GDPR Compliance

GDPR Privacy Policy

Last Updated: June 26, 2026. Learn how Sendexa protects your personal data in compliance with the General Data Protection Regulation (GDPR).

Effective: June 26, 2026
Version: 1.0
GDPR Compliant

Our Commitment

At Sendexa, we are committed to protecting your privacy and ensuring that your personal data is handled in accordance with the GDPR. This policy explains how we collect, use, and protect your data.

1. Introduction

This GDPR Privacy Policy ("Policy") describes how Sendexa ("Company", "we", "us", "our") collects, uses, processes, and protects personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR").

We are committed to transparency in our data processing activities. This Policy applies to all personal data we collect from our users, customers, website visitors, and any other individuals whose personal data we process.

This Policy is an integral part of our Terms of Service and should be read together with our Privacy Policy and Acceptable Use Policy.

✅ Compliance:Sendexa is fully committed to GDPR compliance and data protection by design and by default.

2. Key Definitions

Understanding these key GDPR terms will help you navigate this policy:

Personal Data

Any information relating to an identified or identifiable natural person ("data subject").

Processing

Any operation performed on personal data, including collection, storage, use, disclosure, and deletion.

Data Controller

The entity that determines the purposes and means of processing personal data.

Data Processor

The entity that processes personal data on behalf of the data controller.

Consent

Freely given, specific, informed, and unambiguous indication of the data subject's agreement to processing.

3. Data Controller & Processor

3.1 Data Controller

Sendexa acts as the Data Controller for personal data collected directly from you when you:

  • Create an account with Sendexa
  • Visit our website and use our services
  • Contact us for support or inquiries
  • Sign up for our newsletters or communications

3.2 Data Processor

Sendexa acts as a Data Processor when you use our Services to process the personal data of your customers, users, or other data subjects. In these cases:

  • You are the Data Controller
  • We process data only according to your instructions
  • We have Data Processing Agreements (DPAs) in place
  • We implement appropriate technical and organizational measures

DPA Available:We provide a Data Processing Agreement (DPA) that meets GDPR requirements. Contact us to sign our DPA.

4. Data We Collect

We collect the following categories of personal data:

4.1 Account Information

  • Full name and email address
  • Phone number and contact details
  • Company name and business information
  • Billing and payment information
  • Account preferences and settings

4.2 Usage Data

  • API call logs and usage patterns
  • Message content and communication metadata
  • Device and browser information
  • IP addresses and geolocation data
  • Performance and error logs

4.3 Communication Data

  • Messages sent and received through our Services
  • Call records and voice data
  • Support tickets and correspondence
  • Survey responses and feedback

4.4 Special Categories of Data

Our Identity Verification and Fraud Detection services process biometric data under Article 9 GDPR, on the basis of your explicit consent (Article 9(2)(a)), strictly where you or your end users choose to use those services:

  • Identity documents (passports, national IDs, driver's licenses) submitted for KYC verification
  • Facial images and biometric templates used for liveness detection and identity matching

Outside of Identity Verification and Fraud Detection, we do not seek to collect other special categories of personal data, including:

  • Racial or ethnic origin
  • Political opinions or religious beliefs
  • Health data
  • Sexual orientation or sexual life
  • Trade union membership

⚠️ Important:Please do not send us sensitive personal data through channels other than the Identity Verification service (e.g. message content, support tickets). If you must, ensure you have appropriate consent and legal basis.

5. How We Use Your Data

We use your personal data for the following purposes:

Service Delivery
  • Provide and maintain our Services
  • Process API requests and communications
  • Manage your account and billing
Security & Compliance
  • Monitor for security threats and fraud
  • Ensure compliance with legal obligations
  • Enforce our Terms of Service and AUP
Product Improvement
  • Analyze usage patterns and trends
  • Develop new features and services
  • Optimize performance and user experience
Communications
  • Send service updates and notifications
  • Respond to support inquiries
  • Provide marketing communications (with consent)

7. Data Sharing & Transfers

7.1 Data Sharing

We share your personal data with:

  • Service Providers: Third-party vendors who help us deliver our Services (e.g., cloud providers, payment processors).
  • Business Partners: With your consent, we may share data with trusted partners.
  • Legal Authorities: When required by law or to protect our rights and safety.

