Alphalock™
Privacy policy
Last updated 12/09/2026.
Boardmarks™ is a training platform operated by Alphalock Ltd ("Alphalock", "we", "us"), a company registered in Nigeria. Organisations use it to give their learners access to courses, and some also have courses of their own on it. This policy explains what personal data the platform collects, why, and what you can do about it. It applies to everyone who uses Boardmarks, whether you were assigned a course by your employer or signed up directly. If an employer or another organisation assigned you a course, its administrators can see some of your data, as described below.
What we collect
Account and enrolment data: your name and email address, whether provided by you directly or by your employer/organisation when they enrol you in a course.
Course activity: which lessons you have viewed, exam answers and scores, and completion status. This is what makes a completion record meaningful.
Payment records: if you pay for a course directly, payment is handled entirely by Paystack. We never receive or store your card details, only confirmation that a payment succeeded, its amount, and a transaction reference.
Administrative action logs: the platform keeps a record of administrative actions (invitations sent, records reset, organisation settings changed, data requests updated) for audit purposes, whether an organisation's own administrators or Alphalock staff take them. An organisation's administrators can read the entries recorded against their own organisation.
Points and badges: if you complete courses, we record points earned and badges awarded against your email, and any reward you redeem points for. Unlike a completion record, this is not a permanent record: when Alphalock deletes your account on request, your points, badges and reward redemptions are deleted with it.
What we do not do
We do not run advertising, do not sell personal data, and do not use third-party tracking or analytics cookies. The platform sets three cookies in total: the one that keeps you signed in, one that remembers a dark mode preference if you choose it, and one that holds a colour so a customer's own pages load in their brand colour. Each is listed, with what it does and how long it lasts, in our cookie policy.
Who else sees it
We use the following providers to run the service. None of them is authorised to use your data for their own purposes. The list matches the one we give to customers in our security documentation, so that what you are told and what a procurement team is told are the same list.
- Supabase holds our database, our stored files, and your sign-in account, and sends the one-time codes you receive by email.
- Vercel hosts the application, so every request you make reaches the service through them. Their analytics and performance tools record aggregate page metrics, not individual browsing histories.
- Resend delivers the emails we send about setting up an organisation, which carry the recipient name and address. It also delivers the email telling an Alphalock administrator that a support report or data request has been assigned to them, which carries the sender's name, email address and message, and the email telling the sender that it has been resolved.
- Cloudflare runs the challenge on our sign-in page that tells a person apart from a script, and receives the request details needed to do that.
- Paystack processes payments for paid courses. Card details go to Paystack directly and never pass through Boardmarks.
- Google and LinkedIn confirm who you are if you choose to sign in with one of those accounts rather than by email code.
- Mux and Cloudflare Stream deliver course video where a course contains any. No course does today.
- Sentry receives a report when something goes wrong in the service or in your browser, so that we can fix it. A report holds the error, the address of the page or request it happened on, and the type of browser in use. Email addresses, sign-in tokens, cookies and anything typed into a form are removed from a report or never collected.
If your course was assigned by an employer or another organisation, that organisation's administrators can see your name, email, and progress on courses they assigned you, which is inherent to how employer-assigned training works. If your account belongs to that organisation and no other, its administrators can also see any request you send about your data from Your data, including anything you write in it, and can change its status and add notes to it. Where that organisation has connected its own systems to Boardmarks, completion events are sent to the address it configured.
Verification records
When you complete a course, we create a public verification record, reachable only by someone who already has its record ID or, where the course issues a certificate, the certificate number printed on it. It shows your name, the course title, code and version, the date that version took effect, the date the record was issued, that you passed, the record ID, and the certificate number where there is one. It also names the record's issuer, the course's publisher as recorded on the record: Alphalock Ltd for a course of its own, or the organisation that owned the course when the record was issued. This exists specifically so a third party (an employer checking a certificate, an auditor) can confirm a record is genuine. It never shows your email address or your score.
How long we keep it
Completion records and administrative audit logs are kept permanently and cannot be edited or deleted, by design. This is what makes a completion record trustworthy for compliance and audit purposes; a record that could quietly be altered or removed later would not be worth much as proof of anything. Other account data is kept for as long as your account is active, or as long as your organisation's contract requires.
Your rights
Under Nigeria's Data Protection Act, you can ask to see the personal data held about you, ask for inaccurate data to be corrected, object to certain uses of it, or ask for your account to be deleted. If you are signed in, Your data lets you download straight away a copy of your account's email address and organisation memberships, and your enrolments, completion records, payments, points, badges and reward redemptions. It also lets you send any of these requests. Sending a request records it, and nothing in it is carried out automatically, so it is not instant. What an organisation's administrators can see of a request is set out under Who else sees it, above. Alphalock's administrators can see requests too, and the one a request is assigned to, where there is one, is sent its details by email.
Only Alphalock can delete a sign-in account. When it does so on request, the account's organisation memberships, unfinished enrolments, points, badges, reward redemptions and playlists are deleted with it. Completion records, completed enrolments, payment records and audit logs are kept as a permanent record. A support report or data request filed under that email address is not deleted: its subject and message are overwritten with "[erased]", the name and email address on it are replaced, and any screenshot, page address, notes and link to the account or an enrolment are removed. The rest of that record, such as its date and the course it concerned, remains. A record of a voucher redeemed with that email address also remains, with the email address on it replaced. You can also use the contact details below instead.
Changes to this policy
If this policy changes in a way that affects how we handle your data, we will update the date at the top of this page.
Contact
Questions about this policy, or about how the Boardmarks platform handles personal data: contact@alphalockltd.com. If an employer or another organisation gave you access to Boardmarks, you may also take a question or request about your data to that organisation.
