1. Introduction
Cauta Solutions Group Limited ("we", "us", or "our"), a company incorporated in Ghana with its registered office in Accra, Ghana, operates the CautaManage platform for serviced-apartment operations and real-estate development & construction management. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform, website, and mobile applications.
This Privacy Policy is drafted in accordance with the Data Protection Act, 2012 (Act 843) of the Republic of Ghana and is subject to the oversight of the Ghana Data Protection Commission (DPC). For our serviced-apartment functionality, it also reflects the obligations of accommodation operators under the Immigration Act, 2000 (Act 573) and the operational guidance of the Ghana Immigration Service (GIS) regarding the maintenance and disclosure of foreign-guest registers.
By accessing or using CautaManage, you agree to this Privacy Policy. If you do not agree, please discontinue use of our services.
1.1 Data Controller and Processor
The CautaManage subscriber — a serviced-apartment operator or a property developer — that subscribes to the platform is the data controller. It determines the purposes and means of processing the personal data of its guests, staff, investor-owners, off-plan buyers, and contractors. Cauta Solutions Group Limited acts as a data processor, processing personal data on behalf of and under the instructions of the subscriber, in accordance with Act 843.
Cauta Solutions Group Limited is registered with the Ghana Data Protection Commission as a data controller. We act as the data controller for the personal data we collect for our own purposes — platform accounts and login records, support and privacy requests, enquiries and demo requests submitted through our websites, and job applications — and as a data processor for the subscriber data described above. Subscribers (data controllers) are responsible for registering their own data processing activities with the DPC where required under Section 46 of Act 843, and for ensuring that data entered into the platform — including guest passport and identification details, buyer identification numbers, contact records, and contractor details — is collected and used in compliance with applicable data protection laws.
1.2 Data Protection Supervisor
Cauta Solutions Group Limited has designated a Data Protection Supervisor responsible for overseeing compliance with Act 843 and coordinating with the Ghana Data Protection Commission. For data protection inquiries or complaints, contact our Data Protection Supervisor at privacy@cautamanage.com.
2. Information We Collect
CautaManage supports two kinds of operation — serviced-apartment management and real-estate development. Depending on which a subscriber uses, we process the categories below. Items are labelled where they apply to only one kind of operation.
2.1 Information You Provide
- Account information: name, email address, phone number, and password when you (operator or developer staff, investor-owner, guest, off-plan buyer, or contractor) create an account.
- Facility & development data: for serviced apartments — property name, address, unit details, and rate plans; for development — project name and location, the units (type, floor, price, specifications and photos), the bill of quantities (BOQ), budget lines, and the construction schedule and milestones. Plus configuration settings in both cases.
- Guest records (serviced apartments): guest names, nationalities, identification document types and numbers, dates of birth, and primary-guest flags entered by the operator during check-in. Identification numbers (passport / Ghana Card / driver's licence) are encrypted at rest the moment they are saved and are surfaced in cleartext only through the audited GIS foreign-guest register export (see section 5.2).
- Booking data (serviced apartments): check-in and check-out dates, unit assignment, rate plan applied, total charged, payment status, and guest contact details for stay-related notifications.
- Buyer & sale records (development): buyer names, contact details, national identification document type and number, sale contract details, deposit and purchase price. Identification numbers (Ghana Card / passport / driver's licence) are encrypted at rest the moment they are saved and are surfaced in cleartext only through an audited, management-only reveal action (see section 5.3).
- Payment-plan data (development): instalment schedules whose payments fall due as construction milestones are reached, deposit and payment status, and the amounts and currency (GHS or USD) applied to each instalment.
- Financial data: billing accounts, charges, payment records and invoicing details; per-investor commission entries for serviced apartments (gross amount, operator share, investor share, paid / pending status); and, for development, budget / committed / spent figures by line, tender awards, variations, progress draws and valuation certificates, invoices and purchase orders.
- Smart-lock data (serviced apartments): per-stay PIN values are encrypted at rest; the cleartext PIN is shown to the operator exactly once at issue and never recoverable thereafter.
- Site & quality records (development): requests for information (RFIs), non-conformance reports (NCRs) and their corrective-action lifecycle, inspection checklists and scores, daily site-diary entries with photos, and snagging (punch-list) items at handover.
- Contractor & tender data (development): tender and bid packages, prices submitted by contractors against the BOQ, and the company and contact records held in the project directory.
- Documents: for development — permits, drawings, certificates and contracts uploaded against the project; served securely over short-lived secure links.
- Communications: messages sent through automated stay communications (pre-arrival, check-in, post-checkout) for serviced apartments; payment-plan reminders, milestone updates and handover invitations for development; and, in both cases, broadcast features, support tickets, and contact form submissions.
