Data Protection Notice

Effective Date: 01 January 2026
Last Updated: 01 June 2026

CBET Master is developed, operated and supported by ABNO Softwares International Ltd.

This Data Protection Notice explains how personal data is handled when CBET Master is used by Qualification Awarding Bodies, QAIs, institutions, authorized staff, assessors, verifiers, candidates, trainees and other platform users.

CBET Master supports digital CBET assessment management. EduBridge supports trainee ePOE, assessment readiness and evidence submission workflows where applicable.

1. Purpose of This Notice

This notice is intended to inform users how personal data may be collected, used, stored, shared, protected and retained when using CBET Master and related services.

It applies to:

  • CBET Master public website interactions
  • QAB tenant portals
  • User accounts and login activities
  • Candidate registration workflows
  • Assessment and moderation workflows
  • Results and reporting workflows
  • Certificate generation and verification where enabled
  • EduBridge linkage and ePOE readiness workflows
  • Support and onboarding communications
  • System logs, audit trails and security monitoring

2. Who Controls Your Data?

For official assessment, candidate, trainee, staff and institutional data:

The QAB, QAI or Institution is generally the Data Controller.

This means the QAB or institution decides why the data is collected and how it should be used for assessment, certification, reporting, compliance and related institutional purposes.

ABNO Softwares International Ltd is generally the Data Processor.

This means ABNO processes the data on behalf of the QAB or institution to operate, host, support, maintain, secure and improve CBET Master and related services.

For direct website enquiries, onboarding requests, executive briefing requests, support enquiries and general business communications submitted directly to ABNO, ABNO may act as the Data Controller.

3. Personal Data We May Process

Depending on your role and use of CBET Master, the following personal data may be processed.

Candidate, Trainee or Student Data

  • Name
  • Admission, registration, index or candidate number
  • Contact details
  • Identification details where required
  • Institution, department and programme
  • Course, level, module or unit of competency
  • Assessment registration details
  • ePOE or evidence readiness status
  • Assessment outcomes
  • Results, marks, comments and competence decisions
  • Certificate details where enabled
  • Verification records

Staff, Assessor, Verifier and Administrator Data

  • Name
  • Designation
  • Department or office
  • Work email address
  • Phone number
  • User role
  • Login records
  • Approval, review or assessment actions
  • Comments and workflow decisions
  • Audit trail records

Institution and QAB Data

  • QAB or institution name
  • Official address and contacts
  • County and sub-county
  • Institution logo
  • Programme and curriculum data
  • Units of competency
  • Assessment series
  • Grading schemes
  • Fee and clearance rules where applicable
  • User access lists
  • Implementation and onboarding records

Technical and Security Data

  • IP address
  • Device and browser information
  • Login attempts
  • System activity logs
  • Audit trails
  • Error logs
  • Integration logs
  • Support records
  • Notification logs

Communication and Support Data

  • Email messages
  • Phone or WhatsApp contact details
  • Support tickets
  • Issue descriptions
  • Onboarding requests
  • Executive briefing requests
  • System notification records

4. Why We Process Personal Data

Personal data is processed for legitimate CBET Master and EduBridge-related purposes, including:

  • Setting up QAB tenant portals
  • Creating and managing user accounts
  • Supporting candidate registration
  • Managing assessment series
  • Supporting assessor, verifier and moderation workflows
  • Processing results and reports
  • Supporting certificate generation and verification where enabled
  • Supporting EduBridge ePOE and assessment readiness workflows
  • Routing approved records to the correct assessment pathway
  • Providing dashboards and reports
  • Maintaining audit trails
  • Supporting data validation and system configuration
  • Providing technical support
  • Sending system notifications and reminders
  • Securing the platform
  • Maintaining backups and logs
  • Handling onboarding and implementation
  • Complying with legal, regulatory, audit or contractual obligations

ABNO does not sell QAB, candidate, trainee or assessment data.

5. Legal Basis for Processing

Personal data may be processed based on one or more of the following:

  • Performance of a contract, MoU or service arrangement
  • Lawful instructions from a QAB, QAI or institution
  • Institutional mandate or assessment responsibility
  • Legal or regulatory obligation
  • Legitimate interest in operating and securing the platform
  • Consent where required
  • Protection of platform integrity, auditability and accountability

Where consent is required from candidates, trainees, staff or users, the relevant QAB or institution is generally responsible for obtaining and maintaining that consent unless otherwise agreed in writing.

