TERMS OF SERVICE, END-USER TERMS, PRIVACY AND DATA PROTECTION POLICY

Document Classification: Public
Version: 1.0
Effective Date: 1st January 2026
Last Updated: 16th July, 2026
Document Owner: Akwaaba Solutions
Approved by: Executive Management


IMPORTANT NOTICE

These Terms of Service, End-User Terms, Privacy and Data Protection Policy govern access to and use of the Akwaaba Smart HRM Suite.

They apply to subscribing institutions, authorised representatives, administrators, employees, contractors, individual users and other persons whose personal data are processed through the platform.

Please read this document carefully before accessing or using the platform.

A subscribing institution accepts the applicable contractual provisions of this document by signing a service agreement, accepting an approved quotation or order form, paying an applicable subscription fee, authorising implementation, or otherwise expressly agreeing to use the platform.

An individual user accepts the End-User Terms and Acceptable Use provisions by completing the platform’s approved electronic acceptance process, including selecting an acceptance checkbox or signing an acknowledgement made available before or upon first access.

Biometric enrolment, standing alone, does not constitute acceptance of all commercial provisions of this document.

A person who does not agree to the terms applicable to that person must not access or continue to use the platform.

Nothing in this document excludes, restricts or overrides any right, duty, remedy or protection that cannot lawfully be excluded under the laws of the Republic of Ghana.


PART I

GENERAL PROVISIONS

1. INTRODUCTION

1.1 About Akwaaba Solutions

Akwaaba Solutions provides technology-enabled workforce, attendance, communication and institutional-management services, including the Akwaaba Smart Human Resource Management Suite.

The Akwaaba Smart HRM Suite is designed to assist organisations in managing their authorised workforce and administrative functions through approved digital channels.

1.2 Purpose of This Document

This document explains:

  1. the conditions governing institutional and individual use of the platform;
  2. the respective responsibilities of Akwaaba Solutions, subscribing institutions, administrators and users;
  3. the rules governing user accounts, security and acceptable conduct;
  4. the categories of personal data that may be processed through the platform;
  5. the purposes and lawful grounds for processing personal data;
  6. the safeguards applied to biometric and other sensitive personal data;
  7. the rights of persons whose personal data are processed;
  8. the commercial conditions governing subscriptions and services; and
  9. the limitations, remedies and dispute-resolution procedures applicable to the platform.

1.3 Nature of the Document

This document contains four related components:

  1. institutional terms governing the relationship between Akwaaba Solutions and subscribing institutions;
  2. end-user terms governing individual access and conduct;
  3. an acceptable-use policy applicable to all authorised users; and
  4. a public privacy and data-protection notice.

The commercial provisions apply principally to subscribing institutions. Individual users are bound principally by the account-security, acceptable-use, confidentiality, privacy and platform-conduct provisions relevant to their access.

1.4 Legal Framework

This document shall be interpreted in accordance with applicable laws of the Republic of Ghana, including:

  1. the Data Protection Act, 2012 (Act 843);
  2. the Electronic Transactions Act, 2008 (Act 772);
  3. the Cybersecurity Act, 2020 (Act 1038);
  4. applicable employment and labour legislation;
  5. applicable electronic-communications legislation; and
  6. regulatory directives, standards and guidance issued by competent Ghanaian authorities.

1.5 Relationship with Other Agreements

This document must be read together with any applicable:

  1. service agreement;
  2. subscription agreement;
  3. data-processing agreement;
  4. order form;
  5. accepted quotation;
  6. implementation agreement;
  7. service-level agreement;
  8. support agreement; or
  9. other written instrument executed by Akwaaba Solutions and the Customer.

1.6 Order of Precedence

Where an inconsistency arises, the following order of precedence applies:

  1. a signed Data Processing Agreement, for matters concerning personal-data processing;
  2. a signed enterprise, service or subscription agreement;
  3. an accepted order form;
  4. a signed service-level or implementation agreement;
  5. these Terms;
  6. the Acceptable Use Policy; and
  7. other published operational guidance.

A proposal or quotation does not amend these Terms unless it expressly identifies the provision being amended and is accepted by an authorised representative of Akwaaba Solutions.


2. DEFINITIONS

In this document, unless the context requires otherwise:

2.1 “Account”

Means a registered user profile, login credential or authorised access arrangement through which a person accesses the platform.

2.2 “Account Owner”

Means the Customer representative authorised to manage the principal institutional account and appoint administrators.

2.3 “Administrator”

Means a person authorised by the Customer to configure designated platform functions, manage users, assign roles, enrol personnel, access reports or perform other authorised administrative functions.

2.4 “Akwaaba Solutions,” “we,” “us” or “our”

Means the legal entity identified in Section 42 that owns, licenses, operates or supports the Akwaaba Smart HRM Suite.

2.5 “Applicable Law”

Means the laws, regulations, directives, orders and binding regulatory requirements applicable to the relevant processing activity or contractual relationship.

2.6 “Authorised Representative”

Means a person with authority to bind a Customer in relation to subscriptions, payments, data-processing instructions or contractual amendments.

2.7 “Biometric Data”

Means personal data resulting from technical processing relating to the physical, physiological or behavioural characteristics of an individual for identification or authentication, including fingerprint templates, facial-recognition templates and approved enrolment images.

2.8 “Confidential Information”

Means non-public commercial, technical, operational, financial, security or personal information disclosed by one party to another.

2.9 “Customer” or “Client Institution”

Means the organisation, employer, hospital, educational institution, church, government agency, business, association, non-governmental organisation or other entity that subscribes to or authorises use of the platform.

2.10 “Customer Data”

Means information, files, records, instructions and personal data submitted to, generated through or lawfully processed within the platform on behalf of a Customer.

2.11 “Data Controller”

Means the person or organisation that determines the purpose and manner in which personal data are processed.

2.12 “Data Processor”

Means a person or organisation that processes personal data on behalf of and under the documented instructions of a Data Controller.

2.13 “Data Subject”

Means an identified or identifiable individual to whom personal data relate.

2.14 “Device”

Means an approved biometric terminal, computer, mobile phone, tablet, server or other equipment used to access or interact with the platform.

2.15 “Documentation”

Means user guides, implementation materials, technical instructions and other materials provided by Akwaaba Solutions.

2.16 “Personal Data”

Means information relating to an identified or identifiable living individual.

2.17 “Platform” or “Service”

Means the Akwaaba Smart HRM Suite and its authorised websites, applications, modules, interfaces, APIs, databases, dashboards, devices and related services.

2.18 “Processing”

Means an operation performed on personal data, including collection, recording, organisation, storage, retrieval, consultation, use, transmission, disclosure, correction, restriction, archiving or deletion.

2.19 “Sensitive Personal Data”

Means personal data requiring heightened protection under applicable law, including biometric, medical, health, financial or other specially protected information.

2.20 “Self-Hosted Deployment”

Means a deployment in which the platform or relevant infrastructure is hosted on systems owned, controlled or commissioned by the Customer.

2.21 “Subscription”

Means the Customer’s authorised right to access specified services, modules, users, personnel records, branches or devices for an agreed period.

2.22 “Subscription Term”

Means the period for which a Customer is authorised to use the subscribed services.

2.23 “User,” “you” or “your”

Means an individual who accesses or uses the platform, including an employee, administrator, supervisor, contractor or institutional officer.


3. ACCEPTANCE AND AUTHORITY

3.1 Institutional Acceptance

A Customer accepts the institutional provisions of this document when it:

  1. signs a service or subscription agreement;
  2. accepts an approved proposal, quotation or order form;
  3. authorises implementation or onboarding;
  4. pays an applicable fee; or
  5. otherwise expressly accepts the provisions electronically or in writing.

3.2 End-User Acceptance

An individual user accepts the applicable End-User Terms when the user:

  1. selects an electronic acceptance option;
  2. signs a user acknowledgement;
  3. activates an account after being presented with the Terms; or
  4. continues to use the platform following valid notification of the applicable Terms.

3.3 Authority to Bind a Customer

A person accepting contractual provisions on behalf of a Customer represents that the person has authority to bind that Customer.

A system administrator does not automatically have authority to:

  1. amend a subscription;
  2. accept a price increase;
  3. approve a new processing purpose;
  4. execute a Data Processing Agreement;
  5. waive legal rights; or
  6. bind the Customer commercially.

Such actions may be taken only by an Authorised Representative.

3.4 Electronic Contracting

To the extent permitted by law:

  1. electronic acceptance may have the same effect as a handwritten signature;
  2. electronic records may establish the time, method and version of acceptance;
  3. notices may be delivered electronically; and
  4. system records may constitute prima facie evidence, subject to investigation, correction and contrary evidence.

3.5 Opportunity to Review

The applicable Terms shall be made reasonably accessible before or during account activation.

Users should be given an opportunity to review the Terms and correct material registration errors before completing acceptance.


4. ELIGIBILITY AND AUTHORISED ACCESS

4.1 Permitted Users

The platform may be accessed only by:

  1. Customers with a valid subscription or authorised trial;
  2. persons authorised by a Customer;
  3. Akwaaba Solutions personnel acting within assigned responsibilities; and
  4. approved service providers acting under appropriate contractual safeguards.

4.2 Institutional Control

The Customer is responsible for determining:

  1. who may access its account;
  2. which roles are assigned;
  3. which modules are available;
  4. which data each user may access;
  5. the lawful purposes for which access is granted; and
  6. when access must be suspended or terminated.

4.3 Unauthorised Access

A person must not:

  1. access an account without permission;
  2. use another person’s credentials;
  3. impersonate another user;
  4. enrol another person’s biometric data as the user’s own;
  5. bypass an authentication or approval control; or
  6. continue using the platform after authority has been withdrawn.

4.4 Children and Persons Lacking Legal Capacity

The Akwaaba Smart HRM Suite is primarily designed for workforce and institutional administration.

It is not intended for independent use by children.

Where a separately authorised solution processes children’s data, the relevant Customer must:

  1. establish a lawful basis;
  2. obtain any required parental, guardian or institutional authorisation;
  3. provide an appropriate privacy notice;
  4. restrict access appropriately; and
  5. implement safeguards proportionate to the age and vulnerability of the individuals concerned.

PART II

PLATFORM SERVICES AND CUSTOMER OBLIGATIONS

5. SCOPE OF THE SERVICES

5.1 Platform Functions

Depending on the Customer’s subscription, the platform may provide:

  1. personnel and employee database management;
  2. attendance and time management;
  3. facial, fingerprint or other approved identity authentication;
  4. duty rosters and work schedules;
  5. leave, absence and excuse-duty administration;
  6. employee self-service functions;
  7. event and visitor management;
  8. birthday and institutional notifications;
  9. bulk SMS, email, voice or other approved communications;
  10. productivity and work-item tracking;
  11. executive dashboards and reports;
  12. customer- or service-management functions;
  13. fees, dues or accounting-support functions;
  14. mobile, web, USSD or administrative clocking;
  15. multi-branch administration;
  16. integrations with approved third-party systems; and
  17. other modules introduced or agreed in writing.

5.2 Subscription Limits

The Customer may access only:

  1. the modules included in its subscription;
  2. the approved number of users, staff records, devices or branches;
  3. the agreed hosting model;
  4. the selected support package; and
  5. additional services expressly agreed in writing.

5.3 Optional Modules

Optional modules are not activated merely because they appear within the platform.

Activation may require:

  1. written authorisation;
  2. additional configuration;
  3. payment of applicable fees;
  4. a privacy assessment; or
  5. acceptance of supplementary terms.

5.4 Product Changes

Akwaaba Solutions may:

  1. improve or update features;
  2. modify workflows or interfaces;
  3. replace unsupported technologies;
  4. introduce new functionality;
  5. withdraw insecure or obsolete features;
  6. impose reasonable technical limits; or
  7. take measures necessary to protect the platform.

Akwaaba Solutions shall use reasonable efforts not to materially reduce essential paid functionality during an active Subscription Term without reasonable justification.

5.5 Trial and Preview Services

A trial, beta, preview or experimental feature may:

  1. be incomplete;
  2. contain errors;
  3. be changed or withdrawn;
  4. have limited support; and
  5. be unsuitable for critical institutional decisions.

Unless expressly agreed otherwise, trial and preview services are provided without a service-level commitment.

5.6 Third-Party Dependencies

Certain functions may depend on third-party services, including telecommunications networks, internet providers, cloud infrastructure, email gateways, SMS providers, payment services, mapping services and operating-system providers.

Akwaaba Solutions is not responsible for interruptions caused solely by systems outside its reasonable control, but shall use reasonable efforts to manage supported integrations and communicate material service issues.


6. CUSTOMER TRUST COMMITMENTS

6.1 Customer Control

As between Akwaaba Solutions and the Customer, the Customer retains its rights and lawful control over Customer Data, subject to:

  1. the rights of data subjects;
  2. applicable law;
  3. lawful regulatory requirements; and
  4. the limited processing rights necessary for Akwaaba Solutions to provide the services.

6.2 No Sale of Personal Data

Akwaaba Solutions does not sell, rent or trade Customer Data or personal data processed through the platform.

6.3 No Unauthorised Advertising

Customer Data and biometric data shall not be used for third-party advertising, unrelated commercial profiling or unauthorised marketing.

6.4 Biometric Purpose Limitation

Biometric data shall be processed only for authorised purposes such as:

  1. identity verification;
  2. authentication;
  3. attendance validation;
  4. access control; and
  5. prevention of impersonation or attendance fraud.

6.5 Artificial-Intelligence Commitment

Akwaaba Solutions shall not use Customer Data, personnel records or biometric data to train general-purpose artificial-intelligence models without:

  1. the Customer’s express written authorisation;
  2. an appropriate lawful basis;
  3. a documented assessment of the processing; and
  4. appropriate safeguards for affected individuals.

6.6 Privacy by Design and by Default

Akwaaba Solutions seeks to embed privacy and security into the platform by:

  1. limiting collection to relevant data;
  2. restricting access according to role;
  3. protecting data transmissions;
  4. applying enhanced authentication where appropriate;
  5. logging privileged activity;
  6. limiting administrative access;
  7. disabling unnecessary functions until authorised; and
  8. assessing material new processing activities.

6.7 Controlled Support Access

Akwaaba Solutions personnel may access Customer Data only where access is:

  1. necessary to provide authorised support;
  2. required for security, maintenance or incident response;
  3. permitted under an agreement;
  4. authorised by the Customer; or
  5. required by law.

Where reasonably practicable, privileged support access shall be:

  1. assigned to identified personnel;
  2. limited to necessary information;
  3. time-bound;
  4. logged;
  5. protected by confidentiality obligations; and
  6. withdrawn when the support activity ends.

Emergency access may be used to contain an imminent security threat, provided the access is documented and reviewed afterwards.


7. CUSTOMER RESPONSIBILITIES

7.1 Lawful Use

The Customer shall use the platform in accordance with:

  1. applicable data-protection requirements;
  2. employment and labour obligations;
  3. sector-specific requirements;
  4. the Customer’s internal policies;
  5. contractual obligations; and
  6. these Terms.

7.2 Data-Protection Registration

Each party is responsible for obtaining and maintaining any registration, renewal, approval or authorisation required for its processing activities.

The Customer must not instruct Akwaaba Solutions to conduct processing that the Customer is not lawfully entitled to undertake.

