BUK CDL
Privacy Notice

How we collect, use and protect personal data

Effective date: 22 July 2026

1. About this Privacy Notice

Bayero University Kano, acting through its Centre for Distance Learning (the “Institution”, “we”, “us” or “our”), respects your privacy and is committed to protecting your personal data. This Privacy Notice explains how we collect, use, disclose, retain and protect personal data when students, applicants, staff and other authorised users interact with our admissions, administration and learning services through Klastra.

The Institution is the Data Controller for the personal data described in this notice. We determine why personal data is processed and how that processing is carried out.

This notice should be read together with any programme-specific, employment, admissions or other privacy information provided by the Institution.

2. About Klastra and Voostech’s role

Klastra is the software platform used by the Institution to manage admissions, student and staff records, learning activities, assessments, results, payments and related institutional processes.

Klastra was built and initially deployed by Voostech. The platform is delivered to the Institution without student or staff records. Following deployment, the Institution’s authorised personnel populate and administer the system on infrastructure controlled by the Institution.

Voostech does not have routine access to personal data stored in the Institution’s production deployment. If the Institution separately authorises Voostech or another provider to access personal data for support, maintenance, migration or another service, that access will be limited to the authorised purpose and governed by appropriate confidentiality, security and data-protection obligations.

3. Who this notice applies to

This notice applies to:

  • prospective students and applicants;
  • current and former students;
  • academic and non-academic staff;
  • instructors, assessors and external reviewers;
  • sponsors, guardians and next of kin where their information is provided;
  • alumni and graduates whose academic records are retained; and
  • other authorised users of the Institution’s Klastra platform.

4. Personal data we process

Depending on your relationship with the Institution and the services you use, we may process:

  • Identity information: name, photograph, date of birth, gender, nationality, identification numbers, registration or staff number, signature and identity documents.
  • Contact information: email address, telephone number, residential or postal address, emergency contact, sponsor, guardian and next-of-kin details.
  • Application and admission information: programme choices, application responses, admission decisions, reviewer comments, qualifications, certificates, transcripts and supporting documents.
  • Student and academic information: programme, level, academic status, course registrations, attendance, learning activity, assignments, examinations, submitted answers, grades, results, transcripts and graduation records.
  • Staff and professional information: role, department, staff number, qualifications, employment-related information and assigned academic or administrative responsibilities.
  • Financial and transaction information: invoices, fees, scholarships, payment status, transaction references and records received from authorised payment channels. Payment-card details are handled directly by an approved payment provider and are not stored in Klastra.
  • Communications and support information: enquiries, support requests, complaints, feedback, announcements and communications with the Institution.
  • Verification and access information: identity-card details, QR or credential verification events, access history and verification records.
  • Technical and security information: username, IP address, browser and device information, login history, session information, security events, system activity and audit logs.
  • Sensitive personal data: health, disability, accommodation or other sensitive information where necessary and lawfully authorised for an institutional purpose.

5. How we obtain personal data

We may obtain personal data:

  • directly from you when you apply, register, complete your profile, submit coursework, make an enquiry or otherwise use Klastra;
  • from authorised staff who create or update institutional records;
  • from information imported from approved institutional records or legacy systems;
  • from examination, admissions, payment, identity or regulatory bodies where the Institution is authorised to receive it;
  • from sponsors, guardians or employers where relevant; and
  • automatically when Klastra records login, usage, security and audit activity.

6. Why we process personal data

The Institution may process personal data to:

  • receive, assess and administer applications and admission decisions;
  • create and manage student and staff accounts;
  • deliver programmes, courses and learning materials;
  • record attendance and participation;
  • conduct assessments, examinations and academic-integrity checks;
  • calculate, approve, publish and maintain results and transcripts;
  • administer fees, invoices, payments, scholarships and refunds;
  • provide student, academic, technical and administrative support;
  • issue and verify institutional credentials and identity cards;
  • communicate academic, administrative and security information;
  • protect accounts, investigate misuse and maintain audit trails;
  • prepare institutional, accreditation and regulatory reports; and
  • comply with legal, regulatory and public-interest obligations.

