EchoHouse

Legal

Privacy Policy

EchoHouse Ghana — Data Protection and Privacy Policy

1. Introduction

1.1 Echo House Ghana (hereinafter referred to as 'The Company') is a company incorporated under the laws of the Republic of Ghana and are the organizers of various marketing campaigns and events.

1.2 As part of our business operations, we may collect your SPDI and the protection and privacy of this data is of primary importance to us.

1.3 We value the trust and confidence of our employees, clients, and stakeholders which is why this Data Protection and Privacy Policy (hereinafter referred to as 'The Policy') outlines our commitment to protecting the personal data of our employees, clients and stakeholders in accordance with applicable laws and regulations.

1.4 This Policy applies to all our employees, clients and stakeholders and it is meant to help them understand the data we may collect, the reason we collect the data, the means by which we may collect, use or share them, the steps we take to protect personal data and the choices you are provided, with respect to the use of this information.

1.5 This Policy also applies to anyone who visits any of the Company's websites or events, engages with any of the Company's social media channels, purchases a ticket, a hospitality table or any other product and/or service, collectively referred to as 'Products and Services'.

2. Purpose

2.1 Protect the personal data of employees, clients and stakeholders whose information are taken from time to time from unauthorized access, disclosure, alteration, or destruction.

2.2 Ensure compliance with applicable laws and regulations related to data protection.

2.3 Establish procedures for collecting, processing, storing, and disposing of employee personal data.

3. Scope

This Policy applies to all our employees, including full-time, part-time, and contract employees, clients and stakeholders, covering all personal data collected, processed, stored, or transmitted in the course of our business operations.

4. Definitions

Anti-Money Laundering Act — the Anti-Money Laundering Act, 2008 (Act 749) including its amendments and regulations.

Authorized Personnel — an individual or entity appointed by the Company for the purposes of this Policy, authorized to receive all the SPDI required pursuant to providing services to the Company.

Client(s) — the individual or entity who is obtaining or is desirous of obtaining services from the Company and whose SPDI is subject matter for protection and security under this Policy.

Cyber Security Act — the Cyber Security Act, 2020 (Act 1038) including its amendments and regulations.

Data Protection Act — the Data Protection Act, 2012 (Act 843) including its amendments and regulations.

DPO — Data Protection Officer.

Data Subject — an individual whose personal data is being collected, processed, stored, or transmitted.

Electronic Transaction Act — the Electronic Transaction Act, 2008 (Act 772), including its amendments and regulations.

RSPP — Reasonable Security Practices and Procedures, where they become necessary.

SPDI — Sensitive Personal Data or Information as per the relevant laws.

The Company — EchoHouse Ghana and its affiliates.

The Policy — EchoHouse Ghana Data Protection and Privacy Policy.

5. Principles

5.1 Lawfulness, Fairness, and Transparency: We collect and process personal data in accordance with applicable laws and regulations, fairly and transparently.

5.2 Purpose Limitation: We collect personal data for specified, legitimate purposes and use it only for those purposes.

5.3 Data Minimization: We collect only the minimum amount of personal data necessary to achieve the specified purposes.

5.4 Accuracy: We ensure that personal data is accurate and up-to-date.

5.5 Storage Limitation: We store personal data for only as long as necessary to achieve the specified purposes.

5.6 Security: We implement robust security measures to protect personal data from unauthorized access, disclosure, alteration, or destruction.

5.7 Accountability: We are accountable for our actions and decisions regarding personal data.

6. Type of Data We Collect

6.1 Identity Data — such as your name, email address and telephone number; gender; date of birth, age and/or age range; account login details etc.

6.2 Audio/Visual Data — recordings and images collected from surveillance cameras, social media surveillance of the event.

6.3 Transaction Data — information about the services the Company provides to you and about transactions you make with the Company or other companies for events and services at the Company's events and venues, and similar information.

6.4 Contact Data — identity data the Company can use to contact you, such as email and physical addresses, phone numbers, social media or communications platform usernames/handles.

6.5 Device / Network Data — browsing history, search history, and information regarding your interaction with a website, application, or advertisement (e.g. session navigation history and similar browsing metadata, and other data generated through applications and browsers, including cookies and similar technologies or other device identifiers or persistent identifiers).

6.6 General Location Data — non-precise location data, e.g. location information derived from social media tags/posts, or general areas of the Company's events and venues you visited.

6.7 Sensitive Personal Data — like your national identification card, account log-in and password, financial account, debit card, or credit card number; precise location data; racial or ethnic origin, religious or philosophical beliefs.

7. Procedure

7.1 Collecting Data — the data we collect are only for specified, legitimate purposes, and we ensure that employees, clients and stakeholders are aware of the purposes and scope of data collection.

7.2 Processing Data — the data is processed in accordance with this Policy and applicable laws and regulations.

7.3 Storage of Data — the data is stored securely, using robust security measures to protect against unauthorized access, disclosure, alteration, or destruction.

7.4 Disclosure of Collected Data — collected data is only disclosed to authorized individuals or organizations, and we ensure that they are bound by confidentiality and data protection obligations.

7.5 Data Breach Response — there are procedures in place to respond to data breaches and security incidents, including notification of affected persons and regulatory authorities.

8. Third Party Websites

Except for processing by the Company's service providers, this Privacy Policy does not apply to third party websites, products, or services.

9. Disclosure / Sharing of Personal Data

9.1 Subsidiary Companies: to streamline the Company's business operations, the Company may share your data with other companies or subsidiaries under or connected to the Company.

9.2 Service providers: the Company may share your personal data with service providers who provide certain services or process data on our behalf in connection with our general business operations.

9.3 Social media platforms, sponsors and advertisers: the Company may share some personal data with social media platforms, advertisers, ad exchanges, data management platforms, or sponsors for business, marketing and commercial purposes.

9.4 Venue and event partners: to the extent that the law permits, or with your consent, we will share your data with event promoters and producers, venues and hospitality services providers, artists, or sponsors that perform or operate an event or our venue.

9.5 Other data processors or aggregators: the Company may share your data with data processors or aggregators in the performance and enhancement of our business and provision of the Company's services.

9.6 Successors: in case of a business transition such as a joint venture, merger, acquisition, sale of a portion (or all) of the Company's assets or liquidation, your personal data may be part of the transferred assets or may be disclosed during, for instance, the performance of due diligence processes for a potential transaction.

9.7 Legally required/approved recipients: under certain circumstances, the Company may be legally obligated to grant access or disclose your data and/or communications sent or received by you and any other information that we may have gathered from or about you to the extent of our belief that such disclosure is legally required to prevent or respond to a crime, to contribute to an investigation of a crime, or of the Company's event policy. However, in our discretion (without obligation), the Company may object to such disclosure.

10. Why Your Data Is Collected

10.1 Account Registration: where any of the Company's websites require a login or any of the Company's events require collection of data, the Company may use your data to create and maintain your account, to provide the products and services you request and for other business and commercial purposes like promotions and marketing. The Company does not sell or 'share' payment data or use it for purposes not permitted under applicable law.

10.2 Purchases and transactions: the Company may use your data when you complete a purchase transaction. The Company does not permanently store your payment data, except at your request, and processes your personal data as necessary to perform or initiate a transaction with you, process your order, payment, or refund, carry out fulfillment and delivery, document transactions, and for the Company's business purposes like marketing.

10.3 Marketing communications: we use your data for marketing emails, SMS, push notifications, or similar communications. You may receive marketing communications if you consent.

10.4 Visiting events and venues: the Company processes data when you visit our events and other venues, including audio/visual data in relation to security cameras or footage taken by the Company or any attendee of our events — as necessary to operate its events and provide its services, for security, identity verification, returning lost property, fraud prevention and managing access to specific areas of our event venues.

11. Obligations of the Company

The Company undertakes to use, disclose and process SPDI only for the reasonable, practical purposes agreed at the time the SPDI was collected; to inform employees, clients and stakeholders of any change in Authorized Personnel within 24 hours; to maintain a well-defined, standardized information and data security system with regular risk analysis; to not transfer SPDI beyond its possession without prior written consent (save where required by the laws of Ghana, where informing shall suffice); to comply with RSPP after any consented transfer; to take all possible physical, logical and technical security measures against copying, leaking, disclosure, modification or destruction of SPDI; to maintain the accuracy and originality of SPDI, rectifying perceived errors within five (5) working days of written request; to not retain SPDI beyond the term specified for its collection; and to return or delete SPDI (and instruct transferees likewise) on written request, with written confirmation.

12. Rights of Employees, Clients, and Stakeholders

12.1 Access — the right to request access to their personal data.

12.2 Rectification — the right to request correction or update of their personal data.

12.3 Erasure — the right to request deletion of their personal data (for employees, where they are no longer in the employ of the Company).

12.4 Restriction — the right to request restriction of processing of their personal data (for employees, where they are no longer in the employ of the Company).

12.5 Objection — the right to object to processing of their personal data (for employees, where they are no longer in the employ of the Company).

13. Minors

The Company's services are neither directed at nor intended for use by persons under the age of 18 in Ghana. The Company generally collects information relating to this age group only from parents or with parental consent, and only knowingly collects personal data from such individuals directly in limited circumstances where reasonably necessary to provide the service (such as underage talents that may or may not be part of families or dance groups or groups of a creative sort). If the Company learns that it has inadvertently collected such information, it will promptly delete such personal data if required by law.

14. Data Security

The Company uses and consistently maintains commercially reasonable security measures to secure your data privacy and prevent it from unauthorized processing. While the Company endeavors to protect your data from unauthorized access, modification, use and disclosure, the Company cannot absolutely guarantee that any information, during transfer or while being stored in the Company's systems, will be completely safe from intrusion by others.

15. Data Retention

The Company retains personal data for so long as it is reasonably necessary to achieve the relevant processing purposes described in this Privacy Policy, or for as long as is required by law.

16. Governing Law

This Policy shall be governed by the laws of the Republic of Ghana.

17. Updates to This Policy

17.1 The Company reserves the right to update this Policy from time to time to reflect changes in its business operations, applicable laws and regulations, or industry best practices.

17.2 The Company shall notify employees, clients and stakeholders of any changes via emails and updated copies on the Company's website(s), and the 'Last Updated' date will be revised accordingly.

17.3 Any changes to this Policy that may materially affect the Company's practices with regard to the information the Company has previously collected will be communicated.

18. Data Protection Officer (DPO)

The Company shall designate a Data Protection Officer (DPO) to oversee data protection activities for the purposes of this Policy, including: ensuring compliance with this Policy, applicable laws and regulations; providing guidance and training to employees on data protection; handling data subject requests and complaints; and investigating data breaches and security incidents.

19. Acknowledgement & Implementation

By acknowledging this Policy, employees, clients, and stakeholders confirm that they understand and agree to comply with its terms, provided always that the Company shall provide training and support to ensure that employees are aware of their responsibilities and obligations under this Policy.

This Policy is effective as of the date it is sent out via email and/or posted on the websites of the Company, whichever first precedes the other, and will be reviewed and updated regularly to ensure compliance with applicable laws and regulations.

20. Contact Us

Any questions, concerns and/or help on this Policy may be addressed to the DPO through the email address info@theechohouse.com.