These documents govern your use of Nnarksup and are written to be read. Nothing here replaces advice from your own lawyer on your particular situation.
Part I. Privacy Policy
Nnarksup Privacy Policy
- Effective Date: 01/08/2026
- Last Updated: 20/08/2026
- Controller: Nnarksup Company Limited, Accra, Ghana
- Contact: legal@nnarksup.com
I.1 Introduction
I.1.1 Our Commitment to Privacy
- Nnarksup Company Limited ("Nnarksup," "we," "us," "our") is committed to protecting the privacy and security of your personal data. This Privacy Policy explains how we collect, use, share, store, and protect information when you use our Platform and Services.
I.1.2 Scope
This Privacy Policy applies to:
- All Users: Individuals and businesses using Nnarksup to manage projects
- All Providers: Contractors and service providers registered on the Platform
- Website Visitors: Anyone browsing www.nnarksup.com
I.1.3 Your Rights
- You have rights regarding your personal data, including the right to access, correct, delete, and object to processing. See Section 9 for details.
I.1.4 Updates to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the updated Policy on the Platform
- Sending email notification (for significant changes)
- Requiring re-acceptance upon next login (for material changes affecting your rights)
- Continued use after updates constitutes acceptance.
I.2 Information We Collect
I.2.1 Information You Provide Directly
2.1.1 Account Registration Data:
- Full name
- Email address
- Phone number
- Date of birth (for age verification)
- Government-issued ID (passport, national ID, driver's license) - for KYC
- Proof of address (utility bill, bank statement)
- Country of residence / nationality
- Preferred language
2.1.2 Financial Information:
- Bank account details (account number, bank name, branch, SWIFT/routing codes)
- Payment method information (credit/debit card numbers are tokenized by payment processors - we do not store full card numbers)
- Transaction history (amounts, dates, recipients - limited to Platform transactions)
- Tax identification numbers (TIN, VAT registration)
2.1.3 Business Information (for Business Accounts):
- Business name and registration number
- Business address
- Business type (sole proprietorship, partnership, company)
- Number of employees
- Annual revenue (estimated)
- Industry sector
2.1.4 Project Information:
- Project descriptions, specifications, and documentation
- Budget and timeline
- Uploaded files (plans, drawings, photos, videos, contracts)
- Communications with Providers (messages, calls via Platform)
- Milestone definitions and payment schedules
2.1.5 Provider-Specific Information:
- Professional licenses and certifications
- Portfolio (photos, descriptions of past work)
- Client references
- Insurance certificates
- Specializations and service areas
2.1.6 Verification Information:
- Photos and videos submitted for Milestone verification
- Invoices, receipts, and other proof-of-work documentation
- Field officer inspection reports
2.1.7 Communications:
- Emails, chat messages, and calls made through the Platform
- Customer support inquiries and correspondence
2.1.8 Feedback You Send Us:
When you report a problem from inside the Platform, or from the feedback box on our website, we receive:
- What you write
- Any screenshot you attach or paste. A screenshot is whatever was on your screen, which can include another party's information
- Any voice recording you make, and the text transcript we produce from it (see Section 5.3.7). A recording contains your voice
- On the website, the email address you choose to leave. It is optional there, and it is the only way we can reply
- Feedback is attributed, not anonymous: inside the Platform it is linked to your account and the workspace you were in
Alongside it, and without asking you, we capture the technical context that makes a report usable: the page you were on, the Platform requests that page had made, any request that failed in the minute before you sent it, the release of the Platform you were running, your screen size, your browser's user-agent string and your browser's language. We do not capture your keystrokes, your screen contents or a recording of your session.
I.2.2 Information Collected Automatically
2.2.1 Device & Technical Information:
- IP address
- Device type (smartphone, tablet, computer)
- Operating system (iOS, Android, Windows, macOS)
- Browser type and version
- Screen resolution
2.2.2 Usage Data:
- Pages visited, features used
- Time spent on pages
- Click patterns and navigation paths
- Search queries within the Platform
- Projects created, bids placed, Milestones completed
- Login frequency and session duration
2.2.3 Location Data:
- Approximate location (derived from IP address)
- Project site locations
2.2.4 Cookies & Similar Technologies:
- We use cookies, web beacons, and similar technologies (see Section 2.3)
I.2.3 Cookies & Tracking Technologies
2.3.1 What Are Cookies?
Cookies are small text files stored on your device that help us recognize you, remember your preferences, and improve your experience.
2.3.2 Types of Cookies We Use:
(a) Strictly Necessary Cookies
- Keep you signed in and identify your session
- Remember, for up to 60 days, that you have signed in from this device before, which we use to decide how hard to make the next sign-in look suspicious
- Cannot be disabled: without them you cannot sign in
(b) Functional Cookies
- Remember your preferences: theme, language, sidebar state, and how you like lists displayed
(c) We run no analytics and no advertising cookies. The Platform carries no analytics service, no tag manager, no advertising pixel and no remarketing tag of any kind.
2.3.3 Third-Party Cookies:
- No third party sets cookies on our own pages. Services we embed, such as the Calendly scheduling window, may set their own cookies when you open them
- We do not control these cookies; refer to third parties' privacy policies
2.3.4 Managing Cookies:
- Browser Settings: Configure your browser to block or delete cookies
- Note: The Platform sets only cookies that are essential to signing in and staying signed in, plus cookies that remember your display preferences. Blocking them will stop you signing in.
I.2.4 Information from Third Parties
2.4.1 Subscription Billing (Paystack):
- Billing contact email, company and plan identifiers
2.4.2 Email Delivery (Brevo):
- Your email address and the content of messages we send you
2.4.3 AI Assistant (OpenRouter and the model vendor serving your request):
- The messages you send the assistant, their project context, and access to any document you attach
2.4.4 Voice Transcription (OpenRouter and the speech-to-text vendor serving the request):
- The audio of any voice recording you send us as feedback, and the text transcript returned for it
2.4.5 We do not offer sign-in through Google, Facebook or any other social account, and we receive no profile information from them.
2.4.6 Partner Banks:
- Controlled Hold status, payment execution confirmations
- We do NOT receive full bank account balances or other detailed banking data
2.4.7 We do not pull data from public registers. Business registration details come from the documents you upload, and we verify them by reading those documents.
I.3 How We Use Your Information
I.3.1 Primary Purposes
We use your personal data for the following purposes:
3.1.1 Provide Services:
- Create and maintain your Account
- Facilitate Project creation, Provider matching, Milestone verification
- Process payments (coordinate with banks and payment processors)
- Provide customer support
- Send transactional communications (order confirmations, payment receipts, Verification reports)
3.1.2 Verify Identity & Prevent Fraud:
- KYC/AML compliance (confirm you are who you say you are)
- Detect and prevent fraud, money laundering, terrorist financing
- Screen against sanctions lists (OFAC, UN, EU)
- Monitor transactions for suspicious activity
- Conduct background checks on Providers
3.1.3 Improve & Personalize Services:
- Read and act on the problems you report, and reply to you about them
- Analyze usage patterns to improve Platform functionality
- Develop new features
- Personalize recommendations (e.g., suggest relevant Providers based on Project type)
- Conduct A/B testing
3.1.4 Marketing & Communications:
- Send promotional emails (new features, special offers, educational content)
- Display targeted ads on third-party websites (remarketing)
- Conduct surveys and request feedback
- You may opt out of marketing communications (see Section 3.2)
3.1.5 Legal & Regulatory Compliance:
- Comply with Applicable Laws (Data Protection Act, AML laws, tax laws)
- Respond to court orders, subpoenas, regulatory requests
- Enforce our Terms of Service
- Protect our rights, property, and safety (and those of Users, Providers, and the public)
3.1.6 Dispute Resolution:
- Investigate disputes and complaints
- Provide evidence in mediation, arbitration, or litigation
- Maintain audit trails
3.1.7 Business Operations:
- Conduct internal audits and quality assurance
- Manage risk and security
- Business analytics and reporting
- Prepare financial statements
I.3.2 Marketing Communications - Opt-Out
3.2.1 You will receive marketing communications ONLY if:
- You have opted in (checked a box during registration), OR
- You are an existing customer and the communications relate to similar services (soft opt-in)
3.2.2 You may opt out at any time by:
- Emailing: privacy@nnarksup.com with subject "Opt-Out Marketing"
- Note: Nnarksup sends no marketing email today. Every message the Platform sends is transactional: sign-in codes, verification outcomes, project invitations, and notices about projects you are part of. Notification settings inside the Platform control which of those you receive.
3.2.3 Even if you opt out of marketing, you will still receive:
- Transactional emails (payment confirmations, Milestone updates, customer support responses)
- Important service announcements (Terms updates, security alerts)
- Legal notices
I.4 Legal Bases for Processing (GDPR & Data Protection Act Compliance)
I.4.1 Lawful Bases
We process personal data under the following legal bases:
4.1.1 Contractual Necessity (Primary Basis):
- Processing is necessary to perform our contract with you (User Agreement / Provider Agreement)
- Examples: Creating your Account, processing payments, verifying Milestones
4.1.2 Legal Obligation:
- Processing is required by Applicable Law
- Examples: KYC/AML checks, tax reporting, responding to court orders
4.1.3 Legitimate Interests:
- Processing is necessary for our legitimate business interests (or third parties'), provided these do not override your fundamental rights
- Examples:
- Fraud prevention and security
- Direct marketing to existing customers
- Analytics and service improvement
- Debt collection
- Your Right: You may object to processing based on legitimate interests (see Section 9.5)
4.1.4 Consent:
- For processing that requires explicit consent (e.g., certain marketing, use of non-essential cookies)
- Your Right: You may withdraw consent at any time (see Section 3.2 for marketing opt-out)
4.1.5 Vital Interests:
- Rarely, processing may be necessary to protect someone's life (e.g., emergency situation)
4.1.6 Public Interest:
- Processing for regulatory, law enforcement, or public safety purposes
I.4.2 Automated Decision-Making
4.2.1 AI-Assisted Verification:
- We use AI to analyze photos, invoices, and other Documentation for Milestone verification
- This is not fully automated decision-making because:
- AI provides recommendations, but field officers and Users make final decisions
- You have the right to challenge AI-generated recommendations
4.2.2 Fraud Detection:
- Automated systems may flag suspicious transactions
- Flagged transactions are reviewed by humans before action is taken (suspension, reporting)
4.2.3 Your Right:
- You have the right not to be subject to decisions based solely on automated processing (including profiling) that produce legal effects or significantly affect you
- If you believe you've been subjected to such processing, contact: privacy@nnarksup.com
I.5 How We Share Your Information
I.5.1 We Do NOT Sell Your Personal Data
5.1.1 Nnarksup does NOT sell, rent, or trade your personal data to third parties for their marketing purposes.
I.5.2 Sharing Within the Platform
5.2.1 User ↔ Provider Sharing:
When you engage a Provider, they see:
- Your name, contact information
- Project details
- Payment schedule
- Communications between you
- Providers share with you:
- Their business information, portfolio
- Proof-of-work Documentation
- Invoice and payment details
5.2.2 Co-Funders (if applicable):
If multiple Users co-fund a Project, they share access to:
- Project information
- Payment status
- Verification reports
I.5.3 Sharing with Service Providers (Data Processors)
We share data with third parties who provide services on our behalf. These providers are contractually obligated to:
- Use data only for specified purposes
- Implement security measures
- Delete data when no longer needed
- Not use data for their own purposes
5.3.1 Email Delivery:
- Who: Brevo (Sendinblue), operated by Sendinblue SAS
- Data Shared: Your email address, and the full content of every message we send you, which includes sign-in codes and links, verification outcomes, and project invitations
- Purpose: Deliver transactional email
5.3.2 Object Storage:
- Who: Our object-storage provider, currently Cloudflare (Cloudflare R2)
- Data Shared: Every file you upload: identity and business verification documents, project evidence, project documents such as contracts and permits, documents attached to conversations with the assistant, screenshots and voice recordings you attach to feedback, company logos, service cover images and avatars
- Purpose: Store uploaded files
5.3.3 AI Assistant:
- Who: OpenRouter, Inc., which routes each request onward to the vendor serving the selected model. The available models are an administrative setting, and today they are Anthropic and OpenAI models.
- Data Shared: The messages you send the assistant, the project and company context attached to them, and, when you attach a document, a temporary link that the model vendor uses to fetch that file directly from our storage
- Purpose: Operate the in-product AI assistant
- Note: Content you send the assistant leaves the Platform. Do not paste anything into it that you would not send to a third party.
5.3.4 Subscription Billing:
- Who: Paystack Payments Limited
- Data Shared: The billing contact's email address, and identifiers for the company and the plan
- Also: Paying a subscription takes you to Paystack's own hosted page, where Paystack receives your card details, IP address and device information directly. We never see or store card details.
- Purpose: Take subscription payments. Paystack is not used to move project or escrow funds.
5.3.5 Call Scheduling:
- Who: Calendly LLC
- Data Shared: Your name and email address, when you open the scheduling window from inside the Platform. The window is loaded from Calendly, so Calendly also receives your IP address and browser details and may set its own cookies.
- Purpose: Book a call with our team
5.3.6 Hosting:
- Who: Our infrastructure provider, which hosts the Platform's servers and database
- Data Shared: All Platform data, in the course of running the service
- Purpose: Operate the Platform
5.3.7 Voice Transcription:
- Who: OpenRouter, Inc., which routes each request onward to the vendor serving the selected speech-to-text model. The available models are an administrative setting, and today they are OpenAI's Whisper Large V3 Turbo and Alibaba's Qwen3 ASR Flash.
- Data Shared: The audio of a voice recording you attach to feedback, sent as the file itself. Nothing else about you goes with it: no name, no account identifier and no project context.
- Purpose: Produce a written transcript so a person can read and search what you said, rather than a queue of recordings nobody listens to
- Note: This happens only for feedback recordings. Nothing else you say or upload is transcribed, and the Platform does not record you at any other point. Your recording leaves the Platform to be transcribed; do not say anything into it you would not send to a third party.
5.3.8 Public pages on our marketing site also load images from third-party hosts, which receive your IP address and browser details in the course of serving them. Signed-in areas of the Platform do not.
5.3.9 If we add a processor that receives your personal data, we will update this list.
I.5.4 Sharing with Partner Banks
5.4.1 Data Shared:
- User bank account details (for Controlled Hold setup)
- Disbursement Authorization instructions
- Transaction IDs, amounts, recipients
5.4.2 Purpose:
- Facilitate Controlled Hold mechanism
- Execute payments to Providers
5.4.3 Legal Basis:
- Contractual necessity (performing payment services)
5.4.4 Bank's Use:
- Banks use data only for executing banking services
- Banks have independent privacy policies (refer to your bank's policy)
I.5.5 Sharing for Legal, Regulatory & Safety Reasons
5.5.1 We may disclose your data to:
(a) Law Enforcement / Regulatory Authorities
- Police, Bank of Ghana, Data Protection Commission, Financial Intelligence Centre (FIC)
- When: Required by law, court order, or to prevent/detect crime
(b) Legal Proceedings
- Courts, arbitrators, mediators
- When: Involved in dispute resolution
(c) Professional Advisors
- Lawyers, accountants, auditors, insurers
- When: Seeking advice, defending legal claims, insurance purposes
(d) Fraud Prevention Agencies
- Anti-fraud databases, credit bureaus
- When: Detecting or preventing fraud
5.5.2 Safety Disclosures:
- To protect rights, property, or safety of Nnarksup, Users, Providers, or the public
- Example: Reporting suspected child abuse, terrorism, imminent harm
I.5.6 Business Transfers
5.6.1 If Nnarksup is involved in a merger, acquisition, asset sale, bankruptcy, or similar transaction, your personal data may be transferred to the acquiring entity.
5.6.2 We will notify you (via email and Platform notice) before your data is transferred and becomes subject to a different privacy policy.
5.6.3 You will have the option to:
- Continue using the Platform under new ownership, OR
- Delete your Account (if you do not consent to the new entity's privacy practices)
I.6 International Data Transfers
I.6.1 Cross-Border Transfers
6.1.1 Nnarksup is based in Ghana, but we serve Users globally (UK, USA, Canada, Europe, etc.). Your data may be transferred to and processed in:
- Ghana (Platform servers, Nnarksup offices)
- Countries where our service providers operate (e.g., USA for AWS, Ireland for Google Cloud)
6.1.2 These countries may not have the same data protection laws as your country of residence (particularly if you are in the EU/EEA).
I.6.2 Safeguards for International Transfers
6.2.1 We implement the following safeguards:
(a) Standard Contractual Clauses (SCCs)
- We use EU-approved SCCs when transferring data from the EU/EEA to countries without adequate data protection (e.g., USA, Ghana)
- SCCs are contractual commitments ensuring recipients protect data per EU standards
(b) Adequacy Decisions
- If the European Commission has determined that a country provides adequate protection (e.g., UK), we rely on that decision
(c) Processor Agreements
All service providers (data processors) sign agreements requiring them to:
- Implement appropriate security measures
- Transfer data only as necessary
- Delete data upon request
6.2.2 For EU/EEA Users:
- You have the right to request a copy of the safeguards in place (SCCs, etc.)
- Contact: privacy@nnarksup.com
I.7 Data Security
I.7.1 Security Measures
We implement technical and organizational measures to protect your personal data:
7.1.1 Technical Measures:
- Encryption in transit: TLS on every connection to the Platform
- Encryption at rest: provided by our hosting and object-storage providers on the volumes and buckets holding your data. We do not additionally encrypt individual fields inside the database.
- Access Controls: role-based permissions, so people reach only the data their role requires
- Sign-in: a one-time code sent to your email address is the primary way in. A password path also exists for accounts that set one, and those passwords are stored only as bcrypt hashes, never in readable form.
- Audit trail: an append-only record of account activity that the database itself prevents from being altered or deleted
- Secure Coding Practices: input validation and parameterised queries
7.1.2 Organizational Measures:
- Employee Training: Privacy and security awareness training (annually)
- Confidentiality Obligations: Employees and contractors sign confidentiality agreements
- Incident Response Plan: Procedures for detecting, responding to, and reporting data breaches
- Data Minimization: Collect only data necessary for purposes; delete when no longer needed
- Privacy by Design: Build privacy into systems from the outset
7.1.3 Third-Party Security:
- Service providers are reviewed before they receive personal data. The ones that do are listed in Section I.5.3.
I.7.2 Your Responsibility
7.2.1 You are responsible for:
- Keeping your Account password secure (do not share with anyone)
- Using strong passwords (minimum 12 characters, mix of letters/numbers/symbols)
- Logging out of shared devices
- Not falling for phishing emails (Nnarksup will NEVER ask for your password via email)
7.2.2 If you suspect unauthorized access to your Account:
- Change your password immediately
- Contact: security@nnarksup.com
I.7.3 Data Breach Notification
7.3.1 In the event of a data breach that risks your rights and freedoms, we will:
- Notify you without undue delay once we become aware, and notify the regulator within any period the applicable law requires
- Describe the nature of the breach, likely consequences, and measures taken
- Provide steps you can take to protect yourself
7.3.2 Notification will be via:
- Email (to registered email address)
- Platform notification
- Public notice on website (if large-scale breach affecting many Users)
7.3.3 We will also notify relevant authorities (Data Protection Commission, Bank of Ghana) as required by law.
I.8 Data Retention
I.8.1 How Long We Keep Your Data
We keep your data for as long as your account exists, with one exception, stated in full in Section I.8.1a.
Apart from that exception we do not operate fixed expiry timers on personal data, and we would rather say so than publish periods we do not enforce. What determines how long we hold something is whether your account is open, not a countdown.
I.8.1a Feedback Recordings and Screenshots: 12 Months
Voice recordings and screenshots attached to feedback are the exception, and they are deleted on a timer:
- What is deleted: the recording and the screenshot themselves, from our object storage
- When: 12 months after they were sent
- How: by a scheduled job that runs daily, not on request. This is enforced by the Platform rather than by a person remembering
- What is kept: what you wrote, and the transcript of what you said. The transcript is the part that tells us what to fix, and it carries neither your voice nor an accidental view of somebody's screen
- Why 12 months: long enough for a report to be acted on and revisited, short enough that we are not holding a library of people's voices indefinitely. This is the most sensitive content the Platform holds and it is the one category we put a clock on
The period is an administrative setting. If we change it, this section will state the new period before it takes effect, as Section I.8.4 requires.
