Last Updated: June 26, 2026. Learn how Sendexa protects your personal data in compliance with the General Data Protection Regulation (GDPR).
At Sendexa, we are committed to protecting your privacy and ensuring that your personal data is handled in accordance with the GDPR. This policy explains how we collect, use, and protect your data.
This GDPR Privacy Policy ("Policy") describes how Sendexa ("Company", "we", "us", "our") collects, uses, processes, and protects personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR").
We are committed to transparency in our data processing activities. This Policy applies to all personal data we collect from our users, customers, website visitors, and any other individuals whose personal data we process.
This Policy is an integral part of our Terms of Service and should be read together with our Privacy Policy and Acceptable Use Policy.
✅ Compliance:Sendexa is fully committed to GDPR compliance and data protection by design and by default.
Understanding these key GDPR terms will help you navigate this policy:
Any information relating to an identified or identifiable natural person ("data subject").
Any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
The entity that determines the purposes and means of processing personal data.
The entity that processes personal data on behalf of the data controller.
Freely given, specific, informed, and unambiguous indication of the data subject's agreement to processing.
Sendexa acts as the Data Controller for personal data collected directly from you when you:
Sendexa acts as a Data Processor when you use our Services to process the personal data of your customers, users, or other data subjects. In these cases:
DPA Available:We provide a Data Processing Agreement (DPA) that meets GDPR requirements. Contact us to sign our DPA.
We collect the following categories of personal data:
Our Identity Verification and Fraud Detection services process biometric data under Article 9 GDPR, on the basis of your explicit consent (Article 9(2)(a)), strictly where you or your end users choose to use those services:
Outside of Identity Verification and Fraud Detection, we do not seek to collect other special categories of personal data, including:
⚠️ Important:Please do not send us sensitive personal data through channels other than the Identity Verification service (e.g. message content, support tickets). If you must, ensure you have appropriate consent and legal basis.
We use your personal data for the following purposes:
Under the GDPR, we process your personal data based on the following legal grounds:
You have given explicit consent for specific processing purposes (e.g., marketing communications).
Processing is necessary for the performance of a contract with you (e.g., providing our Services).
Processing is necessary for compliance with legal obligations (e.g., tax and regulatory requirements).
Processing is necessary for our legitimate business interests (e.g., security, analytics, product improvement).
Under the GDPR, you have the following rights regarding your personal data:
You can request a copy of the personal data we hold about you and information about how we process it.
You can request the deletion of your personal data when there is no compelling reason for us to keep it.
You can request your data in a structured, commonly used, and machine-readable format.
You can request correction of inaccurate or incomplete personal data.
You can object to processing based on legitimate interests or direct marketing.
You can request restriction of processing in specific circumstances.
Supervisory Authority:You can lodge a complaint with the Ghana Data Protection Commission or your local data protection authority.
We implement comprehensive technical and organizational measures to protect your personal data:
We retain your personal data for as long as necessary to fulfill the purposes outlined in this Policy:
Retained for the duration of your active account and for 30 days after account termination, unless otherwise required by law.
Retained for up to 12 months for security and audit purposes, then anonymized or deleted.
Retained as necessary to provide the Services and as required by applicable laws and regulations.
Retained for up to 7 years to comply with tax and financial regulations.
You can request deletion of your data at any time by contacting our Data Protection Officer.
👶 Parental Responsibility:Parents and guardians are responsible for supervising their children's use of our Services.
If you have any questions about this Policy or want to exercise your rights, please contact our Data Protection Officer:
Akatsi
Volta Region, Ghana
Monday - Friday: 9:00 AM - 6:00 PM GMT
24/7 data breach reporting available
📋 For data privacy inquiries, contact our DPO at dpo@sendexa.co
Our Data Protection Officer is here to answer your questions about how we process and protect your personal data under GDPR.