We collect only information connected to a clear purpose, protect sensitive and child-related records more strictly, do not sell personal data, and give people practical ways to access or correct their information and withdraw optional consent.
Who controls your information and what this policy covers
Joy for Children Uganda ("JFCU", "we", "us" or "our") is the data controller for personal data described in this policy unless a form, programme or partner notice clearly identifies another controller. JFCU is a Ugandan non-profit children's-rights organisation registered with the National Bureau for NGOs under registration number INDR66874691NB.
This policy covers information handled through this public website and connected services, including enquiries, newsletter subscriptions, feedback, volunteer and sponsorship enquiries, event participation, donations, safeguarding reports, success stories, media consent, downloads and administrative accounts. A specific programme, research activity, employment process or partner service may provide an additional privacy notice. That additional notice should be read together with this policy.
Our principal public contact address is Plot 23, Ntinda Avenue, Kampala, Uganda. The privacy contact details and rights-request form appear below.
Our privacy framework includes Uganda's Data Protection and Privacy Act, the Data Protection and Privacy Regulations, and child-protection obligations under the Children Act. This policy applies alongside other duties that may require JFCU to preserve or disclose information to protect a child, prevent serious harm or comply with law.
Privacy principles we follow
JFCU aims to process personal data in a manner that is accountable, lawful, fair and transparent. In practical terms, we seek to:
- explain the purpose before or when information is collected;
- collect information that is adequate, relevant and not excessive for that purpose;
- use information only for the stated purpose or another compatible and lawful purpose;
- keep information accurate and provide a route to correct it;
- retain identifiable information only for as long as it is reasonably needed;
- apply stronger access controls to safeguarding, health, child and other sensitive information;
- document consent where consent is the basis for optional publication or communication;
- assess service providers and international transfers; and
- respect the dignity, safety, agency and best interests of children and affected communities.
We do not sell or rent personal information. We do not use safeguarding reports, private feedback or children's information for behavioural advertising.
Information we may collect and where it comes from
The exact information depends on how you interact with JFCU. Fields marked optional do not need to be completed to use that particular service.
Website and security information
Our systems may receive IP address, browser and device type, requested page, date and time, referring page, session identifiers, consent preference, validation results, security events and diagnostic logs. Where appropriate, an address may be shortened, keyed-hashed or separated from content to reduce identifiability. We also use rate limits, anti-forgery tokens and anti-automation signals to protect forms.
Contact, feedback and correspondence
When you contact us, we may collect your name, contact details, organisation, subject, message, preferred response route and our correspondence with you. Secure feedback invitations collect a name and response; email is optional. Permission to publish feedback and permission to begin newsletter confirmation are separate choices.
Newsletters and communications
Newsletter records may include email address, optional name, subscription topics, confirmation time, consent source, status, preference history, unsubscribe history and the minimum suppression evidence needed to ensure that a withdrawn address is not accidentally re-added. We do not use purchased or scraped mailing lists. Open and click measurement is disabled by default.
Donations and fundraising
Donation records may include donor name, contact details, amount, currency, frequency, campaign or designation, transaction reference, payment-provider status, receipt and reconciliation records, communication preferences and fraud-review information. Banks, card processors, mobile-money operators, PayPal, GlobalGiving or another named provider process payment credentials. JFCU does not intentionally collect or store a complete card number, security code or mobile-money PIN in its ordinary website forms.
Participation, volunteer, event and sponsorship enquiries
We may collect identity and contact details, interests, location, skills, availability, accessibility needs, application answers, references, safeguarding declarations, participation records and related correspondence. If a role requires a background, identity or suitability check, we will explain the additional information and purpose at the relevant stage.
Safeguarding and protection information
A protection report may contain the reporter's contact preference, details about a child or other affected person, an alleged incident, risks, location, relationships, health or disability information, supporting material and case-management actions. A reporter can omit optional identifying details where possible. Because these records can be highly sensitive, they are held in a restricted case pathway rather than a general contact inbox.
Stories, photographs, video and publications
Where JFCU documents its work, records may include a contributor's name or approved pseudonym, image, voice, story, project relationship, language, consent scope, guardian details where applicable, safeguarding review, agreed channels, expiry or review date, and any withdrawal or restriction. A public story may be edited to remove identifying or risk-creating details.
