01 — Information We Collect
What Data We Hold
At SESA, we collect and process personal data based on explicit consent provided during account registration.
We only collect what is necessary to deliver the platform's services safely and effectively.
- Registration Data: Name, username, email address, date of birth, gender, and school
details.
- Health & Assessment Data: Responses to psychological assessments and the AI-generated
or counsellor-provided clinical feedback associated with your scores.
- Professional Data (Counsellors only): National ID numbers (Ghana Card) and professional
certification details.
- Technical Data: IP addresses and browser session metadata collected automatically to
maintain platform security.
02 — Functional Usage
How We Use Your Information
The information collected is strictly used for the following core purposes:
- Operating and maintaining the SESA platform effectively.
- Calculating mental health assessment scores to provide context-aware, personalised clinical feedback.
- Enabling authorised school administrators and verified counsellors to support students identified at
elevated or clinical risk.
- Ensuring secure communication channels between counsellors and students.
- Maintaining audit trails of authorised data access for accountability.
03 — Security Standards
How We Protect Your Data
We implement robust, industry-standard security safeguards to protect your data at every layer:
- Encryption at Rest: Highly sensitive health data (clinical feedback) and National IDs are
encrypted at rest using Fernet symmetric encryption.
- Password Hashing: All passwords are irreversibly hashed using PBKDF2 — they are never
stored in plain text.
- Audit Logging: All system and clinical events are securely logged to maintain
accountability and track authorised actions without exposing sensitive payload content.
- Access Controls: Data is accessible only to the specific role authorised to view it
(e.g., a student's results are not visible to other students).
04 — Retention Policy
How Long We Keep It
We only retain your personal data for as long as necessary to fulfill the operational purposes outlined in
this policy. In accordance with the data minimality principles of the Ghana Data Protection Act 2012 (Act
843):
Inactive accounts that have not been accessed for five (5) consecutive years are
automatically and permanently purged from our systems. You may also request deletion at any time through your
Account Settings.
05 — Data Subject Rights
Your Rights Under Act 843
Under Ghana's Data Protection Act, you inherently retain full control over your personal data on the SESA
platform. These rights are exercisable at any time through your Account
Settings.
Right to Access
Review your assessment history and results at any time from your personal dashboard.
Right to Portability
Export a full, machine-readable JSON copy of your personal data and complete assessment history.
Right to Rectification
Contact your school administrator or our team to correct inaccurate data held on your account.
Right to Erasure
Permanently delete your account and withdraw consent for further processing of your data at any time.