PRODUCTION NOC: ACCRA-CLUSTER-01
UTC --:--:-- 99.98% SLA
Home / Governance & Compliance / Privacy Policy

Operational Data & Privacy Policy

Operational compliance standards, data handling procedures, cryptographic audit mandates, and uptime SLA commitments for Npontu SRE systems.

Revision: 2026.1 (Active) • Npontu Legal
Active Production Policy • Legal Ref: OPSORA-SRE-POL-01

Effective Date: January 1, 2026 • Last Reviewed: September 17, 2026

Contact Data Protection Officer →

1 Scope and Architectural Purpose

This Operational Data & Privacy Policy governs the collection, processing, storage, and forensic archiving of operational telemetry, telemetry health probes, user activity records, shift handover briefs, and real-time operational communications executed within the Opsora SRE platform ("Opsora SRE", "we", or "the Platform").

This platform is strictly designated for internal site reliability engineering, telemetry monitoring, shift custody transfer, and infrastructure oversight across enterprise telecommunications and payment gateway nodes.

2 Categories of Operational Data Collected

A. Operator Identity & Authentication

Full name, authorized operator email address (email@email.com / enterprise SRE domain), SRE technical grade (L1 through L5), assigned operational department, session tokens, and bcrypt-hashed password credentials.

B. Immutable Audit Trail Telemetry

Actor identity snapshots, client IPv4/IPv6 addresses, HTTP User-Agent strings, polymorphic model state mutations, before-and-after JSON attribute diffs, and cryptographic event timestamps.

C. Shift Handover & Custody Logs

Outgoing shift briefings, checklist completion states, blocker remarks, incident ticket references, and incoming lead sign-on verification stamps.

D. System Health Probes & Monitoring

Database latency heartbeats, cache eviction metrics, queue throughput, storage volume usage, and API response timings (< 100ms targets).

3 Legal Basis & Regulatory Compliance

Data processing on this platform is executed pursuant to:

  • Ghana Data Protection Act, 2012 (Act 843): Compliance with principles of lawful data processing, data minimization, and protection against unauthorized alteration.
  • ISO/IEC 27001:2022 Security Standards: Mandatory operational logging (Control A.8.15), separation of duties, and access privilege controls.
  • PCI-DSS v4.0 Requirement 10: Comprehensive audit logs tracking all access to system components and automated integrity verification.

4 Data Retention and Forensic Archival

Because this application provides mission-critical infrastructure oversight, audit records are subject to strict non-repudiation mandates:

Data Classification Retention Window Encryption At Rest Purge Policy
Immutable Audit Logs 7 Years (Statutory) AES-256 WORM (Write Once, Read Many) - No manual deletions
Shift Handover Sign-Offs 5 Years AES-256 Archived into compliance cold storage
Operational Chat War Rooms 2 Years AES-256 Automated annual archival rotation
Ephemeral Health Probes 90 Days AES-256 Rolled up into daily percentile summaries

5 Cookies, Session Tokens & Client Storage

Opsora SRE utilizes strictly necessary security tokens only. We do not use advertising, marketing, or third-party behavioral tracking cookies.

  • XSRF-TOKEN: Cryptographic token defending against Cross-Site Request Forgery attacks.
  • opsora_sre_session: Encrypted session identifier expiring after 120 minutes of inactivity.
  • local_storage / clock: Ephemeral UTC synchronization cache to ensure synchronized handover clocks across all engineering timezones.

6 Mobile Companion Application & App Store / Play Store Disclosures

The Npontu SRE Mobile Companion (available for Android and iOS) adheres strictly to Google Play User Data Policies and Apple App Store Review Guidelines (specifically Guideline 5.1.1 on Data Collection and Storage):

Mobile OS Permissions Requested

  • Push Notifications: Used exclusively for real-time P1/P2 incident escalations and shift handover transfer requests. No promotional or marketing notifications are ever sent.
  • Local Encrypted Storage: Encrypted shared preferences cache operational checklists, handover history, and active war rooms for offline resilience.
  • Camera / Photo Library: Strictly optional; used only if an operator chooses to attach an error screenshot or topology diagram to an operational chat or activity log.
  • Biometrics (FaceID / Fingerprint): Handled locally on-device by OS Secure Enclave / Keystore; biometric vectors are never transmitted to Npontu servers.

Zero Third-Party Trackers or Data Brokers

The mobile application does NOT include Google AdMob, Meta Audience Network, Firebase Analytics, or any third-party behavioral tracking SDKs. No Advertising ID (IDFA / AAID) is ever accessed or collected. All telemetry connects directly to authorized Npontu enterprise endpoints via TLS 1.3 encryption with certificate pinning capabilities.

7 Account Deletion & Data Subject Rights

In compliance with Apple App Store Guideline 5.1.1(v), Google Play User Data Policy, and the Ghana Data Protection Act (Act 843), any registered operator or authorized user possesses the right to request the deletion or deactivation of their account and the extraction of their personal information:

How to initiate account deletion: Users can request account deletion directly within the mobile application under Settings → Legal, Privacy & Compliance → Account Deletion, or by submitting an email to our Data Protection Office at hello@johnokyere.xyz with the subject line "Account Deletion Request - [Employee ID/Email]".

Processing & SLA: Deletion requests are acknowledged within 48 hours and processed within 30 days. Personal profile identifiers, direct message channels, and active authentication credentials will be permanently erased or cryptographically pseudonymized.

* Note on Statutory Compliance: In accordance with PCI-DSS v4.0 Requirement 10 and ISO 27001 Control A.8.15, historic immutable audit trail logs and formal shift handover custody records associated with past system mutations are retained in immutable cold storage for the statutory retention period (7 years) to satisfy regulatory non-repudiation requirements.

Governance & Data Protection Inquiries

For inquiries regarding compliance, forensic audit data extraction, or account deletion requests, contact the Opsora SRE Data Protection Office and SRE Security Lead:

Data Protection Officer:

hello@johnokyere.xyz

SRE Security & Compliance Lead:

hello@johnokyere.xyz