Domain Hosting Business Resources Support
Legal Document

Privacy
Policy

Your privacy matters deeply to us. This policy explains exactly what data we collect, why we collect it, how we protect it, and your rights over it — in plain, honest language.

Effective: 1 June 2025 Version 3.0 Ghana Law + GDPR Jurisdiction: Ghana

Privacy at a Glance

Plain-English highlights — the full document below is authoritative.

We collect only the data necessary to provide and improve our services to you.
We never sell your personal data to advertisers or third-party marketers.
Data is shared only with partners who help us deliver services (payment processors, registrars).
You have the right to access, correct, export, or delete your data at any time.
We use industry-standard encryption and security measures to protect your information.
We comply with Ghana's Data Protection Act 2012 (Act 843) and GDPR principles.
Ghana Data Protection Act 2012 (Act 843) GDPR Principles Compliant Ghana Cybersecurity Act 2020 (Act 1038) TLS/SSL Encrypted Minimal Cookie Usage
01
Who We Are
Identity of the data controller

This Privacy Policy is published by Vikalink Domain And Hosting, a web hosting and internet services business legally registered and operating in the Republic of Ghana.

Trading NameVikalink
Registered AddressAD-026-2556, Adjacent Holy Mount Zion Model School, Fawoade New Site, Kumasi, Ashanti Region, Ghana
Data ControllerVikalink Domain And Hosting
Support Phone+233 59 470 9323

As the data controller, Vikalink determines the purposes and means of processing your personal data. This policy applies to all services we operate, including our website, client dashboard, hosting infrastructure, domain management platform, and support channels.

02
Data We Collect
Categories of personal information we hold about you

We collect only the personal data that is necessary to provide our services and improve your experience with us. The categories of data we collect include:

Identity Data
Full name, username, date of birth (where required for age verification), and business name (for commercial customers).
Contact Data
Email address, phone number, postal/billing address, and WhatsApp number if provided voluntarily via support channels.
Payment Data
Transaction records, invoice history, and payment method type (e.g., Mobile Money, card). Full card numbers and Mobile Money PINs are never stored by Vikalink — these are handled solely by our PCI-compliant payment processors.
Technical Data
IP address, browser type and version, operating system, device identifiers, server access logs, cPanel activity logs, and session data.
Usage Data
Pages visited on our website, features used in the client dashboard, support ticket history, and interactions with our service platform.
Communications Data
Content of support tickets, live chat conversations, email exchanges, and WhatsApp messages with our support team, retained for service quality and security purposes.

Data We Do Not Collect

  • We do not collect sensitive personal data such as racial or ethnic origin, political opinions, religious beliefs, biometric data, or health information.
  • We do not store full payment card numbers or Mobile Money PINs at any point.
  • We do not knowingly collect data from children under 18 without verifiable parental consent.
03
How We Collect Your Data
The sources through which your information reaches us

Directly From You

  • When you register an account on our client portal
  • When you place an order for hosting, a domain, or any other service
  • When you contact our support team via ticket, live chat, email, WhatsApp, or phone
  • When you subscribe to our newsletter or marketing communications
  • When you complete surveys or provide feedback

Automatically

  • Server and application access logs generated when you visit our website or use your hosting account
  • Cookies and similar tracking technologies placed on your browser (see Section 9)
  • Analytics tools that record aggregate usage patterns on our website
  • Security monitoring systems that log unusual or suspicious access patterns

From Third Parties

  • Payment processors (Paystack, Flutterwave, Stripe, PayPal) who confirm transaction status and flag fraudulent activity
  • Domain registrar partners who provide WHOIS and registration verification data
  • Our fraud prevention partners who may provide risk-scoring data on transactions
04
Why We Use Your Data
The specific purposes for which we process your personal information
Purpose Data Used Basis
Account creation & management Identity, Contact Contract
Service provisioning (hosting setup, domain registration) Identity, Contact, Technical Contract
Billing, invoicing & payment processing Identity, Contact, Payment Contract
Customer support (tickets, chat, WhatsApp) Identity, Contact, Communications Contract
Security, fraud prevention & abuse detection Technical, Usage, Payment Legitimate Interest
Service notifications (renewals, downtime, maintenance) Identity, Contact Contract
Platform improvement & analytics Usage, Technical Legitimate Interest
Marketing & promotional emails Identity, Contact Consent
Legal compliance & law enforcement requests All categories as required Legal Obligation
05
Legal Bases for Processing
The lawful grounds under which we process personal data

In accordance with Ghana's Data Protection Act 2012 (Act 843) and GDPR principles, we rely on one or more of the following legal bases when processing your personal data:

Contractual Necessity

The majority of data processing we carry out is necessary to perform the contract we have with you — i.e., to provide the hosting services, manage your domain, process your payment, and support your account. Without this processing, we cannot fulfil your order.

Legitimate Interests

We process certain data on the basis of our legitimate business interests, such as detecting fraud, maintaining server security, improving our platform, and sending service-related communications. We always balance our legitimate interests against your rights and freedoms before relying on this basis.

Consent

Where we rely on consent — primarily for marketing emails and non-essential cookies — we will ask for your explicit opt-in. You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.

Legal Obligation

We may be required by Ghanaian law, court order, or valid request from a law enforcement authority to process or disclose certain data. In such cases, we will comply with our legal obligations while taking all reasonable steps to protect your interests.

06
Data Sharing & Disclosure
Who receives your data and under what conditions

We never sell your personal data. Vikalink does not sell, rent, or trade your personal information to advertisers, data brokers, or any third party for commercial gain.

We share data only in the limited circumstances described below, and always under strict data processing agreements:

RecipientPurposeData Shared
Payment Processors
Paystack, Flutterwave, Stripe, PayPal
Processing payments and detecting fraud Name, email, billing address, transaction amount
Domain Registrars
ICANN-accredited partners, NIC Ghana
Domain registration, transfer, renewal Registrant contact details (WHOIS data)
Infrastructure Providers
Data centre operators in EU, UK, USA
Hosting and storing service data Server usage data; no direct customer PII beyond what is in hosted files
Customer Support Tools
Ticketing, live chat platforms
Delivering support services Name, email, support ticket content
Email Service Providers Sending transactional and marketing emails Email address, name
Law Enforcement / Courts Compliance with legal obligations Data as required by valid legal order

All third-party processors are required to handle your data in accordance with applicable data protection laws and our data processing agreements. They may not use your data for their own purposes beyond what is specified.

07
International Data Transfers
How your data is protected when it crosses borders

As Vikalink's servers are located in the European Union (Frankfurt, Germany), the United Kingdom (London), and the United States of America, your personal data will inevitably be processed in jurisdictions outside Ghana.

We ensure that all cross-border transfers are protected by one or more of the following safeguards:

  • EU/UK: The EU and UK are recognised as jurisdictions providing an adequate level of data protection. Processing in our Frankfurt and London data centres is governed by GDPR, which meets or exceeds Ghana's Data Protection Act standards.
  • USA: Data transfers to US-based infrastructure are governed by Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring equivalent protections apply.
  • All international data processing partners are contractually bound to implement appropriate technical and organisational security measures.

You may request details of the specific safeguards in place for any international transfer of your data by contacting us at privacy@vikalink.com.

08
Data Retention
How long we keep your personal information

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected and to comply with our legal obligations. Our standard retention periods are:

Data CategoryRetention PeriodReason
Account & identity dataDuration of account + 3 yearsContract fulfilment; fraud prevention
Billing & payment records7 yearsGhana Revenue Authority tax compliance
Server & access logs90 days rollingSecurity monitoring; incident investigation
Support ticket content3 years from ticket closureService quality; dispute resolution
Marketing consent recordsUntil consent is withdrawn + 1 yearProof of lawful marketing
Backup files (customer hosting data)7 days rollingService recovery; disaster recovery
Terminated account data14 days post-termination, then deletedAllowing for account recovery requests

When the applicable retention period expires, data is securely deleted or anonymised so it can no longer be associated with you. Anonymised aggregate data may be retained indefinitely for statistical analysis.

09
Cookies & Tracking Technologies
What we place on your device and how to control it

Vikalink uses cookies and similar technologies on its website and client dashboard. A cookie is a small text file stored on your device that helps us recognise you across sessions and provide a better experience.

Types of Cookies We Use

Cookie TypePurposeCan Be Declined?
Strictly Necessary Session management, login authentication, security tokens, CSRF protection. These are essential for the site to function. No — Required
Functional Remembering your language, currency, and UI preferences across visits. Optional
Analytics Aggregate data on which pages are visited and how users navigate the site. We use anonymised analytics only. Optional
Marketing Tracking whether you clicked a promotional email or ad before arriving at our site. Used to measure campaign effectiveness only. Optional — Consent required

Managing Cookies

You can control and delete cookies through your browser settings at any time. Disabling strictly necessary cookies will impair the functionality of the client dashboard and checkout process. Instructions for managing cookies in popular browsers:

  • Google Chrome: Settings → Privacy & Security → Cookies
  • Mozilla Firefox: Settings → Privacy & Security → Cookies
  • Safari: Preferences → Privacy → Manage Website Data
  • Microsoft Edge: Settings → Cookies and Site Permissions
10
Security Measures
How we protect your data from unauthorised access

Vikalink takes data security seriously and employs a combination of technical, organisational, and physical measures to protect your personal data against unauthorised access, loss, destruction, or disclosure.

Technical Safeguards

  • TLS 1.3 encryption on all data transmitted between your browser and our servers
  • At-rest encryption for sensitive stored data including account credentials
  • Bcrypt/Argon2 password hashing — we never store plaintext passwords
  • Two-factor authentication (2FA) available for all client accounts
  • Web Application Firewall (WAF) and DDoS mitigation on all servers
  • Automated malware scanning across all hosted accounts
  • Intrusion Detection System (IDS) monitoring network traffic for anomalies
  • Segregated network architecture isolating customer accounts from one another

Organisational Safeguards

  • Access to customer data is restricted to authorised staff on a strict need-to-know basis
  • All staff with access to personal data are bound by confidentiality obligations
  • Regular internal security awareness training
  • Documented data handling procedures and incident response plan

No method of transmission over the internet is 100% secure. While we use industry-best-practice security measures, we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.

11
Your Data Rights
What you can ask us to do with your personal information

Under the Ghana Data Protection Act 2012 (Act 843) and GDPR principles, you have the following rights over your personal data. We will respond to all valid requests within 30 calendar days.

Right to Access
Request a copy of all personal data we hold about you, along with details of how it is used.
Right to Rectification
Ask us to correct inaccurate or incomplete personal data we hold about you.
Right to Erasure
Request that we delete your personal data where there is no compelling reason for us to continue processing it.
Right to Object
Object to processing based on legitimate interests or for direct marketing purposes at any time.
Right to Restriction
Request that we temporarily restrict processing of your data while a dispute about accuracy or lawfulness is resolved.
Right to Portability
Receive your personal data in a structured, machine-readable format so you can transfer it to another provider.

How to Exercise Your Rights

Submit your request by email to privacy@vikalink.com or via a support ticket at dashboard.vikalink.com. We may need to verify your identity before processing the request. We will not charge a fee for reasonable requests; however, we may charge a reasonable administrative fee for manifestly unfounded or excessive requests.

Right to Lodge a Complaint

If you believe we have handled your data unlawfully, you have the right to lodge a complaint with the Data Protection Commission of Ghana at dataprotection.org.gh, or with the relevant supervisory authority in your country of residence.

12
Children's Privacy
Our commitment to protecting the privacy of minors

Vikalink's services are not directed at children under the age of 18. We do not knowingly collect personal data from minors.

If you are a parent or guardian and believe that your child has provided us with personal information without your consent, please contact us immediately at privacy@vikalink.com. We will take prompt steps to delete such information from our records.

