Ubuntu Roots Coaching™
Data Governance
Ethical stewardship in research and practice.
Last updated: September 2026
At Ubuntu Roots, data carries dignity. When leaders entrust us with their stories, assessment responses, or coaching insights, they are offering vulnerability, not merely information. This page describes the standards we commit to for data arising from Ubuntu Roots Coaching™ research, programs, and community initiatives. For everyday information collected through this website, see our Privacy Policy; this document is the research-and-ethics layer above it.
1. Core governing principles
Informed consent
Research participation requires explicit, informed consent. Participants understand the purpose, procedures, risks, benefits, and their rights before agreeing, and may withdraw at any time without penalty.
Confidentiality
We protect identifiable information through encryption, access controls, and secure storage, and separate personal identifiers from research data wherever practical.
Data minimisation
We collect only what is necessary for a specific, legitimate purpose, retain it only as long as needed, and then dispose of it securely.
Voluntary participation
Involvement is opt-in, never coerced. Power differentials — employer and coachee, coach and client — do not justify implicit pressure, and withdrawal carries no consequences.
Ethics review
Any formal research involving the methodology, assessment instruments, or program outcomes is submitted for independent ethics review before it begins.
Cultural respect
Our governance honours the African epistemological foundations of Ubuntu. Community knowledge and cultural context are protected from extractive or exploitative research practices.
2. Standards for any formal research
Before research we conduct or sponsor begins, we require:
Published governance notice
Describing data ownership, retention, and participant rights, available before consent is sought.
Independent ethics review
By an appropriate ethics board, with approval documented.
Legal review
Of protocols, consent forms, and data-handling procedures for compliance with applicable regulations.
Stakeholder consultation
During study design, to surface concerns and address power dynamics.
Risk–benefit assessment
Documented; studies whose risks outweigh benefits are redesigned or declined.
Data-management plan
Covering collection, storage, access, retention, and deletion.
3. Data ownership & control
Our governing stance on who controls what:
| Data type | Controlled by | Our commitment |
|---|---|---|
| Personal identifiers (name, email, contact) | The participant | Stored with restricted access; exportable on request; deleted on withdrawal, subject to legal retention. |
| Assessment responses | The participant | De-identified for analysis where possible; available to you; correctable. |
| Coaching session notes | Shared (participant & coach) | Stored securely; copies or redactions available on request. |
| Aggregate, anonymised findings | Ubuntu Roots / Maturity.Coach | Published without personal identifiers and not designed to be re-identifiable. |
| Organisational sponsor data | The sponsoring organisation | Reported only in aggregate, with minimum cohort sizes, never as individual results. |
4. Retention & secure disposal
We define retention periods by purpose and document them, keeping data only as long as it serves the purpose it was collected for or as the law requires, then disposing of it securely — digital records deleted beyond recovery and physical documents destroyed. Anonymised, non-identifiable insights may be retained to support cumulative learning.
[CONFIRM: if you want to publish specific retention periods (e.g. "assessments: 5 years") or specific disposal methods, list only the ones you actually follow.]
5. De-identification
When we publish findings or share data with researchers, we apply recognised de-identification techniques: replacing direct identifiers with codes (pseudonymisation), releasing data only at aggregation levels large enough to prevent individuals being singled out, and generalising quasi-identifiers such as role or tenure. De-identified datasets are not used to re-contact participants without fresh, separately obtained consent.
6. Participant rights
Participants may request access to their data, correction, deletion, restriction or objection to processing, portability, and withdrawal of consent — the same rights set out, with how to exercise them, in our Privacy Policy. We aim to respond within 30 days. To make a request, contact [email protected].
7. If something goes wrong
In the event of unauthorised access to or exposure of personal data, we commit to contain the incident, assess its scope and risk, notify the relevant authorities and affected individuals where legally required, remediate to prevent recurrence, and review our response afterwards.
8. Service providers
We engage a small number of service providers to operate the site and deliver services — our hosting and content-delivery provider, an email delivery service, and, where paid services are offered, a payment processor. Each is engaged under confidentiality and data-processing obligations, and cross-border transfers use appropriate legal safeguards.
[CONFIRM: name specific processors only once confirmed. As of our records, the confirmed provider is the site's hosting/CDN (Cloudflare); do not list Stripe, Zoom, or any email vendor unless they are actually in use.]
9. Contact & escalation
For questions, rights requests, or complaints, contact [email protected]; we aim to respond within 30 days. If you are not satisfied with our response, you retain the right to lodge a complaint with the relevant regulator in your jurisdiction — for example, the FTC or a state attorney general in the United States, the ICO in the United Kingdom, or your local supervisory authority in the EU.
Our covenant
This framework is more than compliance — it reflects a core belief: belonging requires mutual accountability. We do not treat data as a commodity to be extracted, but as a trust to be honoured. Participants are not subjects; they are co-guardians of this relationship.
Umuntu ngumuntu ngabantu — a person is a person through other people.
This document provides informational guidance and does not constitute legal advice. Consult qualified counsel; actual implementation may vary based on jurisdiction, study type, and applicable regulations.