Privacy Policy of Loomox Technologies
Effective Date: [20/05/2024]
Last Updated : [09/09/2026]

Loomox Technologies is an IT Service Management (ITSM) company headquartered in Ghana, providing managed IT services, IT support, infrastructure management, application development, cloud solutions, advanced telematics and IoT, cybersecurity, and related managed services, and consultancy to clients locally and globally.

Loomox Technologies operates the https://loomox.digital website for its service provision.

We are committed to protecting the personal data and privacy of our clients, partners, employees, website visitors, and end-users.

This Privacy Policy describes how we collect, use, store, share, and protect personal data when you visit our websites, use our services, communicate with us, or otherwise interact with us. It applies to our activities as a data controller (for our own operations, website visitors, employees, and marketing) and as a data processor (when we process personal data on behalf of clients under IT service contracts).

We comply with Ghana’s Data Protection Act, 2012 (Act 843) and the Data Protection Commission (DPC) requirements, the EU/UK General Data Protection Regulation (GDPR), and other applicable international laws (including principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality, and accountability). Where laws conflict, we apply the higher standard of protection.

By using our services, website, or interacting with us, you consent to the practices outlined in this Policy.

 

Scope of This Policy

This Policy applies to all personal data processed by Loomox Technologies, including data collected through our websites, ITSM platforms, helpdesk/ticketing systems, remote support tools, cloud services, contracts, emails, recruitment processes, and our interactions with clients, vendors, and employees.

 

Personal Data We Collect

We collect only data that is necessary and relevant:

  • Identity and Contact Data: Name, job title, company, email, phone, postal address, identification documents (where legally required).
  • Account and Transaction Data: Client account details, billing information, payment records, service usage logs.
  • Technical and Usage Data: IP address, device identifiers, browser type, cookies, log files, and interaction data from our websites, portals, or support tools.
  • Communications Data: Records of emails, tickets, calls, or chats with our support or sales teams.
  • Special Category or Sensitive Data: Collected only when strictly necessary (e.g., for employment, security clearances, or client-mandated processing) and with appropriate legal basis and safeguards.
  • Client-Provided Data: When acting as processor, we process personal data supplied by or on behalf of our clients (e.g., employee or customer data within IT systems we manage). Clients remain responsible for the lawfulness of that data.

We obtain data directly from you, automatically via our systems and cookies, from clients (as processor), from publicly available sources, or from third-party service providers (with appropriate agreements).

How We Use Personal Data and Legal Bases

We process personal data for these purposes, relying on the following legal bases under Ghana Act 843 and GDPR:

  • To provide, manage, and improve our IT services and fulfil contracts (contractual necessity).
  • To operate our websites, authenticate users, and ensure security (legitimate interests; legal obligation).
  • To communicate about services, support, billing, and updates (contract; legitimate interests; consent where required).
  • For marketing and newsletters (consent; you may withdraw at any time).
  • To comply with legal, regulatory, tax, audit, or law-enforcement obligations (legal obligation).
  • For recruitment, employment, and internal administration (contract; legal obligation; legitimate interests).
  • To protect our rights, prevent fraud, and ensure network/information security (legitimate interests; legal obligation).
  • For analytics and service improvement (legitimate interests; consent for non-essential cookies).

We do not use personal data for automated decision-making that produces legal or similarly significant effects without appropriate safeguards and, where required, human review or consent.

Sharing and Disclosure of Personal Data

We do not sell personal data. We share it only as necessary:

  • With trusted service providers (hosting, payment processors, analytics, security, professional advisers) under written contracts that require confidentiality and data-protection compliance.
  • With affiliates or group companies for internal administration, subject to the same protections.
  • With clients, when we act as processor, strictly in accordance with their instructions and our Data Processing Agreements.
  • When required by law, court order, regulator (including Ghana DPC), or to protect vital interests, rights, or safety.
  • In connection with a merger, acquisition, or asset sale, with appropriate protections for the data.

All recipients are required to implement adequate safeguards.

International Data Transfers

Loomox Technologies is based in Ghana. Personal data may be transferred to, stored, or processed in Ghana, other African countries, the EU/EEA, the UK, the United States, or other jurisdictions where our service providers or clients operate.

For transfers from the EU/UK or other regions with adequacy requirements, we use appropriate safeguards such as:

  • Adequacy decisions where available.
  • Standard Contractual Clauses (SCCs) or equivalent approved mechanisms.
  • Binding corporate rules or other legally recognised tools.
  • Additional technical and organisational measures (encryption, access controls, etc.).

Transfers comply with Ghana Act 843 (adequate protection or DPC authorisation where required) and applicable international rules. You may request details of the safeguards in place.

Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, or disclosure. These include access controls, encryption in transit and at rest where appropriate, regular security assessments, staff training, incident-response procedures, and contracts with processors. No method of transmission or storage is 100% secure; we continuously review and improve our controls.

In the event of a personal-data breach likely to result in risk to individuals, we will notify the Ghana Data Protection Commission (and other relevant authorities) and affected individuals as required by law, without undue delay.

Data Retention

We retain personal data only as long as necessary for the purposes described, to fulfil contracts, meet legal/accounting/audit requirements, or resolve disputes. Retention periods vary by data type and legal obligations (typically aligned with Ghana limitation periods and international standards). When no longer needed, data is securely deleted or anonymised.

Your Rights

Depending on your location and applicable law (Ghana Act 843, GDPR, or others), you have the following rights:

  • Access and obtain a copy of your personal data.
  • Rectification of inaccurate or incomplete data.
  • Erasure (“right to be forgotten”) in certain circumstances.
  • Restriction of processing.
  • Data portability (where processing is based on consent or contract and carried out by automated means).
  • Objection to processing based on legitimate interests or for direct marketing.
  • Withdrawal of consent (does not affect prior lawful processing).
  • Lodge a complaint with a supervisory authority.

To exercise these rights, contact us using the details below. We will respond within the timeframes required by law (generally 30 days under Ghana law, with possible extensions). We may need to verify your identity. Some rights are subject to exceptions (e.g., legal obligations, public interest).

Ghana residents: You may also contact the Data Protection Commission (www.dataprotection.org.gh).

EU/UK residents: You may contact your local Data Protection Authority. Our EU/UK representative details (if appointed) will be provided on request.

Cookies and Similar Technologies

Our websites use cookies and similar technologies for essential functionality, security, analytics, and (with consent) marketing. You can manage preferences via our cookie banner or browser settings. Non-essential cookies require consent. Details are in our Cookie Policy (available on our website).

Children’s Privacy

Our services are not directed at children under 18 (or the applicable age of majority). We do not knowingly collect personal data from children without appropriate parental/guardian consent or as required by law. If we become aware of such collection, we will take steps to delete the data.

Third-Party Websites and Services

Our websites or services may contain links to third-party sites. We are not responsible for their privacy practices. Review their policies before providing data.

Changes to This Policy

We may update this Policy to reflect legal, operational, or service changes. Material changes will be notified via our website, email, or other appropriate means. The “Last Updated” date indicates the current version. Continued use after changes constitutes acceptance where permitted by law.

Contact Us

For questions, to exercise your rights, or to report concerns:

Loomox Technologies
Atlantic Tower, Airport City, Accra, Ghana
Email: privacy@loomox.digital
Phone: +233(0)240173212
Data Protection Officer / Privacy Contact

Loomox Technologies is committed to protecting your privacy and handling personal data responsibly in accordance with Ghanaian and international standards.