Legal

Data Processing Policy

Last Updated: March 2026

This Data Processing Policy (“Policy”) sets out how Freedom Protocol Ghana Limited Company, trading as Freedom Protocol (“we”, “us”, “the Controller”), collects, processes, stores, and protects personal data. This Policy is drafted in compliance with the Ghana Data Protection Act, 2012 (Act 843) and its implementing regulations, and incorporates principles from the EU General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679 to the extent that data subjects located in the European Economic Area interact with our platform.

Freedom Protocol is a proprietary health platform developed and operated by Freedom Protocol Ghana Limited Company.

1. Definitions

  • “Personal Data”means any information relating to an identified or identifiable natural person (“Data Subject”), including name, email, location, IP address, and health-related information.
  • “Special Category Data” (GDPR Art. 9) / “Sensitive Personal Data” (Act 843, s.96) means data concerning health, including self-reported metabolic conditions, community group memberships, and any content shared in health-related discussions.
  • “Processing” means any operation performed on Personal Data, whether automated or manual, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
  • “Data Subject” means any individual whose Personal Data is processed by us, including community members, health professionals, and site visitors.
  • “Sub-Processor” means any third-party entity that processes Personal Data on our behalf.

2. Data Controller

The data controller responsible for processing under this Policy is:

Entity:
Freedom Protocol Ghana Limited Company
Trading As:
Freedom Protocol
Jurisdiction:
Republic of Ghana
Email:
dpo@freedomprotocol.health
Address:
Freedom Protocol Ghana Limited Company, House Number HNC/24, Oak Street, First Link Road, McCarthy Hills, Accra, Greater Accra, Ghana, GS-138-1590

We are registered (or in the process of registration) as a Data Controller with the Data Protection Commission of Ghana in accordance with Section 26 of Act 843.

3. Lawful Basis for Processing

We process Personal Data only where we have a lawful basis to do so. The applicable bases under Act 843 (Section 18) and GDPR (Article 6) are:

3.1 Consent (Act 843 s.18(1)(a) / GDPR Art. 6(1)(a))

Where Data Subjects provide explicit, informed, freely given, and withdrawable consent — for example, when registering an account, joining a condition-specific community group, or enabling analytics cookies.

3.2 Performance of a Contract (GDPR Art. 6(1)(b))

Processing necessary to provide our platform services, including account management, event registration, and connecting members with health professionals.

3.3 Legitimate Interest (Act 843 s.18(1)(e) / GDPR Art. 6(1)(f))

Processing necessary for platform security, fraud prevention, service improvement, and anonymised analytics — where such interests are not overridden by the rights and freedoms of the Data Subject.

3.4 Legal Obligation (Act 843 s.18(1)(c) / GDPR Art. 6(1)(c))

Processing required to comply with applicable laws, regulatory requirements, or lawful court orders within the Republic of Ghana or other applicable jurisdictions.

3.5 Vital Interests (GDPR Art. 6(1)(d))

In exceptional circumstances involving a threat to life or health, we may process data without prior consent where necessary to protect vital interests.

4. Processing of Special Category / Sensitive Data

Freedom Protocol processes health-related data that qualifies as Special Category Data under GDPR Article 9 and Sensitive Personal Data under Act 843 Section 96. We process this data only where:

  • The Data Subject has given explicit consent (GDPR Art. 9(2)(a) / Act 843 s.97(a));
  • Processing is necessary for reasons of substantial public interest in the area of public health (GDPR Art. 9(2)(i));
  • Processing relates to data manifestly made public by the Data Subject — e.g., voluntary posts in public community forums (GDPR Art. 9(2)(e)).

We implement additional safeguards for health data, including privacy-by-design architecture that masks user identities in anonymous posts at the database level, and restricts profile access via role-based security views.

