Privacy & Data Protection Policy
How we collect, store, process, and safeguard personal information of students (minors), educators, and schools under the Uganda Data Protection and Privacy Act, 2019.
1. Scope & Legal Framework
This Privacy & Data Protection Policy applies to all personal data collected and processed by Matigo Examinations Board through `matigoexams.org`. Our data processing practices strictly comply with:
- The Data Protection and Privacy Act, 2019 (Republic of Uganda)
- National Information Technology Authority - Uganda (NITA-U) Data Protection Regulations
- International standards for minor data handling and educational record protection
2. Data Controller vs. Data Processor Roles
The participating educational institution collects student records, verifies parental consent, and directs which assessments candidates take.
We process candidate data on the documented instructions of the School pursuant to our Data Processing Agreement (DPA).
3. Categories of Personal Data We Process
A. Student / Candidate Records (Minors)
Uploaded by school administrators via spreadsheet import, UNEB register PDF, or manual entry:
- Candidate Legal Full Name
- Student ID / UNEB Candidate Index Number
- Education Level (PLE, UCE, UACE)
- Gender / Sex and Age (where present in official registers)
- Stream / Class Division
- Subject Combinations, Paper Mark Scores, Aggregates, and Final Grades
B. School Administrator & Educator Accounts
- School Name, UNEB Center Number, District Location
- Administrator Name, Official Email Address, Phone Number, Recovery Email
- Securely hashed account credentials (never stored in plaintext)
C. Scorers & Examiners
- Teacher Name, Telephone, Personal Email, School of Contact
- Subject Competency, Paper Codes, Teaching Experience, Registration Number
- Marking audit logs and assessment completion timestamps
4. Lawful Bases for Processing
- Contractual Necessity: To coordinate mock exams, process marks, calculate grades, and generate school result slips.
- Institutional Mandate & Parental Consent: Schools submit candidate information based on lawful educational mandate or parental consent.
- Legitimate Educational Interest: Standardizing assessment rubrics, error detection, and academic analytics.
- Explicit Consent: Provided by applicants submitting examiner applications or contact requests.
5. Data Security & Storage Architecture
We maintain strict technical and organizational safeguards:
- End-to-End Transit Encryption: Enforced HTTPS / TLS 1.3 encryption across all client-server communications.
- Cloud Infrastructure at Rest: Enterprise Google Cloud / Firebase hosting with AES-256 encryption at rest in ISO 27001-certified data centers.
- Granular Database Security Rules: Multi-tenant isolation ensuring schools cannot access data belonging to other institutions.
- Zero Public Results Access: Student scores are accessible only behind authenticated role-based portals.
6. Data Retention & Erasure
Student records and result slips are retained for the duration of the active examination cycle and the subsequent comparative reporting period. Upon written request by a school controller or upon account termination, student candidate records may be exported and securely deleted from active production databases within sixty (60) days.
7. Data Subject Rights & Inquiries
Under the Uganda Data Protection and Privacy Act, 2019, individuals have rights of access, rectification, erasure, and objection.
Because student data is controlled by schools, students and parents should first direct requests to their respective school administration. For platform-level privacy inquiries or to reach our Data Protection Officer: