Privacy Policy

Last updated: August 5, 2026

1. Introduction

Coridr Limited (“Coridr”, “We”, “Us” or “Our”) is the owner and operator of Coridr, an application, online platform, website, mobile or tablet application or domain used to provide our services (referred to as the “Platform”).

Coridr is a document audit and application review platform that supports educational providers, international education consultants, and travel agencies in reviewing application documents before submission to educational institutions, immigration authorities, and other relevant organisations (the “Services”).

This Privacy Policy explains how we collect, use, disclose, store, and otherwise process personal data through our website, platform, and related services, as well as the rights available to individuals in relation to their personal data.We are committed to protecting personal data and processing it responsibly, securely, and in accordance with applicable data protection laws.

Coridr acts as a data controller in relation to personal data processed for account administration, authentication, billing, customer support, security, analytics, and provision of the Services. Where we process Customer Content solely on your documented instructions in order to provide the Services, we generally act as a data processor (or service provider, where applicable).

2. When This Privacy Policy Applies

2.1. This Privacy Policy applies to the processing of personal data in connection with the Services.

Specifically, it applies to:

  • Coridr Platform users;
  • Persons who registers for, signs in to, or requests access to Coridr;
  • Agency administrators and their team members;
  • Persons who contact us for support, demos, onboarding, information, or product updates;
  • Visitors to Coridr or any page that links to this policy.

2.2. Where Coridr processes personal data on behalf of an educational provider, travel agency, or other customer, that organisation generally acts as the data controller and determines the purposes and means of processing the personal data. In such cases, Coridr acts as a data processor and processes personal data only in accordance with the customer's documented instructions and applicable law.

2.3. If you are an applicant whose personal data has been submitted to Coridr by an educational provider, travel agency, or other customer, your primary relationship is with that organisation. If you have questions about how your personal data was collected, the lawful basis for its processing, or wish to exercise your data protection rights, you should contact the relevant educational provider or agency in the first instance. Where appropriate, Coridr will assist its customers in responding to such requests in accordance with applicable data protection laws.

2.4. This Privacy Policy should be read together with the privacy notice of the educational provider, travel agency, or other customer that collected your personal data, where applicable.

3. Personal Data We Collect

3.1. Account and Registration Information

When you create an account or use Coridr we may collect your:

  • full name;
  • email address;
  • telephone number;
  • organisation or agency name;
  • verification status;
  • date and time of registration;
  • account status and login activity; and
  • authentication and security-related information (such as login sessions and password reset requests).

3.2. Organisation and Agency Information

Where you register as an organisation or agency on the Platform, we may process:

  • organisation or agency name;
  • business address;
  • contact information;
  • authorised users and user roles;
  • branding information (such as logos where uploaded);
  • notification and communication preferences; and
  • account configuration settings.

3.3. Applicant and Application Information

When our customers use the Platform to review applications, we process personal data relating to applicants on behalf of the relevant educational provider or travel agency. Depending on the documents submitted, this may include:

  • full name;
  • passport and travel document information;
  • date of birth;
  • nationality;
  • contact information;
  • academic records, certificates, and transcripts;
  • employment and financial documents;
  • visa or admission application forms;
  • supporting documents submitted by or on behalf of the applicant; and
  • any other information contained in documents uploaded to the Platform.

3.4. Document Review and AI Analysis Information

To provide our document audit and review services, we may process:

  • extracted text and document metadata;
  • document completeness and consistency checks;
  • AI-assisted extraction and analysis results;
  • rule-based validation results;
  • reviewer comments and override decisions;
  • audit findings and risk indicators;
  • generated reports and summaries; and
  • application review history.

AI-generated outputs are advisory only and are subject to review by authorised human reviewers before any final decision is made.

3.5. Communications and File Uploads

We may process documents and communications submitted through supported channels, including the Coridr Platform and approved integrations (such as WhatsApp Business integrations where enabled).

Depending on the method of submission, we may process:

  • uploaded documents and supporting files;
  • document metadata;
  • limited technical information necessary to receive and process uploaded files.

