Privacy and Data Protection Policy cover
icon
INVCOURSES Privacy and Data Protection Policy

Privacy and Data Protection Policy

How INVCOURSES protects learner, instructor, website, and mobile app data.
Privacy and Data Protection Policy

INVCOURSES Privacy and Data Protection Policy


Effective date: 9 August 2026



INVCOURSES is an online learning platform operated by INVCLICK ("INVCLICK", "INVCOURSES", "we", "us", or "our"). This Policy explains how we collect, use, disclose, retain, and protect personal data when you use the INVCOURSES website, Android application, courses, live-learning tools, marketplace, communications, and related services (together, the "Service").


This Policy is intended to support compliance with Ghana's Data Protection Act, 2012 (Act 843), the Electronic Transactions Act, 2008 (Act 772), the Cybersecurity Act, 2020 (Act 1038), and other applicable laws. Foreign data-protection laws, including the European Union General Data Protection Regulation, apply only where their territorial requirements are met. This Policy is not a certification by a regulator.



1. Who Is Responsible for Your Data


INVCLICK operates INVCOURSES and is responsible for personal data processed for its own purposes. Where a school, employer, instructor, training provider, or other organisation provides access to INVCOURSES and determines why and how learner data is used, that organisation may be the data controller and INVCLICK may process the data on its documented instructions.




2. Who This Policy Covers


This Policy applies to visitors, learners, parents and guardians, instructors, organisation administrators, customers, prospective users, support contacts, and other people whose personal data is processed through the Service.



3. Personal Data We Collect


The data we collect depends on your role, choices, and use of the Service. It may include:



  • Identity and profile data: name, email address, telephone number, country, language, profile image, biography, account type, organisation, instructor details, and age or guardian information where needed.

  • Account and authentication data: account identifier, encrypted password, sign-in method, session records, verification status, password-reset activity, and security events.

  • Learning and assessment data: enrolments, attendance, lesson progress, watch or study activity, quizzes, assignments, answers, grades, certificates, prerequisites, bookmarks, reviews, discussions, messages, and instructor feedback.

  • Instructor and organisation data: qualifications, course materials, schedules, learner administration, organisation membership, payout information, and records needed to manage teaching or organisational access.

  • Order and payment data: course or product ordered, amount, currency, discount, payment status, refund status, billing contact, and gateway transaction reference. Payment providers process payment credentials; INVCOURSES does not intend to store complete card or bank-account credentials.

  • Communications and content: support requests, contact-form submissions, emails, notices, comments, uploads, discussion posts, live-class messages, and communication preferences.

  • Device, log, and security data: IP address, browser, device type, operating system, app version, approximate location derived from IP, referring page, requested URLs, timestamps, crash data, API activity, and suspected abuse or fraud indicators.

  • Analytics and interaction data: page views, navigation paths, clicks, scrolling, session interaction, feature usage, campaign parameters, and pseudonymous analytics identifiers.

  • Google service data: if you use Google sign-in, we may receive a Google account identifier, verified email address, display name, profile image, and identity or authentication tokens. If an authorised administrator connects Google Meet, we process the organiser identity and credentials needed to create a meeting space and the meeting URI and space identifier returned by Google.

  • Optional device permissions: camera and microphone for live learning, file or media access for chosen uploads or downloads, and calendar access when you choose to add an event. The Android app is not intended to request contacts, SMS, call-log, or precise-location access.


Please do not submit sensitive personal data unless it is requested for a legitimate Service purpose and an appropriate lawful basis and safeguard are in place.



4. How We Obtain Personal Data


We obtain data directly from you; from a parent, guardian, instructor, employer, school, or organisation that enrols or supervises you; automatically from your device and use of the Service; and from connected providers such as payment gateways, Google services, live-meeting providers, email providers, and security or analytics services.



5. Why We Process Personal Data


We process personal data to:



  • create, authenticate, secure, and administer accounts;

  • deliver courses, assessments, certificates, meetings, downloads, learner support, and organisation services;

  • process and reconcile enrolments, orders, instructor payouts, payments, and refunds;

  • send account, security, course, transactional, and support communications;

  • personalise language, preferences, content, and learning experience;

  • measure performance, understand feature use, troubleshoot errors, and improve the Service and course quality;

  • detect, investigate, and prevent fraud, abuse, malware, unauthorised access, and technical failures;

  • enforce our Terms, protect users and rights, and resolve complaints or disputes;

  • comply with legal, regulatory, tax, accounting, audit, and law-enforcement obligations; and

  • send newsletters or promotional communications where permitted, with a way to opt out.



6. Grounds for Processing


Depending on the activity and applicable law, we process data with your consent; to provide a Service or perform an agreement with you or an organisation; to comply with a legal obligation; to protect a person's vital interests; or for a legitimate and lawful purpose such as security, fraud prevention, Service administration, record keeping, or proportionate product improvement. You may withdraw consent at any time where processing is based on consent, without affecting earlier lawful processing.