7.2 International Data Transfers

  • We operate globally and may transfer data to countries outside the EEA.
  • All transfers are protected by appropriate safeguards, including:
    • Standard Contractual Clauses (SCCs)
    • EU-US Data Privacy Framework (where applicable)
    • Adequacy decisions by the European Commission
  • You can request a copy of our transfer safeguards.

Data Transfers:We ensure that all international data transfers comply with GDPR requirements and provide adequate protection.

8. Your Data Subject Rights

Under the GDPR, you have the following rights regarding your personal data:

Right to Access

You can request a copy of the personal data we hold about you and information about how we process it.

Right to Erasure

You can request the deletion of your personal data when there is no compelling reason for us to keep it.

Right to Data Portability

You can request your data in a structured, commonly used, and machine-readable format.

Right to Rectification

You can request correction of inaccurate or incomplete personal data.

Right to Object

You can object to processing based on legitimate interests or direct marketing.

Right to Restrict Processing

You can request restriction of processing in specific circumstances.

8.1 How to Exercise Your Rights

  • Submit your request via email to dpo@sendexa.co
  • We will respond to your request within 30 days of receipt.
  • We may need to verify your identity before processing.
  • You have the right to lodge a complaint with a supervisory authority.

Supervisory Authority:You can lodge a complaint with the Ghana Data Protection Commission or your local data protection authority.

9. Data Security

We implement comprehensive technical and organizational measures to protect your personal data:

Encryption
  • Data encrypted in transit (TLS 1.3)
  • Data encrypted at rest (AES-256)
Access Control
  • Role-based access control (RBAC)
  • Multi-factor authentication required
Infrastructure
  • Secure, SOC 2 compliant data centers
  • Regular security audits and penetration testing
Training & Policies
  • Employee security awareness training
  • Clear data protection policies and procedures

9.1 Data Breach Response

  • We have a comprehensive Data Breach Response Plan in place.
  • We will notify affected users within 72 hours of becoming aware of a breach.
  • We will cooperate with supervisory authorities in investigating breaches.

10. Data Retention

We retain your personal data for as long as necessary to fulfill the purposes outlined in this Policy:

Account Data

Retained for the duration of your active account and for 30 days after account termination, unless otherwise required by law.

Usage & Log Data

Retained for up to 12 months for security and audit purposes, then anonymized or deleted.

Message Content

Retained as necessary to provide the Services and as required by applicable laws and regulations.

Billing Data

Retained for up to 7 years to comply with tax and financial regulations.

You can request deletion of your data at any time by contacting our Data Protection Officer.

11. Cookies & Tracking

We use cookies and similar tracking technologies to enhance your experience:

Essential Cookies

Required for basic functionality and security. Cannot be disabled.

Analytics Cookies

Help us understand how users interact with our website.

Preference Cookies

Remember your preferences and settings.

Marketing Cookies

Used to deliver relevant advertisements (with consent).

11.1 Cookie Consent

  • We request explicit consent before setting non-essential cookies.
  • You can withdraw your consent at any time.
  • You can manage cookie preferences through your browser settings.
  • We respect Do Not Track (DNT) signals where possible.

12. Children's Data

  • Our Services are not directed to children under the age of 16 (or applicable age in your jurisdiction).
  • We do not knowingly collect personal data from children without parental consent.
  • If you believe we have collected data from a child, please contact us immediately.
  • We will delete such data promptly upon discovery, unless legally required to keep it.

👶 Parental Responsibility:Parents and guardians are responsible for supervising their children's use of our Services.

13. Changes to This Policy

  • We may update this Policy from time to time.
  • We will notify you of significant changes via email or platform notification.
  • Continued use of our Services after changes constitutes acceptance of the updated Policy.
  • If you do not agree to the changes, you must stop using our Services.
  • The "Last Updated" date at the top indicates when this Policy was last revised.

14. Contact Us

If you have any questions about this Policy or want to exercise your rights, please contact our Data Protection Officer:

Email
dpo@sendexa.co

Data Protection Officer

Phone
+233 555 539 152

Privacy Team

Address

Akatsi
Volta Region, Ghana

Hours

Monday - Friday: 9:00 AM - 6:00 PM GMT
24/7 data breach reporting available

📋 For data privacy inquiries, contact our DPO at dpo@sendexa.co

Questions About Data Privacy?

Our Data Protection Officer is here to answer your questions about how we process and protect your personal data under GDPR.