GDPR Compliance

Your data rights. Our commitments.

Overview

At Sporafind, we are deeply committed to protecting the privacy and personal data of our users. This page explains how we comply with the General Data Protection Regulation (GDPR) — the European Union's comprehensive data protection framework — and what that means for you as a data subject. We process personal data lawfully, fairly, and transparently, and we have designed our platform with privacy at its core.

This GDPR Compliance page applies to all users of the Sporafind platform, website visitors, and individuals whose data may appear in our diaspora intelligence datasets. It describes our role as both data controller and data processor, the legal bases we rely on, the rights you hold, and the measures we take to safeguard your information.

Data Controller Information

Sporafind is a product of Gabochie Intelligence Ltd, a Ghanaian company headquartered in Accra, Ghana. We act as the data controller for the personal data we collect directly from our users and platform visitors.

Data Controller

Sporafind / Gabochie Intelligence Ltd
Accra, Ghana
Email: privacy@sporafind.com

Data Protection Officer

We have appointed a Data Protection Officer (DPO) who is responsible for overseeing our data protection strategy and ensuring our compliance with GDPR requirements. The DPO serves as the primary point of contact for data subjects and supervisory authorities.

Data Protection Officer

DPO, Gabochie Intelligence Ltd
Email: dpo@sporafind.com
All enquiries related to data protection, privacy, and GDPR rights should be directed to this address. We commit to responding to all legitimate requests within the statutory timeframe of one month.

Legal Basis for Processing

Under the GDPR, we are required to establish a lawful basis for any processing of personal data. Sporafind relies on the following legal bases depending on the context of processing:

Your Rights Under GDPR

As a data subject, you have the following rights under the GDPR. We have designed our systems and processes to enable you to exercise these rights freely and without hindrance.

Right to Access

You have the right to obtain confirmation of whether we process your personal data and, if so, to request a copy of that data along with information about our processing activities.

Right to Rectification

If your personal data is inaccurate or incomplete, you have the right to have it corrected or completed without undue delay.

Right to Erasure

Also known as the "right to be forgotten," this entitles you to request the deletion of your personal data where it is no longer necessary for the purposes collected, or where you withdraw consent or object to processing.

Right to Restrict Processing

You may request that we restrict the processing of your data while we verify its accuracy, consider an objection, or determine whether our legitimate grounds override your interests.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller without hindrance from us.

Right to Object

You may object, on grounds relating to your particular situation, to processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we demonstrate compelling legitimate grounds.

Data We Collect and Why

We collect and process only the personal data that is necessary for the specific purposes for which it was obtained. Below is a summary of the categories of data we process and the purposes of processing:

We do not process special categories of personal data (sensitive data such as race, religion, health, or political opinions) unless you have explicitly provided such information in a support communication. Where we do, we will seek your explicit consent.

Data Retention Periods

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. Our retention schedules are as follows:

When retention periods expire, personal data is securely deleted or anonymised so that it can no longer be attributed to an identifiable individual.

International Data Transfers

Sporafind operates globally, and your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). Where we transfer personal data from the EEA to countries not deemed adequate by the European Commission, we rely on Standard Contractual Clauses (SCCs) adopted by the European Commission as an appropriate safeguard under Article 46 of the GDPR.

Our primary infrastructure is hosted in the United States through Google Cloud Platform and Amazon Web Services. Both providers are certified under the EU-US Data Privacy Framework and have executed SCCs with us. We conduct Transfer Impact Assessments (TIAs) for all international data flows to ensure an equivalent level of protection is maintained.

If you would like a copy of the relevant SCCs or further information about our transfer safeguards, please contact our DPO at dpo@sporafind.com.

Security Measures

We implement a comprehensive set of technical and organisational security measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, and access. Our security programme includes:

Subprocessors

We engage trusted third-party service providers (subprocessors) to assist in delivering the Sporafind platform. Each subprocessor is subject to a Data Processing Agreement (DPA) that reflects the requirements of Article 28 of the GDPR. Current subprocessors include:

We review our subprocessor list at least annually. If we engage a new subprocessor that processes personal data, we will update this page and notify affected users via email or in-app notification at least 30 days prior to engagement.

Data Breach Notification Process

Sporafind has implemented a robust data breach detection, investigation, and notification process that complies with Articles 33 and 34 of the GDPR. In the unlikely event of a personal data breach:

How to Exercise Your Rights

You may exercise any of your GDPR rights by submitting a request through the form below or by contacting our DPO directly:

Contact Our DPO

Email: dpo@sporafind.com
Response time: We commit to responding to all legitimate requests within 30 days. In complex cases or where we receive a high volume of requests, we may extend this period by a further 60 days, but we will inform you of any such extension within the first 30 days.

When submitting a request, we may need to verify your identity before processing your request. This is a security measure to ensure that personal data is not disclosed to unauthorised persons. We may ask for additional information reasonably necessary to confirm your identity.

Please be as specific as possible in your request to help us process it efficiently. If you are requesting access to or deletion of data that appears in our diaspora intelligence datasets, please provide sufficient identifying information (such as name, approximate location, and professional context) so that we can accurately locate and process your data.

Complaints

If you believe that our processing of your personal data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your habitual residence, place of work, or place of the alleged infringement.

We encourage you to contact our DPO first so that we may address your concerns directly and resolve any issues promptly. You may also contact the Ghana Data Protection Commission (DPC) as our lead supervisory authority in Ghana, or the data protection authority in your country of residence if you are located in the European Union.

Submit a GDPR Request

Use this form to submit an access, rectification, erasure, restriction, portability, or objection request. We will respond within 30 days.

Request submitted

Thank you. We have received your GDPR request and will review it within 30 days. A confirmation has been sent to your email address. If you have any urgent enquiries, please contact dpo@sporafind.com.