6membership6membershipA 6clement Joshua service™Legal & Trust Center
Rights · Legal document

Country-Specific Privacy Rights Addendum

Detailed terms governing applications, membership relationships, payment review, benefits, conduct, verification and status.

Version 0.9-draftUpdated 6 August 202620 sections106 detailed clauses
Statusdraft
Effective dateNot yet effective
Change typeinitial publication
ReacceptanceNot required yet
Before you continue

Understanding this document

This Country-Specific Privacy Rights Addendum explains additional privacy rights that may apply because of a person’s country, state, province, territory or other jurisdiction.

It supplements the Privacy and Data Protection Notice. It does not replace the general explanations concerning information collection, lawful purposes, photographs, Flutterwave payment processing, disclosures, international transfers, security or retention.

6membership is a membership service operated by 6clement Joshua under the laws of the Federal Republic of Nigeria, with mandatory local privacy, consumer and statutory rights preserved where they apply.

Privacy laws do not apply identically to every visitor. A right described in one jurisdictional section applies only where the relevant law covers the person, 6membership and the processing activity.

A request may concern information held directly by 6membership or information processed through a listed provider. Where Flutterwave, a bank, card network or another organisation independently determines its own processing purposes, that organisation may need to address part of the request under its own legal responsibilities.

Nothing in this Addendum should be interpreted as voluntarily submitting every 6membership activity to every privacy law worldwide where that law would not otherwise apply.

Your location does not automatically determine every applicable law

Applicable rights may depend on residence, physical location, business thresholds, establishment, targeting, monitoring, processing purpose, information type and other legal factors. 6membership will assess each verified request under the laws that actually apply.

Scope

Who these Terms apply to

01

Applicants and members in Nigeria.

02

Persons in the European Union or European Economic Area where the GDPR applies.

03

Persons in the United Kingdom where UK data-protection law applies.

04

California residents where the California Consumer Privacy Act applies to 6membership and the relevant processing.

05

Persons protected by South Africa’s Protection of Personal Information Act.

06

Visitors in another jurisdiction that grants applicable privacy rights.

07

Parents, guardians and authorised representatives exercising rights for another person.

08

Persons challenging an automated or substantially automated decision where an applicable law grants that right.

09

Persons submitting access, correction, deletion, objection, portability, restriction or opt-out requests.

Jump toDocument sections
1

Relationship with the general Privacy Notice

How this jurisdictional Addendum fits into the wider privacy framework.

1.1

Supplementary document

This Addendum supplements the Privacy and Data Protection Notice.

The Privacy Notice explains what information may be collected, where it comes from, why it is processed, how it may be shared, how it is secured and how long it may be retained.

This Addendum focuses on rights and procedures that vary according to applicable law.

Related documents
Privacy and Data Protection Notice
1.2

Specific rights prevail where mandatory

Where an applicable law grants a mandatory right that is more specific or protective than the general Privacy Notice, that mandatory right will be preserved.

Where this Addendum provides a broader voluntary process than the law requires, 6membership may still apply reasonable identity, security, fraud-prevention and legal-retention controls.

1.3

No universal-law claim

A reference to a jurisdiction does not mean that its law governs every 6membership visitor or activity.

6membership will not represent that it is automatically subject to a law merely because a person can access the public website from that jurisdiction.

Jurisdiction, territorial scope and statutory thresholds will be assessed according to the relevant law.

1.4

Mandatory protections are not waived

A person does not waive a non-excludable privacy right by applying for membership, accepting the Membership Terms, paying a fee or using the website.

A consent checkbox will not be used to remove a right that applicable law makes mandatory.

2

General rights-request process

The procedure ordinarily used before applying the jurisdiction-specific rules.

2.1

Submitting a privacy request

A request should identify the person making it, the right being exercised and the relevant application, Flutterwave transaction, refund, chargeback or membership record where available.

The request should be submitted through the official privacy channel.

Where the request concerns a Flutterwave-held payment record, 6membership may use the transaction reference and its merchant records to locate the relevant processing and may direct or coordinate the request with Flutterwave where the provider acts independently.

The requester should not send passwords, complete payment-card details, banking credentials or unnecessary identity documents in the initial message.

2.2

Privacy Request Reference

6membership may generate a unique Privacy Request Reference to track the request.

