01 Introduction
TDTH Holdings Limited ("TDTH", "we", "us", or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or interact with our digital platforms.
We operate across multiple jurisdictions including the United Kingdom, Ghana, Kenya, Senegal, and Singapore. This policy is designed to comply with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and relevant local data protection legislation in each jurisdiction where we operate.
Important: By accessing or using our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our policies and practices, please do not use our services.
02 Definitions
For the purposes of this Privacy Policy, the following terms have the meanings set out below:
03 Data Controller Information
TDTH Holdings Limited is the data controller responsible for the processing of your personal data. Our registered office and primary contact details are as follows:
- Company Name: TDTH Holdings Limited
- Registered Office: [Registered Address], United Kingdom
- Email: privacy@tdth.com
- Data Protection Officer: dpo@tdth.com
For matters relating to our operations in specific jurisdictions, you may also contact our regional data protection representatives as published on our regional websites.
04 Information We Collect
We collect several types of information from and about users of our services, including:
4.1 Information You Provide Directly
- Identity Information: Name, title, date of birth, government-issued identification numbers, and biometric data where required for identity verification services.
- Contact Information: Email address, postal address, telephone number, and professional contact details.
- Account Information: Username, password, and security questions when you register for our services.
- Transaction Information: Details of payments to and from you, billing address, and other information required to complete financial transactions.
- Communications: Records of your correspondence with us, including emails, chat logs, and customer service interactions.
4.2 Information Collected Automatically
- Technical Data: IP address, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform, device identifiers, and other technology on the devices you use to access our services.
- Usage Data: Information about how you use our website, products, and services, including clickstream data, page response times, download errors, length of visits to certain pages, page interaction information, and methods used to browse away from the page.
- Location Data: General geographic location derived from your IP address or, with your consent, precise GPS location from mobile devices.
4.3 Information from Third Parties
We may receive personal data about you from various third parties, including:
- Technical, payment, and delivery service providers;
- Analytics providers such as Google Analytics;
- Identity verification and fraud prevention partners;
- Publicly available sources such as company registries and professional networks;
- Government agencies and regulatory bodies where legally required.
05 Legal Basis for Processing
We will only process your personal data where we have a valid legal basis under applicable data protection law. The legal bases we rely on include:
- Consent: Where you have given clear consent for us to process your personal data for a specific purpose.
- Contract: Where processing is necessary for the performance of a contract to which you are a party, or to take steps at your request before entering into such a contract.
- Legal Obligation: Where processing is necessary for compliance with a legal obligation to which we are subject, including anti-money laundering (AML) and know-your-customer (KYC) requirements.
- Legitimate Interests: Where processing is necessary for our legitimate interests or those of a third party, provided your interests and fundamental rights do not override those interests. Our legitimate interests include network and information security, fraud prevention, and business analytics.
- Vital Interests: Where processing is necessary to protect your vital interests or those of another natural person.
- Public Interest: Where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in us.
06 How We Use Your Information
We use the information we collect about you for the following purposes:
- To provide, operate, and maintain our services, including digital identity verification, cybersecurity solutions, and intelligent infrastructure platforms;
- To verify your identity and conduct due diligence in compliance with legal and regulatory requirements;
- To process transactions, manage payments, fees, and charges, and collect amounts owed to us;
- To communicate with you regarding your account, service updates, security alerts, and support requests;
- To improve our website, products, and services through research, analytics, and user feedback;
- To detect, prevent, and respond to fraud, security breaches, and other potentially prohibited or illegal activities;
- To comply with applicable laws, regulations, court orders, and government requests;
- To enforce our terms of service and other agreements;
- To provide you with information about goods and services that may interest you, where you have consented to receive such communications;
- To administer our business, including record-keeping, auditing, and corporate governance.
07 Data Sharing and Disclosure
We may share your personal data with the following categories of recipients:
7.1 Service Providers
We engage third-party companies and individuals to facilitate our services, provide services on our behalf, perform service-related functions, or assist us in analysing how our services are used. These include cloud hosting providers, payment processors, customer support platforms, and analytics providers.
7.2 Business Partners
We may share personal data with our strategic partners, including Memcyco and other cybersecurity, technology, and infrastructure partners, where necessary to deliver integrated services to you.
7.3 Government and Regulatory Authorities
We may disclose personal data where required by law, regulation, legal process, or governmental request, including to law enforcement agencies, regulatory bodies, and tax authorities.
7.4 Corporate Transactions
If TDTH is involved in a merger, acquisition, asset sale, financing, or similar transaction, your personal data may be transferred as part of that transaction, subject to appropriate confidentiality protections.
7.5 With Your Consent
We may share your personal data with third parties when you have given your explicit consent to such sharing.
Important: We do not sell your personal data to third parties for marketing purposes. Any sharing of data is conducted under contractual safeguards and in accordance with this Privacy Policy.
08 International Data Transfers
TDTH operates globally, and your personal data may be transferred to, stored at, and processed in countries outside your country of residence, including the United Kingdom, Ghana, Kenya, Senegal, Singapore, and the United States.
When we transfer personal data outside the UK or EEA, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the UK Information Commissioner's Office;
- Adequacy decisions by the UK Secretary of State or the European Commission;
- Binding Corporate Rules for intra-group transfers;
- Other legally recognised transfer mechanisms.
We take all reasonable steps to ensure that your personal data is treated securely and in accordance with this Privacy Policy and applicable data protection laws, regardless of where it is processed.
09 Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements.
The criteria used to determine our retention periods include:
- The duration of our ongoing relationship with you;
- Legal and regulatory obligations requiring us to retain records for specified periods;
- Statutes of limitations applicable to potential legal claims;
- Our legitimate business needs and operational requirements;
- Your consent and preferences regarding data retention.
When personal data is no longer required, we will securely delete or anonymise it in accordance with our data retention schedule and applicable law.
10 Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using TLS 1.3 and at rest using AES-256;
- Multi-factor authentication for access to systems containing personal data;
- Role-based access controls and principle of least privilege;
- Regular security assessments, penetration testing, and vulnerability management;
- Incident response and business continuity planning;
- Staff training on data protection and information security;
- Physical security measures at our facilities and data centres.
Despite our efforts, no method of transmission over the internet or electronic storage is completely secure. While we strive to use commercially acceptable means to protect your personal data, we cannot guarantee its absolute security.
11 Your Data Protection Rights
Depending on your location and applicable law, you may have the following rights regarding your personal data:
- Right to Access: You have the right to request copies of your personal data.
- Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or incomplete.
- Right to Erasure: You have the right to request that we erase your personal data, subject to certain conditions.
- Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data.
- Right to Object: You have the right to object to our processing of your personal data, including for direct marketing purposes.
- Right to Data Portability: You have the right to request that we transfer the data we have collected to another organisation, or directly to you, in a structured, commonly used, and machine-readable format.
- Right to Withdraw Consent: Where we rely on your consent, you have the right to withdraw that consent at any time.
- Right to Complain: You have the right to lodge a complaint with a supervisory authority if you believe our processing violates applicable data protection law.
To exercise any of these rights, please contact us using the details provided in Section 3. We will respond to your request within the timeframe required by applicable law.
12 Cookies and Tracking Technologies
We use cookies and similar tracking technologies to track activity on our services and store certain information. Cookies are files with a small amount of data which may include an anonymous unique identifier.
The types of cookies we use include:
- Essential Cookies: Necessary for the website to function properly and cannot be switched off in our systems.
- Performance Cookies: Allow us to count visits and traffic sources so we can measure and improve the performance of our site.
- Functional Cookies: Enable the website to provide enhanced functionality and personalisation.
- Targeting Cookies: May be set through our site by our advertising partners to build a profile of your interests.
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our services.
13 Children's Privacy
Our services are not intended for individuals under the age of 18. We do not knowingly collect personal data from children under 18. If we become aware that we have collected personal data from a child under 18 without verification of parental consent, we will take steps to remove that information from our servers.
If you are a parent or guardian and you believe your child has provided us with personal data, please contact us immediately so that we can take appropriate action.
14 Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, and other factors. When we make material changes, we will notify you by updating the "Last Updated" date at the top of this policy and, where appropriate, by providing additional notice through our services or by email.
We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of our services after any changes constitutes your acceptance of the revised policy.
15 Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, please contact us:
- Email: privacy@tdth.com
- Data Protection Officer: dpo@tdth.com
- Postal Address: TADTH, [Registered Office], Ghana