Ijanaposa Company Limited

Privacy Policy

What personal data Ijanaposa collects, why, who sees it, how long we keep it and your rights under the Data Protection and Privacy Act 2019.

This policy explains what personal data Ijanaposa Company Limited collects, why we collect it, who sees it, how long we keep it, and what you can do about it. It applies to this website, to the equipment and personnel portals, and to the records we keep about clients, professionals, suppliers and site visitors.

Who we are

Ijanaposa Company Limited is a Ugandan lifting, transport, safety and equipment management company registered with the Uganda Registration Services Bureau. Our office is at Josephine House, 2nd Floor, Kayunga–Bugerere Road, Mukono, and our postal address is P.O. Box 152539, Kampala, Uganda. Our registration and tax numbers go to procurement teams on request.

For the purposes of the Data Protection and Privacy Act 2019 and the Data Protection and Privacy Regulations 2021, Ijanaposa Company Limited is the data collector, data processor and data controller for the personal data described in this policy.

Outstanding: registration with the Personal Data Protection Office. Registration under Part V of the Regulations is required and lasts twelve months. It has to be in place before this page is published.

The law this policy follows

We handle personal data under:

  • the Data Protection and Privacy Act 2019, which sets the principles, the obligations of data collectors, controllers and processors, and the rights of data subjects
  • the Data Protection and Privacy Regulations 2021 (S.I. No. 21 of 2021), which set the procedures, the registration requirement and the response times
  • Article 27 of the Constitution of Uganda, which protects privacy of the person, home and correspondence

The regulator is the Personal Data Protection Office, which sits within the National Information Technology Authority Uganda and enforces the Act.

Section 3 of the Act sets seven principles that govern everything below: we must be accountable to you, collect and process data fairly and lawfully, take no more than we need, keep it only as long as the law or the purpose allows, keep it accurate, be open with you about what we hold, and protect it.

Who this policy covers

You areWhat we hold
A visitor to this websiteTechnical data about your visit, and anything you type into a form
A client or an enquirerYour contact details, your company’s details, and the detail of the job you asked us about
A professional in our personnel networkA full professional file, including identity documents, certificates and work history
A supplier or subcontractorContact details, company records and payment details
A visitor to our premises or a site we runSite sign-in records, and any site safety records that name you
An applicant for a job with usYour application, and what you send with it

Our own employees are covered by a separate staff privacy notice, not by this page.

What we collect

When you visit this website

  • Your IP address, browser, device type, operating system and approximate location
  • The pages you open, how you arrived and how long you stay
  • Cookie identifiers, if you allow non-essential cookies

How this works and how to change your choice is in our Cookie Policy.

When you ask us for a quote or send us a message

  • Your name, job title, company, email address, phone number and country
  • Whether your number takes WhatsApp messages
  • What you tell us about the project: the scope, the load, the site, the district, the dates, the equipment and the crew you need
  • Anything you attach: a scope of work, drawings, a lift plan, a method statement, site photographs, permits or prequalification documents
  • The messages you exchange with us afterwards, including WhatsApp messages, emails and notes of phone calls

If you join our personnel network

This is the most sensitive set of records we hold, because a client will not put a person on a lifting operation without evidence that they are who they say they are and competent to do the work. We collect:

  • Identity: your full name, date of birth, gender, nationality, photograph, and a copy of your national identity card, passport or driving licence
  • Contact: phone number, email address, and the district or town you are based in
  • Competence: your profession, specialisations, years of experience, skills, the makes, models and capacity classes of equipment you are competent on
  • Certificates and licences: operator licences, rigging and lifting certificates, HSE certificates, first aid certificates, and the issuing body, certificate number and expiry date for each, together with the certificate document itself
  • Work history: previous employers, positions, periods, projects and equipment used
  • References: the name, company, position and contact details of the referees you give us, and the notes of what they tell us
  • Availability: where you are willing to work and when you are free
  • Medical fitness: a certificate of fitness where a role or a client site requires one
  • Payment details: bank or mobile money details, and your TIN and NSSF number where you are engaged directly

If you work on a site we run, or ride in our vehicles

  • Site sign-in and induction records
  • Toolbox talk and briefing attendance
  • Incident, near-miss and investigation records that name you
  • Staff transport manifests, where we carry your employer’s staff

Our fleet

Our vehicles and machines carry GPS tracking, and we log odometer and hour-meter readings against every job. This is equipment data, but where a named driver or operator is assigned to a machine it becomes personal data about that person’s movements and working hours. We use it to plan jobs, to schedule servicing by readings, to bill clients accurately, and to investigate incidents. We do not use it to monitor a person outside working hours.

Why we collect it, and our lawful basis

Section 7 of the Act says personal data may be collected or processed with your consent, or without it where the law authorises or requires it, where it is necessary to perform a contract with you or to take steps at your request before a contract, or where we have a legal obligation.