The reference confirms that a request record exists. It does not by itself confirm identity, applicability of a particular law or the outcome of the request.

2.3

Acknowledgement and applicable period

6membership will acknowledge and respond to a valid request within the period required by the applicable law.

Different jurisdictions may use different acknowledgement, response and extension periods.

Where additional time is legally permitted because of complexity, volume or verification difficulty, the requester will be informed as required.

2.4

Clarification

Where a request is broad, unclear or relates to several independent records, 6membership may ask the requester to clarify its scope.

Clarification should be used to identify the requested information or action and not to obstruct a valid request.

2.5

Accessible request methods

Request methods should be reasonably accessible and appropriate to the way the person ordinarily interacts with 6membership.

Where applicable law requires more than one request method or a particular privacy link, 6membership will provide the required method when that law applies.

Related documents
Accessibility and Official Communications PolicyElectronic Communications Consent
3

Identity and authority verification

How 6membership protects records before disclosing, changing or deleting them.

3.1

Proportionate verification

Before disclosing, correcting, deleting, exporting or restricting protected information, 6membership may take reasonable steps to confirm the requester’s identity.

Verification should be proportionate to the sensitivity of the information and the risk of acting on an unauthorised request.

A request involving identity documents, payment records, a private membership tier or another person’s information may require stronger verification than a request concerning an ordinary email preference.

3.2

Use of existing information

Where reasonably possible, verification should use information already held by 6membership rather than collecting excessive new information.

The requester may be asked to confirm an Application Reference, Membership ID, registered email address, recent application activity or another record-specific fact.

3.3

Additional evidence

Additional identity or authority evidence may be requested where the ordinary details do not provide sufficient confidence.

Any new document should be limited to what is reasonably necessary and handled according to the Application, Identity and Photograph Policy.

Related documents
Application, Identity and Photograph Policy
3.4

Authorised representatives

A person may use an authorised representative where applicable law permits it.

6membership may request written authority, proof of guardianship, a power of attorney or another legally sufficient authorisation.

6membership may also contact the individual directly where permitted to confirm identity and the representative’s authority.

3.5

Younger applicants and guardians

A parent or guardian seeking to exercise rights for a younger applicant may be required to establish identity, relationship and legal authority.

The process should consider the younger person’s maturity, applicable law and whether the right can or should be exercised directly by the younger person.

Related documents
Eligibility, Age and Guardian Consent Policy
3.6

Unable to verify

Where 6membership cannot reasonably verify the requester, it may pause or deny the protected action to prevent unauthorised disclosure or destruction.

Where required, the requester will be informed of the reason and any available method for supplying additional evidence or challenging the decision.

4

Information and access rights

Rights to understand processing and receive relevant personal information.

4.1

Right to be informed

Where applicable, an individual has the right to receive clear information about the collection and use of personal information.

The information may include the operator’s identity, processing purposes, lawful basis, information categories, recipients, retention, international transfers, rights and complaint methods.

This information may be provided through the Privacy Notice, this Addendum, a form notice, a consent interface or another context-specific notice.

4.2

Right of access

Where applicable, an individual may request confirmation of whether 6membership processes personal information concerning them.

The individual may also request access to the information and legally required supplementary details.

The response may be delivered through a secure electronic copy, protected portal, structured export or another appropriate method.

4.3

Scope of an access response

An access response may include application details, contact information, consent records, membership status, Flutterwave transaction references, payment and refund statuses, chargeback records, communication history and other information within the applicable right.

6membership will not disclose or attempt to retrieve a complete card number, card security code, PIN, banking password or payment OTP that it does not hold as an ordinary membership record.

The response does not necessarily require disclosure of every internal document, system design, source code, legal privilege record, confidential fraud rule or information concerning another person.

4.4

Redaction and protection of others

Information may be redacted or withheld where disclosure would adversely affect another person’s rights, reveal protected legal advice, compromise security or violate another lawful restriction.

Where reasonably possible, 6membership will provide the remainder of the information rather than refusing the entire request.

4.5

Additional and repeated copies

The first copy may be provided without charge where applicable law requires it.

Where legally permitted, a reasonable fee may apply to additional, excessive or repeatedly duplicative copies.

5

Correction and completion

How inaccurate or incomplete personal information may be challenged.

5.1

Correction of inaccurate information

Where applicable, an individual may request correction of personal information that is inaccurate.