3.6. Technical and Usage Information

We automatically collect certain technical information necessary to operate, secure, and improve the Platform, including:

  • IP address;
  • browser type and device information;
  • operating system;
  • Platform usage information;
  • login history;
  • timestamps;
  • audit logs;
  • system diagnostics; and
  • security and error logs.

3.7. Support and Communications

If you contact us or request support, we may process:

  • your name;
  • email address;
  • telephone number;
  • organisation or agency name;
  • support requests and correspondence;
  • screenshots or documents you choose to share; and
  • feedback relating to the Platform or our services.

4. How We Use Personal Data

We use personal data to:

Provide the Services

  • create, verify, and manage user accounts;
  • authenticate users and facilitate account access, password resets, and account recovery;
  • configure organisation and agency profiles, user roles, and account settings;
  • receive, process, and review application documents uploaded through the Platform or approved integrations;
  • perform AI-assisted document extraction, validation, and analysis;
  • generate document audit reports, findings, and recommendations;
  • enable authorised reviewers to review, comment on, and override AI-generated findings where necessary;
  • maintain audit trails and application review records; and
  • provide other features and services requested by our customers.

To Operate and Secure the Platform

  • protect the security, integrity, and availability of the Platform;
  • detect, prevent, investigate, and respond to fraud, unauthorised access, security incidents, and other misuse of the Platform;
  • monitor system performance and diagnose technical issues;
  • maintain audit logs and security records; and
  • enforce our Terms of Use and other applicable policies.

Support and Improve Our Services

  • provide customer support, onboarding, and technical assistance;
  • respond to enquiries and support requests;
  • improve the functionality, reliability, performance, accessibility, and user experience of the Platform;
  • monitor service performance and identify opportunities for improvement; and
  • develop, test, and enhance new features and services.

Comply with Legal and Regulatory Obligations

  • comply with applicable laws, regulations, regulatory guidance, and lawful requests from competent authorities;
  • establish, exercise, or defend legal claims;
  • fulfil our contractual obligations; and
  • maintain records necessary to demonstrate compliance with applicable legal and regulatory requirements.

5. Lawful Bases for Processing

The lawful basis applicable to a particular processing activity depends on the nature of the personal data, the services being provided, and whether Coridr acts as a data controller or a data processor in relation to that processing activity.

BasisWhen we rely on it
ContractTo provide the Coridr Platform and related services, manage user accounts, and fulfil our contractual obligations to our customers.
ConsentWhere you choose to provide optional information, connect third-party services, or receive certain communications from us.
Legitimate interestsTo operate, secure, maintain, monitor, improve and protect Coridr in ways that do not override your rights.
Legal obligationWhere we are required to process personal data to comply with applicable laws, regulations, lawful requests, court orders, or regulatory obligations.
Processing on behalf of our customersWhere Coridr processes personal data solely on behalf of educational providers, international education consultants, travel agencies, or other customers, we do so in accordance with their documented instructions. In such cases, the relevant customer, as the data controller, is responsible for identifying and relying on the appropriate lawful basis under the Nigeria Data Protection Act (NDPA) or any other applicable data protection law.

6. Your Rights as a Data Subject

6.1. Subject to the Nigeria Data Protection Act, 2023 ("NDPA") and other applicable data protection laws, you have the following rights in relation to your personal data:

  • Right of Access – to request access to, and obtain a copy of, the personal data we hold about you.
  • Right to Rectification – to request the correction of inaccurate or incomplete personal data.
  • Right to Restrict Processing – to request that we restrict the processing of your personal data in certain circumstances.
  • Right to Object – to object to the processing of your personal data in circumstances permitted by applicable law, including where personal data is processed for direct marketing purposes.
  • Right Not to Be Subject to Solely Automated Decisions – not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except where permitted by applicable law.
  • Right to Data Portability – where applicable, to receive the personal data you have provided in a structured, commonly used, and machine-readable format and to transmit that data to another data controller.
  • Right to Erasure – to request the deletion of your personal data in circumstances permitted by applicable law.
  • Right to Withdraw Consent – where processing is based on your consent, to withdraw that consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
  • Right to Lodge a Complaint – to lodge a complaint with the Nigeria Data Protection Commission (NDPC) or any other competent supervisory authority if you believe your personal data has been processed in violation of applicable data protection laws.

