Back Legal

Privacy Policy

Version 1.0 · Last updated 26 September 2026 · Governed by the laws of the Republic of Ghana

This Privacy Policy explains how personal data is collected, used, stored and protected when you use KabCore HR System. It is written to comply with the Data Protection Act, 2012 (Act 843) and the directives of the Data Protection Commission ("DPC") of Ghana, and should be read together with our Terms & Conditions.

1. Who is responsible for your data

Two different roles apply. The business that subscribes to KabCore HR System (your employer or the company whose workspace you join) is the data controller for employee and HR records — it decides what is collected and why. KabCore HR System is the data processor: we hold and process that data only on the controller's documented instructions and to operate the Service.

For our own account, billing and website data (for example administrator login details and payment records) we act as data controller.

2. Legal framework we follow

We process personal data in accordance with the Data Protection Act, 2012 (Act 843) and the Data Protection Regulations, 2012 (L.I. 2205); the Electronic Transactions Act, 2008 (Act 772); the Cybersecurity Act, 2020 (Act 1038); the Payment Systems and Services Act, 2019 (Act 987) for payments; and, for employment records, the Labour Act, 2003 (Act 651) together with SSNIT and Ghana Revenue Authority requirements that apply to your employer.

3. Personal data we hold

Through the Service we may hold the following categories of data:

Account and business data: company name, contact person, work email, phone number, company access code, subscription plan, billing period, payment reference and channel (card or mobile money).

Employee HR data: name, employee number, date of birth, gender, marital status, nationality, contact details, emergency contacts, job title, department, branch, reporting manager, employment type, date hired, job grade, status, photograph, qualifications and skills.

Sensitive and financial data: bank account and mobile money details, Tax Identification Number, SSNIT number, salary and payroll figures, and — where an employer records it — health or medical information submitted to support sick leave, maternity or paternity leave, or a medical claim. These are treated as sensitive personal data with restricted access.

Operational data: attendance and clock-in records, leave and expense requests, HR requests, documents you attach, in-app notifications, and activity logs recording who changed what and when.

Technical data: session and authentication data needed to keep your account secure.

4. Why we process it and our lawful bases

We process employee data on the instructions of the employer (data controller), generally on the basis of the employment relationship, the employer's legal obligations, or the employee's consent. Employees should direct access and correction requests to their employer first; we will assist the employer in responding.

We process account, billing and security data to perform our contract with the business, to comply with legal obligations (including tax and accounting requirements and lawful requests from regulators), and on the basis of our legitimate interest in keeping the Service secure and preventing fraud and abuse. We do not sell personal data, and we do not use employee data for advertising.

5. Who we share data with

We share data only as needed: with our cloud hosting and storage providers; with Paystack for payment processing; with email delivery providers for notifications and invitations; and with professional advisers or authorities where the law requires it. All processors are bound to keep the data confidential and secure.

6. International transfers

Our infrastructure may store or process data outside Ghana. Where personal data is transferred abroad, we require the recipient to apply protections at least equivalent to Act 843, and transfers are made with the safeguards required by the DPC, including contractual protections and, where necessary, your consent.

7. How we protect your data

Security is built into the platform. Measures include: encrypted transmission of data; strict row-level access rules so that each company's records are isolated from every other company; role-based permissions so that employee self-service accounts can reach only their own records while HR staff manage the wider workspace; private storage for uploaded documents; authentication controls including email verification, one-time codes and password reset flows; audit logging of actions in the workspace; and least-privilege access for our own staff.

We also maintain an incident response process. If a breach affecting your personal data occurs, we will notify the affected controller and the DPC as required by Act 843 and the Cybersecurity Act, 2020 (Act 1038).

8. How long we keep data

Employee and HR records are kept for as long as the employer's workspace is active. When a business account is deleted, the workspace is retained in a restoration bin for sixty (60) days so that it can be restored in full; after that period it is removed. Subscription, invoice and payment records are kept for the period required by Ghanaian tax and accounting rules (generally six years). Activity logs are kept for a limited period for security and audit purposes.

9. Your rights

Subject to Act 843, you have the right to be informed about how your data is used; to access a copy of your personal data; to have inaccurate data corrected; to object to or withdraw consent for processing; to request deletion where there is no lawful ground to keep it; and to complain to the DPC.

Employees should first raise requests with their employer, who controls the records. If you are an administrator or contact person, or you cannot resolve a request with the employer, contact us through your platform administrator. You may also lodge a complaint with The Data Protection Commission, Accra, Ghana (info@dataprotection.org.gh).

10. Cookies and local storage

We use essential cookies and local storage to keep you signed in, remember your preferences (such as light or dark mode) and secure your session. We do not use advertising cookies. You can clear this data in your browser settings, but you may then need to sign in again.

11. Children

The Service is designed for businesses and their adult employees. It is not intended for anyone under the age of eighteen (18), and we do not knowingly process children's personal data.

12. Registration with the Data Protection Commission

Businesses that use KabCore HR System to process employee personal data may be required to register as data controllers with the Data Protection Commission and to renew that registration as prescribed. Your business is responsible for that registration; we are happy to support you with the information you need.

13. Changes to this policy

We may update this Privacy Policy to reflect legal or operational changes. Material changes will be notified in the application or by email before they take effect.

These documents are written for compliance with Ghanaian law. Businesses should have their own legal adviser review them against their specific operations. Questions: contact your KabCore HR System administrator.