7.3 Lawful Basis and Transparency

Where the Customer determines why and how workforce or institutional data are processed, the Customer is ordinarily the Data Controller.

The Customer is responsible for:

  1. identifying and documenting an appropriate lawful basis;
  2. informing affected persons about the processing;
  3. issuing appropriate privacy notices;
  4. determining whether consent is legally appropriate;
  5. documenting consent where relied upon;
  6. assessing necessity and proportionality;
  7. responding to complaints and rights requests; and
  8. ensuring that instructions given to Akwaaba Solutions are lawful.

7.4 Employment-Related Consent

The Customer must not assume that consent is automatically valid merely because an employee has signed a form.

Where consent is relied upon, the Customer must assess whether it is:

  1. freely given;
  2. specific;
  3. informed;
  4. unambiguous;
  5. capable of withdrawal; and
  6. appropriate in the circumstances of the employment relationship.

7.5 Data Accuracy

The Customer must take reasonable steps to ensure that Customer Data are:

  1. accurate;
  2. complete;
  3. current;
  4. relevant;
  5. not misleading; and
  6. corrected when an error is identified.

Akwaaba Solutions is not responsible for decisions based on inaccurate information supplied or maintained by the Customer, except to the extent that the inaccuracy results directly from a failure of the platform for which Akwaaba Solutions is responsible.

7.6 User Access Management

The Customer must:

  1. appoint appropriate administrators;
  2. assign roles according to responsibilities;
  3. apply least-privilege access;
  4. review access periodically;
  5. disable access after termination or transfer;
  6. prevent account sharing;
  7. protect administrative credentials; and
  8. report suspected compromise promptly.

7.7 Employment and Management Decisions

The Customer remains responsible for employment, disciplinary, payroll, performance and management decisions.

Before taking adverse action based on platform records, the Customer should consider:

  1. approved leave;
  2. excuse duty;
  3. authorised off-site work;
  4. roster errors;
  5. device or network failure;
  6. delayed synchronisation;
  7. account compromise;
  8. pending correction requests;
  9. relevant supporting evidence; and
  10. the affected employee’s explanation.

Platform reports and alerts are decision-support tools and should not replace fair investigation or applicable due process.

7.8 Customer Infrastructure

For self-hosted or Customer-controlled environments, the Customer is responsible for:

  1. server and physical security;
  2. operating-system maintenance;
  3. network and firewall protection;
  4. server-level access;
  5. backup infrastructure;
  6. power and environmental protection;
  7. Customer-appointed third parties; and
  8. compliance with agreed technical requirements.

7.9 Prohibited Instructions

The Customer shall not instruct Akwaaba Solutions to:

  1. process data unlawfully;
  2. conceal processing from affected individuals;
  3. use biometric information for unrelated surveillance;
  4. disclose data without authority;
  5. retain data indefinitely without justification;
  6. bypass security safeguards; or
  7. act contrary to applicable law.

Akwaaba Solutions may refuse or suspend an instruction that it reasonably believes is unlawful, insecure or inconsistent with the applicable agreement.


PART III

USER ACCOUNTS AND ACCEPTABLE USE

8. USER ACCOUNTS

8.1 Account Creation

Users must provide accurate information when an account is created or activated.

The Customer or Akwaaba Solutions may require:

  1. identity verification;
  2. employee identification;
  3. a valid telephone number or email address;
  4. assignment to an approved institution, branch or department;
  5. biometric enrolment where authorised; and
  6. additional security information.

8.2 Individual Use

Each account is intended for use by the person to whom it is assigned.

A user must not:

  1. share passwords, PINs or verification codes;
  2. allow another person to clock in or out through the user’s account;
  3. share biometric access;
  4. leave an authenticated device unattended;
  5. use another person’s account; or
  6. permit unauthorised access.

8.3 Password and Authentication Security

Users must:

  1. create strong passwords where permitted;
  2. protect credentials;
  3. use multi-factor authentication where enabled;
  4. protect registered email accounts and devices;
  5. change compromised credentials promptly; and
  6. comply with reasonable security instructions.

8.4 Account Activity

Activity recorded through an account may be attributed to the account holder unless:

  1. unauthorised access is promptly reported;
  2. credible evidence indicates compromise; or
  3. investigation establishes that another person was responsible.

A user remains entitled to challenge an inaccurate record.

8.5 Account Categories

The Customer may designate separate roles, including:

  1. Account Owner;
  2. Authorised Representative;
  3. System Administrator;
  4. Billing Administrator;
  5. Human Resource Administrator;
  6. Data-Protection Contact;
  7. Supervisor; and
  8. General User.

Access granted to one role does not confer the authority assigned to another role.

8.6 Suspension for Security Reasons

Akwaaba Solutions or the Customer may temporarily restrict an account where reasonably necessary to:

  1. investigate suspicious activity;
  2. protect personal data;
  3. prevent unauthorised access;
  4. contain a security incident;
  5. enforce these Terms;
  6. comply with law; or
  7. protect the platform and its users.

9. ACCEPTABLE USE POLICY

9.1 Permitted Use

The platform may be used only:

  1. for legitimate institutional purposes;
  2. within the user’s authorised role;
  3. in accordance with applicable institutional policies;
  4. in compliance with law; and
  5. in a manner that does not compromise the platform or the rights of others.

9.2 Prohibited Conduct

A Customer or user must not:

  1. access information beyond assigned authority;
  2. impersonate another person;
  3. falsify attendance, leave, productivity or personnel records;
  4. clock in or clock out for another person;
  5. enrol false or substituted biometric data;
  6. interfere with an attendance device;
  7. disable or bypass authentication controls;
  8. introduce malware or harmful code;
  9. conduct unauthorised vulnerability testing;
  10. reverse engineer the platform except where permitted by law;
  11. copy, resell or sublicense the platform without approval;
  12. scrape or extract data by unauthorised automated means;
  13. access the platform to develop an unauthorised competing product;
  14. upload unlawful, defamatory, fraudulent or infringing content;
  15. send deceptive, abusive or unauthorised communications;
  16. sell or monetise personal data;
  17. modify records to conceal misconduct;
  18. disable audit logs or security safeguards;
  19. use the platform for covert or unlawful surveillance;
  20. use biometric data for an unrelated purpose;
  21. overload, damage or disrupt the platform; or
  22. assist another person to engage in prohibited conduct.

9.3 Communications

Customers using SMS, email, voice or other communication functions must ensure that:

  1. recipients are lawfully contacted;
  2. messages serve legitimate institutional purposes;
  3. recipient information is accurate;
  4. required permissions have been obtained;
  5. opt-out rights are respected where applicable;
  6. confidential information is not unnecessarily disclosed; and
  7. communications are not unlawful, abusive or misleading.

9.4 Location-Enabled Attendance

Where location-enabled attendance is activated, the platform may process, depending on configuration:

  1. a location captured at the time of clocking;
  2. GPS coordinates;
  3. confirmation that the user is within an approved geofence;
  4. the device’s network or internet-protocol information; or
  5. other location indicators disclosed to the user.

Location processing shall be limited to authorised purposes.

Continuous background tracking shall not be enabled unless it is separately justified, authorised, disclosed and lawfully configured.

A user must not falsify, manipulate or conceal relevant location information.


10. REPORTING MISUSE AND SECURITY INCIDENTS

10.1 User Reporting Obligations

Users and Customers must promptly report:

  1. unauthorised access;
  2. lost or stolen access devices;
  3. suspicious account activity;
  4. phishing attempts;
  5. incorrect biometric association;
  6. accidental data disclosure;
  7. compromised equipment;
  8. malware; or
  9. suspected security incidents.

10.2 Reporting Channels

Reports may be submitted to:

  1. the Customer’s authorised administrator;
  2. the Customer’s Human Resource or management office;
  3. the Customer’s Data Protection Officer;
  4. Akwaaba Solutions’ support channel; or
  5. Akwaaba Solutions’ privacy contact.

10.3 No Retaliation for Good-Faith Reporting

A person should not be penalised by Akwaaba Solutions for making a good-faith report of a suspected security or privacy incident.

This provision does not prevent action against a person who knowingly makes a false or malicious report.


PART IV

BIOMETRIC DATA AND ATTENDANCE RECORDS

11. BIOMETRIC PROCESSING

11.1 Nature of Biometric Data

The platform may support fingerprint, facial-recognition or other approved biometric authentication.

Biometric data require heightened protection because they relate to characteristics that may uniquely identify an individual.

11.2 Permitted Purposes

Biometric data may be processed only for authorised purposes, including:

  1. identity verification;
  2. attendance validation;
  3. access control;
  4. prevention of impersonation; and
  5. another compatible purpose clearly disclosed to the affected person.

11.3 Necessity and Proportionality

Before activating biometric processing, the Customer should assess:

  1. whether the processing is necessary;
  2. whether the purpose could reasonably be achieved through a less intrusive method;
  3. the effect on affected individuals;
  4. the applicable lawful basis;
  5. the proposed retention period;
  6. the safeguards available;
  7. whether an alternative method is required; and
  8. whether a Data Protection Impact Assessment is appropriate.

11.4 Biometric Enrolment

Biometric enrolment must:

  1. be carried out by authorised personnel;
  2. be linked to the correct person;
  3. use an approved device or process;
  4. be limited to necessary information;
  5. be protected from unauthorised access;
  6. be appropriately documented; and
  7. not occur secretly.

11.5 Categories of Biometric Information

Depending on the approved technology, the platform may process:

  1. fingerprint templates;
  2. facial-recognition templates;
  3. enrolment photographs;
  4. device identifiers;
  5. authentication results; and
  6. attendance timestamps.

11.6 Biometric Security

Appropriate safeguards may include:

  1. encrypted transmission;
  2. restricted administrative access;
  3. role-based access controls;
  4. enhanced authentication;
  5. protected server infrastructure;
  6. audit logging;
  7. controlled device configuration;
  8. backup safeguards; and
  9. secure deletion or deactivation.

The applicable safeguards may vary according to the deployment model, device capability and Customer infrastructure.

11.7 Accuracy Limitations

Biometric technology may occasionally produce:

  1. unsuccessful matches;
  2. false rejections;
  3. incorrect associations;
  4. poor-quality captures;
  5. failures caused by lighting or device condition;
  6. connectivity-related delays; or
  7. other technical errors.

Biometric results must not be treated as infallible or conclusive evidence without appropriate review.

11.8 Alternative Authentication

Where required by law, reasonable accommodation or institutional policy, the Customer should provide an appropriate alternative for an individual who cannot reliably use the selected biometric method.

11.9 Prohibited Biometric Uses

Biometric information must not be:

  1. sold;
  2. used for advertising;
  3. used for unrelated profiling;
  4. used for covert surveillance;
  5. disclosed without authority;
  6. copied to unauthorised devices;
  7. retained indefinitely without justification; or
  8. used to train a general-purpose artificial-intelligence model without express authorisation and a lawful basis.

11.10 Biometric Incidents

Where a suspected incident affects biometric data, Akwaaba Solutions and the Customer shall, according to their respective responsibilities:

  1. restrict access to affected records;
  2. disable the affected authentication method where necessary;
  3. provide an alternative authentication method where appropriate;
  4. assess whether templates or related data were exposed;
  5. investigate relevant devices, servers and logs;
  6. prevent further unauthorised use;
  7. determine notification obligations; and
  8. document the incident and remedial action.

12. ATTENDANCE RECORDS AND CORRECTIONS

12.1 Nature of Attendance Records

Attendance records may include:

  1. clock-in and clock-out times;
  2. work dates;
  3. assigned shifts or rosters;
  4. authentication method;
  5. clocking location;
  6. approved leave or absence;
  7. lateness;
  8. early departure;
  9. missed clock-out records;
  10. manual corrections; and
  11. relevant audit history.

12.2 Records as Evidence

System records may constitute prima facie evidence of recorded activity but are not necessarily conclusive.

Records may require review where affected by:

  1. incorrect device time;
  2. failed synchronisation;
  3. network interruption;
  4. account compromise;
  5. roster errors;
  6. authorised off-site duties;
  7. administrative changes; or
  8. other credible contrary evidence.

12.3 Correction Requests

A user may request correction of an attendance or personnel record through an approved institutional channel.

The request should identify:

  1. the disputed record;
  2. the reason for the correction;
  3. available supporting evidence; and
  4. any relevant supervisor or departmental confirmation.

12.4 Customer Review

The Customer is responsible for determining correction requests, subject to its policies and applicable law.

Where appropriate, the Customer should:

  1. acknowledge the request;
  2. investigate the facts;
  3. consider supporting evidence;
  4. communicate the outcome;
  5. permit escalation; and
  6. complete the review within a reasonable period.

12.5 Audit History

Where technically supported, a corrected record may retain an audit history showing:

  1. the original entry;
  2. the correction;
  3. the date of correction;
  4. the person who approved it; and
  5. the stated reason.

12.6 Payroll Deadlines

A pending correction request does not automatically require Akwaaba Solutions to delay the Customer’s payroll or reporting process.

The Customer remains responsible for determining how unresolved records are treated in accordance with applicable law and institutional policy.


PART V

PRIVACY AND DATA PROTECTION

13. PRIVACY COMMITMENT

Akwaaba Solutions is committed to processing personal data:

  1. lawfully;
  2. fairly;
  3. transparently;
  4. for specified purposes;
  5. in a manner compatible with those purposes;
  6. accurately;
  7. securely;
  8. only for as long as necessary; and
  9. with due regard to the rights of data subjects.

14. DATA-CONTROLLER AND DATA-PROCESSOR ROLES

14.1 Customer as Data Controller

The Customer is ordinarily the Data Controller where it determines:

  1. which employees or individuals are enrolled;
  2. why attendance information is collected;
  3. which modules are activated;
  4. how long institutional records are retained;
  5. which administrators have access; and
  6. how records are used for management, payroll or disciplinary purposes.

14.2 Akwaaba Solutions as Data Processor

Where Akwaaba Solutions processes Customer Data on behalf of a Customer, it shall:

  1. act on documented lawful instructions;
  2. apply appropriate safeguards;
  3. limit personnel access;
  4. assist with data-subject requests where reasonably required;
  5. support incident response;
  6. manage approved subprocessors appropriately; and
  7. return or delete data in accordance with the applicable agreement.

14.3 Akwaaba Solutions as Data Controller

Akwaaba Solutions may act as Data Controller for information it independently determines how and why to process, including:

  1. customer-contact information;
  2. account-administration records;
  3. billing and payment records;
  4. website enquiries;
  5. support correspondence;
  6. security and fraud-prevention records;
  7. contractual records;
  8. authorised marketing preferences; and
  9. legal and regulatory records.

14.4 Joint or Separate Responsibilities

Where the parties independently determine different purposes for processing the same information, each party remains responsible for its own processing.

A party does not become a joint controller merely because it provides technical assistance to another party.


15. PERSONAL DATA THAT MAY BE COLLECTED

Depending on the activated modules and Customer instructions, the platform may process:

15.1 Identification Information

  1. full name;
  2. employee or membership number;
  3. photograph;
  4. date of birth;
  5. gender, where lawfully required;
  6. job title;
  7. department;
  8. branch or work location; and
  9. employment status.

15.2 Contact Information

  1. telephone number;
  2. email address;
  3. postal or residential information, where authorised;
  4. emergency-contact information; and
  5. institutional contact details.

