What personal data Ijanaposa collects, why, who sees it, how long we keep it and your rights under the Data Protection and Privacy Act 2019.
This policy explains what personal data Ijanaposa Company Limited collects, why we collect it, who sees it, how long we keep it, and what you can do about it. It applies to this website, to the equipment and personnel portals, and to the records we keep about clients, professionals, suppliers and site visitors.
Ijanaposa Company Limited is a Ugandan lifting, transport, safety and equipment management company registered with the Uganda Registration Services Bureau. Our office is at Josephine House, 2nd Floor, Kayunga–Bugerere Road, Mukono, and our postal address is P.O. Box 152539, Kampala, Uganda. Our registration and tax numbers go to procurement teams on request.
For the purposes of the Data Protection and Privacy Act 2019 and the Data Protection and Privacy Regulations 2021, Ijanaposa Company Limited is the data collector, data processor and data controller for the personal data described in this policy.
Outstanding: registration with the Personal Data Protection Office. Registration under Part V of the Regulations is required and lasts twelve months. It has to be in place before this page is published.
We handle personal data under:
The regulator is the Personal Data Protection Office, which sits within the National Information Technology Authority Uganda and enforces the Act.
Section 3 of the Act sets seven principles that govern everything below: we must be accountable to you, collect and process data fairly and lawfully, take no more than we need, keep it only as long as the law or the purpose allows, keep it accurate, be open with you about what we hold, and protect it.
| You are | What we hold |
|---|---|
| A visitor to this website | Technical data about your visit, and anything you type into a form |
| A client or an enquirer | Your contact details, your company’s details, and the detail of the job you asked us about |
| A professional in our personnel network | A full professional file, including identity documents, certificates and work history |
| A supplier or subcontractor | Contact details, company records and payment details |
| A visitor to our premises or a site we run | Site sign-in records, and any site safety records that name you |
| An applicant for a job with us | Your application, and what you send with it |
Our own employees are covered by a separate staff privacy notice, not by this page.
How this works and how to change your choice is in our Cookie Policy.
This is the most sensitive set of records we hold, because a client will not put a person on a lifting operation without evidence that they are who they say they are and competent to do the work. We collect:
Our vehicles and machines carry GPS tracking, and we log odometer and hour-meter readings against every job. This is equipment data, but where a named driver or operator is assigned to a machine it becomes personal data about that person’s movements and working hours. We use it to plan jobs, to schedule servicing by readings, to bill clients accurately, and to investigate incidents. We do not use it to monitor a person outside working hours.
Section 7 of the Act says personal data may be collected or processed with your consent, or without it where the law authorises or requires it, where it is necessary to perform a contract with you or to take steps at your request before a contract, or where we have a legal obligation.
| What we do with it | Why | Lawful basis |
|---|---|---|
| Answer your enquiry and prepare a quotation | You asked us to | Steps taken at your request before a contract, section 7(2)(c) |
| Plan, run and invoice a hire or a project | To do the job you engaged us for | Performance of a contract, section 7(2)(c) |
| Verify a professional’s identity and qualifications | A client will not accept a crane operator whose licence has not been checked, and we would be negligent to send one | Consent, section 7(1), and our legal obligations as an employer and a supplier of lifting services |
| Keep operator competence records, pre-use checks and inspection registers | The Occupational Safety and Health Act 2006 requires lifting equipment and the competence of the people who use it to be documented | Legal obligation, section 7(2)(e) |
| Present a professional to a client for a specific job | To place you in work, and only with your agreement to that placement | Consent, section 7(1) |
| Keep tax, accounting and statutory employment records | The law requires it | Legal obligation, section 7(2)(e) |
| Investigate an incident on site or involving our equipment | To establish what happened, to meet reporting duties, and to defend or settle a claim | Legal obligation, section 7(2)(e), and the performance of the contract |
| Send you occasional updates about equipment and services | You ticked the box | Consent, section 7(1) |
| Measure how the website is used | To make it more useful | Consent, given through the cookie banner |
Where we rely on your consent, you can withdraw it. Section 7(3) of the Act says that where you object to the collection or processing of your personal data, we must stop, except where we are relying on one of the exceptions in section 7(2). We will tell you when that is the case, and why.
