FITC Learning Store and FITC Mobile Learning Privacy Policy

Effective date: 27 July 2026
Last updated: 27 July 2026

1. About this policy

This Privacy Policy explains how FITC LTD/GTE, also known as the Financial Institutions Training Centre ("FITC", "we", "us", or "our"), collects, uses, shares, stores, and protects personal data when you use:

  • the FITC Learning Store and learning management system;
  • the FITC Mobile Learning application for Android and iOS (the "App");
  • FITC account registration, sign-in, course enrolment, learning, assessment, messaging, certification, support, and related services; and
  • pages or learning activities displayed inside the App through a secure web view.

FITC is the data controller for the processing described in this Policy unless another organisation, such as your employer or programme sponsor, determines the purpose and means of processing your data. In that situation, the other organisation may also be a controller and its privacy notice may apply.

This Policy should be read together with the FITC Learning Store Terms and Conditions and any programme-specific privacy notice provided to you.

2. Personal data we collect

The data we collect depends on the services and features you use.

2.1 Account, registration, and profile data

We may collect:

  • first name, last name, username, email address, and telephone number;
  • organisation, job title, location, and other profile information you choose to provide or that your sponsoring organisation provides;
  • Moodle user ID and other account identifiers;
  • password credentials, which are protected using one-way password hashing on the server;
  • account status, preferences, consent or policy-acceptance records, and support communications; and
  • the identity of an employer, institution, or sponsor connected with your enrolment.

Please keep your account information accurate and do not share your password or one-time code with anyone.

2.2 Sign-in and security data

Depending on the sign-in method you use, we may process:

  • a username and password;
  • an email address or telephone number used to send a one-time password ("OTP");
  • an opaque OTP request identifier, hashed OTP, delivery channel, verification attempts, expiry and use times;
  • a Google or Microsoft identity-provider type, provider-issued account identifier, email address, and security tokens when you choose single sign-on;
  • Moodle web-service and private tokens used to keep you signed in and securely access protected content;
  • IP address, browser or application user-agent, authentication time, event type, and error or security-audit information; and
  • a QR sign-in key and related account identifier when you choose QR sign-in.

Authentication tokens are stored in secure device storage where supported. FITC does not receive your Google or Microsoft password.

2.3 Learning, assessment, and certification data

We may collect or generate:

  • course searches, enrolments, learning paths, attendance, access dates, and course participation;
  • content viewed, activity completion, time or session information, bookmarks, and learning progress;
  • quiz and assignment attempts, responses, submitted files, grades, feedback, and assessment results;
  • SCORM activity and attempt data, including resume location, completion status, scores, and pending offline progress;
  • certificates, badge records, certificate issue details, and verification codes;
  • calendar events and course notifications; and
  • information needed to provide instructor-led, virtual, blended, or self-paced learning.

Your learning record may be visible to authorised FITC personnel, facilitators, assessors, and, where applicable, an employer, institution, or programme sponsor.

2.4 Communications and user content

When you use collaboration or submission features, we may process:

  • messages and conversation content;
  • forum discussions and replies;
  • assignment text and uploaded files;
  • glossary entries, feedback, comments, and other content you submit; and
  • notification status, such as whether a notification has been read.

Do not include unnecessary sensitive personal data in free-text fields, messages, forums, or uploaded files.

2.5 Purchases and payment information

Where the Learning Store offers paid programmes, we may process:

  • course order and purchase history;
  • payer and billing contact information;
  • amount, currency, payment status, transaction reference, receipt, refund, and reconciliation information; and
  • information required to investigate a failed, duplicate, disputed, or fraudulent transaction.

Payment card or bank-account details are entered into the selected payment provider's service. FITC does not intend to store complete payment-card numbers or card security codes. The payment provider processes those details under its own privacy policy. The current version of the App does not process in-app card payments.

2.6 Device, app, and technical data

We may process:

  • device name and model, operating-system type and version, App version, and network status;
  • an App-generated per-install device identifier that is not an advertising identifier;
  • an Apple Push Notification service or Firebase Cloud Messaging push token when you enable notifications;
  • server and security logs, including IP address, request time, requested function, response or error information, and user-agent; and
  • cached copies of authorised Moodle responses and content needed for performance or offline access.

The current App does not include third-party advertising, behavioural-tracking, mobile analytics, or crash-reporting SDKs. FITC does not use App data for cross-app advertising tracking. Apple and Google may independently process App Store, Google Play, device, and platform diagnostic information under their own privacy policies.

