Innov8ProTech

Privacy Policy

How we handle
your personal data.

This policy explains what personal data Innov8ProTech collects, how we use it, who we share it with, and the rights you have over it. It applies to our website, our marketing, our recruitment, and any other context where we handle personal data directly.

Contact privacy contact

Version 1.2 · Effective April 2026

Section 01

Who we are

Innov8ProTech Ltd (“Innov8ProTech”, “we”, “us”) is a software engineering company registered in the Republic of Ghana, with its registered office at St. Mark Street, Com 18, Tema, Ghana.

For the purposes of Ghana’s Data Protection Act 843 (Act 843) we are the data controller for personal data we collect directly through our website, our business enquiries, and our recruitment. For personal data we process on behalf of a client inside a system we have built or operate, we act as a data processor — see Section 13.

Where the EU or UK GDPR applies (for example, if you are an EU-based visitor to our site), we accept the corresponding obligations under those regimes.

Section 02

Summary in plain language

The rest of this document is written to be legally precise. Here is the same thing in plain language:

  • We collect the smallest amount of personal data we can to do the job. We don't ask for information we don't need.
  • We use your data to answer your enquiries, run our projects, hire our team, and meet our legal obligations. We don't sell it. We don't rent it. We don't use it to train AI models.
  • We share data only with a small number of trusted service providers — hosting, email, analytics — listed in Section 8.
  • We keep data only as long as we need it, then delete it.
  • You have rights — access, correction, deletion, objection. Section 12 tells you exactly how to use them.
  • If you have a concern, contact us first at privacy@innov8protech.com. If we can't resolve it, you can complain to Ghana's Data Protection Commission.

Section 03

What personal data we collect

We collect personal data in the following categories. Not all categories apply to every person — for example, careers data only applies to job applicants.

Identity data

Examples

Full name, title, job role, company or agency name

Why

To know who we are talking to and to personalise communications

Contact data

Examples

Work email, phone number, postal address, country

Why

To respond to enquiries, send documents, and provide support

Technical data

Examples

IP address, browser type and version, device type, operating system, time zone

Why

To keep the site secure, diagnose issues, and understand aggregate usage

Usage data

Examples

Pages viewed, time on page, links clicked, referring URL

Why

To improve the website and understand what is useful

Form and enquiry data

Examples

Content of messages, project briefs, tender references, uploaded files

Why

To answer enquiries and prepare proposals

Application data (careers)

Examples

CV, cover letter, portfolio links, references

Why

To assess job applications and manage recruitment

Client project data

Examples

Data processed on behalf of clients inside systems we build or operate

Why

Handled under the Data Processor terms in Section 13, not under this policy

Section 04

How we use your data

We process personal data for the following purposes:

  • To respond to enquiries submitted through our contact, proposal, or SLA request forms.
  • To prepare proposals, contracts, and statements of work for prospective and active clients.
  • To deliver, maintain, and support software we have built or operate for clients.
  • To assess job applications and manage recruitment.
  • To send transactional emails related to your enquiry or project (confirmations, updates, incident notifications).
  • To protect the website from spam, abuse, and security threats.
  • To analyse aggregate usage of the website so we can improve it. This is always anonymised or aggregated before review.
  • To meet legal, tax, accounting, and regulatory obligations.
  • To establish, exercise, or defend legal claims.

We do not sell personal data. We do not rent or share it for third-party marketing. We do not use customer data to train artificial intelligence models.

Section 06

Cookies and tracking

Our website uses a small number of cookies and similar technologies. We have deliberately kept this minimal.

Strictly necessary

Required for the site to function — session, security, load balancing. Cannot be disabled.

Analytics

Aggregate, anonymised usage statistics. No cross-site tracking. Can be disabled in your browser.

Preferences

Remember your last choices — for example, whether you dismissed a notice. Optional.

Marketing

We do not currently run any marketing or advertising cookies, and have no current plans to.

You can control cookies through your browser settings. Blocking strictly necessary cookies may prevent parts of the website from working.

