Data Protection & Compliance Policy

Effective Date: 8th June 2026Last Updated: 7th June 2026
Version 1.0GhanaData Protection Act 2012GDPR Compliant

1. Introduction

Pickseat Transport Services ("Pickseat", "we", "our", or "us") is committed to protecting the privacy and security of personal data entrusted to us. This Data Protection & Compliance Policy outlines our obligations under the Data Protection Act, 2012 (Act 843) of Ghana, the General Data Protection Regulation (GDPR) where applicable, and other relevant data protection laws.

We handle personal data with the utmost care and respect, ensuring that all processing activities comply with applicable legal requirements and industry best practices.

This policy applies to:

  • All personal data processed by Pickseat
  • All employees, contractors, and third-party processors
  • All systems, applications, and services operated by Pickseat
  • All data processing activities, whether automated or manual

2. Legal Framework

Pickseat complies with the following data protection laws and regulations:

2.1 Data Protection Act, 2012 (Act 843) - Ghana

  • Data Protection Principles (Section 1)
  • Collection and Processing of Personal Data (Section 17)
  • Rights of Data Subjects (Section 21-28)
  • Data Security Measures (Section 29)
  • Data Retention and Disposal (Section 30)
  • Compliance and Enforcement (Section 31-40)

2.2 General Data Protection Regulation (GDPR)

  • Lawfulness, Fairness, and Transparency (Article 5)
  • Purpose Limitation (Article 5)
  • Data Minimization (Article 5)
  • Accuracy (Article 5)
  • Storage Limitation (Article 5)
  • Integrity and Confidentiality (Article 5)
  • Data Subject Rights (Articles 12-22)

2.3 Other Applicable Laws

  • Electronic Communications Act, 2008 (Act 775)
  • National Identity Register Act, 2008 (Act 750)
  • Banking Act, 2004 (Act 673) - Financial Data Protection
  • Road Traffic Act, 2004 (Act 683) - Driver and Vehicle Data

3. Data Protection Principles

Pickseat adheres to the following data protection principles:

3.1 Lawfulness, Fairness, and Transparency

  • Processing is lawful, fair, and transparent to data subjects
  • Data subjects are informed about how their data is used
  • Consent is obtained where required

3.2 Purpose Limitation

  • Data is collected for specified, explicit, and legitimate purposes
  • Data is not processed in a manner incompatible with those purposes

3.3 Data Minimization

  • Only data that is adequate, relevant, and limited to what is necessary is collected
  • Unnecessary data is not collected or retained

3.4 Accuracy

  • Personal data is accurate and kept up to date
  • Inaccurate data is corrected or deleted without delay

3.5 Storage Limitation

  • Data is kept only as long as necessary for the intended purpose
  • Data is securely disposed of when no longer needed

3.6 Integrity and Confidentiality

  • Data is processed in a manner that ensures security
  • Appropriate technical and organizational measures are in place

3.7 Accountability

  • We are responsible for and can demonstrate compliance with these principles
  • Records of processing activities are maintained

4. Data Subject Rights

Under the Data Protection Act, 2012 (Act 843) and GDPR, data subjects have the following rights:

RightDescriptionResponse Time
Right to AccessRequest access to personal data we hold about you30 days
Right to CorrectionRequest correction of inaccurate or incomplete data30 days
Right to DeletionRequest deletion of personal data ("right to be forgotten")30 days
Right to RestrictionRequest restriction of data processing30 days
Right to ObjectObject to processing based on legitimate interests30 days
Right to PortabilityRequest transfer of data to another controller30 days
Right to Withdraw ConsentWithdraw consent where processing is based on consentImmediate

To exercise your rights: Submit a request to makosagroups@gmail.com. We may require verification of identity before processing certain requests.

5. Categories of Personal Data

Pickseat processes the following categories of personal data:

CategoryExamplesProcessing Purpose
Identity DataFull name, Ghana Card, driver's licenseVerification, compliance, safety
Contact DataEmail address, phone number, physical addressCommunication, account management
Location DataGPS coordinates, route history, stop dataService provision, tracking, analytics
Payment DataTransaction references, billing details, payment statusPayment processing, accounting
Vehicle DataVehicle registration, insurance, inspection recordsVerification, safety, compliance
Usage DataApp interactions, features used, search historyService improvement, analytics
Technical DataIP address, device information, operating systemSecurity, troubleshooting, compatibility

5.1 Special Categories of Data

Pickseat does not knowingly collect special categories of personal data (sensitive data) including:

  • Racial or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade union membership
  • Health data
  • Biometric data
  • Sexual orientation

If we inadvertently collect special categories of data,it will be immediately deleted unless required by law.

