Legal
Data processing agreement
Last updated 5 October 2026 · Effective 5 October 2026
This agreement sets out how Ardent Africa Foundation LBG processes personal data on behalf of each organisation that uses Agoo. Ghana’s Data Protection Act, 2012 (Act 843) requires processing by a data processor to be governed by a written contract that requires confidentiality and security (section 30); this is that contract.
On this page
- 1. Parties and scope
- 2. Processing on the customer’s instructions
- 3. Details of the processing
- 4. Ardent’s obligations
- 5. Security measures
- 6. Sub-processors
- 7. Requests from data subjects
- 8. Help with compliance
- 9. Security compromises
- 10. International transfers
- 11. Return and deletion
- 12. Information and audits
- 13. Liability
- 14. Duration, precedence and changes
- 15. Contact
1. Parties and scope
- This data processing agreement (“DPA”) is between the customer named on the Agoo account (the “customer”), as data controller, and Ardent Africa Foundation LBG (“Ardent”), as data processor. It forms part of the terms of service and is accepted with them. Customers who need a signed copy can ask us for one.
- It applies to personal data that Ardent processes for the customer in providing Agoo (“customer personal data”). Ardent’s processing of customer account, billing and support data as a controller is covered by our privacy notice instead.
- Words such as personal data, processing, data subject, data controller, data processor and special personal data have the meanings given in Act 843. A “security compromise” means unauthorised access to, or acquisition of, customer personal data, as in section 31 of Act 843.
2. Processing on the customer’s instructions
- Ardent processes customer personal data only on the customer’s documented instructions. These are the terms of service, this DPA, the customer’s settings and configuration in Agoo, and other written instructions from the customer’s authorised administrators that are consistent with the agreement.
- If Ardent believes an instruction breaks Act 843 or another data protection law, it will tell the customer and need not follow it until the customer confirms or changes it.
- If the law requires Ardent to process customer personal data in another way, Ardent will tell the customer before doing so, unless the law forbids that.
- The customer is responsible for the lawfulness of its instructions and of the personal data it collects, including its lawful basis, its notices to data subjects, its registration with the Data Protection Commission and any consent it needs.
3. Details of the processing
| Subject matter | Providing Agoo to the customer under the terms of service. |
| Duration | For as long as the customer uses Agoo, and afterwards until the data is deleted under section 11. |
| Nature | Collecting, recording, storing, organising, retrieving, displaying, syncing to the customer’s paired devices, matching (for example against the customer’s watchlist), sending messages, reporting, exporting and deleting; and, when the customer joins an organisation group, making available to that group what the customer chooses: its totals, its watchlist entries for screening at the group’s other organisations, or access for the group’s administrators as the customer’s own Auditors or Admins. |
| Purposes | Visitor management (walk-in check-in, the built-in visitor types and any the customer creates, invitations and passes, host approvals, watchlist screening, badges, deliveries and contractors); appointment booking, including bookings that need a host’s confirmation; staff attendance (clock-in, shifts, leave and timesheets); emergency roll call; QR codes the customer makes, including sending people who scan a tracked code to its destination and counting its scans; notifications by SMS, WhatsApp, email and push, including scheduled report emails to the customer’s staff; reporting and audit; organisation groups the customer joins or leads, as the customer’s Owner instructs in Agoo (accepting an invitation, choosing the group’s access, sharing the watchlist, leaving); Agoo AI features the customer turns on; and support the customer asks for. |
| Data subjects | Visitors and guests; people who book appointments or are invited; hosts, employees, receptionists, security guards and other staff; the customer’s administrators and users; contractors and their workers; delivery riders; and, depending on the customer, residents and domestic staff, pupils, parents, guardians and authorised pick-up people, members and children of a congregation, people visiting patients, people on the customer’s watchlist, people recorded in paper logbooks the customer imports, and people who scan the customer’s tracked QR codes. |
| Personal data | Names and contact details; staff profile photos, the names staff go by and their pronouns, their choices of how Agoo notifies them, and the scheduled reports they get or stopped; visit and booking details (host, purpose, visitor type, site, times); photos; signatures and signed documents; vehicle registrations; ID details where the customer asks for them (ID numbers stored masked and encrypted, ID images deleted on the customer’s schedule); answers to the customer’s own form fields; attendance records (clock-in times, method, device, the location or Wi-Fi check result for mobile clock-in and, where the customer turns them on, selfies taken at clock-in, exact clock-in locations and Wi-Fi network names; shifts, leave and timesheets); notices to staff, acknowledgements and consent records; messages and delivery status; QR code scans (time; the country, region and city estimated from the network; kind of device, operating system, browser and language; the outcome; and a one-way scanner code that changes daily, never an IP address); contact details the customer puts in its QR codes; device and usage logs; and audit trail entries. |
| Special personal data | Depending on how the customer uses Agoo: data about children; data that may reveal religious belief (for example church attendance), health (for example hospital visits or health questionnaires) or criminal behaviour (for example a watchlist entry). Face templates for staff clock-in are created and kept, encrypted, on the kiosk where the employee enrols, only after the customer has published a notice to its staff and recorded its basis (its legal basis as the employer, or the employee’s consent); they are never exported to Agoo’s servers, reports, the API or anyone else, and are never used for visitors. |
4. Ardent’s obligations
- Ardent processes customer personal data only to provide Agoo to the customer. It does not sell it, use it for its own marketing, combine it with other customers’ data, or use it to train AI models.
