WASID Privacy Policy
Last updated: 2026-07-28 Controller: Boldstep Productions Ltd, Accra, Ghana Contact: the access-request form Supervisory authority: Data Protection Commission, Ghana — https://dataprotection.org.gh
0. The short version
WASID ("Whole Africa Sentinel Intelligence Data") is a risk-intelligence product. Its job is to watch events and places — protests, port disruptions, thermal anomalies, weather, and similar — across Africa, verify them, and tell paying customers what's happening and where.
WASID is not a surveillance product. It does not build profiles of named people, does not track individuals, and is not designed to identify who did something — only what happened, where, and how confident we are that it's real.
Two very different kinds of data touch this system, and we want that distinction to be clear rather than buried in boilerplate:
- Data about the public we monitor — this is event data (an incident, a location, a time, a severity, a confidence score) and measurement data (satellite/thermal/weather/marine readings of places, not people). We do not collect personal data about members of the public as part of this monitoring, and any personal data that incidentally appears in a raw source (e.g. a phone number pasted into a news snippet) is stripped or irreversibly obscured before it is stored — see §2.
- Data about our paying customers and internal team — account details, API keys, and console login sessions for the people and organisations who use WASID. This is ordinary account data, handled like any B2B software account.
The rest of this policy explains both in detail.
1. Who this policy covers
- Customers: organisations and individuals who hold a WASID API key (Signal, Watch, or Analyst tier) or a console login.
- The public whose environment WASID monitors: this policy explains what we do — and, more importantly, what we deliberately do not do — with respect to this group. They are not our "users" in the account sense; they do not sign up, log in, or interact with WASID.
- Visitors to any WASID web page: if a separate public marketing site collects its own data (contact forms, analytics), it carries its own privacy notice or an addendum here.
2. What we collect, and why
2.1 Public risk-event and measurement data (not personal data)
WASID ingests candidate risk events from public sources (public news feeds and public reporting) and from measurement sources — satellite thermal readings, weather forecasts, marine/vessel aggregates, and similar instruments that observe places, not people.
- Each candidate is passed through an automated extraction step and, for reported (news-derived) events, held as unverified until a human analyst confirms it. Only verified events are served to Signal/Watch customers by default; unverified candidates are internal-only.
- Every event carries an audit trail (who verified or dismissed it, when, and why) — this is an operational quality/liability record, not a record about a member of the public.
- Measured events (from satellite/thermal/weather/marine connectors) are aggregate readings of a place — e.g. a thermal anomaly at a set of coordinates, a rainfall forecast for a cell, a count of vessels in an area. They do not carry individual identifiers (for example, vessel-level tracking data is used only as counts/aggregates, never as an individual vessel or person record).
PII scrubbing at ingestion. Free-text fields (an event's title, summary, and the raw place-name text) are passed through an automated privacy-scrubbing step before anything is stored: - Credential-shaped values (API keys, tokens, passwords) are replaced with a one-way hash — irreversible, never recoverable by us or anyone else. - Personal-data-shaped values that appear incidentally in source text (an email address, a phone number, a national ID pattern) are replaced with a pseudonymous token. Public-source scrubbing runs in irreversible mode in production: no re-identification vault is enabled, and no one — including us — can turn a stored token back into the original value. - This scrubbing happens before the data is stored or used to detect duplicate reports of the same incident, so no unscrubbed personal data reaches our database from an ingested source.
We do not: build profiles of named individuals; track a specific person's location or movements; run facial recognition or biometric identification; sell or share public-source data as if it were personal data about identifiable people. If any future feature would do this, it is out of scope for WASID and would require a new, separate legal basis and disclosure — it does not exist today.
2.2 Customer / account data
If you are a paying customer (Signal, Watch, or Analyst tier) or use a customer-facing account, we hold: - Organisation/account name, plan tier, and an internal client identifier. - API keys — stored only as a salted one-way hash; the plaintext key is shown to you once at creation and never stored or recoverable by us afterward. - Billing/contact details necessary to invoice and support your account. We will name the payment processor in this policy before paid billing goes live. - Usage/rate-limit data (request counts per API key, for abuse prevention and plan enforcement).
2.3 Console login / internal session data
WASID has an internal "verifier console" used by our own analysts/verifiers to review and confirm candidate events. If you are an internal team member with console access: - We hold the display name you type at login and a session cookie that keeps you signed in. See the separate Cookie Policy (Cookie Policy) for the specific cookie. - The console is only reachable when explicitly enabled for a deployment, and is gated by a separate console password — it is not a public-facing product surface.
2.4 Server logs and technical data
Like any web service, our servers generate ordinary operational logs (timestamps, request paths, response codes, error traces) for reliability and security purposes. These are retained for approximately 90 days for debugging and abuse-prevention and are not used to build profiles of individuals.
2.5 A note on the training corpus
WASID banks extracted candidate text plus the automated labels used to produce it (with source provenance) in an internal training/evaluation store, so the extraction pipeline can be measured and improved over time. The same PII-scrubbing step described in §2.1 is applied before this text is stored, and entries are deduplicated so the same source text is not banked twice. This corpus is used only to evaluate and improve WASID's own extraction pipeline — it is not sold, shared externally, or used to identify individuals.
