Protecting learner data is fundamental to how we run Ubora Institute. This statement describes the technical and organisational measures we take to keep your information safe.
1. Encryption in transit
All traffic between your device and the platform is protected with HTTPS/TLS, so information cannot be read by third parties on the network.
2. Secure database storage
Learner data is stored in a managed, hosted database with encryption at rest, automated backups, and network-level isolation.
3. Role-based access controls
Row-Level Security policies enforce that learners can only read and edit their own data. Administrative access is limited to a small number of authorised staff and every privileged action is auditable.
4. International privacy standards
We align our practices with widely recognised privacy principles including the Kenya Data Protection Act and, where applicable, the EU General Data Protection Regulation (GDPR).
5. Data retention
- Account and profile data: retained while your account is active, then archived or deleted upon request.
- Payment records: retained as required by tax and accounting law (typically up to 7 years).
- Course progress and certificates: retained so that certificates remain verifiable.
- Server and security logs: retained for a limited period for security investigations.
6. Breach notification
If we discover a personal-data breach that is likely to result in a risk to your rights, we will notify affected users and the relevant supervisory authority without undue delay, in line with applicable law.
7. Your responsibilities
- Use a strong, unique password for your account.
- Do not share your login details with anyone.
- Report suspicious activity to us as soon as possible.
8. Contact
Security or data-protection concerns? uborainstituteofdigitalskills@gmail.com