- Ardent gives access to customer personal data only to staff and contractors who need it for their work and are bound by a duty of confidentiality. Support access to a customer’s data is read-only unless one of the customer’s Owners approves changes, is limited in time, needs a recorded reason, is notified to the customer’s Owners when it begins, can be ended by the customer at any time, and is recorded in the customer’s audit trail. Emergency access without prior approval is limited to Ardent’s platform owner, for events that cannot wait (such as no administrator being able to sign in, a security incident or a safety emergency), after verifying the request through contact details already held; every Owner and administrator is notified when it begins and receives a written report of what was done within 72 hours. Support access never includes exporting data, changing billing, erasing data or granting anyone access.
- Ardent resets a user’s two-step verification only after the user has confirmed their email address and either one of the customer’s Owners or administrators of at least the same seniority has approved it, or Ardent has verified the user’s identity itself, in which case the reset takes effect no sooner than 24 hours later. Ardent makes a new person the customer’s Owner only on documented evidence, verified through contact details already held, and only after notifying the customer’s Owner and administrators at least 72 hours in advance, during which any of them may stop it. Each such event is recorded in the customer’s audit trail.
- Ardent keeps the security measures in section 5 in place and reviews them regularly.
- Ardent keeps records of its processing for customers and makes relevant information available to the customer on request.
- Privacy and security questions about this DPA can be sent to agoo@ardentafrica.com.
5. Security measures
Section 28 of Act 843 requires appropriate, reasonable technical and organisational measures to protect personal data. Agoo is designed with the measures below. Agoo is in early access, so each measure applies to each part of the platform as it launches.
Technical measures
- Encryption in transit with TLS, and encryption at rest (AES-256) for the database, backups and stored files.
- Field-level encryption for ID numbers, with a secure hash for matching so the full number need not be shown.
- Tenant isolation: every customer record belongs to one customer, and isolation enforced at the data layer refuses access to other customers’ records.
- Role-based access with site permissions, so users see only what their role and sites allow.
- Two-step verification for customer administrators, mandatory two-step verification for Ardent staff with access to internal systems, time-limited sessions and single sign-on on plans that include it.
- Kiosks paired as individual devices with hardware-bound keys, which can be revoked at any time.
- Private file storage reached only through short-lived signed links or through the API by signed-in users, with location data removed from uploaded photos. Staff profile photos are re-encoded when uploaded, which removes all metadata, are served only to signed-in users allowed to see the customer’s directory, and are deleted within the hour of being replaced or removed, or of the person being deactivated, unless a legal hold applies.
- An append-only, hash-chained audit trail of sign-ins, views, exports, changes, deletions and Ardent support access, with hourly checkpoints.
- Automatic deletion on the customer’s retention schedule, with every deletion logged; ID images deleted after 24 hours by default, and clock-in selfies and exact locations after 90 days by default.
- Daily encrypted backups, and the ability to restore service from them.
- A web application firewall, rate limits and bot protection in front of the API and public forms; credentials and secrets kept out of code, encrypted, and scanned for automatically before code is merged.
Organisational measures
- Least-privilege access to production systems, reviewed when people join, change role or leave.
- Confidentiality obligations for everyone with access to customer personal data.
- Reviewed changes: code and database changes are reviewed before they reach production.
- An incident response procedure, including the notification steps in section 9.
- Due diligence on sub-processors, and written contracts with each of them.
Ardent may improve these measures over time but will not reduce the overall level of protection. More detail is on our security page.
6. Sub-processors
- The customer authorises Ardent to use the sub-processors on our sub-processor list. Some process data only when the customer turns on the related feature, such as WhatsApp or Agoo AI.
- Ardent puts a written contract in place with each sub-processor that requires it to protect customer personal data to a standard at least as protective as this DPA, and remains responsible to the customer for its sub-processors.
- Ardent will tell customers at least 30 days before a new sub-processor starts processing customer personal data, by email to the Owner and by updating the list. If a sub-processor must be replaced urgently, for example because it has failed, Ardent will tell customers as soon as possible.