Section 07

Who we share data with

We share personal data only in these circumstances:

  • Service providers. A small number of trusted vendors that help us run the business — hosting, email delivery, analytics, source control. These are listed in Section 8 and each is bound by a data processing agreement.
  • Professional advisers. Lawyers, auditors, and accountants, where necessary and under confidentiality obligations.
  • Legal and regulatory. Where we are required by law, court order, or a regulator — for example, in response to a lawful request from a Ghanaian authority.
  • Business transfers. If Innov8ProTech is acquired, merged, or its assets transferred, personal data may transfer as part of that transaction. We would notify affected individuals and any new controller would be bound by this policy or an equivalent one.

We do not sell data. We do not share it for advertising. We do not share it with the police or any authority except under a lawful, written request.

Section 08

Subprocessors

The current list of vendors that may process personal data on our behalf. We notify affected parties before adding a new subprocessor where the change is material.

Vercel

Website hosting and edge delivery

Global edge network

Resend

Transactional email delivery

United States

Cloudflare

CDN, DDoS protection, DNS

Global edge network

Google Analytics

Aggregate website usage analytics

United States / EU

Microsoft 365

Business email and document storage

EU / United States

GitHub

Source code hosting

United States

Current as of April 2026. Material changes announced at least 30 days in advance to active clients.

Section 09

International transfers

Some of our service providers are based outside Ghana. Where personal data is transferred internationally, we ensure the transfer is lawful by one of the following mechanisms:

  • Transferring only to jurisdictions recognised as providing adequate protection.
  • Using standard contractual clauses or equivalent safeguards in the provider agreement.
  • Where possible, storing data inside the client’s own region or on-premises.

For client project data (Section 13), the region is chosen by the client at contract stage. We do not move client data between regions without written instruction.

Section 10

How long we keep data

Contact and enquiry data

24 months from last contact, then deleted

Client project and contract records

Contract duration + 7 years (tax and legal requirement)

Job applications (unsuccessful)

12 months from decision, unless you ask us to keep longer

Job applications (hired)

Transferred to personnel record, retained while employed + 7 years

Website technical and usage logs

90 days rolling

Analytics (aggregated, anonymised)

26 months rolling

Marketing consent records

While consent is active + 3 years after withdrawal for proof

Finance and invoice records

7 years (Ghana Revenue Authority requirement)

Where a legal or regulatory obligation requires longer retention, that obligation overrides the period above.

Section 11

How we protect data

We apply technical and organisational measures proportionate to the sensitivity of the data:

  • Encryption in transit (TLS 1.3) for all traffic between your device and our systems.
  • Encryption at rest (AES-256) for databases and file storage.
  • Access control — least privilege, role-based, with regular access reviews.
  • Two-factor authentication (2FA) required for all internal systems.
  • Audit logs of administrative access, retained and reviewed.
  • Regular dependency scanning and security patching.
  • Backups tested quarterly, stored separately from production.
  • Staff confidentiality obligations and annual data protection training.

No system is 100% secure. If we become aware of a breach affecting your data, we will follow the notification process in Section 16.

Section 12

Your rights

You have the following rights under Act 843, and where applicable under the GDPR. We will respond to any request within 30 days, usually much sooner.

Right to be informed

You have the right to know how we handle your data. This page is how we do that.

Right of access

You can ask for a copy of the personal data we hold about you.

Right to rectification

You can ask us to correct data that is inaccurate or incomplete.

Right to erasure

You can ask us to delete your data where we no longer have a lawful reason to keep it.

Right to restrict processing

You can ask us to stop processing your data while a concern is being resolved.

Right to data portability

You can ask for your data in a structured, commonly used, machine-readable format.

Right to object

You can object to processing based on legitimate interests, or to direct marketing at any time.

Rights related to automated decisions

You have the right not to be subject to decisions made solely by automated means that have a significant effect on you. We do not currently make such decisions about you.

