Privacy Policy
Review required before launch. Items tagged [REVIEW: ...] below are placeholders the business must confirm with counsel and the Ghana Data Protection Commission before this policy goes live. Every occurrence is resolved via the single source of truth at src/lib/legal/config.ts.
1. Who we are
Vedge Technologies Ltd is a company incorporated in the Republic of Ghana under registration number [REVIEW: Ghana RGD company registration number], with its registered office at [REVIEW: registered office address — Ghana company registration].
Vedge is registered with the Ghana Data Protection Commission as a Data Processor under §46 of the Data Protection Act 2012 (Act 843). Our registration number is [REVIEW: Ghana DPC Data Processor Registration Number — §46 DPA 2012], valid until [REVIEW: DPC registration expiry date].
2. Scope of this policy
Vedge plays two distinct roles depending on whose data is being processed. This policy covers both, and you should read the section relevant to your relationship with us.
2.1 Data Vedge controls directly
We are the “data controller” for information we collect directly from you:
- Visitors to https://tryvedge.com
- Prospective customers who request a demo or contact us
- Tenant admins who register and use the dashboard
- Staff of tenants who log in to perform their work
2.2 Data Vedge processes on a tenant’s behalf
When a healthcare organisation (hospital, clinic, lab, pharmacy, diagnostic centre) uses Vedge to record patient information, that organisation is the data controllerand Vedge is the “data processor.” We process patient health information (PHI) only on the tenant’s documented instructions, under a binding Data Processing Agreement. For patient-facing questions about how your clinic uses Vedge, see our Patient Privacy Notice.
3. Data we collect
3.1 As controller (our data)
- Identity + contact: name, work email, phone, job title, organisation name.
- Authentication: password hashes, MFA device tokens, login history.
- Device + usage telemetry: IP address, browser, pages visited, feature usage, error traces.
- Cookies + local storage: strictly-necessary, analytics (consented), and preference cookies. See Cookie Policy.
- Billing: card metadata (last 4 digits, expiry) via our payment processors. We never see full PANs.
3.2 As processor (patient health data)
- Patient demographics, contact, and identifiers (Ghana Card, NHIS, passport).
- Clinical records: encounters, diagnoses, prescriptions, lab results, imaging reports, referrals, vitals, allergies.
- Appointment and billing records generated by the tenant’s facility.
- Audit metadata — who looked at what, when — retained for 6 years from event.
4. Lawful basis for processing
Under §27 of the Data Protection Act 2012, every processing activity must have a lawful basis. We rely on the following:
- Contract performance (§27(1)(b)) — for everything we do to run the SaaS product for our tenants.
- Consent (§27(1)(a)) — for marketing communications, analytics cookies, and the AI diagnostic assist feature (which is tenant-opt-in only).
- Legal obligation (§27(1)(c)) — for tax, statutory reporting to the Ministry of Health (via DHIS2), anti-money-laundering checks on payment flows.
- Legitimate interest (§27(1)(f)) — for security logging, fraud prevention, and service improvement (with data minimisation).
- Vital interests (§27(1)(d)) — narrowly, for emergency clinical access flows where a treating clinician needs a patient record without prior consent.
5. How we use your data
We process personal data to:
- Provide, maintain, and secure the Vedge platform for our tenants.
- Authenticate users and enforce access controls (RBAC).
- Route clinical workflows — appointment reminders, lab result notifications, imaging report share-links — on the tenant’s behalf.
- Bill tenants for their subscription and any enabled add-ons.
- Communicate service changes, security advisories, and required legal notices.
- Improve the platform through aggregated, de-identified analytics.
We do not sell personal data, use it to train third-party AI models, or share it for advertising.
6. Retention
Retention periods vary by data type:
- Patient clinical records (processor role): retained for the duration of the tenant’s relationship with the patient, plus the windows below to meet HEFRA minimum standards —
- Adult records: 6 years from last interaction
- Minor records: 12 years from the minor's age of majority (21)
- Maternal + death records: indefinitely
- Audit log: 6 years from event.