The Act calls religious or philosophical beliefs, political opinion, sexual life, financial information, health status and medical records special personal data, and section 9 prohibits collecting or processing it except in limited cases, including where the law imposes an obligation on an employer and where you give it freely and with consent.
We do not ask anyone for their religion, political opinion or sexual life, and we do not want it. Where a special category does reach us, it is one of these two:
Identity documents are not in the section 9 list, but a copy of a national ID or a passport is the document most likely to be used against someone if it leaks. We treat identity documents and certificates with the same care as special personal data:
Inside Ijanaposa. Only the people who need it for the task in front of them. Enquiries go to the commercial team, personnel files to the vetting team, invoices to accounts, and incident records to HSE.
Clients. When we put a professional forward for a job, the client is given the professional profile: name, profession, experience, skills, equipment competency, the certificates the job requires, and verification status. When we quote a job, the client sees the contact details of the person who raised the enquiry.
Verification sources. We contact the referees you give us, the employers on your work history, and the bodies that issued your certificates and licences, to confirm what you have told us. Giving us a referee’s details is your confirmation that you have their permission to pass them on.
Service providers. Website hosting, email, file storage, analytics and messaging providers process data on our behalf. They act on our instructions and are not allowed to use your data for their own purposes. Outstanding: the actual list, once hosting, email and analytics are chosen. Regulation 32 makes us responsible for ensuring any processor working for us implements appropriate security measures, so the list has to be real before this page is published.
Regulators and authorities. The Personal Data Protection Office, the Uganda Revenue Authority, the Ministry of Gender, Labour and Social Development, the Petroleum Authority of Uganda, the National Social Security Fund, the Police, a court, or a client’s regulator, where the law requires it or an investigation calls for it.
Insurers and advisers. Our insurers, brokers, auditors and lawyers, where a claim, an audit or a dispute makes it necessary.
We do not sell personal data. We do not pass your details to anyone for their own marketing.
Section 18 of the Act says personal data must not be kept longer than is necessary for the purpose it was collected for, unless the law requires or authorises us to keep it.
Outstanding: the table below states the rule for each record. It does not yet state a period. A retention schedule with real figures has to be agreed with the lawyer reviewing this policy and with the company’s accountant, and written in, before this page is published.
| Record | How long |
|---|---|
| An enquiry that did not become a job | Kept while it is live, and for a short period afterwards in case you come back to it, then deleted |
| A client file for a completed hire or project | Kept for as long as a claim or a tax authority could reasonably ask about it, then deleted |
| Lifting operation records: lift plans, pre-use checks, inspection registers, operator competence | Kept for the period required by the Occupational Safety and Health Act 2006 and by the client’s own project requirements |
| A personnel profile with an active professional | Kept while you are in the network and available for work |
| A personnel profile you have asked us to close | Identity documents deleted, and a minimal record of the placements we made kept for the period a payroll, tax or liability question could arise |
| An application to join the network that we did not take forward | Deleted, with the identity documents removed first |
| Accounting, tax and statutory employment records | Kept for the period Ugandan tax and employment law requires |
| Incident and investigation records | Kept for the period the law and our insurers require |
| GPS and odometer records | Kept for the period needed for billing, servicing and incident investigation |
| Website analytics | Kept for the period set in the analytics tool, in aggregate form |
Sections 20 to 22 of the Act require us to secure the data we hold, and to make sure anyone processing it for us does the same.
Outstanding: the specific technical measures, once hosting is in place. Where the data is hosted, encryption at rest, the backup regime, who holds administrator access, and whether two-factor authentication is enforced on admin accounts. Regulation 31 requires compliance with the information security practices the Office publishes in the Gazette.