I.8.1b Who Can Read Feedback
Feedback, its attachments and its transcripts are readable only by Nnarksup staff who hold the operator permission for working on customer records. It is not visible to other customers, not visible to your counterparties, and not visible to colleagues in your own workspace. This is enforced by the Platform's permission system, on every read.
I.8.2 When You Close Your Account
When you delete your account we act immediately rather than waiting for a period to elapse:
- Your name and email address are overwritten, so the account can no longer be identified or signed into
- Your sign-in credentials are destroyed
- The name of your personal workspace is cleared
What remains after that, and why, is set out in full in Section I.9.4. In short: the account row is kept as a tombstone because other people's transactions refer to it, uploaded documents are kept because they are evidence in transactions involving other parties, content you posted in shared project spaces stays visible to the other parties, and the audit trail cannot be erased by anyone, including us.
I.8.3 Legal Retention
Where law requires us to keep specific records for a specific period, we keep them for that period regardless of the above, and no longer than we must.
I.8.4 If This Changes
If we introduce automatic deletion after fixed periods, this section will state those periods before they take effect. Section I.8.1a is the first of them.
I.9 Your Rights
I.9.1 Overview of Rights
Under the Ghana Data Protection Act, 2012 (Act 843) and GDPR (for EU/EEA Users), you have the following rights:
9.1.1 Right to Access (Section 9.2)
9.1.2 Right to Rectification (Section 9.3)
9.1.3 Right to Erasure / "Right to be Forgotten" (Section 9.4)
9.1.4 Right to Restriction of Processing (Section 9.5)
9.1.5 Right to Data Portability (Section 9.6)
9.1.6 Right to Object (Section 9.7)
9.1.7 Rights Related to Automated Decision-Making (Section 9.8)
9.1.8 Right to Withdraw Consent (Section 9.9)
9.1.9 Right to Lodge a Complaint (Section 9.10)
I.9.2 Right to Access
9.2.1 What It Means:
- You can request a copy of all personal data we hold about you
9.2.2 What You'll Receive:
A comprehensive report including:
- Account information
- Transaction history
- Communications
- Verification Documentation
- Data shared with third parties
9.2.3 How to Request:
- Email: privacy@nnarksup.com (subject: "Data Access Request"). A person handles the request; there is no self-service export.
9.2.4 Response Time:
- Within 30 days (may be extended to 60 days for complex requests)
9.2.5 Format:
- PDF report, or machine-readable format (CSV, JSON) if requested
9.2.6 Fee:
- FREE for your first request in a 12-month period
- Subsequent requests: GH₵50 administrative fee (to prevent abuse)
- Exception: Free if you can demonstrate the previous data provided was incomplete/inaccurate
I.9.3 Right to Rectification
9.3.1 What It Means:
- You can request correction of inaccurate or incomplete personal data
9.3.2 How to Request:
- Login → Account Settings → Edit Profile (for basic information)
- Email: privacy@nnarksup.com (for data you cannot edit yourself)
9.3.3 Response Time:
- Within 10 Business Days (corrections are typically immediate for self-service edits)
9.3.4 Verification:
- We may request proof of corrected information (e.g., new ID if name changed)
I.9.4 Right to Erasure ("Right to be Forgotten")
9.4.1 What It Means:
- You can request deletion of your personal data
9.4.2 When This Right Applies:
- Data is no longer necessary for the purposes for which it was collected
- You withdraw consent (where processing was based on consent)
- You object to processing and there are no overriding legitimate grounds
- Data was processed unlawfully
- Data must be erased to comply with legal obligation
9.4.3 When We May Refuse:
- Retention is required by law (e.g., tax, AML obligations)
- Needed for legal claims (active disputes)
- Public interest / regulatory purposes
9.4.4 How to Request:
- Login → Account Settings → "Delete My Account"
- Email: privacy@nnarksup.com (subject: "Erasure Request")
9.4.5 What Gets Erased:
- Your name and email address, which are overwritten so the account can no longer be identified or signed into
- Your sign-in credentials
- The name of your personal workspace
- Any feedback recording or screenshot older than the period in Section I.8.1a, which the scheduled sweep deletes whether or not you close your account
9.4.6 What Remains, and Why
We want to be exact about this, because "deletion" is often used loosely.
Your account row is not removed from the database. It is emptied of anything that identifies you and kept as a tombstone, because Projects, milestones and ledger entries refer to it. Removing it would break the record of transactions that other people were party to and that they are entitled to keep.
Your verification documents and uploaded files are retained. Identity and business documents, project evidence and anything attached to a conversation stay stored. They are evidence in transactions involving other parties, and in some cases we are required to keep them.
The audit trail is permanent and cannot be erased by anyone, including us. Every significant action on the Platform is written to an append-only record that the database itself refuses to change or delete, for any user and for any administrator. That is deliberate: an audit trail that can be edited is not an audit trail, and on a platform where people commit money to strangers it is the thing that makes the history trustworthy. Those entries include the acting account's identifier, the IP address and browser the action came from, and in some cases an email address.
