Back to home
Data Protection

Compliance is the floor. Protection is the commitment.

Tanzania's data protection framework creates obligations for organisations like ours. We treat those obligations as a starting point, not an endpoint — because the families who trust us with their children's data deserve more than legal minimum compliance.

Last updated: July 2026 United Republic of Tanzania Jali Global Tech Limited

This document describes how Jali Global Tech Limited complies with Tanzania's Personal Data Protection Act No. 11 of 2022 (PDPA), explains the legal bases on which we process your data, and sets out the full framework of rights available to you as a data subject.

01

Data Controller Identity

The data controller for all personal data processed through Math GiG is:

  • Entity name: Jali Global Tech Limited
  • Registration: Incorporated under the Companies Act (Cap. 212), United Republic of Tanzania
  • Registered office: P.O. Box 1234, Arusha, Tanzania
  • Data Protection Officer: info@jaliglobaltech.com
  • General contact: info@jaliglobaltech.com

As data controller, Jali Global Tech Limited determines the purposes and means of processing personal data collected through Math GiG. We process data in compliance with Tanzania's Personal Data Protection Act No. 11 of 2022 (“PDPA”) and its implementing regulations.

03

Categories of Personal Data We Hold

The following table summarises the categories of personal data we hold, the purpose of processing, and how long we retain it:

CategoryExamplesPurposeRetention
Identity dataParent full name, email, phone numberAccount access, communicationsAccount lifetime + 30 days post-deletion
Child identity dataChild first name, grade, birth yearLearning personalisationWhile profile exists; deleted within 30 days of removal
Learning dataQuestions answered, accuracy, XP, levels, streaksAdaptive difficulty, dashboard, rewardsAccount lifetime; anonymised on account deletion
Financial dataSubscription amounts, payment references, wallet balance, withdrawal historyBilling, coin economy, wallet7 years (Tanzania Tax Administration Act)
Device and usage dataDevice type, OS, session times, features used, crash logsService delivery, bug fixing, aggregate analytics90 days (logs); 2 years (aggregated analytics)
CommunicationsSupport emails, in-app messages to support teamIssue resolution2 years from last contact
Battle dataMatch outcomes, opponents' grade (anonymised)Fair play, leaderboards2 years then anonymised

We do not process special category data (health, biometric, political, religious, or financial credit data) and have no intention to do so.

04

International Data Transfers

Math GiG's infrastructure involves transfers of personal data outside Tanzania to the following sub-processors. Each transfer is protected by contractual safeguards:

Supabase Inc. (United States / EU)

Our production database and file storage run on Supabase, with data stored in the EU West (Frankfurt) region. Supabase is ISO 27001 certified and processes data under a GDPR-compliant Data Processing Agreement. Data in the EU region does not leave EU territory under normal operations.

Vercel Inc. (United States)

Our web application is hosted on Vercel's global edge network. Server-side rendering occurs in the nearest Vercel region. Vercel operates under its Data Processing Addendum, which includes Standard Contractual Clauses (SCCs) for transfers from the EU/EEA.

Snippe

Payment data is transmitted to Snippe for transaction processing. Snippe's data residency and transfer policies are governed by its own privacy framework; we recommend reviewing Snippe's documentation for details on cross-border payment data flows.

Your transfer rights

If you have concerns about international data transfers, or if you are a resident of a country with stricter transfer restrictions, please contact info@jaliglobaltech.com. We will work with you to address your concerns within the limits of what is technically and legally practicable.
05

Your Rights Under the PDPA Tanzania

The Personal Data Protection Act grants you the following rights, which Jali is committed to upholding:

  1. 1Right to be informed — you have the right to know what personal data we hold about you and how we use it. This document, together with our Privacy Policy, fulfils this obligation.
  2. 2Right of access — you may request a copy of all personal data we hold about you in a readable format. We will respond within 30 days. The first copy is free; subsequent copies within 12 months may incur a reasonable administrative fee.
  3. 3Right to rectification — if any data we hold about you is inaccurate or incomplete, you have the right to have it corrected. Most information can be updated directly in your account settings.
  4. 4Right to erasure — you may request deletion of your personal data where: the data is no longer necessary for the purpose collected; you withdraw consent; you object to processing and there is no overriding legitimate interest; or the data has been unlawfully processed. We will fulfil valid erasure requests within 30 days, subject to retention obligations under Tanzania law.
  5. 5Right to data portability — you may receive your personal data in a structured, commonly used, machine-readable format (JSON or CSV), and have it transmitted to another controller where technically feasible.
  6. 6Right to restrict processing — you may request that we restrict processing of your personal data while the accuracy or lawfulness of processing is being contested.
  7. 7Right to object — you may object to processing based on our legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
  8. 8Rights related to automated decision-making — Math GiG uses automated difficulty adjustment, but this does not constitute a legal or similarly significant automated decision. You have the right to request human review of any automated process that significantly affects you.
06

How to Exercise Your Rights

To submit a data subject request of any kind:

  1. 1Email info@jaliglobaltech.com from the email address registered to your account.
  2. 2State clearly which right you wish to exercise and provide sufficient detail to identify your request.
  3. 3We will acknowledge your request within 5 business days.
  4. 4We may request proof of identity (e.g., a government-issued ID) before processing requests involving sensitive data disclosure or deletion. This is to protect you from unauthorised access to your own data.
  5. 5We will fulfil valid requests within 30 calendar days. Complex requests may take up to 60 days; we will notify you if an extension is needed and explain why.

Escalation and complaints

If you are dissatisfied with how we have handled your data or responded to a request, you may lodge a complaint with:

  • Personal Data Protection Commission of Tanzania (PDPC) — the supervisory authority under the PDPA. Website: pdp.go.tz
  • The Communications Regulatory Authority of Tanzania (TCRA) — where your complaint relates to electronic communications.

We encourage you to contact us first so that we may resolve the matter before escalation.

07

Technical and Organisational Security

We implement the following security measures in accordance with Article 28 of the PDPA (security of processing):

Technical measures

  • End-to-end encryption of all data in transit using TLS 1.3 (minimum TLS 1.2)
  • Database encryption at rest using AES-256 via Supabase's managed encryption layer
  • Bcrypt password hashing with per-user salts; passwords are never stored in recoverable form
  • Row-Level Security (RLS) policies ensuring each user can only read their own data
  • Automated intrusion detection and rate limiting on all API endpoints
  • Regular automated vulnerability scanning of web and API surfaces
  • Payment data handled exclusively by PCI-DSS compliant processors; raw card data never touches our servers

Organisational measures

  • Access to production systems is granted on a need-to-know basis and requires multi-factor authentication
  • All staff with access to personal data are bound by confidentiality obligations
  • New engineering team members receive data protection training before accessing production environments
  • A formal data breach response procedure is in place with defined notification timelines
  • We conduct periodic data protection impact assessments (DPIAs) for significant new processing activities
  • Third-party sub-processors are vetted for security compliance before engagement and reviewed annually

Breach notification obligation

Under Section 43 of the PDPA, we are required to notify the PDPC of a personal data breach within 72 hours of becoming aware, where the breach is likely to result in risk to the rights and freedoms of data subjects. We will simultaneously notify affected users by email.
08

Data Protection Officer

Jali Global Tech Limited has appointed a Data Protection Officer (DPO) responsible for overseeing our compliance with the PDPA and this policy.

  • DPO email: info@jaliglobaltech.com
  • General data enquiries: info@jaliglobaltech.com
  • Security disclosures: info@jaliglobaltech.com
  • Postal address: Data Protection Officer, Jali Global Tech Limited, P.O. Box 1234, Arusha, Tanzania

The DPO can be contacted on any matter relating to the processing of your personal data or the exercise of your rights under the PDPA. All communications are treated as confidential and are not accessible to Jali management unless required for resolution.

This Data Protection document is reviewed annually and following any material change to our processing activities. The current version was reviewed and approved in July 2026.