A request should identify the disputed field, the proposed correction and supporting evidence where reasonably necessary.

5.2

Completion of incomplete information

An individual may request that materially incomplete information be completed where the applicable law grants that right.

Completion may be achieved by adding a supplementary statement where replacing the original historical record would make the record misleading.

5.3

Historical accuracy

A record that accurately reflects what was submitted or decided at an earlier time will not necessarily be rewritten merely because circumstances later changed.

6membership may preserve the original historical entry and add the corrected or updated information with a timestamp and audit record.

Example

If a member changes their registered address, the current address may be updated while the previous address remains in a restricted historical record where required for payment, verification or legal purposes.

5.4

Disputed accuracy

Where the accuracy of information is contested and cannot immediately be resolved, 6membership may restrict the disputed use or attach a note explaining that the information is challenged.

The response may explain the evidence relied upon and any available appeal or complaint process.

5.5

Notification to recipients

Where applicable and reasonably practicable, 6membership may notify relevant recipients of a completed correction.

The individual may be informed about those recipients where the applicable law requires it.

6

Deletion and erasure

When an individual may request removal and when records may lawfully remain.

6.1

Requesting deletion

Where applicable, an individual may request deletion or erasure of personal information.

The request should identify the relevant application, membership, communication or other processing activity where possible.

6.2

Possible deletion grounds

Deletion may be available where information is no longer necessary, consent has been withdrawn and no other lawful basis applies, processing was unlawful, a valid objection prevails or deletion is otherwise required by applicable law.

6.3

Records that may remain

Deletion is not absolute.

Information may remain where reasonably necessary for legal compliance, payment and accounting records, fraud prevention, security, defence of claims, complaint handling, regulatory cooperation, public-interest functions or another lawful exception.

6membership may also retain a minimal suppression record to ensure that deleted information is not unintentionally reintroduced or used for a prohibited purpose.

6.4

Effect on an application or membership

Deleting information required to review an application, verify payment, issue a membership card or maintain membership status may make the relevant service impossible to continue.

Where no other lawful basis supports the necessary processing, the application may be cancelled or the membership relationship may need to end.

The requester will be informed of this consequence before deletion where reasonably possible and legally appropriate.

6.5

Backups and delayed deletion

Deletion from active systems may not immediately remove encrypted backup copies.

Backup copies may remain unavailable for ordinary use until they are overwritten or expire under controlled backup schedules.

Where a backup is restored, applicable deletion or suppression instructions should be reapplied.

6.6

Third-party recipients

Where required and reasonably practicable, relevant processors or recipients may be instructed to delete or restrict the affected information.

Flutterwave, a participating bank, card network or another independent controller may be required to assess part of the request under its own legal responsibilities.

Deletion from 6membership systems does not automatically require deletion of transaction, settlement, chargeback, fraud-prevention, tax or regulatory records that Flutterwave or a financial institution must lawfully retain.

Related documents
Data Retention, Deletion and Records PolicyThird-Party Service Providers List
7

Restriction and objection

Rights to pause or challenge particular processing activities.

7.1

Restriction of processing

Where applicable, an individual may request restriction of processing while accuracy, lawfulness, an objection or another qualifying issue is assessed.

Restricted information may remain stored while ordinary use, disclosure or alteration is limited.

7.2

Permitted use during restriction

Restricted information may still be processed with the individual’s consent or where necessary for legal claims, protection of another person, important public interests or another legally permitted ground.

7.3

Objection to interest-based processing

Where applicable, an individual may object to processing based on legitimate interests, public-interest tasks or comparable lawful grounds.

The objection should explain the person’s particular situation where the law requires that explanation.

6membership may continue only where it demonstrates a legally sufficient overriding ground or the processing is required for legal claims or another applicable exception.

7.4

Objection to direct marketing

Where applicable, an individual may object to processing for direct marketing.

Once a valid objection applies, personal information will no longer be used for the covered direct-marketing purpose.

Necessary application, payment, membership, security and policy communications are not automatically treated as optional marketing.

7.5

Lifting a restriction

Where applicable, the individual will be informed before a restriction is lifted and ordinary processing resumes.

Related documents
Electronic Communications ConsentPrivacy and Data Protection Notice
8

Data portability

Receiving certain information in a structured and reusable format.

8.1

When portability may apply

Where applicable, an individual may request certain personal information in a structured, commonly used and machine-readable format.

