Privacy Policy
Last updated: August 2026
An institution that researches privacy must hold itself to a higher standard than it recommends to others. This policy is written to that measure.
Who we are
Our website address is: https://cipher-sl.org.
The Center for Information Privacy, Human-Centered Technology, and Ethics Research (“CIPHER”, “we”, “us”) is a not-for-profit company limited by guarantee registered in Sierra Leone under the Companies Act, 2009, with its registered office at 49 Main Motor Road, Congo Cross, Freetown, Sierra Leone.
For the purposes of this policy, CIPHER is the controller of the personal data described below. Our Data Protection Officer may be contacted at privacy@cipher-sl.org.
Scope
This policy applies to personal data we process through this website, through correspondence with us, through participation in our training and events, and through participation in our research. It does not apply to third-party websites we link to, which operate under their own policies.
The standard we apply
Sierra Leone does not at present have a comprehensive data protection statute in force. We therefore apply, as a matter of policy and by our own choice, the principles common to established international frameworks, including the African Union Convention on Cyber Security and Personal Data Protection, the ECOWAS Supplementary Act on Personal Data Protection, and the EU General Data Protection Regulation.
Those principles are lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; and accountability. Where Sierra Leonean legislation is enacted, we will comply with it and revise this policy accordingly. Where our standard exceeds what the law requires, we will keep the higher standard.
What we collect
This website
This website is built without analytics, advertising, tracking pixels, social media embeds or third-party scripts. It does not set cookies. We do not profile visitors and we do not build audience segments.
Our hosting provider may retain standard server logs, which can include IP address, browser type, pages requested and timestamp. These are generated by the infrastructure rather than by us, are used only for security and availability, and are not linked by us to any identified person.
When you contact us
We process your name, contact details, the institution you represent where relevant, and any information you choose to include in your message.
Training, events and mailing lists
We process registration details including name, institution, role, contact details and any accessibility or dietary requirements you tell us about. Where you ask to receive updates, we process the address you give us for that purpose only.
Research participation
Where you take part in our research, we process the data described in the consent materials for that specific study, and no other. Research involving people is preceded by ethics review, informed consent, and a documented data management plan. Personal identifiers are separated from research data and removed at the earliest point consistent with the research purpose.
Lawful basis for processing
We process personal data on the following bases: your consent, for updates, event registration and research participation, which you may withdraw at any time; the performance of an agreement with you or your institution, for training and advisory engagements; our legitimate interests in responding to correspondence, securing our systems and pursuing our registered objects, where those interests are not overridden by your rights; and legal obligation, where retention or disclosure is required by law.
What we do not do
- We do not sell, rent or trade personal data under any circumstances.
- We do not share personal data for marketing purposes.
- We do not use personal data to train automated profiling systems.
- We do not make decisions producing legal or similarly significant effects by automated means alone.
- We do not collect special category data except where essential to a specific research study, covered by explicit informed consent, and approved under ethics review.
Sharing and disclosure
We share personal data only where necessary, and only with service providers who process data on our documented instructions under written agreement; research collaborators and named peer reviewers where consent covers it; auditors and professional advisers under a duty of confidence; and public authorities where disclosure is required by law.
Where we publish research, we publish findings in aggregated or de-identified form. We do not publish personal data obtained through research without the separate, specific and written consent of the person concerned.
International transfers
Some of our service providers operate outside Sierra Leone. Where personal data is transferred internationally, we will ensure that it is protected by appropriate contractual safeguards and a standard of protection no lower than that set out in this policy.
Retention
We retain personal data only for as long as the purpose for which it was collected requires. At the end of a retention period, data is securely deleted or irreversibly anonymised. We do not retain data indefinitely by default.
Security
We apply technical and organisational measures proportionate to the sensitivity of the data we hold, including encryption in transit and at rest, access control on a need-to-know basis, documented incident response procedures, and periodic internal review.
No system is entirely secure. Where a breach occurs that is likely to result in a risk to the people affected, we will notify them and the relevant authority without undue delay.
Your rights
Subject to applicable law, you may ask us to confirm whether we hold personal data about you and provide a copy; correct inaccurate data; delete data where there is no continuing lawful basis; restrict or object to processing; transmit data in a portable format; and withdraw consent at any time.
Requests should be sent to privacy@cipher-sl.org. We will acknowledge within seven days and respond substantively within thirty days.
Children
This website is not directed at children. Where research involves people under eighteen, we obtain the consent of a parent or legal guardian in addition to the assent of the young person, and we apply heightened safeguards under ethics review.
Complaints
If you are dissatisfied with how we have handled your personal data, write to privacy@cipher-sl.org and we will investigate. You are also entitled to complain to any competent supervisory authority in Sierra Leone once established.
Changes to this policy
We review this policy at least annually and on any material change to our processing or to the applicable law. Material changes will be notified directly where we hold contact details.
Contact
Data Protection Officer, CIPHER, 49 Main Motor Road, Congo Cross, Freetown, Sierra Leone — privacy@cipher-sl.org