5. Categories of Personal Data Processed

CategoryExamplesPurpose
Identity DataFull name, email, phoneAccount creation, communication
Location DataRegion, districtRegional community matching
Health DataSelf-reported conditions, community group membershipsCondition-specific peer support
Professional DataCredentials, registration numbers, institutionProfessional verification
Content DataDiscussion posts, replies, event chat messagesCommunity engagement
Technical DataIP address, browser type, device info, cookiesSecurity, analytics, performance

6. Data Processing Principles

In accordance with Act 843 (Section 17) and GDPR (Article 5), we adhere to the following principles:

  • Lawfulness, Fairness, and Transparency: Data is processed lawfully, fairly, and in a transparent manner. Data Subjects are informed of processing activities through this Policy and related notices.
  • Purpose Limitation: Data is collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
  • Data Minimisation: We collect only data that is adequate, relevant, and limited to what is necessary for the stated purposes.
  • Accuracy: We take reasonable steps to ensure data is accurate and, where necessary, kept up to date. Data Subjects may request corrections at any time.
  • Storage Limitation: Data is retained only for as long as necessary for the purposes for which it was collected, or as required by law.
  • Integrity and Confidentiality: Data is processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing, accidental loss, destruction, or damage.
  • Accountability: The Controller is responsible for, and able to demonstrate compliance with, all of the above principles.

7. Data Subject Rights

Under Act 843 (Sections 18–20) and GDPR (Articles 15–22), Data Subjects have the following rights:

  • Right of Access (Art. 15 / s.18(3)): Request a copy of your Personal Data and information about how it is processed.
  • Right to Rectification (Art. 16 / s.18(4)): Request correction of inaccurate or incomplete data.
  • Right to Erasure (Art. 17): Request deletion of your data where there is no compelling reason for continued processing.
  • Right to Restriction (Art. 18): Request that processing be limited in certain circumstances.
  • Right to Data Portability (Art. 20): Receive your data in a structured, commonly used, machine-readable format.
  • Right to Object (Art. 21 / s.18(5)): Object to processing based on legitimate interests or direct marketing.
  • Right to Withdraw Consent (Art. 7(3) / s.18(6)): Withdraw consent at any time without affecting the lawfulness of prior processing.
  • Right to Lodge a Complaint: File a complaint with the Data Protection Commission of Ghana or, for EEA residents, the relevant supervisory authority.

To exercise any of these rights, contact dpo@freedomprotocol.health. We will respond within 30 days (Act 843) or one calendar month (GDPR), as applicable.

8. Data Retention Schedule

Data TypeRetention PeriodBasis
Account / profile dataDuration of active account + 12 monthsContract / consent
Community posts & discussionsDuration of active account; deleted on requestConsent
Professional credentialsDuration of verified status + 24 monthsLegitimate interest
Event registration records12 months after event dateContract
Server logs & technical data90 days (rolling)Legitimate interest / security
Anonymised analyticsIndefinite (non-identifiable)Legitimate interest

9. Sub-Processors and Third-Party Sharing

We engage the following categories of Sub-Processors, each bound by Data Processing Agreements (DPAs) that meet Act 843 and GDPR requirements:

  • Cloud Infrastructure: Hosting, database, and authentication services (data encrypted at rest and in transit).
  • Email / Communication: Transactional email delivery for account verification and event notifications.
  • Analytics: Anonymised usage analytics to improve platform performance (no Personal Data shared without consent).
  • Social Authentication Providers: Google and Facebook for optional sign-in — limited to name, email, and profile photo as authorised by the Data Subject.

We do NOT sell, rent, or trade Personal Data to any third party for marketing or commercial purposes.