What we do with itWhyLawful basis
Answer your enquiry and prepare a quotationYou asked us toSteps taken at your request before a contract, section 7(2)(c)
Plan, run and invoice a hire or a projectTo do the job you engaged us forPerformance of a contract, section 7(2)(c)
Verify a professional’s identity and qualificationsA client will not accept a crane operator whose licence has not been checked, and we would be negligent to send oneConsent, section 7(1), and our legal obligations as an employer and a supplier of lifting services
Keep operator competence records, pre-use checks and inspection registersThe Occupational Safety and Health Act 2006 requires lifting equipment and the competence of the people who use it to be documentedLegal obligation, section 7(2)(e)
Present a professional to a client for a specific jobTo place you in work, and only with your agreement to that placementConsent, section 7(1)
Keep tax, accounting and statutory employment recordsThe law requires itLegal obligation, section 7(2)(e)
Investigate an incident on site or involving our equipmentTo establish what happened, to meet reporting duties, and to defend or settle a claimLegal obligation, section 7(2)(e), and the performance of the contract
Send you occasional updates about equipment and servicesYou ticked the boxConsent, section 7(1)
Measure how the website is usedTo make it more usefulConsent, given through the cookie banner

Where we rely on your consent, you can withdraw it. Section 7(3) of the Act says that where you object to the collection or processing of your personal data, we must stop, except where we are relying on one of the exceptions in section 7(2). We will tell you when that is the case, and why.

Identity documents and special personal data

The Act calls religious or philosophical beliefs, political opinion, sexual life, financial information, health status and medical records special personal data, and section 9 prohibits collecting or processing it except in limited cases, including where the law imposes an obligation on an employer and where you give it freely and with consent.

We do not ask anyone for their religion, political opinion or sexual life, and we do not want it. Where a special category does reach us, it is one of these two:

  • Health status, where a role or a client site requires a certificate of medical fitness. We record that a valid certificate exists and when it expires. We do not ask for the underlying medical record.
  • Financial information, meaning bank or mobile money details used to pay you or to invoice you.

Identity documents are not in the section 9 list, but a copy of a national ID or a passport is the document most likely to be used against someone if it leaks. We treat identity documents and certificates with the same care as special personal data:

  • they are uploaded through the portal, never collected over WhatsApp, email or a photograph sent to a personal phone
  • they are stored in the personnel record, not in a shared folder or an inbox
  • they are visible only to the staff who carry out verification
  • we record the document number and expiry date, and we keep the image only as long as the retention rules below allow
  • a client is told that a person’s identity and certificates have been verified, and is sent the certificate evidence the project requires. A client is not sent a copy of a national ID or a passport unless the site operator requires it for a gate pass, and then only with your agreement

Who sees your data

Inside Ijanaposa. Only the people who need it for the task in front of them. Enquiries go to the commercial team, personnel files to the vetting team, invoices to accounts, and incident records to HSE.

Clients. When we put a professional forward for a job, the client is given the professional profile: name, profession, experience, skills, equipment competency, the certificates the job requires, and verification status. When we quote a job, the client sees the contact details of the person who raised the enquiry.

Verification sources. We contact the referees you give us, the employers on your work history, and the bodies that issued your certificates and licences, to confirm what you have told us. Giving us a referee’s details is your confirmation that you have their permission to pass them on.

Service providers. Website hosting, email, file storage, analytics and messaging providers process data on our behalf. They act on our instructions and are not allowed to use your data for their own purposes. Outstanding: the actual list, once hosting, email and analytics are chosen. Regulation 32 makes us responsible for ensuring any processor working for us implements appropriate security measures, so the list has to be real before this page is published.

Regulators and authorities. The Personal Data Protection Office, the Uganda Revenue Authority, the Ministry of Gender, Labour and Social Development, the Petroleum Authority of Uganda, the National Social Security Fund, the Police, a court, or a client’s regulator, where the law requires it or an investigation calls for it.

Insurers and advisers. Our insurers, brokers, auditors and lawyers, where a claim, an audit or a dispute makes it necessary.

We do not sell personal data. We do not pass your details to anyone for their own marketing.

How long we keep it

Section 18 of the Act says personal data must not be kept longer than is necessary for the purpose it was collected for, unless the law requires or authorises us to keep it.

Outstanding: the table below states the rule for each record. It does not yet state a period. A retention schedule with real figures has to be agreed with the lawyer reviewing this policy and with the company’s accountant, and written in, before this page is published.

RecordHow long
An enquiry that did not become a jobKept while it is live, and for a short period afterwards in case you come back to it, then deleted
A client file for a completed hire or projectKept for as long as a claim or a tax authority could reasonably ask about it, then deleted
Lifting operation records: lift plans, pre-use checks, inspection registers, operator competenceKept for the period required by the Occupational Safety and Health Act 2006 and by the client’s own project requirements
A personnel profile with an active professionalKept while you are in the network and available for work
A personnel profile you have asked us to closeIdentity documents deleted, and a minimal record of the placements we made kept for the period a payroll, tax or liability question could arise
An application to join the network that we did not take forwardDeleted, with the identity documents removed first
Accounting, tax and statutory employment recordsKept for the period Ugandan tax and employment law requires
Incident and investigation recordsKept for the period the law and our insurers require
GPS and odometer recordsKept for the period needed for billing, servicing and incident investigation
Website analyticsKept for the period set in the analytics tool, in aggregate form

How we protect it

Sections 20 to 22 of the Act require us to secure the data we hold, and to make sure anyone processing it for us does the same.

