HiA Collaboration Services Privacy
Effective date: October 2026
This notice explains how privacy and personal information are handled specifically in connection with HiA Collaboration Services.
It supplements the main HiA Privacy Statement. The main Privacy Statement continues to apply to use of the Hosted in Africa website, HiA Network and other general interactions with HiA.
Where a Collaboration Service is supplied to an organisation, additional privacy, data-processing or contractual arrangements may also apply.
1. Services covered by this notice
HiA Collaboration Services may include:
- HiA Workspace;
- Managed Digital Home;
- Dedicated Managed Digital Home;
- Independent Digital Home;
- HiA Federation;
- onboarding, migration, training and support;
- related collaboration and organisational services.
The information handled will depend on the service actually provided and the way the individual or organisation chooses to use it.
2. Our approach
What matters is not only what the tools can do, but how we as individuals, teams and organisations can retain our identities, exercise meaningful control and remain responsible for how we use them.
HiA therefore seeks to limit unnecessary personal information, keep organisational boundaries clear and explain where information is held, who can administer it and what responsibilities belong to HiA and to the organisation using the service.
3. Information used to establish and administer a service
Depending on the service, HiA may process information such as:
- names and contact details;
- account identifiers;
- organisation name and organisational role;
- membership, team or group information;
- administrator and authorised-contact details;
- account and permission settings;
- service configuration information;
- support and onboarding communications;
- billing, proposal and service-administration records;
- technical and security information reasonably required to operate and protect the service.
We aim to collect only what is reasonably necessary for the service and its administration.
4. Information placed in a Workspace or Digital Home
Members and organisations may use Collaboration Services to create, upload, store or share information including:
- files and documents;
- messages and chat content;
- calendars and events;
- meeting information;
- organisational records;
- comments and collaborative content;
- information generated through applications enabled for the particular service.
The organisation or member using the service remains responsible for determining what information they place within the environment and for ensuring that they have an appropriate basis for doing so.
HiA does not obtain ownership of customer content merely because HiA hosts, manages or supports the environment.
5. Organisational administration
A Digital Home may have administrators or other authorised people who can manage members, groups, permissions and aspects of the organisation’s environment.
Those administrators may be able to see account information and other information necessary to carry out their organisational role.
The organisation is responsible for deciding who receives administrative authority and for notifying HiA when that authority should change.
6. HiA’s role and the organisation’s role
HiA may handle different information in different capacities.
For example, HiA may determine how it processes information needed for its own:
- service administration;
- security;
- billing;
- support;
- legal obligations;
- relationship with the customer.
Where HiA processes personal information contained within an organisation’s Digital Home on that organisation’s instructions, the organisation may have primary responsibility for determining the purposes of that processing.
Where required, the applicable proposal, service agreement or data-processing agreement will clarify these responsibilities.
7. Support and administrative access
Authorised HiA personnel may require administrative access to an environment for purposes such as:
- configuration;
- onboarding;
- maintenance;
- security;
- troubleshooting;
- recovery;
- support requested by the organisation.
Access should be limited to what is reasonably required for the task.
HiA does not treat administrative access as permission to use customer information for unrelated purposes.
8. Security and operational information
HiA may process technical information necessary to operate and protect Collaboration Services, which may include:
- login and authentication information;
- IP addresses;
- timestamps;
- application and service logs;
- security events;
- device or browser information where generated by the service;
- system-performance and diagnostic information.
Such information may be used to maintain the service, investigate faults, respond to security incidents and protect members and organisations.
9. Hosting, backups and data location
The actual primary hosting location, backup arrangements, relevant providers, administrative access and responsibilities may differ between Collaboration Services.
Where material to the service, these arrangements will be confirmed in the applicable proposal, onboarding information or service documentation.
HiA serves communities across Global Africa, including the continent, diaspora and international partners. Infrastructure may therefore develop across more than one location to support privacy, resilience, performance and appropriate reach.
A reference to HiA or Hosted in Africa should not by itself be interpreted as a guarantee that all information is physically stored in Africa.
Where applicable law requires particular safeguards for international or cross-border processing, those requirements will be considered as part of the service arrangement.
