Privacy notice
How we handle your data
Effective: 23 July 2026
1. Who we are
This is a free, open-source compliance self-check operated as a community resource. Source code for this portal: github.com/madjanorjedidiah/compliance-check-portal (sibling of the larger privacy-compliance platform).
2. What personal data we collect
We collect
Email address
Used solely to deliver your private report link. Never marketed, never sold, never shared.
We collect
Company / organisation name
Strictly speaking not personal data, but listed for transparency.
We do not ask for your name, phone, address, IP-based location, payment details, or any other identifier. The portal uses only strictly-necessary CSRF and session cookies. Optional cookieless analytics (Plausible or Umami) may be enabled by the operator — these never set cookies, never receive your IP in identifiable form, and are listed in the deployed instance's footer.
The toolkit pages (policy templates, DPIA wizard, comparison view, cookie-banner generator) are stateless: what you type is processed on submission to render your result and is never stored in our database. Like any web form, submitted values transit our server (and personalised-policy values appear in the page address so you can bookmark or share it) — if that matters for a sensitive project name, use placeholder text. The two flagged exceptions that do store data are saving a DPIA (90-day token link) and the law-update subscription.
If a separate "law update" subscription is offered, that is a separate consent flow with its own clear notice — opting into it stores your email so we can email you when laws change. You can unsubscribe with one click from any email.
3. Lawful basis
Performance of pre-contractual measures at your request (GDPR Art. 6(1)(b) / Ghana DPA s.20 / Kenya DPA s.30 / NDPA s.25) — you ask us to compute and deliver your report, and we do.
4. Retention & deletion
The entire assessment record — email, company name, and every answer — is permanently deleted 90 days after creation. The unique link in your email stops working at the same point. We do not retain anonymised metrics, analytics, or any other derived record after deletion.
5. Security
HTTPS only · HSTS · CSP · same-origin referrer · no third-party trackers. The assessment URL contains a long random token; only someone holding the link can view the result.
6. Your rights
Under GDPR Arts. 15-22, Ghana DPA s.32-37, Kenya DPA s.26, NDPA s.34-39 and the CCPA, you have the right to access, rectify, erase, restrict, port, and object. Email support@spatialsusty.com with the link from your report email and we will respond within 30 days.
7. Sub-processors
We use the minimum number of processors needed to run the service, and we publish the current list in full below — not "on request". Each one is bound by a data-processing agreement and may only process your data on our documented instructions.
| Processor | Purpose | Location | Data it sees | Safeguards |
|---|---|---|---|---|
| DigitalOcean, LLC | Cloud hosting of the portal and its PostgreSQL database | Frankfurt (FRA1) — European Union | All assessment data at rest (email, organisation name, answers) until it auto-deletes | EU/EEA data centre; encrypted in transit (TLS) and at rest; isolated VPS behind our own reverse proxy |
| Google LLC (Gmail / Workspace SMTP) | Transactional email delivery — your report link and law-update confirmations | Global (Google data centres, EU/US) | Recipient email address and the message body containing your private report link | TLS-encrypted SMTP; sent only when you request a report or opt into law updates; never used for marketing |
Analytics & trackers: none. This instance loads no third-party analytics, advertising tags, or trackers of any kind.
We operate from Ghana. Where a processor stores data outside your own country — for example, EU-hosted infrastructure serving a Ghanaian organisation — that transfer relies on the processor's standard contractual protections, and the full assessment record is deleted after 90 days regardless.
8. Complaints
You may complain to the Ghana Data Protection Commission, your EU lead supervisory authority, the Kenya ODPC, the Nigeria Data Protection Commission, or the California Privacy Protection Agency.
9. Changes
Material changes are recorded with a new effective date.
Questions about this notice?
support@spatialsusty.com