- Channel-manager data (serviced apartments): iCal feed URLs (for inbound OTA imports) and export tokens (for outbound OTA exports). Outbound tokens are stored only as hashes, never in cleartext; the token is shown to the operator exactly once at creation.
2.2 Information Collected Automatically
- Usage data: pages visited, features used, and actions taken within the platform.
- Device information: browser type, operating system, device type, and screen resolution.
- Log data: IP addresses, access times, and referring URLs.
- Audit log entries: every significant action is recorded with the actor, timestamp, and target object identifier for compliance and forensic purposes — including, for serviced apartments, views of the GIS foreign-guest register, downloads of investor-yield reports, smart-lock PIN issuance and revocation, and changes to rate plans; and, for development, reveals of a buyer's national identification number, access to secured documents, changes to payment plans and budget lines, and handover approvals.
- Cookies and similar technologies: session cookies for authentication and preferences.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the CautaManage platform.
- Process bookings, manage billing accounts, and compute per-investor commission entries (serviced apartments).
- Issue, push, and revoke smart-lock PINs against integrated hardware — Dahua / Hikvision / ZKTeco (serviced apartments).
- Generate the GIS foreign-guest register CSV for compliance with the Immigration Act, 2000 (Act 573) (serviced apartments).
- Synchronise availability with OTA channel partners (Airbnb, Booking.com, etc.) via iCal — strictly limited to BUSY/BLOCKED date ranges; no guest personal data is included in outbound iCal feeds (serviced apartments).
- Manage off-plan sales, build instalment plans tied to construction milestones, and record deposits and payments (development).
- Maintain the project budget — committing tender awards, variations, draws and valuation certificates into the relevant budget lines (development).
- Run tendering — distribute bid packages to invited contractors and receive their bids priced against the BOQ (development).
- Track site quality — RFIs, NCRs, scored inspections, the daily site diary, and snagging (development).
- Onboard owners at handover, so a completed sale carries straight into the buyer's owner portal (development).
- Send stay-related notifications, payment-plan reminders, milestone updates and handover invitations via email, SMS, and push notifications.
- Provide customer support and respond to inquiries.
- Monitor and analyze usage to improve our services.
- Detect, prevent, and address security issues and fraud.
- Comply with legal obligations.
3.1 Legal Basis for Processing
Under Act 843, we process personal data on the following lawful bases (Sections 18–20):
- Performance of a contract: processing necessary to provide the CautaManage platform as agreed in the subscription terms — e.g., booking management, PIN issuance and payment recording for serviced apartments; and off-plan sale management, payment-plan tracking and document storage for development.
- Consent: where explicitly obtained — for example, when a guest opts in to SMS notifications during check-in, when an investor-owner accepts a read-only invitation to view their unit's calendar, when an off-plan buyer opts in to SMS notifications, or when an investor accepts an invitation to their own read-only investor portal.
- Legitimate interest: processing necessary for security monitoring, fraud prevention, audit logging, and platform improvement, where such interests are not overridden by the data subject's rights.
- Legal obligation: processing required to comply with applicable Ghanaian laws, regulations, or court orders — including the foreign-guest register obligation under the Immigration Act, 2000 (Act 573) for serviced apartments, and record-keeping obligations for financial and tax purposes.
3.2 Sensitive Personal Data
The platform processes certain categories of sensitive personal data as defined under Section 37 of Act 843, including:
- National identification numbers (Ghana Card, passport, driver's licence) — collected during guest check-in for identity verification and GIS register compliance (serviced apartments), and from off-plan buyers for identity verification and to support the sale contract and the developer's know-your-customer obligations (development). Stored encrypted at rest; never displayed in cleartext except through the audited GIS export (section 5.2) or an audited, management-only reveal action (section 5.3).
- Nationality and date of birth — collected during guest check-in for GIS foreign-guest register compliance (serviced apartments).
- Smart-lock PIN values — treated as authentication secrets. Encrypted at rest; cleartext shown to the operator exactly once at issue and never recoverable thereafter (serviced apartments).
This data is processed only with the data subject's knowledge and for the specific purpose of facility operation, statutory compliance, and managing the sale and development. Subscribers are responsible for displaying appropriate consent and notice to guests and buyers at the point of data collection.
4. Data Sharing and Disclosure
We do not sell your personal information. We may share data in the following circumstances:
- Within your organisation: Operator or developer staff can view and manage the data for users, guests, units, sales, budget, site quality and documents within their property or development as required by their role.
- With investor-owners (serviced apartments): When an operator invites an investor as a read-only user of their unit, that investor sees their unit's calendar (BUSY/BLOCKED date ranges only) and their per-owner Investor Yield statement. Guest personal data is never exposed to investor-owner accounts.
- With buyers and investors (development): Each buyer or investor invited into their own portal sees only their own unit — their payment plan, the development's published progress and process, their unit's specifications and photos, their documents and financing details. They never see other buyers' data, or the developer's internal budget, BOQ or estimates.