6.2. Where Coridr processes personal data on behalf of an educational provider, international education consultant, travel agency, or other customer, that organisation is generally responsible for responding to requests relating to the exercise of these rights. If you submit a request directly to Coridr in relation to such personal data, we may refer your request to the relevant organisation or assist them in responding in accordance with applicable law and our contractual obligations.

Where Coridr acts as the data controller, you may exercise your rights by contacting us at hello@coridr.com.

7. How We Process and Store Personal Data

7.1. Coridr processes personal data through its secure cloud-based Platform to provide the Services.

7.2. Personal data submitted to the Platform may be processed for the purposes of document extraction, validation, AI-assisted analysis, report generation, audit logging, and other services requested by our customers.

7.3. Where AI-assisted analysis is used, Coridr processes only the information reasonably necessary to perform the requested analysis. AI-generated outputs are advisory only and are subject to meaningful human review before any final determination is made.

7.4. We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, loss, or destruction. Access to personal data is restricted to authorised users and personnel with a legitimate business need to access such information.

8. Third-Party Service Providers

8.1. We may engage trusted third-party service providers to support the operation, security, and delivery of the Platform. These providers process personal data only where necessary to perform services on our behalf or, where applicable, in accordance with their own privacy policies.

8.2. Depending on the services you use, we may share personal data with:

  • Cloud hosting and infrastructure providers to host and secure the Platform and its data.
  • Artificial intelligence and document processing providers to facilitate document extraction, validation, and AI-assisted analysis.
  • Communication service providers, including approved messaging and email providers, to facilitate document intake, notifications, and customer communications.
  • Authentication and identity management providers to enable secure user authentication and account management.
  • Payment service providers, where applicable, to process subscription fees and other payments.
  • Professional advisers, auditors, regulators, law enforcement agencies, or other competent authorities where disclosure is required by law or necessary to establish, exercise, or defend legal claims.

8.3. We require service providers processing personal data on our behalf to implement appropriate security measures and to process personal data only in accordance with our instructions and applicable law.

8.4. Where a third-party provider acts as an independent data controller, the processing of personal data by that provider will be governed by its own privacy policy and terms of service.

9. AI-Assisted Processing and Human Review

9.1. CORIDR uses artificial intelligence and automated technologies to assist in the extraction, validation, and review of application documents submitted through the Platform.

9.2. AI-assisted processing may be used to:

  • extract information from uploaded documents;
  • identify missing, inconsistent, or incomplete information;
  • perform rule-based validation checks; and
  • generate document audit findings and recommendations for authorised reviewers.

9.3. AI-generated outputs are intended solely to assist authorised users in reviewing application documents. They do not constitute legal, immigration, admissions, or professional advice and are not used as the sole basis for decisions affecting applicants. All significant findings and recommendations remain subject to meaningful human review. Authorised reviewers are responsible for assessing AI-generated outputs and making any final determination or recommendation.

10. How We Share Personal Data

We may share personal data in the following circumstances:

  • With our customers, including educational providers, international education consultants, travel agencies, and other organisations that use the Platform, in connection with the services we provide.
  • With authorised users within a customer's organisation who require access to perform their responsibilities.
  • With trusted service providers and sub-processors that provide cloud hosting, infrastructure, artificial intelligence, document processing, authentication, communication, technical support, security, analytics, or other services necessary for the operation of the Platform.
  • With our employees, contractors, and professional advisers who require access to personal data to operate, support, secure, or improve the Platform, subject to appropriate confidentiality obligations.
  • With regulators, courts, law enforcement agencies, or other competent authorities where disclosure is required by law or necessary to establish, exercise, or defend legal rights.

We do not sell, rent, or disclose personal data to third parties for their own advertising or direct marketing purposes.

11. International Transfers of Personal Data

11.1. To provide the Platform and related services, Coridr may transfer or permit access to personal data by authorised service providers or sub-processors located outside Nigeria.

11.2. Where personal data is transferred internationally, we will implement appropriate legal, technical, and organisational safeguards to ensure that such transfers comply with the requirements of the Nigeria Data Protection Act, 2023 (NDPA), and other applicable data protection laws.