15.3 Employment and Administrative Information

  1. employment date;
  2. staff category;
  3. supervisor;
  4. duty roster;
  5. leave information;
  6. absence and excuse-duty records;
  7. productivity information;
  8. training records;
  9. disciplinary or administrative references, where authorised; and
  10. payroll-supporting attendance information.

15.4 Attendance and Device Information

  1. clock-in and clock-out records;
  2. dates and times;
  3. location at the time of clocking;
  4. device identifiers;
  5. internet-protocol addresses;
  6. login history;
  7. browser or application information;
  8. authentication records; and
  9. system audit logs.

15.5 Biometric Information

  1. fingerprint templates;
  2. facial-recognition templates;
  3. approved enrolment images;
  4. authentication results; and
  5. related biometric identifiers.

15.6 Communication Information

  1. SMS records;
  2. email records;
  3. notification-delivery information;
  4. voice-notification records;
  5. complaint records;
  6. support messages; and
  7. communication preferences.

15.7 Billing and Contract Information

  1. Customer representative details;
  2. invoices;
  3. payment references;
  4. subscription records;
  5. contract history; and
  6. tax-related information.

Akwaaba Solutions does not ordinarily require complete payment-card credentials where payment is processed by an authorised payment-service provider.


16. SOURCES OF PERSONAL DATA

Personal data may be obtained from:

  1. the data subject;
  2. the Customer;
  3. authorised administrators;
  4. biometric or attendance devices;
  5. mobile or web applications;
  6. approved integrations;
  7. communications with Akwaaba Solutions;
  8. platform-generated logs; and
  9. lawful third-party sources.

The Customer must not upload personal data obtained unlawfully.


17. PURPOSES OF PROCESSING

Personal data may be processed to:

  1. create and manage user accounts;
  2. maintain employee or institutional records;
  3. authenticate identity;
  4. record and validate attendance;
  5. manage rosters, leave and absence;
  6. support payroll verification;
  7. generate institutional reports;
  8. facilitate authorised communication;
  9. provide customer support;
  10. maintain service security;
  11. detect fraud or unauthorised access;
  12. troubleshoot technical problems;
  13. manage subscriptions and billing;
  14. improve authorised platform functionality;
  15. maintain audit and compliance records;
  16. comply with legal obligations;
  17. establish, exercise or defend legal claims; and
  18. perform another compatible and lawfully authorised purpose.

Personal data shall not be used for a materially incompatible purpose without an appropriate lawful basis and required notice or authorisation.


18. LAWFUL GROUNDS FOR PROCESSING

Depending on the circumstances, processing may be based on:

  1. performance of a contract;
  2. compliance with a legal obligation;
  3. legitimate institutional or business interests that do not unjustifiably override individual rights;
  4. consent, where consent is legally appropriate;
  5. protection of the vital interests of an individual;
  6. performance of a function authorised by law; or
  7. another lawful ground recognised under applicable law.

The Customer is responsible for establishing the lawful basis for processing that it determines.


19. DATA MINIMISATION AND ACCURACY

19.1 Data Minimisation

Only personal data reasonably necessary for authorised purposes should be collected.

Optional modules should not be activated without a legitimate need and appropriate authorisation.

19.2 Data Accuracy

Akwaaba Solutions and the Customer shall take reasonable steps, according to their respective responsibilities, to ensure that personal data are accurate, complete and current.

19.3 Unnecessary Information

Users must not upload unnecessary sensitive information into open-text fields, support messages or communication modules.


20. COOKIES AND ONLINE TECHNOLOGIES

20.1 Cookies

Akwaaba Solutions’ websites and web applications may use cookies or similar technologies to:

  1. maintain authenticated sessions;
  2. remember user preferences;
  3. protect account security;
  4. understand platform performance;
  5. diagnose errors; and
  6. improve user experience.

20.2 Essential Cookies

Essential cookies may be required for the platform to operate securely and cannot always be disabled without affecting functionality.

20.3 Analytics

Where analytics tools are used, Akwaaba Solutions shall seek to limit collection to information reasonably necessary to understand system performance and usage.

20.4 Cookie Choices

Where required, users shall be given appropriate information or choices concerning non-essential cookies.

A separate Cookie Notice may provide additional details.


21. ARTIFICIAL INTELLIGENCE AND AUTOMATED ANALYTICS

21.1 Decision-Support Functions

The platform may provide automated calculations, summaries, alerts, rankings or analytics.

These functions are intended to support human review and should not be treated as unquestionable conclusions.

21.2 Human Review

Where a result may materially affect an individual, the Customer should ensure appropriate human review before taking adverse action.

21.3 AI Training Restriction

Customer Data shall not be used to train a general-purpose AI model without express written authorisation and a lawful basis.

21.4 New AI Functions

Before introducing a material AI function involving personal data, Akwaaba Solutions may:

  1. assess privacy and security risks;
  2. define the permitted purpose;
  3. restrict access;
  4. provide relevant notices;
  5. test for material inaccuracies; and
  6. require supplementary terms.

22. DATA SHARING AND DISCLOSURE

Personal data may be disclosed only:

  1. to authorised Customer personnel;
  2. to Akwaaba Solutions personnel who require access;
  3. to approved service providers;
  4. to professional advisers subject to confidentiality;
  5. where necessary to provide an authorised integration;
  6. where required by law, court order or regulatory authority;
  7. to protect rights, security or property; or
  8. with appropriate authorisation.

Akwaaba Solutions does not sell personal data.


23. THIRD-PARTY SERVICE PROVIDERS

23.1 Approved Providers

Akwaaba Solutions may engage providers for:

  1. hosting;
  2. communications;
  3. software infrastructure;
  4. security monitoring;
  5. customer support;
  6. payment processing; and
  7. other operational services.

23.2 Safeguards

Where a provider processes personal data, Akwaaba Solutions shall seek to ensure appropriate provisions concerning:

  1. confidentiality;
  2. purpose limitation;
  3. security;
  4. incident reporting;
  5. access limitation;
  6. deletion or return of data; and
  7. restrictions on unauthorised onward processing.

23.3 Customer-Appointed Providers

The Customer is responsible for providers selected, instructed or controlled directly by the Customer.


24. CROSS-BORDER PROCESSING

Personal data shall not be transferred outside Ghana unless:

  1. the transfer is lawful;
  2. the Customer has authorised the transfer where required;
  3. appropriate contractual or technical safeguards are in place;
  4. the recipient is subject to an adequate level of protection or equivalent obligations; and
  5. affected persons are informed where required.

Where reasonably practicable, preference may be given to Ghana-based or Customer-controlled hosting arrangements.


25. INFORMATION SECURITY

25.1 Security Measures

Akwaaba Solutions shall maintain technical and organisational safeguards appropriate to:

  1. the nature of the information;
  2. the sensitivity of the data;
  3. the risks involved;
  4. the deployment model; and
  5. available technology.

Safeguards may include:

  1. encryption in transit;
  2. access controls;
  3. enhanced authentication;
  4. logging and monitoring;
  5. secure configuration;
  6. firewall protection;
  7. backup and recovery;
  8. vulnerability and patch management;
  9. personnel confidentiality; and
  10. incident-response procedures.

25.2 No Absolute Security Guarantee

No technology system is completely immune from error, interruption or unauthorised attack.

Akwaaba Solutions does not guarantee absolute security but shall take reasonable and appropriate measures to protect personal data and respond to incidents.

25.3 Customer Security Responsibilities

The Customer must protect:

  1. Customer-controlled devices;
  2. administrative credentials;
  3. networks;
  4. physical access points;
  5. self-hosted infrastructure;
  6. exported reports; and
  7. data downloaded outside the platform.

26. PERSONAL-DATA BREACHES

26.1 Incident Response

Where a personal-data breach is suspected, Akwaaba Solutions may:

  1. identify affected systems;
  2. contain the incident;
  3. assess the nature and scope;
  4. evaluate potential harm;
  5. preserve relevant evidence;
  6. implement remediation;
  7. communicate with the Customer; and
  8. support applicable notification obligations.

26.2 Processor Notification

Where Akwaaba Solutions acts as Data Processor, it shall notify the affected Customer without undue delay after confirming or reasonably suspecting a material breach affecting Customer Data.

26.3 Controller Notification

Where Akwaaba Solutions acts as Data Controller, it shall assess whether notification to affected individuals or a competent authority is required.

26.4 Customer Cooperation

The Customer shall provide timely information and cooperation reasonably required to investigate and respond to an incident.

26.5 Confidentiality of Investigations

Information relating to an active security investigation may be restricted to persons who require access, subject to legal disclosure obligations.


27. DATA RETENTION

27.1 General Principle

Personal data shall not be retained for longer than necessary for the purpose for which they were collected, subject to legal, contractual, audit and security requirements.

27.2 Customer-Controlled Retention

The Customer ordinarily determines retention periods for:

  1. employee records;
  2. attendance data;
  3. leave and roster information;
  4. biometric records;
  5. institutional communications; and
  6. Customer-generated reports.

27.3 Akwaaba-Controlled Retention

Akwaaba Solutions may retain its own controller records for periods reasonably necessary to:

  1. administer contracts;
  2. manage billing;
  3. provide support;
  4. maintain security;
  5. comply with law;
  6. manage disputes; and
  7. protect legitimate business interests.

27.4 Biometric Retention

Biometric data should be deleted, deactivated or rendered inaccessible when:

  1. the authorised purpose ends;
  2. the individual’s employment or relationship ends and no lawful basis remains;
  3. the Customer terminates the relevant service;
  4. an approved deletion request is implemented; or
  5. the applicable retention period expires.

27.5 Backups

Deleted information may remain temporarily within protected backups until the applicable backup cycle expires.

Backup data shall not ordinarily be restored for active use except for disaster recovery, security or legal requirements.


28. DATA RETURN AND DELETION

28.1 During the Subscription

The Customer may request an export of available Customer Data, subject to:

  1. the Customer’s subscription;
  2. technical feasibility;
  3. security verification;
  4. applicable fees for exceptional work; and
  5. rights of third parties.

28.2 Upon Termination

Following termination, Akwaaba Solutions may:

  1. provide a reasonable period for authorised export;
  2. restrict further platform access;
  3. delete or return Customer Data according to the agreement; and
  4. retain only information required by law or legitimate legal necessity.

28.3 Secure Deletion

Deletion measures may include:

  1. removal from active databases;
  2. deactivation of biometric templates;
  3. account closure;
  4. device-level deletion;
  5. secure media wiping; and
  6. expiration through backup cycles.

29. DATA-SUBJECT RIGHTS

Subject to applicable law, a data subject may have the right to:

  1. be informed about processing;
  2. request access to personal data;
  3. request correction of inaccurate data;
  4. object to certain processing;
  5. request prevention of processing causing unjustified damage or distress;
  6. request deletion where legally applicable;
  7. withdraw consent where processing depends on consent; and
  8. lodge a complaint with the appropriate authority.

29.1 Requests Relating to Customer Data

Where Akwaaba Solutions acts as Data Processor, requests should ordinarily be directed to the Customer.

Akwaaba Solutions may refer a request to the relevant Customer and assist the Customer where reasonably required.

29.2 Requests Relating to Akwaaba-Controlled Data

Requests concerning data for which Akwaaba Solutions is the Data Controller may be submitted through the privacy contact in Section 42.

29.3 Identity Verification

Before disclosing or changing personal data, identity may be verified to prevent unauthorised access.

29.4 Limitations

A request may be limited or refused where:

  1. identity cannot be verified;
  2. disclosure would adversely affect another person’s rights;
  3. retention is required by law;
  4. the request is legally exempt; or
  5. another lawful ground justifies refusal.

Reasons shall be provided where required.


30. DATA PROTECTION IMPACT ASSESSMENTS

A Data Protection Impact Assessment should be considered where proposed processing is likely to create significant privacy risks, including:

  1. large-scale biometric processing;
  2. new biometric modalities;
  3. systematic monitoring;
  4. continuous location tracking;
  5. materially new AI processing;
  6. large-scale sensitive-data processing;
  7. cross-border processing; or
  8. material integration with external systems.

The Customer remains responsible for assessments relating to processing purposes determined by the Customer. Akwaaba Solutions may provide relevant technical assistance.


31. SELF-HOSTED DEPLOYMENTS

31.1 Customer Control

In a self-hosted deployment, the Customer ordinarily controls:

  1. server infrastructure;
  2. physical hosting;
  3. server-level administrators;
  4. network configuration;
  5. backups; and
  6. infrastructure access.

31.2 Akwaaba Solutions’ Role

Akwaaba Solutions shall provide support within the scope of the applicable agreement and documented Customer instructions.

31.3 Allocation of Risk

The Customer is responsible for risks arising from:

  1. Customer infrastructure;
  2. unsupported configuration;
  3. unauthorised Customer personnel;
  4. Customer-selected hosting providers;
  5. failure to apply agreed updates; and
  6. inadequate Customer backups.

Akwaaba Solutions remains responsible for its own personnel, software obligations and actions within its control.

31.4 Support Access

Server access provided to Akwaaba Solutions must be:

  1. authorised;
  2. limited;
  3. appropriately secured;
  4. withdrawn when no longer needed; and
  5. logged where reasonably practicable.

PART VI

COMMERCIAL TERMS

32. SUBSCRIPTIONS, FEES AND PAYMENT

32.1 Subscription Fees

The Customer shall pay the fees stated in the applicable quotation, order form or service agreement.

32.2 Taxes

Unless expressly stated otherwise, fees are exclusive of applicable taxes, levies, duties and statutory charges.

32.3 Invoicing

Invoices shall be issued according to the agreed billing schedule.

32.4 Payment Due Dates

Payments must be made by the due date stated on the invoice or agreement.

32.5 Late Payment

Where payment is overdue, Akwaaba Solutions may:

  1. issue a payment reminder;
  2. restrict non-essential services;
  3. suspend access after reasonable notice;
  4. charge an agreed late-payment amount where lawful; or
  5. exercise contractual recovery rights.

32.6 Fee Changes

Akwaaba Solutions may revise fees for a future Subscription Term.

Unless otherwise agreed, a fee change shall not retrospectively alter fees already paid for an active prepaid term.

32.7 Renewals

A subscription may renew:

  1. automatically, where expressly agreed; or
  2. upon acceptance of a renewal quotation or invoice.

The applicable agreement shall determine the renewal procedure.

32.8 Refunds

Fees are non-refundable except where:

  1. the agreement expressly permits a refund;
  2. Akwaaba Solutions agrees in writing;
  3. the service cannot be provided due to Akwaaba Solutions’ material breach; or
  4. applicable law requires a refund.

32.9 Third-Party Charges

The Customer is responsible for separately identified telecommunications, SMS, email, payment-provider or other third-party usage charges unless the applicable package expressly includes them.


33. IMPLEMENTATION, TRAINING AND SUPPORT

33.1 Implementation

The Customer shall provide accurate information, authorised personnel and reasonable cooperation required for implementation.

33.2 Training

Training shall be provided according to the agreed package.

The Customer is responsible for ensuring that relevant personnel attend training and comply with operating instructions.

33.3 Support

Support may include:

  1. incident logging;
  2. troubleshooting;
  3. configuration guidance;
  4. remote assistance;
  5. agreed on-site support; and
  6. software updates.

