Effective date: August 4, 2026

Africa Privacy Notice

This Africa Privacy Notice supplements the Skkrum Privacy Policy for users located in African jurisdictions. Privacy and data-protection requirements differ by country. Hubroot applies the global Privacy Policy together with any mandatory local rights and obligations that apply to a user or customer.

Common Commitments Across African Markets

Process personal data for disclosed, legitimate service, security, billing, support, and legal purposes.

Collect data reasonably relevant to operating Skkrum and avoid unnecessary collection.

Use reasonable technical and organizational safeguards, including secure transmission, encryption at rest in supported production environments, access controls, authentication, logging, and incident response.

Support applicable rights of access, correction, deletion, objection, restriction, portability, withdrawal of consent, complaint, or other locally recognized rights.

Use service providers under appropriate contractual and security obligations.

Apply legally required safeguards to cross-border transfers.

Notify regulators, customers, or affected persons of qualifying breaches as required by the law of the affected country.

Complete controller/processor or data-handler registration where Skkrum is legally required to register before or while operating in a jurisdiction.

Country-Specific Administration

Where local law requires registration with a data-protection authority, appointment or registration of a data-protection officer or representative, filing of assessments, or other regulatory steps, Hubroot will complete the applicable requirement as part of market activation. These administrative obligations do not require users to take action unless Skkrum specifically asks for information needed to comply.

Nigeria

For processing subject to Nigeria's data-protection framework, Hubroot will comply with applicable Nigeria Data Protection Act and Nigeria Data Protection Commission requirements, including controller/processor registration where required, lawful processing, security safeguards, data-subject rights, cross-border transfer requirements, and breach reporting.

South Africa

For processing subject to South Africa's Protection of Personal Information Act (POPIA), Hubroot will apply applicable responsible-party/operator requirements, lawful-processing principles, security safeguards, data-subject rights, cross-border transfer restrictions, and security-compromise notification requirements. Where an Information Officer or regulatory registration is required for Hubroot's activities, Hubroot will complete the applicable process.

Kenya

For processing subject to Kenya's Data Protection Act, Hubroot will comply with applicable controller/processor obligations, registration requirements, data-subject rights, security safeguards, cross-border transfer requirements, and breach reporting obligations administered by the Office of the Data Protection Commissioner.

Ghana

For processing subject to Ghana's Data Protection Act, Hubroot will comply with applicable Data Protection Commission requirements, including registration where required, lawful and fair processing, security safeguards, data-subject rights, and applicable transfer and breach obligations.

Other African Countries

For Algeria, Angola, Benin, Botswana, Burkina Faso, Burundi, Cabo Verde, Cameroon, Central African Republic, Chad, Comoros, Democratic Republic of the Congo, Republic of the Congo, Côte d'Ivoire, Djibouti, Egypt, Equatorial Guinea, Eritrea, Eswatini, Ethiopia, Gabon, The Gambia, Guinea, Guinea-Bissau, Lesotho, Liberia, Libya, Madagascar, Malawi, Mali, Mauritania, Mauritius, Morocco, Mozambique, Namibia, Niger, Rwanda, São Tomé and Príncipe, Senegal, Seychelles, Sierra Leone, Somalia, South Sudan, Sudan, Tanzania, Togo, Tunisia, Uganda, Zambia, and Zimbabwe, Hubroot will apply the Skkrum Global Privacy Policy together with the mandatory data-protection, cybersecurity, communications, consumer, registration, transfer, breach, and regulatory requirements applicable in the relevant country at the time the Service is offered there.

Users in Africa may exercise applicable privacy rights through Skkrum's published privacy/support contact. If local law provides a right to complain to a national data-protection or privacy regulator, that right is not limited by this Policy.