Privacy Policy
A legal disclaimer
TULLANY PRIVACY POLICY
Effective Date: [28/06/2025]
Last Updated: [29/06/2025]
1. INTRODUCTION
TULLANY HOLDINGS LIMITED ("we," "our," or "us") is committed to protecting your privacy and personal data in accordance with the Data Protection and Privacy Act 2019 of Uganda and other applicable laws. This Privacy Policy explains how we collect, use, process, store, and protect your personal information when you interact with our services, website, or organization.
Data Protection Registration: TULLANY HOLDINGS LIMITED is registered with the Personal Data Protection Office (PDPO) under registration number [Insert Registration Number].
2. WHO WE ARE
Organization Name: TULLANY HOLDINGS LIMITED
Physical Address: Kitala, Wakiso, Entebbe, Uganda
Postal Address: P.O Box 701980, Entebbe, Uganda
Email: info@tullany.org
Phone: (+256) (0) 742 014277
Website: www.tullany.org
Data Protection Officer: [Insert Name and Contact Details]
3. INFORMATION WE COLLECT
3.1 Personal Data We Collect
We may collect the following types of personal data:
Identity Information:
-
Full name
-
Date of birth
-
Gender
-
Nationality
-
Identification numbers (National ID, passport number)
-
Photographs
Contact Information:
-
Physical address
-
Postal address
-
Email address
-
Phone numbers
-
Emergency contact details
Professional Information:
-
Employment details
-
Educational background
-
Professional qualifications
-
Work experience
Financial Information:
-
Bank account details
-
Payment information
-
Transaction records
-
Financial assistance records
Technical Information:
-
IP address
-
Browser type and version
-
Device information
-
Website usage data
-
Cookies and tracking data
Special Categories of Personal Data: We may process special categories of personal data including:
-
Health information (where relevant to our services)
-
Information about vulnerable individuals
-
Biometric data (if applicable)
3.2 How We Collect Information
We collect personal data through:
-
Direct interactions (forms, applications, communications)
-
Our website and digital platforms
-
Third parties (partners, service providers)
-
Public records and databases
-
Event participation and registrations
4. LEGAL BASIS FOR PROCESSING
We process your personal data based on the following legal grounds under the Data Protection and Privacy Act 2019:
-
Consent: You have given clear, informed consent for specific purposes
-
Legal Obligation: Processing is required by Ugandan law
-
Legitimate Interests: Processing is necessary for our legitimate organizational interests
-
Vital Interests: Processing is necessary to protect someone's life
-
Public Task: Processing is necessary for tasks carried out in the public interest
5. HOW WE USE YOUR INFORMATION
5.1 Primary Purposes
We use your personal data for:
Service Delivery:
-
Providing our programs and services
-
Managing beneficiary relationships
-
Delivering support and assistance
-
Coordinating activities and events
Communication:
-
Responding to inquiries and requests
-
Sending important updates and notifications
-
Marketing communications (with consent)
-
Emergency communications
Operations and Administration:
-
Record keeping and reporting
-
Financial management and accounting
-
Compliance with legal requirements
-
Risk management and security
Improvement and Development:
-
Analyzing service effectiveness
-
Research and evaluation
-
Developing new programs
-
Quality improvement initiatives
5.2 Marketing Communications
We will only send you marketing communications if:
-
You have given explicit consent, or
-
You are an existing participant/beneficiary and the communications relate to similar services
You can opt out of marketing communications at any time by:
-
Clicking unsubscribe links in emails
-
Contacting our Data Protection Officer
-
Updating your preferences on our website
6. INFORMATION SHARING AND DISCLOSURE
6.1 When We Share Information
We may share your personal data with:
Internal Teams: Authorized staff members who need access to perform their duties
Service Providers: Third-party organizations that help us deliver services, including:
-
IT support providers
-
Financial service providers
-
Legal and professional advisors
-
Marketing and communications agencies
Partners and Collaborators:
-
Government agencies (when required by law)
-
Other NGOs and charitable organizations
-
Donors and funding organizations
-
Research institutions
Legal Requirements:
-
When required by court orders or legal processes
-
To comply with regulatory requirements
-
To protect rights, property, or safety
6.2 Data Sharing Principles
We ensure that:
-
Data sharing agreements are in place
-
Recipients have adequate security measures
-
Only necessary information is shared
-
Recipients understand their obligations
-
Data subjects are informed when appropriate
7. INTERNATIONAL DATA TRANSFERS
If we transfer your personal data outside Uganda, we ensure:
-
The destination country has adequate data protection measures equivalent to Uganda's DPPA 2019, or
-
We have obtained your explicit consent, or
-
Appropriate safeguards are in place through binding agreements
Current International Transfers: [List any regular transfers to other countries]
8. DATA SECURITY
8.1 Security Measures
We implement appropriate technical and organizational measures to protect your personal data:
Technical Safeguards:
-
Encryption of sensitive data
-
Secure servers and databases
-
Regular security updates and patches
-
Access controls and authentication
-
Backup and recovery systems
Organizational Safeguards:
-
Staff training on data protection
-
Clear data handling procedures
-
Regular security assessments
-
Incident response procedures
-
Access restrictions based on roles
8.2 Data Breach Notification
In case of a data security breach:
-
We will investigate and contain the breach immediately
-
The PDPO will be notified within 72 hours if required
-
Affected individuals will be notified without undue delay
-
We will take steps to minimize harm and prevent recurrence
9. DATA RETENTION
9.1 Retention Periods
We retain personal data only for as long as necessary:
Beneficiary Records: 7 years after program completion Financial Records: 7 years as required by law Employee Records: 7 years after employment ends Website Data: 2 years unless deleted earlier Marketing Data: Until consent is withdrawn Legal Documents: As required by applicable laws
9.2 Secure Disposal
When retention periods expire, we securely delete or destroy personal data in a manner that prevents reconstruction in an intelligible form.
