Legal
Privacy notice
Last updated 5 October 2026 · Effective 5 October 2026
This notice explains how Ardent Africa Foundation LBG collects and uses personal data through Agoo and this website, how we protect it, and the choices and rights you have. We write it plainly because the people at your front door deserve to understand it.
On this page
- 1. Who we are
- 2. Our two roles
- 3. If you visit or work at an organisation that uses Agoo
- 4. If you use our websites or contact us
- 5. If your organisation is an Agoo customer
- 6. Why we use personal data and our lawful bases
- 7. Agoo AI and automated decisions
- 8. Who we share personal data with
- 9. Where data is stored and international transfers
- 10. How long we keep personal data
- 11. How we protect personal data
- 12. Your rights
- 13. If you are outside Ghana
- 14. Children and special personal data
- 15. Marketing
- 16. Contact us and complaints
- 17. Changes to this notice
1. Who we are
Agoo by Ardent is provided by Ardent Africa Foundation LBG (“Ardent”, “we”, “us”), a company limited by guarantee registered in Ghana, of 10A Mega Street, Adentan Municipality, Accra, Ghana. Agoo was founded, designed and developed by Mawuli Dzaka under Ardent Africa Foundation LBG.
This notice covers our websites (agoo.ardent.africa and docs.agoo.ardent.africa), the Agoo web console, visitor pages, QR code links and apps, and the way we deal with customers, people who contact us and people whose details organisations keep in Agoo.
Agoo is in early access and parts of it are still being built. Where this notice describes something that is planned rather than live, we say so. Our documentation marks each feature as available, in early access, in preview or planned.
You can contact us about anything in this notice at agoo@ardentafrica.com or on +233 30 398 3393. Full details are in section 16.
2. Our two roles
Ghana’s Data Protection Act, 2012 (Act 843) distinguishes between a data controller, who decides why and how personal data is processed, and a data processor, who processes it on a controller’s behalf. We are both, for different data.
| Data | Controller | Ardent’s role |
|---|---|---|
| Visitors, staff, contractors, people who scan its QR codes and other people an organisation records in Agoo | The organisation that uses Agoo (our customer) | Processor, acting only on the customer’s instructions under our data processing agreement |
| Customer accounts, billing, support, enquiries, and use of our websites | Ardent | Controller |
If you are a visitor or an employee of an organisation that uses Agoo, that organisation’s own privacy notice is the main one for you. Section 3 explains our part. Our obligations to customers as their processor are in the data processing agreement.
3. If you visit or work at an organisation that uses Agoo
The organisation decides what to ask for, why, and how long to keep it. Depending on how it has set Agoo up, it may record:
- Visitors and guests: your name, phone number, email address, company, who you are visiting and why, your visitor type, the site, times in and out, your photo, your signature and any documents you sign (such as a non-disclosure agreement), answers to the organisation’s own questions, a vehicle registration, and booking details if you book an appointment.
- Identity documents, only if the organisation asks for them: your name and ID number as read from the ID, and sometimes a photo of the ID.
- Staff: your name, contact details, role, sites, team, and attendance records such as clock-in and clock-out times, the method used, shifts, leave and timesheets. If you or the organisation add them, also a profile photo, the name you go by and your pronouns, and how you want Agoo to reach you (which alerts come by WhatsApp, SMS or email, and quiet hours). If the organisation sends you scheduled report emails (totals of visits, never names), Agoo keeps which reports you get and any you stopped. The organisation decides which of your details you can change yourself in the console. If you clock in on your phone, Agoo checks that you are within the site’s area, or on its Wi-Fi, at that moment. If the organisation turns them on, Agoo also keeps a selfie taken when you clock in, the exact location of a phone clock-in, or the Wi-Fi network you used, for as long as the organisation sets (90 days by default for selfies and exact locations).
- Others, depending on the organisation: contractors and their documents, delivery riders, residents and domestic staff on an estate, or a school’s authorised pick-up people.
