Imara Stride

Data Privacy and Protection Policy

Aligned to the Uganda Data Protection and Privacy Act, 2019, the EU General Data Protection Regulation (GDPR), and applicable U.S. privacy standards.

Document ownerCrawl Walk Run Digital Solutions Ltd
Version1.1
StatusConfirmed
Governing lawUganda Data Protection and Privacy Act, 2019
Applies toImara Stride, all modules, CWR staff, field agents, authorised distributors and their CWR-certified agents, and contracted institutional partners.

1. Purpose and Scope

This policy sets out how Crawl Walk Run Digital Solutions Ltd (“CWR,” “the Company”), trading the Imara Stride platform, collects, uses, stores, shares, and protects personal data. It applies to data processed through all Imara Stride modules — Business Profile, Service Identification, Members/Partners, Customers, Sales, Inventory, Procurement (Suppliers, RFQs, Purchase Orders, Goods Receipt Notes, Supplier Bills, Payments), Assets, Expenses, Finance Ledger, Surveys, Files, Approvals, GPS, and Reports — and to data handled by CWR staff, field agents, authorized distributors and their CWR-certified agents, and any institutional partner or sub-processor acting on the Company's behalf.

The policy governs three categories of people whose data Imara Stride may process:

Local Partners — the MSEs, NGOs/CSOs, SACCOs, and MFIs who use Imara Stride to record their own

business, programme, or member data.

Individuals within Local Partners — owners, staff, members, customers, suppliers, and beneficiaries

whose personal data is recorded inside those modules (e.g., a customer in the Customer Directory, a supplier in Procurement, a member in Members/Partners).

CWR's own people and counterparties — employees, field agents, authorized distributors and their

certified agents, contractors, institutional partners, and investors.

Where this policy refers to “personal data,” it means any information relating to an identified or identifiable natural person, consistent with the definition used in the Uganda Data Protection and Privacy Act, 2019 (“Uganda DPPA”) and the EU GDPR.

CWR is incorporated in Uganda and the large majority of Local Partners and individuals whose data the platform processes are located in Uganda and elsewhere in East Africa. The policy is therefore built in three layers, applied in this order of priority:

2.1 Primary law: Uganda Data Protection and Privacy Act, 2019

The Uganda DPPA, together with the Data Protection and Privacy Regulations, 2021, and the Personal Data Protection Office (PDPO) under NITA-U, is the binding legal regime for CWR's processing activities. Under current PDPO guidance (including its July 2025 decision concerning unregistered controllers), registration as a data controller and/or data collector with the PDPO is mandatory for any entity processing personal data of persons in Uganda unless and until a specific gazetted exemption applies — CWR has no exemption and must register (see Section 12).

2.2 Reference standard: EU General Data Protection Regulation (GDPR)

The GDPR does not apply to CWR by default — it applies based on the location and citizenship of data subjects and the location of establishment, not the nationality of a donor or funder. CWR adopts GDPR principles as a voluntary best-practice benchmark for three practical reasons: (a) institutional partners and funders — the EU, FCDO, World Bank, and EU-headquartered NGOs — increasingly write GDPR-equivalent data protection clauses into grant and sub-contract agreements; (b) GDPR is the most demanding of the frameworks referenced here, so designing to it generally satisfies the Uganda DPPA and most US contractual requirements as well; and (c) it strengthens CWR's procurement readiness alongside INPAS compliance. If CWR onboards an EU-based Local Partner, EU staff member, or EU data subject directly, the relevant GDPR obligations become directly binding rather than aspirational, and this policy should be reassessed at that point.

2.3 Contextual standard: United States privacy law

The United States has no single comprehensive federal privacy law. CCPA/CPRA (California) applies only to entities meeting specific revenue or data-volume thresholds and processing the data of California residents — CWR does not currently meet these thresholds. US relevance to CWR instead arises contractually: USAID and other US government-funded partners typically impose their own data management, PII handling, and “do no harm” data clauses in awards and sub-awards, and these should be tracked per-contract rather than assumed. This policy adopts CCPA-style individual rights language (the right to know, delete, and opt out of sale/sharing of personal information) as a contractual-readiness measure, recognising it may apply if CWR onboards US-based users (e.g., through the identified Jamaica/Caribbean expansion or a US-based institutional partner with its own staff data in the system).

