under a data-processing agreement requiring appropriate security and data-protection safeguards:

Sub-processor Function Data involved Hosting region
Paystack (Paystack Payments Limited)Payment processing and split settlementTransaction/settlement data (card data handled by Paystack only)Nigeria
TermiiSMS delivery (where enabled)Recipient phone numbers, message content, delivery logsNigeria
ResendEmail deliveryRecipient email addresses, message content, delivery logsUnited States
Laravel CloudApplication hosting and PostgreSQL databaseAll College DataEuropean Union (eu-west-1, Ireland)
Amazon Web Services (AWS S3)File and media storageUploaded documents, passport photographs, filesEuropean Union (eu-west-1, Ireland)
Cloudflare, Inc.Marketing website and content deliveryWebsite visitor technical dataGlobal edge network
  1. 9.2. Mahhfaz will give Colleges reasonable prior notice of the addition or replacement of a Sub-processor.
  2. 9.3. Mahhfaz may also disclose Personal Data where required by law, regulation, court order, or a competent authority, or to establish, exercise, or defend legal claims.
  3. 9.4. Mahhfaz does not sell Personal Data.

10. Cross-Border Transfers

  1. 10.1. Some Sub-processors process data on infrastructure outside Nigeria: hosting and file storage (Laravel Cloud and AWS S3) in the European Union (Ireland); email delivery (Resend) in the United States; and content delivery (Cloudflare) via a global edge network. Payment and SMS processing (Paystack and Termii) occur in Nigeria.
  2. 10.2. Where Personal Data is transferred outside Nigeria, Mahhfaz relies on a transfer mechanism permitted by the NDPA (sections 41–43) and GAID Schedule 5 — namely transfer to a jurisdiction subject to an NDPC adequacy determination, or, where none applies, appropriate contractual safeguards (including a data-processing agreement with the recipient), or another permitted basis such as the necessity of the transfer for performance of the contract.

11. Data Retention and Deletion

  1. 11.1. Personal Data is retained only for as long as necessary for the purposes described in this Policy, to satisfy the College’s instructions (where Mahhfaz is Processor), and to comply with legal, accounting, and statutory retention obligations.

11.2. Retention schedule:

Data category Retention Basis
Active student/academic recordsDuration of enrolment plus 5 years after the student leavesCollege instruction; academic record-keeping
Examination results and transcriptsRetained for the life of the College’s account; made available for download during offboarding, then deleted on terminationAcademic record-keeping; controlled offboarding
Applicant data (unsuccessful applicants)90 days after the admission cycleData minimisation
Guardian/sponsor contact data5 years after the related student leavesContract; communication
Staff HR records5 years after employment endsEmployment record-keeping
Payroll and financial records (bank details, payslips, transactions)6 yearsStatutory (CAMA 2020; CITA section 63; FIRS)
Activity/audit logs and IP addressesRetained on a permanent basisSecurity and accountability
Message-delivery logs (email/SMS)Retained on a permanent basisOperational and audit
Mahhfaz account/billing dataDuration of the relationship plus 6 yearsContract; tax/accounting

11.3. Deletion process. On expiry of the applicable retention period, or on a valid deletion instruction from the College (as Controller), or on termination in accordance with the Terms of Service, Mahhfaz will delete or irreversibly anonymise the relevant Personal Data, including from primary storage and, within 90 days, from backups, save where longer retention is required by law or is necessary to establish, exercise, or defend legal claims. Deletion is logged for accountability.

12. Data Subject Rights

  1. 12.1. Subject to applicable law and to any conditions and exemptions in the NDPA (and the GDPR where it applies), Data Subjects have the right to:
    1. (a) be informed about how their data is processed;
    2. (b) access their Personal Data;
    3. (c) rectification of inaccurate or incomplete data;
    4. (d) erasure / the “right to be forgotten”, where a legal basis to retain the data no longer exists;
    5. (e) restriction of processing in certain circumstances;
    6. (f) object to processing, including to direct marketing;
    7. (g) data portability — to receive their data in a structured, commonly used, machine-readable format and, where technically feasible, have it transmitted to another controller; and
    8. (h) not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, and to withdraw consent at any time where processing is based on consent.
  2. 12.2. How to exercise rights. Because a College is usually the Controller of student, guardian, and staff data, Data Subjects should generally direct requests to their College. Where Mahhfaz receives a request relating to College Data, Mahhfaz will refer it to the College and assist the College in responding. For data where Mahhfaz is the Controller, requests may be made to Mahhfaz using the contact details in Clause 16.
  3. 12.3. Mahhfaz (or the College, as applicable) will respond without undue delay and, in any event, within one month of receipt, extendable where permitted by law for complex or numerous requests.
  4. 12.4. There is normally no fee for exercising these rights, though a reasonable fee or refusal may apply to manifestly unfounded or excessive requests, to the extent permitted by law.

13. Data Security

  1. 13.1. Mahhfaz implements appropriate technical and organisational measures to protect Personal Data, including: logical tenant separation; role-based access control aligned to the roles described in the Terms of Service, on a need-to-know basis; encryption of Personal Data in transit and at rest using industry-standard encryption; enforced rotation of temporary credentials on first login and password-strength requirements; a content-security policy and secure session cookies; audit logging; regular automated backups with periodic restoration testing; patch management and vulnerability monitoring; and periodic staff data-protection training.
  2. 13.2. Access to Sensitive Personal Data and to payroll data (for example bank account numbers) is restricted to roles with a legitimate need.
  3. 13.3. No system is completely secure. Mahhfaz cannot guarantee absolute security but maintains measures proportionate to the risk, including for the processing of minors’ data.
  4. 13.4. Colleges are responsible for managing their own Users’ access, keeping credentials secure, and assigning roles appropriately.

14. Personal-Data Breach Notification

  1. 14.1. Mahhfaz maintains procedures to detect, investigate, and respond to personal-data breaches.
  2. 14.2. Where Mahhfaz is a Processor: on becoming aware of a personal-data breach affecting College Data, Mahhfaz will notify the affected College (as Controller) without undue delay, providing the information the College reasonably needs to meet its own obligations.
  3. 14.3. Where Mahhfaz is a Controller: Mahhfaz will notify the NDPC of a breach that is likely to result in a risk to the rights and freedoms of individuals within 72 hours of becoming aware of it (with information provided in phases where necessary), and will communicate the breach to affected Data Subjects without undue delay where it is likely to result in a high risk to their rights and freedoms.
  4. 14.4. Breaches and the response taken are documented for accountability.

15. Cookies and Marketing Sites

  1. 15.1. Mahhfaz’s marketing websites (delivered via Cloudflare) may use cookies or similar technologies for functionality and analytics, and will present a cookie notice and obtain consent for non-essential cookies in accordance with GAID requirements.
  2. 15.2. The Platform application itself uses cookies or tokens necessary for authentication and security.

16. Contact and Complaints

16.1. Data Protection Officer.
Name: Anas Muhammad Yahaya
Email: dpo@mahhfaz.com.ng
Address: No. 17, Kasuwan Yelwa Street, Palace Way, Jalingo, Taraba State, Nigeria

16.2. Controller identity. Mahhfaz Group, RC 9612441, No. 17, Kasuwan Yelwa Street, Palace Way, Jalingo, Taraba State, Nigeria. General enquiries: info@mahhfaz.com.ng.

16.3. Right to complain. A Data Subject who believes their data has been mishandled may complain to Mahhfaz and has the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC) at https://ndpc.gov.ng.

17. Changes to This Policy

  1. 17.1. Mahhfaz may update this Policy from time to time. Material changes will be notified by email or in-Platform notice, and the Platform will prompt affected Users to re-accept where required. The “Last updated” date at the top reflects the latest version.

Independent legal review. This document is not legal advice. It should receive a final confirmatory review by a legal practitioner qualified and admitted in the Federal Republic of Nigeria — with attention to the lawful-basis and consent architecture for minors’ data (Clauses 6–7), the permanent retention of audit and message-delivery logs (Clause 11), Mahhfaz’s NDPC registration tier and DPIA, and the cross-border transfer basis for United-States-hosted email delivery (Clause 10) — before being relied upon.

© 2026 SHATTIMA COLLEGE OF HEALTH SCIENCE AND TECHNOLOGY, JALINGO TARABA STATE. All rights reserved.