2.7 Camera, biometrics, files, and local device data

The App requests only the permissions needed for the feature you choose:

  • Camera: If you choose QR sign-in, the camera scans the sign-in code. Camera images are processed on the device and are not saved or uploaded by the App. The scanned sign-in information is used to complete authentication with the FITC learning system.
  • Biometrics: If you enable Face ID, fingerprint, or another supported biometric for App Lock, authentication is performed by your device's operating system. FITC does not receive or store your biometric template.
  • PIN: If you enable App Lock, a one-way hash of the PIN and your lock preference are stored in secure storage on your device. FITC does not receive the PIN.
  • Notifications: If you allow notifications, the App registers a push token and limited device information with the learning system so that course and account notifications can be delivered.
  • Files and offline content: The App may store downloaded course resources, SCORM packages, certificates, cached learning information, and pending progress on your device. A file you deliberately export or share may remain outside the App and is controlled through your device and the destination you selected.

The App does not request access to your precise location, contacts, microphone, call logs, or SMS message history.

3. How we use personal data

We use personal data to:

  • create, verify, administer, support, and secure learner accounts;
  • authenticate users through password, OTP, QR sign-in, or optional Google or Microsoft sign-in;
  • enrol learners, deliver courses and learning activities, and provide offline functionality;
  • save and synchronise course progress, assessments, grades, messages, badges, and certificates;
  • process course orders, payments, refunds, and financial reconciliation;
  • send service, security, course, assessment, certification, and account notifications;
  • respond to support, complaint, privacy, and technical requests;
  • prevent fraud, misuse, unauthorised access, and attacks on the learning system;
  • maintain service availability, troubleshoot faults, and improve accessibility and user experience;
  • maintain training, certification, financial, audit, and regulatory records;
  • comply with applicable law, lawful requests, and contractual obligations; and
  • send marketing communications where you have consented or where otherwise permitted by law. You may opt out of non-essential marketing at any time.

We do not sell personal data.

4. Legal bases for processing

Under the Nigeria Data Protection Act 2023 and other applicable laws, we rely on one or more of the following legal bases:

  • Contract: processing needed to create your account, enrol you, deliver purchased or sponsored learning, assess participation, provide certificates, and administer the service;
  • Consent: optional marketing, camera access, push notifications, optional biometric App Lock, and other processing where consent is requested. You may withdraw consent, but this will not affect processing already carried out lawfully;
  • Legitimate interests: protecting accounts and systems, preventing fraud, keeping proportionate audit logs, administering learning services, improving service quality, and establishing or defending legal claims, provided these interests are not overridden by your rights and freedoms;
  • Legal obligation: processing and retention required by tax, accounting, regulatory, court, law-enforcement, or other legal requirements;
  • Vital interests: processing necessary to protect someone's life or physical safety in exceptional circumstances; and
  • Public interest or official authority: where applicable to a programme or a lawful request.

If your employer, institution, or sponsor arranges your learning, processing may also be necessary to fulfil FITC's contract with that organisation or its legitimate interests in administering the programme. We will seek consent where applicable law requires it.

5. When we share personal data

We share only the data reasonably necessary for the relevant purpose. Recipients may include:

  • authorised FITC personnel, facilitators, assessors, support staff, system administrators, and professional advisers;
  • your employer, institution, programme sponsor, or authorised representative where they arranged or paid for your learning, subject to the applicable agreement and notice;
  • technology, hosting, backup, email, customer-support, learning-platform, and security service providers;
  • the configured OTP delivery provider, which may include Termii, Twilio, or Africa's Talking, for delivery of an OTP to your telephone number;
  • Google reCAPTCHA, when enabled for account registration or password recovery, to help prevent automated abuse;
  • Google or Microsoft, if you choose the relevant single sign-on option;
  • Apple Push Notification service, Firebase Cloud Messaging, and the configured Moodle notification service when you enable push notifications;
  • payment processors, banks, and financial institutions used for course purchases, refunds, and reconciliation;
  • auditors, insurers, legal advisers, regulators, courts, law-enforcement bodies, and other authorities where disclosure is required or permitted by law; and
  • a successor organisation in connection with a restructuring, merger, transfer, or similar transaction, subject to appropriate safeguards and notice where required.

Service providers may use personal data only for the contracted service and in accordance with applicable data-protection obligations. We do not authorise service providers to use learner data for their own advertising.

6. International data transfers

Some technology, identity, messaging, notification, payment, or support providers may process data outside Nigeria. Where personal data is transferred internationally, FITC will use a transfer mechanism permitted by applicable law and take reasonable steps to ensure an adequate level of protection. Measures may include contractual safeguards, vendor due diligence, data minimisation, encryption, and transfer to a country or recipient recognised as providing appropriate protection.

7. Data retention and deletion

We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including to deliver learning, maintain valid training and certification records, meet legal and contractual obligations, resolve disputes, and protect the service.

Current authentication controls include:

  • unconfirmed email registrations are scheduled for deletion after 24 hours;
  • expired OTP records are scheduled for deletion after a short security window;
  • abandoned, unlinked OTP identities are scheduled for deletion after 24 hours when no related OTP remains;
  • OTP authentication audit logs are normally retained for 90 days, although an authorised administrator may configure a period between 1 and 365 days; and
  • mobile web-service tokens normally expire after 30 days, although an authorised administrator may configure a period between 1 and 90 days.

