1. In short
We collect only data that is relevant to service delivery, account management, support, security, and legal compliance. We do not sell personal data to third parties.
- We process data using clear legal grounds.
- We limit access to authorized personnel and vendors.
- You can request access, correction, deletion, or export.
2. Categories of personal data
The exact data processed depends on the services you use and how you interact with our website and support channels.
Information you provide
- Name, work email, phone number, company, and role.
- Project details, planning notes, and uploaded files.
- Billing and invoicing details submitted for contracts.
- Payment references, invoice status, and provider confirmation details.
- Messages sent through support and contact forms.
Information collected automatically
- Device, browser, and operating system metadata.
- Usage events, log files, and diagnostics.
- Approximate location derived from IP address.
- Cookie and tracker preferences saved on your device.
- Browser storage for theme choices, language preferences, and form drafts.
3. Purpose and legal basis
We process personal data only when there is a defined purpose and an appropriate legal basis under applicable privacy law.
| Processing purpose | Legal basis | Retention snapshot |
|---|---|---|
| Deliver projects and configured features | Contract performance | Project lifecycle and support window |
| Account management and customer support | Contract performance and legitimate interests | Up to 36 months after the last activity |
| Security monitoring, fraud prevention, and abuse detection | Legitimate interests and legal obligations | 6 to 24 months depending on risk logs |
| Service analytics and performance improvement | Legitimate interests and consent (where required) | Up to 24 months in grouped form |
| Accounting, tax, and compliance records | Legal obligation | As required by applicable law |
4. Sharing and international transfers
We share data only with service providers that help us operate infrastructure, communications, analytics, billing, and support.
- All providers are contractually bound to protect data.
- Access is limited to data required for their service scope.
- Where a project or invoice uses Paystack, payment credentials are collected and processed by Paystack, not stored in Faako systems.
- Cross-border transfers use contractual and organizational safeguards.
6. Data retention
We retain data only for the period necessary to fulfill the processing purpose, then securely delete or anonymize it unless longer retention is required by law.
Retention periods vary by category, such as support logs, security events, project files, and financial records.
7. Your rights
Depending on your location, you may exercise the following rights regarding your personal data:
8. Security controls
We maintain administrative, technical, and operational controls that help protect data from unauthorized access, misuse, and loss.
- Role-based access, credential controls, and monitoring.
- Encrypted transport for data in transit.
- Security reviews and incident response procedures.
9. Policy updates
We may update this policy to reflect service, regulatory, or operational changes. Updated versions are posted on this page with a revised date.
10. Contact and requests
To submit a privacy request, email privacy@faako.nanaabaackah.com with the subject line Privacy Request.
You can also review our Terms of Service for related legal terms.
