This Privacy Policy is published by Vikalink Domain And Hosting, a web hosting and internet services business legally registered and operating in the Republic of Ghana.
As the data controller, Vikalink determines the purposes and means of processing your personal data. This policy applies to all services we operate, including our website, client dashboard, hosting infrastructure, domain management platform, and support channels.
We collect only the personal data that is necessary to provide our services and improve your experience with us. The categories of data we collect include:
Data We Do Not Collect
- We do not collect sensitive personal data such as racial or ethnic origin, political opinions, religious beliefs, biometric data, or health information.
- We do not store full payment card numbers or Mobile Money PINs at any point.
- We do not knowingly collect data from children under 18 without verifiable parental consent.
Directly From You
- When you register an account on our client portal
- When you place an order for hosting, a domain, or any other service
- When you contact our support team via ticket, live chat, email, WhatsApp, or phone
- When you subscribe to our newsletter or marketing communications
- When you complete surveys or provide feedback
Automatically
- Server and application access logs generated when you visit our website or use your hosting account
- Cookies and similar tracking technologies placed on your browser (see Section 9)
- Analytics tools that record aggregate usage patterns on our website
- Security monitoring systems that log unusual or suspicious access patterns
From Third Parties
- Payment processors (Paystack, Flutterwave, Stripe, PayPal) who confirm transaction status and flag fraudulent activity
- Domain registrar partners who provide WHOIS and registration verification data
- Our fraud prevention partners who may provide risk-scoring data on transactions
| Purpose | Data Used | Basis |
|---|---|---|
| Account creation & management | Identity, Contact | Contract |
| Service provisioning (hosting setup, domain registration) | Identity, Contact, Technical | Contract |
| Billing, invoicing & payment processing | Identity, Contact, Payment | Contract |
| Customer support (tickets, chat, WhatsApp) | Identity, Contact, Communications | Contract |
| Security, fraud prevention & abuse detection | Technical, Usage, Payment | Legitimate Interest |
| Service notifications (renewals, downtime, maintenance) | Identity, Contact | Contract |
| Platform improvement & analytics | Usage, Technical | Legitimate Interest |
| Marketing & promotional emails | Identity, Contact | Consent |
| Legal compliance & law enforcement requests | All categories as required | Legal Obligation |
In accordance with Ghana's Data Protection Act 2012 (Act 843) and GDPR principles, we rely on one or more of the following legal bases when processing your personal data:
Contractual Necessity
The majority of data processing we carry out is necessary to perform the contract we have with you — i.e., to provide the hosting services, manage your domain, process your payment, and support your account. Without this processing, we cannot fulfil your order.
Legitimate Interests
We process certain data on the basis of our legitimate business interests, such as detecting fraud, maintaining server security, improving our platform, and sending service-related communications. We always balance our legitimate interests against your rights and freedoms before relying on this basis.
Consent
Where we rely on consent — primarily for marketing emails and non-essential cookies — we will ask for your explicit opt-in. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
Legal Obligation
We may be required by Ghanaian law, court order, or valid request from a law enforcement authority to process or disclose certain data. In such cases, we will comply with our legal obligations while taking all reasonable steps to protect your interests.
We never sell your personal data. Vikalink does not sell, rent, or trade your personal information to advertisers, data brokers, or any third party for commercial gain.
We share data only in the limited circumstances described below, and always under strict data processing agreements:
| Recipient | Purpose | Data Shared |
|---|---|---|
| Payment Processors Paystack, Flutterwave, Stripe, PayPal |
Processing payments and detecting fraud | Name, email, billing address, transaction amount |
| Domain Registrars ICANN-accredited partners, NIC Ghana |
Domain registration, transfer, renewal | Registrant contact details (WHOIS data) |
| Infrastructure Providers Data centre operators in EU, UK, USA |
Hosting and storing service data | Server usage data; no direct customer PII beyond what is in hosted files |
| Customer Support Tools Ticketing, live chat platforms |
Delivering support services | Name, email, support ticket content |
| Email Service Providers | Sending transactional and marketing emails | Email address, name |
| Law Enforcement / Courts | Compliance with legal obligations | Data as required by valid legal order |
All third-party processors are required to handle your data in accordance with applicable data protection laws and our data processing agreements. They may not use your data for their own purposes beyond what is specified.
As Vikalink's servers are located in the European Union (Frankfurt, Germany), the United Kingdom (London), and the United States of America, your personal data will inevitably be processed in jurisdictions outside Ghana.
We ensure that all cross-border transfers are protected by one or more of the following safeguards:
- EU/UK: The EU and UK are recognised as jurisdictions providing an adequate level of data protection. Processing in our Frankfurt and London data centres is governed by GDPR, which meets or exceeds Ghana's Data Protection Act standards.
- USA: Data transfers to US-based infrastructure are governed by Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring equivalent protections apply.
- All international data processing partners are contractually bound to implement appropriate technical and organisational security measures.
You may request details of the specific safeguards in place for any international transfer of your data by contacting us at privacy@vikalink.com.
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected and to comply with our legal obligations. Our standard retention periods are:
| Data Category | Retention Period | Reason |
|---|---|---|
| Account & identity data | Duration of account + 3 years | Contract fulfilment; fraud prevention |
| Billing & payment records | 7 years | Ghana Revenue Authority tax compliance |
| Server & access logs | 90 days rolling | Security monitoring; incident investigation |
| Support ticket content | 3 years from ticket closure | Service quality; dispute resolution |
| Marketing consent records | Until consent is withdrawn + 1 year | Proof of lawful marketing |
| Backup files (customer hosting data) | 7 days rolling | Service recovery; disaster recovery |
| Terminated account data | 14 days post-termination, then deleted | Allowing for account recovery requests |
When the applicable retention period expires, data is securely deleted or anonymised so it can no longer be associated with you. Anonymised aggregate data may be retained indefinitely for statistical analysis.
Vikalink uses cookies and similar technologies on its website and client dashboard. A cookie is a small text file stored on your device that helps us recognise you across sessions and provide a better experience.
Types of Cookies We Use
| Cookie Type | Purpose | Can Be Declined? |
|---|---|---|
| Strictly Necessary | Session management, login authentication, security tokens, CSRF protection. These are essential for the site to function. | No — Required |
| Functional | Remembering your language, currency, and UI preferences across visits. | Optional |
| Analytics | Aggregate data on which pages are visited and how users navigate the site. We use anonymised analytics only. | Optional |
| Marketing | Tracking whether you clicked a promotional email or ad before arriving at our site. Used to measure campaign effectiveness only. | Optional — Consent required |
Managing Cookies
You can control and delete cookies through your browser settings at any time. Disabling strictly necessary cookies will impair the functionality of the client dashboard and checkout process. Instructions for managing cookies in popular browsers:
- Google Chrome: Settings → Privacy & Security → Cookies
- Mozilla Firefox: Settings → Privacy & Security → Cookies
- Safari: Preferences → Privacy → Manage Website Data
- Microsoft Edge: Settings → Cookies and Site Permissions
Vikalink takes data security seriously and employs a combination of technical, organisational, and physical measures to protect your personal data against unauthorised access, loss, destruction, or disclosure.
Technical Safeguards
- TLS 1.3 encryption on all data transmitted between your browser and our servers
- At-rest encryption for sensitive stored data including account credentials
- Bcrypt/Argon2 password hashing — we never store plaintext passwords
- Two-factor authentication (2FA) available for all client accounts
- Web Application Firewall (WAF) and DDoS mitigation on all servers
- Automated malware scanning across all hosted accounts
- Intrusion Detection System (IDS) monitoring network traffic for anomalies
- Segregated network architecture isolating customer accounts from one another
Organisational Safeguards
- Access to customer data is restricted to authorised staff on a strict need-to-know basis
- All staff with access to personal data are bound by confidentiality obligations
- Regular internal security awareness training
- Documented data handling procedures and incident response plan
No method of transmission over the internet is 100% secure. While we use industry-best-practice security measures, we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.
Under the Ghana Data Protection Act 2012 (Act 843) and GDPR principles, you have the following rights over your personal data. We will respond to all valid requests within 30 calendar days.
