Terms & Conditions v1.0

ST. GONZAGA SECONDARY SCHOOL — School Management System (SMS)
Effective Date: 26 March 2026
Download PDF Privacy Policy Effective: 26 March 2026  |  Version 1.0
Plain-Language Summary (For All Users)

Before reading the full legal text, here is what these Terms mean for you:

Table of Contents
  1. Introduction and Acceptance
  2. Definitions
  3. Eligibility and Authorised Users
  4. User Account Responsibilities
  5. Permitted Use of the System
  6. Prohibited Activities
  7. Data Ownership, Confidentiality and Privacy
  8. Intellectual Property
  9. Activity Logging and Monitoring
  10. Session Management and Security
  11. Data Accuracy and Integrity
  12. Children's Data — Special Obligations
  13. System Availability and Maintenance
  14. Disclaimers and Limitation of Liability
  15. Consequences of Breach
  16. Reporting Violations
  17. Updates to These Terms
  18. Governing Law
  19. Contact Information

1. Introduction and Acceptance

These Terms and Conditions of Use (hereinafter referred to as the Terms) govern access to and use of the web-based School Management System (hereinafter the System or SMS) operated by ST. GONZAGA SECONDARY SCHOOL (hereinafter the School, we, us, or our).

The System is a password-protected, role-based platform designed exclusively for the management of student academic records, staff information, and related administrative functions of the School. It is not a public system and access is strictly limited to authorised users as described in Section 3.

By logging in to or otherwise accessing the System, you confirm that you have read, understood, and agree to be legally bound by these Terms in their entirety. If you do not agree to these Terms, you must immediately cease using the System and notify the school administrator.

These Terms must be read in conjunction with the School's Privacy Policy, which governs the collection, use, and protection of personal data processed through the System. The Privacy Policy forms an integral part of the overall framework under which the System operates.

These Terms are prepared in compliance with:

  1. The Uganda Data Protection and Privacy Act, 2019 (DPPA 2019)
  2. The Uganda Data Protection and Privacy Regulations, 2021
  3. The Uganda Computer Misuse Act, 2011 (as amended)
  4. The Uganda Electronic Transactions Act, 2011
  5. General international data governance best practices including principles inspired by the EU General Data Protection Regulation (GDPR)

2. Definitions

For the purposes of these Terms, the following definitions apply:

System / SMS The web-based School Management System operated by the School at stgonzagasssk.com or any local/test instance thereof.
User Any individual who has been granted an authorised account to access the System, including administrators and teachers.
Administrator A User with full system privileges, including access to all modules, student records, staff records, system settings, activity logs, and reports.
Teacher A User with role-restricted access, limited to student records, marks, and academic data for their specifically assigned classes and subjects.
Credentials The unique username and password combination assigned to a User for the purpose of authenticating to the System.
Personal Data Any information that identifies or can be used to identify a living individual, including student names, dates of birth, academic results, photographs, and staff contact details.
Academic Records Marks, grades, examination results, report cards, teacher comments, class assignments, and related academic performance information stored in the System.
Activity Log A system-generated record of User actions including login events, data creation, modification, deletion, report generation, printing, and data export events.
Minor / Child Any person under the age of 18 years, in accordance with the Children Act (Cap. 59) of Uganda.
Unauthorised Access Any access to the System or to data within the System that exceeds the permissions granted to the User's assigned role, or access by any person who has not been issued valid credentials by the School.
Confidential Information All personal data, academic records, staff information, system configuration details, and any other non-public information accessible through the System.
Data Breach Any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed by the System.

3. Eligibility and Authorised Users

3.1 Who May Use the System

Access to the System is strictly limited to individuals who:

  1. Have been formally employed by or engaged with ST. GONZAGA SECONDARY SCHOOL in a role that requires access to student academic data or school management functions;
  2. Have been issued a valid set of login credentials by the System Administrator; and
  3. Have been assigned a specific role (Administrator or Teacher) that defines the scope of their access within the System.

3.2 Account Creation

User accounts are created exclusively by the System Administrator. No individual may self-register or create an account without administrative authorisation. The Administrator is responsible for ensuring that accounts are created only for eligible persons and that role assignments accurately reflect each user's operational responsibilities.

3.3 Role-Based Access

Any attempt to access System data or functionality beyond one's assigned role constitutes an unauthorised access attempt and may trigger a security alert and/or disciplinary action.