Accounts and organisational records
Authorised users may have an account name, work contact, role and permissions, authentication records, multi-factor status, login history and audit entries showing administrative actions. We may also obtain information from a parent or guardian, authorised representative, colleague, programme partner, payment provider, referral body, public authority or public source where collection is lawful and relevant.
Why we use information and the legal grounds
We identify a purpose and appropriate legal ground before processing. Depending on the context, we use personal data to:
- provide a service or take steps you request, such as responding to an enquiry, registering interest, delivering a newsletter, managing an event or processing a donation;
- carry out JFCU's child-rights, education, advocacy and community programmes;
- receive, triage, document, investigate or refer a protection concern and help prevent serious harm;
- verify consent and safeguarding approval before publishing a story, quotation, photograph or feedback item;
- keep financial, donor, employment, governance, audit and regulatory records required by law or accountable non-profit management;
- secure accounts, prevent fraud and spam, detect misuse, investigate incidents and preserve service availability;
- manage volunteers, participants, partners and authorised personnel;
- respond to a rights request, complaint, legal claim, regulator or authorised public body; and
- measure public website use in aggregate where the visitor has separately allowed optional analytics.
The relevant ground may be your informed consent; steps requested by you or performance of an agreement; compliance with a legal duty; protection of a vital interest or child safety; performance of a public-interest or statutory function where applicable; or another ground permitted by Ugandan law. We will not rely on consent where a person has no genuine choice or where another legal duty requires action.
You may withdraw consent for future optional processing, but withdrawal does not invalidate earlier lawful processing. We may still retain limited information where necessary to record the withdrawal, protect a person, meet a legal duty or resolve a claim.
Children's information and safeguarding
Child safety and best interests take priority over publicity, convenience or fundraising value. JFCU applies heightened safeguards to information about a child, particularly information concerning health, disability, violence, family circumstances, location, education or alleged abuse.
- We seek valid parent or guardian consent where required and involve the child in an age-appropriate manner, while recognising that consent may not be the correct basis for an urgent protection response.
- We collect only what is needed to understand and respond to the situation.
- Access is limited by role and legitimate case purpose; sensitive access and decisions may be logged.
- Public content is assessed for identification, retaliation, stigma, location and future digital-footprint risks.
- Names, exact locations, schools, family details or images may be withheld, changed or combined where publication could create risk.
- Safeguarding records are not included in optional analytics, public search or newsletter marketing.
JFCU may act without ordinary publication or communication consent where this is lawfully necessary to protect a child, obtain urgent medical or protection support, make a required referral, preserve evidence or comply with an authorised request. Disclosure should be limited to what the receiving professional or authority needs.
If a child may be in danger, use the confidential safeguarding pathway. Do not put urgent protection information in a public comment, newsletter form or social-media message.
Public stories, feedback and media consent
Providing information to JFCU does not automatically authorise publication. Publication consent is requested separately and should identify what may be shared, where, for what purpose and, where appropriate, for how long. An authorised reviewer must also approve material before it appears publicly.
Consent can be refused without losing access to a programme or ordinary service. A person may ask us to stop future use or remove material under our control. We will act where required and reasonably practicable, although we may not be able to recall printed material already distributed, copies lawfully made by others or content cached outside our control. We will explain any limit.
For children and people at heightened risk, guardian permission alone does not make publication safe. JFCU also considers the child's views, maturity, best interests, changing circumstances and possible future harm. We may decline or anonymise a story even where consent was given.
Processing outside Uganda
Some website, email, analytics, payment, cloud or backup providers may process information on infrastructure outside Uganda. Before making an international transfer, JFCU should consider the destination, the recipient, the sensitivity of the information, contractual and technical safeguards, and whether the receiving environment provides adequate protection or another lawful transfer condition applies.
Where consent is the required transfer condition, we will provide relevant information and seek it expressly. Where a provider offers regional controls, encryption, access restrictions, data-processing terms or deletion tools, JFCU will use settings appropriate to the risk. Safeguarding and children's records require a more restrictive assessment than ordinary website analytics.
