01Privacy Policy

Data as a
fiduciary obligation.

This policy explains what personal data AITW Authentica collects, why we hold it, how long we keep it, and the rights you can exercise over it.

02

Scope

Who this covers.

This policy applies to aitwauthentica.com and to personal data AITW Authentica processes as a data controller — enquiries, briefing requests, career applications, and business-contact information.

Where we process data inside a client engagement or on one of our platforms, the client is the controller and we act as processor under the engagement agreement or data processing agreement. Those terms govern, and they take precedence over this policy for that data.

Last updated — 30 July 2026

03

The detail

What we hold, and why.

Data we collect

You give us: name, organisation, email address, telephone number, and the content of your message when you contact us, request a briefing, or apply for a role.

We generate: correspondence records and engagement notes necessary to respond to and service your request.

Collected automatically: server logs including IP address, browser type, and pages requested, retained for security and operational integrity.

Lawful basis

We process contact and enquiry data on the basis of legitimate interest in responding to you and in conducting our business, or on the basis of steps taken at your request prior to entering a contract. Where we rely on consent — for example, optional marketing — you may withdraw it at any time without affecting processing carried out beforehand.

How we use it

To answer enquiries, scope and deliver engagements, assess applications, meet legal and regulatory obligations, and secure our systems. We do not sell personal data, and we do not share it for cross-context behavioural advertising.

AI and model training

We do not use client data, customer data, or personal data submitted to us to train shared or third-party AI models. Where our platforms apply AI, they operate on your data for your benefit, within your boundary, with the provenance of each output traceable to its source.

Data residency and transfers

Data residency is configurable per platform and per engagement. Where a jurisdiction requires in-country or in-region storage, we deploy to meet that requirement. Any international transfer is made under an adequacy decision or appropriate safeguards such as standard contractual clauses.

Security

Personal data is encrypted in transit and at rest. Our platforms use per-tenant isolation, and access is scoped to the smallest set of people who need it, reviewed periodically, and logged. Client material is held under engagement-level confidentiality.

Retention

We keep personal data only as long as the purpose requires. Enquiry correspondence is retained for up to 24 months from last contact; unsuccessful applications for up to 12 months; engagement records for the period required by contract, professional obligation, and applicable statute. After that, data is deleted or irreversibly anonymised.

Subprocessors

We use a small number of vetted providers for hosting, email, and productivity, each bound by written terms that meet or exceed the commitments in this policy. A current subprocessor list is available to clients and prospective clients on request from request@aitwauthentica.com.

Cookies and analytics

This website uses only the cookies strictly necessary to serve and secure the site. We do not run advertising trackers or third-party behavioural profiling on it. If that changes, this policy will be updated and consent obtained where the law requires it.

Your rights

Subject to applicable law, you may request access to your personal data, correction of inaccuracies, deletion, restriction of or objection to processing, and portability. Under CCPA you may additionally request disclosure of the categories of information collected and opt out of any sale or sharing — we conduct neither.

To exercise a right, email request@aitwauthentica.com. We respond within 30 days and will tell you if we need longer. You also have the right to complain to your supervisory authority.

Assurance and audit

Control documentation, evidence, and audit trails are available to clients and their auditors under engagement terms — the same assurance discipline our Lumiaxiom platform exists to systematise.

Changes to this policy

We update this policy as our processing changes. Material changes affecting clients or applicants are communicated directly; the date above always reflects the current version.

04

Contact

Data protection contact.

Privacy enquiries, data subject requests, and subprocessor list requests are handled by our data protection contact.

request@aitwauthentica.com
+233 50 149 3877
GW-0299-8745, Mt. Crossfell Street, Accra, Ghana