Legal
Privacy and POPIA summary
This is a plain-language summary of how Uhambo Atlas Academy handles personal information under the Protection of Personal Information Act, 2013. It is written to be read, not to be survived. It summarises — it does not replace — the operator agreement and privacy notice that form part of a tenant contract.
Last reviewed: 28 July 2026. This summary describes the platform as specified and built. Where a control is sequenced rather than live, it says so.
1. Who is responsible for what
Two distinct relationships exist, and confusing them is the most common mistake in this market.
- Your learners’ data. The accredited provider — our tenant — is the responsible party. Uhambo Atlas is the operator, processing that data only on the provider’s documented instruction, under an operator agreement as required by section 21 of POPIA. We do not decide the purpose of that processing, we do not use it for our own ends, and we do not sell it. Ever.
- Your data as a visitor or prospect. For the enquiry form on this site and our own sales correspondence, Uhambo Atlas is the responsible party.
2. What the platform processes
Because the platform carries a statutory reporting obligation on behalf of providers, it holds more identity data than a general learning system would. That is the nature of NLRD and SETA reporting, and it is exactly why the controls below exist.
| Category | Examples | Why it is held |
|---|---|---|
| Statutory identity | Legal names in Home Affairs format, South African identity number or passport and nationality, date of birth, citizenship, contact details, structured addresses | Mandatory fields of the national learner-record data set and SETA submissions |
| Special-category (section 26) | Race, disability status and type, health-adjacent accommodation information | Required by national reporting and by B-BBEE skills-development reporting; accommodations exist to make assessment fair |
| Learning and assessment | Enrolments, attendance, attempts, marks and their provenance, moderation decisions, portfolio artefacts, logbook hours and mentor signatures | The evidence chain a provider must be able to produce on audit |
| Employment context | Employer, learnership agreement reference, funding type | Cohort administration, grant and scorecard reporting |
| Behavioural telemetry | Learning-record statements; simulation session metrics | Mastery modelling, readiness scoring, assessor review |
| Biometric-adjacent telemetry | Aggregate attention features from eye-tracking-capable headsets; optional physiological signals in pilots only | Only where a scenario is criterion-mapped to attention behaviour, and only with explicit, purpose-bound consent |
3. Special-category data and the consent gates
Race, disability, health-adjacent and biometric-adjacent information is treated as special personal information under section 26 and is gated in the software itself, not in a policy document:
- Consent is purpose-scoped, timestamped and withdrawable, and the consent registry is checked at the point of processing.
- These columns are encrypted at field level with per-tenant keys, and searchable only through blind indexes — a learner can be found by identity number without the plaintext ever being indexed.
- Raw eye-gaze and physiological streams are refused outright. Only aggregate features are computed, wherever possible on the device, and retention is short and fixed.
- Learners can see a data page showing exactly what a simulation session recorded about them.
- A data-protection impact assessment is completed before any such processing goes live, and the feature is dropped rather than compromised if the assessment fails.
Remote proctoring is deliberately not in the product. If it is ever piloted, it will be high-stakes only, opt-in, human-reviewed and retention-bounded.
4. Lawful basis
- Statutory obligation — the reporting a provider owes the QCTO, its SETA and SAQA.
- Contract — delivering, assessing and certifying the programme a learner enrolled on.
- Consent — special-category processing, simulation telemetry beyond the criterion, and marketing communication.
- Legitimate interest — platform security, fraud and abuse detection, and service integrity.
5. Your rights, and how they are executed
Learners exercise data-subject rights through their provider, who is the responsible party; the platform gives that provider a workflow rather than a mailbox. Access, correction, objection, complaint and deletion requests are handled as follows:
- Access — an export of everything held about the data subject, generated from the same record spine the audit pack uses.
- Correction — corrections to assessment records are forward-only versioned events. Nothing is silently overwritten, because a regulator has to be able to see what the record said before and after.
- Deletion — executed by destroying the relevant encryption key. That makes erasure provable and immediate, and it reaches backups by construction rather than by promise.
- The limit on deletion, stated honestly — statutory evidence that a provider is legally required to retain cannot be deleted on request while that retention obligation runs. This is a legal constraint on your provider, not a technical excuse from us; the retention clock per record class is visible and enforced.
6. Retention and residency
- Retention schedules are set per record class. Statutory evidence is retained for the period the QCTO, the relevant SETA and NLRD obligations require. Operational telemetry is aged aggressively.
- Evidence artefacts sit under compliance-mode object lock: unalterable and undeletable within their retention window, including by our own administrators.
- Hosting is in-country by default, in the South African cloud region, across three availability zones.
- Any cross-border transfer — including encrypted backup replication — happens only under the cross-border transfer register with contractual safeguards under section 72, and only where a tenant has asked for it.
7. Subprocessors
The platform is built with zero runtime dependencies on third-party code, but it does use infrastructure and specialist services — cloud hosting and key management, communications transport, speech services, device management for immersive fleets, and AI model providers under a per-tenant policy. Every subprocessor carries an operator agreement, appears on a register available to tenants, and is subject to a vendor security review before it touches data. Tenants are notified before a new subprocessor is added.
8. Automated processing and AI
AI is used for tutoring, drafting content, assisting marking and generating reports. Three commitments constrain it:
- Every mark carries provenance — deterministic, AI with the model and prompt version, or human.
- AI never auto-fails a learner. Integrity flags route to a human moderator queue, and no adverse action is taken on an AI decision alone.
- A default sample of AI marks is audited by a person, and every model or prompt change is regression-tested against a golden set before it can affect a regulated assessment.
Per-tenant AI policy controls which models may be used, where they may run, who may invoke them and what may be spent.
9. Security incidents and breach notification
The security architecture is described in full on the trust architecture section of the main site. On the notification side specifically: a section 22 breach-notification workflow is pre-drafted — decision tree, Information Regulator template and data-subject template — rather than written under pressure on the day. Incident runbooks are severity-classified, per-tenant isolation switches allow one tenant’s data plane to be frozen without touching its neighbours, and tabletop exercises run twice a year, including a ransomware-on-the-evidence-vault scenario and a malicious-tenant-administrator scenario.
10. This website
- This marketing site sets no advertising or analytics cookies and embeds no third-party scripts, fonts, tag managers or trackers. Every asset it loads is served from this origin, enforced by a content-security policy of default-src 'self'.
- The demo-request form collects your name, role, organisation, work email, learner-volume band, authority and message. It is used to respond to your enquiry and for related follow-up, kept for 24 months from last contact, and never sold or shared for marketing.
- The signed-in application surfaces store a session token in your browser’s local storage. That is the only client-side state the product keeps.
11. Contact
- Information Officer
- informationofficer@uhambo.academy
- General enquiries
- academy@uhambo.academy
- Security disclosure
- security@uhambo.academy — we will acknowledge a good-faith report within one business day and will not pursue researchers who act within a coordinated disclosure.
- Regulator
- You may complain directly to the Information Regulator of South Africa at any time.