This document describes how Jali Global Tech Limited complies with Tanzania's Personal Data Protection Act No. 11 of 2022 (PDPA), explains the legal bases on which we process your data, and sets out the full framework of rights available to you as a data subject.
Data Controller Identity
The data controller for all personal data processed through Math GiG is:
- Entity name: Jali Global Tech Limited
- Registration: Incorporated under the Companies Act (Cap. 212), United Republic of Tanzania
- Registered office: P.O. Box 1234, Arusha, Tanzania
- Data Protection Officer: info@jaliglobaltech.com
- General contact: info@jaliglobaltech.com
As data controller, Jali Global Tech Limited determines the purposes and means of processing personal data collected through Math GiG. We process data in compliance with Tanzania's Personal Data Protection Act No. 11 of 2022 (“PDPA”) and its implementing regulations.
Legal Bases for Processing
Under the PDPA, we must have a lawful basis for each type of processing. The bases we rely on are:
| Processing activity | Legal basis | Notes |
|---|---|---|
| Account creation and authentication | Performance of contract | Necessary to provide the service you signed up for |
| Adaptive learning algorithm | Performance of contract | Core feature of the subscription |
| Child profile data (progress, XP, coins) | Consent of parent/guardian | Parent consents by creating the child profile |
| Payment processing | Performance of contract + Legal obligation | Billing and tax records |
| Parent dashboard analytics | Performance of contract | Included in the subscription offering |
| Security and fraud detection | Legitimate interests | Protecting users and the platform |
| Marketing emails | Explicit consent (opt-in only) | You can withdraw consent at any time |
| Legal compliance (tax records) | Legal obligation | Tanzania Tax Administration Act |
Withdrawing consent
Categories of Personal Data We Hold
The following table summarises the categories of personal data we hold, the purpose of processing, and how long we retain it:
| Category | Examples | Purpose | Retention |
|---|---|---|---|
| Identity data | Parent full name, email, phone number | Account access, communications | Account lifetime + 30 days post-deletion |
| Child identity data | Child first name, grade, birth year | Learning personalisation | While profile exists; deleted within 30 days of removal |
| Learning data | Questions answered, accuracy, XP, levels, streaks | Adaptive difficulty, dashboard, rewards | Account lifetime; anonymised on account deletion |
| Financial data | Subscription amounts, payment references, wallet balance, withdrawal history | Billing, coin economy, wallet | 7 years (Tanzania Tax Administration Act) |
| Device and usage data | Device type, OS, session times, features used, crash logs | Service delivery, bug fixing, aggregate analytics | 90 days (logs); 2 years (aggregated analytics) |
| Communications | Support emails, in-app messages to support team | Issue resolution | 2 years from last contact |
| Battle data | Match outcomes, opponents' grade (anonymised) | Fair play, leaderboards | 2 years then anonymised |
We do not process special category data (health, biometric, political, religious, or financial credit data) and have no intention to do so.
International Data Transfers
Math GiG's infrastructure involves transfers of personal data outside Tanzania to the following sub-processors. Each transfer is protected by contractual safeguards:
Supabase Inc. (United States / EU)
Our production database and file storage run on Supabase, with data stored in the EU West (Frankfurt) region. Supabase is ISO 27001 certified and processes data under a GDPR-compliant Data Processing Agreement. Data in the EU region does not leave EU territory under normal operations.
Vercel Inc. (United States)
Our web application is hosted on Vercel's global edge network. Server-side rendering occurs in the nearest Vercel region. Vercel operates under its Data Processing Addendum, which includes Standard Contractual Clauses (SCCs) for transfers from the EU/EEA.
Snippe
Payment data is transmitted to Snippe for transaction processing. Snippe's data residency and transfer policies are governed by its own privacy framework; we recommend reviewing Snippe's documentation for details on cross-border payment data flows.
Your transfer rights
Your Rights Under the PDPA Tanzania
The Personal Data Protection Act grants you the following rights, which Jali is committed to upholding:
- 1Right to be informed — you have the right to know what personal data we hold about you and how we use it. This document, together with our Privacy Policy, fulfils this obligation.