- The customer may object to a new sub-processor on reasonable data protection grounds within that notice period. Ardent will then work in good faith to address the objection, for example by not using that sub-processor for the customer’s data. If that isn’t possible, the customer may end the affected service and receive a refund of fees paid for the period after it ends.
7. Requests from data subjects
- Agoo gives the customer tools to find, export, correct and erase a person’s data, including records hidden by the customer’s plan, so the customer can answer requests under sections 32, 33 and 35 and objections under sections 20 and 39 of Act 843.
- If Ardent receives a request about customer personal data directly, it will pass it to the customer within five working days and won’t answer it, other than to say it has been passed on, unless the customer asks it to.
- Where the tools aren’t enough, Ardent will help the customer respond, taking into account the nature of the processing.
8. Help with compliance
Ardent will give the customer reasonable help with its data protection impact assessments (including the template Agoo provides for face clock-in), its records of processing, consultations with the Data Protection Commission, and any inquiry by the Commission about the processing, by providing information about Agoo and how it processes data.
9. Security compromises
- Ardent will tell the customer without undue delay, and within 72 hours, after becoming aware of a security compromise affecting customer personal data.
- The notice will describe, as far as Ardent then knows, what happened, the kinds of data and approximate number of people affected, the likely consequences, what Ardent has done and will do about it, and who to contact. Ardent will add information as it becomes available.
- Ardent will help the customer meet its duty under section 31 of Act 843 to notify the Data Protection Commission and the people affected as soon as reasonably practicable, and will take steps to restore the integrity of the affected systems. Ardent will not notify the customer’s data subjects itself unless the customer asks or the law requires it.
- Ardent will also make any report the law requires of it, including to the Cyber Security Authority under the Cybersecurity Act, 2020 (Act 1038) where that Act applies.
- Telling the customer about a security compromise is not an admission of fault.
10. International transfers
- Customer personal data is stored mainly in London, United Kingdom, and is processed in the other locations shown on the sub-processor list, which include the European Union, the United States, Ghana and Nigeria. The customer authorises these transfers.
- Ardent protects transferred data with written contracts with each sub-processor, encryption in transit and at rest, access controls, and by sending each provider only what it needs.
- Where a customer is subject to another country’s data protection law that requires specific transfer terms, such as the GDPR or UK GDPR, the Nigeria Data Protection Act, 2023 or Kenya’s Data Protection Act, 2019, Ardent will agree reasonable additional terms on request.
11. Return and deletion
- The customer can export its data at any time. On every plan, including the Free plan, this includes a full export of the organisation, with records hidden by the plan and the files still kept, requested from the console by an Owner or Admin and downloaded from the console for 7 days. It leaves out passwords, keys and other secrets, face templates, and full ID numbers, which never leave Agoo (their last four characters are included). Cancelling a paid plan moves the organisation to the Free plan and does not end this DPA or delete data. Moving to any lower plan never deletes data by itself: records older than the new plan’s history are kept, hidden, and come back when the customer moves to a plan with a longer history.
- When the customer asks for its organisation to be deleted, or the agreement ends, Ardent deletes customer personal data within 30 days, or after the export period in the terms of service where that applies. Copies in encrypted backups expire within a further 30 days and are not restored in the meantime except to recover from an incident.
- Ardent may keep data that the law requires it to keep, protected and used for no other purpose. Ardent will confirm deletion in writing on request.
- Data deleted under the customer’s retention settings, or by erasing a person, is deleted in the same way, and each deletion is logged.
12. Information and audits
- Ardent will make available the information reasonably needed to show that it meets this DPA, such as descriptions of its security measures, sub-processor details and any independent reports it holds, and will answer one reasonable security questionnaire a year.
- If that information is not enough, or the Data Protection Commission requires it, or after a security compromise affecting the customer, the customer may audit Ardent’s compliance. The customer must give at least 30 days’ notice, use an independent auditor bound by confidentiality, audit during business hours without disrupting the service or accessing other customers’ data, and bear its own costs. Audits are limited to once in any 12 months, except after a security compromise or at the Commission’s request.
- Sub-processors are audited through their own reports and certifications.
13. Liability
Each party’s liability under this DPA is subject to the limits in the terms of service. Each party is responsible for its own compliance with Act 843 and for its share of any compensation awarded to a data subject (section 43), in proportion to its responsibility for the damage.
14. Duration, precedence and changes
- This DPA lasts as long as Ardent processes customer personal data.
- On matters of personal data, this DPA takes priority over the terms of service. An order form takes priority only where it expressly changes this DPA.
- Ardent may update this DPA as the terms of service describe, and will not reduce the protection it gives customer personal data without the customer’s agreement, except where the law requires a change.
15. Contact
Ardent Africa Foundation LBG10A Mega Street, Adentan Municipality, Accra, Ghana
Email: agoo@ardentafrica.com (put “Privacy” in the subject line)
Phone: +233 30 398 3393