2.4 Where the three frameworks differ

Topic Uganda DPPA (binding) GDPR (reference) US / CCPA-style (contractual) Registration with regulator Mandatory unless gazetted exemption No general registration; records of processing required No general registration Lawful basis required Consent or other DPPA ground Consent, contract, legitimate interest, etc. (Art. 6) Notice and opt-out model; optin for sale of minors’ data Sensitive data Extra consent/safeguards for sensitive personal data Special category data (Art. 9) — stricter conditions “Sensitive personal information” opt-out right (CPRA) Breach notification Immediate notice to PDPO; PDPO decides on subject notice 72 hours to supervisory authority where feasible Varies by state; contractspecific timelines Cross-border transfer Permitted with consent or adequate safeguards in recipient country (s.19) Adequacy decision, SCCs, or other Art. 46 safeguard No general restriction; contract may impose one Individual rights Access, correction, deletionstyle rights under DPPA Access, rectification, erasure, portability, objection Know, delete, correct, opt-out of sale/sharing This comparison is a working summary, not legal advice. It should be reviewed by Ugandan counsel (Director N.

Swabra) and, before any EU or US data subject is onboarded directly, by counsel qualified in that jurisdiction.

2.5 Distributor jurisdictions (Ethiopia, Somaliland and future markets)

Where CWR delivers Imara Stride through an authorized distributor in another jurisdiction, that jurisdiction’s data-protection law forms a fourth, territory-specific layer, applied to processing that takes place there in the same order-of-priority logic used for the Uganda DPPA at home, tracked under Section 14 and confirmed with local counsel before Local Partners are onboarded. Imara Stride currently operates in Ethiopia (Somali Regional State) and Somaliland through Aspire Nexus Consulting; Ethiopia’s Personal Data Protection Proclamation (2024) and any applicable Somaliland requirements are treated as the binding local layer for processing carried out there.

3. Roles and Responsibilities

3.1 Privacy lead

CWR designates a Privacy Lead (recommended: Director & Counsel, supported by the Founder/Managing Director) responsible for: maintaining this policy, the data inventory, and the record of processing activities; completing and maintaining PDPO registration; coordinating breach response; reviewing institutional contracts for data protection terms; and acting as point of contact for individual rights requests and regulator correspondence.

3.2 Controller and processor roles

Two distinct roles run through the platform, and both must be documented per-contract:

CWR as controller — for data CWR collects and decides the purpose of in its own right: employee and

agent records, institutional partner contacts, billing and subscription data, marketing and demorequest data, and platform usage/security logs.

CWR as processor — for data a Local Partner enters or has entered on its behalf into its own modules

(Sales, Customers, Members/Partners, Expenses, Finance Ledger, Inventory, Procurement, Assets, Surveys, GPS). The Local Partner is the controller of this data; CWR (and its agents) process it strictly on the Local Partner's instructions, including during the Crawl phase when a CWR agent performs data entry for the client.

Every institutional contract and every individual Local Partner subscription agreement must include, or attach as an addendum, the data processing terms summarised in Appendix B, regardless of contract size.

3.3 Local Partner responsibilities

As controller of its own records, each Local Partner is responsible for: having a lawful basis to collect the personal data it enters (e.g., member or customer consent); informing its own staff, members, customers, suppliers, and beneficiaries that their data is recorded on Imara Stride and how to exercise their rights; and promptly correcting or removing data on request. CWR provides the tools and, on request, template notices and consent language to support this; CWR does not collect consent on a Local Partner's behalf except where it is itself acting as controller (Section 3.2).

3.4 Authorized distributors and certified agents

An authorized distributor appointed by CWR (for example, Aspire Nexus Consulting) and its service agents act as processors — and, where they engage their own personnel, as sub-processors — of the personal data they handle when delivering Imara Stride. They process personal data only to deliver the contracted service, strictly under this policy, their distribution agreement with CWR, and the instructions of the relevant controller (CWR or the Local Partner).

Certified agents only — a distributor may deploy only CWR-certified agents to onboard, train or coach Local Partners; certification, re-certification and withdrawal are governed by CWR’s Agent Certification Process.

Flow-down obligations — the confidentiality, access-control, security, sensitive-data (GESI) and breachnotification requirements of this policy apply to the distributor and its agents, and are reflected in the distribution agreement.

No independent data holding — the distributor obtains no independent or exportable copy of MSE records or the platform database (see Section 8); records remain hosted on the platform.

4. Data Inventory: What Is Collected, Where, and Why

This inventory reflects the platform's current module structure and must be updated whenever a module, field, or integration changes — it is CWR's working Record of Processing Activities (the GDPR Art. 30 equivalent) and satisfies the Uganda DPPA's expectation that controllers document their processing.

