MONGU TRADES TRAINING INSTITUTE
Website & Integrated ERP Digital Services

Privacy Policy

This policy explains how Mongu Trades Training Institute (MTTI) collects, uses, protects, retains, and shares information through its website and integrated ERP platform, including the limited use of Google APIs for institutional email delivery.

Effective date
16 September 2026
Domain
mongutradesinstitute.com
Privacy contact
enockmongutrades@gmail.com
Plain-language summary: MTTI uses this platform to deliver admissions, academic, student, staff, accommodation, communication, and administrative services. Personal information is used only for legitimate institutional purposes. Google Gmail API access is used only to send system-generated institutional emails; the application does not read users' Gmail inboxes or sell Google user data.

1. Who We Are

Mongu Trades Training Institute is the institution responsible for the operation of the public website and the Integrated Enterprise Resource Planning (ERP) platform available through mongutradesinstitute.com. References to “MTTI”, “the Institute”, “we”, “our”, or “us” in this policy refer to Mongu Trades Training Institute in its role as operator of these digital services.

The platform supports institutional functions including applications, admissions, student registration, programme and course administration, lecturer and staff services, timetables, attendance, assessment and results, accommodation workflows, appeals, announcements, learning resources, user administration, reporting, and related institutional communications.

2. Scope of This Policy

This policy applies to information processed through the MTTI public website, applicant and student services, lecturer and staff portals, administrative dashboards, institutional forms, uploaded documents, system-generated communications, and related online services operated under this domain.

It should be read together with applicable institutional policies, records-management requirements, employment/student rules, and the laws of the Republic of Zambia, including the Data Protection Act No. 3 of 2021 where applicable.

3. Information We May Collect

CategoryExamplesTypical institutional purpose
Identity and contact dataName, student or staff identifiers, NRC/passport details where required, email, phone, address, date of birth.Identity, admissions, registration, communication, records administration.
Application and admission dataProgramme choices, qualifications, supporting documents, application status and review history.Applicant assessment and admission processing.
Academic dataProgramme, courses, enrolment, attendance, assessments, grades, results, transcripts, progression and timetable information.Teaching, learning, assessment, certification and academic governance.
Staff and lecturer dataDepartment, role, qualifications, assigned courses, profile information and employment-related institutional records.Human-resource and academic administration.
Accommodation and student-support dataHostel/room information, appeals and related support requests.Student welfare and institutional administration.
Financial/sponsorship contextSponsor category, finance-related status or references where configured.Institutional finance and sponsorship administration.
Uploaded filesApplication documents, profile images, learning resources and other authorized institutional files.Delivery of the relevant institutional service.
Technical and security dataAccount identifiers, authentication events, timestamps, security logs, device/browser information and IP-related records where generated by infrastructure.Security, fraud prevention, diagnostics and service reliability.

4. How We Use Information

MTTI processes information only for legitimate and authorized institutional purposes, which may include:

We do not use personal information for unrelated advertising or sell institutional personal data.

Google API disclosure Gmail send only

5. Google Gmail API and Google User Data

The MTTI platform uses the Google Gmail API for a narrow operational purpose: sending authorized institutional and transactional email from the Institute's configured sending account. This includes messages such as password-reset emails, account notifications, and other system-generated institutional communications.

What Google access the application requests

The application is configured to request the minimum Gmail permission required for its sending function, currently the scope https://www.googleapis.com/auth/gmail.send.

What the application does not do

How Google authorization data is handled

OAuth credentials required to send mail are stored as protected server-side configuration and are not intentionally exposed to end users, public source-code repositories, or public webpages. Access is limited to authorized technical operation and maintenance of the MTTI platform.

Google Limited Use

MTTI's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements, to the extent those requirements apply to the Google API data processed by this platform.

6. Legal and Institutional Basis for Processing

Depending on the service and the person concerned, processing may be necessary to provide requested educational or administrative services, perform institutional responsibilities, comply with law or regulation, protect legitimate institutional interests, protect the security of users and systems, or act on consent where consent is the appropriate basis.

Where information relating to children, vulnerable persons, or sensitive personal data is processed, MTTI will apply the additional safeguards required by applicable law and institutional policy.

7. Service Providers and International Cloud Infrastructure

The platform uses reputable technology providers to operate portions of the service. Depending on configuration, these may include:

Because these services may operate infrastructure outside Zambia, information may be processed or transmitted across borders. MTTI will use reasonable contractual, technical and organizational safeguards and will review service arrangements as required by applicable law and institutional policy.

8. Cookies, Sessions and Technical Data

The platform may use essential cookies or session technologies to keep users signed in, preserve security state, protect forms, and provide requested functionality. Essential authentication/security cookies are not intended for behavioural advertising. Where additional non-essential analytics or tracking technologies are introduced in future, appropriate disclosures and controls should be added before deployment.

9. Data Security

MTTI and authorized system administrators apply reasonable safeguards appropriate to the nature of the system, including HTTPS transport, authenticated access, role-based permissions, protected server-side configuration, password controls, restricted administrative access, managed cloud infrastructure, and controlled software deployment.

No internet-connected system can be guaranteed to be completely risk-free. Users should protect their passwords, avoid credential sharing, sign out of shared devices, and report suspected compromise promptly.

10. Data Retention

Information is retained for as long as reasonably necessary for the educational, administrative, legal, audit, security, archival or records-management purpose for which it was collected. Retention periods may differ by record category. Information that no longer needs to be retained should be securely deleted, anonymised, archived, or otherwise handled in accordance with approved institutional and legal requirements.

11. Your Data Protection Rights

Subject to applicable law and lawful institutional record-retention obligations, individuals may have rights concerning their personal data, including rights to be informed, request access, request correction, object to certain processing, request restriction or erasure in appropriate circumstances, and lodge a complaint with the competent authority.

Some institutional records cannot lawfully or operationally be deleted merely on request—for example, where MTTI must preserve official academic, financial, employment, disciplinary, audit, or statutory records.

12. Data Accuracy and User Responsibilities

Users should provide accurate information and promptly update information that changes. Authorized staff should make corrections only within their role and institutional authority. Deliberate falsification, unauthorized alteration, credential sharing, or misuse of another user's account is prohibited.

13. Security Incidents and Breach Response

Where MTTI becomes aware of a material security incident affecting personal information, it will take reasonable steps to investigate, contain and remediate the incident; rotate affected credentials where appropriate; preserve relevant evidence; and make notifications required by applicable law or institutional policy.

14. Changes to This Privacy Policy

MTTI may update this policy when the platform, legal requirements, service providers, or data practices change. The current version will be published at https://mongutradesinstitute.com/privacy with an updated effective date. Material changes affecting how Google user data or other personal information is used should be reflected here before or when the changed processing begins.

15. Contact and Privacy Requests

Questions, access/correction requests, or privacy concerns relating to this platform may be directed to:

Mongu Trades Training Institute
Digital Services / System Administration
Email: enockmongutrades@gmail.com
Website: https://mongutradesinstitute.com/

For formal statutory complaints, individuals may also exercise rights available under Zambian data-protection law through the competent Data Protection Commission.