How long information is retained
We retain personal information for the shortest period reasonably needed for its purpose, legal and funder obligations, safeguarding accountability, audit, dispute resolution and secure deletion. Retention depends on record type rather than one universal period.
| Record | Retention approach |
|---|---|
| Unconfirmed newsletter request | Anonymised after up to 30 days unless confirmation is completed. |
| Newsletter engagement events | Where enabled, retained for up to 365 days. Open and click measurement is disabled by default. |
| Unsubscribed address | Minimum suppression evidence may be retained to honour withdrawal and prevent accidental re-subscription. |
| Policy and cookie choice | Stored in the browser for up to 365 days, unless removed earlier or the policy version changes. |
| Enquiries and feedback | Kept for operational follow-up, accountability and any publication consent period, then deleted or anonymised under the applicable schedule. |
| Donations and financial records | Kept for statutory accounting, audit, anti-fraud, donor accountability and dispute periods. |
| Safeguarding records | Kept under a restricted safeguarding schedule reflecting child-protection, evidence, referral, limitation and legal requirements. These records are not deleted merely because a public website account closes. |
| Security and audit records | Kept for the period needed to investigate misuse, demonstrate authorised access and protect systems, then deleted or de-identified. |
When the operational purpose ends, information is deleted, securely destroyed or irreversibly anonymised unless continued retention is authorised. Backups may persist for a limited recovery cycle and remain protected from ordinary use.
Security, confidentiality and personal-data breaches
JFCU uses safeguards proportionate to the nature and risk of the information. Measures may include encrypted transport, protected storage, least-privilege permissions, multi-factor authentication for privileged accounts, server-side validation, malware-resistant uploads, anti-forgery controls, rate limiting, spam and bot controls, audit logging, backups, patching and staff confidentiality requirements.
No internet service can guarantee absolute security. If we identify a personal-data breach, we will contain and assess it, preserve relevant evidence, reduce further harm and notify the Personal Data Protection Office and affected people where required. A notification may be delayed or limited where lawfully necessary to avoid increasing risk or interfering with an authorised investigation.
If you believe information has been exposed or an account is compromised, contact info@joyforchildren.org promptly. Do not send confidential child details in the first email; ask for a secure follow-up route.
Your data-protection rights
Subject to applicable conditions and exemptions, you may ask JFCU to:
- confirm whether we process personal data about you and provide access to it;
- correct, complete, update or block inaccurate information;
- delete information that is no longer authorised or necessary;
- restrict or object to particular processing, including direct marketing;
- stop future processing based on consent after you withdraw that consent;
- provide eligible information in a commonly usable form where portability applies;
- explain a significant decision based solely on automated processing and request human review; and
- complain to JFCU or Uganda's Personal Data Protection Office.
We may need to verify identity and authority before disclosing, correcting or deleting records. This protects you and other people named in the same record. We will request only verification proportionate to the risk and will not disclose another person's confidential data without an appropriate basis.
Some rights are not absolute. For example, JFCU may preserve information required for child protection, financial accountability, legal claims, another person's rights or a statutory duty. If we cannot fully grant a request, we will explain the reason to the extent permitted. You may authorise a representative, but we may verify that authority.
Spam screening, risk signals and automated decisions
Public forms may use automated signals to detect bots, repeated submissions, malicious uploads, unusual speed, invalid security tokens or other abuse. A submission may be rate-limited, quarantined or held for manual review. Technical identifiers may be keyed-hashed so abuse can be recognised without keeping a plainly readable address in the operational queue.
JFCU does not intend to make a decision producing legal or similarly significant effects about a person solely through website spam scoring. In particular, a safeguarding concern is not rejected as false merely because an automated score is high. Authorised people review and triage protection information under safeguarding procedures.
Policy changes, questions and complaints
We may update this policy when services, risks, providers, organisational practices or law change. The current version and effective date appear at the top. A material revision changes the configured policy version and causes the website acknowledgement notice to reappear.
If we cannot resolve your concern, you may contact Uganda's Personal Data Protection Office (PDPO). Its official guidance explains individual data-protection rights and complaint routes.
Submit a data-protection request
Use this form for access, correction, deletion, restriction, objection or portability requests. We send a verification email before processing to reduce impersonation and unauthorised disclosure. Do not include confidential child or safeguarding details here.