- 2Right of access — you may request a copy of all personal data we hold about you in a readable format. We will respond within 30 days. The first copy is free; subsequent copies within 12 months may incur a reasonable administrative fee.
- 3Right to rectification — if any data we hold about you is inaccurate or incomplete, you have the right to have it corrected. Most information can be updated directly in your account settings.
- 4Right to erasure — you may request deletion of your personal data where: the data is no longer necessary for the purpose collected; you withdraw consent; you object to processing and there is no overriding legitimate interest; or the data has been unlawfully processed. We will fulfil valid erasure requests within 30 days, subject to retention obligations under Tanzania law.
- 5Right to data portability — you may receive your personal data in a structured, commonly used, machine-readable format (JSON or CSV), and have it transmitted to another controller where technically feasible.
- 6Right to restrict processing — you may request that we restrict processing of your personal data while the accuracy or lawfulness of processing is being contested.
- 7Right to object — you may object to processing based on our legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
- 8Rights related to automated decision-making — Math GiG uses automated difficulty adjustment, but this does not constitute a legal or similarly significant automated decision. You have the right to request human review of any automated process that significantly affects you.
How to Exercise Your Rights
To submit a data subject request of any kind:
- 1Email info@jaliglobaltech.com from the email address registered to your account.
- 2State clearly which right you wish to exercise and provide sufficient detail to identify your request.
- 3We will acknowledge your request within 5 business days.
- 4We may request proof of identity (e.g., a government-issued ID) before processing requests involving sensitive data disclosure or deletion. This is to protect you from unauthorised access to your own data.
- 5We will fulfil valid requests within 30 calendar days. Complex requests may take up to 60 days; we will notify you if an extension is needed and explain why.
Escalation and complaints
If you are dissatisfied with how we have handled your data or responded to a request, you may lodge a complaint with:
- Personal Data Protection Commission of Tanzania (PDPC) — the supervisory authority under the PDPA. Website: pdp.go.tz
- The Communications Regulatory Authority of Tanzania (TCRA) — where your complaint relates to electronic communications.
We encourage you to contact us first so that we may resolve the matter before escalation.
Technical and Organisational Security
We implement the following security measures in accordance with Article 28 of the PDPA (security of processing):
Technical measures
- End-to-end encryption of all data in transit using TLS 1.3 (minimum TLS 1.2)
- Database encryption at rest using AES-256 via Supabase's managed encryption layer
- Bcrypt password hashing with per-user salts; passwords are never stored in recoverable form
- Row-Level Security (RLS) policies ensuring each user can only read their own data
- Automated intrusion detection and rate limiting on all API endpoints
- Regular automated vulnerability scanning of web and API surfaces
- Payment data handled exclusively by PCI-DSS compliant processors; raw card data never touches our servers
Organisational measures
- Access to production systems is granted on a need-to-know basis and requires multi-factor authentication
- All staff with access to personal data are bound by confidentiality obligations
- New engineering team members receive data protection training before accessing production environments
- A formal data breach response procedure is in place with defined notification timelines
- We conduct periodic data protection impact assessments (DPIAs) for significant new processing activities
- Third-party sub-processors are vetted for security compliance before engagement and reviewed annually
Breach notification obligation
Data Protection Officer
Jali Global Tech Limited has appointed a Data Protection Officer (DPO) responsible for overseeing our compliance with the PDPA and this policy.
- DPO email: info@jaliglobaltech.com
- General data enquiries: info@jaliglobaltech.com
- Security disclosures: info@jaliglobaltech.com
- Postal address: Data Protection Officer, Jali Global Tech Limited, P.O. Box 1234, Arusha, Tanzania
The DPO can be contacted on any matter relating to the processing of your personal data or the exercise of your rights under the PDPA. All communications are treated as confidential and are not accessible to Jali management unless required for resolution.
Related Policies