Privacy Policy
How we handle
your personal data.
This policy explains what personal data Innov8ProTech collects, how we use it, who we share it with, and the rights you have over it. It applies to our website, our marketing, our recruitment, and any other context where we handle personal data directly.
Version 1.2 · Effective April 2026
Contents
Section 01
Who we are
Innov8ProTech Ltd (“Innov8ProTech”, “we”, “us”) is a software engineering company registered in the Republic of Ghana, with its registered office at St. Mark Street, Com 18, Tema, Ghana.
For the purposes of Ghana’s Data Protection Act 843 (Act 843) we are the data controller for personal data we collect directly through our website, our business enquiries, and our recruitment. For personal data we process on behalf of a client inside a system we have built or operate, we act as a data processor — see Section 13.
Where the EU or UK GDPR applies (for example, if you are an EU-based visitor to our site), we accept the corresponding obligations under those regimes.
Section 02
Summary in plain language
The rest of this document is written to be legally precise. Here is the same thing in plain language:
- We collect the smallest amount of personal data we can to do the job. We don't ask for information we don't need.
- We use your data to answer your enquiries, run our projects, hire our team, and meet our legal obligations. We don't sell it. We don't rent it. We don't use it to train AI models.
- We share data only with a small number of trusted service providers — hosting, email, analytics — listed in Section 8.
- We keep data only as long as we need it, then delete it.
- You have rights — access, correction, deletion, objection. Section 12 tells you exactly how to use them.
- If you have a concern, contact us first at privacy@innov8protech.com. If we can't resolve it, you can complain to Ghana's Data Protection Commission.
Section 03
What personal data we collect
We collect personal data in the following categories. Not all categories apply to every person — for example, careers data only applies to job applicants.
Identity data
Examples
Full name, title, job role, company or agency name
Why
To know who we are talking to and to personalise communications
Contact data
Examples
Work email, phone number, postal address, country
Why
To respond to enquiries, send documents, and provide support
Technical data
Examples
IP address, browser type and version, device type, operating system, time zone
Why
To keep the site secure, diagnose issues, and understand aggregate usage
Usage data
Examples
Pages viewed, time on page, links clicked, referring URL
Why
To improve the website and understand what is useful
Form and enquiry data
Examples
Content of messages, project briefs, tender references, uploaded files
Why
To answer enquiries and prepare proposals
Application data (careers)
Examples
CV, cover letter, portfolio links, references
Why
To assess job applications and manage recruitment
Client project data
Examples
Data processed on behalf of clients inside systems we build or operate
Why
Handled under the Data Processor terms in Section 13, not under this policy
Section 04
How we use your data
We process personal data for the following purposes:
- To respond to enquiries submitted through our contact, proposal, or SLA request forms.
- To prepare proposals, contracts, and statements of work for prospective and active clients.
- To deliver, maintain, and support software we have built or operate for clients.
- To assess job applications and manage recruitment.
- To send transactional emails related to your enquiry or project (confirmations, updates, incident notifications).
- To protect the website from spam, abuse, and security threats.
- To analyse aggregate usage of the website so we can improve it. This is always anonymised or aggregated before review.
- To meet legal, tax, accounting, and regulatory obligations.
- To establish, exercise, or defend legal claims.
We do not sell personal data. We do not rent or share it for third-party marketing. We do not use customer data to train artificial intelligence models.
Section 05
Legal bases for processing
Under Act 843 and, where applicable, the GDPR, every processing activity must rest on a legal basis. We rely on the following:
Contract
We need the data to enter into or perform a contract with you — for example, to deliver a project you have engaged us for.
Legitimate interest
We have a legitimate business interest that does not override your rights — for example, protecting the site from abuse or replying to a business enquiry.
Consent
You have given us clear permission — for example, to send you a newsletter. You can withdraw consent at any time.
Legal obligation
We must process the data to comply with Ghanaian or other applicable law — for example, tax or accounting requirements.
Vital interests
Processing is necessary to protect someone's life — rare, but included for completeness.
Section 08
Subprocessors
The current list of vendors that may process personal data on our behalf. We notify affected parties before adding a new subprocessor where the change is material.
Vercel
Website hosting and edge delivery
Global edge network
Resend
Transactional email delivery
United States
Cloudflare
CDN, DDoS protection, DNS
Global edge network
Google Analytics
Aggregate website usage analytics
United States / EU
Microsoft 365
Business email and document storage
EU / United States
GitHub
Source code hosting
United States
Current as of April 2026. Material changes announced at least 30 days in advance to active clients.
Section 09
International transfers
Some of our service providers are based outside Ghana. Where personal data is transferred internationally, we ensure the transfer is lawful by one of the following mechanisms:
- Transferring only to jurisdictions recognised as providing adequate protection.
- Using standard contractual clauses or equivalent safeguards in the provider agreement.
- Where possible, storing data inside the client’s own region or on-premises.
For client project data (Section 13), the region is chosen by the client at contract stage. We do not move client data between regions without written instruction.
Section 10
How long we keep data
Contact and enquiry data
24 months from last contact, then deleted
Client project and contract records
Contract duration + 7 years (tax and legal requirement)
Job applications (unsuccessful)
12 months from decision, unless you ask us to keep longer
Job applications (hired)
Transferred to personnel record, retained while employed + 7 years
Website technical and usage logs
90 days rolling
Analytics (aggregated, anonymised)
26 months rolling
Marketing consent records
While consent is active + 3 years after withdrawal for proof
Finance and invoice records
7 years (Ghana Revenue Authority requirement)
Where a legal or regulatory obligation requires longer retention, that obligation overrides the period above.
