Overview
WAI Group ("we", "our", or "us") is a private membership network for senior women investment professionals working across African markets, operated by Lelapa S.A.S.U. We support our community through curated convenings, member directories, research, and shared initiatives.
Because we handle personal information, including professional details, member directory data, and payment information, we are committed to the highest standards of data protection. This Privacy Policy explains what data we collect, why we collect it, how it is used, and your rights under applicable law including the General Data Protection Regulation (GDPR).
GDPR Compliance. WAI Group is fully compliant with the EU General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. Your data is processed lawfully, fairly, and transparently.
Data We Collect
We collect only the information necessary to operate the network and deliver our services. The categories of data we collect include:
- Contact and identity data - your name, email address, phone number, and professional title.
- Application data - information you submit during the membership application, including organisation, investment focus, and references.
- Member directory data - biography, photo, and the professional details you choose to share with other members.
- Payment data - billing details required to process membership fees. Card numbers are handled by our PCI-DSS compliant payment partner and are never stored on our servers.
- Usage data - how you interact with our website and member portal, including pages visited and events attended.
We do not collect more data than is strictly necessary for the purpose for which it was obtained. Full payment card numbers are never stored on our servers - all payment processing is handled by our PCI-DSS compliant payment partner.
How We Use Your Data
Your personal data is used exclusively to deliver and improve our services. The legal bases for processing under GDPR are noted in brackets.
- To review your membership application and confirm fit against our eligibility criteria [Contract Performance]
- To administer your membership, send communications, and provide access to the member directory and platform [Contract Performance]
- To process payments and issue receipts for membership fees and event registrations [Contract Performance]
- To organise convenings, events, and city circles, and to keep you informed about them [Contract Performance]
- To verify your identity and prevent fraudulent applications [Legitimate Interest]
- To comply with legal obligations, including tax and record-keeping requirements [Legal Obligation]
- To improve our platform through aggregated, anonymised usage analytics [Legitimate Interest]
- To send occasional service-related announcements or updates [Legitimate Interest / Consent]
No Marketing Without Consent. We will never send you promotional marketing emails without your explicit consent. You can manage your email preferences at any time from your member dashboard.
Data Sharing & Disclosure
We do not sell, rent, or trade your personal data to third parties. We only share your data in the following limited circumstances:
- Other members - your member directory profile is shared with other approved WAI members in accordance with the visibility settings you choose.
- Stripe (payment processing) - securely processes membership and event payments. Stripe is PCI-DSS Level 1 certified.
- Sendgrid (transactional email) - delivers magic links and member notifications. Only your email address is shared.
- Cloudflare (infrastructure) - provides CDN and DDoS protection. Processes IP address data.
- Legal or regulatory authorities - if required by applicable law, court order, or to protect the rights and safety of WAI Group and its members.
All third-party data processors are bound by data processing agreements and are required to handle your data in accordance with GDPR and this Privacy Policy.
Data Security
Protecting your information is our highest priority. We implement the following security measures:
- AES-256 encryption for all data at rest, including member directory profiles and uploaded documents
- TLS 1.3 encryption for all data in transit between your browser and our servers
- Passwordless authentication - we use magic links and OAuth only, eliminating password breach risks
- Multi-factor authentication for all internal team access to production systems
- Regular third-party penetration testing and security audits
- Access controls ensuring only authorised personnel can access member data, on a need-to-know basis
- Automatic session expiry and magic link expiration after 15 minutes
Encryption at Every Step. Your member data is encrypted both in transit and at rest. We follow OWASP Top 10 security guidelines and conduct quarterly security reviews.
Data Retention
We retain your personal data only for as long as necessary to provide our services and comply with our legal obligations.
- Member profile and directory data: retained for the duration of your active membership and for 24 months after membership ends, then securely deleted
- Application records (declined): retained for 12 months and then anonymised
- Payment records: retained for 7 years as required by financial regulations
- Account data: retained while your account is active; deleted within 90 days of an account closure request
- Server logs: retained for 90 days for security and debugging purposes, then automatically purged
You may request early deletion of your data at any time (see Contact Us below), subject to our legal obligations to retain certain records.
International Transfers
Because WAI Group operates across Africa, Europe, and other regions, your personal data may be transferred to and processed in countries outside your country of residence. Where we transfer data outside the European Economic Area, we rely on appropriate safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission, signed with all relevant data processors
- Adequacy decisions where the destination country has been recognised as providing equivalent data protection
- Encryption and pseudonymisation of data in transit and at rest, regardless of where it is processed
You can request a copy of the safeguards we have in place by contacting us at the address below.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service offerings. When we make significant changes, we will notify you via email (to the address associated with your membership) and update the "Last Updated" date at the top of this page. We encourage you to review this policy periodically.
Your continued use of WAI Group services after changes are published constitutes acceptance of the updated policy.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at hello@waigroup.com.