6. Assessment Pathway Clarification

CBET Master respects assessment mandates.

TVET CDACC-assessed programmes follow the TVET CDACC pathway.

QAB or QAI-assessed programmes may be managed through CBET Master where the QAB is authorized to assess and certify those programmes.

EduBridge supports trainee ePOE, evidence readiness and guided registration workflows where enabled.

CBET Master does not replace the mandate of any regulator.

7. Who May Access Personal Data?

Access to personal data is limited based on role and authorization.

Personal data may be accessed by:

  • Authorized QAB administrators
  • Registrars and assessment officers
  • ICT officers
  • QA officers
  • Finance officers where applicable
  • HODs, trainers, assessors and verifiers
  • Institution users with approved access
  • Management viewers with reporting access
  • ABNO support, implementation or technical staff where required
  • Approved third-party service providers where necessary for hosting, communication, payment or platform operation
  • Regulators or public authorities where legally required or properly authorized

Users should only access data required for their assigned role.

8. Role-Based Access and Sensitive Settings

CBET Master uses role-based access.

Not every user should access sensitive system settings.

Sensitive settings may include:

  • QAB profile and branding
  • Programmes and units
  • Grading schemes
  • Assessment series
  • Fees and payment rules
  • Certificate templates
  • Certificate verification settings
  • User roles and permissions
  • EduBridge linkage
  • ERP or payment integrations
  • Email, SMS or WhatsApp settings
  • Data export permissions
  • Storage settings

Sensitive access should be limited to authorized administrators and properly audited.

9. Data Sharing

Personal data may be shared only where necessary and lawful.

Data may be shared with:

  • The relevant QAB, QAI or institution
  • Authorized users within the relevant QAB or institution
  • EduBridge where integration is enabled
  • Approved assessment systems where routing is authorized
  • Hosting and infrastructure providers
  • Email, SMS or WhatsApp service providers where enabled
  • Payment service providers where payment workflows are enabled
  • Technical support providers under confidentiality obligations
  • Regulators, courts or public authorities where required by law
  • Professional advisers where necessary for legal, audit or compliance purposes

ABNO does not disclose QAB or candidate data to unauthorized third parties.

10. Data Security Measures

ABNO applies reasonable technical and organizational measures to protect personal data.

These may include:

  • Role-based access control
  • Password-protected accounts
  • User authentication
  • Audit trails
  • Access logs
  • Secure hosting
  • Backups
  • Administrative access restrictions
  • System monitoring
  • Security updates
  • Controlled support access
  • User deactivation
  • Confidentiality obligations for authorized personnel

QABs and institutions must also protect their side of the platform by ensuring that users keep login details confidential, avoid sharing accounts and report suspected misuse promptly.

11. Tenant Isolation

Each QAB has its own CBET Master tenant portal.

Users should only access data belonging to their QAB, institution, assigned role or approved permission level.

One QAB should not access another QAB’s data.

ABNO internal access to tenant data is restricted to authorized support, implementation, maintenance, security or compliance purposes.

12. Data Accuracy

The QAB or institution is responsible for ensuring that official data submitted into CBET Master is accurate, lawful, complete and approved.

This includes:

  • Candidate data
  • Staff data
  • Programme data
  • Unit data
  • Assessment data
  • Result data
  • Certificate data
  • User access data

ABNO may support data formatting, upload, validation and troubleshooting, but the QAB or institution remains responsible for approving official institutional and assessment data.

13. Data Retention

Personal data is retained only for as long as reasonably required for:

  • Assessment administration
  • Certification and verification
  • Institutional records
  • Audit trails
  • Legal or regulatory compliance
  • Candidate record continuity
  • System backups
  • Dispute resolution
  • Platform operation and support
  • The relevant MoU, contract or service relationship
  • Any agreed transition or data export period

Retention periods may vary based on the type of data, QAB requirements and applicable law.