Section 11
How we protect data
We apply technical and organisational measures proportionate to the sensitivity of the data:
- Encryption in transit (TLS 1.3) for all traffic between your device and our systems.
- Encryption at rest (AES-256) for databases and file storage.
- Access control — least privilege, role-based, with regular access reviews.
- Two-factor authentication (2FA) required for all internal systems.
- Audit logs of administrative access, retained and reviewed.
- Regular dependency scanning and security patching.
- Backups tested quarterly, stored separately from production.
- Staff confidentiality obligations and annual data protection training.
No system is 100% secure. If we become aware of a breach affecting your data, we will follow the notification process in Section 16.
Section 12
Your rights
You have the following rights under Act 843, and where applicable under the GDPR. We will respond to any request within 30 days, usually much sooner.
Right to be informed
You have the right to know how we handle your data. This page is how we do that.
Right of access
You can ask for a copy of the personal data we hold about you.
Right to rectification
You can ask us to correct data that is inaccurate or incomplete.
Right to erasure
You can ask us to delete your data where we no longer have a lawful reason to keep it.
Right to restrict processing
You can ask us to stop processing your data while a concern is being resolved.
Right to data portability
You can ask for your data in a structured, commonly used, machine-readable format.
Right to object
You can object to processing based on legitimate interests, or to direct marketing at any time.
Rights related to automated decisions
You have the right not to be subject to decisions made solely by automated means that have a significant effect on you. We do not currently make such decisions about you.
How to exercise a right
Email privacy@innov8protech.com with the right you want to exercise and enough information to identify you. We may ask for proof of identity before acting, to prevent someone else requesting your data.
If you are not satisfied with our response, you have the right to complain to the Data Protection Commission of Ghana or, where the GDPR applies, to your local supervisory authority.
privacy@innov8protech.comSection 13
Client data — our role as data processor
When we build or operate software for a client, personal data inside that system is owned and controlled by the client. Innov8ProTech acts as a data processor on the client’s behalf.
What that means in practice:
- The client decides what personal data is collected, why, and for how long. We process it only on the client’s documented instructions.
- Data subjects who want to exercise rights over client data should contact the client first. We will assist the client in responding.
- We do not use client data for our own purposes, and we do not disclose it except as required to deliver the service.
- If a client terminates, we return or delete the data on the client’s instruction and provide a deletion certificate.
- A Data Processing Agreement (DPA) is available on request and is signed before processing begins for any client project.
Section 14
Children’s data
Our website and services are not directed at children under 18. We do not knowingly collect personal data from children.
Where a client project involves processing data about minors (for example, a school admissions system), that processing is governed by the client’s data protection obligations under Section 13, and the client is responsible for obtaining any required parental consent.
If you believe we have inadvertently collected data about a child, contact privacy@innov8protech.com and we will delete it.
Section 15
Automated decision-making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals.
Where AI features are built into client systems (for example, recommendation engines, fraud detection, or document classification), those systems always run with human oversight, and the client is responsible for the design and justification of any automated decision-making that falls under their control.
Section 16
Data breaches
A personal data breach is any confirmed or suspected unauthorised access to, disclosure of, or loss of personal data.
Detection and assessment. We monitor for breaches continuously and assess any detected event within 24 hours to establish its scope, severity, and likely impact on individuals.
Notification. Where a breach is likely to result in a risk to individuals’ rights and freedoms, we notify:
- Affected individuals, without undue delay and where possible within 72 hours of assessment.
- The Data Protection Commission of Ghana, where the breach meets the notification threshold under Act 843.
- Client’s designated contact, where the affected data is client project data — within 24 hours of confirming the breach.
A full written post-incident report — timeline, root cause, remediation, and preventive measures — is provided within 5 business days.
Section 17
Changes to this policy
We review this policy at least once a year, and whenever we make a material change to how we handle personal data.
The current version is always available at innov8protech.com/privacy. The version number and effective date appear at the top of this page.
Material changes are announced to active clients by email at least 30 days before they take effect. If you continue to use our website or services after the effective date, you accept the updated policy.
If a change significantly reduces your rights, we will ask for your consent where the law requires it — we will not rely on continued use alone.
Section 18
How to contact us
Postal address
Innov8ProTech Ltd
St. Mark Street, Com 18
Tema, Ghana
Regulatory
We are registered with the Data Protection Commission of Ghana. If we cannot resolve your concern, you have the right to complain to the Commission directly.
Data Protection Commission of Ghana · dataprotection.org.gh
Section 19
Definitions
Personal data
Any information relating to an identified or identifiable natural person.
Data subject
The individual to whom personal data relates.
Controller
The entity that determines the purposes and means of processing personal data.
Processor
The entity that processes personal data on behalf of, and on the instructions of, a controller.
Processing
Any operation performed on personal data — collection, storage, use, disclosure, deletion, and so on.
Act 843
Ghana's Data Protection Act, 2012 (Act 843), and its subsidiary regulations.
GDPR
The EU General Data Protection Regulation (2016/679), where it applies to our processing.
Data breach
Any confirmed or suspected unauthorised access, disclosure, loss, or destruction of personal data.
Data Protection Commission
The statutory body in Ghana responsible for enforcing Act 843.
Questions
Something not covered here?
Our data protection contact answers within one business day. This includes access requests, correction requests, and questions about client project data.