  • Accounts on the portal are individual. Staff do not share logins
  • Access follows the job. A person who does not do verification cannot open a verification file
  • Identity documents and certificates are stored in the personnel record, which is not browsable by staff without a reason to be in it
  • The website and the portals run over an encrypted connection
  • We keep a record of who looked at a personnel file and when
  • Anything we no longer have a reason to hold is deleted, not archived indefinitely

Outstanding: the specific technical measures, once hosting is in place. Where the data is hosted, encryption at rest, the backup regime, who holds administrator access, and whether two-factor authentication is enforced on admin accounts. Regulation 31 requires compliance with the information security practices the Office publishes in the Gazette.

If something goes wrong

Section 23 of the Act and regulation 33 require us to notify the Personal Data Protection Office immediately after a data breach, using the prescribed form, with the nature of the breach, the data involved, how many people are affected, the likely consequences and what we are doing about it. The Office then decides whether the people affected must be told directly. Where a breach puts you at risk, we will tell you whether or not we are directed to.

Sending data outside Uganda

Section 19 of the Act and regulation 30 say we may not process or store personal data outside Uganda unless the country it goes to has protection at least equivalent to the Act, or you have consented. Data sent abroad on that basis cannot then be passed to a third country without your express consent.

Some of the tools this website depends on, including hosting, email and analytics, may store data outside Uganda. Where that is the case we will name the country and the provider here, and we will not use a provider we cannot account for.

Outstanding: where the site and the portal databases will be hosted, and in which country the email and analytics providers store data. The registration application under regulation 16 requires a written undertaking on exactly this point, so it has to be settled before launch.

Your rights

Part V of the Act gives you these rights. They are free to use, and using one of them will never affect how we treat you.

RightWhat it meansWhat the law says we must do
Access (section 24, regulation 35)Ask whether we hold personal data about you, and get a copyConfirm our decision in writing within seven days of your request. We will ask you to prove your identity with a national ID, a passport or a driving licence
Correction and deletion (section 28, regulation 29)Ask us to correct or delete data that is wrong, out of date, incomplete, misleading, excessive or obtained unlawfully, or to destroy a record we no longer have authority to holdTell you our decision in writing within seven days. If we act on it, we must also tell anyone we have already disclosed the data to
Prevent processing (section 25, regulation 36)Tell us in writing to stop processing your data where the processing does not match the purpose it was collected forTell you in writing within fourteen days whether we have complied or intend to. If we refuse, we must give reasons and send a copy to the Personal Data Protection Office
Stop direct marketing (section 26)Tell us to stop using your data to market to youTell you within fourteen days that we have complied, intend to, or why not
Object to an automated decision (section 27, regulation 38)Require that a decision that significantly affects you is not taken by automatic means aloneTell you within fourteen days whether we have complied
Complain (section 31)Complain to us, and to the Personal Data Protection OfficeHandle your complaint, and cooperate with any investigation
Compensation (section 33)Go to court for compensation where a breach of the Act has caused you damage or distress

Nothing on this site takes a decision about a person by automatic means. Verification and placement decisions are made by people.

How to exercise a right, or complain

Write to us. Say which right you are using, and give us enough detail to find your record. Attach a copy of your national ID, passport or driving licence so we can be sure we are giving your data to you and not to someone else.

Emailinfo@ijanaposa.com
PostData Protection Contact, Ijanaposa Company Limited, P.O. Box 152539, Kampala, Uganda
In personJosephine House, 2nd Floor, Kayunga–Bugerere Road, Mukono

Outstanding: the name or job title of the person responsible for data protection. Regulation 47 requires a designated data protection officer where the core activity involves regular and systematic monitoring of people on a large scale, or the processing of special personal data. Whether the personnel portal crosses that line is a question for the lawyer reviewing this policy. Either way somebody has to own these requests and be named here.

If you are not satisfied with how we deal with your request, you can complain to the Personal Data Protection Office, which sits within the National Information Technology Authority Uganda. The Office has its own complaint forms and procedure under Part IX of the Regulations. See pdpo.go.ug.

Cookies

This site uses cookies. Which ones, what they do, and how to change your choice are set out in the Cookie Policy.

Children

Our services are for businesses and for adults looking for work. We do not knowingly collect personal data about anyone under eighteen. Section 8 of the Act prohibits collecting or processing a child’s personal data without the consent of a parent or guardian, except where the law requires it. If you believe we hold data about a child, tell us and we will delete it.

Changes to this policy

When we change this policy we will change the date at the top. Where a change affects how we use data we already hold, we will tell the people affected rather than rely on them noticing the date.