- With contractors (development): An invited contractor sees only their own tender package. They price the BOQ lines and submit their bid, and never see the developer's estimate or any other contractor's bid.
- With Ghana Immigration Service (GIS) (serviced apartments): The foreign-guest register CSV produced by the platform is provided to the operator (data controller). The operator is responsible for submitting it to GIS in accordance with the Immigration Act. CautaManage facilitates the data preparation but does not transmit data to GIS directly.
- With OTA channel partners (Airbnb, Booking.com, VRBO, etc.) (serviced apartments): Only BUSY/BLOCKED date ranges are shared via outbound iCal feeds. No guest names, contact details, or identification data are ever included in iCal exports. Inbound iCal sync from OTAs imports only date-range data; we do not retrieve guest details from OTA APIs.
- Service providers: We use third-party services for email delivery (SMTP), SMS, payment processing (Paystack, Hubtel, MTN MoMo), push notifications (Firebase), and — where the developer enables it — accounting and ERP synchronisation (QuickBooks Online, Microsoft Dynamics 365 Business Central). These providers only receive the data necessary to perform their services.
- Smart-lock hardware (serviced apartments): Per-stay PINs are transmitted to the configured smart-lock controller (Dahua / Hikvision / ZKTeco) over the operator's local network or vendor cloud, depending on configuration. Only the PIN value and validity window are transmitted; no guest personal data is sent to lock hardware.
- Legal requirements: We may disclose information if required by law, regulation, or legal process.
5. Data Storage and Security
Your data is stored on secure servers. We implement industry-standard security measures including:
- Encryption in transit (TLS/HTTPS) for all communications.
- Encryption at rest for sensitive PII (guest and buyer identification numbers, smart-lock PINs, and OTA export tokens).
- Industry-standard password hashing algorithms.
- Secure session management with encrypted, HTTP-only cookies.
- Cross-site request forgery (CSRF) protection on all state-changing operations.
- Role-based access control to limit data access; investor-owners are limited to their unit's data, buyers and investors to their own unit's data, and contractors to their own tender package.
- Rate limiting and brute-force protection.
- Input validation and sanitisation to prevent injection attacks.
- SSRF guards on all outbound HTTP fetches (iCal sync from OTA partners; accounting / ERP synchronisation).
- Short-lived, signed links for access to stored documents, drawings and certificates (development).
- Site-diary photos recorded against the project, so the site record holds up when a delay or variation is disputed (development).
- Automated daily database backups, encrypted at rest.
- Comprehensive audit logging of all significant actions — including every view of the GIS register and every smart-lock PIN issue (serviced apartments), and every reveal of a buyer's national identification number and every access to a secured document (development).
- Webhook signature verification for all third-party integrations (payment gateways, lock hardware).
5.1 Data Breach Notification
In the event of a data breach that affects your personal data, we will notify affected subscribers without undue delay, and no later than 72 hours after becoming aware of the breach. The notification will include the nature of the breach, the categories and approximate number of records affected, and the measures taken or proposed to address the breach. Subscribers are responsible for notifying affected guests, buyers, investors, staff, and the Ghana Data Protection Commission as required by Section 30 of Act 843.
5.2 GIS Foreign-Guest Register (serviced apartments)
The platform produces a Ghana Immigration Service foreign-guest register on demand, in CSV format, listing non-Ghanaian guests of stays in a chosen date window. The CSV contains decrypted identification numbers required by the Immigration Act, 2000 (Act 573). Every download of this register is recorded in the audit log with the operator's identity, the date range, and the row count. Only operators with management-level access to the Rentals module may generate this export. The cleartext PII contained in the CSV file becomes the responsibility of the operator the moment it is downloaded; we recommend operators encrypt the CSV at rest and transmit it to GIS only through secure channels.
5.3 Buyer Identification Data (development)
National identification numbers collected from off-plan buyers are encrypted at rest the moment they are saved and are never returned in cleartext through ordinary read endpoints. A buyer's identification number can be revealed only through a deliberate, management-only action by a user with management-level access to the Development module. Every such reveal is recorded in the audit log with the actor's identity, a timestamp, and the buyer record concerned. The cleartext identification data becomes the responsibility of the developer the moment it is revealed; we recommend developers handle and store any exported identification data securely and share it only through secure channels.
6. Data Retention
We retain your data for as long as your account is active or as needed to provide services. Specific retention windows:
- Active account data — retained for the duration of the subscription. Subscribers may delete records within the platform.
- GIS foreign-guest register data (serviced apartments) — guest records are retained for 90 days after the last day of a guest's stay, after which the encrypted identification data is automatically purged from the live database and cannot be recovered. Backup archives may retain historical encrypted snapshots for longer per the operator's backup retention policy.
