Data Protection

Nkoala – Data Protection Policy

Data Protection Policy

Last updated: April 2026

Introduction

Nkoala (“we,” “us,” “our”) is committed to protecting the privacy and security of your personal data. This Data Protection Policy explains how we collect, process, store, and protect your information in compliance with the Ghana Data Protection Act, 2012 (Act 843) and relevant international standards such as the GDPR where applicable. We respect your rights and handle your data with the utmost care, especially given our focus on products for babies and families.

Legal Basis for Processing

We process your personal data only when we have a lawful basis to do so, including:

  • Contract performance: To process orders, provide services, and deliver products.
  • Consent: For marketing communications, cookies, and optional data collection (you may withdraw consent at any time).
  • Legal obligation: To comply with tax, consumer protection, or other legal requirements.
  • Legitimate interests: To improve our website, prevent fraud, and ensure network security, provided your rights do not override those interests.

What Personal Data We Collect

Depending on your interaction with us, we may collect:

  • Identity & contact data: Name, email address, phone number, billing/shipping address.
  • Transaction data: Order details, payment information (processed securely by our payment partners), purchase history.
  • Technical data: IP address, browser type, device identifiers, and usage statistics via cookies.
  • Communications data: Your enquiries, support tickets, and feedback.
  • Special categories (sensitive data): We do not knowingly collect sensitive data such as health information, even in relation to skin care products; any accidental submission should be reported.

We never collect data from children under 13 without verifiable parental consent. If you believe a child has provided us with personal data, please contact us.

How We Use Your Data

We use personal data for the following purposes:

  • Processing and delivering orders, returns, and refunds.
  • Managing your account and providing customer support.
  • Sending service-related communications (order confirmations, shipping updates).
  • Improving our products, website, and marketing campaigns (with your consent where required).
  • Preventing fraud, ensuring security, and complying with legal obligations.

Data Subject Rights

Under the Ghana Data Protection Act and similar laws, you have the following rights:

  • Right to access: Request a copy of the personal data we hold about you.
  • Right to rectification: Correct inaccurate or incomplete data.
  • Right to erasure (“right to be forgotten”): Request deletion of your data, subject to legal retention obligations.
  • Right to restrict processing: Limit how we use your data under certain circumstances.
  • Right to data portability: Receive your data in a structured, machine-readable format.
  • Right to object: Object to processing based on legitimate interests or direct marketing.
  • Right to withdraw consent: For any processing based on consent, you may withdraw at any time.

To exercise any of these rights, please contact us at privacy@nkoala.com. We will respond within 30 days as required by law.

Data Security & Retention

Security: We implement technical and organisational measures including encryption (SSL/TLS), access controls, firewalls, and regular security assessments to protect your data from unauthorised access, alteration, or destruction.

Retention: We retain personal data only as long as necessary for the purposes outlined in this policy, or as required by law. For example:

  • Order data: 7 years (to comply with tax and consumer protection laws in Ghana).
  • Customer account data: Until you close your account or request deletion.
  • Marketing data: Until you unsubscribe or withdraw consent.
  • Website usage logs: Up to 12 months for security analysis.

Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Data Protection Commission (Ghana) within 72 hours and inform affected users without undue delay, as required by Act 843. We maintain an internal breach register and response plan to minimise harm.

Sharing with Third Parties

We do not sell or rent your personal data. However, we may share data with:

  • Service providers: Payment processors (e.g., Stripe, Paystack), shipping companies (e.g., FedEx, Ghana Post), IT hosting, and email platforms. These parties are contractually bound to protect your data.
  • Legal authorities: When required by law, court order, or to enforce our rights.
  • Business transfers: In the event of a merger or acquisition, we will notify you before data is transferred.

All third parties are required to respect data protection laws and only process data for specified purposes.

International Data Transfers

Nkoala is based in Ghana, but we may use cloud services and partners located in other countries (e.g., EU, US). When transferring personal data internationally, we ensure appropriate safeguards are in place, such as:

  • Standard contractual clauses approved by the EU Commission or Ghana Data Protection Commission.
  • Transfer impact assessments where necessary.
  • Binding corporate rules for internal transfers.

By using our website, you acknowledge that your data may be transferred to countries with different data protection laws. We strive to apply the same level of protection as required by Act 843.

Cookies & Tracking Technologies

Our website uses cookies to enhance your experience, analyse traffic, and personalise content. You can manage cookie preferences through our cookie consent banner or your browser settings. Essential cookies cannot be disabled as they are necessary for site functionality. For more details, see our Cookie Policy.

Children’s Data

Nkoala does not knowingly collect or process personal data from children under 13 years of age without parental or guardian consent. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. In cases where we become aware of such data, we will delete it unless we have lawful grounds to retain it (e.g., for legal claims).

Compliance & Complaints

We are committed to full compliance with Ghana’s Data Protection Act, 2012 (Act 843). If you believe that we have violated your data protection rights, you have the right to lodge a complaint with:

We encourage you to contact us first so we can resolve any concerns internally.

Changes to This Policy

We may update this Data Protection Policy periodically to reflect changes in laws, technology, or our operations. The “Last updated” date at the top of this page indicates when the policy was last revised. We will notify you of material changes via email or a prominent notice on our website. Continued use of our services after changes constitutes acceptance of the updated policy.

If you have any questions about this Data Protection Policy, wish to exercise your rights, or report a data protection concern, please contact our Data Protection Officer:

Nkoala Data Protection Office
Email: dpo@nkoala.com
Address: H No: C, 217, 14 Brown Link, Accra, Dzorwulu, Ghana

Shopping Cart