Privacy Policy

1. Who We Are

This Privacy Policy explains how DoubleOsec Ltd, also known as DoubleOsec or OOSEC, collects, uses, shares and protects personal data when you visit https://oosecgh.com/, contact us, purchase a product or service, attend an activity we administer, or otherwise interact with us.

DoubleOsec Ltd is a company registered in Ghana under company registration number 1943226. Our office is at BO59 Mendskrom, opposite Jayee University, Accra, Ghana.

For general questions or privacy requests, contact info@oosecgh.com.

2. When This Policy Applies

This Policy applies to personal data for which DoubleOsec determines the purpose and manner of processing, including website, enquiry, marketing, customer-relationship and business-administration data.

During some cybersecurity engagements, we may process personal data on behalf of a client and under that client’s instructions. In those situations, the client is generally responsible for the primary privacy notice, and our handling of the data is also governed by the client agreement or a data-processing agreement.

3. Personal Data We May Collect

Depending on how you interact with us, we may collect:

Contact and identity information

Your name, job title, organisation, email address, phone number, business address and other information you provide when contacting us or registering for a service.

Business and engagement information

Requests for quotation, service requirements, contracts, authorised contacts, correspondence, meeting notes, support requests, feedback and information needed to deliver an engagement.

Payment and transaction information

Invoice details, payment status, amount, transaction reference and the payment method selected. Online payment information may be processed by Paystack or another approved payment provider. We do not receive or store full card numbers, card verification values or payment account credentials processed directly by the payment provider.

Website and device information

Internet Protocol address, browser type, device type, pages visited, referring page, approximate location derived from an IP address, date and time of access, cookie identifiers and security logs.

Security-service data

Where required for an authorised engagement, we may process system identifiers, account names, network and endpoint telemetry, logs, vulnerability evidence, incident information and other technical data supplied by the client or generated during delivery. This information may sometimes contain personal data. Its scope and handling are governed by the applicable engagement terms.

Training and event information

Registration details, attendance, organisation, role, dietary or accessibility information where voluntarily provided and necessary, assessment results, certificates and participant feedback.

We ask that you do not send passwords, private keys, full payment-card details or sensitive security evidence through our general website forms or email unless we have provided an approved secure method.

4. How We Collect Personal Data

We may collect personal data:

  • directly from you through forms, email, telephone, meetings, contracts, registrations and payments;

  • from your employer or organisation when it appoints you as a contact or user;

  • through authorised security tools and systems used to deliver a contracted service;

  • automatically through website logs, cookies and similar technology; and

  • from lawful public sources, partners, professional contacts or service providers where relevant to a legitimate business purpose.

5. Why We Use Personal Data

We may use personal data to:

  • respond to enquiries and prepare proposals or quotations;

  • verify identity, authority and business information;

  • enter into and administer contracts;

  • deliver cybersecurity services, products, support, training and events;

  • create and manage authorised user accounts;

  • process payments, invoices, refunds and financial records;

  • communicate service notices, security alerts and administrative information;

  • protect our website, systems, clients and users against fraud, misuse and cyber threats;

  • maintain service quality, investigate complaints and improve our offerings;

  • meet legal, regulatory, licensing, tax, audit and record-keeping obligations;

  • establish, exercise or defend legal claims; and

  • send marketing communications where you have consented or where otherwise permitted by law.

We process personal data only where there is an appropriate legal justification, which may include consent, steps taken at your request before a contract, performance of a contract, compliance with a legal obligation, protection of vital interests, or a legitimate and lawful business purpose. Where we rely on consent, you may withdraw it, but withdrawal does not affect processing that was lawful before withdrawal.

6. Marketing Communications

We may send updates about relevant DoubleOsec services, products, training or events where you have agreed to receive them or where applicable law permits. You can opt out at any time by using the unsubscribe option in the message or contacting info@oosecgh.com.

We will not use personal data for direct marketing where consent is required and has not been obtained.