Module Typical personal data Whose data Purpose Sensitivity Business Profile / Service Identification Owner/director name, national ID or business registration number, contact details, location Local Partner owner/representative Onboarding, identity verification, account setup Standard Members/Partners Name, contact details, role, shareholding or membership status, ID number SACCO/cooperative members, business partners Membership records, governance, payouts Standard — may include ID numbers Customers (Directory, Invoices, Payments, Receipts, Delivery Notes, Sales) Customer name, contact details, transaction history, payment method/reference Local Partner's customers Sales recording, invoicing, payment reconciliation Standard — payment data needs care Procurement (Suppliers, RFQs, Purchase Orders, Goods Receipt Notes, Supplier Bills, Payments) Supplier contact name, business and bank/mobile-money payment details Local Partner's suppliers Purchasing, payment processing Elevated — financial account details Expenses / Finance Ledger / Reports (P&L, Balance Sheet, Cash Flow, AR/AP Aging) Transaction-level financial data, may include payee names Local Partner and counterparties Bookkeeping, automated financial statements Standard, financially sensitive Assets / Asset Register Asset custodian name, location, assigned staff Local Partner staff Fixed asset tracking Standard Module Typical personal data Whose data Purpose Sensitivity Surveys (GESI / INPAS reporting) Gender, age bracket, disability status, household or beneficiary data Beneficiaries, members, programme participants Donor-required disaggregated reporting Sensitive — special category data GPS Location data tied to a business, asset, or field visit Local Partner staff/agents, assets Field verification, logistics, service mapping Elevated — location can reveal patterns of life Files / Approvals Uploaded documents (IDs, contracts, photos), approver identity and decision trail Varies by upload Document storage, audit trail, rolebased sign-off Varies — may contain ID documents CWR-controlled: HR, agents, accounts, billing Employee/agent ID, payroll and bank details, contracts, performance records, partner/investor contacts CWR staff, agents, institutional contacts, investors Employment, payroll, contracting, fundraising Elevated — payroll and ID data

5. Lawful Basis for Processing

CWR relies on the following bases, mapped to the closest equivalent ground in each framework:

Contract performance — onboarding a Local Partner, providing the subscription service, and

processing the records that service requires (DPPA general processing condition; GDPR Art. 6(1)(b); CCPA business purpose).

Consent — for sensitive/special category data collected via Surveys (gender, disability, agedisaggregated data), and for any marketing communications. Consent must be specific, informed, and

recorded, and must be obtainable from the actual data subject or, for beneficiary survey data collected by a Local Partner, documented as the Local Partner's responsibility under Section 3.3.

Legitimate interest — for platform security, fraud prevention, and service improvement analytics,

balanced against individual rights and not used for sensitive data.

Legal obligation — for data CWR must keep to satisfy Ugandan tax, companies, or labour law, or PDPO

regulatory requirements.

CWR does not sell personal data. Where a CCPA-style “sharing” analysis applies (e.g., cross-context analytics or advertising integrations), none is currently in use; if introduced, this section must be updated and an opt-out mechanism added before launch.

6. Sensitive and Special Category Data (GESI Data)

Gender, age, and disability-disaggregated data collected for GESI (Gender Equality and Social Inclusion) and INPAS donor reporting is sensitive personal data under the Uganda DPPA and special category data under GDPR Art. 9. It requires handling beyond the platform's standard controls:

Explicit, separately recorded consent from the data subject, or documented justification where

collected by a Local Partner under its own statistical/donor-reporting basis.

Field- and role-level access restriction within the Surveys module — not visible by default to all

platform users with access to a Local Partner's account.

Aggregation and de-identification before inclusion in donor reports wherever the report does not

require individual-level detail.

Exclusion from routine analytics, exports, or sub-processor access unless specifically authorised.

Action item: confirm with the Director & Counsel whether current Survey module field-level permissions meet this standard before the next donor reporting cycle.

7. Data Collection and the Crawl → Walk → Run Model

Imara Stride's adoption model has a direct privacy implication: during the Crawl phase, a CWR-certified agent (whether CWR own field agent or an authorized distributor certified agent) enters a Local Partner's records on its behalf, often from paper source documents. This means CWR (through its agents) has handson access to personal data before the Local Partner is independently managing it. Controls required at each stage:

Crawl — agent-entered data

Agents collect only the data fields the relevant module requires; no incidental personal data (e.g.,

photographing a full notebook page) should be retained beyond what is entered.

