This Privacy Policy explains how Dev Surge Infotech Ltd (“we”, “us”, or “our”) collects, uses, stores, and protects information about you when you visit our website, utilize our software platforms, or participate in our corporate training programs. By using our services, you agree to the practices described in this document.
1 Who We Are
Dev Surge Infotech Ltd is an enterprise technology company incorporated in the Republic of Ghana, headquartered in Accra. We design, engineer, and deploy high-performance custom software platforms, cloud applications, cybersecurity systems, and professional corporate IT training across Africa and globally.
Under applicable data protection laws (including the Data Protection Act, 2012 of Ghana and international best practices), Dev Surge Infotech Ltd acts as the Data Controller for personal data collected through our primary website and marketing channels.
2 Information We Collect
We only collect personal information that is necessary for business communication, service delivery, platform authentication, or legal compliance.
2.1 Information You Provide Voluntarily
- Inquiry & Contact Data: Name, work email address, telephone number, organization name, and message content submitted via our contact and consultation forms.
- Client Portal & Platform Accounts: Full name, verified email address, organization role, and authentication credentials when registered for the Dev Surge Client Portal or administrative dashboards.
- Corporate Training & Certifications: Participant legal name, corporate sponsor, course completion metrics, examination results, and digital certificate serial identifiers.
- Billing & Commercial Records: Corporate billing addresses, tax identifiers, invoice histories, and payment references. (Note: We do not store credit card or bank credentials; transactions are routed through regulated PCI-DSS Level 1 payment processors).
2.2 Information Collected Automatically
- Device & Telemetry Data: IP address, browser user-agent, operating system, screen dimensions, language preferences, and network provider.
- Session & Usage Diagnostics: Page view durations, navigation paths, feature interactions, crash logs, and referral URLs.
2.3 Information from Third-Party Integrations
- Single Sign-On (SSO): When logging in via Google Workspace / OAuth2, we receive your Google verified identity token (name, email address, profile picture) to facilitate seamless authentication.
3 How We Use Your Information
We process your data strictly for legitimate business and operational purposes:
| Processing Purpose | Data Categories Used | Primary Lawful Basis |
|---|---|---|
| Service delivery, portal access & platform maintenance | Account details, session tokens, usage logs | Contractual Necessity |
| Responding to client inquiries & RFP proposals | Contact data, corporate details | Legitimate Business Interest |
| Issuance & public verification of training credentials | Certificate IDs, recipient names, course records | Contract / Public Verification Service |
| System security, brute-force mitigation & fraud prevention | IP addresses, authentication event logs | Legitimate Interest & Security Compliance |
| Accounting, tax filings & regulatory reporting | Invoices, transaction references | Legal & Statutory Obligation |
4 Legal Basis for Processing
Depending on your relationship with Dev Surge Infotech Ltd, we rely on one or more of the following legal grounds:
- Performance of a Contract: Necessary to fulfill our obligations under service level agreements, development contracts, and training engagements.
- Legitimate Interests: Necessary for conducting IT security auditing, improving system reliability, preventing abuse, and managing client relationships.
- Legal Compliance: Necessary to meet statutory tax, financial auditing, and corporate governance laws in the Republic of Ghana.
- Consent: When you explicitly opt in to receive newsletters, marketing insights, or promotional updates (which you can revoke at any time).
5 Sharing & Third-Party Disclosures
Dev Surge Infotech Ltd never sells, rents, or monetizes personal data to any third parties. We share data only with vetted enterprise infrastructure partners bound by strict confidentiality and Data Processing Agreements (DPAs):
- Cloud Infrastructure: Google Cloud Platform & Firebase (Tier-4 SOC-2 / ISO 27001 certified cloud database and hosting infrastructure).
- Transactional Messaging: Enterprise SMTP & communication APIs for system alert notifications and verification codes.
- Corporate Clients: When training is sponsored by your employer or corporate sponsor, attendance and certification records are shared with the authorized sponsor.
- Legal & Regulatory Authorities: Where mandated by a valid court subpoena, law enforcement inquiry, or national regulatory directive.
6 Cookies & Tracking Technologies
We use essential and functional cookies to ensure platform reliability, persist authenticated portal sessions, and remember user interface preferences.
| Cookie Type | Function & Lifespan | Essential Status |
|---|---|---|
| connect.sid | Secures and identifies your active session on the Client Portal. Expires on session close or 24 hours. | Strictly Necessary |
| dsi_cookie_consent | Records your cookie preference banner selection. Stored in localStorage. | Functional |
| Security Tokens | CSRF mitigation tokens to protect against cross-site request forgery attacks. | Strictly Necessary |
You can configure your browser to block or alert you about cookies, but certain core features of the Client Portal may become unavailable.
7 Data Retention Policy
We retain personal information only for the duration required to satisfy the operational and legal purposes outlined in this policy:
- Portal Account Records: Retained for the active duration of the commercial agreement, plus 3 years following account closure.
- Certificate & Credential Verification Data: Retained indefinitely in our verifiable registry to allow perpetual third-party authenticity verification of issued certificates, unless explicit revocation or deletion is requested.
- Financial Invoices & Receipts: Retained for 7 years in accordance with Ghanaian statutory corporate tax requirements.
- System Security & Access Logs: Retained for 12 months for security auditing, then automatically purged.
8 Your Rights as a Data Subject
Under applicable data protection legislation, you possess comprehensive rights regarding your personal information:
- Right to Access: Request a complete copy of the personal data we hold about you.
- Right to Rectification: Request the prompt correction of inaccurate or incomplete records.
- Right to Erasure (“Right to be Forgotten”): Request deletion of your personal records where no statutory or contractual retention obligation applies.
- Right to Restrict Processing: Request the temporary suspension of processing while an accuracy or legitimacy claim is assessed.
- Right to Data Portability: Obtain your data in a structured, standard, machine-readable format (JSON/CSV).
- Right to Object: Object to processing based on legitimate business interests or direct marketing outreach.
To exercise any of these rights, please email our Data Privacy Officer at privacy@devsurgeinfotech.com. We acknowledge and fulfill requests within 30 calendar days free of charge.
9 International Data Transfers
When services utilize cloud hosting facilities situated across multinational data centers, we enforce Standard Contractual Clauses (SCCs) and enterprise data processing agreements that guarantee data encryption in transit (TLS 1.3) and at rest (AES-256), meeting or exceeding international standards.
10 Security Architecture & Safeguards
Information security is central to our engineering ethos. Dev Surge Infotech Ltd employs enterprise-grade defense-in-depth measures:
- Mandatory HTTPS / TLS encryption for all public web and API endpoints.
- Database encryption at rest utilizing industry-standard AES-256 cipher suites.
- Role-Based Access Control (RBAC) enforcing least-privilege principles across all administrative portals.
- Continuous vulnerability assessment, code auditing, and rate-limiting to prevent automated brute-force attacks.
- Multi-Factor Authentication (MFA) on all internal administrative systems.
11 Children's Privacy
Our website, enterprise software platforms, and corporate training services are designed exclusively for business professionals, enterprises, and adult learners aged 16 and above. We do not knowingly collect personal data from minors.
12 Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect technological enhancements, operational changes, or new regulatory standards. When significant updates occur, we will revise the “Last Updated” date at the top of this document and provide notification across our client channels.
13 Contact Our Privacy Office
For inquiries, questions regarding your data rights, or compliance matters, please reach out to our dedicated team: