Moneta Privacy Policy
Effective date: 16 Feb 2026
Last updated: 16 Jul 2026
1. Scope and privacy roles
This Policy explains how the Moneta platform collects, uses, shares, protects, and retains personal data. It is intended to reflect the Data Protection Act, 2012 (Act 843) of Ghana.
Moneta acts as a data controller for information used to create and administer platform accounts, secure the service, manage subscriptions and billing, provide support, and meet our own legal obligations. For personal data that a Customer uploads or manages about its members, students, guardians, staff, customers, suppliers, donors, event attendees, or payors, the Customer generally acts as the data controller and Moneta acts as its data processor or service provider.
2. Personal data we collect
- Account and organization data: names, email addresses, phone numbers, roles, permissions, organization details, subscription records, and support communications.
- Identity, compliance, and payout data: identity-verification records, Ghana Card information or images where required, bank or mobile-money payout details, verification results, and account-holder information.
- Payment and financial records: payment references, amounts, status, wallet, invoice, receipt, settlement, refund, reversal, and related transaction metadata. Full card details are handled by the Payment Provider and are not stored by Moneta.
- Customer-managed sector data: church membership and giving records; school applications, student, guardian, attendance, billing, and academic records; business customer, supplier, inventory, invoice, payroll, and accounting records; and event registration or attendee records.
- Communications and technical data: email and SMS delivery records, notification preferences, device and browser information, IP address, access and audit logs, cookies, uploaded media, and security events.
3. Sources of personal data
We receive data directly from Customers and Authorized Users, from people who use public payment, application, registration, or portal pages, from Payment Providers and communications providers, and automatically from use of the Services. Customers may also import data they are lawfully permitted to manage.
4. Why we process personal data
We process personal data to provide requested services and perform our contract; follow Customer instructions; authenticate users and apply permissions; create payment, billing, receipt, accounting, and audit records; configure and protect payout destinations; prevent fraud and misuse; send operational communications; provide support; improve reliability; and comply with legal obligations.
Depending on the context, processing is based on contract, consent, compliance with law, protection of legitimate interests that do not override individual rights, or another lawful basis available under applicable law. We do not use Customer Data for unrelated advertising.
5. Children and special personal data
School and family workflows may contain information about children. Customers must have an appropriate lawful basis, provide required notices, obtain parent or guardian authorization where required, limit access to authorized personnel, and avoid collecting more information than necessary. Moneta processes this data only to provide and secure the relevant Customer service or as required by law.
6. Sharing and service providers
We share only the data reasonably required with Payment Providers such as Paystack; email and SMS providers; hosting, database, security, monitoring, and media-storage providers; analytics providers where consent is given; professional advisers; and authorities where disclosure is legally required. Providers are expected to process data for the contracted purpose and apply appropriate safeguards.
We may also disclose information to prevent fraud or harm, investigate security incidents, enforce our Terms, complete a corporate transaction subject to appropriate protection, or follow a Customer's valid instructions.
7. International processing
Some infrastructure and service providers may process data outside Ghana. Where this occurs, we use reasonable contractual, organizational, and technical safeguards and consider the nature of the data and the protections available in the destination.
8. Retention
We keep personal data only for as long as it is reasonably needed for the purposes described in this Policy. Retention depends on the type of record, account status, Customer instructions, payment and accounting requirements, dispute and fraud-prevention needs, backup cycles, and legal obligations. Data may be deleted, anonymized, or retained with restricted access when the applicable period ends.
9. Security and incidents
Moneta uses administrative, technical, and organizational safeguards such as role-based access, encryption where appropriate, audit and security logging, provider verification, and OTP verification for sensitive payout changes. Customers remain responsible for Authorized User access, secure devices, and accurate security contact details. No service can guarantee absolute security.
We investigate suspected personal-data breaches and notify affected Customers, individuals, and the Data Protection Commission where notification is required by applicable law.
10. Your rights and choices
Subject to applicable law, individuals may request access to personal data, correction or deletion of inaccurate or unlawfully held data, information about processing, objection to certain processing or direct marketing, and review of qualifying automated decisions. Individuals may also complain to the Data Protection Commission and may have rights to compensation or other remedies.
For data controlled by a Customer, contact that organization first so it can assess and instruct Moneta. For Moneta-controlled data, email us using the address below. We may verify identity before acting and may retain information where law or valid security, fraud, accounting, or dispute requirements apply.
11. Cookies and analytics
Essential cookies support login, security, preferences, and core service operation. With permission, Moneta uses Google Analytics to understand public-page usage and improve the Services. Analytics storage is denied by default and the analytics script is not loaded unless analytics cookies are accepted. A browser's Moneta site data can be cleared to withdraw that choice.
12. Customer responsibilities
Customers must provide appropriate privacy notices, collect and use personal data lawfully, respond to requests concerning Customer-controlled data, configure access carefully, keep records accurate, and notify Moneta promptly of suspected unauthorized access. Customers must not upload data they have no right to process.
13. Changes to this Policy
We may update this Policy when the Services, providers, or legal requirements change. The current version and its last-updated date will be published here. We will provide additional notice where a change materially affects rights or is otherwise required by law.
14. Contact and complaints
For privacy questions or requests, contact support.moneta@ikobgh.com and include your organization name where relevant.
You may also contact Ghana's Data Protection Commission about your data-protection rights or a complaint.
15. Relationship to the Terms
This Privacy Policy should be read with the Moneta Terms of Service.