How we protect your identity, your money and your record.
You are trusting us with identity documents and your company’s legal record. This page sets out what we do with them, what we never do, and who is responsible for what.
Private company · Not a government agency · Government fees shown separately
Who we are, and how we protect you.
The short version. Each point is explained in more detail below.
A private company
GHBusinessDesk is a private business-services company. We are not a government agency and we do not decide registrations.
- Company
- GHBusinessDesk
- Data Protection Commission
- To be issued
- Ghana office
- Accra, Ghana
Vetted partner professionals
Lawyers, chartered accountants and company secretaries, each licence-verified before they work on a GHBusinessDesk file. Their fees always appear on their own line.
- Commissioner-for-oaths witnessing and partner-witnessed signing
- Qualified company secretaries for new companies
- Foreign-investment and GIPA advice from partner lawyers
Our service levels
- First review within 1 working day of payment
- Submission within 1 working day of a complete, clean file
- Replies within 4 working hours, 08:00–21:00 GMT
- Documents in your vault within 1 working day of approval
Authority processing time is outside our control and never promised.
Refunds
- Before review starts: Full refund.
- During review, before submission: 50% of our service fee, plus all government fees not yet paid.
- After submission: Service fee not refundable.
- Rejected because of our error: Free rework or a full service-fee refund, and we cover any repeat government fee.
- Rejected because of information you provided: Rework at a reduced service fee. Government and professional fees already paid are not refunded.
Government fees already paid to an authority are refunded only if the authority refunds them.
Security
- Documents encrypted in transit and at rest
- Every access to your file is logged
- Staff see only the files they are assigned
- Registration with the Data Protection Commission
What we do not do
Three parties, three different jobs.
Every application involves an authority that decides, GHBusinessDesk that prepares and tracks, and sometimes a licensed professional. The same distinction runs through our terms, our screens and our partner contracts.
| Responsibility | Government authority | GHBusinessDesk | Professional partner |
|---|---|---|---|
| Decides on your registration | Yes | Never | No |
| Sets government fees and requirements | Yes | NoWe reflect them, from a versioned schedule | No |
| Prepares and submits applications | No | YesWhere the law permits | Yes |
| Gives legal or tax advice | No | NoGeneral guidance only | YesUnder their licence |
| Holds your documents | Its own records | YesAs data controller or processor | Case documents onlyThose shared for their task |
| Is responsible for | Its decisions | Our preparationIts accuracy, our service levels and data security | Their professional work |
Government authorities include the Office of the Registrar of Companies, the Ghana Revenue Authority, the Ghana Investment Promotion Authority and local assemblies.
Security is part of the product.
These are the controls the GHBusinessDesk platform is built to. They are our commitments, and we will be held to them.
Encryption
- TLS 1.2 or later for every connection, with HSTS
- Encryption at rest, with keys separated by data class
- Identity numbers encrypted again at field level
- Keys rotated on a schedule
Access control
- Your business’s data is walled off from every other customer’s
- Staff see only the applications assigned to them
- Partners see only the case they are working on
- Multi-factor sign-in for staff and partners, and for owners of companies
Audit logging
- Every view, download, share and status change is logged
- Each entry records who, when and why
- Logs are append-only and chained, so edits show
- Stored separately from the systems they record
Your documents
- Private storage only; never a public link
- Every upload scanned for malware before it is accepted
- Downloads through short-lived links, logged before issue
- Replaced versions kept, never overwritten
Collecting less
- We ask only what your application requires
- Identity details masked on screen by default
- Abandoned drafts deleted after 90 days
- Messages carry links, never your documents
Resilience and testing
- Automated backups held in a separate region and account
- Restores rehearsed every quarter
- Critical security fixes applied within 72 hours
- An external penetration test every year and after major releases
Every cedi has a named destination.
How we handle fees is part of how we earn trust, so the rules are the same on every order.
- Government fees are passed through at cost and paid to the authority through its own channel. The authority’s receipt is attached to your case.
- The GHBusinessDesk service fee is fixed for your selection and shown before you enter any details.
- Professional fees are held and paid to the partner only after their work is signed off as complete.
- Payments are processed by a licensed payment provider. An order is marked paid only when the provider confirms it.
- Refunds follow a published matrix and go back to the method you paid with.
The Data Protection Act, 2012 (Act 843).
Ghana’s data protection law governs how we collect, use, keep and share personal data. The Data Protection Commission oversees it.
- Our role
- Data controller or processor, depending on the dataThe privacy notice explains which applies
- DPC registration
- To be confirmedWe register with the Commission before we process personal data
- Accountable person
- A designated data protection supervisorName to be confirmed
- Your rights
- To see, correct and, where the law allows, delete your data, and to complain to the Commission
How long we keep things
| Record | Kept for | Why |
|---|---|---|
| Official registration documents | For as long as you are a customer, plus 7 years | Your company record; legal limitation periods |
| Identity documents | For as long as the person holds the role, plus 7 years, or earlier on a lawful deletion request | Evidence of verification; collecting no more than needed |
| Payment records and receipts | 7 years after the transaction | Accounting and tax records |
| Abandoned drafts | 90 days after last activity | Collecting no more than needed |
| Audit records | 10 years | Accountability and resolving disputes |
A written plan for security incidents.
We follow the same steps every time, with a named owner, so nothing depends on memory in a stressful moment.
Triage
Assess severity. The most serious incidents get a response within 15 minutes.
Contain
Stop the problem spreading: revoke access, isolate systems, rotate keys.
Preserve evidence
Keep the logs and records needed to understand what happened.
Assess the impact
Work out whose personal data, if anyone’s, was affected, and how.
Notify
Tell the Data Protection Commission and the people affected, as the law requires.
Recover and review
Restore service, then publish the lessons internally and fix the cause.
What we do, and what we do not.
We do
- Check your file for completeness and consistency before it is submitted
- Prepare and submit applications where the law allows a non-professional to do so
- Pay each government fee to the authority and attach its receipt
- Show every status, the next action and who owns it
- Keep your documents in an encrypted vault, with every access logged
- Bring in a vetted, licensed professional where the law requires one
We do not
- Decide registrations or approvals; the authority does
- Promise how long an authority will take
- Give legal or tax advice; a licensed partner does, directly
- Add anything to government fees or bundle them into ours
- Present ourselves as a government body, or use government colours or crests
- Send your documents as message attachments
Start today. Finish when it suits you.
No account needed until you’re ready to save. Most people finish the questions in about 12 minutes.
Private company · Not a government agency · Government fees shown separately