Agents — including an authorized distributor’s certified agents — are bound by a confidentiality

undertaking and access only the Local Partners assigned to them. Authorized distributors process personal data strictly under this policy and their distribution agreement with CWR, and may deploy only CWR-certified agents (see CWR’s Agent Certification Process).

Source paper documents handled during Crawl are returned to the Local Partner or securely

destroyed — not retained by CWR.

Walk — coached self-entry

Access shifts to the Local Partner's own users; CWR agent access becomes view/coach-level rather

than edit-level, logged via the platform's Approvals/role-based access controls.

Run — independent operation

CWR retains administrative/support access only, consistent with the subscription agreement and this

policy's access-control rules (Section 9).

8. Use, Sharing, and Disclosure of Data

CWR shares personal data only as follows:

With the Local Partner itself and its authorised users — the data is theirs; CWR provides access, not

ownership.

With infrastructure sub-processors — the cloud hosting provider and any analytics, email, or SMS

providers strictly necessary to run the platform, under a written agreement that flows down the same protections as this policy (see Appendix C).

With an institutional partner that funded onboarding — limited to the consolidated, aggregate

reporting it is contractually entitled to (e.g., portfolio dashboards, INPAS compliance reports), not raw individual-level Local Partner records, unless the Local Partner has separately agreed to that level of sharing.

With regulators or law enforcement — only where legally required, and logged.

CWR maintains a current list of sub-processors and makes it available to institutional partners and Local Partners on request. Standard data sharing terms are set out in Appendix B.

Platform-hosted records. MSE records remain hosted on, and accessed through, the Imara Stride platform.

Local Partners and the individuals in their records retain ownership of their own data; CWR provides access, not ownership, and authorized distributors and their agents obtain no independent or exportable copy of MSE records or the platform database, and no right to migrate records off the platform. This preserves continuity for Local Partners and donors and limits the spread of personal data.

9. Data Security Measures

9.1 Technical measures

Encryption of data in transit (TLS) and at rest in the hosting environment.

Role-based access control across modules, consistent with the platform's existing Approvals structure

— access scoped to what a user's role requires.

Authentication controls for all platform accounts, with stronger controls (e.g., 2FA) for administrative

and agent accounts.

Secure local storage and encrypted sync for the offline-first capability, given devices may be lost or

shared in low-connectivity field settings.

Audit logging of record creation, edits, and approvals (supporting both the audit-trail value

proposition and breach investigation).

9.2 Organizational measures

Confidentiality undertakings for all CWR staff and agents prior to data access.

Annual (minimum) privacy and security training for staff and agents, with additional onboarding

training for new agents before Crawl-phase data entry.

Device security requirements for field agents (PIN/passcode lock, remote-wipe capability where

feasible, prompt reporting of lost devices).

Vendor due diligence before engaging any new sub-processor that will touch personal data.

10. Data Retention and Deletion

Retention periods balance the platform's value proposition (multi-year audit trails for credit and donor purposes) against the data minimisation principle common to all three frameworks. Defaults, to be confirmed with counsel and adjusted per contract:

Data category Default retention Basis Active Local Partner financial/operational records (Sales, Finance Ledger, Inventory, Procurement, Assets) Duration of subscription + 7 years after closure Aligns with Ugandan tax/financial record-keeping norms and credit/donor evidentiary value Survey/GESI sensitive data Duration required for the specific donor reporting cycle, then anonymised or deleted Minimisation principle for sensitive data GPS location data 12 months rolling, unless tied to an open asset/audit record Limits exposure of movement patterns Marketing/demo-request data (noncustomers) 24 months from last contact, or until opt-out Legitimate interest must be timebound CWR employee/agent HR records Per Ugandan labour law minimums (currently up to 7 years postemployment for relevant records) Legal obligation Account closure / Local Partner offboarding Export provided to Local Partner; CWR copy deleted or anonymised within 90 days unless a legal hold applies Right to deletion / data minimisation Agent / distributor certification records Duration of the agent’s certification validity (currently 24 months) plus a reasonable audit period after it lapses Supports the CWR Agent Certification Register and deliveryquality accountability

11. Individual Rights and Request Handling

Subject to verification of identity, individuals may request, consistent with the strongest applicable standard across the three frameworks:

Access to the personal data held about them.

Correction of inaccurate data.