7. Cookies, Analytics, and Similar Technologies


INVCOURSES uses cookies, local storage, software development kits, and similar technologies. These may be:



  • Strictly necessary: authentication, session continuity, security, load management, and requested Service functions.

  • Functional: language, display, and saved preferences.

  • Analytics: measurement of visits, page performance, navigation, feature use, and technical errors.

  • Communications or marketing: campaign measurement and permitted communications where such tools are enabled.


Our website may use the following analytics services:



  • Google Analytics 4: measures traffic, pages, device characteristics, campaign information, and approximate location derived from network information.

  • Microsoft Clarity: helps us understand page interaction through features such as clicks, scrolling, and session playback. We configure available masking and privacy controls and do not intentionally use Clarity to collect passwords or payment credentials.

  • Mixpanel: measures product and feature events, usage paths, device characteristics, and account or pseudonymous identifiers where configured.

  • Meta Pixel: may measure page visits, campaign referrals, and conversion events and may enable Meta to match events with its users for measurement or permitted advertising where the feature is enabled.


These providers may set or read their own identifiers and process data in countries outside Ghana under their own privacy terms. We seek consent or provide preference controls where required by applicable law. Browser controls may block or delete cookies, but disabling necessary technologies can prevent parts of the Service from working. INVCOURSES does not sell personal data, and these analytics and measurement tools are not used by us to sell personal data.



8. Payments and Financial Information


Payments may be processed by Paystack, Flutterwave, or another provider displayed at checkout. The selected provider receives the information needed to authorise, secure, and reconcile the transaction and applies its own privacy notice. INVCOURSES generally receives a transaction reference, amount, currency, status, and limited payer or billing details. Do not send full card details through messages, support tickets, or course content.



9. Live Classes, Meetings, and Recordings


Live learning may use Google Meet, Jitsi, BigBlueButton, or another identified provider. Participants may provide display names, audio, video, chat, attendance, shared screens, and files. Recording must be clearly disclosed before it starts and must have any consent or authority required by law. A participant should not record, publish, or reuse another person's image, voice, or contribution without permission.



10. Google API Data


INVCOURSES' use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.


Data accessed. Google sign-in may provide the Google account identifier, verified email address, display name, profile image, and identity or authentication tokens needed to authenticate the user. The Google Meet integration requests meetings.space.created, openid, and userinfo.email. It may process the approved organiser's verified email address, encrypted OAuth access and refresh credentials and related token metadata, and the meeting URI, space resource name, or meeting code returned when INVCOURSES creates a Meet space. INVCOURSES does not use this integration to access existing meetings, participants, attendance, audio, video, recordings, transcripts, chat, Google Calendar, Google Drive, Gmail, Google Photos, contacts, or the organiser's Google password. We do not create or use aggregated, anonymised, or derived datasets from Google user data.


Data use. Google sign-in data is used only to authenticate the user, associate the Google identity with the INVCOURSES account, and secure account access. Google Meet data is used only to verify that the approved INVCOURSES organiser completed OAuth, maintain the authorised server-side connection, create a Meet space selected by an authorised instructor or administrator, attach the returned meeting link and identifier to the relevant live-course session, and let authorised course participants join that session. A narrower Meet permission cannot create the requested space.


Data sharing and AI isolation. The meeting link may be displayed to authorised instructors, administrators, and enrolled participants who need it for the live session. Our hosting and infrastructure providers may process encrypted or access-controlled data only as needed to operate and secure INVCOURSES. Google user data is not sold, used for advertising, lending, or surveillance, transferred to data brokers or advertising platforms, or sent to OpenAI or any other artificial-intelligence or machine-learning provider. It is not used to create, train, or improve a foundational or generalised AI/ML model. Human access is restricted to authorised support or security needs, legal requirements, or the user's affirmative agreement.


Protection. Google API traffic is transmitted over HTTPS. OAuth credentials are encrypted at rest using application-level encryption and are restricted to the server-side integration and authorised administration. Access is controlled by role, and the environment is protected through logging, monitoring, firewall and malware controls, backups, and incident procedures.


Retention and deletion. Short-lived access and identity tokens expire according to Google's token lifetime. A Meet refresh credential is retained only while the authorised organiser connection remains active and is deleted when an authorised administrator disconnects the integration, access is revoked, or the credential is no longer required. A meeting URI and space identifier are retained with the corresponding course session while needed to deliver and administer that session, after which they are deleted or restricted under our normal account, course, legal, and backup-retention practices. Google sign-in profile data is retained with the INVCOURSES account while the account is active or as otherwise lawfully required. Backup copies expire through controlled rotation. Users may revoke INVCOURSES access in Google Account permissions, disconnect where that control is available, delete their INVCOURSES account where available, or request access or deletion through info@invcourses.com or the Account Deletion Request page.