How to Exercise Your Rights
Submit your request by email to privacy@vikalink.com or via a support ticket at dashboard.vikalink.com. We may need to verify your identity before processing the request. We will not charge a fee for reasonable requests; however, we may charge a reasonable administrative fee for manifestly unfounded or excessive requests.
Right to Lodge a Complaint
If you believe we have handled your data unlawfully, you have the right to lodge a complaint with the Data Protection Commission of Ghana at dataprotection.org.gh, or with the relevant supervisory authority in your country of residence.
Vikalink's services are not directed at children under the age of 18. We do not knowingly collect personal data from minors.
If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us immediately at privacy@vikalink.com. We will take prompt steps to delete such information from our records.
If a minor registers an account without parental consent, both the minor and any adult who assisted them are in breach of our Terms of Service. The account may be terminated upon discovery.
Our website and client dashboard may contain links to third-party websites, payment portals, and embedded tools (such as live chat widgets or social media buttons). These third-party services operate under their own privacy policies, which we do not control.
- Clicking a link to a third-party site means you are leaving Vikalink's environment and that site's privacy policy applies from that point.
- We are not responsible for the privacy practices or content of any external website.
- We recommend reviewing the privacy policy of any third-party service you interact with.
Third-party services integrated into our platform (payment processors, domain registry interfaces) are contractually required to meet privacy and security standards equivalent to or exceeding our own.
What We Send
With your consent, we may send you:
- Promotional emails about new services, hosting deals, and special offers
- Our newsletter containing web hosting tips, tutorials, and company news
- WhatsApp messages about exclusive promotions (only if you have opted in via our WhatsApp channel)
Transactional Communications
We will always send you service-related communications regardless of your marketing preferences. These include invoices, renewal reminders, service alerts, and support replies. These are not marketing and cannot be unsubscribed from while your account is active.
How to Opt Out
- Click the Unsubscribe link at the bottom of any marketing email
- Update your communication preferences in the client dashboard under Account Settings
- Email privacy@vikalink.com with your opt-out request
Opt-out requests are processed within 5 business days. You may continue to receive transactional messages during this period.
Despite our robust security measures, we recognise that security incidents can occur. Vikalink maintains a formal Data Breach Response Plan to manage such events swiftly and transparently.
Detection & Assessment
Upon becoming aware of a potential data breach, our security team will immediately assess the nature, scope, and likely consequences of the incident. This assessment is completed within 24 hours of detection.
Notification
- Where a breach is likely to result in a high risk to your rights and freedoms, we will notify affected customers without undue delay and within 72 hours of becoming aware of the breach.
- The notification will describe the nature of the breach, the data involved, the likely consequences, and the steps we are taking to address it.
- Where legally required, we will also notify the Data Protection Commission of Ghana within 72 hours.
Remediation
We will take all appropriate steps to contain the breach, recover affected systems, implement additional safeguards, and prevent recurrence. A post-incident report will be prepared and used to improve our security posture.
If you believe your Vikalink account or personal data has been compromised, please report it immediately to security@vikalink.com or open a priority support ticket.
We may update this Privacy Policy from time to time to reflect changes in our data practices, service offerings, or applicable law. When we make material changes, we will:
- Update the Effective Date at the top of this page
- Send an email notification to all registered account holders at least 14 days before the changes take effect
- Display a prominent notice in the client dashboard
Minor changes that do not materially affect your rights (e.g., clarifications or typographical corrections) may be made without specific notice. We encourage you to review this page periodically.
Your continued use of Vikalink services after the effective date of any revision constitutes your acceptance of the updated Privacy Policy. If you do not agree with the changes, you should stop using our services and submit a data deletion request.
If you have any questions about this Privacy Policy, wish to exercise your data rights, or have a concern about how we handle your personal information, please contact us through any of the channels below. We take all privacy enquiries seriously and aim to respond within 3 business days for general enquiries and 30 calendar days for formal rights requests.
Registered Address:
Vikalink Domain And Hosting
AD-026-2556, Adjacent Holy Mount Zion Model School
Fawoade New Site, Kumasi, Ashanti Region
Republic of Ghana
For complaints about our data handling that we have failed to resolve to your satisfaction, you may contact the Data Protection Commission of Ghana:
dataprotection.org.gh