- Smart-lock PIN history (serviced apartments) — the encrypted-at-rest PIN values are deleted at PIN revocation (manual or automatic at stay checkout). Only the metadata (issue time, revoke time, push status) is retained for the audit trail.
- Buyer & sale records (development) — retained while the development and the buyer's account are active. National identification numbers are held encrypted at rest and can be purged on request, subject to the developer's legal and contractual obligations.
- Project & financial records (development) — budget, sales, draw and payment records are retained for the duration of the subscription and may be subject to longer statutory retention for tax and accounting purposes.
- Audit log entries — retained for the lifetime of the subscription; not user-deletable.
- Backup archives — retained per the subscriber's configured backup policy (default 90 days rolling), encrypted at rest.
Upon account termination, we will delete or anonymize live-database data within 90 days. Encrypted backup archives may persist for the subscriber's specified retention window unless the subscriber requests earlier purge.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data.
- Object to or restrict certain processing.
- Export your data in a portable format.
- Withdraw consent where processing is based on consent.
Under Section 34 of Act 843, you also have the right to compensation for damage suffered as a result of unlawful processing of your personal data.
To exercise these rights, contact our Data Protection Supervisor at privacy@cautamanage.com. Note that requests to delete records held under a statutory or contractual obligation — for example, foreign-guest data within the GIS retention window under the Immigration Act, or sale and payment records required for financial or tax purposes — may be limited by the subscriber's obligations. If you are not satisfied with our response, you have the right to lodge a complaint with the Ghana Data Protection Commission:
If you have a portal account, you can also send a request directly from My Account → Privacy & your data after signing in. We confirm every request by email and reply to the address on your account.
8. Cookies
The platform uses essential cookies for authentication and session management. These cookies are strictly necessary for the platform to function and cannot be disabled. We do not use advertising or tracking cookies.
The marketing site at cautamanage.com sets one first-party cookie to remember your cookie choices, and Cloudflare may set bot-protection cookies when a form is displayed. Traffic statistics come from Cloudflare Web Analytics, which is cookieless. Analytics and advertising cookies are switched off unless you enable them. The full list of cookies, their purposes and durations, and the controls for changing your choice at any time are in our Cookie Policy.
9. Third-Party Services
Our platform integrates with the following third-party services, each of which receives only the data necessary to perform its function:
- Paystack — for online payment processing.
- Hubtel — for mobile money payment processing.
- MTN MoMo — for direct mobile money settlement.
- SMS providers — for SMS notifications.
- Firebase (Google) — for push notifications.
- OTA channel partners (Airbnb, Booking.com, VRBO, etc.) — via iCal date-range exchange only; no guest PII (serviced apartments).
- Smart-lock vendors (Dahua, Hikvision, ZKTeco) — receive PIN value + validity window during stay activation (serviced apartments).
- QuickBooks Online (Intuit) — optional accounting synchronisation, where enabled by the developer (development).
- Microsoft Dynamics 365 Business Central (Microsoft) — optional accounting / ERP synchronisation, where enabled by the developer (development).
Each service has its own privacy policy. We encourage you to review their policies.
10. Children's Privacy
CautaManage is a business platform for serviced-apartment operators and property developers and their guests, buyers, investors and contractors. It is not intended for direct use by individuals under the age of 18. Where minors are recorded as part of a guest party (a family checking into a serviced apartment), the responsible parent or guardian is the data subject of record; the minor's name and date of birth are processed strictly for occupancy and statutory purposes under the explicit instruction of the booking guest and the operator. We do not otherwise knowingly collect personal data from children.
11. International Data Transfers
Your data may be processed in countries other than your country of residence. Specifically:
- Push notifications (Firebase/Google) — notification tokens and delivery metadata may be processed in the United States and other countries where Google operates data centres.
- Payment processing (Paystack, Hubtel, MTN MoMo) — transaction data is processed within their respective infrastructure.
- OTA channels (Airbnb, Booking.com, etc.) (serviced apartments) — iCal date-range data exchanged with their servers, typically located outside Ghana.
- Accounting / ERP synchronisation (QuickBooks Online / Intuit, Microsoft Dynamics 365) (development) — where enabled by the developer, the synchronised financial and contact data may be processed in the United States and other countries where these providers operate.
In accordance with Act 843, we ensure that each third-party processor provides a level of protection for personal data that is adequate and consistent with Ghana's data protection standards. We achieve this through contractual obligations, selecting processors with industry-standard security certifications (SOC 2, ISO 27001, or equivalent), and limiting transferred data to the minimum necessary.
Where a sub-processor is not domiciled in Ghana, Cauta Solutions Group Limited ensures that the sub-processor complies with the relevant laws of its country, as required by Act 843.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes at least 30 days in advance by posting the updated policy on our website with a revised "Last updated" date and notifying subscribers by email.
13. Contact Us
If you have questions about this Privacy Policy, contact us at: