Privacy notice
How we handle your data
Effective: 8 September 2026
1. Who we are
Compliance Check is a commercial product operated from Ghana. We are the data controller for the personal data described in this notice. The self-check, the toolkit and your report are provided at no charge; paid advisory services are offered separately and are never required to use them.
For any question about this notice, or to exercise the rights in section 6, contact support@spatialsusty.com.
Open-source edition. A separate open-source edition of this software is published at github.com/madjanorjedidiah/privacy-compliance, which you are free to inspect or run yourself. This hosted platform is operated commercially and maintained separately from that edition.
2. What personal data we collect
We collect
Email address
Used solely to deliver your private report link. Never marketed, never sold, never shared.
We collect
Company / organisation name
Strictly speaking not personal data, but listed for transparency.
We do not ask for your name, phone, address, IP-based location, payment details, or any other identifier. The portal uses only strictly-necessary CSRF and session cookies. Optional cookieless analytics (Plausible or Umami) may be enabled by the operator — these never set cookies, never receive your IP in identifiable form, and are listed in the deployed instance's footer.
The toolkit pages (policy templates, DPIA wizard, comparison view, cookie-banner generator) are stateless: what you type is processed on submission to render your result and is never stored in our database. Like any web form, submitted values transit our server (and personalised-policy values appear in the page address so you can bookmark or share it) — if that matters for a sensitive project name, use placeholder text. The two flagged exceptions that do store data are saving a DPIA (90-day token link) and the law-update subscription.
If a separate "law update" subscription is offered, that is a separate consent flow with its own clear notice — opting into it stores your email so we can email you when laws change. You can unsubscribe with one click from any email.
Reviews. If you choose to leave a review on our reviews page, we store exactly what you type into that form: a star rating, your review text, and — only if you fill them in — a display name, role and organisation. Every one of those three is optional; leave them blank and the review is published anonymously. We do not collect an email address, IP address, or any other identifier with a review, which also means we have no way to contact you about one or to link it back to an assessment you may have run. Reviews are held unpublished until a member of our team approves them, and approved reviews appear publicly on that page (and may be quoted on our home page).
3. Lawful basis
Performance of pre-contractual measures at your request (GDPR Art. 6(1)(b) / Ghana DPA s.20 / Kenya DPA s.30 / NDPA s.25) — you ask us to compute and deliver your report, and we do.
4. Retention & deletion
The entire assessment record — email, company name, and every answer — is permanently deleted 90 days after creation. The unique link in your email stops working at the same point. We do not retain anonymised metrics, analytics, or any other derived record after deletion.
Reviews are the one exception to a fixed deletion clock, because a published review is content rather than a record about you: we keep it until we remove it or you ask us to. Since a review carries no email address, we cannot identify you from it — so if you want yours taken down, email support@spatialsusty.com quoting enough of the text for us to find it, and we will delete it.
Visit counts. We keep a running tally of how many times each page was viewed on each day. It is an aggregate and nothing more — a date, a page address and a number. It contains no IP address, no cookie, no browser fingerprint, no session identifier and no row that corresponds to a person, so it cannot be traced back to you or to anyone else, even by us. Page addresses containing a private report token are recorded with the token masked (/check/***/result) before being counted.
5. Security
HTTPS only · HSTS · CSP · same-origin referrer · no third-party trackers. The assessment URL contains a long random token; only someone holding the link can view the result.
6. Your rights
Under GDPR Arts. 15-22, Ghana DPA s.32-37, Kenya DPA s.26, NDPA s.34-39 and the CCPA, you have the right to access, rectify, erase, restrict, port, and object. Email support@spatialsusty.com with the link from your report email and we will respond within 30 days.
7. Sub-processors
We use the minimum number of processors needed to run the service, and we publish the current list in full below — not "on request". Each one is bound by a data-processing agreement and may only process your data on our documented instructions.
| Processor | Purpose | Location | Data it sees | Safeguards |
|---|---|---|---|---|
| DigitalOcean, LLC | Cloud hosting of the portal and its PostgreSQL database | Frankfurt (FRA1) — European Union | All assessment data at rest (email, organisation name, answers) until it auto-deletes | EU/EEA data centre; encrypted in transit (TLS) and at rest; isolated VPS behind our own reverse proxy |
| Google LLC (Gmail / Workspace SMTP) | Transactional email delivery — your report link and law-update confirmations | Global (Google data centres, EU/US) | Recipient email address and the message body containing your private report link | TLS-encrypted SMTP; sent only when you request a report or opt into law updates; never used for marketing |
Analytics & trackers: none. This instance loads no third-party analytics, advertising tags, or trackers of any kind.
Our own visit counter: separately from any third-party tool, our server keeps the aggregate page-view tally described in section 4. It sets nothing on your device, runs no code in your browser, and records no identifier — it increments a number against a page address and a date. We use it to know whether the portal is reaching anyone.
We operate from Ghana. Where a processor stores data outside your own country — for example, EU-hosted infrastructure serving a Ghanaian organisation — that transfer relies on the processor's standard contractual protections, and the full assessment record is deleted after 90 days regardless.
8. Complaints
You may complain to the Ghana Data Protection Commission, your EU lead supervisory authority, the Kenya ODPC, the Nigeria Data Protection Commission, or the California Privacy Protection Agency.
9. Changes
Material changes are recorded with a new effective date.
Questions about this notice?
support@spatialsusty.com