6. Data Processing Activities

6.1 Collection

  • Data is collected directly from data subjects during registration
  • Data is collected through app usage and interactions
  • Data may be collected from third-party verification services
  • Data is collected only for specified, legitimate purposes

6.2 Storage

  • Data is stored securely on encrypted servers
  • Data is stored in Ghana and internationally (with appropriate safeguards)
  • Access to stored data is strictly controlled
  • Data is retained only as long as necessary

6.3 Processing

  • Data is processed only for legitimate, specified purposes
  • Processing is automated and manual as appropriate
  • Processing is documented and auditable
  • Processing is subject to appropriate security controls

6.4 Sharing

  • Data is shared only with legitimate recipients
  • Data sharing is governed by data processing agreements
  • Data is not sold to third parties
  • International transfers are subject to appropriate safeguards

6.5 Deletion

  • Data is securely deleted when no longer needed
  • Deletion is documented and auditable
  • Data may be anonymized instead of deleted for research purposes
  • Legal retention requirements are respected

7. Data Security Measures

Pickseat implements comprehensive security measures to protect personal data from unauthorized access, disclosure, alteration, or destruction.

7.1 Technical Measures

  • Encryption: Data is encrypted at rest (AES-256) and in transit (TLS 1.3)
  • Access Control: Role-based access controls (RBAC) with least privilege principle
  • Authentication: Multi-factor authentication for critical systems
  • Monitoring: 24/7 system monitoring and intrusion detection
  • Backup: Regular encrypted backups with disaster recovery plans
  • Firewall: Next-generation firewalls for network protection
  • Vulnerability Management: Regular security assessments and penetration testing

7.2 Organizational Measures

  • Policies: Comprehensive data protection and security policies
  • Training: Regular employee training on data protection
  • Audits: Regular internal and external audits
  • Incident Response: Documented incident response procedures
  • Data Protection Officer: Dedicated DPO responsible for compliance

7.3 Physical Measures

  • Secure office premises with access controls
  • Secure server facilities with environmental controls
  • Document and media disposal procedures
  • Visitor access management

8. Data Protection Impact Assessments

Pickseat conducts Data Protection Impact Assessments (DPIAs) for high-risk processing activities.

8.1 When DPIAs are Conducted

  • New processing activities that may pose high risks
  • Significant changes to existing processing activities
  • Processing of special categories of data
  • Implementation of new technologies
  • Large-scale processing of personal data

8.2 DPIA Process

  • Systematic description of the processing
  • Assessment of necessity and proportionality
  • Identification of risks to data subjects
  • Identification of measures to mitigate risks
  • Consultation with the Data Protection Authority where required

9. Data Breach Management

Pickseat has robust procedures in place to detect, report, and investigate personal data breaches.

9.1 Breach Detection

  • 24/7 monitoring for suspicious activity
  • Automated intrusion detection systems
  • Regular security audits and assessments
  • Employee reporting procedures

9.2 Breach Response

  • Immediate containment of the breach
  • Assessment of the risk to data subjects
  • Notification of affected data subjects
  • Notification of the Data Protection Authority
  • Investigation and root cause analysis
  • Implementation of corrective measures

9.3 Reporting Timelines

  • Data Protection Authority: Within 72 hours of becoming aware of the breach
  • Data Subjects: Without undue delay where high risk
  • Internal Reporting: Immediately upon detection

Data breaches can have serious consequences. All employees must report suspected breaches immediately to the Data Protection Officer.

10. Third-Party Processing

Pickseat engages third-party processors for various services. All processors are carefully vetted and subject to data processing agreements.

10.1 Processor Requirements

  • Must comply with applicable data protection laws
  • Must have appropriate technical and organizational measures
  • Must process data only on documented instructions
  • Must ensure adequate security of processing
  • Must report breaches immediately

10.2 Categories of Processors

  • Cloud hosting providers
  • Payment processing services
  • Authentication providers
  • Analytics services
  • Customer support systems
  • Mapping and location services

10.3 Processor Oversight

  • Regular audits of processors
  • Review of processor security practices
  • Sub-processor approval requirements
  • Termination rights for non-compliance

11. International Data Transfers

Pickseat may transfer personal data to countries outside Ghana and the European Economic Area (EEA). Such transfers are subject to appropriate safeguards.

