Legal

    Privacy Policy

    Effective 16 April 2026. We will post changes to this page and update the effective date.

    Under legal review. This policy is being finalised with Ghanaian counsel. It reflects how CediSync actually operates today; wording may be refined as the review completes.
    01

    What we collect

    When you use CediSync we collect information in two ways: what you give us directly (account details, bureau details, billing information) and what the product generates as you use it (transaction records, audit log entries, device and session data).

    • Account data: name, email, phone, role.
    • Bureau data: bureau name, branches, staff list, currencies, rates, trades, customer records, vault balances, expenses.
    • Billing data: subscription status, invoices, payment reference (full card details are handled by Paystack, not us).
    • Usage data: pages visited, actions taken, timestamps, IP address, browser and device identifiers.
    02

    How we use it

    We use this data to operate the service, keep it secure, bill you, support you when you ask, and improve the product.

    We do not sell your data. We do not use your bureau data to train models. We do not use your customer records for anything other than providing the service back to you.

    03

    Legal basis

    We process personal data on the following bases under the Ghana Data Protection Act, 2012 (Act 843):

    • Contract: to deliver the service you have signed up for.
    • Legal obligation: to meet tax, AML, and regulatory requirements.
    • Legitimate interest: to secure the service, prevent fraud, and improve the product.
    • Consent: for optional communications you have opted into.
    04

    Who we share with

    We share data with vetted sub-processors who help us run the service — for hosting, email delivery, payments, and analytics — under written agreements that bind them to comparable or stronger protections than this policy.

    Current sub-processors:

    • Supabase (managed Postgres, auth, edge functions — hosted on AWS eu-west-1, Ireland)
    • Hostinger (marketing site hosting)
    • Resend (transactional email delivery)
    • Paystack (subscription billing and payments)

    We update this list when it changes.

    05

    How long we keep it

    Account and bureau data is retained for the duration of your subscription and for 90 days after cancellation, during which you can export your records or reinstate the account. After 90 days we delete the data from production systems. Encrypted backups are purged on their normal rotation schedule within 35 days.

    Audit log entries are retained for the life of your account. Billing records are retained for the period required by tax law.

    06

    Your rights

    Under Ghanaian data protection law you have the right to:

    • Access a copy of the personal data we hold about you.
    • Correct data that is wrong.
    • Have data deleted where it is no longer needed for the purpose collected.
    • Object to processing in certain cases.
    • Lodge a complaint with the Data Protection Commission.

    To exercise any of these rights, email support@cedisync.com. We respond within 30 days.

    07

    International transfers

    Your data is hosted in AWS eu-west-1 (Ireland) via Supabase. Where a sub-processor operates outside the EU/Ghana, we use appropriate safeguards — standard contractual clauses or equivalent — to ensure protections travel with the data.

    08

    Security

    Encryption at rest and in transit, row-level data isolation per bureau, role-based access (Owner / Supervisor / Teller), audit logging of changes, and daily encrypted backups.

    09

    Changes to this policy

    We update this policy when the underlying facts change. Material changes are notified by email to the account owner at least 30 days before they take effect. Non-material clarifications are posted here with an updated effective date.

    10

    Contact

    For privacy questions, data subject requests, or general enquiries: