CCET RIS legal document
Privacy Policy
Version 1.0Effective 1 September 2026
1. INTRODUCTION AND WHO WE ARE
The Center for Contemporary & Emerging Technologies (“CCET”, “we”, “us”, or “our”) operates the Research Intelligence Service (“RIS”), a subscription and product-based academic research intelligence platform through which users discover, unlock, and access technology-aligned Statement of the Problem (SOP) products. This Privacy Policy explains what personal data we collect through the RIS Platform, why we collect it, how we use and protect it, who we share it with, and the rights available to you under the law.
CCET is the data controller responsible for your personal data. For the purposes of the Data Protection Act No. 3 of 2021 of the Laws of Zambia (the “Act”), this means CCET determines the purposes and means of processing your personal data. This Policy should be read together with the RIS Terms of Use and the Research Advisory Ethics Charter, which together govern your relationship with the RIS.
Data Controller: Center for Contemporary & Emerging Technologies (CCET), Plot 25667, Musioatunya Road, Lusaka, Zambia. Email: ccetzm@gmail.com. Telephone: +260 979 298 145 | 0 769 724 022
2. KEY TERMS
● “Personal Data” means information relating to an identified or identifiable natural person, as defined under the Act.
● “Processing” means any operation performed on personal data, including collection, use, storage, disclosure, or deletion.
● “Data Subject” means the individual to whom personal data relates, in most cases, you.
● “Platform” means the RIS online system, comprising the public website, user dashboard, SOP Bank, payment facilities, and administrative backend.
● “Data Protection Commissioner” means the Office of the Data Protection Commissioner established under the Act as Zambia’s data protection regulator.
3. THE PERSONAL DATA WE COLLECT
Depending on how you use the RIS, we may collect the following categories of personal data:
● Identity data: your full name, email address, telephone number, institution, programme of study, level of study, and discipline.
● Account data: your login credentials (stored only in hashed form), login records, and your Ethics Charter and Terms acceptance records.
● Subscription data: your subscription tier, remaining quota, and expiry date.
● Transaction data: payment references, amounts, currency, and invoice or receipt records.
● Service data: the SOP products you preview, unlock, view, or download.
● Technical data: your IP address, device and browser information, and login timestamps.
● Communication data: support emails or messages you send us, and our responses.
We do not collect or store your payment card details. All card processing is handled securely by our payment provider (see Section 7). We do not knowingly collect sensitive personal data through the RIS, and you should not submit it to us.
4. HOW WE COLLECT YOUR DATA
● Directly from you, when you register an account, complete your profile, purchase or subscribe, contact support, or accept the Ethics Charter and Terms.
● Automatically, when you use the Platform, through cookies and similar technologies and through server and security logs (see Section 6).
● From our service providers, our payment provider confirms the status of your payments so we can activate access; our email and SMS providers confirm message delivery.
● Where you choose Google sign-in (if enabled), we receive basic account information from Google to create or authenticate your account. We do not support Microsoft or institutional sign-in in the current release.
5. WHY WE PROCESS YOUR DATA AND OUR LAWFUL BASES
We process your personal data only where the Act permits. The table below summarises our main purposes and the lawful basis for each:
Purpose Data used Lawful basis
Create and manage your account Identity, account Performance of a contract / your request
Deliver SOP products and activate access Account, subscription, service Performance of a contract
Process payments; issue receipts and invoices Transaction Contract and legal obligation (tax)
Send transactional emails and SMS Identity, communication Contract / legitimate interests
Secure the Platform, prevent fraud, protect content Account, technical, service Legitimate interests / legal obligation
Recommend relevant SOP products Account, service Legitimate interests
Analytics and service improvement Technical, service Legitimate interests / consent
Comply with legal, tax, and regulatory duties Transaction, account Legal obligation
Optional announcements and marketing Communication Consent
Where we rely on your consent (for example, for optional marketing or certain cookies), you may withdraw it at any time without affecting processing carried out before withdrawal.
6. COOKIES AND SIMILAR TECHNOLOGIES
The Platform uses cookies and similar technologies to keep you signed in, remember your preferences, secure your session, and understand how the Platform is used. We use:
● Strictly necessary cookies; required for authentication, session management, and security; these cannot be switched off.
● Analytics cookies; to measure page views, previews, unlocks, purchases, searches, and conversions so we can improve the service; these are used subject to your choices where required.
You can control non-essential cookies through your browser settings or any cookie controls we provide. Disabling strictly necessary cookies may prevent parts of the Platform from working.
7. PAYMENT INFORMATION
Payments are processed through a licensed payment aggregator that supports Zambian mobile money and Visa/Mastercard, in Zambian Kwacha and United States Dollars. Your full card or mobile-money credentials are entered with, and handled by, the payment provider, not by CCET. We receive only a payment confirmation and transaction reference, which we use to activate your access and issue a receipt or invoice. Card handling is tokenised, and we do not store card numbers.
8. HOW WE SHARE YOUR DATA
We do not sell your personal data. We share it only with the following categories of recipients, and only as necessary:
● Payment provider; to process payments, confirm them, and reconcile transactions.
● Email and SMS providers; to deliver account, payment, subscription, and support messages.
● Hosting and infrastructure providers; to host the Platform and store data and backups securely (see Section 10).
● Tax and invoicing systems; to meet invoicing and tax obligations, including ZRA-compliant invoicing where applicable.
● Professional advisers; such as auditors or legal advisers, under duties of confidentiality, where necessary.
● Authorities; where we are required to disclose data by law, court order, or a lawful request, or to protect our rights or the safety of others.
All service providers who process personal data on our behalf are required to do so only on our instructions and to apply appropriate security safeguards.
9. CONTENT PROTECTION AND WATERMARKING
To protect CCET’s intellectual property and detect unauthorised sharing, paid SOP documents may carry visible and invisible watermarks that include your name, your account identifier, and a timestamped document serial, and we track downloads and access. This processing is carried out on the basis of our legitimate interest in preventing the unauthorised redistribution of paid content, as also provided for in the Research Advisory Ethics Charter.
10. DATA HOSTING AND INTERNATIONAL TRANSFERS
We adopt a hybrid hosting approach. Your personal, account, and transaction data are hosted in Zambia or in a jurisdiction that offers an equivalent level of data protection. Non-personal content, public pages, and static assets may be served from international cloud or content-delivery infrastructure for performance and cost efficiency.
Where any transfer of personal data outside Zambia is necessary, we carry it out only in accordance with the Act, which permits such transfers where you have consented, where the transfer is made under standard contracts or intragroup schemes approved by the Data Protection Commissioner, or where otherwise permitted by law. Sensitive personal data is retained within Zambia except where an exemption applies.
11. HOW WE PROTECT YOUR DATA
We apply organisational and technical measures appropriate to the risk, including:
● Encryption of data in transit (TLS) and encrypted storage for documents and backups;
● Secure hashing of passwords and tokenised handling of payment interactions;
● Role-based access control, mandatory two-factor authentication for administrators, and named admin accounts with no shared credentials;
● Automatic session timeout after inactivity, and shorter timeouts for administrators;
● Daily encrypted backups, tested restoration, and append-only audit logs of critical actions;
● Restriction of access to personal data to authorised staff on a strict need-to-know basis.
No system can be guaranteed to be completely secure, but we work to protect your data and to respond promptly to any security incident.
12. HOW LONG WE KEEP YOUR DATA
We keep your personal data only for as long as necessary for the purposes set out in this Policy. Transaction and invoicing records are retained for the period required by applicable tax and accounting law. Ethics Charter acceptance records and audit logs are retained for accountability and compliance. When you close your account, we delete or anonymise your personal data, except for records we are required to retain by law, which we keep only for the required period and then securely delete.
13. YOUR RIGHTS AS A DATA SUBJECT
Under the Act, and subject to its conditions and exemptions, you have the right to:
● be informed about, and obtain access to, the personal data we hold about you (access and notification);
● have inaccurate or incomplete personal data corrected (rectification);
● have your personal data erased in the circumstances provided by the Act (erasure);
● object to certain processing of your personal data (objection);
● not be subject to a decision based solely on automated processing that significantly affects you (automated processing);
● restrict our processing of your personal data in certain circumstances (restriction);
● be informed of the reasons for the collection of your personal data;
● receive your personal data in a structured, commonly used format and have it transferred where feasible (portability);
● withdraw your consent at any time where we rely on consent; and
● lodge a complaint with the Data Protection Commissioner, and to appeal, as provided by the Act.
To exercise any of these rights, contact us at ccetzm@gmail.com. We will respond as soon as practicable and without undue delay. Some rights do not apply where processing is necessary to comply with a legal obligation, for the establishment or defence of legal claims, or for research purposes, as set out in the Act.
14. AUTOMATED DECISION-MAKING AND RECOMMENDATIONS
The Platform includes an AI-powered recommendation feature that suggests SOP products relevant to your discipline and technology interests, using platform-approved content only. This feature supports your browsing; it does not make decisions that produce legal or similarly significant effects on you, and it does not generate submission-ready academic work. We do not carry out solely-automated decision-making of the kind restricted by the Act.
15. CHILDREN AND AGE
The RIS is intended for postgraduate and other adult researchers and is not directed to children. We do not knowingly collect personal data from persons under the age of 18. If you believe a minor has provided us with personal data, please contact us so that we can take appropriate action.
16. DATA BREACH NOTIFICATION
In the event of a personal data breach that meets the threshold under the Act, we will notify the Office of the Data Protection Commissioner within the timeframe required by law (currently within 24 hours of becoming aware of the breach), and will notify affected data subjects where the Act requires. We maintain an internal process for detecting, reporting, and investigating breaches.
17. CHANGES TO THIS POLICY
We may update this Policy from time to time to reflect changes in our practices, the Platform, or the law. Where changes are material, we will notify registered users and, where appropriate, seek renewed acceptance. The current version is published on the Platform, with its version number and effective date.
18. HOW TO CONTACT US AND COMPLAIN
If you have any question about this Policy or wish to exercise your rights, please contact us:
Data Protection Contact — CCET
Center for Contemporary & Emerging Technologies (CCET), Plot 25667 Musioatunya Road, Woodlands Ext, Lusaka, Zambia. Email: ccetzm@gmail.com. Telephone: +260 979 298 145 | 0 767 924 022
Website: www.risscholar.com
If you are not satisfied with how we have handled your personal data, you have the right to lodge a complaint with the Office of the Data Protection Commissioner established under the Data Protection Act No. 3 of 2021. We would, however, appreciate the opportunity to address your concerns before you approach the Commissioner.
19. GOVERNING LAW
This Privacy Policy is governed by and construed in accordance with the laws of the Republic of Zambia, including the Data Protection Act No. 3 of 2021, and is to be read together with the RIS Terms of Use and the Research Advisory Ethics Charter.