Scope and roles
The customer decides which people and businesses are checked and why. MasterID processes that data only to carry out the requested checks, to return results and to keep the audit record the customer relies on.
Categories of data and subjects
Data subjects: applicants, customers, employees, directors, beneficial owners and vendors of the customer organisation.
Data: identity numbers, names, dates of birth, addresses, business registration and tax numbers, bank account numbers, licence numbers, email addresses, phone numbers and the results of checks on them.
Sub processors
MasterID uses infrastructure providers to host and secure the platform, and passes requests to the record sources needed to answer a check, including identity registers, company registries, tax records, credit reference bureaus, banks and network operators.
We give notice before adding a sub processor that materially changes how customer data is handled.
Security measures
Encryption in transit and at rest, role based access control, per organisation data separation, key rotation and full audit logging of every check. Further detail is on the Security page.
Assistance and breach notice
We assist the customer with data subject requests, regulator enquiries and impact assessments relating to the checks we run.
If we become aware of a personal data breach affecting customer data we notify the customer without undue delay, with what we know about scope, cause and remediation.
Retention, return and deletion
Records are kept while the contract runs and for any period the customer must retain them by law. On termination the customer may export its records, after which data is deleted on the agreed schedule.
Location of processing
Processing takes place in Uganda and in the data centre regions used by our infrastructure providers. Where data leaves Uganda, it is transferred under contractual terms that keep these obligations in place.
