Legal

Privacy policy

Draft — pending legal review

This policy explains what personal data Nobicel Ltd collects, why we collect it and what we do with it. It covers this website and the platforms we build and operate.

Who we are

Nobicel Ltd is a software company based in Accra, Ghana. For questions about this policy or about data we hold, contact hello@nobicel.com.

Controller and processor

For enquiries you send us directly, we are the data controller. For personal data held inside a platform we built or operate for an institution — citizen records, patient records, employee records — that institution is the controller and we act as its processor, on its written instruction.

Data we collect

  • Enquiry data — the name, organisation, email, phone number and message you send through this site.
  • Engagement data — contact details of the people we work with at a client organisation.
  • Client system data — personal data inside platforms we build, processed only on the client’s instruction.
  • Technical data — request logs needed to operate and secure our services.

How we use it

  • To respond to your enquiry and to deliver work we have been engaged to do.
  • To operate, support and secure the platforms we run for clients.
  • To meet our own legal, tax and record-keeping obligations.

We do not sell personal data, and we do not use client system data for our own purposes.

Sharing

We share personal data only where it is needed to deliver a service — for example with a hosting provider or a payment provider named in the engagement — and under contract terms that hold them to the same standard.

Retention

Enquiry data is kept only as long as needed to deal with the enquiry. Data inside a client platform is retained according to that client’s policy and any legal requirement, and is returned or deleted at the end of an engagement on request.

Your rights

You may ask for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it where we are not required to keep it. If your data sits inside a platform operated by an institution, raise the request with that institution first and we will support them in answering it.

Security

Access is role-based and enforced on the server, data is encrypted in transit and at rest, and access to sensitive records is logged. Our security posture sets this out in full.

Changes

If this policy changes materially we will say so on this page. Questions go to hello@nobicel.com.