Content you contributed to shared spaces remains. Messages in a project conversation, and evidence you submitted against a milestone, stay visible to the other parties to that project.
Feedback you sent us remains, minus your voice. What you wrote and the transcript of what you said stay, because they are what tells us what to fix and they are no longer identifiable once the account is emptied. The recording and any screenshot are deleted on the timer in Section I.8.1a regardless.
If you need something in the categories above addressed for a specific legal reason, email privacy@nnarksup.com and we will deal with it individually.
9.4.7 Response Time:
- Within 30 days
I.9.5 Right to Restriction of Processing
9.5.1 What It Means:
- You can request that we stop processing your data (but not delete it)
9.5.2 When This Right Applies:
- You contest the accuracy of data (restrict while we verify)
- Processing is unlawful but you don't want erasure
- We no longer need the data, but you need it for legal claims
- You've objected to processing (restrict while we assess if our legitimate interests override yours)
9.5.3 Effect:
- Data is stored but not actively processed (e.g., not used for marketing, analytics)
- May still be used for legal claims, protection of others' rights
9.5.4 How to Request:
- Email: privacy@nnarksup.com (subject: "Restriction Request")
I.9.6 Right to Data Portability
9.6.1 What It Means:
- You can receive your data in a structured, commonly used, machine-readable format
- You can transmit this data to another service (if technically feasible)
9.6.2 Scope:
Applies ONLY to data:
- Provided by you (not data we generated, like analytics)
- Processed by automated means (not manual records)
- Processed based on consent or contract
9.6.3 How to Request:
- Email: privacy@nnarksup.com (subject: "Data Portability Request"). A person handles the request; there is no self-service export.
9.6.4 Response Time:
- Within 30 days
I.9.7 Right to Object
9.7.1 Object to Direct Marketing:
- You have an absolute right to object to marketing communications
- See Section 3.2 for opt-out methods
9.7.2 Object to Processing Based on Legitimate Interests:
- You can object to processing based on our legitimate interests (e.g., fraud prevention, analytics)
- We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests
9.7.3 How to Object:
- Email: privacy@nnarksup.com (subject: "Objection to Processing")
- Specify which processing you object to and your reasons
9.7.4 Response Time:
- Within 30 days (we will explain whether we accept or reject the objection)
I.9.8 Rights Related to Automated Decision-Making
9.8.1 See Section 4.2 for details on our limited use of automated decisions.
9.8.2 You have the right to:
- Request human review of AI-generated recommendations
- Express your point of view
- Contest decisions
9.8.3 This right does NOT apply to decisions:
- Necessary for contract performance (e.g., automated KYC checks required by law)
- Authorized by law (e.g., fraud detection mandated by AML regulations)
I.9.9 Right to Withdraw Consent
9.9.1 Where processing is based on your consent (e.g., marketing, non-essential cookies), you can withdraw consent at any time.
9.9.2 Withdrawal does NOT affect:
- Lawfulness of processing before withdrawal
- Processing based on other legal grounds (contract, legal obligation)
9.9.3 How to Withdraw:
- Marketing: See Section 3.2
- Cookies: See Section 2.3.4
- Other: Email privacy@nnarksup.com
I.9.10 Right to Lodge a Complaint
9.10.1 If you believe we have violated your data protection rights, you can complain to:
Ghana Data Protection Commission:
- Address: Accra, Ghana
- Email: info@dataprotection.org.gh
- Website: www.dataprotection.org.gh
- For EU/EEA Users:
- Your local Data Protection Authority (DPA)
- Find yours at: https://edpb.europa.eu/about-edpb/board/members_en
9.10.2 We encourage you to contact us first (privacy@nnarksup.com) to try to resolve the issue before lodging a formal complaint.
I.10 Children's Privacy
I.10.1 Nnarksup is NOT intended for individuals under 18 years of age.
I.10.2 We do not knowingly collect personal data from children under 18.
I.10.3 If we discover that we have inadvertently collected data from a child under 18:
- We will delete it immediately
- We will terminate the Account
I.10.4 If you are a parent/guardian and believe your child has provided us with personal data, contact: privacy@nnarksup.com
I.11 Third-party Links & Services
I.11.1 The Platform may contain links to third-party websites, apps, or services (e.g., payment gateways, social media).
I.11.2 This Privacy Policy does NOT apply to third-party services. Each has its own privacy policy.
I.11.3 We are not responsible for third parties' privacy practices. Review their policies before providing data.
I.11.4 Examples
- Paystack: https://paystack.com/terms/privacy
- Brevo: https://www.brevo.com/legal/privacypolicy/
- Cloudflare: https://www.cloudflare.com/privacypolicy/
- OpenRouter: https://openrouter.ai/privacy
- Calendly: https://calendly.com/legal/privacy-notice
I.12 California Privacy Rights (CCPA)
I.12.1 Applicability
- If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA).