The right ordinarily concerns information provided by the individual and processed through automated means on the basis specified by the applicable law.

8.2

Export format

An export may use JSON, CSV, PDF combined with structured files or another reasonably interoperable format appropriate to the information.

The format will be selected to balance usability, security, context and protection of third-party information.

8.3

Direct transfer

Where applicable law grants the right and the transfer is technically feasible, an individual may request transfer directly to another controller.

6membership may require confirmation of the destination and use secure transfer methods.

8.4

Limitations

Portability does not require disclosure of internal fraud models, proprietary analysis, another person’s information or information outside the right’s legal scope.

Receiving a portable copy does not automatically delete the original information.

9

Consent and withdrawal

Rights applying where processing depends on consent.

9.1

Voluntary and specific consent

Where consent is relied upon, it should be freely given, specific, informed and expressed through an appropriate affirmative action.

Consent for one purpose does not automatically authorise another unrelated purpose.

9.2

Withdrawing consent

An individual may withdraw consent where processing relies on consent.

Withdrawal should be reasonably accessible and should not require substantially greater effort than giving consent.

9.3

Processing before withdrawal

Withdrawal does not make processing that occurred lawfully before withdrawal unlawful.

Information may also remain where another lawful basis independently requires or permits retention.

9.4

Effect on optional and necessary functions

Withdrawing consent may end an optional feature that depends on that consent.

It will not automatically stop processing necessary for payment records, fraud prevention, legal obligations or another independent lawful basis.

9.5

Separate consent choices

Cookie consent, optional marketing consent, photograph-publication permission and another optional permission are separate choices unless the relevant notice clearly and lawfully combines them.

Related documents
Cookie and Tracking Technologies PolicyApplication, Identity and Photograph PolicyElectronic Communications Consent
10

Automated decisions and profiling

Protections concerning decisions made or materially supported by automated systems.

10.1

Automated screening tools

6membership may use technical tools to identify duplicate submissions, invalid formats, security threats, suspicious transactions, blocked devices or records requiring manual review.

A technical flag does not automatically establish fraud, ineligibility or wrongdoing.

10.2

Legally or similarly significant decisions

Where applicable law restricts solely automated decisions producing legal or similarly significant effects, 6membership will apply the required safeguards.

A final approval, denial, suspension or revocation should not be based solely on an undisclosed automated result where meaningful human review is legally required.

10.3

Information about automated processing

Where applicable, an individual may request information about the use of qualifying automated decision-making, the relevant logic or factors and the significance or expected consequences.

The response may protect source code, confidential security controls, trade secrets and information concerning other persons while still providing meaningful information.

10.4

Human review and challenge

Where the applicable law provides the right, an individual may request human review, submit relevant information, express their position and challenge materially inaccurate inputs or an improper result.

10.5

Opt-out rights

Where an applicable jurisdiction grants a right to opt out of specified automated decision-making or profiling, 6membership will provide the legally required method when the covered processing is used.

This clause does not state that 6membership currently operates every form of automated decision-making described by privacy laws.

No secret membership-worthiness score

The current policy framework does not authorise an undisclosed automated score to make final membership decisions without required safeguards and human review.

11

Nigeria

Rights under the Nigeria Data Protection Act and applicable NDPC instruments.

11.1

Application of the Nigerian framework

The Nigeria Data Protection Act 2023 forms the primary privacy framework for 6membership’s Nigerian operations.

The Nigeria Data Protection Act General Application and Implementation Directive 2025, together with applicable regulations, directives, guidance and binding decisions of the Nigeria Data Protection Commission, may further affect how rights are administered.

Rights described in this section are subject to the conditions, procedures and lawful limitations in the applicable Nigerian framework.

11.2

Information and access

A Nigerian data subject may have the right to receive information about processing and to obtain confirmation and access to relevant personal data.

The response may include processing purposes, categories, recipients, retention, international transfers, available rights and other information required by the applicable framework.

Where the request concerns a Flutterwave transaction, the response may include the payment information held by 6membership and an explanation of any provider-held information that must be requested from Flutterwave or another independent financial participant.

11.3

Correction and erasure

A data subject may request correction of inaccurate or incomplete personal data.

A right to erasure may apply where the statutory conditions are satisfied, subject to lawful exceptions and retention obligations.

