1. Who we are and what this policy covers
Golden Vision Association operates thegoldenvision.org and its learning, mentoring, academy, community and volunteer workspaces. This policy explains how we handle information when you visit the website, contact us, create an account or participate in our services. Golden Vision is responsible for the personal information it collects for these purposes.
Contact us at connect@thegoldenvision.org, or write to Block 10, Twiga Street, Mtoni Kijichi, Dar es Salaam, Tanzania. This policy does not replace a separate privacy notice given for a particular research project, event or partner programme.
2. Information we collect
- Account and profile information: your name, email address, profile details, interests, preferences and requested roles. Optional telephone details are collected when you provide them.
- Learning records: enrolments, lesson check-ins, project drafts, evidence, submissions, feedback, assessments, attendance, coursework, grades and credentials.
- Participation records: mentor or instructor applications, volunteer assignments, activity updates, hours and approval decisions.
- Communication and community content: enquiries, messages, posts, comments, reactions, saved items, connection requests, reports and collaboration requests.
- Technical information: session identifiers, browser/device information and request or security logs used by our hosting, authentication and anti-abuse services.
Private reflections, mentor notes and unpublished work are handled according to their sharing settings and authorised role access. Avoid submitting unnecessary health, financial, identification or other sensitive information, including information about other people without permission.
3. Why we use information
We use information to authenticate users, deliver learning and mentoring, administer enrolments and assessments, review role applications, coordinate volunteering, answer enquiries, provide requested communication and maintain a safe community. We also use relevant records to investigate abuse, resolve disputes, maintain platform security and meet applicable legal obligations.
Depending on the activity, processing relies on consent, providing a service you request, applicable legal obligations or a lawful operational purpose. Optional public sharing and optional marketing communications are choices separate from basic account access. Where processing relies on consent, you may withdraw it; withdrawal does not undo processing that was lawful before it was withdrawn.
4. Who can see your information
Community content is visible to the audience you select. Connection-only content is limited to eligible connections. A published portfolio or credential verification page may be accessible outside the platform, subject to the information you choose to disclose. Other people can copy content they can legitimately see, so do not publish information you need to keep private.
Assigned instructors and mentors receive the records needed for their approved responsibilities. Administrators manage access, applications, moderation and operational records. An administrator role does not by itself provide unrestricted access to private journals, private mentor notes or unrelated conversations. Messages are available to their participants; reported content may be reviewed for safety.
5. Service providers and disclosures
We use Supabase for authentication, database services and file storage, Vercel for website hosting, Resend for transactional email, and Cloudflare Turnstile for contact-form anti-abuse verification. These providers process the information needed to deliver their services under their own contractual and privacy terms.
If a live class or mentoring session uses Zoom, joining that session also involves Zoom processing meeting identifiers, participant details and the audio/video you choose to transmit. The meeting interface or invitation identifies the provider. Enabling your camera or microphone is your choice. Recording requires advance notice and any required consent; participation is not blanket permission to record or publish a session.
We may disclose relevant information when required by law or a valid legal process, to protect people against serious harm, or to investigate fraud and misuse. We do not sell personal information. A partner programme that needs additional disclosures should provide its own notice before collecting that information.
6. Where information is processed
Cloud services may process or store information outside Tanzania. The location depends on the service and its infrastructure. International transfers must meet applicable Tanzanian data-protection requirements, including required safeguards and regulatory permissions.
You can contact us for information about the providers and safeguards relevant to your records.
7. Cookies, browser storage and security
Authentication uses session cookies to keep you signed in. Browser storage may retain interface preferences and temporary verification state. Anti-abuse services may use their own cookies or equivalent technologies. Blocking essential storage can prevent sign-in or security checks from working. Signing out ends the application session; you can also clear website storage in your browser.
We use access controls, authenticated sessions and database permissions to restrict access. No online service can guarantee absolute security. Keep your password private, use a unique passphrase and tell us promptly if you suspect unauthorised access.
8. How long we keep information
We retain records for the purpose for which they were collected, including providing an active account, preserving learning or credential history, resolving disputes and meeting legal obligations. Different records may have different retention needs. Deleting a post or account does not necessarily remove records that must be retained for these reasons, copies held by recipients, or all backup copies immediately.
Ask us to review information you no longer need us to hold. We will explain any applicable retention requirement and whether deletion, restriction or de-identification is appropriate.
9. Your choices and data rights
You can update available profile and preference settings, control optional sharing, withdraw a published portfolio and manage community content. You may also request access to your information, correction, deletion, restriction, portability, object to processing where applicable, withdraw consent or ask for human review of a consequential automated decision. These rights may be subject to lawful exceptions; role approvals, assessments and moderation involve human review.
Send a request to connect@thegoldenvision.org, describing what you need. Do not email your password or full identity documents. We may ask for proportionate identity verification before releasing or changing private records. We will respond within applicable legal requirements and explain any limitation.
You may raise a concern with us or contact Tanzania's Personal Data Protection Commission. Using our complaint route does not remove your right to approach the Commission.
10. Young people and safeguarding
Golden Vision supports youth learning. If you are under 18, involve a parent or guardian before providing personal information or joining a programme. Programme organisers must establish the appropriate permission and safeguarding arrangements for young participants. Do not share a child's personal details, image or work without the necessary authority.
If you believe information about a child was submitted without appropriate permission, contact connect@thegoldenvision.org so that we can review and restrict or remove it where appropriate.
11. Changes and questions
We may update this policy as our services or obligations change. The date on this page identifies the current version. Material changes will be communicated through an appropriate platform notice where required. Questions and privacy requests can be sent to connect@thegoldenvision.org.