Privacy Policy
Effective Date: July 1, 2026 | Last Updated: July 7, 2026
1. Introduction & Scope
XDA Technologies ("we", "us", or "our") respects your privacy and is strictly committed to protecting your personal data. This Privacy Policy outlines how we collect, process, and safeguard your information when you interact with our website, FinTech solutions, API gateways, and consultancy services. This policy ensures strict compliance with the Ghana Data Protection Act, 2012 (Act 843), the General Data Protection Regulation (GDPR), and international data privacy frameworks.
In the context of processing personal data via our telecom and VAS APIs on behalf of our enterprise clients, XDA Technologies strictly acts as a Data Processor, while our Client remains the Data Controller.
2. Categories of Information We Collect
We may collect, use, store, and transfer different kinds of personal data depending on your interaction with our services:
- Account & Identity Data: First name, last name, business email address, phone number, company name, corporate registration documents, and job title when registering for API access or consultancy inquiries.
- Financial & KYC Data: Billing addresses, corporate bank account details for wire transfers, and transaction records. Note: Credit/Debit card processing is handled securely by PCI-DSS certified third-party payment gateways; we do not store raw card PANs or CVVs.
- Technical & Telemetry Data: IP addresses, browser types, time zone settings, operating systems, API request metadata, HTTP headers, and latency logs. This data is strictly utilized for monitoring system health, load balancing, and mitigating Distributed Denial of Service (DDoS) or brute-force attacks.
- Transmission Data (VAS): Metadata related to SMS, USSD, and OTP transmissions processed through our gateways (Sender IDs, recipient MSISDNs, timestamp of transmission, delivery receipts).
- Message Content: Message body content (e.g., OTP codes, transaction alerts) is transiently processed in memory and queued for delivery. It is not permanently stored in our databases unless explicitly required by telecom regulations, audit logging requirements contracted by the Data Controller, or for spam mitigation algorithms.
3. How We Use Your Data
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
- Performance of a Contract: To provision API keys, authenticate requests, process transactions, generate billing invoices, and provide bespoke consultancy services.
- Legitimate Interests: To investigate fraud, prevent spam, enforce our Acceptable Use Policy (AUP), and secure our network infrastructure.
- Legal Compliance: To comply with telecommunication regulations, Anti-Money Laundering (AML) directives, and lawful requests from governmental authorities.
4. Data Sharing and Sub-Processors
XDA Technologies does not sell, rent, or trade your personal data under any circumstances. We may share necessary data strictly on a need-to-know basis with:
- Telecom Carriers & Mobile Network Operators (MNOs): Strictly for the technical routing of SMS and USSD traffic to end-users across global networks.
- Cloud Infrastructure Providers: Highly secure, SOC2 compliant data centers (e.g., AWS, Microsoft Azure, Google Cloud) hosting our infrastructure.
- Regulatory & Law Enforcement Authorities: We will disclose data if legally compelled by a valid subpoena, court order, or regulatory mandate from entities such as the National Communications Authority (NCA) or the Bank of Ghana to assist in fraud or criminal investigations.
5. International Data Transfers
Whenever we transfer your personal data out of your jurisdiction (e.g., for cloud hosting), we ensure a similar degree of protection is afforded to it by utilizing legally recognized transfer mechanisms, such as Standard Contractual Clauses (SCCs) or ensuring the destination country provides an adequate level of data protection.
6. Data Security Measures
We have implemented robust enterprise-grade security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way, altered, or disclosed. These measures include:
- End-to-End Encryption (TLS 1.3) for all API and web traffic in transit.
- AES-256 Encryption for sensitive data at rest.
- Strict Role-Based Access Controls (RBAC) limiting data access to authorized personnel only.
- Regular third-party vulnerability scanning and penetration testing.
7. Data Breach Notification Protocol
In the highly unlikely event of a suspected or confirmed data security breach, XDA Technologies has enacted comprehensive incident response procedures. We will notify affected Clients (Data Controllers) and any applicable regulators of a breach without undue delay, generally within 72 hours of verification, as legally required.
8. Data Retention
We retain your personal data only as long as necessary to fulfill the purposes outlined in this policy, or as mandated by financial, tax, and telecommunication retention laws. Transmission logs (DLRs) are typically retained for 90 days for troubleshooting purposes, after which they are aggressively anonymized or purged.
9. Your Legal Rights
Depending on your jurisdiction, under applicable data protection laws, you possess the right to:
- Request Access: Receive a copy of the personal data we hold about you.
- Request Correction: Have any incomplete or inaccurate data we hold about you corrected.
- Request Erasure (Right to be Forgotten): Ask us to delete or remove personal data where there is no good reason for us continuing to process it, subject to overriding legal retention constraints.
- Object to Processing: Object where we are relying on a legitimate interest and there is something about your particular situation which makes you want to object.
- Request Data Portability: Request the transfer of your personal data to you or to a third party in a structured, machine-readable format.
Data Protection Officer Contact
To exercise any of your rights, or if you have any questions or concerns regarding your privacy or this policy, please contact our Data Protection Officer (DPO).
Email: [email protected]
Address: XDA Technologies Legal Dept, Accra, Ghana