Section 23 of the Act and regulation 33 require us to notify the Personal Data Protection Office immediately after a data breach, using the prescribed form, with the nature of the breach, the data involved, how many people are affected, the likely consequences and what we are doing about it. The Office then decides whether the people affected must be told directly. Where a breach puts you at risk, we will tell you whether or not we are directed to.
Section 19 of the Act and regulation 30 say we may not process or store personal data outside Uganda unless the country it goes to has protection at least equivalent to the Act, or you have consented. Data sent abroad on that basis cannot then be passed to a third country without your express consent.
Some of the tools this website depends on, including hosting, email and analytics, may store data outside Uganda. Where that is the case we will name the country and the provider here, and we will not use a provider we cannot account for.
Outstanding: where the site and the portal databases will be hosted, and in which country the email and analytics providers store data. The registration application under regulation 16 requires a written undertaking on exactly this point, so it has to be settled before launch.
Part V of the Act gives you these rights. They are free to use, and using one of them will never affect how we treat you.
| Right | What it means | What the law says we must do |
|---|---|---|
| Access (section 24, regulation 35) | Ask whether we hold personal data about you, and get a copy | Confirm our decision in writing within seven days of your request. We will ask you to prove your identity with a national ID, a passport or a driving licence |
| Correction and deletion (section 28, regulation 29) | Ask us to correct or delete data that is wrong, out of date, incomplete, misleading, excessive or obtained unlawfully, or to destroy a record we no longer have authority to hold | Tell you our decision in writing within seven days. If we act on it, we must also tell anyone we have already disclosed the data to |
| Prevent processing (section 25, regulation 36) | Tell us in writing to stop processing your data where the processing does not match the purpose it was collected for | Tell you in writing within fourteen days whether we have complied or intend to. If we refuse, we must give reasons and send a copy to the Personal Data Protection Office |
| Stop direct marketing (section 26) | Tell us to stop using your data to market to you | Tell you within fourteen days that we have complied, intend to, or why not |
| Object to an automated decision (section 27, regulation 38) | Require that a decision that significantly affects you is not taken by automatic means alone | Tell you within fourteen days whether we have complied |
| Complain (section 31) | Complain to us, and to the Personal Data Protection Office | Handle your complaint, and cooperate with any investigation |
| Compensation (section 33) | Go to court for compensation where a breach of the Act has caused you damage or distress |
Nothing on this site takes a decision about a person by automatic means. Verification and placement decisions are made by people.
Write to us. Say which right you are using, and give us enough detail to find your record. Attach a copy of your national ID, passport or driving licence so we can be sure we are giving your data to you and not to someone else.
| info@ijanaposa.com | |
| Post | Data Protection Contact, Ijanaposa Company Limited, P.O. Box 152539, Kampala, Uganda |
| In person | Josephine House, 2nd Floor, Kayunga–Bugerere Road, Mukono |
Outstanding: the name or job title of the person responsible for data protection. Regulation 47 requires a designated data protection officer where the core activity involves regular and systematic monitoring of people on a large scale, or the processing of special personal data. Whether the personnel portal crosses that line is a question for the lawyer reviewing this policy. Either way somebody has to own these requests and be named here.
If you are not satisfied with how we deal with your request, you can complain to the Personal Data Protection Office, which sits within the National Information Technology Authority Uganda. The Office has its own complaint forms and procedure under Part IX of the Regulations. See pdpo.go.ug.
This site uses cookies. Which ones, what they do, and how to change your choice are set out in the Cookie Policy.
Our services are for businesses and for adults looking for work. We do not knowingly collect personal data about anyone under eighteen. Section 8 of the Act prohibits collecting or processing a child’s personal data without the consent of a parent or guardian, except where the law requires it. If you believe we hold data about a child, tell us and we will delete it.
When we change this policy we will change the date at the top. Where a change affects how we use data we already hold, we will tell the people affected rather than rely on them noticing the date.
Cookie preferences