Privacy Policy
How we collect, use and protect personal data on this website and in the platforms we operate.
1. Who we are
CoreSoft Technologies Ltd is a company incorporated in Ghana, with its registered office at 97 Mile Street, Mile 7-Chantan Road, Accra. For the purposes of the Data Protection Act, 2012 (Act 843), CoreSoft is the data controller for personal data collected through this website, and a data processor for personal data processed inside platforms we operate on behalf of client institutions.
2. What we collect
Through this website we collect only what you provide and what is necessary to operate the site:
- What you submit through the contact form: name, work email, organisation, role, sector, platform of interest and your message.
- Information you send by email, including applications sent to our careers address.
- A single browser storage entry recording your light or dark colour mode preference. This stays on your device and is never transmitted to us.
- Standard server logs generated by our hosting provider, including IP address, browser type and pages requested, retained for security and diagnostic purposes.
This website does not use advertising cookies, third-party analytics trackers or cross-site profiling.
3. Why we use it
We process the personal data you submit in order to:
- Respond to your enquiry and arrange a demonstration or scoping conversation.
- Send the specific guide, insight piece or event information you requested.
- Assess an application for a role at CoreSoft.
- Maintain the security, availability and integrity of our systems.
- Meet our legal, regulatory and accounting obligations.
We do not add you to a marketing list because you requested a demonstration. If we ever offer a mailing list, it will require separate opt-in consent that you can withdraw at any time.
4. Legal basis
We rely on your consent where you submit a form or send us an email, on the necessity of processing to take steps prior to entering a contract where you are evaluating our platforms, and on our legitimate interest in operating and securing our website. Where we act as a processor for a client institution, that institution determines the purpose and legal basis, and we process only on its documented instructions.
5. Client platform data
Personal data held inside CoreSoft platforms, such as borrower, policyholder, patient, farmer and taxpayer records, belongs to the client institution operating that platform. CoreSoft accesses such data only where necessary to provide support, and under the terms of the relevant services agreement. That agreement, not this policy, governs the handling of that data.
By default, personal data held in a client instance is not used to train models applied to any other client. Any such use requires a separate written agreement with the institution concerned.
6. Sharing
We do not sell personal data, and we do not share it with third parties for their own marketing purposes. We share personal data only with:
- Service providers that host our infrastructure or deliver our email, bound by contractual confidentiality and processing obligations.
- Professional advisers where necessary for legal, audit or accounting purposes.
- Regulators, law enforcement or courts where we are legally required to do so.
7. Retention
Enquiry and demo request records are retained for twenty-four months from your last contact with us, unless you ask us to remove them sooner. Unsuccessful job applications are retained for twelve months so we can consider you for future roles, unless you ask us not to. Server logs are retained for ninety days. Records we are required to keep for statutory accounting or tax purposes are retained for the period the law requires.
8. Security
We apply encryption in transit, role-based access control, least-privilege administrative access and audit logging across our systems. Access to enquiry data is limited to staff who need it to respond to you. No system is perfectly secure, but we treat a breach affecting personal data as an incident requiring notification to affected individuals and the Data Protection Commission where the Act requires it.
9. Your rights
Under the Data Protection Act, 2012 you have the right to:
- Ask what personal data we hold about you and receive a copy of it.
- Ask us to correct data that is inaccurate or incomplete.
- Ask us to delete data where we no longer have a lawful basis to hold it.
- Object to processing, or ask us to restrict it while a concern is resolved.
- Withdraw consent at any time, without affecting processing already carried out.
- Complain to the Data Protection Commission of Ghana.
Where the data sits inside a client institution's platform, we will refer your request to that institution as the controller and support them in answering it.
10. International transfers
Where our hosting or email infrastructure processes data outside Ghana, we ensure appropriate safeguards are in place. Client deployments can be hosted in-country or on client premises where data residency requires it. This is agreed per deployment.
11. Changes to this policy
We will update this page when our practice changes and revise the date above. Material changes affecting how we use data you have already given us will be notified directly where we hold contact details for you.
12. Contact
For any question about this policy, or to exercise any of the rights above, write to us at info@coresoft.com.gh. You can also reach us through our contact page.