Privacy policy

What we collect, why we are allowed to collect it, who processes it on our behalf, how long we keep it, and what you can require us to do about it.

Last updated 3 September 2026


1. Who controls your data

Ardent Lens is published by Ardent Africa Technologies Ltd, a company registered in Ghana with its office in Accra. That company is the data controller for personal data collected through this site and its mobile application.

Our primary obligations arise under the Data Protection Act, 2012 (Act 843) and we are answerable to the Data Protection Commission of Ghana. Where we process the data of readers in the United Kingdom or the European Economic Area, the UK GDPR and the EU GDPR apply in addition, and this policy is written to satisfy both regimes rather than to choose between them.

To exercise any right described here, or to ask a question about how we handle your data, use the contact page.

2. What we collect

Account data
Your name, email address and password when you register. The password is stored only as a cryptographic hash, so it cannot be read by us or recovered from our records. If you complete a profile we also hold a display name, biography, links and an avatar, all optional.
Membership and payment data
Your plan, its status and its renewal date, together with a reference issued by our payment processor. We do not receive, see or store your card number, your mobile money PIN or any equivalent credential at any point.
Reading and interaction data
Where you are signed in: your bookmarks, your reading position, comments you post and reactions you leave. Where you are not signed in, article views are counted without being attached to you as a person.
Communications data
What you send us, and the address you sent it from, when you contact us or subscribe to a newsletter, including your list preferences.
Technical data
IP address, browser and operating system, pages requested, timestamps and referring address. Used for security, performance and aggregate analysis. It is not used to build a commercial profile of you, and there is no advertising here for such a profile to serve.

3. Why we are allowed to process it

Every category above rests on one of four bases, and we do not treat them as interchangeable.

  • Performance of a contract: your account, your membership and the delivery of the content you paid for.
  • Consent: marketing email and push notifications, and analytics when we introduce it. Consent is asked for separately, recorded, and can be withdrawn without affecting anything else.
  • Legitimate interests: securing the platform against abuse, understanding in aggregate which pieces are read, and preventing payment fraud. We have weighed these against your interests, and none of them requires identifying you individually.
  • Legal obligation: retaining financial records for the period Ghanaian tax and company law requires.

4. Who processes data on our behalf

We use a small number of processors, each under contract, each handling only what its function requires. We do not sell personal data, and we have never shared it with an advertising network, because we carry no advertising.

Supabase
Database, authentication and file storage, hosted in London. Holds account, membership, reading and comment data.
Fly.io and Vercel
Application hosting for the API and the website, in London and on a global edge network respectively. They process request data in transit.
Paystack
Payment processing for card and mobile money in Ghana cedis. Paystack is the controller of your payment credentials, which never reach us.
SendGrid and Hubtel
Transactional and newsletter email, and SMS where you have asked for it. They receive the address or number and the message, and nothing else.
Analytics
None at present. No analytics provider runs on this site today and none receives your data. When we introduce one it will load only after you accept analytics cookies, and the cookie policy will be updated before rather than after.
Anthropic and Voyage AI
Search and summarisation over our own published articles. Your search query is sent to these providers to answer it. Neither is given your account data, and neither is permitted to train on what we send.

5. Where your data goes

Our database and application servers are in London. Some processors operate in the United States. Those transfers rely on the standard contractual clauses or an equivalent approved mechanism, and on the Data Protection Commission’s requirements for transfers out of Ghana.

We chose London rather than a United States region deliberately, because it puts reader data under a stricter regime and closer to home.

6. How long we keep it

Account data
For as long as your account exists, and thirty days after you delete it.
Payment records
Six years, because Ghanaian tax and company law requires it. This is the one category that survives account deletion, and it is kept as a financial record rather than as a profile.
Comments
For as long as the article stands. On account deletion a comment is detached from your identity rather than removed, so a conversation does not become unreadable.
Technical logs
Ninety days, then deleted.
Newsletter data
Until you unsubscribe, plus a suppression record so we do not email you again by mistake.

7. Your rights

Under Act 843, and under the GDPR where it applies to you, you may ask us to do all of the following. We answer within thirty days and we do not charge for it.

  • Tell you what we hold about you, and give you a copy.
  • Correct anything inaccurate.
  • Delete your account and the data attached to it, subject only to the financial records above.
  • Stop processing that rests on consent, by withdrawing it.
  • Give you your data in a portable, machine-readable form, or send it directly to another controller where that is technically possible.
  • Object to processing that rests on our legitimate interests, in which case we stop unless we can show a compelling reason not to.

If you believe we have handled your data wrongly, you may complain to the Data Protection Commission of Ghana, or to your own supervisory authority if you are in the UK or the EEA. We would rather you told us first, but that is your choice and not a precondition.

8. Children

This platform is not intended for children under thirteen and we do not knowingly collect their data. If you believe a child has registered, tell us and we will delete the account.

9. Security

Data is encrypted in transit and at rest. Passwords are hashed. Access to production data is limited to the people who need it and is logged. Our database enforces access rules at the row level, which means the restriction is applied by the database itself rather than by the application remembering to ask.

No system is perfect. Where a breach affects your rights we will tell you and the Commission within the periods the law sets, and we will say what happened rather than describing it in a way designed to sound smaller.

10. Changes

When this policy changes materially we will say so on the site and, where the change affects how we use data you have already given us, by email. The date at the top of this page is the date of the current version.