Data protection
How Agoo fits Ghana's Data Protection Act, 2012 (Act 843), who is responsible for what, where data is hosted and who processes it.
Agoo is in early access. This page describes the feature as it ships to early-access organisations; screens are illustrative.
Agoo holds names, phone numbers, photos and sometimes ID numbers. This page explains who is responsible for that data under Ghana's Data Protection Act, 2012 (Act 843), and how Agoo helps you meet your duties.
Who is responsible for what
| Data | Controller (decides why and how) | Processor (handles it on the controller's behalf) |
|---|---|---|
| Your visitors, staff, contractors and contacts, entered into Agoo | Your organisation | Ardent (Ardent Africa Foundation LBG), which runs Agoo |
| Your account and billing details, and enquiries made to Ardent | Ardent | Ardent's service providers |
As controller of your visitor and staff data, your organisation decides what to collect, why, and how long to keep it. Ardent processes it only on your instructions, which include your settings in Agoo.
The data processing agreement
Ardent signs a data processing agreement (DPA) with every customer. It covers:
- processing only on your instructions;
- confidentiality for Ardent's staff and sub-processors;
- the security measures described on our security page;
- telling you within 72 hours of becoming aware of a personal data breach affecting your data;
- helping you answer requests from people and from the Data Protection Commission;
- letting you export your data at any time, including a full export of every record on any plan, and deleting it within 30 days when you ask for your organisation to be deleted or the agreement ends. Copies in encrypted backups expire within a further 30 days and aren't restored in the meantime except to recover from an incident.
These documents are in force from 1 October 2026, on the Agoo website:
Registration with the Data Protection Commission
Act 843 requires data controllers to register with the Data Protection Commission (DPC).
- Your organisation should be registered as the controller of your visitor and staff data. Add your DPC registration number in Console → Settings → Organisation, and Agoo shows it on the privacy notice visitors see at check-in.
- Ardent's registration with the DPC, as controller of its own data and processor for customers, is in progress.
Where your data is hosted
Agoo's database, API and web apps are hosted in London, United Kingdom, with daily encrypted backups. Uploaded files, such as visitor photos and signatures, are stored in Western Europe, and web pages are delivered through global edge networks. When data leaves Ghana, Ardent relies on written contracts and safeguards with each provider to protect it to a standard consistent with Act 843.
Sub-processors
Ardent uses a small number of service providers, called sub-processors, to run Agoo, such as providers for hosting, email, SMS and WhatsApp delivery, payments, and AI features when your organisation turns them on. Each one, with its purpose, the data it can receive and its country, is on the sub-processors page.
The authoritative list, with what each provider receives, where it processes data and when, is the sub-processor list on the Agoo website. The DPA and our security page use the same list.
Ardent gives at least 30 days' notice of any new sub-processor, and you can object on reasonable grounds.
How Agoo protects data
- Encryption in transit (TLS) and at rest (AES-256), with ID numbers encrypted individually.
- Tenant isolation: every record carries your organisation's ID, and the database itself enforces that nobody else can read it.
- Roles by site, so people see only what their job needs. See Roles and permissions.
- A tamper-evident audit trail of views, exports and changes.
- Retention rules that delete data on schedule, with every deletion logged. See Retention and deletion.
- ID numbers masked on screen by default, and ID images deleted on your schedule.
- Face matching for staff only, on a basis your organisation records (required under its legal basis, or consent), with a notice employees see, and never for visitors. See Face clock-in.
Special personal data
Some organisations hold data that Act 843 treats as special. Church attendance can reveal religious belief; a hospital visit can suggest something about a patient's health. Limit who can see it, collect as little as you can, and keep it no longer than you need. The church and hospital guides cover this in more detail.
Your checklist
- Register with the DPC and add your number in Console → Settings → Organisation.
- Write your privacy notice. Agoo shows it to visitors before they check in.
- Collect only the fields you need. Mark personal and sensitive fields in Forms and fields.
- Set retention periods for visits, photos and ID images.
- Decide who handles requests from visitors and staff.