Deletion, where no legal or contractual basis requires retention.

An export of their data in a usable format (portability).

Objection to, or opt-out of, processing based on legitimate interest, marketing, or (if ever introduced)

sale/sharing of personal information.

Requests concerning data inside a Local Partner's own modules (e.g., a customer asking about their record in a Local Partner's Customer Directory) should be directed first to the Local Partner as controller; CWR will support fulfilment within the platform's tools. Requests concerning data CWR controls directly (employee, agent, institutional contact, or billing data) are handled by the Privacy Lead within 30 days (Uganda DPPA / GDPR-aligned) or 45 days (CCPA-aligned) of verified receipt, whichever is shorter.

12. Data Breach Notification Procedure

Where CWR believes personal data has been accessed, lost, or acquired without authorisation:

1. Contain and assess — the Privacy Lead and technical lead immediately assess scope, cause, and

ongoing risk, and take containment action.

2. Notify the PDPO immediately — the Uganda DPPA requires immediate notification to the Personal

Data Protection Office of unauthorised access/acquisition and remedial action taken; this is not discretionary and is the controlling deadline (stricter, in practice, than GDPR's 72-hour standard).

3. Await/apply the PDPO's determination on subject notice — under the DPPA, the PDPO determines

whether and how affected individuals must be notified (registered email, postal mail, website notice, or media, as directed).

4. Apply GDPR-aligned timelines as a backstop — if any EU data subject is plausibly affected, notify the

relevant supervisory authority within 72 hours of becoming aware, in parallel with the PDPO process.

5. Notify affected institutional partners — per the notification timeline in each institutional contract, and

in any event without undue delay.

6. Document and review — record the breach, response, and remedial/preventive action in a breach

register; review at the next policy review cycle.

Maintain current PDPO contact details and an internal breach contact list as a living annex to this policy, not embedded here, since contact details change independently of policy substance.

13. Cross-Border Data Transfers

Under Uganda DPPA s.19, CWR may store or process personal data outside Uganda (for example, with an international cloud hosting provider) only where (a) the data subject has consented to the transfer, or (b) the recipient country/provider has data protection safeguards at least equivalent to the DPPA. CWR is not required to seek PDPO pre-approval for each transfer but must keep records of the legal basis and safeguards relied on, available for inspection.

Confirm and document the physical hosting location(s) of Imara Stride's cloud infrastructure and any

sub-processors.

Where hosting sits outside Uganda, document the safeguard relied on (e.g., the provider's own data

protection certifications, contractual data protection terms, or, where relevant, EU Standard Contractual Clauses if data flows through an EU-based provider).

Update Local Partner-facing notices to disclose, in plain language, that data may be stored outside

Uganda and why.

Consistent with Section 8, records remain hosted on the platform; institutional partners and authorized distributors receive reporting and scoped platform access rather than raw exports of individual-level records, which limits the onward transfer of personal data.

14. Regulatory Registration and Accountability

Register CWR with the Uganda PDPO as a data controller and data collector without delay — current

PDPO enforcement practice treats registration as mandatory pending a gazetted exemption, and operating unregistered carries enforcement risk.

Maintain this policy, the data inventory (Section 4), the breach register, and the sub-processor list as

the core accountability documentation, reviewed at least annually or on material change.

Track data-subject exposure and local data-protection obligations as the company expands. Imara

Stride now operates in Ethiopia (Somali Regional State) and Somaliland through an authorized distributor (Aspire Nexus Consulting); Ethiopia’s Personal Data Protection Proclamation (2024) and any applicable Somaliland requirements should be tracked and confirmed with local counsel as Local Partners are onboarded there. Continue to monitor EU and US data-subject exposure (including any Jamaica/Caribbean or future EAC markets) and escalate to qualified local counsel before GDPR or US state-law obligations could be triggered directly rather than contractually.

Build data protection review into new institutional contracts and new platform modules/features as a

standing step, not an afterthought.

15. Policy Review and Governance

This policy is reviewed at least annually by the Privacy Lead and approved by the Founder/Managing Director, and immediately upon: a material change in the platform's modules or data flows; a new jurisdiction of operation; a confirmed data breach; or a material change in Ugandan, EU, or relevant US law.

Version history is maintained on the cover page.

Appendix A — Public-Facing Privacy Notice (Plain-Language Summary)

This appendix is intended to be lifted out and published on the Imara Stride website/app as a standalone notice, and adapted into a printed or read-aloud version for low-literacy field use during onboarding.