10. Backups and recovery
Where backups form part of the service, copies of customer information may be processed and retained within the agreed backup and recovery arrangements.
Backup copies may persist for a limited period after information is changed or deleted from the active service because of the way backup cycles operate.
Specific backup locations, retention arrangements or recovery commitments apply only where they have been confirmed for the service concerned.
11. Service providers
HiA may use carefully selected infrastructure, communications, payment, backup or other service providers where they are needed to deliver a Collaboration Service.
Those providers may process information only to the extent required for the services they supply and subject to the applicable contractual, technical and legal arrangements.
The main HiA Privacy Statement contains information about providers used for the Hosted in Africa website and general services. HiA Network
Service-specific providers may also be identified in proposals, service documentation or privacy information where appropriate.
12. Payments
Where payment is made through an external payment provider, information required to process or support the transaction may be passed to that provider.
This may include:
- the amount payable;
- transaction reference;
- billing information;
- information required by the selected payment method.
Payment providers may offer cards, bank transfer, mobile money or other payment methods depending on location and availability.
HiA does not need to receive a payer’s full card or mobile-money credentials where those are handled directly by the payment provider.
The main Privacy Statement already explains that selected payment systems may receive information required to process or support payments. HiA Network
13. HiA Federation
Federation may allow otherwise separate Digital Homes to collaborate by consent.
Information shared through a federated relationship may become available to members or systems in another participating environment according to the sharing action and permissions chosen.
Federation does not automatically make all information in one Digital Home available to another.
Organisations should understand and agree the relevant sharing responsibilities before enabling material federated collaboration.
14. Retention and deletion
Different categories of information may need to be retained for different periods.
Customer content is generally retained while the service and relevant account or organisational relationship remain active, subject to:
- the customer’s instructions;
- agreed retention arrangements;
- backup cycles;
- legal requirements;
- security and operational needs.
Service administration, contractual, billing or support information may need to be retained separately from customer content.
Where a service ends, the applicable agreement may provide for export, transition and subsequent deletion of customer-controlled information.
15. Portability and transition
HiA’s direction is to avoid unnecessary organisational lock-in.
Subject to the applicable agreement, technical feasibility and legal requirements, customers may be able to export or migrate information when moving away from a HiA service or changing their level of infrastructure control.
Significant migration or transformation work may need to be separately agreed.
16. Children, education and sensitive information
Some future Collaboration Services may be used by schools, educational initiatives or organisations handling information requiring additional protection.
Such services may require further assessment, contractual controls, permissions or safeguards before activation.
The availability of a HiA service should not be taken as automatic approval to process children’s information, highly sensitive information or other specially regulated information without appropriate arrangements.
17. Community Benefit and Community Builds
Applying for Community Benefit may require an organisation to provide information about its legal status, purpose, activities, communities served and circumstances relevant to the request.
HiA will use that information to assess the support requested and administer any approved arrangement.
Community Builds remain a developing HiA direction. Any future programme involving schools or community institutions will require appropriate privacy and governance arrangements before personal information is processed through it.
18. Your privacy rights
Your rights depend on the law applicable to you and the context in which the information is being processed.
The main HiA Privacy Statement provides information on applicable privacy rights, requests, complaints and regional arrangements. HiA uses Complianz to provide regional privacy information and data-request mechanisms. HiA Network
Where information is controlled primarily by an organisation using a Digital Home, HiA may need to refer a request to that organisation or assist it in responding.
19. Main HiA Privacy Statement
This Collaboration Services notice should be read together with the main HiA Privacy Statement.
The main Privacy Statement contains further information about:
- website privacy;
- cookies;
- contact information;
- regional privacy rights;
- data requests;
- complaints;
- general processing by Hosted in Africa Group Limited.
Main Privacy Statement:
View the Privacy Statement that applies to your region
The regional redirect allows HiA’s privacy system to direct visitors to the appropriate available privacy document.
20. Contact
HiA Collaboration Services are provided by:
Hosted in Africa Group Limited
Kimironko, Gasabo
Umujyi wa Kigali
Rwanda
Email: [email protected]
For a privacy question concerning information controlled by an organisation using a HiA Digital Home, you may also need to contact that organisation directly.
