Last updated: 4 September 2026.
Coriable’s data-protection practices are designed with reference to Ghana’s Data Protection Act, 2012 (Act 843) and guidance from the Data Protection Commission, together with contractual and security responsibilities that apply to the services we provide.
We aim to process personal data for defined purposes, limit collection to relevant information, maintain reasonable accuracy, apply appropriate retention, restrict access and implement safeguards proportionate to the sensitivity and risk of the information.
Depending on the engagement, Coriable may act as a data controller for its own business records and website interactions, or process information on behalf of a client under the applicable service arrangement. Clients remain responsible for defining lawful purposes and instructions for information they control.
Safeguards can include access control, authentication, MFA for privileged operations, secure software development, audit logging, vulnerability review, encrypted transport, private document storage, integrity controls, backup/restore procedures, incident response and vendor/integration review.
Cloud, communication, payment, identity or other providers may process information in different jurisdictions. Provider selection should consider security, contractual terms, data location, access and the nature of the information involved.
Suspected data or security incidents are assessed using documented incident-response procedures. Containment, evidence preservation, impact assessment, recovery and any required notification depend on the facts and applicable obligations.
Individuals or client organisations can contact Coriable through the published channels for data-protection enquiries, corrections, access concerns or other applicable requests.
If you want to request access, correction, deletion where applicable, restriction, objection, consent withdrawal or raise a privacy complaint, use our secure privacy-rights workflow.
Submit a privacy requestCoriable may process first-party website analytics such as pages viewed, anonymous visitor/session identifiers, referrers, campaign tags, browser/device characteristics, approximate country/region/city when supplied by the trusted network edge, and engagement events such as scroll depth or calls-to-action clicked. Form-field contents are not captured by the analytics tracker.
For security, fraud prevention and abuse investigation, source IP addresses may be retained for a limited period in encrypted form, together with request metadata and risk signals. Browser GPS/location permission is not requested by this system. Retention and analytics controls are configurable by Coriable administrators.