UHAMBO ATLAS ACADEMY Request a demo

Legal

Privacy and POPIA summary

This is a plain-language summary of how Uhambo Atlas Academy handles personal information under the Protection of Personal Information Act, 2013. It is written to be read, not to be survived. It summarises — it does not replace — the operator agreement and privacy notice that form part of a tenant contract.

Last reviewed: 28 July 2026. This summary describes the platform as specified and built. Where a control is sequenced rather than live, it says so.

1. Who is responsible for what

Two distinct relationships exist, and confusing them is the most common mistake in this market.

2. What the platform processes

Because the platform carries a statutory reporting obligation on behalf of providers, it holds more identity data than a general learning system would. That is the nature of NLRD and SETA reporting, and it is exactly why the controls below exist.

Categories of personal information held on behalf of provider tenants
Category Examples Why it is held
Statutory identity Legal names in Home Affairs format, South African identity number or passport and nationality, date of birth, citizenship, contact details, structured addresses Mandatory fields of the national learner-record data set and SETA submissions
Special-category (section 26) Race, disability status and type, health-adjacent accommodation information Required by national reporting and by B-BBEE skills-development reporting; accommodations exist to make assessment fair
Learning and assessment Enrolments, attendance, attempts, marks and their provenance, moderation decisions, portfolio artefacts, logbook hours and mentor signatures The evidence chain a provider must be able to produce on audit
Employment context Employer, learnership agreement reference, funding type Cohort administration, grant and scorecard reporting
Behavioural telemetry Learning-record statements; simulation session metrics Mastery modelling, readiness scoring, assessor review
Biometric-adjacent telemetry Aggregate attention features from eye-tracking-capable headsets; optional physiological signals in pilots only Only where a scenario is criterion-mapped to attention behaviour, and only with explicit, purpose-bound consent

3. Special-category data and the consent gates

Race, disability, health-adjacent and biometric-adjacent information is treated as special personal information under section 26 and is gated in the software itself, not in a policy document:

Remote proctoring is deliberately not in the product. If it is ever piloted, it will be high-stakes only, opt-in, human-reviewed and retention-bounded.

4. Lawful basis

5. Your rights, and how they are executed

Learners exercise data-subject rights through their provider, who is the responsible party; the platform gives that provider a workflow rather than a mailbox. Access, correction, objection, complaint and deletion requests are handled as follows:

6. Retention and residency

7. Subprocessors

The platform is built with zero runtime dependencies on third-party code, but it does use infrastructure and specialist services — cloud hosting and key management, communications transport, speech services, device management for immersive fleets, and AI model providers under a per-tenant policy. Every subprocessor carries an operator agreement, appears on a register available to tenants, and is subject to a vendor security review before it touches data. Tenants are notified before a new subprocessor is added.

8. Automated processing and AI

AI is used for tutoring, drafting content, assisting marking and generating reports. Three commitments constrain it:

Per-tenant AI policy controls which models may be used, where they may run, who may invoke them and what may be spent.

9. Security incidents and breach notification

The security architecture is described in full on the trust architecture section of the main site. On the notification side specifically: a section 22 breach-notification workflow is pre-drafted — decision tree, Information Regulator template and data-subject template — rather than written under pressure on the day. Incident runbooks are severity-classified, per-tenant isolation switches allow one tenant’s data plane to be frozen without touching its neighbours, and tabletop exercises run twice a year, including a ransomware-on-the-evidence-vault scenario and a malicious-tenant-administrator scenario.

10. This website

11. Contact

Information Officer
informationofficer@uhambo.academy
General enquiries
academy@uhambo.academy
Security disclosure
security@uhambo.academy — we will acknowledge a good-faith report within one business day and will not pursue researchers who act within a coordinated disclosure.
Regulator
You may complain directly to the Information Regulator of South Africa at any time.

Back to the main site