Data Processing Agreement
This schedule forms part of the Terms of Service between Malticard Uganda Limited and the subscribing school, and governs Malticard’s processing of personal data on the school’s behalf under the Data Protection and Privacy Act, 2019.
1Roles
The School is the data controller. Malticard is the data processor. The School determines the purposes and means of processing; Malticard processes only on the School’s documented instructions, of which this agreement and the Terms of Service are the initial and complete set.
2Scope of processing
| Subject matter | Provision of the Skooltym Access attendance and notification platform |
|---|---|
| Duration | The term of the subscription, plus the deletion periods in section 9 |
| Nature and purpose | Enrolment, biometric matching, attendance recording, SMS notification, reporting, analytics, support and backup |
| Categories of data subject | Students (minors), parents and guardians, school staff |
| Categories of data | Identifiers, contact details, class and stream, attendance events, biometric templates, photographs, access and audit logs |
| Special personal data | Biometric data; children’s data |
3Malticard’s obligations
- Process personal data only on the School’s documented instructions, unless required otherwise by law — in which case we will inform the School first unless the law forbids it.
- Tell the School promptly if, in our opinion, an instruction breaches the Data Protection and Privacy Act, 2019 or other applicable law.
- Ensure that personnel authorised to process the data are bound by confidentiality and trained appropriately.
- Implement the technical and organisational measures set out in section 6.
- Assist the School, at the School’s cost where the effort is more than trivial, with data subject requests, data protection impact assessments and consultations with the Personal Data Protection Office.
- Make available the information reasonably necessary to demonstrate compliance with this agreement.
4The School’s obligations and warranties
The School warrants that it has, and will maintain, a lawful basis for every instruction it gives; that it has obtained and recorded valid parental consent for every biometric enrolment; that the data it supplies is accurate and lawfully obtained; that it has given the required notices to data subjects; and that it has registered with the Personal Data Protection Office where required to do so. The School will indemnify Malticard for losses arising from a breach of these warranties.
5Sub-processors
The School gives general authorisation for Malticard to appoint sub-processors, subject to each being bound by obligations no less protective than those in this agreement. Malticard remains liable for its sub-processors’ acts and omissions. Current categories:
| Sub-processor | Purpose | Location |
|---|---|---|
| [Cloud hosting provider] | Platform hosting, storage, backup | [—] |
| [SMS aggregator / mobile network operators] | Delivery of notifications | Uganda |
| [Payment provider] | Subscription payments | Uganda |
| [Error monitoring / support tooling] | Diagnostics and support | [—] |
Malticard will give the School [30] days’ notice of an intended new or replacement sub-processor. The School may object on reasonable data-protection grounds; if the objection cannot be resolved, the School may terminate the affected service without penalty.
6Security measures
- Encryption of personal data in transit (TLS) and of biometric templates at rest.
- Logical isolation of each school’s data; no cross-school queries.
- Role-based access control, individual named accounts, and audit logging of administrative actions.
- Least-privilege, time-bounded and logged engineer access for support.
- Encrypted backups with a [35]-day cycle and documented restore testing.
- Vulnerability management, dependency patching and periodic security review.
- Documented incident response, with defined severity levels and escalation.
7Personal data breach
Malticard will notify the School without undue delay, and in any event within [72] hours of becoming aware of a personal data breach affecting the School’s data, describing the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Malticard will cooperate with the School’s own notification duties. Malticard will not notify the Personal Data Protection Office or data subjects on the School’s behalf unless the School instructs it in writing.
8Audit
Once per twelve months, and on [30] days’ written notice, the School may audit Malticard’s compliance with this agreement — by questionnaire, by review of our security documentation, or, where those are genuinely insufficient, by an on-site inspection conducted by the School or an independent auditor bound by confidentiality, during business hours and without disrupting our operations or other customers’ data. Additional audits following a confirmed breach are permitted.
9Return and deletion
On termination, the School may export its attendance and student data for [30] days. Malticard will then delete all personal data from the live platform, from all gate terminals at the School, and from backups within the following backup cycle of [35] days, and will confirm deletion in writing on request. Biometric templates are deleted on termination and are never retained. Data required to be retained by law is kept only for that period and only for that purpose.
10Cross-border transfer
Personal data will not be transferred outside Uganda except in accordance with section 19 of the Data Protection and Privacy Act, 2019 — that is, to a jurisdiction with adequate protection or under contractual safeguards — and the School will be told where its data is held.
11Liability and precedence
Liability under this agreement is subject to the limitation of liability in the Terms of Service. In the event of conflict between this agreement and the Terms of Service on a data protection matter, this agreement prevails.