7. Lawful bases for processing

The lawful basis depends on the purpose and circumstances. We may process personal data where:

  • processing is necessary to provide educational or related services under an agreement with you;
  • processing is necessary to meet a legal or regulatory obligation;
  • processing is necessary for a task carried out in the public interest or in the exercise of the Institution’s official authority, where applicable;
  • processing is necessary for the legitimate interests of the Institution or another person, provided those interests do not improperly override your rights;
  • you have given valid consent for a specific optional purpose; or
  • another lawful basis recognised by applicable law applies.

Where we rely on consent, you may withdraw it at any time. Withdrawal will not affect processing that was lawful before the withdrawal. We do not rely on consent where processing is mandatory and another lawful basis is more appropriate.

8. When personal data may be disclosed

Where necessary and lawfully permitted, personal data may be disclosed to:

  • authorised academic, administrative, finance, support and IT personnel;
  • departments, faculties and units within the Institution;
  • accreditation, examination, education and government authorities;
  • banks, payment providers and financial institutions involved in authorised transactions;
  • professional advisers, auditors and insurers;
  • technology or support providers appointed under appropriate contractual safeguards;
  • sponsors, guardians or employers where you have authorised the disclosure or another lawful basis applies; and
  • law-enforcement bodies, courts or other authorities where disclosure is required or permitted by law.

We do not sell personal data.

9. International transfers

Where personal data is transferred outside Nigeria, the Institution will apply safeguards required by applicable data-protection law. These may include an approved transfer mechanism, contractual protection and an assessment of the destination and recipient.

10. Data retention

The Institution retains personal data only for as long as reasonably needed for the purpose for which it was collected and to meet academic, financial, legal, accreditation, security and regulatory obligations.

Different records require different retention periods. Permanent or long-term academic records, such as final results and transcripts, may need to be retained for significantly longer than support requests, temporary uploads, application drafts or routine technical logs. When personal data is no longer required, it will be securely deleted, anonymised or archived in accordance with the Institution’s approved records-retention schedule.

11. How we protect personal data

The Institution applies reasonable and appropriate administrative, physical and technical measures to protect personal data. Depending on the deployment, these measures may include role-based access, authentication controls, encryption, activity logging, backups, staff confidentiality obligations, security monitoring and incident-response procedures.

Access is limited to authorised persons who require personal data for approved institutional duties. Users are responsible for protecting their passwords, signing out of shared devices and promptly reporting suspected unauthorised access.

12. Personal data breaches

The Institution maintains procedures for assessing and responding to suspected personal data breaches. Where a breach is likely to create a risk to affected individuals, the Institution will notify the Nigeria Data Protection Commission within the period required by applicable law. Where a breach is likely to result in a high risk to an individual, the Institution will also communicate relevant information to that individual as required by law.

13. Your data-protection rights

Subject to applicable law and lawful limitations, you may have the right to:

  • ask whether we process your personal data and request access to it;
  • request correction of inaccurate or incomplete information;
  • request deletion where the Institution has no lawful reason to retain it;
  • request restriction of, or object to, certain processing;
  • request portability of eligible information;
  • withdraw consent where processing is based on consent;
  • object to certain solely automated decisions, where applicable; and
  • complain to the Institution or the Nigeria Data Protection Commission.

To exercise a right, contact the Privacy Office using the details below. We may need to verify your identity. Some requests may be limited where retention or continued processing is required by law, academic-record obligations, the rights of another person or another lawful ground.

14. Children and vulnerable persons

Where the Institution provides services to a child or another person who requires legally recognised assistance, it will apply appropriate safeguards. These may include age verification, guardian or representative involvement, accessible notices and additional controls over sensitive information, as required by law and institutional policy.

15. Cookies and similar technologies

Klastra uses essential cookies and similar technologies to authenticate users, maintain sessions, remember necessary preferences and protect the platform. These technologies are required for the service to operate securely.

16. Changes to this notice

We may update this Privacy Notice when our processing activities, institutional services or legal obligations change. The current version will be published on this page with its effective date. Where a change materially affects how personal data is processed, the Institution will take reasonable steps to bring it to the attention of affected users.

17. Contact and complaints

Data Controller

Bayero University Kano
Centre for Distance Learning
PMB 3011, Kano State, Nigeria

Privacy Office

Email: cdl@buk.edu.ng
Telephone: 07085753547, 08140036765

Please contact us first if you have a concern about how your personal data is handled so that we can investigate and respond. You also have the right to submit a complaint to the Nigeria Data Protection Commission through its official channels.