10. International Data Transfers

Our infrastructure may process data in jurisdictions outside of Ghana. Where cross-border transfers occur, we ensure adequate protection through:

  • Adequacy Decisions: Transfers to countries recognised by the Data Protection Commission or the European Commission as providing adequate protection.
  • Standard Contractual Clauses (SCCs): EU-approved SCCs incorporated into Sub-Processor agreements (GDPR Art. 46(2)(c)).
  • Supplementary Measures: Encryption in transit (TLS 1.3), encryption at rest (AES-256), and access controls ensuring data remains protected irrespective of jurisdiction.
  • Act 843 Compliance: Prior authorisation from the Data Protection Commission obtained where required under Section 50 for transfers to non-adequate jurisdictions.

11. Technical and Organisational Security Measures

In accordance with GDPR Article 32 and Act 843 Section 28, we implement the following measures:

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for data at rest
  • Row-Level Security (RLS) policies on all database tables ensuring users can access only their own data unless authorised
  • Privacy-by-design database views that mask user identity for anonymous posts
  • Role-based access controls (RBAC) for administrators and moderators
  • Leaked password protection and secure authentication flows
  • Regular vulnerability scanning and security audits
  • Automated backup and disaster recovery procedures
  • Principle of least privilege for all system access

12. Data Protection Impact Assessments (DPIAs)

Where processing is likely to result in a high risk to the rights and freedoms of Data Subjects — particularly given the health-related nature of our platform — we conduct Data Protection Impact Assessments in accordance with GDPR Article 35 and the guidance of the Data Protection Commission. DPIAs are reviewed and updated when processing activities change materially.

13. Data Breach Notification

In the event of a personal data breach:

  • Regulatory Notification:We will notify the Data Protection Commission of Ghana within 72 hours of becoming aware of a breach that is likely to result in a risk to Data Subjects' rights and freedoms (GDPR Art. 33 / Act 843 s.29).
  • Data Subject Notification: Where a breach is likely to result in a high risk to Data Subjects, we will notify affected individuals without undue delay (GDPR Art. 34).
  • Record-Keeping: All breaches, including those not requiring notification, are documented in an internal breach register with details of the nature, effects, and remedial actions taken.

14. Children's Data

Freedom Protocol is not directed at individuals under the age of 18. We do not knowingly collect or process Personal Data from minors. If a Data Subject is between 13 and 17 years of age, use of the platform requires verifiable parental or guardian consent. If we become aware that we have collected data from a child without appropriate consent, we will take steps to delete such data promptly.

15. Automated Decision-Making and Profiling

Freedom Protocol does not currently engage in automated decision-making or profiling that produces legal effects or similarly significant effects on Data Subjects (GDPR Art. 22). Any future use of automated processing will be disclosed in this Policy and will be subject to appropriate safeguards including the right to obtain human intervention.

16. Cookies and Tracking Technologies

Our use of cookies and similar technologies is governed by our separate Cookie Policy. Data Subjects may manage their cookie preferences at any time through the Cookie Settings control in the site footer.

17. Governing Law and Jurisdiction

This Policy is governed by the laws of the Republic of Ghana, including the Data Protection Act, 2012 (Act 843). For Data Subjects located in the European Economic Area, the provisions of the GDPR shall apply concurrently to the extent required. Any disputes arising from this Policy shall be subject to the exclusive jurisdiction of the courts of the Republic of Ghana, without prejudice to the right of EEA Data Subjects to lodge complaints with their local supervisory authority.

18. Changes to This Policy

We reserve the right to amend this Policy at any time. Material changes will be communicated to Data Subjects via email or a prominent notice on the platform. The “Last Updated” date at the top of this page indicates the most recent revision. Continued use of the platform after changes take effect constitutes acceptance of the revised Policy.

19. Data Protection Officer

For all data protection inquiries, rights requests, or complaints:

Data Protection Officer:
Freedom Protocol Ghana Limited Company
Email:
dpo@freedomprotocol.health
Address:
Freedom Protocol Ghana Limited Company, House Number HNC/24, Oak Street, First Link Road, McCarthy Hills, Accra, Greater Accra, Ghana, GS-138-1590
Supervisory Authority:
Data Protection Commission of Ghana — www.dataprotection.org.gh