- Billing records: 6 years (Ghana Revenue Authority requirement).
- Marketing contacts: until unsubscribed, + 2 years.
On termination of a tenant’s subscription, data is exportable for 60 days in the following formats: PostgreSQL dump (tenant schema), CSV bundle per entity, FHIR R4 bundle (selected resources). After the export window, data is deleted or irreversibly anonymised.
8. International transfers
Under §§47–48 of the Data Protection Act 2012, patient data may be transferred outside Ghana only where the destination provides an adequate level of protection or the data subject has consented. Vedge maintains Standard Contractual Clauses (SCCs) with every sub-processor that processes data outside Ghana. The current destinations are:
- AWS / Cloudflare — infrastructure hosting + CDN (South Africa, Ireland, US edge). SCCs in place.
- OpenAI — optional AI diagnostic assist (United States). Tenant-opt-in only; zero-data-retention agreement in effect.
- Stripe — card processing (Ireland / United States). No clinical data transmitted.
- Paystack, Flutterwave — mobile money + card (Nigeria / United States). No clinical data transmitted.
- mNotify — SMS delivery (Ghana; intra-jurisdiction).
- Resend — transactional email (United States). No clinical data in message bodies.
Tenants may opt out of AI-based processing at any time via the tenant admin console.
9. Your rights
Under §§32–36 of the Data Protection Act 2012 you have the right to:
- Access — a copy of the personal data we hold about you.
- Rectification — correction of inaccurate or incomplete data.
- Erasure — deletion of personal data, subject to overriding legal retention obligations.
- Objection — to specific processing activities, including direct marketing.
- Portability — your data in a structured, machine-readable format.
- Withdraw consent — at any time, without affecting the lawfulness of prior processing.
Requests should be sent to dpo@tryvedge.com. We respond within 21 calendar days, as required by the DPA.
Patients: for data your clinic holds in Vedge, contact your clinic first — they are the data controller. Vedge acts as a fallback if they do not respond.
10. Security
We apply technical and organisational measures appropriate to the risk, as required by §§17–18 of the DPA. A full list is on our Security page. Highlights:
- AES-256 encryption at rest, TLS 1.2+ in transit.
- Role-based access control, least-privilege, just-in-time admin access to production.
- Multi-tenant schema isolation — one tenant cannot access another tenant’s data through the application or the database.
- Append-only audit log of every PHI access, retained for 6 years from event.
- Annual third-party penetration test.
- Documented responsible-disclosure channel at security@tryvedge.com.
11. Breach notification
If Vedge experiences a personal-data breach, we notify the affected tenant within 48 hours of confirming the breach. Tenants remain the notifiers of record to the Data Protection Commission and to data subjects, and we provide the technical information they need to meet their own obligations.
For incidents that meet the Cybersecurity Authority’s Critical Information Infrastructure reporting threshold, we commit to a 24 hours to CSA for designated CII operators so tenant CII operators can meet their own clock.
12. Children
Vedge does not knowingly collect data directly from children. Paediatric records in the platform exist because a tenant clinic is caring for that child; the child’s parent or guardian provides the consent and exercises the data-subject rights on their behalf until they reach the age of majority.
13. Data Protection Officer
Our Data Protection Officer, appointed under §58 of the DPA, is the named contact point for all data-protection matters:
- Name: [REVIEW: named DPO — required by §58 DPA 2012]
- Email: dpo@tryvedge.com
- Phone: [REVIEW: DPO contact number]
- Postal: [REVIEW: registered office address — Ghana company registration]
14. Changes to this policy
We review this policy at least annually and update it whenever there is a material change to our processing activities. The “Last updated” date at the top of the page reflects the most recent material change. For changes that affect your rights, we provide reasonable advance notice by email to tenant admins and by in-dashboard notification.
15. Complaints
If you believe we have mishandled your personal data, please write to dpo@tryvedge.com first — we would like the chance to resolve it. If you are not satisfied with our response, you have the right to lodge a complaint with the Data Protection Commission, Ghana.