Plain-language rule: ResearchBridge Africa will collect only data reasonably needed for a clear purpose, protect it according to its sensitivity, and avoid using consent where a person has no genuine choice. Optional consent may be refused or withdrawn without losing unrelated core services.
1. Purpose and relationship to the Privacy Notice
These Notices explain ResearchBridge Africa’s data-protection principles and the choices presented when a person creates an account, joins a pilot, orders a service, participates in research, submits or reviews work, publishes content, receives communications or earns through the platform. The Privacy Notice gives an overview of platform processing; these Notices add detailed consent and rights rules.
They should be read with the Terms, Peer-Review Policy, Plagiarism and Responsible AI-Use Policy, Content-Removal and Complaints Procedure, Refund and Payout Policy, and any specific research-participant information sheet.
2. Data-protection principles
- Process personal data lawfully, fairly and transparently.
- Collect it for specific, explicit and legitimate purposes.
- Use only data that is adequate, relevant and not excessive.
- Take reasonable steps to keep data accurate and current.
- Retain identifiable data only as long as a documented purpose requires.
- Protect confidentiality, integrity and availability through proportionate safeguards.
- Keep evidence of decisions, permissions, consent and accountability without exposing it unnecessarily.
3. Who is responsible
ResearchBridge Africa is responsible for deciding how platform account, service, editorial, repository, learning, support, finance, security and audit data is handled. A university, researcher, lecturer, consultant or other organisation may be separately responsible for personal data it asks the platform to process or for data collected in an independent research study.
Where responsibilities are shared, users should be told which organisation answers the request. ResearchBridge Africa will not describe itself as the sole controller of data where another party determines the research purpose and means.
4. Personal data covered
Do not upload personal data about another person unless it is necessary, accurate, ethically appropriate and lawfully obtained. Manuscripts and datasets should be anonymised or minimised before upload wherever identifiable details are not required.
5. Purposes and authority for processing
Personal data may be used to provide accounts and role permissions; deliver topic, learning, review, editorial, repository and support functions; issue and reconcile invoices, refunds, wallet credits and payouts; maintain academic records; prevent fraud and misconduct; respond to complaints; protect users and systems; meet contractual and legal duties; and create de-identified or appropriately aggregated operational reports.
Depending on the activity and applicable law, processing may be necessary to provide a requested contract or service, meet a legal duty, protect a person’s vital interests, perform a legitimate and proportionate platform or academic function, carry out an authorised public or institutional task, or act on valid consent. The relevant notice or form should identify the applicable reason rather than presenting every activity as consent-based.
6. What valid consent means
Where consent is used, it must be informed, specific, freely given and expressed by a clear affirmative action. Consent requests must use understandable language, identify the purpose and data, name or describe relevant recipients, explain withdrawal, and remain separate from unrelated terms.
- No pre-ticked optional boxes, silence or inactivity as consent.
- No bundled “all or nothing” consent for unrelated purposes.
- No disadvantage for refusing optional marketing, publicity or research participation.
- Separate choices for materially different purposes.
- A dated record of the notice version, choice, method and person giving consent.
- Renewed consent where a materially new purpose cannot reasonably be covered by the original choice.
7. Consent choices on the platform
8. Research-participant consent
Before collecting identifiable research data, the researcher should provide a participant information sheet explaining the study, investigator, institution, purpose, procedures, duration, risks, benefits, confidentiality, recording, data sharing, retention, compensation where applicable, voluntary nature, withdrawal limits, contacts and ethics approval. Consent must be documented in a suitable written, electronic, recorded or witnessed form approved for the study.
Participants must not be misled about academic, financial or personal consequences. A lecturer, employer, clinician or person in authority should address undue influence and provide a genuinely voluntary route. Withdrawal may not require deletion of data already anonymised, included in completed analysis, or lawfully retained for research integrity; this limit must be explained before participation.
9. Children and people needing additional protection
The platform is designed primarily for adults in tertiary education and professional research. Where a study or service lawfully involves a child or a person who may not independently provide informed consent, the responsible party must apply appropriate age, capacity, assent, parental or guardian permission, safeguarding and ethics requirements. A child’s welfare prevails over publicity or commercial convenience.
ResearchBridge Africa may pause an upload or activity where age, authority or consent evidence is unclear. It will not knowingly use a child’s image, testimony or research information for marketing without the required specific permission and safeguards.
10. Sharing and service providers
Data is shared only where needed with authorised lecturers, editors, assigned reviewers, support or finance staff, institutional administrators within defined limits, and vetted providers for hosting, authentication, storage, communications, payment or security. A provider receives only the data reasonably needed for its role and is expected to protect it under suitable terms.
ResearchBridge Africa does not sell personal data. Reviewer identity, unpublished manuscripts, private support messages, payout details and participant data must not be disclosed to advertisers or unrelated users. Disclosure to a regulator, court, law-enforcement body, institution or rights holder may occur where lawful, necessary and properly recorded.
11. Publication, repositories and open access
Before public release, the author should see what will be published and confirm the chosen access level. Public metadata may include title, authors, affiliations, abstract, keywords, year, type, identifier and licence. Full text, images, appendices or data should be public only where rights, ethics, confidentiality and the selected access setting permit.
Withdrawing optional publication consent does not automatically erase a valid permanent scholarly record. ResearchBridge Africa may restrict or remove full text while retaining limited metadata, a correction, withdrawal or retraction notice where necessary for academic integrity, citation history, legal compliance or the rights of others. Requests are handled through the Content-Removal and Complaints Procedure.