33.4 Excluded Support

Unless otherwise agreed, support does not include:

  1. Customer internet service;
  2. repair of unrelated hardware;
  3. unsupported third-party software;
  4. unauthorised modifications;
  5. Customer-created data errors;
  6. staff training outside the agreed scope; or
  7. services resulting from misuse.

33.5 Additional Work

Custom development, data correction, migration, on-site work or services outside the subscription may attract additional fees.


34. SERVICE AVAILABILITY AND MAINTENANCE

34.1 Reasonable Availability

Akwaaba Solutions shall use reasonable efforts to maintain service availability, subject to:

  1. planned maintenance;
  2. emergency maintenance;
  3. third-party service interruptions;
  4. internet or telecommunications failure;
  5. Customer infrastructure failure;
  6. security incidents;
  7. force majeure; and
  8. other circumstances outside reasonable control.

34.2 Planned Maintenance

Where practicable, material planned maintenance shall be scheduled to minimise disruption and communicated through an appropriate channel.

34.3 Emergency Maintenance

Emergency maintenance may be performed without prior notice where necessary to protect security, integrity or service continuity.

34.4 Offline and Delayed Synchronisation

Where offline functionality is available, records may synchronise when connectivity is restored.

Delayed synchronisation may affect the time at which information becomes visible in reports.

34.5 Service Levels

Any guaranteed availability, response or restoration commitment applies only where stated in a signed Service-Level Agreement.


35. INTELLECTUAL PROPERTY

35.1 Akwaaba Solutions’ Rights

Akwaaba Solutions and its licensors retain all rights in:

  1. the platform;
  2. software;
  3. source code;
  4. databases and structures;
  5. designs;
  6. trademarks;
  7. documentation;
  8. workflows;
  9. reports and templates developed by Akwaaba Solutions; and
  10. improvements and derivative works.

35.2 Customer Licence

During an active subscription, the Customer receives a limited, non-exclusive, non-transferable and revocable right to use the subscribed services for authorised internal purposes.

35.3 Customer Data

The Customer retains its rights and lawful control over Customer Data, subject to data-subject rights and applicable law.

35.4 Feedback

Where the Customer voluntarily provides suggestions, Akwaaba Solutions may use them to improve the platform without disclosing the Customer’s Confidential Information.

35.5 Restrictions

The Customer shall not:

  1. reproduce the platform beyond authorised use;
  2. remove proprietary notices;
  3. create an unauthorised derivative product;
  4. resell access;
  5. disclose source code;
  6. circumvent licensing controls; or
  7. use Akwaaba Solutions’ trademarks without permission.

36. CONFIDENTIALITY

36.1 Confidentiality Obligation

Each party shall:

  1. protect the other party’s Confidential Information;
  2. use it only for the agreed purpose;
  3. restrict access to persons who require it;
  4. apply reasonable safeguards; and
  5. not disclose it without authority.

36.2 Exclusions

Confidential Information does not include information that:

  1. is publicly available without breach;
  2. was lawfully known before disclosure;
  3. is received lawfully from another source;
  4. is independently developed; or
  5. must be disclosed by law.

36.3 Required Disclosure

Where disclosure is legally required, the receiving party shall, where permitted:

  1. notify the other party;
  2. limit the disclosure; and
  3. cooperate with reasonable protective measures.

36.4 Continuing Obligation

Confidentiality obligations continue after termination for as long as the information remains confidential.


PART VII

SUSPENSION, TERMINATION AND LIABILITY

37. SUSPENSION

Akwaaba Solutions may suspend access where:

  1. fees remain overdue after notice;
  2. use creates a security risk;
  3. there is suspected unlawful activity;
  4. the Customer materially breaches the agreement;
  5. suspension is required by law;
  6. the Customer exceeds agreed subscription limits; or
  7. continued access could harm the platform or another person.

Where reasonably practicable, Akwaaba Solutions shall notify the Customer and provide an opportunity to remedy the issue.

Immediate suspension may occur where urgent action is required to protect security, personal data or legal compliance.


38. TERMINATION

38.1 Termination by Agreement

Either party may terminate according to the applicable agreement.

38.2 Termination for Material Breach

A party may terminate where the other party:

  1. materially breaches the agreement;
  2. fails to remedy a remediable breach within the stated period;
  3. becomes insolvent or ceases business;
  4. uses the platform unlawfully; or
  5. creates an unacceptable security or regulatory risk.

38.3 Effect of Termination

Upon termination:

  1. the Customer’s licence ends;
  2. user access may be disabled;
  3. outstanding fees become payable;
  4. Customer Data shall be handled under Section 28;
  5. each party shall return or protect Confidential Information; and
  6. provisions intended to survive termination remain effective.

38.4 Survival

Provisions concerning confidentiality, intellectual property, data protection, payment obligations, liability, dispute resolution and accrued rights survive termination where applicable.


39. WARRANTIES AND DISCLAIMERS

39.1 Authority

Each party warrants that it has authority to enter into the applicable agreement.

39.2 Service Performance

Akwaaba Solutions warrants that it shall provide the services with reasonable skill and care.

39.3 No Guarantee of Error-Free Operation

The platform is a technology service and may experience errors, interruptions, delayed synchronisation or third-party failures.

Akwaaba Solutions does not warrant that every feature will operate without interruption or error at all times.

39.4 Customer Decisions

Akwaaba Solutions does not warrant that a report, alert or automated result is sufficient by itself to justify an employment, disciplinary, payroll or legal decision.

39.5 Unauthorised Modifications

Akwaaba Solutions is not responsible for defects caused by:

  1. unauthorised modification;
  2. unsupported integrations;
  3. Customer infrastructure failure;
  4. misuse;
  5. failure to follow instructions; or
  6. third-party systems outside its control.

40. LIMITATION OF LIABILITY

40.1 Excluded Losses

To the extent permitted by law, neither party shall be liable to the other for indirect, incidental, special or consequential loss, including loss of anticipated profit, goodwill or opportunity, except where such exclusion is prohibited by law.

40.2 Liability Cap

Except for liabilities that cannot lawfully be limited, Akwaaba Solutions’ aggregate contractual liability arising from the services shall not exceed the total subscription fees paid by the Customer for the affected service during the twelve months immediately preceding the event giving rise to the claim.

40.3 Exceptions

The limitation in Section 40.2 does not apply to:

  1. fraud or fraudulent misrepresentation;
  2. wilful misconduct;
  3. liability that cannot lawfully be excluded;
  4. unauthorised use of the other party’s intellectual property;
  5. breach of confidentiality caused by deliberate misconduct; or
  6. any separate liability expressly agreed in writing.

40.4 Customer Responsibility

Akwaaba Solutions is not liable for loss arising from:

  1. unlawful Customer instructions;
  2. inaccurate Customer Data;
  3. unauthorised Customer administrators;
  4. Customer employment decisions;
  5. failure to maintain Customer infrastructure;
  6. unsupported third-party systems;
  7. compromised credentials not promptly reported; or
  8. use outside the agreed scope.

40.5 Fair Allocation

The parties acknowledge that the fees and liability provisions reflect a reasonable allocation of commercial risk.


41. INDEMNITY

41.1 Customer Indemnity

To the extent permitted by law, the Customer shall indemnify Akwaaba Solutions against third-party claims arising directly from:

  1. unlawful Customer instructions;
  2. data supplied without lawful authority;
  3. unauthorised use of the platform;
  4. Customer infringement of third-party rights;
  5. Customer misuse of biometric or location data; or
  6. Customer breach of applicable law.

41.2 Akwaaba Solutions Indemnity

Akwaaba Solutions shall defend the Customer against a third-party claim that the authorised use of the platform infringes that third party’s intellectual-property rights, subject to:

  1. prompt written notice;
  2. reasonable cooperation;
  3. Akwaaba Solutions controlling the defence; and
  4. the claim not arising from Customer modification, misuse or combination with an unsupported system.

41.3 Mitigation

The indemnified party must take reasonable steps to reduce avoidable loss.


PART VIII

LEGAL AND ADMINISTRATIVE PROVISIONS

42. COMPANY AND CONTACT INFORMATION

Before publication, the following information must be completed:

Legal Name: [Insert Registered Legal Name]
Trading Name: Akwaaba Solutions
Company or Business Registration Number: [Insert Number]
Data Protection Commission Registration Number: [Insert Valid Number]
Principal Business Address: [Insert Address]
Postal Address: [Insert Postal Address]
General Email: [Insert Email Address]
Support Email: [Insert Support Email]
Privacy Email: [Insert Privacy Email]
Telephone: [Insert Telephone Number]
Website: [Insert Official Website]

42.1 Data Protection Officer

Privacy enquiries may be addressed to:

Data Protection Officer
Akwaaba Solutions
[Insert Address]
[Insert Privacy Email]
[Insert Telephone Number]

42.2 Complaints

A person dissatisfied with the handling of a privacy matter may:

  1. contact the Data Protection Officer;
  2. use the Customer’s internal complaint process where the Customer controls the data; and
  3. lodge a complaint with the Data Protection Commission of Ghana where legally appropriate.

43. NOTICES

43.1 Permitted Methods

Notices may be delivered through:

  1. email;
  2. the platform;
  3. SMS;
  4. registered post;
  5. courier;
  6. an administrator dashboard; or
  7. another agreed channel.

43.2 Customer Contact Information

The Customer must keep its official contact information current.

A notice sent to the Customer’s last recorded official contact shall be treated as properly addressed.

43.3 Legal Notices

A formal notice of breach, termination or legal proceedings must be delivered in accordance with the applicable signed agreement.


44. CHANGES TO THIS DOCUMENT

44.1 Right to Update

Akwaaba Solutions may revise, replace or update this document at any time, including without prior individual notice, where permitted by law.

Updates may be made to reflect:

  1. legal or regulatory developments;
  2. changes to the platform;
  3. security requirements;
  4. operational improvements;
  5. new technology;
  6. new modules;
  7. third-party service changes; or
  8. corrections and clarifications.

44.2 Minor Changes

Minor, administrative, formatting, clarification or non-material changes may take effect when published without prior individual notice.

44.3 Material Changes

Where a change materially affects:

  1. paid subscription rights;
  2. fees during an active term;
  3. data-processing purposes;
  4. categories of personal data collected;
  5. material data disclosures;
  6. limitation-of-liability provisions;
  7. dispute-resolution rights; or
  8. termination rights,

Akwaaba Solutions shall, where reasonably practicable and legally required, provide notice through email, the platform, SMS or an authorised Customer representative.

44.4 Changes Requiring Consent

Where applicable law or contract requires express acceptance, renewed consent or a written amendment, the relevant change shall take effect only after the required action has occurred.

44.5 No Retrospective Effect

Unless required by law or expressly agreed, a material contractual change shall not operate retrospectively.

44.6 Publication

The current version shall be published through the official website, platform or another approved channel.

Users and Customers should review the current published version periodically.

44.7 Continued Use

Continued use after an updated version takes effect constitutes acceptance where legally valid, except where express acceptance or renewed consent is required.


45. FORCE MAJEURE

Neither party shall be liable for delay or failure caused by circumstances beyond its reasonable control, including:

  1. natural disaster;
  2. fire;
  3. flood;
  4. epidemic or public-health emergency;
  5. war or civil disturbance;
  6. government action;
  7. widespread telecommunications failure;
  8. national power failure;
  9. industrial action not confined to the affected party;
  10. cyberattack that could not reasonably have been prevented; or
  11. failure of critical third-party infrastructure.

The affected party shall take reasonable steps to reduce the disruption and resume performance.

Payment obligations already accrued are not automatically excused by force majeure.


46. ASSIGNMENT AND SUBCONTRACTING

46.1 Assignment

The Customer may not assign its subscription without Akwaaba Solutions’ prior written consent, except as part of an approved corporate restructuring or transfer agreed in writing.

46.2 Akwaaba Assignment

Akwaaba Solutions may assign the agreement as part of a merger, restructuring, sale of business or transfer to an affiliate, provided that the assignee assumes the relevant obligations.

46.3 Subcontracting

Akwaaba Solutions may use appropriately qualified subcontractors but remains responsible for contractual obligations assigned to them, subject to the applicable agreement.


47. NON-WAIVER

A failure or delay in exercising a right does not waive that right.

A waiver is effective only where clearly communicated by an authorised representative.


48. SEVERABILITY

Where a provision is found invalid or unenforceable:

  1. the remaining provisions remain effective;
  2. the invalid provision shall be limited to the minimum extent necessary; and
  3. where possible, it shall be interpreted to reflect the original lawful intention.

49. ENTIRE AGREEMENT

The applicable signed agreements, order forms, Data Processing Agreement and these Terms constitute the entire agreement concerning the subscribed services and replace prior discussions relating to the same subject.

This clause does not exclude liability for fraud or fraudulent misrepresentation.


50. GOVERNING LAW

This document and any dispute arising from it shall be governed by the laws of the Republic of Ghana.


51. DISPUTE RESOLUTION

51.1 Good-Faith Negotiation

The parties shall first attempt to resolve a dispute through good-faith negotiation between authorised representatives.

51.2 Escalation

Where the dispute remains unresolved, either party may request escalation to senior management.

51.3 Mediation

The parties may agree to refer the dispute to mediation in Ghana before commencing formal proceedings.

51.4 Court Jurisdiction

Where a dispute is not resolved, the courts of competent jurisdiction in Ghana shall have jurisdiction, unless the parties have agreed in writing to arbitration.

51.5 Urgent Relief

Nothing prevents a party from seeking urgent injunctive or protective relief where necessary to protect personal data, intellectual property, confidential information or system security.

51.6 Regulatory Complaints

Nothing in this section prevents a data subject from lodging a complaint with a competent regulatory authority.


52. LANGUAGE AND ACCESSIBILITY

52.1 Governing Language

The official version of this document is the English version.

Where a translation is provided, it is intended to improve accessibility. In the event of an inconsistency, the English version prevails to the extent permitted by law.

52.2 Accessible Format

Akwaaba Solutions may make this document available in:

  1. web format;
  2. downloadable PDF;
  3. mobile-readable format;
  4. large-print or accessible format where reasonably practicable; and
  5. a plain-language summary.

A summary does not replace the complete legal document.


53. DOCUMENT CONTROL

Document Title: Akwaaba Smart HRM Suite Terms of Service, End-User Terms, Privacy and Data Protection Policy
Version: 1.0
Classification: Public
Effective Date: [Insert Date]
Approval Date: [Insert Date]
Approved by: Executive Management
Document Owner: Akwaaba Solutions
Next Review Date: [Insert Date]
Official Publication Location: [Insert Website Address]


54. ACKNOWLEDGEMENT

By validly accepting or using the Akwaaba Smart HRM Suite, the relevant Customer or user acknowledges, according to the provisions applicable to that person, that:

  1. access is limited to authorised purposes;
  2. account credentials must be protected;
  3. attendance and personnel records must not be falsified;
  4. personal and biometric data must be processed only for lawful and disclosed purposes;
  5. platform activity may be logged for security and accountability;
  6. biometric and automated results may require human review;
  7. Customers remain responsible for employment and management decisions;
  8. personal-data rights remain subject to applicable law;
  9. commercial use is subject to the applicable subscription agreement; and
  10. this document may be updated in accordance with Section 44.

END OF DOCUMENT
:::

The document’s statutory foundation is consistent with the Data Protection Commission’s published requirements concerning transparency, data-subject rights and registration, and with Ghana’s recognition of electronic agreements. (Data Protection Commission)orate particulars in Section 42 and document-control dates must be completed and the security representations verified against the live production environment before publication.

The document below consolidates the institutional terms, end-user rules, privacy notice, biometric-data provisions and acceptable-use requirements into one publication-ready instrument. Before publication, Akwaaba Solutions should insert its registered legal name, registration numbers, physical address and official priv(Data Protection Commission)A SMART HRM SUITE

Document Classification: Public
Version: 1.0
Effective Date: [Insert Effective Date]
Last Updated: [Insert Date]
Document Owner: Akwaaba Solutions
Approved by: Executive Management


IMPORTANT NOTICE

These Terms of Service, End-User Terms, Privacy and Data Protection Policy govern access to and use of the Akwaaba Smart HRM Suite.

They apply to subscribing institutions, authorised representatives, administrators, employees, contractors, individual users and other persons whose personal data are processed through the platform.

Please read this document carefully before accessing or using the platform.

A subscribing institution accepts the applicable contractual provisions of this document by signing a service agreement, accepting an approved quotation or order form, paying an applicable subscription fee, authorising implementation, or otherwise expressly agreeing to use the platform.

An individual user accepts the End-User Terms and Acceptable Use provisions by completing the platform’s approved electronic acceptance process, including selecting an acceptance checkbox or signing an acknowledgement made available before or upon first access.

Biometric enrolment, standing alone, does not constitute acceptance of all commercial provisions of this document.

A person who does not agree to the terms applicable to that person must not access or continue to use the platform.

Nothing in this document excludes, restricts or overrides any right, duty, remedy or protection that cannot lawfully be excluded under the laws of the Republic of Ghana.


PART I

GENERAL PROVISIONS

1. INTRODUCTION

1.1 About Akwaaba Solutions

Akwaaba Solutions provides technology-enabled workforce, attendance, communication and institutional-management services, including the Akwaaba Smart Human Resource Management Suite.

The Akwaaba Smart HRM Suite is designed to assist organisations in managing their authorised workforce and administrative functions through approved digital channels.

1.2 Purpose of This Document

This document explains:

  1. the conditions governing institutional and individual use of the platform;
  2. the respective responsibilities of Akwaaba Solutions, subscribing institutions, administrators and users;
  3. the rules governing user accounts, security and acceptable conduct;
  4. the categories of personal data that may be processed through the platform;
  5. the purposes and lawful grounds for processing personal data;
  6. the safeguards applied to biometric and other sensitive personal data;
  7. the rights of persons whose personal data are processed;
  8. the commercial conditions governing subscriptions and services; and
  9. the limitations, remedies and dispute-resolution procedures applicable to the platform.

1.3 Nature of the Document

This document contains four related components:

  1. institutional terms governing the relationship between Akwaaba Solutions and subscribing institutions;
  2. end-user terms governing individual access and conduct;
  3. an acceptable-use policy applicable to all authorised users; and
  4. a public privacy and data-protection notice.

The commercial provisions apply principally to subscribing institutions. Individual users are bound principally by the account-security, acceptable-use, confidentiality, privacy and platform-conduct provisions relevant to their access.

1.4 Legal Framework

This document shall be interpreted in accordance with applicable laws of the Republic of Ghana, including:

  1. the Data Protection Act, 2012 (Act 843);
  2. the Electronic Transactions Act, 2008 (Act 772);
  3. the Cybersecurity Act, 2020 (Act 1038);
  4. applicable employment and labour legislation;
  5. applicable electronic-communications legislation; and
  6. regulatory directives, standards and guidance issued by competent Ghanaian authorities.

1.5 Relationship with Other Agreements

This document must be read together with any applicable:

  1. service agreement;
  2. subscription agreement;
  3. data-processing agreement;
  4. order form;
  5. accepted quotation;
  6. implementation agreement;
  7. service-level agreement;
  8. support agreement; or
  9. other written instrument executed by Akwaaba Solutions and the Customer.

1.6 Order of Precedence

Where an inconsistency arises, the following order of precedence applies:

  1. a signed Data Processing Agreement, for matters concerning personal-data processing;
  2. a signed enterprise, service or subscription agreement;
  3. an accepted order form;
  4. a signed service-level or implementation agreement;
  5. these Terms;
  6. the Acceptable Use Policy; and
  7. other published operational guidance.

A proposal or quotation does not amend these Terms unless it expressly identifies the provision being amended and is accepted by an authorised representative of Akwaaba Solutions.


2. DEFINITIONS

In this document, unless the context requires otherwise:

2.1 “Account”

Means a registered user profile, login credential or authorised access arrangement through which a person accesses the platform.

2.2 “Account Owner”

Means the Customer representative authorised to manage the principal institutional account and appoint administrators.

2.3 “Administrator”

Means a person authorised by the Customer to configure designated platform functions, manage users, assign roles, enrol personnel, access reports or perform other authorised administrative functions.

2.4 “Akwaaba Solutions,” “we,” “us” or “our”

Means the legal entity identified in Section 42 that owns, licenses, operates or supports the Akwaaba Smart HRM Suite.

2.5 “Applicable Law”

Means the laws, regulations, directives, orders and binding regulatory requirements applicable to the relevant processing activity or contractual relationship.

2.6 “Authorised Representative”

Means a person with authority to bind a Customer in relation to subscriptions, payments, data-processing instructions or contractual amendments.

2.7 “Biometric Data”

Means personal data resulting from technical processing relating to the physical, physiological or behavioural characteristics of an individual for identification or authentication, including fingerprint templates, facial-recognition templates and approved enrolment images.

2.8 “Confidential Information”

Means non-public commercial, technical, operational, financial, security or personal information disclosed by one party to another.

2.9 “Customer” or “Client Institution”

Means the organisation, employer, hospital, educational institution, church, government agency, business, association, non-governmental organisation or other entity that subscribes to or authorises use of the platform.

2.10 “Customer Data”

Means information, files, records, instructions and personal data submitted to, generated through or lawfully processed within the platform on behalf of a Customer.

2.11 “Data Controller”

Means the person or organisation that determines the purpose and manner in which personal data are processed.

2.12 “Data Processor”

Means a person or organisation that processes personal data on behalf of and under the documented instructions of a Data Controller.

2.13 “Data Subject”

Means an identified or identifiable individual to whom personal data relate.

2.14 “Device”

Means an approved biometric terminal, computer, mobile phone, tablet, server or other equipment used to access or interact with the platform.

2.15 “Documentation”

Means user guides, implementation materials, technical instructions and other materials provided by Akwaaba Solutions.

2.16 “Personal Data”

Means information relating to an identified or identifiable living individual.

2.17 “Platform” or “Service”

Means the Akwaaba Smart HRM Suite and its authorised websites, applications, modules, interfaces, APIs, databases, dashboards, devices and related services.

2.18 “Processing”

Means an operation performed on personal data, including collection, recording, organisation, storage, retrieval, consultation, use, transmission, disclosure, correction, restriction, archiving or deletion.

2.19 “Sensitive Personal Data”

Means personal data requiring heightened protection under applicable law, including biometric, medical, health, financial or other specially protected information.

2.20 “Self-Hosted Deployment”

Means a deployment in which the platform or relevant infrastructure is hosted on systems owned, controlled or commissioned by the Customer.

2.21 “Subscription”

Means the Customer’s authorised right to access specified services, modules, users, personnel records, branches or devices for an agreed period.

2.22 “Subscription Term”

Means the period for which a Customer is authorised to use the subscribed services.

2.23 “User,” “you” or “your”

Means an individual who accesses or uses the platform, including an employee, administrator, supervisor, contractor or institutional officer.


3. ACCEPTANCE AND AUTHORITY

3.1 Institutional Acceptance

A Customer accepts the institutional provisions of this document when it:

  1. signs a service or subscription agreement;
  2. accepts an approved proposal, quotation or order form;
  3. authorises implementation or onboarding;
  4. pays an applicable fee; or
  5. otherwise expressly accepts the provisions electronically or in writing.

3.2 End-User Acceptance

An individual user accepts the applicable End-User Terms when the user:

  1. selects an electronic acceptance option;
  2. signs a user acknowledgement;
  3. activates an account after being presented with the Terms; or
  4. continues to use the platform following valid notification of the applicable Terms.

3.3 Authority to Bind a Customer

A person accepting contractual provisions on behalf of a Customer represents that the person has authority to bind that Customer.

A system administrator does not automatically have authority to:

  1. amend a subscription;
  2. accept a price increase;
  3. approve a new processing purpose;
  4. execute a Data Processing Agreement;
  5. waive legal rights; or
  6. bind the Customer commercially.

Such actions may be taken only by an Authorised Representative.

3.4 Electronic Contracting

To the extent permitted by law:

  1. electronic acceptance may have the same effect as a handwritten signature;
  2. electronic records may establish the time, method and version of acceptance;
  3. notices may be delivered electronically; and
  4. system records may constitute prima facie evidence, subject to investigation, correction and contrary evidence.

3.5 Opportunity to Review

The applicable Terms shall be made reasonably accessible before or during account activation.

Users should be given an opportunity to review the Terms and correct material registration errors before completing acceptance.


4. ELIGIBILITY AND AUTHORISED ACCESS

4.1 Permitted Users

The platform may be accessed only by:

  1. Customers with a valid subscription or authorised trial;
  2. persons authorised by a Customer;
  3. Akwaaba Solutions personnel acting within assigned responsibilities; and
  4. approved service providers acting under appropriate contractual safeguards.

4.2 Institutional Control

The Customer is responsible for determining:

  1. who may access its account;
  2. which roles are assigned;
  3. which modules are available;
  4. which data each user may access;
  5. the lawful purposes for which access is granted; and
  6. when access must be suspended or terminated.

4.3 Unauthorised Access

A person must not:

  1. access an account without permission;
  2. use another person’s credentials;
  3. impersonate another user;
  4. enrol another person’s biometric data as the user’s own;
  5. bypass an authentication or approval control; or
  6. continue using the platform after authority has been withdrawn.

4.4 Children and Persons Lacking Legal Capacity

The Akwaaba Smart HRM Suite is primarily designed for workforce and institutional administration.

It is not intended for independent use by children.

Where a separately authorised solution processes children’s data, the relevant Customer must:

  1. establish a lawful basis;
  2. obtain any required parental, guardian or institutional authorisation;
  3. provide an appropriate privacy notice;
  4. restrict access appropriately; and
  5. implement safeguards proportionate to the age and vulnerability of the individuals concerned.

PART II

PLATFORM SERVICES AND CUSTOMER OBLIGATIONS

5. SCOPE OF THE SERVICES

5.1 Platform Functions

Depending on the Customer’s subscription, the platform may provide:

  1. personnel and employee database management;
  2. attendance and time management;
  3. facial, fingerprint or other approved identity authentication;
  4. duty rosters and work schedules;
  5. leave, absence and excuse-duty administration;
  6. employee self-service functions;
  7. event and visitor management;
  8. birthday and institutional notifications;
  9. bulk SMS, email, voice or other approved communications;
  10. productivity and work-item tracking;
  11. executive dashboards and reports;
  12. customer- or service-management functions;
  13. fees, dues or accounting-support functions;
  14. mobile, web, USSD or administrative clocking;
  15. multi-branch administration;
  16. integrations with approved third-party systems; and
  17. other modules introduced or agreed in writing.

5.2 Subscription Limits

The Customer may access only:

  1. the modules included in its subscription;
  2. the approved number of users, staff records, devices or branches;
  3. the agreed hosting model;
  4. the selected support package; and
  5. additional services expressly agreed in writing.

5.3 Optional Modules

Optional modules are not activated merely because they appear within the platform.

Activation may require:

  1. written authorisation;
  2. additional configuration;
  3. payment of applicable fees;
  4. a privacy assessment; or
  5. acceptance of supplementary terms.

5.4 Product Changes

Akwaaba Solutions may:

  1. improve or update features;
  2. modify workflows or interfaces;
  3. replace unsupported technologies;
  4. introduce new functionality;
  5. withdraw insecure or obsolete features;
  6. impose reasonable technical limits; or
  7. take measures necessary to protect the platform.

Akwaaba Solutions shall use reasonable efforts not to materially reduce essential paid functionality during an active Subscription Term without reasonable justification.

5.5 Trial and Preview Services

A trial, beta, preview or experimental feature may:

  1. be incomplete;
  2. contain errors;
  3. be changed or withdrawn;
  4. have limited support; and
  5. be unsuitable for critical institutional decisions.

Unless expressly agreed otherwise, trial and preview services are provided without a service-level commitment.

5.6 Third-Party Dependencies

Certain functions may depend on third-party services, including telecommunications networks, internet providers, cloud infrastructure, email gateways, SMS providers, payment services, mapping services and operating-system providers.

Akwaaba Solutions is not responsible for interruptions caused solely by systems outside its reasonable control, but shall use reasonable efforts to manage supported integrations and communicate material service issues.


6. CUSTOMER TRUST COMMITMENTS

6.1 Customer Control

As between Akwaaba Solutions and the Customer, the Customer retains its rights and lawful control over Customer Data, subject to:

  1. the rights of data subjects;
  2. applicable law;
  3. lawful regulatory requirements; and
  4. the limited processing rights necessary for Akwaaba Solutions to provide the services.

6.2 No Sale of Personal Data

Akwaaba Solutions does not sell, rent or trade Customer Data or personal data processed through the platform.

6.3 No Unauthorised Advertising

Customer Data and biometric data shall not be used for third-party advertising, unrelated commercial profiling or unauthorised marketing.

6.4 Biometric Purpose Limitation

Biometric data shall be processed only for authorised purposes such as:

  1. identity verification;
  2. authentication;
  3. attendance validation;
  4. access control; and
  5. prevention of impersonation or attendance fraud.

6.5 Artificial-Intelligence Commitment

Akwaaba Solutions shall not use Customer Data, personnel records or biometric data to train general-purpose artificial-intelligence models without:

  1. the Customer’s express written authorisation;
  2. an appropriate lawful basis;
  3. a documented assessment of the processing; and
  4. appropriate safeguards for affected individuals.

6.6 Privacy by Design and by Default

Akwaaba Solutions seeks to embed privacy and security into the platform by:

  1. limiting collection to relevant data;
  2. restricting access according to role;
  3. protecting data transmissions;
  4. applying enhanced authentication where appropriate;
  5. logging privileged activity;
  6. limiting administrative access;
  7. disabling unnecessary functions until authorised; and
  8. assessing material new processing activities.

6.7 Controlled Support Access

Akwaaba Solutions personnel may access Customer Data only where access is:

  1. necessary to provide authorised support;
  2. required for security, maintenance or incident response;
  3. permitted under an agreement;
  4. authorised by the Customer; or
  5. required by law.

Where reasonably practicable, privileged support access shall be:

  1. assigned to identified personnel;
  2. limited to necessary information;
  3. time-bound;
  4. logged;
  5. protected by confidentiality obligations; and
  6. withdrawn when the support activity ends.

Emergency access may be used to contain an imminent security threat, provided the access is documented and reviewed afterwards.


7. CUSTOMER RESPONSIBILITIES

7.1 Lawful Use

The Customer shall use the platform in accordance with:

  1. applicable data-protection requirements;
  2. employment and labour obligations;
  3. sector-specific requirements;
  4. the Customer’s internal policies;
  5. contractual obligations; and
  6. these Terms.