3.4 No Public or Student Access

The System does not provide a student-facing login portal. Students, parents, and guardians do not have direct access to the System. All data concerning students is managed exclusively through authorised staff accounts.

4. User Account Responsibilities

4.1 Credential Security

Each User is personally responsible for maintaining the confidentiality and security of their login credentials. You must:

  1. Keep your username and password strictly confidential at all times;
  2. Never disclose your credentials to any other person, including colleagues, students, or family members;
  3. Never use another person's credentials to access the System;
  4. Use a strong password and change it immediately if you suspect it has been compromised;
  5. Log out of the System whenever you leave your device unattended or have completed your session.
Important: Sharing your login credentials is a serious violation of these Terms. The User to whom credentials are issued shall be held fully accountable for all actions performed under their account, regardless of who physically performed those actions.

4.2 Reporting Compromised Credentials

If you believe your account has been compromised, accessed without your authorisation, or that your credentials have been disclosed to an unauthorised party, you must notify the System Administrator immediately at stgonzassk@gmail.com. Prompt reporting limits potential harm and fulfils your obligation under these Terms.

4.3 Account Termination on Exit

Upon the conclusion of your employment, engagement, or assignment with the School — for any reason — your account shall be deactivated by the Administrator promptly. You must not attempt to access the System after your authorisation has ended, and you must not retain any data obtained through the System beyond the period of your engagement.

5. Permitted Use of the System

Users may access and use the System solely for the following authorised purposes, and only within the scope of their assigned role:

  1. Student Record Management — registering, viewing, updating, and managing student personal and enrolment information;
  2. Academic Records — entering, reviewing, and managing marks, grades, teacher comments, and examination results for assigned classes;
  3. Report Generation — generating, printing, and downloading academic reports, report cards, and class performance summaries as authorised by role;
  4. Staff Management (Administrators only) — creating, managing, and deactivating teacher and staff accounts and assignments;
  5. Academic Structure (Administrators only) — managing levels, classes, streams, subjects, and academic calendar settings;
  6. System Administration (Administrators only) — bulk student uploads, promotions, archiving, activity log review, and school information management;
  7. Audit and Monitoring (Administrators only) — reviewing activity logs for accountability and security purposes.
Principle of Minimum Necessary Access: Users shall access only the data and functions strictly necessary to perform their current, specific school-related task. Browsing, downloading, or exporting data out of curiosity or for purposes unrelated to an active school duty is not a permitted use.

6. Prohibited Activities

The following activities are strictly prohibited and constitute material violations of these Terms, applicable law, or both:

6.1 Unauthorised Access and Circumvention

6.2 Data Misuse

6.3 Data Integrity Violations

6.4 Security Violations

6.5 Reputational and Legal Harm

Legal Notice: Certain prohibited activities — including unauthorised access to computer systems, data theft, and fraudulent manipulation of records — may constitute criminal offences under the Uganda Computer Misuse Act, 2011 (as amended) and the Uganda Data Protection and Privacy Act, 2019. The School reserves the right to report violations to law enforcement authorities.

7. Data Ownership, Confidentiality and Privacy

7.1 Ownership of Data

All data stored in the System — including student records, academic results, staff records, activity logs, and any other information — is and remains the property of ST. GONZAGA SECONDARY SCHOOL. Users do not acquire any ownership, licence, or proprietary rights in any data accessed through the System by virtue of their role or use of the System.

7.2 Confidentiality Obligation

All information accessed through the System is strictly confidential. Users are bound by an ongoing duty of confidentiality that continues to apply after the termination of their employment or engagement with the School. You shall not, without prior written authorisation from the School Administrator:

7.3 Privacy Policy

The collection, use, storage, and protection of personal data processed through the System is governed by the School's Privacy Policy (Version 1.0, effective 26 March 2026). The Privacy Policy is incorporated into these Terms by reference and must be read alongside them. Users are required to familiarise themselves with the Privacy Policy and to act consistently with its provisions at all times.

7.4 Data Subject Rights

Users who handle personal data of others must respect and, where applicable, facilitate the exercise of data subject rights as described in Section 8 of the Privacy Policy. Users must not obstruct, delay, or ignore legitimate data access or correction requests received from students, parents, or guardians.

8. Intellectual Property

The System — including its source code, database schema, design, user interface, graphics, logic, and documentation — is the intellectual property of ST. GONZAGA SECONDARY SCHOOL or its contracted developers. All rights are reserved.