Account, purchase, enrolment, assessment, grade, certificate, and financial records may be retained for longer where needed to verify qualifications, administer a continuing learner relationship, meet accounting or regulatory requirements, prevent fraud, or establish and defend legal claims. When data is no longer required, we delete it, anonymise it, or securely restrict its use.

On your device:

  • signing out deletes the App's secure authentication tokens and its general web-service response cache;
  • some downloaded course packages, certificates, resources, preferences, and offline learning data may remain until removed through an available App or device control or until the App is uninstalled; and
  • files that you exported or shared outside the App must be removed from their destination separately.

8. Security

We use administrative, technical, and organisational safeguards appropriate to the nature and risk of the data. These include access controls, role and capability checks, encrypted network connections, secure device storage for authentication tokens, one-way hashing for passwords and OTPs, token expiry, rate limiting, audit logging, backups, and staff or service-provider confidentiality requirements.

No system can be guaranteed completely secure. You should use a strong, unique password, keep your device and App updated, enable a device lock, and report suspected account misuse promptly. FITC will manage qualifying personal-data breaches in accordance with applicable law.

9. Your rights and choices

Subject to applicable law and any lawful exemptions, you may have the right to:

  • be informed about how your personal data is processed;
  • request access to your personal data and a copy of it;
  • correct inaccurate or incomplete data;
  • request deletion of data that is no longer required or is processed unlawfully;
  • restrict or object to certain processing;
  • withdraw consent for consent-based processing;
  • request data portability where applicable;
  • object to a decision based solely on automated processing that produces legal or similarly significant effects, and request human review; and
  • lodge a complaint with the Nigeria Data Protection Commission.

The App does not currently make decisions about you based solely on automated processing that produce legal or similarly significant effects.

To exercise a right, contact us using section 14. We may ask for information reasonably necessary to verify your identity and protect your account. We will not ask you to send your password, PIN, OTP, or complete payment-card details. A request may be limited or refused where permitted by law, including where disclosure would adversely affect another person's rights or where retention is legally required. We will explain our decision where required.

You may also:

  • deny or later disable camera, notification, or biometric permissions in your device settings;
  • disable App Lock within the App;
  • opt out of non-essential marketing through the unsubscribe method provided or by contacting us; and
  • control cookies and similar technologies used by the web Learning Store through the available cookie controls or your browser settings. Disabling essential cookies may prevent sign-in or other requested functions.

10. Account deletion

You may request deletion of your FITC learning account and associated personal data by emailing customercare@fitc-ng.com with the subject Account Deletion Request, or by using any account-deletion form or in-App option made available by FITC.

Please identify the account using the email address registered with FITC and do not include your password or OTP. We may need to verify your identity before acting. Deleting an account is permanent and may remove access to courses, submitted work, messages, grades, badges, certificates, and other learning records.

We will delete or de-identify data associated with the account unless we must retain specified records for a lawful reason, such as financial reporting, fraud prevention, certification verification, dispute resolution, or another legal obligation. If data must be retained, we will restrict it to the permitted purpose and retain it only for the required period.

Uninstalling the App removes App-managed data from that device but does not delete your FITC account or server-side learning records.

11. Children's privacy

The Learning Store and App are intended primarily for adult professional learners and are not directed to children under 13. A person under 18 may use the service only where permitted by the applicable programme and with the authorisation or sponsorship of a parent or guardian, employer, educational institution, or other responsible organisation as required.

If you believe a child has provided personal data without the required authorisation, contact us so that we can investigate and take appropriate action.

12. Third-party links and services

Courses and messages may contain links to websites or services not operated by FITC. Their privacy practices are governed by their own notices. We encourage you to review those notices before providing personal data.

Relevant third-party privacy information may include:

The presence of a provider in this list does not mean that every provider is enabled for every learner or at all times.

13. Changes to this Policy

We may update this Policy to reflect changes in the service, law, technology, or our processing practices. We will post the updated Policy at the public Privacy Policy URL and change the "Last updated" date. Where a change materially affects your rights or how we use personal data, we will provide additional notice where required.

14. Contact us

For privacy questions, complaints, or rights requests, contact:

Data Protection Officer
FITC LTD/GTE (Financial Institutions Training Centre)
164/166 Murtala Mohammed Way
Ebute-Metta, Lagos, Nigeria

Email: customercare@fitc-ng.com
Subject line: Data Protection Request
Telephone: +234 816 620 6182

For Learning Store support, you may also contact:

Email: learninganddevelopment@fitc-ng.com
Telephone: +234 703 068 6004

If you are not satisfied with our response, you may lodge a complaint with the Nigeria Data Protection Commission.