1. Scope
This pack explains how personal data is handled on basic.edu.gh and any public forms or pages hosted under this domain. It supports compliance with the Ghana Data Protection Act, 2012 (Act 843) and, where applicable, GDPR/UK GDPR-aligned good practice.
2. Definitions
- Personal data: information that can identify a person (e.g., name, phone, email).
- Special category / sensitive data: health, biometrics, religion, etc. (handled with extra care).
- Controller: decides why/how data is processed.
- Processor: processes data on behalf of a controller.
3. Controller / Contact
For basic.edu.gh site enquiries and public form submissions, the site operator is the data controller. If your submission relates to a specific school or a school system deployment, the relevant school may also be a controller for certain data it provides or collects.
Email: privacy@basic.edu.gh (replace if different)
Support: support@basic.edu.gh (replace if different)
Address: [Insert business / registered address]
Email: security@basic.edu.gh (replace if different)
Include: domain, date/time, screenshots, and steps to reproduce.
4. What data we collect
4.1 Website interactions
- Basic technical logs (IP address, device/browser type, pages visited, approximate location).
- Cookie preferences (where cookie consent is enabled).
4.2 Contact and onboarding forms
- Name, email, phone number, organization/school details, role/title.
- Operational info needed to respond (e.g., number of learners, location, service needs).
- Attachments you choose to submit (e.g., documents, screenshots).
4.3 What we try not to collect on the public site
- We do not request children’s personal data on basic.edu.gh public pages unless explicitly needed for a service request.
- We avoid collecting special category data via public web forms unless legally required and explicitly indicated.
5. Why we collect and use data (Purpose)
- To respond to enquiries and provide requested information.
- To evaluate and process onboarding requests for schools/partners.
- To provide support, troubleshoot issues, and communicate updates.
- To maintain site security (fraud prevention, abuse detection, logging).
- To comply with legal obligations where applicable.
6. Lawful basis (Good-practice mapping)
Depending on the context, we process personal data using one or more lawful bases:
- Consent: where you explicitly choose to submit an enquiry or opt into communications.
- Contract / steps to contract: to process a request for services or onboarding.
- Legitimate interests: to operate and secure the site, prevent abuse, and improve services (balanced against your rights).
- Legal obligation: where required by applicable law.
7. Children and safeguarding
- We minimize collection of children’s data on public forms.
- We encourage schools to submit operational information without identifying learners.
- If learner data is required for a support case, we encourage anonymization where possible.
8. Data sharing and third parties
We may share limited data with trusted service providers only as needed to deliver and secure the website and communications, such as web hosting, DNS, email delivery, privacy-respecting analytics, and onboarding automation tools.
- No sale of personal data: we do not sell personal data.
- Minimum necessary: we share only what is needed to provide the service or protect the site.
9. International transfers
Some service providers may process data outside Ghana/UK/EU. Where this occurs, we take reasonable steps to ensure appropriate safeguards are in place (contractual protections and access controls).
10. Retention (how long we keep data)
- Enquiry messages: as needed to respond and maintain business records (commonly 12–24 months).
- Onboarding submissions: while evaluating/operating the relationship (and for a reasonable audit period).
- Security logs: for monitoring and incident response (commonly 30–180 days).
11. Security controls (Information Security)
- HTTPS/TLS encryption
- Role-based access controls for admin systems
- Strong passwords and, where available, multi-factor authentication
- Regular updates and vulnerability patching
- Backups and disaster recovery practices
- Monitoring for abuse, spam, and suspicious activity
12. Cookies
- Essential: security and basic site functionality
- Analytics: understanding site usage to improve content (where enabled)
- Preferences: saving cookie consent or language choices
If cookie consent is enabled, you can adjust preferences via the cookie banner or browser settings.
13. Your rights
- Request access to your personal data
- Request correction of inaccurate data
- Request deletion (where legally permitted)
- Object to certain processing
- Request restriction of processing
- Withdraw consent where processing is based on consent
To exercise rights, contact: privacy@basic.edu.gh (replace if different).
14. Data breach and incident handling
We maintain an incident response approach to assess, contain, and remediate suspected breaches. Where required, we will notify relevant authorities and affected individuals within applicable timeframes.
15. Complaints
If you have concerns about our data practices, contact us first so we can resolve the matter. You may also have the right to complain to the relevant data protection authority in your jurisdiction (e.g., Ghana Data Protection Commission).
16. Relationship to SchoolManager™ and other services
basic.edu.gh may link to other services (including SchoolManager™ portals and related platforms). Those services have their own privacy notices and terms depending on the role (e.g., school as controller, platform as processor).
17. Updates to this pack
We may update this page to reflect operational, legal, or security changes. The “Last updated” date at the top will be revised.