14. Data Subject Rights

Subject to applicable law, a data subject may have rights relating to their personal data, including:

  • Right to be informed
  • Right to access personal data
  • Right to correction of inaccurate data
  • Right to deletion where applicable
  • Right to object to processing where applicable
  • Right to restrict processing where applicable
  • Right to data portability where applicable
  • Right to lodge a complaint with the relevant authority

Where CBET Master processes data on behalf of a QAB or institution, data subject requests should generally be directed to the relevant QAB or institution first.

ABNO will provide reasonable technical assistance where the request relates to data processed in CBET Master.

15. Children and Minor Trainees

Some trainees or learners whose data is processed through CBET Master or EduBridge may be minors.

Where data relates to minors, the relevant QAB or institution must ensure that the data is collected and processed lawfully, with appropriate notices, consent, authority or institutional mandate where required.

ABNO processes such data only for authorized platform, assessment, ePOE, reporting, certification, support and system administration purposes.

16. Certificate Verification

Where certificate verification is enabled, CBET Master may allow authorized stakeholders to verify certificate authenticity.

Verification should only display information reasonably necessary to confirm whether a certificate is valid, issued by the relevant QAB or institution, and linked to the stated qualification or assessment outcome.

Certificate verification must not be used for harassment, profiling, fraud or unauthorized personal data access.

17. System Notifications and Communications

CBET Master may send system notifications through:

  • In-app notifications
  • Email
  • SMS where enabled
  • WhatsApp where enabled
  • Other approved communication channels

Notifications may relate to:

  • User accounts
  • Password resets
  • Assessment registration
  • Approval status
  • Deadlines
  • ePOE readiness
  • Failed submissions
  • Support updates
  • Security alerts

Marketing communications are separate from essential system or security messages.

ABNO will not use QAB candidate or trainee assessment data for unrelated marketing.

18. Cross-Border Processing

Where hosting, backup, support, communication or technical service providers process data outside Kenya, ABNO will take reasonable steps to ensure that personal data remains protected in line with applicable law, contractual safeguards and data protection obligations.

Cross-border transfers, where applicable, shall be handled lawfully and responsibly.

19. Data Breach and Incident Response

Where ABNO becomes aware of a data breach or security incident affecting CBET Master, ABNO will take reasonable steps to:

  • Investigate the incident
  • Contain the risk
  • Notify affected QABs or institutions where required
  • Support legally required reporting
  • Take corrective action
  • Improve controls where necessary

Users should promptly report suspected unauthorized access, password compromise, data misuse or system abuse.

20. User Responsibilities

Users must:

  • Use CBET Master only for authorized purposes
  • Keep login credentials confidential
  • Avoid sharing accounts
  • Submit accurate and authorized data
  • Avoid uploading unlawful or misleading content
  • Respect confidentiality of candidate and assessment data
  • Report suspected unauthorized access
  • Follow QAB, institution and ABNO guidance
  • Log out from shared devices
  • Use only approved support channels for confidential matters

Misuse of data or unauthorized access may lead to access restriction, suspension or other action.

21. Contact for Data Protection Matters

For questions about this Data Protection Notice, CBET Master data handling, privacy requests or suspected misuse, contact:

ABNO Softwares International Ltd
Kaka House, 3rd Floor
Maua Close, Off Parklands Road
Westlands, Nairobi, Kenya

Email: info@abnosoftwares.com
Phone: +254 792 550 077

Where the concern relates to official candidate, trainee, staff, assessment or institutional data, users should first contact the relevant QAB or institution.

22. Complaints

Where a privacy concern relates to data controlled by a QAB or institution, the user should first contact the relevant QAB or institution.

Where the concern relates to ABNO’s operation of CBET Master, users may contact ABNO using the details above.

Users may also lodge a complaint with the relevant data protection authority where applicable.

23. Updates to This Notice

ABNO may update this Data Protection Notice from time to time to reflect changes in law, platform features, operational processes, security practices or contractual requirements.

The updated notice will be published through the CBET Master website or relevant platform channels.

24. Final Statement

CBET Master is built to support secure, credible and traceable digital CBET assessment.

Data protection is central to that trust.

CBET Master powers assessment and verifiable certification.

EduBridge powers trainee evidence readiness.

Responsible data handling protects every QAB, institution, trainee and stakeholder in the CBET ecosystem.