PRIVACY POLICY
Plain-English version. We collect a small amount of information to enrol your child and keep them safe during camp. We don't sell it, we don't share it for marketing, and we delete it when it's no longer needed.
1. Who we are
IMMERSIA (“we”, “us”) operates the AI & XR Summer Bootcamp, a summer programme for kids aged 10–17 split into three back-to-back two-week cohorts and based in Lagos, Nigeria. This policy applies to everything on this site and to information you give us during registration.
2. What we collect
- About the camper: full name, date of birth, gender, school, class/grade, t-shirt size.
- About the parent / guardian: full name, relationship, phone numbers, email, home address.
- Emergency contact: name, phone, relationship.
- Medical notes: only what you choose to disclose (allergies, conditions we should know about).
- Payment metadata: Paystack reference + status. We do not store card numbers or bank details, those live with Paystack.
- Site analytics: page-view data grouped by an anonymous device cookie (not your identity), plus device type, approximate location, and IP address used for abuse prevention and traffic reporting.
3. Why we collect it
- To enrol your child in the cohort, assign them to courses, and produce their name badge / t-shirt.
- To reach you about logistics, drop-off, pick-up, schedule changes, and Demo Day.
- To contact your emergency contact if your child needs medical attention.
- To process payment via Paystack.
- To comply with the Nigeria Data Protection Regulation (NDPR) and the Nigeria Data Protection Act 2023.
4. Who we share it with
By default, nobody outside the IMMERSIA team. The exceptions:
- Paystack, to process payment.
- Our email provider, to send registration confirmations, receipts and pre-camp logistics.
- Medical responders, only if your child needs urgent care during camp.
- Law enforcement, only if compelled by a valid Nigerian court order.
We do not sell, rent, or trade your data to anyone.
4b. Emails we send you
We send two kinds of email, and they follow different rules.
- Essential emails — payment receipts, your registration confirmation, one-time login links and urgent safety notices. These are part of providing the service you paid for, so they are sent for as long as you have an active registration.
- Camp updates — logistics, schedules, reminders and news about the programme. Every one of these carries a one-click unsubscribe link, and you can also reply to any email to ask us to stop. We action it immediately, and it applies to every future update. Unsubscribing from updates never stops your essential emails.
Some camp updates may include an invisible one-pixel image that tells us whether the email was opened, so we know whether important logistics actually reached you. It records only that the email was opened and when — never your location or what you did next. It is off unless we switch it on for a specific email, and blocking images in your email app prevents it entirely.
5. How long we keep it
Registration records and payment metadata are kept for two years after the cohort ends, then permanently deleted. Site analytics (cookie-grouped, not identity-linked) are kept for up to 12 months. Medical notes are deleted within 30 days of camp ending unless required for an ongoing incident report.
6. Your rights
Under NDPR you may at any time:
- Ask for a copy of the data we hold on you or your child.
- Ask us to correct anything inaccurate.
- Ask us to delete your data (we'll comply unless we're legally required to retain it).
- Withdraw consent for marketing communications — use the unsubscribe link in any camp update, or email us.
Email any of these requests to privacy@immersia.ng and we'll respond within 14 days.
7. Children specifically
The camp is for kids 10–17. We only collect a camper's data with the explicit consent of a parent or legal guardian completing the registration form. We do not market directly to children. Photos taken during camp are only used in cohort communications and IMMERSIA channels with parental consent given on the registration form (you can opt out at registration or by emailing us).
8. Security
Data is encrypted in transit (HTTPS) and at rest. Access is limited to the IMMERSIA team members who need it to run the cohort. We do not store any payment card data. Paystack handles that under PCI-DSS rules.
9. Changes to this policy
If we change anything material, we'll email everyone who has an active registration and update the “Last updated” date at the top of this page.
10. Contact
Privacy questions: privacy@immersia.ng
General questions: /contact