7. Cookies and Similar Technology

Our website may use cookies and similar technology for essential site functions, security, preferences, traffic measurement and, where enabled with appropriate consent, marketing.

You can manage non-essential cookies through the cookie banner or your browser settings. Blocking some cookies may affect website features. More information is available in our Cookie Policy.

8. When We Share Personal Data

We may share limited personal data with:

  • personnel and approved subcontractors who need it to perform their duties;

  • hosting, cloud, communications, customer-support, analytics and security providers;

  • Paystack and other payment providers for transaction processing and fraud prevention;

  • professional advisers, auditors, insurers and financial institutions;

  • a client organisation where you interact with us on its behalf;

  • regulators, law-enforcement bodies, courts or public authorities where disclosure is required or lawfully requested; and

  • a successor or relevant party during a proposed merger, acquisition, financing, reorganisation or transfer of business assets, subject to appropriate confidentiality and data-protection measures.

We do not sell personal data.

Service providers are expected to process personal data only for the authorised purpose and to apply suitable safeguards.

9. International Data Transfers

Some service providers may process data outside Ghana. Where personal data is transferred internationally, we will take reasonable steps to use a lawful transfer method and require appropriate protection, considering the nature of the data and the applicable legal requirements.

Client security data will be hosted or transferred according to the applicable contract and agreed service architecture.

10. Data Retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, including service delivery, security, dispute resolution and legal, tax, audit, licensing and regulatory obligations.

Retention periods vary by data type. Contract and financial records may be retained for the applicable statutory period. Security evidence and client engagement data are retained, returned or deleted according to the applicable agreement, our documented retention procedures and legal requirements. Backup copies may remain for a limited period until they are securely overwritten through routine cycles.

11. How We Protect Personal Data

We use administrative, technical and physical safeguards appropriate to the sensitivity and risk of the data. These may include access control, authentication, encryption where appropriate, secure transfer methods, logging, confidentiality duties, staff awareness and review of service providers.

No electronic system is completely secure. If a personal-data incident occurs, we will investigate, contain and respond to it and make required notifications in accordance with applicable law and contracts.

12. Your Data-Protection Rights

Subject to applicable law and relevant exemptions, you may have the right to:

  • be informed about the collection and use of your personal data;

  • request access to personal data we hold about you;

  • request correction of inaccurate or incomplete personal data;

  • object to or request that certain processing stop where it causes or is likely to cause unwarranted damage or distress;

  • withdraw consent where processing is based on consent;

  • object to direct marketing;

  • request appropriate review of a decision based solely on automated processing where it significantly affects you; and

  • complain to us or to the Data Protection Commission of Ghana.

To make a request, email info@oosecgh.com with the subject “Privacy Request”. We may need to verify your identity and authority before responding. If we process the information only on behalf of a client, we may refer your request to that client.

You may also contact the Data Protection Commission of Ghana through https://dataprotection.org.gh/.

13. Children’s Information

Our general website and commercial services are not directed to children. We do not knowingly collect personal data from a child through this website without an appropriate lawful basis and, where required, the involvement of a parent, guardian, school or responsible organisation.

If a youth training or educational programme requires participant information, a specific notice and consent process may be provided for that programme. If you believe a child’s information has been submitted to us inappropriately, contact info@oosecgh.com.

14. Third-Party Links

Our website may link to third-party websites, platforms or social media pages. Their privacy practices are controlled by their operators. Review the applicable privacy notice before submitting personal data to an external service.

15. Changes to This Policy

We may update this Privacy Policy to reflect operational, service or legal changes. The latest version will be published on this page with its effective date. Material changes may also be communicated through another appropriate channel.

16. Contact Us

DoubleOsec Ltd
Company registration number: 1943226
BO59 Mendskrom, opposite Jayee University, Accra, Ghana
GhanaPost GPS: [insert confirmed digital address]
Email: info@oosecgh.com
Phone: (+233) 30 285 2909