1. Who We Are
Bihak Center ("Bihak Center", "we", "us", or "our") is a youth empowerment organization headquartered in Burundi. We operate the website at bihakcenter.com (the "Site"), which provides services including story sharing, mentorship matching, incubation programs, and leadership training to users across Africa and globally.
We are the data controller responsible for the personal information we collect through this Site. This policy applies to all users worldwide.
Data Controller: Bihak Center · Contact: info@bihakcenter.com · Headquarters: Burundi · Serving: Global
2. What Data We Collect
Information you provide directly
- Account data: Full name, email address, password (stored as a one-way hash — we never see your actual password)
- Profile data: Bio, country, city, field of study, skills, profile photos, and your personal story
- Program applications: Startup ideas, team information, incubation exercise submissions
- Mentorship data: Mentor/mentee preferences, goals, messages exchanged through the platform
- Contact messages: Name, email, and message when you use the contact form
- Donation data: Donation amounts and associated contact information
- Security data: Security questions and answers (used for account recovery)
Information collected automatically
- Usage data: Pages visited, time spent, features used
- Device data: Browser type, operating system, screen size
- IP address: Used for security, analytics, and abuse prevention
- Session data: Login sessions and authentication tokens
Information from third parties
- Google Analytics: Aggregated website traffic statistics (see Cookies section)
3. Why We Collect It (Legal Basis)
We only collect and process your personal data when we have a valid legal reason:
- Contract performance: To create and manage your account, provide the services you signed up for
- Consent: For optional features like story publication, newsletter updates, and analytics cookies
- Legitimate interests: Security monitoring, fraud prevention, platform improvements
- Legal obligation: To comply with applicable laws internationally, including Burundian law, GDPR (for EU/EEA users), and equivalent frameworks in other jurisdictions
4. How We Use Your Data
- Create and maintain your account
- Match you with mentors or incubation program opportunities
- Publish your story (only after review and with your explicit consent)
- Send transactional emails (account verification, password reset, program updates)
- Improve the platform based on aggregated usage patterns
- Prevent fraud, abuse, and security threats
- Respond to your support requests
We do not sell your personal data. We do not use your data for automated decision-making or profiling that produces legal effects on you.
5. Who We Share Data With
We do not sell, rent, or share your personal data with any third parties outside the Bihak Center platform.
Your data stays within our platform. The only cases where information moves between users are:
- Mentors/Sponsors: If you join the mentorship program, your profile information is shared with your matched mentor — within the platform.
- Published stories: If you consent to having your story published, it will be visible to other platform users and site visitors.
- Team members: If you join an incubation team, your profile is visible to your team members — within the platform.
Infrastructure
Our servers run on Oracle Cloud Infrastructure. Server-level hosting means your data physically resides on Oracle's hardware — Oracle has no access to application-level data and operates purely as an infrastructure provider under strict contractual terms.
Analytics
Google Analytics receives anonymized, aggregated usage statistics only (pages visited, session counts). No personal identifiers are sent. IP anonymization is enabled.
Legal requirements
We may disclose data if required by a valid court order or law enforcement request from any jurisdiction. We will notify affected users where legally permitted to do so.
6. How Long We Keep Your Data
- Account data: As long as your account is active. Deleted within 30 days of an account deletion request.
- Published stories/profiles: Retained until you request removal or delete your account.
- Messages: Retained for the duration of the mentorship relationship, then deleted after 12 months of inactivity.
- Analytics/IP logs: Automatically purged after 12 months.
- Contact form submissions: Retained for 24 months for support reference, then deleted.
- Donation records: Retained for 7 years to comply with financial record-keeping requirements.
7. How We Protect Your Data
- Encryption in transit: All data is transmitted over HTTPS/TLS
- Password hashing: Passwords are hashed using bcrypt — we cannot recover your password
- Access controls: Staff access to personal data is strictly limited on a need-to-know basis
- Server security: Regular security patches and updates on our Oracle Cloud infrastructure
- CSRF protection: All forms are protected against cross-site request forgery
- Rate limiting: Login and sensitive endpoints are rate-limited to prevent brute-force attacks
No system is 100% secure. In the event of a data breach that affects your rights, we will notify you within 72 hours of becoming aware of it.
8. Your Rights
You have the following rights regarding your personal data:
- Access: Request a copy of all data we hold about you
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your account and all associated data
- Portability: Download your data in a machine-readable format
- Withdraw consent: Withdraw consent for optional processing at any time
- Object: Object to processing based on legitimate interests
You can exercise the Access, Erasure, and Portability rights directly from your My Account page. For other requests, email info@bihakcenter.com. We will respond within 30 days.
9. Cookies & Analytics
Essential cookies
We use session cookies to keep you logged in. These are strictly necessary and cannot be disabled without breaking the site.
Analytics cookies (Google Analytics)
We use Google Analytics (GA4) to understand how visitors use our site. This involves setting cookies that send anonymized data to Google servers in the United States. IP anonymization is enabled. You can opt out using the Google Analytics Opt-out Browser Add-on.
No advertising cookies
We do not use advertising cookies, tracking pixels, or any third-party marketing cookies.
10. International Users
Bihak Center serves users globally. Our servers are hosted on Oracle Cloud Infrastructure. By using the Site from outside Burundi, you consent to your data being processed in accordance with this policy.
We apply the same privacy standards to all users regardless of location. Where specific regional laws grant you additional rights, we honour those:
- EU / EEA (GDPR): Rights to access, rectification, erasure, portability, restriction, and objection. You may also lodge a complaint with your local Data Protection Authority.
- United Kingdom (UK GDPR): Same rights as GDPR apply. You may contact the ICO at ico.org.uk.
- Africa: We respect national data protection laws across African Union member states, including Kenya (DPA 2019), South Africa (POPIA), Rwanda (Law No. 058/2021), and others.
- All other countries: The rights described in Section 8 apply as a global baseline.
For any international data rights requests, contact info@bihakcenter.com.
10. Children's Privacy
Our services are intended for users aged 15 and older. We do not knowingly collect personal data from children under 15. If you believe a child under 15 has created an account, please contact us at info@bihakcenter.com and we will delete the account promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make significant changes, we will notify registered users by email and update the "Last updated" date at the top of this page. Continued use of the Site after changes constitutes acceptance of the updated policy.