10. YOUR RIGHTS
Under the Data Protection and Privacy Act 2019, you have the following rights:
10.1 Right of Access
You can request:
-
Confirmation that we process your personal data
-
Access to your personal data
-
Information about how we use your data
10.2 Right to Rectification
You can request correction of:
-
Inaccurate personal data
-
Incomplete personal data
10.3 Right to Erasure
You can request deletion of your personal data when:
-
It's no longer necessary for the original purpose
-
You withdraw consent
-
Data has been unlawfully processed
-
Legal obligation requires deletion
10.4 Right to Restrict Processing
You can request limitation of processing when:
-
You contest the accuracy of data
-
Processing is unlawful
-
We no longer need the data but you need it for legal claims
10.5 Right to Object
You can object to processing based on:
-
Legitimate interests
-
Direct marketing purposes
-
Research or statistical purposes
10.6 Rights Related to Automated Decision-Making
You have the right not to be subject to automated decision-making, including profiling, that produces legal effects or significantly affects you.
11. EXERCISING YOUR RIGHTS
11.1 How to Make Requests
To exercise your rights, contact us:
-
Email: [Data Protection Email]​
-
Post: [Data Protection Officer Address]
-
Online Form: [Website Link if applicable]
11.2 Response Times
We will respond to your requests:
-
Acknowledgment: Within 3 working days
-
Full Response: Within 30 days (may be extended by 60 days for complex requests)
11.3 Verification
We may request additional information to verify your identity before processing requests.
12. CHILDREN'S PRIVACY
12.1 Age Restrictions
We do not knowingly collect personal data from children under 18 without appropriate consent:
-
Under 13: Parental/guardian consent required
-
13-17: Parental/guardian consent or mature minor assessment
12.2 Special Protections
For children's data, we:
-
Implement enhanced security measures
-
Limit data collection to what's necessary
-
Provide clear, age-appropriate privacy information
-
Allow parents/guardians to access and control their child's data
13. COOKIES AND WEBSITE TRACKING
13.1 Types of Cookies
Our website uses:
-
Essential Cookies: Necessary for website functionality
-
Analytics Cookies: To understand website usage
-
Marketing Cookies: For personalized advertising (with consent)
13.2 Cookie Consent
You can:
-
Accept or reject non-essential cookies
-
Change cookie preferences anytime
-
Delete cookies through browser settings
Cookie Policy: [Link to detailed cookie policy]
14. COMPLAINTS AND DISPUTES
14.1 Internal Complaints
If you're concerned about how we handle your personal data:
-
Contact our Data Protection Officer
-
We'll investigate and respond within 30 days
-
We'll work with you to resolve the issue
14.2 External Complaints
You have the right to lodge a complaint with:
Personal Data Protection Office (PDPO)
-
Address: National Information Technology Authority - Uganda
-
Website: www.pdpo.go.ug
14.3 Legal Remedies
You may seek compensation through the courts of Uganda for:
-
Material damage from data protection violations
-
Non-material damage (distress, inconvenience)
15. POLICY UPDATES
15.1 Changes to This Policy
We may update this Privacy Policy to:
-
Comply with legal changes
-
Reflect new services or practices
-
Improve clarity and transparency
15.2 Notification of Changes
We will notify you of significant changes by:
-
Email to registered users
-
Website announcements
-
Direct communication for major changes
Version Control:
-
Current Version: [0.1]
-
Previous Versions: Available upon request
16. CONTACT INFORMATION
16.1 General Inquiries
TULLANY HOLDINGS LIMITED
P.O Box 701980, Entebbe, Uganda
Email: info@tullany.org
Phone: (+256) (0) 742 014277
16.2 Data Protection Matters
Data Protection Officer
[Tullany]
Email: [DPO Email] info@tullany.org
Phone: [DPO Phone] : (+256) (0) 742 014277
ACKNOWLEDGMENT
By using our services or providing your personal data, you acknowledge that you have read, understood, and agree to this Privacy Policy.
-
Document Reference: TULLANY-HOLDINGS-PP-2024-v1.0
This Privacy Policy is prepared in compliance with the Data Protection and Privacy Act 2019 of Uganda and other applicable laws. For the most current version, please visit our website.