7.2 Data-Protection Registration

Each party is responsible for obtaining and maintaining any registration, renewal, approval or authorisation required for its processing activities.

The Customer must not instruct Akwaaba Solutions to conduct processing that the Customer is not lawfully entitled to undertake.

7.3 Lawful Basis and Transparency

Where the Customer determines why and how workforce or institutional data are processed, the Customer is ordinarily the Data Controller.

The Customer is responsible for:

  1. identifying and documenting an appropriate lawful basis;
  2. informing affected persons about the processing;
  3. issuing appropriate privacy notices;
  4. determining whether consent is legally appropriate;
  5. documenting consent where relied upon;
  6. assessing necessity and proportionality;
  7. responding to complaints and rights requests; and
  8. ensuring that instructions given to Akwaaba Solutions are lawful.

7.4 Employment-Related Consent

The Customer must not assume that consent is automatically valid merely because an employee has signed a form.

Where consent is relied upon, the Customer must assess whether it is:

  1. freely given;
  2. specific;
  3. informed;
  4. unambiguous;
  5. capable of withdrawal; and
  6. appropriate in the circumstances of the employment relationship.

7.5 Data Accuracy

The Customer must take reasonable steps to ensure that Customer Data are:

  1. accurate;
  2. complete;
  3. current;
  4. relevant;
  5. not misleading; and
  6. corrected when an error is identified.

Akwaaba Solutions is not responsible for decisions based on inaccurate information supplied or maintained by the Customer, except to the extent that the inaccuracy results directly from a failure of the platform for which Akwaaba Solutions is responsible.

7.6 User Access Management

The Customer must:

  1. appoint appropriate administrators;
  2. assign roles according to responsibilities;
  3. apply least-privilege access;
  4. review access periodically;
  5. disable access after termination or transfer;
  6. prevent account sharing;
  7. protect administrative credentials; and
  8. report suspected compromise promptly.

7.7 Employment and Management Decisions

The Customer remains responsible for employment, disciplinary, payroll, performance and management decisions.

Before taking adverse action based on platform records, the Customer should consider:

  1. approved leave;
  2. excuse duty;
  3. authorised off-site work;
  4. roster errors;
  5. device or network failure;
  6. delayed synchronisation;
  7. account compromise;
  8. pending correction requests;
  9. relevant supporting evidence; and
  10. the affected employee’s explanation.

Platform reports and alerts are decision-support tools and should not replace fair investigation or applicable due process.

7.8 Customer Infrastructure

For self-hosted or Customer-controlled environments, the Customer is responsible for:

  1. server and physical security;
  2. operating-system maintenance;
  3. network and firewall protection;
  4. server-level access;
  5. backup infrastructure;
  6. power and environmental protection;
  7. Customer-appointed third parties; and
  8. compliance with agreed technical requirements.

7.9 Prohibited Instructions

The Customer shall not instruct Akwaaba Solutions to:

  1. process data unlawfully;
  2. conceal processing from affected individuals;
  3. use biometric information for unrelated surveillance;
  4. disclose data without authority;
  5. retain data indefinitely without justification;
  6. bypass security safeguards; or
  7. act contrary to applicable law.

Akwaaba Solutions may refuse or suspend an instruction that it reasonably believes is unlawful, insecure or inconsistent with the applicable agreement.


PART III

USER ACCOUNTS AND ACCEPTABLE USE

8. USER ACCOUNTS

8.1 Account Creation

Users must provide accurate information when an account is created or activated.

The Customer or Akwaaba Solutions may require:

  1. identity verification;
  2. employee identification;
  3. a valid telephone number or email address;
  4. assignment to an approved institution, branch or department;
  5. biometric enrolment where authorised; and
  6. additional security information.

8.2 Individual Use

Each account is intended for use by the person to whom it is assigned.

A user must not:

  1. share passwords, PINs or verification codes;
  2. allow another person to clock in or out through the user’s account;
  3. share biometric access;
  4. leave an authenticated device unattended;
  5. use another person’s account; or
  6. permit unauthorised access.

8.3 Password and Authentication Security

Users must:

  1. create strong passwords where permitted;
  2. protect credentials;
  3. use multi-factor authentication where enabled;
  4. protect registered email accounts and devices;
  5. change compromised credentials promptly; and
  6. comply with reasonable security instructions.

8.4 Account Activity

Activity recorded through an account may be attributed to the account holder unless:

  1. unauthorised access is promptly reported;
  2. credible evidence indicates compromise; or
  3. investigation establishes that another person was responsible.

A user remains entitled to challenge an inaccurate record.

8.5 Account Categories

The Customer may designate separate roles, including:

  1. Account Owner;
  2. Authorised Representative;
  3. System Administrator;
  4. Billing Administrator;
  5. Human Resource Administrator;
  6. Data-Protection Contact;
  7. Supervisor; and
  8. General User.

Access granted to one role does not confer the authority assigned to another role.

8.6 Suspension for Security Reasons

Akwaaba Solutions or the Customer may temporarily restrict an account where reasonably necessary to:

  1. investigate suspicious activity;
  2. protect personal data;
  3. prevent unauthorised access;
  4. contain a security incident;
  5. enforce these Terms;
  6. comply with law; or
  7. protect the platform and its users.

9. ACCEPTABLE USE POLICY

9.1 Permitted Use

The platform may be used only:

  1. for legitimate institutional purposes;
  2. within the user’s authorised role;
  3. in accordance with applicable institutional policies;
  4. in compliance with law; and
  5. in a manner that does not compromise the platform or the rights of others.

9.2 Prohibited Conduct

A Customer or user must not:

  1. access information beyond assigned authority;
  2. impersonate another person;
  3. falsify attendance, leave, productivity or personnel records;
  4. clock in or clock out for another person;
  5. enrol false or substituted biometric data;
  6. interfere with an attendance device;
  7. disable or bypass authentication controls;
  8. introduce malware or harmful code;
  9. conduct unauthorised vulnerability testing;
  10. reverse engineer the platform except where permitted by law;
  11. copy, resell or sublicense the platform without approval;
  12. scrape or extract data by unauthorised automated means;
  13. access the platform to develop an unauthorised competing product;
  14. upload unlawful, defamatory, fraudulent or infringing content;
  15. send deceptive, abusive or unauthorised communications;
  16. sell or monetise personal data;
  17. modify records to conceal misconduct;
  18. disable audit logs or security safeguards;
  19. use the platform for covert or unlawful surveillance;
  20. use biometric data for an unrelated purpose;
  21. overload, damage or disrupt the platform; or
  22. assist another person to engage in prohibited conduct.

9.3 Communications

Customers using SMS, email, voice or other communication functions must ensure that:

  1. recipients are lawfully contacted;
  2. messages serve legitimate institutional purposes;
  3. recipient information is accurate;
  4. required permissions have been obtained;
  5. opt-out rights are respected where applicable;
  6. confidential information is not unnecessarily disclosed; and
  7. communications are not unlawful, abusive or misleading.

9.4 Location-Enabled Attendance

Where location-enabled attendance is activated, the platform may process, depending on configuration:

  1. a location captured at the time of clocking;
  2. GPS coordinates;
  3. confirmation that the user is within an approved geofence;
  4. the device’s network or internet-protocol information; or
  5. other location indicators disclosed to the user.

Location processing shall be limited to authorised purposes.

Continuous background tracking shall not be enabled unless it is separately justified, authorised, disclosed and lawfully configured.

A user must not falsify, manipulate or conceal relevant location information.


10. REPORTING MISUSE AND SECURITY INCIDENTS

10.1 User Reporting Obligations

Users and Customers must promptly report:

  1. unauthorised access;
  2. lost or stolen access devices;
  3. suspicious account activity;
  4. phishing attempts;
  5. incorrect biometric association;
  6. accidental data disclosure;
  7. compromised equipment;
  8. malware; or
  9. suspected security incidents.

10.2 Reporting Channels

Reports may be submitted to:

  1. the Customer’s authorised administrator;
  2. the Customer’s Human Resource or management office;
  3. the Customer’s Data Protection Officer;
  4. Akwaaba Solutions’ support channel; or
  5. Akwaaba Solutions’ privacy contact.

10.3 No Retaliation for Good-Faith Reporting

A person should not be penalised by Akwaaba Solutions for making a good-faith report of a suspected security or privacy incident.

This provision does not prevent action against a person who knowingly makes a false or malicious report.


PART IV

BIOMETRIC DATA AND ATTENDANCE RECORDS

11. BIOMETRIC PROCESSING

11.1 Nature of Biometric Data

The platform may support fingerprint, facial-recognition or other approved biometric authentication.

Biometric data require heightened protection because they relate to characteristics that may uniquely identify an individual.

11.2 Permitted Purposes

Biometric data may be processed only for authorised purposes, including:

  1. identity verification;
  2. attendance validation;
  3. access control;
  4. prevention of impersonation; and
  5. another compatible purpose clearly disclosed to the affected person.

11.3 Necessity and Proportionality

Before activating biometric processing, the Customer should assess:

  1. whether the processing is necessary;
  2. whether the purpose could reasonably be achieved through a less intrusive method;
  3. the effect on affected individuals;
  4. the applicable lawful basis;
  5. the proposed retention period;
  6. the safeguards available;
  7. whether an alternative method is required; and
  8. whether a Data Protection Impact Assessment is appropriate.

11.4 Biometric Enrolment

Biometric enrolment must:

  1. be carried out by authorised personnel;
  2. be linked to the correct person;
  3. use an approved device or process;
  4. be limited to necessary information;
  5. be protected from unauthorised access;
  6. be appropriately documented; and
  7. not occur secretly.

11.5 Categories of Biometric Information

Depending on the approved technology, the platform may process:

  1. fingerprint templates;
  2. facial-recognition templates;
  3. enrolment photographs;
  4. device identifiers;
  5. authentication results; and
  6. attendance timestamps.

11.6 Biometric Security

Appropriate safeguards may include:

  1. encrypted transmission;
  2. restricted administrative access;
  3. role-based access controls;
  4. enhanced authentication;
  5. protected server infrastructure;
  6. audit logging;
  7. controlled device configuration;
  8. backup safeguards; and
  9. secure deletion or deactivation.

The applicable safeguards may vary according to the deployment model, device capability and Customer infrastructure.

11.7 Accuracy Limitations

Biometric technology may occasionally produce:

  1. unsuccessful matches;
  2. false rejections;
  3. incorrect associations;
  4. poor-quality captures;
  5. failures caused by lighting or device condition;
  6. connectivity-related delays; or
  7. other technical errors.

Biometric results must not be treated as infallible or conclusive evidence without appropriate review.

11.8 Alternative Authentication

Where required by law, reasonable accommodation or institutional policy, the Customer should provide an appropriate alternative for an individual who cannot reliably use the selected biometric method.

11.9 Prohibited Biometric Uses

Biometric information must not be:

  1. sold;
  2. used for advertising;
  3. used for unrelated profiling;
  4. used for covert surveillance;
  5. disclosed without authority;
  6. copied to unauthorised devices;
  7. retained indefinitely without justification; or
  8. used to train a general-purpose artificial-intelligence model without express authorisation and a lawful basis.

11.10 Biometric Incidents

Where a suspected incident affects biometric data, Akwaaba Solutions and the Customer shall, according to their respective responsibilities:

  1. restrict access to affected records;
  2. disable the affected authentication method where necessary;
  3. provide an alternative authentication method where appropriate;
  4. assess whether templates or related data were exposed;
  5. investigate relevant devices, servers and logs;
  6. prevent further unauthorised use;
  7. determine notification obligations; and
  8. document the incident and remedial action.

12. ATTENDANCE RECORDS AND CORRECTIONS

12.1 Nature of Attendance Records

Attendance records may include:

  1. clock-in and clock-out times;
  2. work dates;
  3. assigned shifts or rosters;
  4. authentication method;
  5. clocking location;
  6. approved leave or absence;
  7. lateness;
  8. early departure;
  9. missed clock-out records;
  10. manual corrections; and
  11. relevant audit history.

12.2 Records as Evidence

System records may constitute prima facie evidence of recorded activity but are not necessarily conclusive.

Records may require review where affected by:

  1. incorrect device time;
  2. failed synchronisation;
  3. network interruption;
  4. account compromise;
  5. roster errors;
  6. authorised off-site duties;
  7. administrative changes; or
  8. other credible contrary evidence.

12.3 Correction Requests

A user may request correction of an attendance or personnel record through an approved institutional channel.

The request should identify:

  1. the disputed record;
  2. the reason for the correction;
  3. available supporting evidence; and
  4. any relevant supervisor or departmental confirmation.

12.4 Customer Review

The Customer is responsible for determining correction requests, subject to its policies and applicable law.

Where appropriate, the Customer should:

  1. acknowledge the request;
  2. investigate the facts;
  3. consider supporting evidence;
  4. communicate the outcome;
  5. permit escalation; and
  6. complete the review within a reasonable period.

12.5 Audit History

Where technically supported, a corrected record may retain an audit history showing:

  1. the original entry;
  2. the correction;
  3. the date of correction;
  4. the person who approved it; and
  5. the stated reason.

12.6 Payroll Deadlines

A pending correction request does not automatically require Akwaaba Solutions to delay the Customer’s payroll or reporting process.

The Customer remains responsible for determining how unresolved records are treated in accordance with applicable law and institutional policy.


PART V

PRIVACY AND DATA PROTECTION

13. PRIVACY COMMITMENT

Akwaaba Solutions is committed to processing personal data:

  1. lawfully;
  2. fairly;
  3. transparently;
  4. for specified purposes;
  5. in a manner compatible with those purposes;
  6. accurately;
  7. securely;
  8. only for as long as necessary; and
  9. with due regard to the rights of data subjects.

14. DATA-CONTROLLER AND DATA-PROCESSOR ROLES

14.1 Customer as Data Controller

The Customer is ordinarily the Data Controller where it determines:

  1. which employees or individuals are enrolled;
  2. why attendance information is collected;
  3. which modules are activated;
  4. how long institutional records are retained;
  5. which administrators have access; and
  6. how records are used for management, payroll or disciplinary purposes.

14.2 Akwaaba Solutions as Data Processor

Where Akwaaba Solutions processes Customer Data on behalf of a Customer, it shall:

  1. act on documented lawful instructions;
  2. apply appropriate safeguards;
  3. limit personnel access;
  4. assist with data-subject requests where reasonably required;
  5. support incident response;
  6. manage approved subprocessors appropriately; and
  7. return or delete data in accordance with the applicable agreement.

14.3 Akwaaba Solutions as Data Controller

Akwaaba Solutions may act as Data Controller for information it independently determines how and why to process, including:

  1. customer-contact information;
  2. account-administration records;
  3. billing and payment records;
  4. website enquiries;
  5. support correspondence;
  6. security and fraud-prevention records;
  7. contractual records;
  8. authorised marketing preferences; and
  9. legal and regulatory records.

14.4 Joint or Separate Responsibilities

Where the parties independently determine different purposes for processing the same information, each party remains responsible for its own processing.

A party does not become a joint controller merely because it provides technical assistance to another party.


15. PERSONAL DATA THAT MAY BE COLLECTED

Depending on the activated modules and Customer instructions, the platform may process:

15.1 Identification Information

  1. full name;
  2. employee or membership number;
  3. photograph;
  4. date of birth;
  5. gender, where lawfully required;
  6. job title;
  7. department;
  8. branch or work location; and
  9. employment status.