Such safeguards may include, where appropriate:

  • transferring personal data to countries recognised as providing an adequate level of protection;
  • entering into appropriate contractual arrangements with recipients of the personal data; and
  • adopting other safeguards recognised under applicable law.

12. Data Retention

12.1. We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, provide our services, comply with legal and regulatory obligations, resolve disputes, enforce our agreements, and protect our legitimate interests.

12.2. Where CORIDR processes personal data on behalf of its customers, we retain such data in accordance with the customer's documented instructions, applicable contractual arrangements, and applicable law.

12.3. Unless otherwise required by law or agreed with the relevant customer:

Data CategoryRetention Approach
Applicant documentsRetained until seven (7) days after the relevant application outcome is recorded, unless an extended retention period has been requested by the customer in accordance with applicable agreements. In all cases, retention shall not exceed the maximum retention period established by Coridr's retention policy, except where required by law.
Audit logs and processing recordsRetained for as long as reasonably necessary to support security, accountability, dispute resolution, regulatory compliance, and audit purposes. Where such records contain personal data, they will be retained only for so long as necessary and in accordance with applicable law.
User account informationRetained for the duration of the customer relationship and thereafter for as long as necessary to comply with legal, regulatory, security, and audit requirements.
Authentication and security recordsRetained only for the period necessary to maintain account security and protect the Platform against fraud and unauthorised access.
Customer support recordsRetained for as long as reasonably necessary to manage support requests, improve our services, resolve disputes, and meet legal or regulatory obligations.
Technical and diagnostic logsRetained for security, troubleshooting, performance monitoring, and audit purposes and periodically reviewed for deletion or anonymisation where appropriate.

13. Security

13.1. We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.

These measures include, where appropriate:

Access Management

  • role-based access controls;
  • authentication and identity verification;
  • multi-factor authentication where applicable; and
  • least-privilege access principles.

Data Protection

  • encryption of personal data in transit and, where appropriate, at rest;
  • secure storage of personal data;
  • audit logging and activity monitoring; and
  • secure deletion and disposal procedures.

Platform Security

  • network and infrastructure security controls;
  • vulnerability management and security monitoring;
  • backup and recovery procedures; and
  • incident detection and response processes.

Operational Security

  • confidentiality obligations for personnel;
  • access restrictions for authorised personnel only; and
  • periodic review of security measures and access permissions.

13.2. While we take reasonable steps to safeguard personal data, no method of electronic transmission or storage is completely secure. Accordingly, we cannot guarantee the absolute security of information transmitted to or stored on the Platform.

14. Children

CORIDR is intended for use by educational providers, international education consultants, travel agencies, and other authorised organisations. It is not intended for direct use by children.

In providing our services, we may process personal data relating to applicants under the age of 18 where such data is submitted to the Platform by our customers for the purposes of reviewing and processing applications. In such cases, our customers are responsible for ensuring that they have an appropriate lawful basis for processing the personal data of children, including obtaining any parental or guardian consent where required by applicable law.

Where CORIDR processes personal data relating to children on behalf of its customers, we do so solely in accordance with their documented instructions and applicable law.

15. Cookies and Similar Technologies

Our website may use cookies and similar technologies to support essential website functionality, enhance user experience, improve security, and analyse website usage.

Where required by applicable law, we will obtain your consent before placing non-essential cookies on your device.

You can manage or disable cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of our website.

16. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our Platform, our data processing practices, or applicable legal and regulatory requirements.

Where we make material changes to this Privacy Policy, we will take reasonable steps to notify affected users through the Platform, our website, email, or other appropriate communication channels before the changes take effect, where required by applicable law.

The "Last Updated" at the beginning of this Privacy Policy indicates when it was last updated. Your continued use of the Platform after any changes become effective constitutes your acknowledgement of the updated Privacy Policy.

17. Contact Us

If you have any questions, requests, or complaints regarding this Privacy Policy or our processing of personal data, please contact us using the details below:

Email: hello@coridr.com

Questions about this document? Email hello@coridr.com.