I.12.2 CCPA Rights
(a) Right to Know: What personal information we collect, use, disclose, and sell (equivalent to our Right to Access, Section 9.2)
(b) Right to Delete: Request deletion of personal information (equivalent to Right to Erasure, Section 9.4)
(c) Right to Opt-Out of Sale: We do NOT sell personal information, so this right does not apply
(d) Right to Non-Discrimination: We will not discriminate against you for exercising CCPA rights (e.g., deny services, charge different prices)
I.12.3 How to Exercise CCPA Rights
- Contact: privacy@nnarksup.com (subject: "CCPA Request")
I.12.4 Verification
- We will verify your identity before fulfilling CCPA requests (to prevent fraudulent requests).
I.12.5 Authorized Agents
You may designate an authorized agent to make CCPA requests on your behalf. We require:
- Signed authorization from you
- Proof of agent's authority
I.13 Contact Information & Data Protection Officer
I.13.1 General Privacy Inquiries
- Email: privacy@nnarksup.com
- Address: Nnarksup Company Limited, Adenta, Accra, Ghana
I.13.2 Data Protection Officer (DPO)
- Email: legal@nnarksup.com
I.13.3 The DPO is responsible for
- Overseeing data protection strategy
- Ensuring compliance with GDPR, Data Protection Act
- Serving as point of contact for regulatory authorities
- Handling data subject requests
I.14 Changes to This Privacy Policy
I.14.1 We may update this Privacy Policy to reflect
- Changes in our practices
- New features or services
- Legal/regulatory changes
I.14.2 Notice of Changes
- Material changes: 30 days' advance notice via email + prominent Platform notice
- Non-material changes: Updated Policy posted on Platform (effective immediately)
I.14.3 Acceptance
- Continued use after effective date = acceptance
- For material changes affecting rights: May require explicit re-acceptance (click "I Agree" upon next login)
I.14.4 Version History
- Previous versions: available on request from privacy@nnarksup.com
I.15 Governing Law
I.15.1 This Privacy Policy is governed by the laws of the Republic of Ghana.
I.15.2 Disputes regarding privacy practices are subject to the Dispute Resolution Framework (Document 6).
Part II. Data Protection & Compliance Framework
II.1 Purpose & Regulatory Compliance
II.1.1 Purpose
- This Data Protection & Compliance Framework ("Framework") establishes the principles, obligations, controls, and governance mechanisms adopted by Nnarksup to ensure the lawful, secure, transparent, and responsible collection, processing, storage, sharing, and disposal of Personal Data and Project Data processed through the Nnarksup Platform.
- This Framework forms part of the Nnarksup Legal Framework and applies to all Users, Employees, Contractors, Vendors, Technical Professionals, Third-Party Service Providers, Financial Institution Partners, and any other persons who process or access data on behalf of Nnarksup.
II.1.2 Regulatory Compliance
Nnarksup is committed to complying with all applicable data protection and privacy laws, including but not limited to:
- Ghana Data Protection Act, 2012 (Act 843)
- General Data Protection Regulation (GDPR) where applicable
- California Consumer Privacy Act (CCPA), where applicable
- Anti-Money Laundering and Counter-Terrorism Financing (AML/CFT) Regulations
- Electronic Transactions and Digital Communications laws
- Banking, Financial Services, and Regulatory Guidelines applicable to Partner Financial Institutions
- Any other applicable national or international privacy legislation governing the processing of Personal Data.
- Where multiple legal frameworks apply, Nnarksup shall apply the higher standard of protection unless prohibited by Applicable Law.
II.2 Data Protection Principles
Nnarksup processes Personal Data in accordance with internationally recognized privacy principles.
Accordingly, all Personal Data shall be:
II.2.1 Lawfully, Fairly and Transparently Processed
- Personal Data shall only be processed where there exists a lawful basis for such processing, including User consent, contractual necessity, legal obligation, legitimate interest, or other lawful grounds permitted by Applicable Law.
II.2.2 Purpose Limited
Personal Data shall only be collected and processed for specified, explicit, and legitimate purposes, including but not limited to:
- Identity verification
- Project governance
- Milestone verification
- Controlled disbursement authorization
- Risk management
- Fraud prevention
- Regulatory compliance
- Customer support
- Platform improvement
II.2.3 Data Minimization
- Nnarksup shall only collect Personal Data that is reasonably necessary for the delivery of its Services.
- Collection of excessive, irrelevant, or unrelated information shall be avoided.
II.2.4 Accuracy
- Reasonable steps shall be taken to ensure Personal Data remains accurate, complete, and up to date.
- Users are encouraged to promptly notify Nnarksup of any inaccuracies.
II.2.5 Storage Limitation
Personal Data shall not be retained longer than reasonably necessary for:
- Service delivery
- Legal obligations
- Regulatory requirements
- Fraud prevention
- Dispute resolution
- Audit purposes
- Upon expiry of applicable retention periods, data shall be securely deleted, anonymized, or archived in accordance with applicable law.
II.2.6 Integrity & Confidentiality
- Nnarksup shall implement appropriate technical and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, destruction, or loss.
II.2.7 Accountability
- Nnarksup shall maintain documented procedures demonstrating compliance with this Framework and applicable privacy laws.
II.3 Data Processing Governance
II.3.1 Lawful Processing Activities
- Nnarksup shall maintain documented records describing categories of Personal Data processed, processing purposes, legal bases, recipients, retention periods, and applicable security controls.
