Privacy Policy
This Privacy Policy describes how Onyina Group Ltd ("Onyina", "we", "us", or "our") collects, uses, and protects personal information you provide through onyina.com and our associated product pages. We are the data controller for all personal data processed under this policy.
1. What Data We Collect
We collect only the information you voluntarily submit. Depending on which form you use, this may include:
- Contact / inquiry form: full name, email address, organisation (optional), inquiry type, and your message.
- Job application form: full name, email address, role applied for, LinkedIn URL (optional), portfolio URL (optional), and cover letter.
- Kasa waitlist: email address and a name derived from your email prefix.
- Technical data: your IP address, collected automatically by our server-side form processing for rate-limiting and security purposes only.
We do not collect payment information, government identification, or sensitive personal data as defined under applicable data protection law.
2. How We Collect It
All personal data is collected through forms on this website. Submissions are processed by our backend edge functions running on Supabase and stored in a secured database. We do not purchase data from third parties or scrape data from any source.
3. Legal Basis for Processing
- Legitimate interests (Art. 6(1)(f) GDPR): to respond to inquiries, assess applications, manage communications, and protect our systems from abuse.
- Pre-contractual steps (Art. 6(1)(b) GDPR): where you submit a job application, processing is necessary to take steps at your request prior to entering a contract.
- Consent (Art. 6(1)(a) GDPR): for analytics where required by applicable law.
4. How We Use Your Data
- To respond to your inquiry or process your job application.
- To communicate with you about next steps, scheduling, or decisions.
- To send transactional email notifications (via our email service provider, Resend).
- To detect and prevent spam and abuse via IP-based rate limiting.
- To aggregate anonymised usage data to improve our website and products.
We will never sell, rent, or share your personal data with third parties for their own marketing purposes.
5. Retention
- Job applications: retained for 12 months from submission date, then deleted unless a separate agreement exists.
- Contact inquiries: retained for 24 months for business continuity, then deleted.
- Waitlist registrations: retained until product launch or upon your request to be removed.
- IP addresses: retained for 30 days solely for rate-limiting, then purged.
6. Data Sharing and Sub-processors
We share your data only with trusted sub-processors who act on our behalf under data processing agreements:
- Supabase Inc.: database and edge functions. Data stored in EU West (Ireland). SOC 2 Type II certified.
- Resend Inc.: transactional email. Data shared is limited to name and email address.
- Cloudflare Inc.: CDN, DDoS protection, and Web Analytics. Analytics is cookieless and privacy-preserving.
7. International Transfers
Supabase stores data in EU (Ireland). Resend and Cloudflare may process data in the United States. Transfers outside the EEA are covered by EU Standard Contractual Clauses (SCCs) or equivalent mechanisms under GDPR Chapter V.
8. Analytics and Cookies
Cloudflare Web Analytics: cookieless, no individual tracking, aggregated metrics only (page views, referrers, geography). No personal data is stored.
Google Analytics 4 (where active): configured with IP anonymisation. A cookie consent prompt will be displayed where required by applicable law.
We do not use advertising cookies, social media trackers, or behavioural profiling tools.
9. Your Rights
Subject to applicable law, you have the right to:
- Access: request a copy of the personal data we hold about you.
- Rectification: request correction of inaccurate or incomplete data.
- Erasure: request deletion where there is no longer a lawful basis for processing.
- Restriction: request that we restrict processing while a dispute is resolved.
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: at any time, without affecting the lawfulness of prior processing.
To exercise any of these rights, email privacy@onyina.com. We respond within 30 days. You may also lodge a complaint with a supervisory authority: the Data Protection Commission in Ghana, or your local data protection authority in the EU.
10. Data Security
- All data in transit encrypted with TLS 1.2 or higher.
- Row-level security enforced on all database tables.
- Service-role credentials never exposed client-side, all submissions processed through server-side edge functions.
- Rate limiting and bot detection on all submission endpoints.
- Admin access protected by authenticated sessions.
In the event of a personal data breach posing risk to your rights, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay.
11. Children's Privacy
This website is not directed at individuals under 16. We do not knowingly collect personal data from children. If you believe we have inadvertently done so, contact us and we will delete it immediately.
12. Changes to This Policy
We may update this policy periodically. The effective date above will reflect any changes. Material changes will be announced on this page. Continued use of the website after changes constitutes acceptance of the updated policy.
13. Contact
- Privacy enquiries: privacy@onyina.com
- General: hello@onyina.com
- Address: Onyina Group Ltd, Accra, Ghana