Skip to content

Privacy policy

Last updated 12 September 2026

This policy explains what personal data the Kampala Parents Old Students Association (“KPOSA”, “we”, “us”) holds about you, why we hold it, who else sees it, and what you can ask us to do about it. It covers the Kampala Parents Legacy Portal at thekposa.com.

It is written to meet Uganda’s Data Protection and Privacy Act, 2019 (the “DPPA”) and the Data Protection and Privacy Regulations, 2021. KPOSA is the data controller.

What we collect

This list is written from the actual database, not from a template. If something is not on this list, we do not store it.

If you register as an alumnus

The registration form is long, because the alumni office uses it to confirm you really did attend the school. It collects:

  • Who you are — first, middle and last name, the name you used at school if it has since changed, a school nickname, email address and a second email if you give one, phone number and a second number if you give one, a photograph if you upload one, and the country and city you live in now.
  • Your time at the school — which branch (Naguru or Old Kampala), the years you joined and left, your classes, stream, house, whether you were day or boarding, your dormitory, your class teacher and head teacher, classmates you remember, clubs, sports, and any leadership roles.
  • What you do now — employment status, line of work, employer, job title, work country and city, business website, LinkedIn profile, and a short biography, all optional.
  • How you want to take part — the activities you are interested in and what you are willing to offer other alumni, such as mentoring.
  • Who referred you, if another alumnus did.

If you start the form and do not finish it, what you have typed so far is saved against a private link so you can come back to it. That partial record is treated as expired after 30 days.

The alumni office can also write internal notes on your record while verifying it — for example, a note that a classmate confirmed your year. These notes are about you, so your right of access below covers them.

If you buy something, donate, or register for an event

  • Orders — your name, email address, phone number, whether you are collecting or want delivery, your delivery address if you give one, any note you add to the order, and what you bought at the price you paid. You do not need an account to buy.
  • Payments — we keep the payment reference, whether it succeeded, the payment method, the name and email you gave the payment provider, and only the last few digits of the mobile money number you approved on. We never receive or store your mobile money PIN, your full card number, or your card security code.
  • A full record of our exchanges with the payment provider, request and response, is kept against each payment. This is what we open when someone says they paid and the order says otherwise. It can contain the contact details you gave at checkout.
  • Donations — your name, email address and phone number, the amount, any message you write, and your class year if you give one. You can give anonymously, in which case we do not record your name or email against the gift at all.
  • Pledges — a promise to give later: name, email, phone, and the amount.
  • Event registrations — your name, email, phone, your ticket code, and, if you attend, the time you were checked in at the door and which staff member checked you in.
  • Gifts received away from the site — cash at a reunion, a bank transfer, a cheque. A staff member records your name and the amount, plus an internal note such as a cheque number. That note is never shown publicly.

If you contact us or share a story

  • Contact messages — your name, email, phone if you give one, your subject and message, and your IP address and browser user-agent string.
  • Story, photo and video submissions — your name, email, phone if you give one, your year group, whatever you submit, and your IP address and browser user-agent string. If a submission is rejected, the reviewer’s note is internal and is never emailed to you.

If you have an account

  • Your email address, your name and phone number if you give them, a profile image if you set one, and a hashed password. We never store the password itself and cannot read it.
  • For staff accounts, the permissions you hold, and a record of any request you made for admin access including the reason you gave and the decision.

Whenever you give or withdraw consent

The DPPA requires us to be able to demonstrate consent, not just assert it. So each time you agree to something, we record what you agreed to, whether you said yes or no, the version of the policy in force at that moment, the time, and your IP address and browser user-agent.

If you subscribe to updates

Your email address and phone number, which channels you opted in to, and a private unsubscribe link unique to you. We also keep a delivery record per message — the address it went to, whether it arrived, and any error.

When staff change things

Administrative actions are logged: which staff member did what, to which record, what it looked like before and after, and their IP address. This is how the association keeps itself accountable for its own members’ data.

Why we hold it, and our lawful basis

  • Your consent — alumni registration, any marketing email or SMS, showing your name on the donor wall, and publishing a story you submit. You can withdraw consent at any time, and withdrawal does not undo anything done lawfully beforehand.
  • To perform a contract with you — taking an order, delivering it, issuing a download link, admitting you to an event you bought a ticket for.
  • Our legitimate interests — verifying that a registrant genuinely attended the school, keeping the membership register accurate, preventing fraud and abuse of the site, and keeping the audit log. We consider these do not override your own rights; if you disagree, you can object, and we will look again.
  • Legal obligation — keeping financial records, and responding to a lawful request from an authority.

What is published, and what is not

Three things on this site can show your name in public. All three are off unless you switch them on.

  • The donor wall. Your name and gift appear only if you gave explicit consent for that. Choosing to give anonymously is a separate, stronger choice: it means we do not record your name against the gift at all.
  • Published stories. A story or photo you submit is only published if you consented to publication at the time you submitted it, and it stays published only while that consent stands. Withdraw it and the story comes down.
  • The alumni directory. The register is designed so that each field is private by default and shared only if you opt that field in. No alumni directory is published on this site at present, and there is currently no screen on which you can set these preferences. Until both exist, nothing from your registration is visible to other alumni or to the public. If you want your details changed or removed in the meantime, email us and we will do it by hand.

Who else sees your data

We do not sell personal data and we do not share it for anyone else’s marketing. We use these service providers, and no others:

  • Pesapal — processes mobile money and card payments. Receives your name, email, phone number and the amount, so it can take the payment. Pesapal operates in Kenya and Uganda.
  • Neon — hosts the database where everything described above is stored. The database is in Frankfurt, Germany.
  • Amazon Web Services (Simple Email Service) — delivers email such as order confirmations and sign-in links. Receives your email address and the contents of that message. Operates from Frankfurt, Germany for us.
  • Vercel — runs the website itself. Web requests, including your IP address, pass through its servers.
  • Vercel Blob — stores uploaded files, including any photograph you submit with a story and product images.

We may also disclose personal data where the law requires it, or to establish or defend the association’s legal rights.

Your data leaves Uganda

This matters, so it gets its own section. The database and the email service are both physically in Germany, and the website is served from infrastructure outside Uganda. Payment processing happens in the region. So yes — your personal data is processed outside Uganda.

Section 19 of the DPPA allows this where the receiving country has comparable protection, or where you have consented to the transfer having been told of the risks. Germany is subject to the EU General Data Protection Regulation, which the Personal Data Protection Office treats as comparable protection. Each provider is bound by its own data processing terms with us.

KPOSA has not yet decided which of these grounds it is relying on, and has not yet confirmed whether the Personal Data Protection Office has been notified of these transfers. That decision is being finalised. Until it is, if you have a question about how your data leaves Uganda, email thekposa@gmail.com.

How long we keep it

Being straight with you: this site does not currently delete anything automatically on a timetable. Deletion happens when you ask us, or when staff clear records by hand. These are the periods we work to:

  • Alumni registration — kept for as long as you wish to remain on the register. Ask us to remove you and we will.
  • Unfinished registration forms — treated as expired after 30 days.
  • Orders, payments and donations — kept as financial records. The exact retention period required under Ugandan tax and accounting law has not yet been confirmed by KPOSA’s accountant, so no fixed period is stated here yet. This will be added once confirmed. Questions in the meantime: thekposa@gmail.com.
  • Contact messages and submissions KPOSA has not yet set a specific retention period for these, and no automatic deletion is currently enforced by the system. If you would like a message or submission deleted sooner, email thekposa@gmail.com and we will do it by hand.
  • Consent records — kept for as long as we hold the data the consent relates to, plus a reasonable period afterwards, because a consent record is the evidence that our processing was lawful.
  • Audit logs — kept for the life of the association’s records.

Your rights

Under the DPPA you can ask us to:

  • tell you what we hold about you, and give you a copy — including the internal notes staff have written on your record;
  • correct anything wrong or incomplete;
  • delete your data, except where we must keep it — a paid order has to stay in the financial records;
  • stop processing it, including stopping all marketing, which we will always do on request;
  • withdraw a consent you previously gave, at any time.

How to do any of this: email thekposa@gmail.com and say what you want. There is no form to fill in and no account you need in order to ask. If you are asking us to delete or release data, we may first need to check you are who you say you are — usually by writing back to the email address already on the record.

Every marketing email carries an unsubscribe link that works without signing in. If SMS is ever switched on, a STOP reply will stop it.

KPOSA has not yet set a specific response-time commitment it can guarantee. Until it does, we aim to respond as promptly as we reasonably can, and you can always follow up at thekposa@gmail.com if you have not heard back.

If you think we have mishandled your data, you can complain to Uganda’s Personal Data Protection Office, which sits within the National Information Technology Authority – Uganda (NITA-U).

Security

Passwords are hashed and cannot be read back, by us or by anyone who obtained the database. Card and mobile money credentials never reach our systems — they are entered on the payment provider’s own page. Access to the admin system is limited to named staff accounts with specific permissions, and what they do is logged. We do not write personal data into plain-text application logs.

No system is perfectly secure. If a breach affects your data, we will tell you and the Personal Data Protection Office as the DPPA requires.

Children

This site is for adult former students. We do not knowingly collect data from children through it. If you believe a child has registered, tell us and we will remove the record.

Changes to this policy

If we change this policy in a way that matters, we update the date at the top and record a new policy version. Because we store which version you agreed to, we can always tell what you were shown at the time — and we will ask again where a change needs fresh consent. See also our cookie policy and terms.

Contact

Questions about this policy, or to exercise any right above: thekposa@gmail.com.

KPOSA has not yet confirmed a postal address for written requests or appointed a named Data Protection Officer. Until it does, the email address above is the association’s data protection contact point for all purposes.