Users are granted a limited, non-exclusive, non-transferable right to access and use the System solely for the purposes described in Section 5. This grant does not include any right to:

Any violation of the School's intellectual property rights may result in civil and/or criminal liability under Ugandan law.

9. Activity Logging and Monitoring

9.1 Comprehensive Audit Logging

The System maintains a comprehensive activity audit log that automatically records the following for every significant user action:

9.2 Consent to Monitoring

By using the System, you explicitly consent to the recording and monitoring of your activities within the System as described in Section 9.1. This monitoring is conducted for purposes of security, accountability, fraud prevention, and compliance with the Uganda Data Protection and Privacy Act, 2019.

9.3 Retention of Logs

Activity logs are retained for a minimum of two (2) years from the date of recording, consistent with the provisions of the School's Privacy Policy. Logs may be retained longer where required for the investigation of a specific incident, legal proceedings, or regulatory requirement.

9.4 Use of Logs

Activity logs may be reviewed by Administrators for internal auditing and accountability purposes. In the event of a suspected security incident, data breach, or policy violation, logs may be disclosed to law enforcement, regulatory authorities (including the Personal Data Protection Office at NITA-U), or used in internal disciplinary proceedings.

10. Session Management and Security

10.1 Session Timeout

For Users in the Teacher role, the System enforces an automatic session timeout of 15 minutes of inactivity. Upon timeout, the session is terminated and the User is required to log in again. This measure is in place to reduce the risk of unauthorised access via unattended devices.

10.2 Session Fixation Prevention

The System regenerates session identifiers upon every successful login to prevent session fixation attacks. Users must not attempt to manipulate, share, or replay session identifiers.

10.3 Single Active Session

Users are expected to maintain only one active session at a time. Logging in from multiple devices simultaneously may trigger a security flag and is discouraged.

10.4 User Responsibilities

Users are responsible for:

11. Data Accuracy and Integrity

11.1 Obligation of Accuracy

Users who enter or modify data within the System bear a professional and legal responsibility to ensure that the information entered is accurate, complete, and current. Deliberate entry of false or misleading data is a serious disciplinary and potentially criminal offence (see Section 6.3).

11.2 Correction of Errors

If a User becomes aware of inaccurate data that they entered, or that they have authority to correct, they must take prompt action to rectify the error. Corrections to academic records (marks, grades, results) require authorisation from the System Administrator to maintain the integrity of the audit trail.

11.3 Report Cards and Official Documents

Reports and report cards generated by the System constitute official school documents. Users must exercise care when generating, printing, or distributing such documents. Unauthorised or premature distribution of official school documents, including report cards, is prohibited.

12. Children's Data — Special Obligations

The majority of personal data processed through this System relates to students who are minors (persons under 18 years of age). All Users who access student data carry heightened obligations under Ugandan law and school policy.

12.1 Enhanced Duty of Care

Users must treat all student data with the highest level of care and discretion. The vulnerabilities inherent in data relating to children demand that Users apply a stricter standard of conduct than might apply to other categories of data.

12.2 Strict Access Limitation

Teachers must not access, view, or export data relating to students in classes or subjects not assigned to them. Any attempt to access data outside one's assignment scope will be logged and may result in disciplinary action.

12.3 Prohibition on External Disclosure

Student data — including names, dates of birth, academic results, photographs, and any other personal information — must not be disclosed outside the school environment without explicit written authorisation from the Administrator and, where applicable, the consent of the student's parent or guardian.

12.4 Photographs

Student photographs stored in the System are for identification purposes only, within the System. Users must not download, copy, share, publish, or use student photographs for any other purpose. Photographs must not be shared via social media, messaging platforms, email, or any other channel.

12.5 Legal Framework

The processing of children's personal data is governed by the Uganda Data Protection and Privacy Act, 2019, the Children Act (Cap. 59) of Uganda, and the School's Privacy Policy. Violations involving children's data may attract elevated regulatory and legal consequences.

13. System Availability and Maintenance

13.1 No Guarantee of Availability

The School endeavours to maintain the System in good working order and to maximise its availability. However, the School does not guarantee that the System will be available continuously, without interruption, or free of errors. The System may be temporarily unavailable due to:

13.2 Maintenance Mode

The System includes a maintenance mode feature activated by Administrators during technical work. During maintenance mode, access is restricted and no new personal data is processed. Users attempting to access the System during maintenance will be redirected to a maintenance notification page.

