Privacy notice

How we handle your data

Effective: 23 July 2026

1. Who we are

This is a free, open-source compliance self-check operated as a community resource. Source code for this portal: github.com/madjanorjedidiah/compliance-check-portal (sibling of the larger privacy-compliance platform).

2. What personal data we collect

We collect

Email address

Used solely to deliver your private report link. Never marketed, never sold, never shared.

We collect

Company / organisation name

Strictly speaking not personal data, but listed for transparency.

We do not ask for your name, phone, address, IP-based location, payment details, or any other identifier. The portal uses only strictly-necessary CSRF and session cookies. Optional cookieless analytics (Plausible or Umami) may be enabled by the operator — these never set cookies, never receive your IP in identifiable form, and are listed in the deployed instance's footer.

The toolkit pages (policy templates, DPIA wizard, comparison view, cookie-banner generator) are stateless: what you type is processed on submission to render your result and is never stored in our database. Like any web form, submitted values transit our server (and personalised-policy values appear in the page address so you can bookmark or share it) — if that matters for a sensitive project name, use placeholder text. The two flagged exceptions that do store data are saving a DPIA (90-day token link) and the law-update subscription.

If a separate "law update" subscription is offered, that is a separate consent flow with its own clear notice — opting into it stores your email so we can email you when laws change. You can unsubscribe with one click from any email.

3. Lawful basis

Performance of pre-contractual measures at your request (GDPR Art. 6(1)(b) / Ghana DPA s.20 / Kenya DPA s.30 / NDPA s.25) — you ask us to compute and deliver your report, and we do.

4. Retention & deletion

The entire assessment record — email, company name, and every answer — is permanently deleted 90 days after creation. The unique link in your email stops working at the same point. We do not retain anonymised metrics, analytics, or any other derived record after deletion.

5. Security

HTTPS only · HSTS · CSP · same-origin referrer · no third-party trackers. The assessment URL contains a long random token; only someone holding the link can view the result.

6. Your rights

Under GDPR Arts. 15-22, Ghana DPA s.32-37, Kenya DPA s.26, NDPA s.34-39 and the CCPA, you have the right to access, rectify, erase, restrict, port, and object. Email support@spatialsusty.com with the link from your report email and we will respond within 30 days.

7. Sub-processors

We use the minimum number of processors needed to run the service, and we publish the current list in full below — not "on request". Each one is bound by a data-processing agreement and may only process your data on our documented instructions.

Processor Purpose Location Data it sees Safeguards
DigitalOcean, LLC Cloud hosting of the portal and its PostgreSQL database Frankfurt (FRA1) — European Union All assessment data at rest (email, organisation name, answers) until it auto-deletes EU/EEA data centre; encrypted in transit (TLS) and at rest; isolated VPS behind our own reverse proxy
Google LLC (Gmail / Workspace SMTP) Transactional email delivery — your report link and law-update confirmations Global (Google data centres, EU/US) Recipient email address and the message body containing your private report link TLS-encrypted SMTP; sent only when you request a report or opt into law updates; never used for marketing

Analytics & trackers: none. This instance loads no third-party analytics, advertising tags, or trackers of any kind.

We operate from Ghana. Where a processor stores data outside your own country — for example, EU-hosted infrastructure serving a Ghanaian organisation — that transfer relies on the processor's standard contractual protections, and the full assessment record is deleted after 90 days regardless.

8. Complaints

You may complain to the Ghana Data Protection Commission, your EU lead supervisory authority, the Kenya ODPC, the Nigeria Data Protection Commission, or the California Privacy Protection Agency.

9. Changes

Material changes are recorded with a new effective date.

Questions about this notice?

support@spatialsusty.com