- People who scan its QR codes: when you scan a tracked QR code an organisation made with Agoo (one that opens an agoo.click or qr.agoo.ardent.africa link), Agoo records when you scanned it; the country, region and city that our network provider, Cloudflare, works out from your connection; the kind of device, its operating system, browser and language; and what happened, for example that you were sent on to the organisation’s web page. To count how many different people scanned a code, it also keeps a one-way code made from your connection, your browser and that day’s date. The code changes every day, so it can’t be used to follow you from one day to the next, and it doesn’t identify you. If a code asks for a password, Agoo stores only a scrambled form of the password, never the password itself. A plain QR code holds its content in the code itself, so scanning it doesn’t reach Agoo and records nothing.
Agoo is designed with these protections, which organisations can’t switch off:
- ID numbers are masked on screen and in exports by default (for example GHA-•••••••••-7) and encrypted individually. ID images are deleted automatically on the schedule the organisation sets; the default is 24 hours.
- Face matching is only for staff attendance and never for visitors. An organisation can use it only after it publishes a notice to its staff saying why, on the basis it records: either its legal basis as the employer, or each employee’s consent. Agoo keeps the notice and each acknowledgement or consent. The face template is created and kept, encrypted, on the kiosk where the employee enrols; it never leaves that kiosk, is never sent to Agoo’s servers, reports, the API or anyone else, and is deleted from every kiosk when the employee leaves. If a face match fails, the employee can still clock in another way, and a supervisor reviews it.
- Selfies and exact locations from clock-in are seen only by people the organisation allows to read attendance, every viewing is logged, and location data is removed from photos when they are uploaded.
- Staff profile photos are copied afresh, pixels only, when they are uploaded, which removes location and camera details, and are shown only to people signed in to the organisation who are allowed to see its directory. A photo that is replaced or removed is deleted within the hour, and so is your photo when the organisation deactivates you, unless it has placed a legal hold.
- Messages about your visit (SMS, WhatsApp or email) are used only for that visit or booking. Ardent never uses your contact details for its own marketing.
- Watchlist checks are decided by people. An organisation can screen check-ins against its own watchlist; a match alerts a person, and Agoo never refuses entry automatically. A watchlist is shared only when an organisation in an organisation group chooses to share it with the other organisations in the group: then a watchlist entry's name, phone number and reason can be checked against visitors at their sites, and a match shows them that entry's name and reason. ID numbers are never shared between organisations.
- Organisation groups. Organisations that work together, such as a company and its subsidiaries, can form a group on Agoo. Each organisation decides what the group gets: its totals only (numbers, never names), or access for the group's administrators to see, or also manage, its records as that organisation's own staff would. Everything they do is recorded in that organisation's audit trail, and the organisation can end it at any time. The organisation you visit or work for remains responsible for your information.
- QR code scans never store your IP address. Cloudflare uses it only while it delivers the link, to work out the approximate location and the daily code above. Scans are kept for two years, or the period the organisation sets, and are then deleted automatically.
- Every view, export and change of personal data is recorded in a tamper-evident audit trail.
To see, correct or delete your data, contact the organisation using the details in its privacy notice, which Agoo shows before you check in. Agoo is adding a way to make these requests online from the organisation’s visitor pages, verified by a code sent to your phone. If you contact us instead, we will pass your request to the organisation, tell you we have done so, and help it respond. We do not act on an organisation’s data without its instructions unless the law requires us to.
4. If you use our websites or contact us
Enquiries and early-access requests
When you use the forms on this website we collect your name, work email, phone number (optional), organisation, sector, number of sites, the products and plan you are interested in, and your message. The form emails these details to our team through our email provider and sends you a confirmation. We use them to reply to you and follow up on your enquiry, not to add you to a mailing list.
To stop spam, the form uses automated anti-spam checks. The form doesn’t store your IP address.
Status updates
If you subscribe at status.agoo.ardent.africa, we keep your email address to send you updates about incidents and planned maintenance, once you’ve confirmed it from the email we send. One click in any of those emails unsubscribes you and deletes the address; one you never confirm is deleted after two days. We use it for nothing else. To stop abuse, the form counts requests from your network for an hour without storing your IP address.