15.2 Contact Information

  1. telephone number;
  2. email address;
  3. postal or residential information, where authorised;
  4. emergency-contact information; and
  5. institutional contact details.

15.3 Employment and Administrative Information

  1. employment date;
  2. staff category;
  3. supervisor;
  4. duty roster;
  5. leave information;
  6. absence and excuse-duty records;
  7. productivity information;
  8. training records;
  9. disciplinary or administrative references, where authorised; and
  10. payroll-supporting attendance information.

15.4 Attendance and Device Information

  1. clock-in and clock-out records;
  2. dates and times;
  3. location at the time of clocking;
  4. device identifiers;
  5. internet-protocol addresses;
  6. login history;
  7. browser or application information;
  8. authentication records; and
  9. system audit logs.

15.5 Biometric Information

  1. fingerprint templates;
  2. facial-recognition templates;
  3. approved enrolment images;
  4. authentication results; and
  5. related biometric identifiers.

15.6 Communication Information

  1. SMS records;
  2. email records;
  3. notification-delivery information;
  4. voice-notification records;
  5. complaint records;
  6. support messages; and
  7. communication preferences.

15.7 Billing and Contract Information

  1. Customer representative details;
  2. invoices;
  3. payment references;
  4. subscription records;
  5. contract history; and
  6. tax-related information.

Akwaaba Solutions does not ordinarily require complete payment-card credentials where payment is processed by an authorised payment-service provider.


16. SOURCES OF PERSONAL DATA

Personal data may be obtained from:

  1. the data subject;
  2. the Customer;
  3. authorised administrators;
  4. biometric or attendance devices;
  5. mobile or web applications;
  6. approved integrations;
  7. communications with Akwaaba Solutions;
  8. platform-generated logs; and
  9. lawful third-party sources.

The Customer must not upload personal data obtained unlawfully.


17. PURPOSES OF PROCESSING

Personal data may be processed to:

  1. create and manage user accounts;
  2. maintain employee or institutional records;
  3. authenticate identity;
  4. record and validate attendance;
  5. manage rosters, leave and absence;
  6. support payroll verification;
  7. generate institutional reports;
  8. facilitate authorised communication;
  9. provide customer support;
  10. maintain service security;
  11. detect fraud or unauthorised access;
  12. troubleshoot technical problems;
  13. manage subscriptions and billing;
  14. improve authorised platform functionality;
  15. maintain audit and compliance records;
  16. comply with legal obligations;
  17. establish, exercise or defend legal claims; and
  18. perform another compatible and lawfully authorised purpose.

Personal data shall not be used for a materially incompatible purpose without an appropriate lawful basis and required notice or authorisation.


18. LAWFUL GROUNDS FOR PROCESSING

Depending on the circumstances, processing may be based on:

  1. performance of a contract;
  2. compliance with a legal obligation;
  3. legitimate institutional or business interests that do not unjustifiably override individual rights;
  4. consent, where consent is legally appropriate;
  5. protection of the vital interests of an individual;
  6. performance of a function authorised by law; or
  7. another lawful ground recognised under applicable law.

The Customer is responsible for establishing the lawful basis for processing that it determines.


19. DATA MINIMISATION AND ACCURACY

19.1 Data Minimisation

Only personal data reasonably necessary for authorised purposes should be collected.

Optional modules should not be activated without a legitimate need and appropriate authorisation.

19.2 Data Accuracy

Akwaaba Solutions and the Customer shall take reasonable steps, according to their respective responsibilities, to ensure that personal data are accurate, complete and current.

19.3 Unnecessary Information

Users must not upload unnecessary sensitive information into open-text fields, support messages or communication modules.


20. COOKIES AND ONLINE TECHNOLOGIES

20.1 Cookies

Akwaaba Solutions’ websites and web applications may use cookies or similar technologies to:

  1. maintain authenticated sessions;
  2. remember user preferences;
  3. protect account security;
  4. understand platform performance;
  5. diagnose errors; and
  6. improve user experience.

20.2 Essential Cookies

Essential cookies may be required for the platform to operate securely and cannot always be disabled without affecting functionality.

20.3 Analytics

Where analytics tools are used, Akwaaba Solutions shall seek to limit collection to information reasonably necessary to understand system performance and usage.

20.4 Cookie Choices

Where required, users shall be given appropriate information or choices concerning non-essential cookies.

A separate Cookie Notice may provide additional details.


21. ARTIFICIAL INTELLIGENCE AND AUTOMATED ANALYTICS

21.1 Decision-Support Functions

The platform may provide automated calculations, summaries, alerts, rankings or analytics.

These functions are intended to support human review and should not be treated as unquestionable conclusions.

21.2 Human Review

Where a result may materially affect an individual, the Customer should ensure appropriate human review before taking adverse action.

21.3 AI Training Restriction

Customer Data shall not be used to train a general-purpose AI model without express written authorisation and a lawful basis.

21.4 New AI Functions

Before introducing a material AI function involving personal data, Akwaaba Solutions may:

  1. assess privacy and security risks;
  2. define the permitted purpose;
  3. restrict access;
  4. provide relevant notices;
  5. test for material inaccuracies; and
  6. require supplementary terms.

22. DATA SHARING AND DISCLOSURE

Personal data may be disclosed only:

  1. to authorised Customer personnel;
  2. to Akwaaba Solutions personnel who require access;
  3. to approved service providers;
  4. to professional advisers subject to confidentiality;
  5. where necessary to provide an authorised integration;
  6. where required by law, court order or regulatory authority;
  7. to protect rights, security or property; or
  8. with appropriate authorisation.

Akwaaba Solutions does not sell personal data.


23. THIRD-PARTY SERVICE PROVIDERS

23.1 Approved Providers

Akwaaba Solutions may engage providers for:

  1. hosting;
  2. communications;
  3. software infrastructure;
  4. security monitoring;
  5. customer support;
  6. payment processing; and
  7. other operational services.

23.2 Safeguards

Where a provider processes personal data, Akwaaba Solutions shall seek to ensure appropriate provisions concerning:

  1. confidentiality;
  2. purpose limitation;
  3. security;
  4. incident reporting;
  5. access limitation;
  6. deletion or return of data; and
  7. restrictions on unauthorised onward processing.

23.3 Customer-Appointed Providers

The Customer is responsible for providers selected, instructed or controlled directly by the Customer.


24. CROSS-BORDER PROCESSING

Personal data shall not be transferred outside Ghana unless:

  1. the transfer is lawful;
  2. the Customer has authorised the transfer where required;
  3. appropriate contractual or technical safeguards are in place;
  4. the recipient is subject to an adequate level of protection or equivalent obligations; and
  5. affected persons are informed where required.

Where reasonably practicable, preference may be given to Ghana-based or Customer-controlled hosting arrangements.


25. INFORMATION SECURITY

25.1 Security Measures

Akwaaba Solutions shall maintain technical and organisational safeguards appropriate to:

  1. the nature of the information;
  2. the sensitivity of the data;
  3. the risks involved;
  4. the deployment model; and
  5. available technology.

Safeguards may include:

  1. encryption in transit;
  2. access controls;
  3. enhanced authentication;
  4. logging and monitoring;
  5. secure configuration;
  6. firewall protection;
  7. backup and recovery;
  8. vulnerability and patch management;
  9. personnel confidentiality; and
  10. incident-response procedures.

25.2 No Absolute Security Guarantee

No technology system is completely immune from error, interruption or unauthorised attack.

Akwaaba Solutions does not guarantee absolute security but shall take reasonable and appropriate measures to protect personal data and respond to incidents.

25.3 Customer Security Responsibilities

The Customer must protect:

  1. Customer-controlled devices;
  2. administrative credentials;
  3. networks;
  4. physical access points;
  5. self-hosted infrastructure;
  6. exported reports; and
  7. data downloaded outside the platform.

26. PERSONAL-DATA BREACHES

26.1 Incident Response

Where a personal-data breach is suspected, Akwaaba Solutions may:

  1. identify affected systems;
  2. contain the incident;
  3. assess the nature and scope;
  4. evaluate potential harm;
  5. preserve relevant evidence;
  6. implement remediation;
  7. communicate with the Customer; and
  8. support applicable notification obligations.

26.2 Processor Notification

Where Akwaaba Solutions acts as Data Processor, it shall notify the affected Customer without undue delay after confirming or reasonably suspecting a material breach affecting Customer Data.

26.3 Controller Notification

Where Akwaaba Solutions acts as Data Controller, it shall assess whether notification to affected individuals or a competent authority is required.

26.4 Customer Cooperation

The Customer shall provide timely information and cooperation reasonably required to investigate and respond to an incident.

26.5 Confidentiality of Investigations

Information relating to an active security investigation may be restricted to persons who require access, subject to legal disclosure obligations.


27. DATA RETENTION

27.1 General Principle

Personal data shall not be retained for longer than necessary for the purpose for which they were collected, subject to legal, contractual, audit and security requirements.

27.2 Customer-Controlled Retention

The Customer ordinarily determines retention periods for:

  1. employee records;
  2. attendance data;
  3. leave and roster information;
  4. biometric records;
  5. institutional communications; and
  6. Customer-generated reports.

27.3 Akwaaba-Controlled Retention

Akwaaba Solutions may retain its own controller records for periods reasonably necessary to:

  1. administer contracts;
  2. manage billing;
  3. provide support;
  4. maintain security;
  5. comply with law;
  6. manage disputes; and
  7. protect legitimate business interests.

27.4 Biometric Retention

Biometric data should be deleted, deactivated or rendered inaccessible when:

  1. the authorised purpose ends;
  2. the individual’s employment or relationship ends and no lawful basis remains;
  3. the Customer terminates the relevant service;
  4. an approved deletion request is implemented; or
  5. the applicable retention period expires.

27.5 Backups

Deleted information may remain temporarily within protected backups until the applicable backup cycle expires.

Backup data shall not ordinarily be restored for active use except for disaster recovery, security or legal requirements.


28. DATA RETURN AND DELETION

28.1 During the Subscription

The Customer may request an export of available Customer Data, subject to:

  1. the Customer’s subscription;
  2. technical feasibility;
  3. security verification;
  4. applicable fees for exceptional work; and
  5. rights of third parties.

28.2 Upon Termination

Following termination, Akwaaba Solutions may:

  1. provide a reasonable period for authorised export;
  2. restrict further platform access;
  3. delete or return Customer Data according to the agreement; and
  4. retain only information required by law or legitimate legal necessity.

28.3 Secure Deletion

Deletion measures may include:

  1. removal from active databases;
  2. deactivation of biometric templates;
  3. account closure;
  4. device-level deletion;
  5. secure media wiping; and
  6. expiration through backup cycles.

29. DATA-SUBJECT RIGHTS

Subject to applicable law, a data subject may have the right to:

  1. be informed about processing;
  2. request access to personal data;
  3. request correction of inaccurate data;
  4. object to certain processing;
  5. request prevention of processing causing unjustified damage or distress;
  6. request deletion where legally applicable;
  7. withdraw consent where processing depends on consent; and
  8. lodge a complaint with the appropriate authority.

29.1 Requests Relating to Customer Data

Where Akwaaba Solutions acts as Data Processor, requests should ordinarily be directed to the Customer.

Akwaaba Solutions may refer a request to the relevant Customer and assist the Customer where reasonably required.

29.2 Requests Relating to Akwaaba-Controlled Data

Requests concerning data for which Akwaaba Solutions is the Data Controller may be submitted through the privacy contact in Section 42.

29.3 Identity Verification

Before disclosing or changing personal data, identity may be verified to prevent unauthorised access.

29.4 Limitations

A request may be limited or refused where:

  1. identity cannot be verified;
  2. disclosure would adversely affect another person’s rights;
  3. retention is required by law;
  4. the request is legally exempt; or
  5. another lawful ground justifies refusal.

Reasons shall be provided where required.


30. DATA PROTECTION IMPACT ASSESSMENTS

A Data Protection Impact Assessment should be considered where proposed processing is likely to create significant privacy risks, including:

  1. large-scale biometric processing;
  2. new biometric modalities;
  3. systematic monitoring;
  4. continuous location tracking;
  5. materially new AI processing;
  6. large-scale sensitive-data processing;
  7. cross-border processing; or
  8. material integration with external systems.

The Customer remains responsible for assessments relating to processing purposes determined by the Customer. Akwaaba Solutions may provide relevant technical assistance.


31. SELF-HOSTED DEPLOYMENTS

31.1 Customer Control

In a self-hosted deployment, the Customer ordinarily controls:

  1. server infrastructure;
  2. physical hosting;
  3. server-level administrators;
  4. network configuration;
  5. backups; and
  6. infrastructure access.

31.2 Akwaaba Solutions’ Role

Akwaaba Solutions shall provide support within the scope of the applicable agreement and documented Customer instructions.

31.3 Allocation of Risk

The Customer is responsible for risks arising from:

  1. Customer infrastructure;
  2. unsupported configuration;
  3. unauthorised Customer personnel;
  4. Customer-selected hosting providers;
  5. failure to apply agreed updates; and
  6. inadequate Customer backups.

Akwaaba Solutions remains responsible for its own personnel, software obligations and actions within its control.

31.4 Support Access

Server access provided to Akwaaba Solutions must be:

  1. authorised;
  2. limited;
  3. appropriately secured;
  4. withdrawn when no longer needed; and
  5. logged where reasonably practicable.

PART VI

COMMERCIAL TERMS

32. SUBSCRIPTIONS, FEES AND PAYMENT

32.1 Subscription Fees

The Customer shall pay the fees stated in the applicable quotation, order form or service agreement.

32.2 Taxes

Unless expressly stated otherwise, fees are exclusive of applicable taxes, levies, duties and statutory charges.

32.3 Invoicing

Invoices shall be issued according to the agreed billing schedule.

32.4 Payment Due Dates

Payments must be made by the due date stated on the invoice or agreement.

32.5 Late Payment

Where payment is overdue, Akwaaba Solutions may:

  1. issue a payment reminder;
  2. restrict non-essential services;
  3. suspend access after reasonable notice;
  4. charge an agreed late-payment amount where lawful; or
  5. exercise contractual recovery rights.

32.6 Fee Changes

Akwaaba Solutions may revise fees for a future Subscription Term.

Unless otherwise agreed, a fee change shall not retrospectively alter fees already paid for an active prepaid term.

32.7 Renewals

A subscription may renew:

  1. automatically, where expressly agreed; or
  2. upon acceptance of a renewal quotation or invoice.

The applicable agreement shall determine the renewal procedure.

32.8 Refunds

Fees are non-refundable except where:

  1. the agreement expressly permits a refund;
  2. Akwaaba Solutions agrees in writing;
  3. the service cannot be provided due to Akwaaba Solutions’ material breach; or
  4. applicable law requires a refund.

32.9 Third-Party Charges

The Customer is responsible for separately identified telecommunications, SMS, email, payment-provider or other third-party usage charges unless the applicable package expressly includes them.


33. IMPLEMENTATION, TRAINING AND SUPPORT

33.1 Implementation

The Customer shall provide accurate information, authorised personnel and reasonable cooperation required for implementation.

33.2 Training

Training shall be provided according to the agreed package.

