Privacy Notice
This notice explains how Nigerian Scholars in Italy (NiSIT) collects, uses, shares, and protects personal data when you visit this website, register as a member, or take part in our events and community.
Effective date: 15 July 2026
1. Who we are
Nigerian Scholars in Italy (“NiSIT”, “we”, “us”) is a national community network supporting Nigerian students and professionals in Italy. NiSIT is the data controller responsible for the personal data described in this notice, as defined by Regulation (EU) 2016/679 (the “GDPR”) and Italian Legislative Decree No. 196/2003, as amended by Legislative Decree No. 101/2018 (the “Italian Data Protection Code”).
For any question about this notice or to exercise your rights, contact us at nisitassociation@gmail.com.
2. Data we collect
We collect the following categories of personal data:
- Account data: email address, password (stored in encrypted/hashed form), account role, membership tier, and account status.
- Profile data: first name, other names, surname, sex, phone number, date of birth, social media link, university, course of study, degree level, region and city in Italy, start date and expected graduation year, funding type, scholarship name, employer or institution details, business name and description, interests and skills, general comments, and profile photo.
- Community and event data: event registrations and attendance, blog posts and comments you submit, and any content you voluntarily share through the platform.
- Communication preferences: whether you are subscribed to receive newsletters or event updates from us.
- Technical data: IP address, browser and device information, and the authentication cookie used to keep you securely signed in (see Section 7, Cookies).
Profile pictures are entirely optional, used solely for account customization, and are not subjected to biometric processing. Photos uploaded to the platform automatically have their embedded metadata (including any GPS location data from smartphone photos) stripped upon upload, before storage.
3. Why we process your data and our legal basis
Under Articles 6(1)(a), (b), and (f) GDPR, we process personal data for the following purposes. Where we rely on consent, we ask for it actively — for example, by an unticked checkbox that you must tick yourself when creating your account — and record the date you gave it.
- To create and administer your account and membership (performance of our membership arrangement with you and our legitimate interest in running a functioning community platform).
- To operate the member directory, events, and blog features you choose to take part in (performance of our arrangement with you and, where applicable, your consent to share specific profile fields).
- To send newsletters and event updates where you have opted in (consent, which you may withdraw at any time).
- To keep the platform secure, prevent fraud, and enforce our Terms & Conditions (legitimate interest).
- To comply with legal obligations, such as responding to lawful requests from public authorities (legal obligation).
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects, and we do not sell personal data to third parties.
5. Sharing with the Nigerian Embassy in Rome
Separately from all processing described above, you may choose — entirely optionally, and independently of creating or keeping your account — to consent to NiSIT sharing a minimized set of your data with the Embassy of Nigeria in Italy (Rome), for its community registry and official updates to Nigerian nationals in Italy. We ask for this consent through its own, never pre-ticked checkbox, separate from the checkbox for this Privacy Notice, so declining it never affects your account or membership (Art. 7(4) GDPR).
Only the following fields are ever included, and nothing else:
- Full name (first name, other names, surname).
- Sex.
- Date of birth (day/month only — we do not collect or share the year).
- Email address and phone number.
- University name, course of study, and degree level.
We never include funding/scholarship details, employer or business information, social media links, your profile photo, interests or comments, or any account/security data in what is shared with the Embassy.
Legal basis and international transfer. This sharing relies on your explicit consent (Art. 6(1)(a) GDPR). Because Nigeria does not benefit from a European Commission adequacy decision, sharing this data is also an international transfer that relies on your explicit, informed consent to that transfer under Art. 49(1)(a) GDPR — data shared with the Embassy is subject to Nigerian law once received, which may not offer protections equivalent to the GDPR, and the Embassy acts as an independent data controller for whatever it does with the data after receiving it.
How reports are generated. NiSIT does not give the Embassy standing or automatic access to member data. A Super Admin periodically generates a report, on demand, drawing only from members whose consent is switched on at that moment; every report is logged with its title, generation date, and the number of members included.
Withdrawing consent. You can switch this sharing on or off at any time from Privacy Settings — just as easily as you gave it. Turning it off takes effect immediately for any future report, but cannot retract data already included in a report already sent to the Embassy.
6. International data transfers
Some of our service providers may process data on servers located outside the European Economic Area (EEA). Where this occurs, we rely on adequacy decisions of the European Commission or Standard Contractual Clauses (Article 46 GDPR) to ensure your data continues to receive a level of protection equivalent to that guaranteed within the EEA. You may request further details of the safeguards in place by contacting us. (See Section 5 above for the separate, consent-based transfer to the Nigerian Embassy.)
7. How long we keep your data
We keep account and profile data for as long as your membership is active. If you deactivate your account or request deletion, we delete or anonymise your personal data within a reasonable period, except where we are required to retain certain records (such as financial or legal records) for longer to comply with a legal obligation or to establish, exercise, or defend legal claims. Event and blog content may be retained in anonymised form for the historical record of the association.
9. Your rights
Under the GDPR, you have the right to:
- Access the personal data we hold about you.
- Request rectification of inaccurate or incomplete data.
- Request erasure of your data (“right to be forgotten”), subject to any legal retention obligations.
- Request restriction of processing in certain circumstances.
- Receive your data in a portable format, or ask us to transmit it to another controller.
- Object to processing based on our legitimate interest, including direct marketing.
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
To exercise any of these rights, contact us at nisitassociation@gmail.com. We will respond within the timeframes required by the GDPR (generally one month). You also have the right to lodge a complaint with the Italian supervisory authority, the Garante per la protezione dei dati personali, or with the supervisory authority of your habitual residence or place of work within the EU.
10. Security
We apply appropriate technical and organisational measures — including password hashing, access controls, and encrypted transport (HTTPS) — to protect personal data against unauthorised access, loss, or misuse. No system is completely secure, and we encourage you to use a strong, unique password for your account.
11. Children
NiSIT’s services are intended for prospective and current students and professionals and are not directed at children under 16. We do not knowingly collect personal data from children under 16 without appropriate parental or guardian consent.
12. Changes to this notice
We may update this notice from time to time to reflect changes in our practices or legal requirements. We will post the updated notice on this page with a revised effective date, and, where changes are material, notify members through the platform or by email.