Legal · Coskon Technologies Ltd
Data Protection (Act 843)
How Akoben approaches Ghana's Data Protection Act 2012 (Act 843): the rights it gives data subjects, the role of the Data Protection Commission, and the commitments we make about your data.
- Last updated
- 17 August 2026
- Document
- AKB-LEG-003
1Our commitment
We do not sell, share or use your operational data to train anything.
This is the same commitment published in the FAQ on our home page, repeated here in full. Your organisation owns the data it puts into Akoben. Coskon Technologies Ltd processes it on your behalf to run the service and for nothing else. We do not make it available to advertisers or data brokers, we do not pool it with other customers' data to create a product, and we do not use it as training material for machine learning or artificial intelligence — neither our own nor a third party's.
The only exceptions are the sub-processors listed in the Privacy Policy, each of which handles a specific, necessary part of running the service, and a disclosure we are legally compelled to make — in which case we will tell you unless we are prohibited from doing so.
2Act 843 in this context
Ghana's Data Protection Act 2012 (Act 843) regulates the processing of personal data and establishes the Data Protection Commission. Under the Act, the entity that determines why and how personal data is processed is the data controller, and an entity processing on its behalf is a data processor.
- Your organisation is the data controller for the staff, contractor, visitor and vehicle records it enters into Akoben. Registration under the Act, and having a lawful basis for that data, is your organisation's responsibility.
- Coskon Technologies Ltd is the data processor for that data. We act on your instructions and do not use it for our own purposes.
- We are the controller for the account and billing data we hold about you directly.
We apply the Act's principles — accountability, lawfulness, specification of purpose, compatibility of further processing, data quality, openness, security safeguards, and data subject participation — to how the product is built, not only to how it is documented.
3Your rights as a data subject
Act 843 gives individuals the following rights over their personal data. Here is how each one works in practice with Akoben.
| Right | What it means | How to exercise it |
|---|---|---|
| Right to be informed | To know that your data is being processed, by whom and for what purpose. That is what this document and the Privacy Policy are for. | Read these documents, or ask your company administrator who holds your record. |
| Right of access | To obtain a copy of the personal data held about you. | Ask your company administrator, who can export it from the reporting module, or write to us and we will retrieve it. |
| Right to correction | To have inaccurate or incomplete data corrected. | Edit your own profile in Settings, or ask your administrator to correct a record you cannot edit. |
| Right to object and to prevent processing | To object to processing likely to cause unwarranted damage or distress, including processing for direct marketing. | Write to us. Notification emails and SMS can also be switched off per user in notification preferences. |
| Right to erasure and blocking | To have data erased or blocked where it is inaccurate, irrelevant, excessive or held longer than necessary. | Write to us. Deletion of a whole workspace is handled manually — there is no self-service button yet. |
| Right to complain | To complain to the Data Protection Commission if you are not satisfied with how we have handled a request. | See the Data Protection Commission section below. |
Requests go to osnimoh@coskon.com. We aim to acknowledge within 5 working days and to respond substantively within 30 days. Where you are an employee of a customer organisation, we will normally route your request through that organisation, because it is the controller of your record — we will tell you when we do.
4The Data Protection Commission
The Data Protection Commission is the independent statutory body established under Act 843 to regulate the processing of personal data in Ghana. It maintains the register of data controllers, issues guidance, investigates complaints, and can order a controller to stop processing or to correct or delete data.
If you are not satisfied with how we have handled a data protection request or complaint, you are entitled to take it to the Commission, and you do not need our permission to do so. Contact details are published on the Commission's official website. We would appreciate the chance to put things right first — but the right to complain is yours to use whenever you choose.
5Cross-border processing
Act 843 places conditions on transferring personal data outside Ghana. You should assume that such a transfer takes place whenever you use Akoben. Akoben runs on Supabase and is not hosted in Ghana. Data is held on Supabase cloud infrastructure, and email delivery (Resend) and application hosting are likewise outside Ghana. SMS delivery uses Arkesel, which operates in Ghana. Payment processing is not active during the pilot, as no charging takes place. When charging begins it will be handled by Paystack, and we will state where that processing occurs before it does.
If your organisation is subject to a data localisation requirement, tell us before onboarding. Akoben cannot keep your data inside Ghana today, and we would rather say so than let you find out during an audit.
6Security safeguards
The measures currently in place:
- Row-level security is enforced in the database on every table, scoping every record to the owning company. Isolation does not depend on the application getting a filter right.
- Roles are scoped per company. Holding an administrator role in one organisation grants no privileges in another.
- Optional TOTP multi-factor authentication, and a stronger authentication level required for sensitive tables where a user has enrolled.
- Sessions expire after 30 minutes of inactivity.
- Encryption in transit and at rest, provided by the underlying platform.
- Audit logs recording who changed what and when.
- Server-side re-validation of input and of company membership in backend functions, rather than trusting the browser.
Stated honestly: we have not undergone an independent security audit or certification, and there is no formal breach notification procedure documented beyond our commitment to notify affected company administrators, and the Commission where the Act requires it, without undue delay after we become aware of a breach.
7Retention and deletion
Data is retained for as long as your workspace is active. You can export records to CSV, Excel or PDF at any time from the reporting module. Deletion of an entire workspace is performed manually on request — there is no self-service control for it yet, and there is no automatic retention schedule expiring old records. Audit logs are deliberately retained so the trail stays tamper-evident.
8Raising a concern with us
Data protection queries, access requests and complaints go to osnimoh@coskon.com or +233 24 315 2717. We have not yet appointed a formal Data Protection Officer; until we do, these requests are handled directly by the company's management.