Trust & Security

How we handle your data.

No badges we haven't earned. No certifications we haven't passed. A plain account of where data lives, who can see it, and what we're working toward.

Last reviewed May 2026 · AI Tech Africa · Accra, Ghana
— 01 / Principles —

What we commit to.

Before any framework or audit, these are the commitments the business operates by. They predate compliance work and they outlast it.

01

Your data is yours.

Custom builds are deployed onto infrastructure you own, with database access we hand over to you. We do not resell client data, and we do not train models on it.

02

Encryption is the floor.

All traffic moves over TLS. Backups are encrypted at rest. Secrets live in environment variables, never in source. No exceptions for "internal" tools.

03

Access is named, not shared.

Every login is a person, not a team. No shared admin accounts. SSH keys are individual. Removing someone is a one-line change.

04

We tell you when something goes wrong.

If we identify an incident affecting your data, we notify you in writing without undue delay — and we explain what happened, not just that something did.

— 02 / Compliance posture —

Where we actually stand.

Compliance frameworks are audits, not stickers. Below is the honest state for each one prospects ask about. Aligned means we operate in accordance with the framework's principles. In progress means formal work is underway. Planned means scheduled for a specific window. On request means we engage with it on a per-contract basis.

GDPR (EU)
European data protection regulation. Lawful-basis processing, subject rights, breach notification, DPA available on request.
Aligned
Ghana DPA 2012
Ghana Data Protection Act. Operating in accordance with the Act; controller registration with the DPC in progress.
In progress
SOC 2 Type II
US-origin audit covering security, availability, and confidentiality controls.
Planned
ISO 27001
International standard for information security management systems.
Planned
HIPAA (US)
US healthcare data. We sign a Business Associate Agreement when scope of work involves US-regulated PHI.
On request
A note on badges We will not display compliance badges we have not earned. When SOC 2 and ISO 27001 are passed, they will appear here with the auditor's name and the report date. Until then, this page is what we offer instead — a plain account of what is and isn't true.
— 03 / Data protection —

Privacy posture.

For client engagements, we act as a data processor — you remain the controller of your end users' data, and we process it on your instructions under a Data Processing Agreement. For our own marketing site and Connect workspace, we act as the controller.

Lawful basis. Contract performance (project work), legitimate interest (security logs, billing), and consent (marketing communications and any cookies beyond strictly necessary).

Data subject rights. Access, rectification, erasure, portability, restriction, and objection — exercised by emailing pako@ai-tech.africa. We respond within 30 days.

International transfers. Where personal data moves outside the EEA or Ghana, we rely on Standard Contractual Clauses or equivalent safeguards with the receiving sub-processor.

Retention. Project data is retained for the contract duration plus a short post-termination window, then deleted or returned at your request. Marketing data is retained until consent is withdrawn.

DPA. Our standard Data Processing Agreement is available on request. Email pako@ai-tech.africa.

— 04 / Security architecture —

How the stack is built.

Our own infrastructure runs on a single VPS with intentionally simple architecture. The fewer moving parts, the smaller the attack surface and the easier it is to reason about.

— 05 / Sub-processors —

Who else touches the data.

Third parties that may process personal data on our behalf. Each is bound by their own data-protection terms and is used only for the purpose listed. We give written notice before adding new sub-processors that materially expand this list.

Provider
Purpose
Region
Resend
Transactional email delivery (magic-link sign-in, system notifications)
United States
VPS host
Server infrastructure for the marketing site and Connect workspace
Provider listed on request

We do not use client-side analytics or third-party tracking pixels on this site. When AI features are deployed inside a client engagement, the LLM provider is named in the Statement of Work for that engagement and added to this list before processing begins.

— 06 / Incident response —

What happens when something goes wrong.

Every system fails eventually. The question is what you do in the first 24 hours after it does.

Detection. Application crashes, repeated failed authentication, and integrity check failures trigger alerts to the on-call engineer. Reports from clients are treated with the same priority as automated alerts.

Containment. Affected services are isolated promptly once an incident is confirmed. If a credential is suspected of being compromised, it is rotated immediately, before further investigation.

Notification. Affected clients are notified in writing without undue delay — typically within 72 hours of confirmation, in line with GDPR Article 33. The notification states what is known, what is being investigated, and what is being done. Updates follow until resolution.

Post-mortem. Incidents with client impact receive a written post-mortem shared with affected clients, describing root cause, timeline, and the specific change made to prevent recurrence.

— 07 / AI agents —

What our agents do with your data.

When we deploy AI agents into a client workspace — attendance summaries, customer-support triage, finance reconciliation — the agent operates on your data inside your environment. The LLM provider processes the conversation to generate a response, then returns it. Under the enterprise terms of the providers we use, client data is not retained by the provider for training.

Agent identity. Every agent action is logged with the agent name, timestamp, and inputs. Agents do not impersonate humans; their messages are labelled as such in your workspace.

The doctrine. Our agents absorb workload, not roles. They do not make terminal decisions on hiring, firing, payroll, or anything else with material consequence to a person — those remain with your team. The agent is the radar; your people still fly the aircraft.

— 08 / Contact —

Talk to a human.

Security disclosures

Found something? Email us. We do not pursue good-faith researchers and we acknowledge reports promptly.

Privacy & data subject requests

Access, deletion, portability, or any GDPR / Ghana DPA right. Response within 30 days.

DPA & legal documents

Data Processing Agreement, sub-processor questions, contract review.

Have a specific question?

Procurement teams, security reviewers, and DPO offices — we'll answer any reasonable due-diligence questionnaire in writing.

Talk to AI Tech Africa