12. Cookies, analytics and communications
Cookies or similar technologies strictly necessary for sign-in, security, preferences and core operation may be used without treating them as optional advertising consent. Non-essential analytics, personalisation or advertising technologies should remain off until the user makes the required choice. The cookie notice must identify categories, providers, duration and a way to change preferences.
Essential account, security, order, review and policy messages may still be sent when marketing is declined. Every marketing message should provide a simple opt-out, and withdrawal should be respected promptly.
13. Retention and deletion
ResearchBridge Africa will maintain a retention schedule based on service delivery, academic integrity, publication history, finance, tax, fraud prevention, disputes, safety, audit and legal obligations. Retention should be reviewed by data category rather than keeping every record indefinitely.
When a purpose expires, personal data should be securely deleted, anonymised or restricted. Backup copies may persist for a limited recovery period and should not return to ordinary use. Audit records should document a decision without reproducing entire sensitive files or unnecessary personal details.
14. Security and confidentiality
Safeguards may include role-based permissions, authentication, protected file delivery, encryption in transit, access logging, separation of duties, secure provider management, tested backups, staff confidentiality, incident response and periodic access review. Controls must reflect the sensitivity and harm that unauthorised access could cause.
Users must protect their credentials, use approved sharing routes and promptly report suspected loss, misdirection or unauthorised access. No system is completely risk-free, and a security statement must not be interpreted as a guarantee that a breach can never occur.
15. International processing
Hosting, authentication, communications, payment or other providers may process data outside Ghana. Before such processing, ResearchBridge Africa should assess the destination, provider, safeguards, contract, access risks and any required authorisation or notification. Users should be told where material international processing occurs and how safeguards may be obtained.
16. Automated tools and AI
AI or automated systems must not make an undisclosed final decision with serious academic, financial, access or disciplinary effect where meaningful human review is required. Similarity, fraud, moderation and AI-detection indicators are screening signals, not automatic proof. Affected users should be able to receive an understandable explanation and request human review.
Confidential manuscripts, personal data, reviewer material or unpublished research must not be entered into an unapproved public AI service. Any authorised provider should be assessed for retention, training use, security, international processing and contractual protection.
17. Individual rights and requests
Requests may be submitted through the Help Center or authenticated Support Services. ResearchBridge Africa may verify identity, clarify scope, protect another person’s data and explain any lawful limit. Requests should be acknowledged and completed within the period required by applicable law, with an update where complexity or a third-party process causes a permitted delay.
18. Withdrawing or changing consent
A user may change optional communication, publicity, publication or research choices through the relevant settings or request route. The platform should record the withdrawal date, scope, action taken and any data that must still be retained under another lawful purpose.
Withdrawal is not account cancellation. A person may stop one optional use while keeping their account and unrelated services. If the requested withdrawal makes a particular optional activity impossible, ResearchBridge Africa will explain that consequence before completing it.
19. Personal-data incidents and breach response
Suspected loss, exposure, alteration, unauthorised access or misuse must be promptly contained, recorded and assessed. The response should identify affected data and people, likely harm, protective action, evidence, provider involvement and improvements.
ResearchBridge Africa will notify the appropriate authority and affected people where and within the period required by applicable law. A notice should give useful protective steps without exposing additional sensitive information or compromising a lawful investigation.
20. Complaints, contact and regulatory route
Use the Help Center or authenticated Support Services for access, correction, deletion, consent withdrawal, privacy complaints or suspected disclosures. Provide enough information to identify the account or record, but never send a password, Mobile Money PIN, card PIN or one-time passcode.
If the matter is not resolved, a person may use the Content-Removal and Complaints Procedure and may contact the Data Protection Commission of Ghana or another competent authority where applicable. ResearchBridge Africa will not retaliate against a good-faith privacy request or complaint.
21. Governance, records and review
ResearchBridge Africa should maintain a data inventory, processing-purpose register, provider register, retention schedule, rights-request log, incident register, access reviews and consent evidence. High-risk processing should receive a documented data-protection and ethics assessment before launch.
These Notices will be reviewed at least annually and after a material platform, provider, legal or processing change. A new notice will show its date and version. Where a new purpose requires fresh consent, merely updating this page will not replace obtaining that consent.
Review notice: Before wider public launch, a qualified Ghanaian adviser should confirm the applicable Data Protection Act requirements, controller registration and contact particulars, cross-border safeguards, statutory response periods, breach-notification duties, retention schedule, cookie controls and consent wording used in each live form.
Appendix A — Consent record
A valid platform consent record should capture: the person or authorised representative; notice and version shown; specific purpose and data; options accepted or declined; date, time and method; relevant study, service or publication; expiry or review date where applicable; and later withdrawal or change.
Appendix B — Model optional consent statement
I have read the information for this specific optional use. I understand what personal data will be used, for what purpose, who may receive it, how long the choice applies, and how to withdraw. I understand that refusing or withdrawing this consent will not remove access to unrelated core ResearchBridge Africa services.
Appendix C — Researcher declaration
I confirm that personal data and research-participant information uploaded through ResearchBridge Africa is necessary for the stated study; the required ethics approval, participant information and consent or other lawful authority has been obtained; identifiable data has been minimised; and any sharing, publication, retention and withdrawal limits have been explained accurately.
My account