What this notice covers

This notice explains, in plain language, how Imara Stride and Crawl Walk Run Digital Solutions Ltd (“we,” “CWR”) handle personal data when you use the Imara Stride platform — whether you are a business owner, NGO/CSO staff member, SACCO/MFI member, or someone whose details are recorded by one of our Local Partners (for example, as a customer or supplier).

What we collect

Depending on how Imara Stride is used by your organisation, we may process: your name and contact details; identification or registration numbers; business, membership, or transaction records; financial and payment details; location data for field verification; and, where relevant to donor reporting, gender, age, or disability information that you or your organisation have agreed to share.

Why we collect it

To set up and run your account; to generate your financial and operational records and reports automatically; to support you during onboarding (including, where you have asked for it, our agents entering records on your behalf); to meet legal, tax, and donor reporting obligations; and to keep the platform secure.

Who sees it

Your organisation's authorised users; CWR staff and agents who support your account, bound by confidentiality; our hosting and technical service providers, under contract; and, only where you or your organisation has agreed, an institutional partner that funded your onboarding, in aggregate/summary form rather than your individual records.

Where it is stored

Your data is stored securely, including on cloud infrastructure that may be located outside Uganda. Where that is the case, we apply safeguards consistent with the Uganda Data Protection and Privacy Act, 2019, and, as a matter of good practice, principles drawn from the EU GDPR.

Your rights

You can ask to see the personal data we (or your organisation, where it is the controller) hold about you, ask us to correct it, ask for it to be deleted where we are not required to keep it, ask for a copy in a usable format, and object to certain uses. To make a request, contact your organisation first if the data is theirs, or contact us directly using the details below.

Contact

Crawl Walk Run Digital Solutions Ltd — cwrdigitalsolutionsltd@gmail.com — Entebbe, Uganda · +256 775 082 120 · imarastride.com.

Appendix B — Data Processing Agreement: Key Terms Checklist

Use this checklist when negotiating an institutional contract (donor, NGO, SACCO/MFI, or other partner that funds onboarding of multiple Local Partners) or a direct Local Partner subscription agreement involving personal data. Attach or reference as a data protection addendum.

Term Minimum requirement Roles Confirms which party is controller and which is processor for each category of data, consistent with Section 3.2.

Scope and purpose Processing is limited to what is needed to deliver the contracted service; no secondary use without written agreement.

Sub-processors CWR may use listed sub-processors (hosting, messaging, etc.); partner is notified of material changes.

Security Sub-processor and CWR apply technical/organisational measures consistent with Section 9 of this policy.

Sensitive/GESI data Additional consent, restricted access, and aggregation rules from Section 6 apply; no use beyond agreed reporting.

Cross-border transfer Discloses hosting location(s) and the safeguard relied on under Uganda DPPA s.19 (Section 13).

Breach notification CWR notifies the partner without undue delay, and in any event within the contract's specified window, following the procedure in Section 12.

Audit/INPAS support Role-based access, audit trails, and disaggregated reporting available to support the partner's donor compliance (INPAS, GESI).

Retention and return On contract end, data is exported to the partner/Local Partner and CWR's copy deleted or anonymised per Section 10.

Liability and termination Material breach of data protection terms is a basis for termination, addressed in the main commercial contract.

Appendix C — Glossary

Term Meaning CWR Crawl Walk Run Digital Solutions Ltd, the company that builds and operates Imara Stride.

Local Partner An MSE, NGO/CSO, SACCO, or MFI that uses Imara Stride to manage its own records.

PDPO Personal Data Protection Office, Uganda's data protection regulator under NITA-U.

Uganda DPPA The Data Protection and Privacy Act, 2019 (Uganda), and its 2021 Regulations.

GDPR The EU General Data Protection Regulation (Regulation (EU) 2016/679).

CCPA/CPRA The California Consumer Privacy Act, as amended by the California Privacy Rights Act.

GESI Gender Equality and Social Inclusion — donor-required disaggregated reporting by gender, age, and disability.

INPAS International Non-Profit Accounting Standard — a donor-facing financial reporting benchmark for NGOs/CSOs.

Controller The party that decides why and how personal data is processed.

Processor The party that processes personal data on a controller's instructions.

Sub-processor A third party engaged by CWR to support processing (e.g., cloud hosting

Data protection contactJeffrey Campbell, Founder & Managing Directorcwrdigitalsolutionsltd@gmail.com+256 775 082 120