13.3 Data During Downtime

All data stored in the System remains securely held during any period of downtime or maintenance. The School is not liable for temporary inaccessibility of data during planned or unplanned maintenance periods, provided reasonable steps are taken to minimise disruption.

14. Disclaimers and Limitation of Liability

14.1 "As Is" Provision

The System is provided on an "as is" and "as available" basis. The School makes no warranties, express or implied, regarding the System's fitness for a particular purpose, accuracy of data outputs, or freedom from defects.

14.2 User Responsibility for Data Entry

The School is not liable for the consequences of inaccurate, incomplete, or fraudulent data entered by Users. Users bear full personal responsibility for the accuracy of information they enter or modify in the System.

14.3 Third-Party Services

The System relies on third-party infrastructure, including web hosting and content delivery networks. The School is not liable for data loss, service disruptions, or security incidents caused by third-party service failures, provided the School has taken reasonable steps to select reputable providers and maintain appropriate data processing agreements.

14.4 No Liability for Unauthorised Use

The School is not liable for any harm resulting from unauthorised use of the System where such use occurred as a result of a User's failure to safeguard their credentials or comply with these Terms.

15. Consequences of Breach

A violation of any provision of these Terms may result in one or more of the following consequences, depending on the nature and severity of the breach:

Severity Example Violations Possible Consequences
Minor Failing to log out on a secure school device; accessing a page outside your scope by error, immediately reported Verbal or written warning; mandatory refresher on these Terms
Moderate Sharing credentials with a colleague; downloading data to a personal device without authorisation; repeated minor violations Formal disciplinary proceedings; suspension of System access; written reprimand on employment record
Serious Deliberate falsification of academic records; exporting student data for personal use; sharing student photographs externally; intentional unauthorised access Immediate suspension or termination of System access; referral to school disciplinary committee; potential dismissal
Criminal Computer hacking; data theft; fraud involving academic records; mass disclosure of student data All of the above, plus referral to law enforcement; reporting to the Personal Data Protection Office (NITA-U); civil or criminal prosecution

The School reserves the right to immediately suspend a User's access to the System at any time where there is reasonable suspicion of a breach of these Terms, pending investigation.

16. Reporting Violations

All Users have a responsibility to report any known or suspected violations of these Terms to the System Administrator promptly. Reports should be made in good faith and may include:

Reports may be made confidentially by contacting:

The School will protect, to the extent possible, the identity of any person who reports a suspected violation in good faith. Retaliation against a person who reports a genuine concern is itself a violation of these Terms.

17. Updates to These Terms

The School reserves the right to update or amend these Terms at any time to reflect:

When material changes are made, the School will:

  1. Update the Effective Date and Version at the top of this document;
  2. Make the updated Terms accessible through the Admin Dashboard and Teacher Dashboard footer links;
  3. Notify all active Users via the System's communication channels and/or by direct communication where feasible.
Continued use of the System after the effective date of any updated Terms constitutes your acceptance of the revised Terms. Where changes significantly affect User rights or obligations, the School may require fresh explicit acknowledgement before access is restored.

All Users are encouraged to review these Terms periodically. The current version is always accessible from the footer of the Admin and Teacher Dashboards.

18. Governing Law and Jurisdiction

These Terms and Conditions of Use are governed by and construed in accordance with the laws of the Republic of Uganda, including but not limited to:

Any dispute arising out of or in connection with these Terms, or any breach thereof, shall be subject to the exclusive jurisdiction of the competent courts of the Republic of Uganda. The parties agree to attempt to resolve disputes amicably before resorting to formal legal proceedings.

19. Contact Information

For any questions, concerns, or reports relating to these Terms and Conditions, please contact the School's designated Data Protection Administrator:

School Name ST. GONZAGA SECONDARY SCHOOL
System Name School Management System (SMS)
Contact Person School Data Protection Administrator
Email Address stgonzassk@gmail.com
Postal Address P.O Box 1809, Jinja-Kagoma
Telephone +256782741977
System URL stgonzagasssk.com

You also have the right to escalate unresolved complaints to:


These Terms and Conditions are effective as of 26 March 2026 and supersede all previous versions.
© 2026 ST. GONZAGA SECONDARY SCHOOL. All rights reserved.
Privacy Policy