11.4

Objection and restriction

A data subject may have rights to object to qualifying processing and request restriction in circumstances recognised by Nigerian law.

Direct-marketing objections will be applied to the covered marketing processing.

11.5

Data portability

Where the statutory conditions are satisfied, a data subject may request qualifying data in a structured, commonly used and machine-readable format and may request transmission where technically feasible.

11.6

Automated-decision protections

A data subject may have protections against qualifying solely automated decisions and may be entitled to safeguards such as human intervention, an opportunity to express a view and a method to contest the decision.

11.7

Complaint to the Nigeria Data Protection Commission

A data subject may submit a complaint to the Nigeria Data Protection Commission where the Nigerian framework grants that right.

Using 6membership’s internal privacy process first may help resolve an issue, but it does not remove a mandatory regulatory complaint right.

11.8

Remedies and enforcement

Applicable Nigerian law may provide regulatory, administrative or judicial remedies.

Nothing in this Addendum restricts the lawful authority of the Commission or a court of competent jurisdiction.

12

European Union and European Economic Area

Rights where the EU General Data Protection Regulation applies.

12.1

Territorial application

This section applies only where the EU General Data Protection Regulation applies to the relevant processing.

Website accessibility from the EU or EEA does not by itself determine every territorial-scope question.

12.2

Principal GDPR rights

Subject to the applicable conditions and exceptions, an individual may have rights to information, access, rectification, erasure, restriction, portability and objection.

The individual may also have rights concerning consent and qualifying automated decision-making.

12.3

Response period

A valid request will be handled within the period required by the GDPR.

Where the GDPR permits additional time because of complexity or request volume, the individual will receive the required extension notice.

12.4

Supervisory-authority complaint

Where the GDPR applies, an individual may lodge a complaint with an applicable EU or EEA supervisory authority.

The appropriate authority may depend on habitual residence, place of work, the alleged infringement or another jurisdictional factor.

12.5

International-transfer information

Where applicable, an individual may request information about relevant safeguards used for transfers outside the EU or EEA.

12.6

EU representative

Where the GDPR requires 6membership to appoint an EU representative, the representative’s contact details will be published before or when that obligation applies.

This draft does not falsely identify a representative who has not yet been appointed.

13

United Kingdom

Rights where the UK GDPR, Data Protection Act 2018 and Data (Use and Access) Act 2025 amendments apply.

13.1

Application of UK law

This section applies only where United Kingdom data-protection law covers the relevant person, organisation and processing activity.

The applicable framework includes the UK GDPR and Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025 and relevant commencement instruments.

13.2

Principal UK rights

Subject to applicable conditions and exceptions, an individual may have rights to be informed, access, rectification, erasure, restriction, portability and objection.

An individual may also have rights concerning consent and qualifying automated decisions under the UK framework as amended.

The safeguards and scope for automated decision-making may differ from the EU GDPR and must be assessed under the current UK legislation rather than assumed to be identical.

13.3

Response timing

A valid UK request will be handled within the period required by applicable UK law.

Any permitted extension will be communicated as required.

13.4

Information Commissioner’s Office

Where UK law applies, an individual may have the right to complain to the United Kingdom Information Commissioner’s Office.

An internal complaint may be submitted first but does not remove a mandatory right to contact the regulator.

13.5

UK representative

Where UK law requires appointment of a United Kingdom representative, the representative’s contact information will be published when the obligation applies.

14

California

Rights for California residents where the CCPA applies to 6membership.

14.1

CCPA applicability

This section applies only where the California Consumer Privacy Act covers 6membership and the relevant processing.

The inclusion of this section does not state that 6membership currently satisfies every statutory threshold that determines whether a business is subject to the CCPA.

14.2

Right to know

Where applicable, a California consumer may request information about categories and specific pieces of personal information collected, sources, purposes and relevant disclosures, sales or sharing.

14.3

Deletion and correction

Where applicable, a California consumer may request deletion of covered personal information and correction of inaccurate personal information.

Statutory exceptions may allow or require particular information to remain.

14.4

Opt out of sale or sharing

6membership does not intend to sell applicant or member information for money.

Where 6membership engages in an activity legally defined as sale or sharing under the CCPA, covered consumers will receive the required notice and opt-out method.

A recognised opt-out preference signal will be processed where and when California law requires it.

14.5

Limiting sensitive personal information

Where 6membership uses or discloses sensitive personal information beyond legally permitted purposes and the CCPA right applies, a California consumer may request that the use or disclosure be limited.

A limitation right does not prevent uses permitted by the statute and regulations for specified necessary purposes.

14.6

Automated decision-making technology

Where current California requirements apply to a qualifying use of automated decision-making technology, a consumer may receive required pre-use information and applicable access or opt-out rights.

6membership will not display an automated-decision opt-out merely to suggest that qualifying technology is used when it is not.

14.7

No unlawful discrimination

6membership will not unlawfully discriminate against a covered California consumer for exercising a CCPA right.

A feature may nevertheless be unavailable where the requested deletion or limitation makes that feature impossible and applicable law permits the resulting difference.

14.8

Authorised agents

A California consumer may use an authorised agent where the CCPA permits it.

6membership may request legally permitted evidence of the agent’s authority and may verify the consumer directly where allowed.

14.9

Complaints

A covered consumer may contact the California Privacy Protection Agency or another competent authority where California law provides that right.

15

South Africa

Rights where the Protection of Personal Information Act applies.

15.1

Application of POPIA

This section applies where South Africa’s Protection of Personal Information Act covers the relevant processing.

6membership may be regarded as a responsible party for covered processing where it determines the purpose and means of that processing.

15.2

Notification and access

A data subject may have rights to receive information about processing and request confirmation and access to personal information.

Access may be subject to identity verification, applicable procedures, lawful grounds of refusal and permitted fees.

15.3

Correction, deletion or destruction

A data subject may request correction or deletion of personal information that is inaccurate, irrelevant, excessive, outdated, incomplete, misleading or unlawfully obtained.

A request may also concern destruction or deletion where 6membership is no longer authorised to retain the information.

15.4

Objection to processing

Where POPIA permits it, a data subject may object on reasonable grounds relating to their particular situation.

A valid objection will be assessed against any lawful justification for continuing the processing.

15.5

Direct-marketing objection

A person may object to covered direct marketing and use applicable opt-out mechanisms.

Necessary membership, security, payment and legal notices are not automatically treated as unsolicited direct marketing.

15.6

Information Regulator complaint

Where POPIA applies, a data subject may submit a complaint to South Africa’s Information Regulator using the applicable procedure.

16

Other countries, states and territories

How rights outside the specifically listed jurisdictions are handled.

16.1

Individual assessment

A person in another jurisdiction may have rights under a national, state, provincial or territorial privacy law.

6membership will assess a verified request according to the law applicable to the person, the service and the relevant processing.

16.2

Comparable voluntary handling

Where no specific statutory right applies, 6membership may still consider a reasonable request for access, correction, deletion or preference changes.

Voluntary handling remains subject to identity verification, security, fraud prevention, legal retention and protection of other persons.

16.3

No reduction of stronger rights

This section does not replace or reduce a stronger mandatory right granted by an applicable law.

16.4

Future jurisdictional sections

6membership may add a dedicated jurisdictional section where operations, applicant volume or legal obligations make that section appropriate.

Material additions will be managed through the policy-update framework.

Related documents
Policy Updates, Effective Dates and Change Log
17

Limitations, refusals and excessive requests

When a request may be restricted and how the decision is communicated.

17.1

Lawful exceptions

A privacy right may be limited where the applicable law contains an exception.

Possible grounds may concern legal obligations, fraud prevention, security, another person’s rights, legal privilege, regulatory functions, public interests, research, records required for claims or another recognised exception.

17.2

Manifestly unfounded or excessive requests

Where the applicable law permits it, 6membership may charge a reasonable fee or refuse a request that is manifestly unfounded, excessive or repeatedly duplicative.

The burden of establishing the permitted ground remains with 6membership where the law places that burden on the controller.

17.3

Security and fraud restrictions

6membership will not disclose credentials, authentication secrets, protected security configurations or confidential fraud methods through an access request.

A requester may still receive meaningful information about personal data and a decision without receiving material that would enable abuse.

17.4

Rights of other persons

A response may be redacted where disclosure would reveal another person’s private information or adversely affect their rights and freedoms.

17.5

Decision notice

Where a request is refused or limited, the response will provide the information required by the applicable law.

This may include the reason, applicable exception and available complaint or appeal route.

18

Complaints, appeals and regulatory remedies

How a person may challenge the handling of a privacy request.

18.1

Internal privacy complaint

A person may ask 6membership to review the handling or outcome of a privacy request.

The complaint should identify the Privacy Request Reference, disputed action and reason the person believes the response is incorrect.

18.2

Independent internal review

Where reasonably possible, a complaint should be reviewed by a person who was not solely responsible for the original disputed decision.

18.3

Regulatory complaint

A person may contact an applicable privacy or data-protection regulator where the relevant law provides that right.

6membership will not state that an internal complaint is mandatory where applicable law allows the person to approach the regulator directly.

18.4

Judicial and other remedies

Applicable law may provide access to courts, tribunals, administrative remedies, compensation or another enforcement procedure.

Nothing in this Addendum removes a remedy that cannot lawfully be excluded.

Related documents
Complaints, Appeals and Dispute Resolution PolicyLaw-Enforcement, Regulatory and Government Requests Policy
19

Request records and accountability

Records maintained to demonstrate fair and secure handling of rights requests.

19.1

Privacy-request records

6membership may retain the request, Privacy Request Reference, requester details, verification steps, correspondence, decision, legal basis, completion date and relevant audit events.

19.2

Record minimisation

Request records should contain enough information to demonstrate proper handling without unnecessarily duplicating identity documents or unrelated private information.

19.3

Retention

Privacy-request records may be retained for accountability, dispute handling, regulatory compliance, security and legal claims.

The applicable period depends on legal requirements, limitation periods, request type and associated risk.

Related documents
Data Retention, Deletion and Records Policy
19.4

Administrative audit trail

Material administrative actions may be logged to identify who accessed, exported, corrected, restricted or deleted a protected record.

Audit records should not be alterable by an ordinary applicant or member.

20

Updates and official contact channels

How jurisdictional changes are published and where requests are sent.

20.1

Changes in applicable law

Privacy laws, regulations, regulatory guidance and territorial-scope interpretations may change.

6membership may update this Addendum to reflect new rights, request methods, response obligations or jurisdictional requirements.

20.2

Material notices

A material change affecting existing rights or processing may be communicated through the website, application flow, membership portal or registered email address where appropriate.

20.3

No unlawful retrospective reduction

A policy update will not be used to retrospectively remove a mandatory right or validate processing that was unlawful when it occurred.

20.4

Official privacy channel

Privacy requests should be submitted to privacy@6membership.com.

Formal legal and regulatory correspondence may be sent to legal@6membership.com.

The requester should retain the Privacy Request Reference and relevant correspondence.

20.5

Policy-update framework

Version numbers, effective dates, change notices and renewed-acceptance requirements are governed by the Policy Updates, Effective Dates and Change Log.

Related documents
Policy Updates, Effective Dates and Change LogElectronic Communications Consent
Cross-reference

Related policies

Privacy and Data Protection Notice

Explains the wider collection, use, disclosure and protection of personal information.

Cookie and Tracking Technologies Policy

Explains browser technologies, consent and privacy preference signals.

Application, Identity and Photograph Policy

Explains identity verification for protected requests.

Data Retention, Deletion and Records Policy

Explains deletion exceptions, backups and legal holds.

Security, Account Access and Incident Response Policy

Explains safeguards protecting rights-request records.

Third-Party Service Providers List

Identifies Flutterwave and other providers that may hold relevant information or independently handle part of a request.

Complaints, Appeals and Dispute Resolution Policy

Explains challenges, escalations and formal complaint procedures.

Law-Enforcement, Regulatory and Government Requests Policy

Explains regulatory disclosures and preservation requirements.

Electronic Communications Consent

Explains electronic notices and request communications.

Policy Updates, Effective Dates and Change Log

Explains future jurisdictional and rights changes.

Official channels

Contact points

Privacy rights requestsprivacy@6membership.com

Access, correction, deletion, restriction, objection, portability, opt-out and consent-withdrawal requests.

Privacy complaintsprivacy@6membership.com

Complaints concerning the handling or outcome of a privacy request.

Security reportssecurity@6membership.com

Suspected unauthorised access, disclosure or account compromise.

Legal and regulatory correspondencelegal@6membership.com

Formal notices from regulators, courts and authorised legal representatives.

6membershipA 6clement Joshua service™

© 2026 6clement Joshua. All rights reserved.