If a minor registers an account without parental consent, both the minor and any adult who assisted them are in breach of our Terms of Service. The account may be terminated upon discovery.

13
Third-Party Links & Services
External websites and integrations we link to

Our website and client dashboard may contain links to third-party websites, payment portals, and embedded tools (such as live chat widgets or social media buttons). These third-party services operate under their own privacy policies, which we do not control.

  • Clicking a link to a third-party site means you are leaving Vikalink's environment and that site's privacy policy applies from that point.
  • We are not responsible for the privacy practices or content of any external website.
  • We recommend reviewing the privacy policy of any third-party service you interact with.

Third-party services integrated into our platform (payment processors, domain registry interfaces) are contractually required to meet privacy and security standards equivalent to or exceeding our own.

14
Marketing Communications
How we market to you and how to opt out

What We Send

With your consent, we may send you:

  • Promotional emails about new services, hosting deals, and special offers
  • Our newsletter containing web hosting tips, tutorials, and company news
  • WhatsApp messages about exclusive promotions (only if you have opted in via our WhatsApp channel)

Transactional Communications

We will always send you service-related communications regardless of your marketing preferences. These include invoices, renewal reminders, service alerts, and support replies. These are not marketing and cannot be unsubscribed from while your account is active.

How to Opt Out

  • Click the Unsubscribe link at the bottom of any marketing email
  • Update your communication preferences in the client dashboard under Account Settings
  • Email privacy@vikalink.com with your opt-out request

Opt-out requests are processed within 5 business days. You may continue to receive transactional messages during this period.

15
Data Breach Response Policy
How we handle security incidents involving personal data

Despite our robust security measures, we recognise that security incidents can occur. Vikalink maintains a formal Data Breach Response Plan to manage such events swiftly and transparently.

Detection & Assessment

Upon becoming aware of a potential data breach, our security team will immediately assess the nature, scope, and likely consequences of the incident. This assessment is completed within 24 hours of detection.

Notification

  • Where a breach is likely to result in a high risk to your rights and freedoms, we will notify affected customers without undue delay and within 72 hours of becoming aware of the breach.
  • The notification will describe the nature of the breach, the data involved, the likely consequences, and the steps we are taking to address it.
  • Where legally required, we will also notify the Data Protection Commission of Ghana within 72 hours.

Remediation

We will take all appropriate steps to contain the breach, recover affected systems, implement additional safeguards, and prevent recurrence. A post-incident report will be prepared and used to improve our security posture.

If you believe your Vikalink account or personal data has been compromised, please report it immediately to security@vikalink.com or open a priority support ticket.

16
Changes to This Privacy Policy
How we notify you when this policy is updated

We may update this Privacy Policy from time to time to reflect changes in our data practices, service offerings, or applicable law. When we make material changes, we will:

  • Update the Effective Date at the top of this page
  • Send an email notification to all registered account holders at least 14 days before the changes take effect
  • Display a prominent notice in the client dashboard

Minor changes that do not materially affect your rights (e.g., clarifications or typographical corrections) may be made without specific notice. We encourage you to review this page periodically.

Your continued use of Vikalink services after the effective date of any revision constitutes your acceptance of the updated Privacy Policy. If you do not agree with the changes, you should stop using our services and submit a data deletion request.

17
Contact Us & Data Protection Officer
How to reach us with privacy questions or requests

If you have any questions about this Privacy Policy, wish to exercise your data rights, or have a concern about how we handle your personal information, please contact us through any of the channels below. We take all privacy enquiries seriously and aim to respond within 3 business days for general enquiries and 30 calendar days for formal rights requests.

Registered Address:
Vikalink Domain And Hosting
AD-026-2556, Adjacent Holy Mount Zion Model School
Fawoade New Site, Kumasi, Ashanti Region
Republic of Ghana

For complaints about our data handling that we have failed to resolve to your satisfaction, you may contact the Data Protection Commission of Ghana:
dataprotection.org.gh