3. Legal basis for processing
We process data under Ghana's Data Protection Act, 2012 (Act 843), and — for the personal data of customers or staff who may be in the EU/EEA/UK, or where we process data of an EU data subject — our practices are designed to align with the GDPR / UK GDPR. [Do not read this as a claim of GDPR certification or compliance audit — see §10.]
- Customer/account data: processed under our contract with you (providing the service you signed up for) and our legitimate interest in running and securing the service.
- Public event/measurement data: this is, by design, not personal data about an identifiable individual (see §2.1). Where a fragment of incidental personal data is detected in raw source text, our legal basis for the brief scrubbing step itself is our legitimate interest in operating the product safely and lawfully (i.e., removing personal data promptly, rather than a basis for retaining it).
- Console/session data: legitimate interest in operating internal security controls (knowing who is signed in to make a verification decision, and keeping the audit trail meaningful).
4. Retention
- Verified/unverified risk events and measurement readings: retained indefinitely as the historical operational record of the feed — the value of a risk feed includes its history. Dismissed candidates are retained with their audit record as evidence of the decision.
- Audit records (who verified/dismissed what, and why): retained as long as the associated event, as the integrity/liability record for that decision.
- Customer account/API-key data: retained for the life of the account plus six years (the contract-claim limitation period), for billing and legal-defence purposes.
- Console session data: see the Cookie Policy for the session cookie's technical lifetime; the display name is not retained beyond the session/audit record it is attached to.
- Server logs: approximately 90 days (§2.4).
- Training corpus: reviewed at least annually; entries no longer needed to evaluate or improve the extraction pipeline are purged.
5. Your rights
If you are a customer or otherwise have personal data held by us (e.g. as account contact data), under Act 843 you have the right to: - Access the personal data we hold about you. - Rectification of inaccurate data. - Erasure of data we no longer have a lawful basis to hold. - Object to processing based on legitimate interest. - Lodge a complaint with Ghana's Data Protection Commission (https://dataprotection.org.gh) if you believe we have mishandled your data.
If you are in the EU/EEA or UK, you additionally have the corresponding rights under the GDPR / UK GDPR (access, rectification, erasure, restriction, portability, objection), and the right to complain to your local supervisory authority.
To exercise any of these, contact us at the access-request form. We respond within one month of receipt, extendable where the law allows for complex requests.
Members of the public whose events/locations WASID reports on are, by design, not data subjects we hold identifying records on (§2.1). If you believe an event record about a specific incident is inaccurate, or that personal data about you has slipped through the scrubbing step and reached our store, contact us at the address above and we will investigate and correct/erase as appropriate.
6. Sub-processors and third parties
We use third-party infrastructure and services to run WASID. As categories, today these include: - Cloud hosting / infrastructure — the API and database are hosted on Render, with the production database in an EU (Frankfurt) region. - AI model provider — Anthropic's Claude models are used in the extraction pipeline to help triage and structure candidate event text. Only PII-scrubbed public-source candidate text is processed this way; customer account data is not sent to the model provider. - Data source providers — public news/RSS feeds and weather/satellite/marine data providers supplying the measurement readings described in §2.1. - Payment processing — to be named in this policy before paid billing goes live. - Communications — the SMS/email alert-delivery provider for Watch-tier customers will be named here before push alert delivery ships.
We do not sell personal data. Any sub-processor handling personal data is required to protect it under terms consistent with Act 843 (and GDPR-aligned terms where relevant); the current list with processing locations is maintained in the DPA's Annex III.
7. International transfers
Because WASID's infrastructure may be hosted outside Ghana (e.g. in the EU), and because customers or data subjects may be located in multiple jurisdictions, some data may cross borders. Where personal data does travel outside its country of origin, our design intent is to pseudonymise or otherwise protect it in transit and at rest, consistent with the AU Malabo Convention and GDPR's transfer-safeguard concepts.
For customers in the EU/EEA or UK specifically: Ghana does not currently hold an EU adequacy decision, so any transfer of EU/UK personal data to Boldstep in Ghana (e.g. account contact details) is covered by an appropriate safeguard — the EU Standard Contractual Clauses (and the UK Addendum for UK data), which we make available as part of our Data Processing Agreement (Data Processing Agreement). Where our hosting is in the EU (the Frankfurt-region database), customer data held there does not leave the EU for storage; the transfer analysis applies to access from Ghana and any non-EU processing.
8. Security
We apply technical measures appropriate to the data involved, including: hashed (not plaintext) API keys, PII/credential scrubbing before storage, an append-only audit trail for verification decisions, transport encryption, and restricted internal console access behind a password, session controls, and production-hardened cookies.
9. Children
WASID is a B2B risk-intelligence product and is not directed at, or knowingly used by, children. We do not knowingly collect data from children.
10. What this policy does not claim
We are not a certified GDPR compliance service, and this policy does not claim WASID "is GDPR compliant" or "is Act 843 compliant" as a certified or audited status. Our practices are designed to align with Act 843 and, where relevant, GDPR principles.
11. Changes to this policy
We will update this policy as the product and our data practices evolve, and will note the "last updated" date above. Material changes affecting customers are notified by email to account contacts at least 30 days before taking effect.
12. Contact
Boldstep Productions Ltd Accra, Ghana the access-request form
© 2026 Boldstep Productions Ltd. This policy reflects WASID's actual data-handling behaviour as implemented.