Home How It Works About Pricing Contact
DATA GOVERNANCE & PRIVACY FRAMEWORK

Global Privacy Policy

How NileBridge Global Services Ltd and its affiliated entities collect, process, secure, and govern corporate client data, personnel records, and customer interaction logs across Uganda, the United Kingdom, and the United States.

Effective Date: January 1, 2026
Version: v3.4 (Enterprise)
Governance: GDPR • UK GDPR • Uganda DPA 2019 • CCPA
Enterprise Client Overview: NileBridge operates primarily as a Data Processor when handling client customer inquiries and business workflows, and as an independent Data Controller for our direct website visitors, enterprise business contacts, and dedicated employees.
Section 01

1. Scope & Legal Entities

This Privacy Policy applies to all services, software interfaces, websites, and physical delivery operations provided by NileBridge Global Services Ltd (incorporated in the Republic of Uganda), its UK liaison entity NileBridge UK Ltd, and its US governance holding NileBridge Inc. (collectively referred to as "NileBridge", "we", "us", or "our").

This policy governs personal data collected through nilebridge.com, our client communication portals, vendor agreements, and dedicated customer care pods executing business process outsourcing (BPO) from our flagship facilities in Kampala.

Section 02

2. Data Categories We Collect

Depending on your relationship with NileBridge, we may collect and process the following categories of information:

Corporate & Lead Inquiries

Company name, authorized representative name, corporate email address, business phone number, timezone, team scaling requisitions, and budget estimates.

Workforce & Placement Data

Candidate CVs, government identification, background verification records, English fluency assessments, technical test scores, and payroll banking credentials.

Technical & Telemetry Data

IP addresses, browser signatures, referring URLs, session timestamps, device hardware identifiers, and MDM terminal security health checks.

Client Work Product & Interactions

Omnichannel support ticket transcripts, telephone call recordings (with client consent), KYC review documents, and audit trails recorded within client-designated CRM tools.

Section 03

3. Legal Basis & Processing Purposes

Under Article 6 of the General Data Protection Regulation (GDPR) and the Uganda Data Protection and Privacy Act 2019, our processing is lawful under the following legal bases:

  • Performance of Contract: To deliver dedicated BPO talent pods, process monthly billing, manage shift rosters, and execute Master Service Agreements (MSAs).
  • Legitimate Interests: To optimize our website performance, prevent fraud, secure network perimeters, and communicate with enterprise decision-makers.
  • Legal Compliance: To satisfy statutory tax withholding, labor laws, anti-money laundering (AML) protocols, and local employment standards in Uganda.
  • Consent: Explicit opt-in consent for marketing communications or specialized customer analytics.
Section 04

4. Cross-Border Transfers & Standard Contractual Clauses

As a global outsourcing partner, data originating within the European Economic Area (EEA), the United Kingdom, or the United States may be accessed by authorized operational staff at our delivery centers in Kampala, Uganda.

Standard Contractual Clauses (SCCs): We execute the European Commission's approved Standard Contractual Clauses (Module 2: Controller-to-Processor and Module 3: Processor-to-Processor) along with the UK International Data Transfer Addendum (IDTA) with all enterprise clients before workforce deployment.

Furthermore, our Kampala facilities undergo regular third-party Transfer Impact Assessments (TIAs) to ensure Uganda's domestic legal framework maintains enforceable rights for data subjects equivalent to European standards.

Section 05

5. Security Controls & Clean Desk Policy

NileBridge enforces defense-in-depth physical and digital safeguards across all delivery stations:

Clean-Desk & Mobile-Free Floors: Production floors are strictly zero-phone zones. Personal recording devices, external storage media, and paper notes are prohibited from operational desks.
Encrypted Workstations & MDM: Laptops and desktops are hardened with central Mobile Device Management (MDM), full-disk AES-256 BitLocker/FileVault, and remote wipe capabilities.
Biometric Perimeter Access: 24/7 CCTV surveillance with 90-day retention and multi-factor biometric door access restricted solely to assigned pod members.
Dedicated VPNs & Zero Trust: Split-tunneling disabled. Staff connect directly to client virtual desktop infrastructure (VDI) with zero local caching of sensitive consumer data.
Section 06

6. Data Retention & Erasure

We retain personal data only for as long as necessary to fulfill the operational purposes for which it was collected, or as mandated by legal, statutory, or audit requirements:

  • Client Relationship & Contract Data: 7 years following contract termination for fiscal and legal audit defense.
  • Employee & Contractor Personnel Files: 6 years post-employment under Uganda Ministry of Gender, Labour and Social Development guidelines.
  • Prospect & Inactive Requisition Records: 24 months from last recorded communication, after which records are irreversibly pseudonymized or deleted.
  • Client-Managed CRM / Ticket Data: Governed entirely by client instruction; erased upon master service contract conclusion.
Section 07

7. Sub-processors & Cloud Infrastructure

NileBridge engages audited enterprise third-party sub-processors to power our global cloud services. Each vendor is bound by Data Processing Agreements guaranteeing equivalent data protection:

Vendor / Entity Service Role Data Location
Amazon Web Services (AWS) Cloud Virtual Machines & Database Hosting US / EU Regions
Google Workspace Corporate Email & Encrypted Document Collaboration Global / Ireland
Cloudflare Inc. Edge CDN, DDoS Mitigation & WAF Protection Global Edge
Stanbic Bank / Absa Uganda Local Statutory Payroll & Commercial Banking Kampala, Uganda
Section 08

8. Your Data Subject Rights

Subject to applicable local and international data protection regulations (including GDPR Articles 15–22, CCPA, and Uganda DPA Part VII), you possess the following rights:

Right of Access: Request confirmation and an itemized copy of personal data processed.
Right to Rectification: Demand correction of inaccurate or incomplete corporate/personal information.
Right to Erasure ("Right to be Forgotten"): Request data deletion when retention is no longer legally justified.
Right to Restriction & Objection: Object to processing for direct marketing or under legitimate interests.
Section 09

9. Data Protection Officer (DPO) Contact

If you have questions, wish to exercise statutory data subject rights, or require signed DPAs/SCCs for your enterprise vendor onboarding, please contact our designated compliance officer:

Office: Data Protection Officer & Legal Compliance Directorate
Corporate Entity: NileBridge Global Services Ltd
Physical Address: Plot 14 Lumumba Avenue, Nakasero Business District, Kampala, Uganda
Email Contact: privacy@nilebridge.com
UK Liaison Office: 1 Canada Square, Canary Wharf, London, E14 5AA, United Kingdom