Legal

Privacy Policy

Last updated: 1 July 2026

1. Who We Are

MJN Health Academy and Professional Services (“MJN,” “we,” “us”) is a healthcare career consulting agency registered in Cameroon. We provide international healthcare licensing support, exam preparation, staffing placement, and related professional services.

Data controller contact: privacy@mjnhealthcare.com

2. What Data We Collect

We collect the following categories of personal data:

  • Identity data: Name, date of birth, nationality, passport details
  • Contact data: Email address, phone number, WhatsApp number, postal address
  • Professional data: Nursing/medical degree, registration numbers, clinical experience, employer history
  • Document data: Copies of passports, degree certificates, transcripts, licences, and other credential documents uploaded to our platform
  • Financial data: Payment records (we do not store card details — these are held by our payment processors)
  • Usage data: How you use our website and portal, including IP address, browser type, pages visited
  • Communications data: Email, WhatsApp, and chat correspondence with our team

3. Why We Collect Your Data

We collect and use your data to:

  • Provide licensing, placement, and consulting services under your signed engagement
  • Submit applications to regulatory bodies and employers on your behalf (where you have authorised us via Letter of Authorization)
  • Process payments and issue receipts
  • Communicate with you about your case status, document requirements, and service updates
  • Deliver Academy content, study plans, and exam preparation
  • Meet our legal and compliance obligations (Cameroon data protection law; UK and Irish GDPR obligations where applicable)
  • Send marketing communications (where you have opted in — you can opt out at any time)

4. Legal Basis for Processing

  • Contract performance: Processing necessary to deliver your signed engagement
  • Legitimate interests: Fraud prevention, platform security, improving our services
  • Consent: Marketing communications, AI-assisted features (where applicable)
  • Legal obligation: Compliance with applicable law and regulatory body requirements

5. Who We Share Your Data With

We share personal data only when necessary:

  • Regulatory bodies: DHA, MOH, DOH, NMC, NMBI, CGFNS, and other authorities — solely when you have signed a Letter of Authorization
  • Employers: Partner hospitals and clinics — only with your explicit consent for each introduction
  • Service providers: Cloudflare (file storage), Brevo (email), Africa's Talking (SMS), Twilio (WhatsApp), Neon (database), Dropbox Sign (e-signature), Tranzak/Paystack (payments), Daily.co (live classes), Anthropic (AI features)
  • Legal advisors: Where required for dispute resolution or compliance

We do not sell your personal data to third parties.

6. Cross-Border Data Transfers

Your data is processed and stored on servers located in the United States and European Union (Neon PostgreSQL, Cloudflare R2). Cross-border transfers are made under standard contractual clauses or equivalent safeguards. Given that your engagement involves submission to regulatory bodies in the UAE, UK, US, and Ireland, your credential data will necessarily be transferred to those jurisdictions as part of the service.

7. Data Retention

  • Active engagement data: Retained for the duration of the engagement plus 5 years (for legal and audit purposes)
  • Credential documents: Deleted on request after engagement closure, unless retention is required by law
  • Financial records: Retained for 7 years (tax and audit requirements)
  • Marketing data: Retained until you unsubscribe or request deletion

8. Your Rights

Depending on your jurisdiction, you have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Request deletion of your data (subject to retention obligations)
  • Object to processing based on legitimate interests
  • Withdraw consent where processing is based on consent
  • Data portability (receive your data in a portable format)
  • Lodge a complaint with your local data protection authority

To exercise any of these rights, email privacy@mjnhealthcare.com. We will respond within 30 days.

9. Security

Credential documents are encrypted at rest and in transit (Cloudflare R2 encryption). Access to your data is role-based — only your assigned consultant and relevant operations staff can access your case. All document access is audit-logged. We conduct regular security reviews.

10. Changes to This Policy

We may update this policy. Material changes will be notified by email or prominent notice on the platform. Continued use of our services after the effective date constitutes acceptance of the revised policy.

11. Contact

Data protection enquiries: privacy@mjnhealthcare.com

General contact: Contact page