11.1 Transfer Mechanisms

  • Standard Contractual Clauses: EU-approved clauses for data transfers
  • Adequacy Decisions: Where the destination country has been deemed adequate
  • Derogations: Where specific exceptions apply (e.g., explicit consent)

11.2 Data Localization

  • Ghana Data: Primary data storage is in Ghana
  • International Storage: Some data may be stored in other jurisdictions
  • Reasonable Efforts: We make reasonable efforts to keep data within Ghana where feasible

12. Children's Data

Pickseat does not knowingly collect personal data from children under the age of 18. Our platform is intended for adults.

  • Age Verification: We require users to confirm they are 18 or older during registration
  • Detection: We take reasonable steps to detect if a child is using the platform
  • Removal:If we become aware of children's data, we will delete it promptly
  • Parental Consent:In rare cases where children's data is required, we will obtain parental consent

13. Data Subject Requests

Pickseat has procedures in place to handle data subject requests efficiently and in compliance with legal requirements.

13.1 Request Process

  • Submit request via email to makosagroups@gmail.com
  • We will verify the identity of the requester
  • We will respond within 30 days
  • We may extend the response time for complex requests

13.2 Verification

  • We will request additional information to verify identity
  • We will not disclose data without proper verification
  • We may use authentication methods to verify requesters

13.3 Fees

  • Standard Requests: Free of charge
  • Excessive Requests: May be subject to a reasonable fee
  • Manifestly Unfounded: May be refused or subject to a fee

14. Data Protection Officer

Pickseat has appointed a Data Protection Officer (DPO) responsible for overseeing data protection compliance.

14.1 DPO Responsibilities

  • Monitor compliance with data protection laws
  • Provide advice on data protection matters
  • Cooperate with supervisory authorities
  • Act as a point of contact for data subjects
  • Conduct data protection training

14.2 Contact the DPO

  • Email: makosagroups@gmail.com
  • Address: Spintex Road, Accra-Ghana

15. Compliance Monitoring

Pickseat continuously monitors compliance with data protection laws and internal policies.

15.1 Internal Audits

  • Regular internal audits of data protection practices
  • Review of processing activities
  • Assessment of security controls

15.2 External Audits

  • Independent external audits as required
  • Audits by supervisory authorities
  • Third-party security assessments

15.3 Reporting

  • Quarterly compliance reports to management
  • Annual data protection reports
  • Reporting to supervisory authorities as required

16. Record of Processing Activities

Pickseat maintains detailed records of all data processing activities as required by law.

16.1 Record Contents

  • Purpose of processing
  • Categories of data processed
  • Categories of data subjects
  • Recipients of data
  • Retention periods
  • Security measures

16.2 Record Management

  • Records are kept up to date
  • Records are accessible to supervisory authorities
  • Records are retained for the required period

17. Data Subject Complaints

If you have a complaint about how we handle your personal data, please contact us.

17.1 Internal Complaint Process

  • Contact our Data Protection Officer
  • We will investigate your complaint
  • We will respond within 30 days
  • We will work to resolve the issue

17.2 External Complaint Process

If you are not satisfied with our response, you may lodge a complaint with the Data Protection Commission:

  • Data Protection Commission (Ghana)
  • Location: Accra, Ghana
  • Website: www.dataprotection.org.gh

18. Training and Awareness

Pickseat provides regular data protection training to all employees and relevant contractors.

  • Induction Training: All new employees receive data protection training
  • Annual Training: Regular refresher training for all employees
  • Specialized Training: Role-specific training for data handlers
  • Awareness Campaigns: Regular awareness communications

19. Policy Review and Updates

This Data Protection & Compliance Policy is reviewed regularly to ensure it remains current and effective.

  • Annual Review: Comprehensive review of the policy
  • Triggered Reviews: When there are changes in law or business practices
  • Post-Breach Review: After any significant data breach
  • Continuous Improvement: We update our practices based on lessons learned

Version Control: This policy is version-controlled, and all changes are documented.

20. Contact Information

For questions about this policy or data protection matters, please contact:

Pickseat Data Protection Office

Company: Pickseat Transport Services

Email: makosagroups@gmail.com

Address: Spintex Road, Accra-Ghana

Data Protection Officer: Available at makosagroups@gmail.com

21. Acceptance

By using Pickseat, you acknowledge that you have read, understood, and agreed to this Data Protection & Compliance Policy.

We are committed to protecting your privacy and handling your personal data with the utmost care and respect.

© 2026 Pickseat Transport Services. All rights reserved.

This Data Protection & Compliance Policy is for informational purposes only and does not constitute legal advice.