11. When We Disclose Personal Data


We disclose only data reasonably necessary for the relevant purpose to:



  • instructors, guardians, supervisors, and authorised organisation administrators involved in the relevant learning activity;

  • hosting, backup, security, content-delivery, email, support, communications, analytics, and technical providers acting for INVCLICK;

  • Paystack, Flutterwave, Google, meeting providers, and other services you choose or that are identified when a feature is used;

  • professional advisers, auditors, insurers, regulators, courts, or law-enforcement bodies where authorised or required;

  • parties needed to investigate fraud, security events, threats, or violations and protect users, the public, or legal rights; and

  • a lawful successor in a merger, financing, restructuring, or transfer, subject to appropriate confidentiality and data-protection safeguards.


Service providers that process personal data for us are expected to follow documented instructions, confidentiality duties, proportionate security requirements, and applicable data-protection law.



12. International Processing


Some connected providers may process or store data outside Ghana. Before such processing, we assess the data, provider, destination, and available safeguards and use appropriate contractual, technical, and organisational measures. Our primary hosting and backup locations are being verified and will be reflected in our internal processing records and this Policy where the information materially affects users.



13. Retention and Disposal


We keep personal data only for as long as it is reasonably needed for the stated purpose and applicable legal, tax, accounting, audit, certificate, fraud-prevention, security, and dispute requirements. The period varies by record type. Account and active-course data is generally retained while access is active; transaction and compliance records may be retained for required statutory periods; security logs and analytics are retained for limited operational periods; and backups expire according to controlled rotation schedules. When data is no longer required, it is deleted, anonymised, or securely restricted. You may ask the Privacy and Data Protection Supervisor for information about the period applicable to a particular record.



14. Your Rights and Choices


Subject to applicable law and lawful exceptions, you may:



  • ask whether we process your personal data and request access to it;

  • request correction or completion of inaccurate or incomplete data;

  • request deletion, blocking, restriction, or cessation of processing where legally available;

  • object to direct marketing or certain other processing;

  • withdraw consent where consent is the basis for processing;

  • request a copy or transfer of information where applicable; and

  • complain to the Ghana Data Protection Commission or another competent authority.


Submit a request to info@invcourses.com for the attention of the Privacy and Data Protection Supervisor. We may verify your identity and authority before acting. We will respond as soon as reasonably practicable and explain any lawful limit or refusal.



15. Account and Data Deletion


You may request deletion through Settings > Delete Account in the app, where available, or through our public Account Deletion Request page. Deleting an account may not erase records that must be retained for transactions, certificates, safety, fraud prevention, legal claims, or statutory compliance. We will restrict retained data to those purposes and explain material retention when responding.



16. Learners Under 18


Learners under 18 may use INVCOURSES only through, or under the authorisation and active supervision of, a parent, legal guardian, school, employer, or other authorised supervisor. The responsible adult or organisation must provide required notices and permissions, supervise account use, and avoid unnecessary disclosure of a minor's data. A minor must not create or operate an unsupervised account where consent or supervision is legally required. Contact us if you believe a minor's data was provided without proper authority.



17. Security


We use proportionate technical and organisational safeguards, including encrypted network connections, role-based access, restricted administration, application and firewall hardening, logging and monitoring, malware controls, backups, change control, and incident procedures. Access is limited according to role and business need. No internet service can guarantee absolute security, so users should use unique passwords, secure their devices, and promptly report suspected unauthorised access.



18. Personal Data Incidents


We investigate suspected loss, unauthorised access, alteration, disclosure, or destruction of personal data. Where required by law, we will notify the Ghana Data Protection Commission and affected individuals as soon as reasonably practicable, provide available material facts and protective steps, and update the notice as the investigation develops.



19. Automated Decisions and Artificial Intelligence


The Service may use automated rules for recommendations, fraud checks, moderation signals, progress calculations, or assessment support. We do not intend to make a solely automated decision that has a legal or similarly significant effect on a person without appropriate notice, lawful authority, safeguards, and a means to request human review where required.


INVCOURSES includes an optional AI Content Generator that connects directly to the OpenAI API and processes prompts deliberately entered by an authorised LMS user. This feature is separate from Google sign-in and Google Meet. It has no application data path to Google OAuth credentials, organiser identity, Meet responses, meeting links, or other raw, aggregated, anonymised, or derived Google user data. Google user data is not submitted to OpenAI. Users must not place personal, confidential, Google Workspace, or Google Photos data in an AI prompt unless INVCLICK has expressly authorised that processing and implemented the required lawful, contractual, and technical safeguards.



20. Changes to This Policy


We may update this Policy to reflect changes in law, providers, security, or the Service. We will publish the updated effective date and provide additional notice where a change materially affects rights or processing. Earlier versions may be requested from the Privacy and Data Protection Supervisor.



21. Questions and Complaints


Send privacy questions, rights requests, or complaints to the Privacy and Data Protection Supervisor at info@invcourses.com, telephone +233 50 963 3306, or write to M29C Bukere Residential Area, UB-0091-6488, Ghana. You may also complain to Ghana's Data Protection Commission through its official contact channels.