The Customer is responsible for ensuring that relevant personnel attend training and comply with operating instructions.

33.3 Support

Support may include:

  1. incident logging;
  2. troubleshooting;
  3. configuration guidance;
  4. remote assistance;
  5. agreed on-site support; and
  6. software updates.

33.4 Excluded Support

Unless otherwise agreed, support does not include:

  1. Customer internet service;
  2. repair of unrelated hardware;
  3. unsupported third-party software;
  4. unauthorised modifications;
  5. Customer-created data errors;
  6. staff training outside the agreed scope; or
  7. services resulting from misuse.

33.5 Additional Work

Custom development, data correction, migration, on-site work or services outside the subscription may attract additional fees.


34. SERVICE AVAILABILITY AND MAINTENANCE

34.1 Reasonable Availability

Akwaaba Solutions shall use reasonable efforts to maintain service availability, subject to:

  1. planned maintenance;
  2. emergency maintenance;
  3. third-party service interruptions;
  4. internet or telecommunications failure;
  5. Customer infrastructure failure;
  6. security incidents;
  7. force majeure; and
  8. other circumstances outside reasonable control.

34.2 Planned Maintenance

Where practicable, material planned maintenance shall be scheduled to minimise disruption and communicated through an appropriate channel.

34.3 Emergency Maintenance

Emergency maintenance may be performed without prior notice where necessary to protect security, integrity or service continuity.

34.4 Offline and Delayed Synchronisation

Where offline functionality is available, records may synchronise when connectivity is restored.

Delayed synchronisation may affect the time at which information becomes visible in reports.

34.5 Service Levels

Any guaranteed availability, response or restoration commitment applies only where stated in a signed Service-Level Agreement.


35. INTELLECTUAL PROPERTY

35.1 Akwaaba Solutions’ Rights

Akwaaba Solutions and its licensors retain all rights in:

  1. the platform;
  2. software;
  3. source code;
  4. databases and structures;
  5. designs;
  6. trademarks;
  7. documentation;
  8. workflows;
  9. reports and templates developed by Akwaaba Solutions; and
  10. improvements and derivative works.

35.2 Customer Licence

During an active subscription, the Customer receives a limited, non-exclusive, non-transferable and revocable right to use the subscribed services for authorised internal purposes.

35.3 Customer Data

The Customer retains its rights and lawful control over Customer Data, subject to data-subject rights and applicable law.

35.4 Feedback

Where the Customer voluntarily provides suggestions, Akwaaba Solutions may use them to improve the platform without disclosing the Customer’s Confidential Information.

35.5 Restrictions

The Customer shall not:

  1. reproduce the platform beyond authorised use;
  2. remove proprietary notices;
  3. create an unauthorised derivative product;
  4. resell access;
  5. disclose source code;
  6. circumvent licensing controls; or
  7. use Akwaaba Solutions’ trademarks without permission.

36. CONFIDENTIALITY

36.1 Confidentiality Obligation

Each party shall:

  1. protect the other party’s Confidential Information;
  2. use it only for the agreed purpose;
  3. restrict access to persons who require it;
  4. apply reasonable safeguards; and
  5. not disclose it without authority.

36.2 Exclusions

Confidential Information does not include information that:

  1. is publicly available without breach;
  2. was lawfully known before disclosure;
  3. is received lawfully from another source;
  4. is independently developed; or
  5. must be disclosed by law.

36.3 Required Disclosure

Where disclosure is legally required, the receiving party shall, where permitted:

  1. notify the other party;
  2. limit the disclosure; and
  3. cooperate with reasonable protective measures.

36.4 Continuing Obligation

Confidentiality obligations continue after termination for as long as the information remains confidential.


PART VII

SUSPENSION, TERMINATION AND LIABILITY

37. SUSPENSION

Akwaaba Solutions may suspend access where:

  1. fees remain overdue after notice;
  2. use creates a security risk;
  3. there is suspected unlawful activity;
  4. the Customer materially breaches the agreement;
  5. suspension is required by law;
  6. the Customer exceeds agreed subscription limits; or
  7. continued access could harm the platform or another person.

Where reasonably practicable, Akwaaba Solutions shall notify the Customer and provide an opportunity to remedy the issue.

Immediate suspension may occur where urgent action is required to protect security, personal data or legal compliance.


38. TERMINATION

38.1 Termination by Agreement

Either party may terminate according to the applicable agreement.

38.2 Termination for Material Breach

A party may terminate where the other party:

  1. materially breaches the agreement;
  2. fails to remedy a remediable breach within the stated period;
  3. becomes insolvent or ceases business;
  4. uses the platform unlawfully; or
  5. creates an unacceptable security or regulatory risk.

38.3 Effect of Termination

Upon termination:

  1. the Customer’s licence ends;
  2. user access may be disabled;
  3. outstanding fees become payable;
  4. Customer Data shall be handled under Section 28;
  5. each party shall return or protect Confidential Information; and
  6. provisions intended to survive termination remain effective.

38.4 Survival

Provisions concerning confidentiality, intellectual property, data protection, payment obligations, liability, dispute resolution and accrued rights survive termination where applicable.


39. WARRANTIES AND DISCLAIMERS

39.1 Authority

Each party warrants that it has authority to enter into the applicable agreement.

39.2 Service Performance

Akwaaba Solutions warrants that it shall provide the services with reasonable skill and care.

39.3 No Guarantee of Error-Free Operation

The platform is a technology service and may experience errors, interruptions, delayed synchronisation or third-party failures.

Akwaaba Solutions does not warrant that every feature will operate without interruption or error at all times.

39.4 Customer Decisions

Akwaaba Solutions does not warrant that a report, alert or automated result is sufficient by itself to justify an employment, disciplinary, payroll or legal decision.

39.5 Unauthorised Modifications

Akwaaba Solutions is not responsible for defects caused by:

  1. unauthorised modification;
  2. unsupported integrations;
  3. Customer infrastructure failure;
  4. misuse;
  5. failure to follow instructions; or
  6. third-party systems outside its control.

40. LIMITATION OF LIABILITY

40.1 Excluded Losses

To the extent permitted by law, neither party shall be liable to the other for indirect, incidental, special or consequential loss, including loss of anticipated profit, goodwill or opportunity, except where such exclusion is prohibited by law.

40.2 Liability Cap

Except for liabilities that cannot lawfully be limited, Akwaaba Solutions’ aggregate contractual liability arising from the services shall not exceed the total subscription fees paid by the Customer for the affected service during the twelve months immediately preceding the event giving rise to the claim.

40.3 Exceptions

The limitation in Section 40.2 does not apply to:

  1. fraud or fraudulent misrepresentation;
  2. wilful misconduct;
  3. liability that cannot lawfully be excluded;
  4. unauthorised use of the other party’s intellectual property;
  5. breach of confidentiality caused by deliberate misconduct; or
  6. any separate liability expressly agreed in writing.

40.4 Customer Responsibility

Akwaaba Solutions is not liable for loss arising from:

  1. unlawful Customer instructions;
  2. inaccurate Customer Data;
  3. unauthorised Customer administrators;
  4. Customer employment decisions;
  5. failure to maintain Customer infrastructure;
  6. unsupported third-party systems;
  7. compromised credentials not promptly reported; or
  8. use outside the agreed scope.

40.5 Fair Allocation

The parties acknowledge that the fees and liability provisions reflect a reasonable allocation of commercial risk.


41. INDEMNITY

41.1 Customer Indemnity

To the extent permitted by law, the Customer shall indemnify Akwaaba Solutions against third-party claims arising directly from:

  1. unlawful Customer instructions;
  2. data supplied without lawful authority;
  3. unauthorised use of the platform;
  4. Customer infringement of third-party rights;
  5. Customer misuse of biometric or location data; or
  6. Customer breach of applicable law.

41.2 Akwaaba Solutions Indemnity

Akwaaba Solutions shall defend the Customer against a third-party claim that the authorised use of the platform infringes that third party’s intellectual-property rights, subject to:

  1. prompt written notice;
  2. reasonable cooperation;
  3. Akwaaba Solutions controlling the defence; and
  4. the claim not arising from Customer modification, misuse or combination with an unsupported system.

41.3 Mitigation

The indemnified party must take reasonable steps to reduce avoidable loss.


PART VIII

LEGAL AND ADMINISTRATIVE PROVISIONS

42. COMPANY AND CONTACT INFORMATION

Before publication, the following information must be completed:

Legal Name: Akwaaba Solutions
Trading Name: Akwaaba Smart HRM Suite
Company or Business Registration Number: [Insert Number]
Data Protection Commission Registration Number: [Insert Valid Number]
Principal Business Address: Anvil Road I.63, Afariwa-Seprepor, Tema
Postal Address: P.O.Box SQ 228, Tema
General Email: akwaabahr@gmail.com
Support Email: akwaabaoffice@gmail.com
Telephone: +233206007255

42.1 Complaints

A person dissatisfied with the handling of a privacy matter may:

  1. contact Akwaaba Solutions;
  2. use the Customer’s internal complaint process where the Customer controls the data; and
  3. lodge a complaint with the Data Protection Commission of Ghana where legally appropriate.

43. NOTICES

43.1 Permitted Methods

Notices may be delivered through:

  1. email;
  2. the platform;
  3. SMS;
  4. registered post;
  5. courier;
  6. an administrator dashboard; or
  7. another agreed channel.

43.2 Customer Contact Information

The Customer must keep its official contact information current.

A notice sent to the Customer’s last recorded official contact shall be treated as properly addressed.

43.3 Legal Notices

A formal notice of breach, termination or legal proceedings must be delivered in accordance with the applicable signed agreement.


44. CHANGES TO THIS DOCUMENT

44.1 Right to Update

Akwaaba Solutions may revise, replace or update this document at any time, including without prior individual notice, where permitted by law.

Updates may be made to reflect:

  1. legal or regulatory developments;
  2. changes to the platform;
  3. security requirements;
  4. operational improvements;
  5. new technology;
  6. new modules;
  7. third-party service changes; or
  8. corrections and clarifications.

44.2 Minor Changes

Minor, administrative, formatting, clarification or non-material changes may take effect when published without prior individual notice.

44.3 Material Changes

Where a change materially affects:

  1. paid subscription rights;
  2. fees during an active term;
  3. data-processing purposes;
  4. categories of personal data collected;
  5. material data disclosures;
  6. limitation-of-liability provisions;
  7. dispute-resolution rights; or
  8. termination rights,

Akwaaba Solutions shall, where reasonably practicable and legally required, provide notice through email, the platform, SMS or an authorised Customer representative.

44.4 Changes Requiring Consent

Where applicable law or contract requires express acceptance, renewed consent or a written amendment, the relevant change shall take effect only after the required action has occurred.

44.5 No Retrospective Effect

Unless required by law or expressly agreed, a material contractual change shall not operate retrospectively.

44.6 Publication

The current version shall be published through the official website, platform or another approved channel.

Users and Customers should review the current published version periodically.

44.7 Continued Use

Continued use after an updated version takes effect constitutes acceptance where legally valid, except where express acceptance or renewed consent is required.


45. FORCE MAJEURE

Neither party shall be liable for delay or failure caused by circumstances beyond its reasonable control, including:

  1. natural disaster;
  2. fire;
  3. flood;
  4. epidemic or public-health emergency;
  5. war or civil disturbance;
  6. government action;
  7. widespread telecommunications failure;
  8. national power failure;
  9. industrial action not confined to the affected party;
  10. cyberattack that could not reasonably have been prevented; or
  11. failure of critical third-party infrastructure.

The affected party shall take reasonable steps to reduce the disruption and resume performance.

Payment obligations already accrued are not automatically excused by force majeure.


46. ASSIGNMENT AND SUBCONTRACTING

46.1 Assignment

The Customer may not assign its subscription without Akwaaba Solutions’ prior written consent, except as part of an approved corporate restructuring or transfer agreed in writing.

46.2 Akwaaba Assignment

Akwaaba Solutions may assign the agreement as part of a merger, restructuring, sale of business or transfer to an affiliate, provided that the assignee assumes the relevant obligations.

46.3 Subcontracting

Akwaaba Solutions may use appropriately qualified subcontractors but remains responsible for contractual obligations assigned to them, subject to the applicable agreement.


47. NON-WAIVER

A failure or delay in exercising a right does not waive that right.

A waiver is effective only where clearly communicated by an authorised representative.


48. SEVERABILITY

Where a provision is found invalid or unenforceable:

  1. the remaining provisions remain effective;
  2. the invalid provision shall be limited to the minimum extent necessary; and
  3. where possible, it shall be interpreted to reflect the original lawful intention.

49. ENTIRE AGREEMENT

The applicable signed agreements, order forms, Data Processing Agreement and these Terms constitute the entire agreement concerning the subscribed services and replace prior discussions relating to the same subject.

This clause does not exclude liability for fraud or fraudulent misrepresentation.


50. GOVERNING LAW

This document and any dispute arising from it shall be governed by the laws of the Republic of Ghana.


51. DISPUTE RESOLUTION

51.1 Good-Faith Negotiation

The parties shall first attempt to resolve a dispute through good-faith negotiation between authorised representatives.

51.2 Escalation

Where the dispute remains unresolved, either party may request escalation to senior management.

51.3 Mediation

The parties may agree to refer the dispute to mediation in Ghana before commencing formal proceedings.

51.4 Court Jurisdiction

Where a dispute is not resolved, the courts of competent jurisdiction in Ghana shall have jurisdiction, unless the parties have agreed in writing to arbitration.

51.5 Urgent Relief

Nothing prevents a party from seeking urgent injunctive or protective relief where necessary to protect personal data, intellectual property, confidential information or system security.

51.6 Regulatory Complaints

Nothing in this section prevents a data subject from lodging a complaint with a competent regulatory authority.


52. LANGUAGE AND ACCESSIBILITY

52.1 Governing Language

The official version of this document is the English version.

Where a translation is provided, it is intended to improve accessibility. In the event of an inconsistency, the English version prevails to the extent permitted by law.

52.2 Accessible Format

Akwaaba Solutions may make this document available in:

  1. web format;
  2. downloadable PDF;
  3. mobile-readable format;
  4. large-print or accessible format where reasonably practicable; and
  5. a plain-language summary.

A summary does not replace the complete legal document.


53. DOCUMENT CONTROL

Document Title: Akwaaba Smart HRM Suite Terms of Service, End-User Terms, Privacy and Data Protection Policy
Version: 1.0
Classification: Public
Effective Date: 1st January, 2026
Approval Date: 16th July, 2026
Approved by: Executive Management
Document Owner: Akwaaba Solutions
Official Publication Location: www.akwaabasolutions.com


54. ACKNOWLEDGEMENT

By validly accepting or using the Akwaaba Smart HRM Suite, the relevant Customer or user acknowledges, according to the provisions applicable to that person, that:

  1. access is limited to authorised purposes;
  2. account credentials must be protected;
  3. attendance and personnel records must not be falsified;
  4. personal and biometric data must be processed only for lawful and disclosed purposes;
  5. platform activity may be logged for security and accountability;
  6. biometric and automated results may require human review;
  7. Customers remain responsible for employment and management decisions;
  8. personal-data rights remain subject to applicable law;
  9. commercial use is subject to the applicable subscription agreement; and
  10. this document may be updated in accordance with Section 44.

Latest Insights

Blog & resources

Stay informed with expert insights, industry trend