Data Protection & GDPR Compliance Statement
1Data Protection Principles
We process personal data in accordance with the following principles, common to both Act 843 and the GDPR:
- Lawfulness, fairness, and transparency: we process data only on a valid legal basis, and we tell you how;
- Purpose limitation: data is collected for specified, explicit purposes, and is not processed further in a manner incompatible with those purposes;
- Data minimisation: we collect only what is necessary to provide the Service;
- Accuracy: we take reasonable steps to keep data accurate and up to date;
- Storage limitation: data is kept only for as long as necessary;
- Integrity and confidentiality: data is protected against unauthorised or unlawful processing, loss, or damage; and
- Accountability: Bisama takes responsibility for, and can demonstrate, compliance with these principles.
2Roles: Controller and Processor
For account, billing, and platform-level data, Bisama Technologies acts as the Data Controller. For business data that a Tenant/Company enters into the Software about its own customers, such as customer names on a receipt, Bisama acts as a Data Processor on behalf of that Tenant/Company, which remains the Controller of that data. Each Tenant/Company is responsible for ensuring it has a lawful basis to collect and process its own customers' data within the Software.
3Your Rights as a Data Subject
Regardless of your location, we extend the following rights to individuals whose personal data we process:
- Right to be informed: to know how your data is collected and used, as set out in our Privacy Policy;
- Right of access: to request a copy of the personal data we hold about you;
- Right to rectification: to correct inaccurate or incomplete data;
- Right to erasure: to request deletion of your data, subject to legal retention obligations;
- Right to restrict processing: to limit how we use your data in certain circumstances;
- Right to data portability: to receive your data in a structured, commonly used, machine-readable format;
- Right to object: to object to processing based on legitimate interests or for direct marketing; and
- Rights related to automated decision-making: Bisama does not use fully automated decision-making that produces legal or similarly significant effects on Users without human involvement.
Requests may be made by emailing info@bisamapos.com. We will verify your identity and respond within thirty days, or as otherwise required by applicable law.
4Lawful Basis for Processing
We rely on one or more of the following lawful bases: performance of a contract with you; your explicit consent; compliance with a legal obligation; and our legitimate interests, such as fraud prevention and service security, always balanced against your fundamental rights and freedoms.
5No Sale or Unlawful Sharing of Personal Data
Consistent with our Privacy Policy, Bisama Technologies does not sell personal data, and does not share personal data with third parties beyond what is strictly necessary to operate the Service, such as payment processors and hosting providers. All such parties are bound by data-processing agreements requiring confidentiality and safeguards equivalent to the GDPR and Act 843.
6International Data Transfers
Where personal data is transferred across borders, for example to cloud infrastructure providers, we ensure that appropriate safeguards are in place, including standard contractual clauses, encryption in transit and at rest, and contractual commitments requiring a level of protection equivalent to Act 843 and the GDPR.
7Data Breach Notification
In the event of a personal data breach that poses a risk to individuals' rights and freedoms, Bisama will, without undue delay and in any event within the timelines required by applicable law, including the GDPR's seventy-two-hour notification standard where it applies, notify the relevant supervisory authority and affected individuals where required.
8Data Protection by Design and by Default
We implement technical and organisational measures, including encryption, access controls, tenant/company data isolation, and regular security reviews, to ensure that data protection principles are embedded into the Software from the design stage, and that only the data necessary for each specific purpose is processed by default.
9Supervisory Authorities
If you are located in Ghana, you may lodge a complaint with the Ghana Data Protection Commission. If you are located in the European Economic Area or the United Kingdom, you may lodge a complaint with your local data protection supervisory authority. We encourage you to contact us first at info@bisamapos.com, so that we may attempt to resolve your concern directly.
10Changes to This Statement
We may revise this Statement to reflect changes in law or in our data practices. The “Last Updated” date at the top of this page indicates when it was last revised.
Bisama POS