How to exercise a right

Email privacy@innov8protech.com with the right you want to exercise and enough information to identify you. We may ask for proof of identity before acting, to prevent someone else requesting your data.

If you are not satisfied with our response, you have the right to complain to the Data Protection Commission of Ghana or, where the GDPR applies, to your local supervisory authority.

privacy@innov8protech.com

Section 13

Client data — our role as data processor

When we build or operate software for a client, personal data inside that system is owned and controlled by the client. Innov8ProTech acts as a data processor on the client’s behalf.

What that means in practice:

  • The client decides what personal data is collected, why, and for how long. We process it only on the client’s documented instructions.
  • Data subjects who want to exercise rights over client data should contact the client first. We will assist the client in responding.
  • We do not use client data for our own purposes, and we do not disclose it except as required to deliver the service.
  • If a client terminates, we return or delete the data on the client’s instruction and provide a deletion certificate.
  • A Data Processing Agreement (DPA) is available on request and is signed before processing begins for any client project.

Section 14

Children’s data

Our website and services are not directed at children under 18. We do not knowingly collect personal data from children.

Where a client project involves processing data about minors (for example, a school admissions system), that processing is governed by the client’s data protection obligations under Section 13, and the client is responsible for obtaining any required parental consent.

If you believe we have inadvertently collected data about a child, contact privacy@innov8protech.com and we will delete it.

Section 15

Automated decision-making

We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals.

Where AI features are built into client systems (for example, recommendation engines, fraud detection, or document classification), those systems always run with human oversight, and the client is responsible for the design and justification of any automated decision-making that falls under their control.

Section 16

Data breaches

A personal data breach is any confirmed or suspected unauthorised access to, disclosure of, or loss of personal data.

Detection and assessment. We monitor for breaches continuously and assess any detected event within 24 hours to establish its scope, severity, and likely impact on individuals.

Notification. Where a breach is likely to result in a risk to individuals’ rights and freedoms, we notify:

  • Affected individuals, without undue delay and where possible within 72 hours of assessment.
  • The Data Protection Commission of Ghana, where the breach meets the notification threshold under Act 843.
  • Client’s designated contact, where the affected data is client project data — within 24 hours of confirming the breach.

A full written post-incident report — timeline, root cause, remediation, and preventive measures — is provided within 5 business days.

Section 17

Changes to this policy

We review this policy at least once a year, and whenever we make a material change to how we handle personal data.

The current version is always available at innov8protech.com/privacy. The version number and effective date appear at the top of this page.

Material changes are announced to active clients by email at least 30 days before they take effect. If you continue to use our website or services after the effective date, you accept the updated policy.

If a change significantly reduces your rights, we will ask for your consent where the law requires it — we will not rely on continued use alone.

Section 18

How to contact us

Data protection contact

privacy@innov8protech.com

For any privacy question, request, or concern.

Postal address

Innov8ProTech Ltd

St. Mark Street, Com 18
Tema, Ghana

Regulatory

We are registered with the Data Protection Commission of Ghana. If we cannot resolve your concern, you have the right to complain to the Commission directly.

Data Protection Commission of Ghana · dataprotection.org.gh

Section 19

Definitions

Personal data

Any information relating to an identified or identifiable natural person.

Data subject

The individual to whom personal data relates.

Controller

The entity that determines the purposes and means of processing personal data.

Processor

The entity that processes personal data on behalf of, and on the instructions of, a controller.

Processing

Any operation performed on personal data — collection, storage, use, disclosure, deletion, and so on.

Act 843

Ghana's Data Protection Act, 2012 (Act 843), and its subsidiary regulations.

GDPR

The EU General Data Protection Regulation (2016/679), where it applies to our processing.

Data breach

Any confirmed or suspected unauthorised access, disclosure, loss, or destruction of personal data.

Data Protection Commission

The statutory body in Ghana responsible for enforcing Act 843.

Questions

Something not covered here?

Our data protection contact answers within one business day. This includes access requests, correction requests, and questions about client project data.