Emails and calls
If you email or call us, we keep what you tell us and our reply so we can help you and keep a record of the conversation.
Technical data
When you load a page, our hosting and DNS providers (Vercel and Cloudflare) process your IP address, browser type, the page requested and the time, and keep them briefly in server logs to deliver the page, keep it secure and fix problems.
Cookies and similar technologies
- Our websites set no cookies and use no analytics, advertising or tracking pixels. Fonts are served from our own site, not from a third party.
- The website stores one setting in your browser’s local storage: whether you chose the light or dark theme. It stays on your device, and you can clear it in your browser’s settings at any time.
- The Agoo console and apps use cookies and device storage that are strictly necessary to keep you signed in and secure, and, on kiosks and staff apps, to keep working offline.
- The emails our website forms send don’t track whether you open them or which links you click.
If we ever add analytics or other non-essential cookies, we will update this notice first and ask for your consent where the law requires it.
5. If your organisation is an Agoo customer
- Account details: the names, work email addresses, phone numbers, roles and sites of your administrators and users; sign-in records; two-step verification and single sign-on settings; and each user’s console appearance (light, dark or same as their device).
- Billing details: your organisation’s name, address and tax details (including a TIN you add), invoices, receipts and payment records, bank-transfer references and purchase-order numbers, and any proof you send with an offer application (such as a registration certificate), kept privately and seen only by Agoo’s platform owner. Card and Mobile Money payments are handled by Paystack; we never receive or store full card numbers or Mobile Money PINs. For a saved card we keep its type, issuing bank, last four digits and expiry date, and, to renew with it, Paystack’s authorisation for it (encrypted), its signature and the email it was paid with. When you remove the card in Billing, or replace it with another, the authorisation, signature and email are deleted; the card type, bank, last four digits and expiry stay with the payment records they belong to.
- Support: what you tell us when you ask for help. If our support team needs to look at your organisation’s data to help you, that access is read-only, time-limited and given a reason; your organisation’s Owners are told when it begins and can end it, changes need an Owner’s approval, and every view and change is recorded in your audit trail. In an emergency that can’t wait (for example, nobody can sign in, or a security incident), our platform owner may act without prior approval after checking the request through contact details we already hold; your Owners and Admins are told at once and receive a written report within 72 hours.
- Account recovery: if you lose access to your two-step verification, the request, the email address it was confirmed from, who approved it and how they checked it was you (for example, in person or on a video call, with a note of the identity document seen, never a copy of it). If your organisation’s Owner has gone and we are asked to appoint a new one, a description of the evidence we were shown and how we checked it. These are kept with your organisation’s audit trail.
- Usage and device data: which features are used, usage against your plan’s limits (such as messages and AI credits), API request logs, and the health of paired kiosks (model, operating system, app version, battery, connectivity and last sync).
We send account holders service messages about billing, security, and changes to Agoo or these documents, and we email Owners and Admins about planned maintenance and anything their organisation needs to do. These aren’t marketing, so they continue while you have an account. News about Agoo’s features is shown only inside Agoo, and we keep a note of which announcements you’ve read or closed so they don’t show again; it’s deleted with your account.
6. Why we use personal data and our lawful bases
Act 843 allows personal data to be processed with the person’s consent, or without it where processing is necessary for a contract they are party to, is required or authorised by law, protects their legitimate interest, is needed for a statutory duty, or is necessary for the legitimate interest of the controller or a third party to whom the data is supplied (section 20).
| What we do as controller | Lawful basis |
|---|---|
| Reply to enquiries and set up early access | Our legitimate interest in answering organisations that contact us, and steps you ask us to take before a contract |
| Send the status updates you subscribed to | Your consent, which you withdraw by unsubscribing |
| Provide Agoo, manage accounts and give support | Contract with your organisation; our legitimate interest in supporting its users |
| Bill, collect payment, and keep tax and accounting records | Contract; legal obligations under tax law |
| Keep Agoo secure, prevent fraud and abuse, keep audit and security logs | Our legitimate interest, and our duty to keep personal data secure under Act 843 |
| Understand how Agoo is used and improve it, using usage statistics | Our legitimate interest in running and improving the service |
| Send product news | Your consent, which you can withdraw at any time |
| Respond to lawful requests and protect our legal rights | Legal obligation; our legitimate interest |
When we process visitor and staff data as a processor, the customer organisation is responsible for having a lawful basis, and we act only on its instructions.
7. Agoo AI and automated decisions
- AI is optional and off by default. Agoo AI (asking questions about your data, reading IDs the kiosk can’t read itself, digitising paper logbooks and drafting) is arriving in stages. Nothing is sent to an AI model until an organisation’s administrator turns it on.
- Provider. Agoo AI uses Anthropic’s Claude models. We send only what each task needs, and remove phone numbers, ID numbers and other personal details where the task doesn’t need them.
- No training. Customer data is never used to train AI models, ours or anyone else’s. Anthropic’s commercial terms do not allow it to train models on customer content sent through its API.
- People decide. Agoo doesn’t make decisions that significantly affect people based solely on automated processing. AI never denies entry, adds anyone to a watchlist or approves a visit. Watchlist matches and AI suggestions are shown to a person, who decides. Face clock-in either finds a confident match or offers another way to clock in, which a supervisor reviews; it never guesses.
- Assistants you connect. If an organisation connects its own AI assistant to Agoo (through our planned MCP server), data the assistant reads goes to that assistant’s provider under the organisation’s own agreement with it, not ours.
Under section 41 of Act 843 you can ask that a decision which significantly affects you is not based solely on automated processing, and ask for such a decision to be reconsidered.
9. Where data is stored and international transfers
Agoo’s primary data is stored in the United Kingdom. Files such as photos and signatures are stored in Western Europe, and offline working for Agoo’s apps runs in the European Union. Some providers are elsewhere: email, AI and push notifications are delivered by providers in the United States, WhatsApp runs on Meta’s global infrastructure, SMS is sent through Hubtel in Ghana, and payments through Paystack in Ghana and Nigeria. The sub-processors page lists each location.
When personal data leaves Ghana, we protect it with:
- written contracts with each provider that require confidentiality and appropriate security, and limit use to providing their service;
- encryption in transit (TLS) and at rest;
- access controls, so only people and systems that need data can reach it;
- sending only what each provider needs, for example removing personal details from AI tasks where they aren’t needed.
You can ask us for more information about the safeguards for a particular provider.
10. How long we keep personal data
| Data | How long |
|---|---|
| Enquiries and early-access requests | Up to two years after our last contact, unless your organisation becomes a customer |
| Status page subscriptions | Until you unsubscribe; an address that isn’t confirmed is deleted after two days |
| Customer account details | While the account exists, then deleted within 30 days of the organisation being deleted |
| Invoices, receipts and payment records | As long as tax and accounting law requires, even after an account is deleted |
| Support conversations | Up to two years after the conversation ends |
| Security logs | Up to 12 months, or longer if needed to investigate a specific incident |
| Visitor, staff and other data an organisation keeps in Agoo | The periods the organisation sets, within its plan’s maximum when it sets them, after which Agoo deletes it automatically and logs the deletion. Moving to a lower plan never deletes data: records older than the new plan’s history are kept and hidden until the organisation moves back up, or deleted when they reach the end of the organisation’s own retention period. If the organisation is deleted, within 30 days. |
| Consent to product news | Until you withdraw it, plus a record that you did |
Deleted data can remain in our encrypted daily backups until those backups expire on their normal cycle, within a further 30 days. We don’t restore deleted data from backups except to recover from an incident, and if we ever do, we delete it again.