II.3.2 Data Protection Impact Assessments
- Where processing activities are likely to present significant risks to the rights and freedoms of individuals, Nnarksup shall conduct appropriate Data Protection Impact Assessments (DPIAs) before commencing such processing.
- Examples include:
- AI-assisted verification systems
- Facial verification
- Biometric technologies
- Automated decision-making
- Large-scale monitoring
- Cross-border processing
II.3.3 Legitimate Interest Assessments
- Where processing relies upon Legitimate Interests, Nnarksup shall assess whether such interests are balanced against the rights and expectations of affected individuals.
II.4 Third-Party Data Processing
II.4.1 Appointment of Processors
- Nnarksup may engage third-party service providers for hosting, cloud infrastructure, payment processing, identity verification, communications, analytics, security monitoring, and other operational services.
II.4.2 Due Diligence
- Prior to engagement, Nnarksup shall undertake commercially reasonable due diligence to ensure processors maintain appropriate technical, organizational, and legal safeguards.
II.4.3 Data Processing Agreements
All processors handling Personal Data on behalf of Nnarksup shall operate under written Data Processing Agreements requiring, at minimum:
- Confidentiality obligations
- Appropriate security measures
- Processing only on documented instructions
- Restrictions on sub-processing
- Incident notification obligations
- Assistance with regulatory compliance
- Secure deletion or return of data upon termination
II.4.4 Ongoing Oversight
- Nnarksup reserves the right to periodically review processor compliance through audits, certifications, questionnaires, or other reasonable assurance mechanisms.
II.5 Cross-Border Data Transfers
Where Personal Data is transferred outside the jurisdiction in which it was collected, Nnarksup shall implement appropriate safeguards, including where applicable:
- Standard Contractual Clauses (SCCs)
- Adequacy Decisions
- Transfer Impact Assessments (TIAs)
- Other lawful transfer mechanisms recognized under Applicable Law.
- Cross-border transfers shall only occur where adequate protections for Personal Data are maintained.
II.6 Data Subject Rights
Subject to Applicable Law, Users may exercise the following rights:
- Right of Access
- Right to Rectification
- Right to Erasure
- Right to Restrict Processing
- Right to Data Portability
- Right to Object to Processing
- Right to Withdraw Consent
- Right to Lodge Complaints with relevant supervisory authorities.
- Requests may be submitted through the designated privacy contact channels published by Nnarksup.
- Nnarksup may require reasonable identity verification before fulfilling any request.
- Requests shall ordinarily be responded to within thirty (30) days unless extended where legally permissible due to complexity.
II.7 Information Security & Data Breach Management
II.7.1 Security Measures
Nnarksup maintains commercially reasonable administrative, technical, and physical safeguards, which may include:
- Encryption in transit, and at rest through our infrastructure providers
- Access controls
- Role-based permissions
- Audit logs
- Secure cloud infrastructure
II.7.2 Security Incidents
- All suspected or confirmed security incidents shall be investigated promptly.
II.7.3 Regulatory Notifications
Where required by Applicable Law, Nnarksup shall notify:
- Relevant supervisory authorities within applicable legal timelines
- Affected Users without undue delay where there exists a high risk to their rights or freedoms
II.7.4 Incident Review
- Following any material security incident, Nnarksup shall conduct a post-incident assessment to identify root causes, corrective actions, and improvements to security controls.
II.8 Privacy by Design & AI Governance
Privacy shall be integrated into the design, development, deployment, and operation of all Nnarksup products and services.
Accordingly:
Privacy considerations shall be incorporated from project inception.
Default settings shall prioritize user privacy.
AI-assisted verification systems shall be subject to appropriate human oversight where necessary.
Automated decisions affecting significant user interests shall incorporate review mechanisms where required by Applicable Law.
New platform features shall undergo privacy and security assessments prior to deployment.
II.9 Internal Compliance & Awareness
Nnarksup shall promote a culture of privacy and compliance through ongoing governance initiatives.
These include:
Regular privacy awareness programmes.
Specialized compliance training for personnel handling sensitive information.
Confidentiality obligations for employees and contractors.
Internal reporting mechanisms for suspected privacy breaches.
Periodic policy reviews to reflect evolving legal and technological developments.
II.10 Accountability, Governance & Continuous Improvement
Nnarksup shall maintain appropriate documentation demonstrating compliance with this Framework, including:
- Records of Processing Activities
- Risk Assessments
- Data Protection Impact Assessments
- Vendor Due Diligence Records
- Data Breach Registers
- Consent Records
- Compliance Reviews
- Internal Audit Reports
- Nnarksup may periodically undertake internal or independent assessments against recognized industry standards, including ISO/IEC 27001, ISO/IEC 27701, SOC 2, or other appropriate information security and privacy frameworks, where commercially appropriate.
- This Framework shall be reviewed periodically and may be amended by Nnarksup to reflect changes in applicable law, regulatory guidance, operational practices, technological developments, or industry best practices. Continued use of the Services following any such amendments shall constitute acceptance of the updated Framework, to the extent permitted by Applicable Law.
Questions about this document? Contact our team.