Privacy Policy

    Last updated: 30 May 2026

    This page explains what data Vantrel collects, why it is collected, how it is used, and what rights you have. It is written to support candidates, partners, and organizations that want a clearer view of how personal data is handled across the platform.

    1. Introduction

    This Privacy Policy explains how Vantrel collects, uses, stores, shares, and protects personal data when you use vantrel.io and related services. It is designed to align with GDPR, UK GDPR, Nigeria NDPA 2023, and CCPA and CPRA principles.

    2. Data Controller

    Data controller: Vantrel Technologies Limited (vantrel.io), Lagos, Nigeria.

    Privacy contact: privacy@vantrel.io

    Referral partner inquiries: referral-partner@vantrel.io

    Legal notices: legal@vantrel.io

    3. What Data We Collect

    • Account data: name, email, profile and authentication metadata.
    • Subscription and billing metadata, without storing full card PAN data.
    • Learning data: question attempts, scores, mock sessions, analytics, and study activity.
    • AI tutor logs and related prompt and response context.
    • Support and contact data: contact form submissions, support chat interactions, and issue-escalation metadata.
    • Waitlist and onboarding data, including stated exam interests, preferred language, and beta or tester opt-in choices.
    • Technical data: browser, OS, IP, diagnostics, and session telemetry.
    • Cookie and local storage preferences.

    Partner Referral Program Data

    For referral program participants, we additionally collect:

    • Legal name, date of birth, and nationality.
    • Government-issued ID number, including passport, national ID, or driver license.
    • ID document expiry and issue dates.
    • Full residential address, including street, city, state, country, and postal code.
    • Bank account details, including account number, bank name, bank code, and account holder name.
    • Beneficiary details for payout disbursement.
    • KYC verification status and document submission history.
    • Referral code unique identifier and activation date.
    • Conversion attribution records showing which referred user is linked to which partner.
    • Commission earned, hold periods, payout batches, and transaction IDs.

    4. Why We Process Data

    • Provide account access and subscribed exam modules.
    • Deliver personalized readiness analytics and recommendations.
    • Process payments and maintain billing records.
    • Operate AI-credit or usage controls, entitlement enforcement, and abuse-rate protection safeguards.
    • Run security, anti-abuse, and fraud controls.
    • Provide user support, route escalation workflows, and investigate service incidents.
    • Verify partner identity and eligibility through Know Your Customer processes.
    • Detect and prevent referral fraud through IP analysis, velocity checks, and self-referral detection.
    • Process payout disbursements to verified referral partners via banking APIs.
    • Maintain fraud audit trails and partner compliance records.
    • Send service communications and optional marketing.
    • Improve platform quality and reliability.

    5. Lawful Bases

    Depending on jurisdiction and context, we rely on:

    • Contract performance
    • Legitimate interests
    • Consent
    • Legal obligation

    6. Who We Share Data With

    • Cloud infrastructure providers, including Supabase.
    • Payment processor Flutterwave for both user payments and referral partner disbursements.
    • Email delivery provider Resend.
    • Operational communications providers, including secure internal alerting channels used for transaction, support, and incident notifications.
    • Analytics provider Google Analytics, subject to cookie consent.
    • AI and media-generation providers used to deliver product features, such as tutoring, narration, or generated educational media.
    • Referral partners, who receive performance data only for their own codes, including impressions, conversions, and commissions.
    • KYC verification providers when identity verification is required.

    We do not sell personal data and do not share personal data for cross-context behavioral advertising.

    7. International Transfers

    Data may be processed in multiple countries where our providers, affiliates, or operations are located. Where required, Vantrel applies contractual and legal safeguards, including SCC and IDTA style controls and NDPA compatible transfer protections.

    8. Data Retention

    • Account and profile data: active subscription period plus 6 years after closure.
    • Payment records: 7 years from transaction date.
    • Usage and performance data: anonymized within 90 days after account closure.
    • AI tutor logs: 6 months from each session, with earlier deletion on request where feasible.
    • Contact and support submissions: up to 3 years from last interaction, unless a longer period is needed for legal claims or compliance.
    • Security, anti-abuse, and fraud detection logs: generally 12 months, and longer where needed for investigations, disputes, or legal obligations.
    • Marketing consent records: 3 years after consent withdrawal.
    • Support correspondence: 3 years from last interaction.
    • KYC documentation, submissions, photos, and verification records: 7 years from submission date or until the partner account is deleted.
    • Referral attribution records: 7 years for audit trail purposes.
    • Referral conversion data: 7 years from conversion.
    • Fraud flag records and investigation notes: 3 years from creation or flag resolution, whichever is later.
    • Payout transaction records and provider confirmations: 7 years from disbursement date.

    9. Cookies and Tracking

    We use necessary, functional, analytics, and, where consented, marketing cookies. Preferences can be managed in the cookie settings interface.

    Do Not Track signals do not currently change processing by themselves; we rely on cookie consent controls.

    See the Cookie Policy for details.

    10. Your Rights

    Depending on your jurisdiction, you may have rights to:

    • Access, correction, deletion, and portability.
    • Restriction of and objection to certain processing.
    • Withdraw consent where consent is the legal basis.
    • Request human review for decisions that are based solely on automated processing where applicable law grants that right.
    • Complain to your data protection authority.

    Standard response timelines:

    • GDPR and UK GDPR: 30 days, extendable where lawful.
    • Nigeria NDPA: 45 days.
    • California CCPA and CPRA: 45 days, extendable where lawful.

    11. Children's Privacy

    Vantrel is intended for adult professional learners and is not directed to individuals under 18. If we discover an underage account, we will take steps to remove the account and associated data as required by law.

    12. AI Features and Data

    Vantrel Tutor interactions are processed to generate educational responses, and some prompts or outputs may be handled by third-party AI providers acting under contractual controls. Vantage Score and adaptive features rely on platform performance data. AI outputs may be inaccurate, and users should validate important guidance.

    13. Security

    We apply technical and organizational safeguards, including encrypted transport, access controls, and monitoring. No system is entirely risk free, but we maintain incident response procedures and legal notification workflows.

    14. Changes to This Policy

    We may revise this policy from time to time. Material changes will be communicated before taking effect where required by law.

    15. Contact Us

    For privacy requests and data-rights inquiries, contact privacy@vantrel.io or use the form below.

    0/2,000