11. How we protect personal data
Act 843 requires us to keep personal data secure with appropriate technical and organisational measures (section 28). Agoo is designed with:
- encryption in transit (TLS) and at rest, with ID numbers encrypted individually;
- tenant isolation: every record carries its organisation’s ID, and the database itself refuses to show it to anyone else;
- roles and site permissions, so people see only what their job needs;
- two-step verification for administrators, and mandatory two-step verification for Ardent staff with access to internal systems;
- a tamper-evident audit trail of views, exports and changes, including any access by Ardent support;
- least-privilege access to production systems, secrets kept out of code and scanned for automatically, and daily backups.
More detail is on our security page. No system is perfectly secure. If a security compromise affects your data, we will tell you and the Data Protection Commission as section 31 of Act 843 requires; for data we process for a customer, we tell the customer without undue delay and help it notify the people affected.
12. Your rights
Under Act 843 you can:
- Access your data: ask whether we hold personal data about you, what it is, why we use it and who we have shared it with, and get a copy in a form you can understand (sections 32 and 35).
- Correct or delete data that is inaccurate, irrelevant, excessive, out of date, incomplete, misleading or obtained unlawfully, and ask us to delete data we are no longer entitled to keep (section 33).
- Object to our processing and ask us to stop (sections 20 and 39).
- Stop direct marketing at any time (section 40).
- Challenge automated decisions that significantly affect you (section 41).
- Withdraw consent where we rely on it, without affecting what we did before.
- Seek compensation if you suffer damage because we fail to comply with the Act (section 43).
To use a right, email agoo@ardentafrica.com with “Privacy” in the subject, or write to us at the address in section 16. We will ask you to prove your identity before we share or change anything. We don’t normally charge, and we reply as soon as we can and within 30 days; if a request is complex, we will tell you why we need longer.
For data an organisation keeps about you in Agoo, contact that organisation first. If you contact us, we will pass your request on and help the organisation answer it.
13. If you are outside Ghana
Act 843 requires personal data of people from other countries to be processed in line with the data protection law of their country (section 18). If you are in Nigeria (Nigeria Data Protection Act, 2023), Kenya (Data Protection Act, 2019), the United Kingdom or the European Union (UK GDPR or GDPR), or another country with a data protection law, you have the rights that law gives you, and you can use them by contacting us as described above. For customers outside Ghana, we support their own compliance under the data processing agreement.
14. Children and special personal data
Our websites and customer accounts are for adults acting for organisations, and we don’t knowingly collect children’s data for our own purposes. If we learn that we have, we delete it.
Some organisations use Agoo in ways that involve children or sensitive data. A school may record pupils and the people allowed to collect them; a church may record children at check-in, and its attendance records can reveal religious belief; a hospital’s visitor records can suggest something about a patient’s health. Act 843 treats data about a child under parental control, and data about religious or philosophical beliefs, ethnic origin, race, trade union membership, political opinions, health, sexual life or criminal behaviour, as special personal data, which may be processed only where it is necessary or the person consents (section 37). The organisation is responsible for meeting those conditions, including parental consent where it is needed; Agoo helps by limiting who can see such records and keeping them only as long as the organisation sets.
15. Marketing
We send product news only to people who have agreed to receive it, and every message has a way to stop. We never use visitor or staff data held in Agoo for our own marketing, and we never sell it. Service messages about your account aren’t marketing.
16. Contact us and complaints
For questions or requests about privacy, contact us:
Ardent Africa Foundation LBG10A Mega Street, Adentan Municipality, Accra, Ghana
Email: agoo@ardentafrica.com (put “Privacy” in the subject line)
Phone: +233 30 398 3393
If you are unhappy with how we have handled your data, please tell us first so we can put it right. You can also complain to the Data Protection Commission, Ghana’s data protection regulator, at dataprotection.org.gh. If you live elsewhere, you can also complain to the data protection authority where you live.
17. Changes to this notice
We will update this notice when our services or the law change, and show the new date at the top. If a change materially affects how we use personal data, we will tell customers by email or in the console at least 30 days before it takes effect. Earlier versions are available on request.