Privacy Policy
Transparency for clients and visitors in Ghana, the UK, the EU, and worldwide — aligned with applicable data protection expectations.
Introduction & scope
This Privacy Policy describes how Hush UX Studio (“HUX”, “we”, “us”, or “our”) processes personal data when you use our websites, engage our professional services, communicate with us, or otherwise interact with our digital properties.
We work with clients and partners based in Ghana, across Africa, in the United Kingdom, the European Economic Area, the United States, and other jurisdictions. We aim to meet applicable privacy expectations in those regions, including the Ghana Data Protection Act, 2012 (Act 843) where it applies to our processing, and—where relevant—requirements aligned with the UK GDPR / EU GDPR for international engagements.
This policy is a general statement. Specific engagements may be governed by additional data processing terms, statements of work, or data processing agreements that supplement or supersede parts of this document where they expressly say so.
Who we are & contact
Hush UX Studio provides product design, UX/UI, software engineering, and related consulting services. Depending on your relationship with us, we may act as a data controller (for example, for marketing, recruitment, or account administration) or as a data processor on behalf of a client (for example, when we host or process personal data strictly under a client’s instructions).
For privacy questions, data subject requests, or complaints, contact us at [email protected]. We will respond within a reasonable period and, where required by law, within statutory timelines.
Personal data we collect
We may collect identifiers and contact data (such as name, email address, phone number, company name, role), professional information (such as job title, industry, procurement details), technical data (such as IP address, device type, browser, approximate location derived from IP, and diagnostic logs), usage data (such as pages viewed and interaction events where analytics are enabled), and content you voluntarily provide (such as messages, briefs, attachments, or feedback).
Where you engage us for services, we may also process billing identifiers, purchase history, and records necessary to perform contracts. Where permitted, we may collect references or due-diligence information for enterprise engagements.
How we use personal data & lawful bases
We use personal data to: provide and improve our services; communicate with you; operate our websites and security controls; comply with law; manage accounts and invoicing; analyse aggregated usage trends; and—where permitted—send relevant marketing that you can opt out of at any time.
Depending on context, we rely on lawful bases such as: performance of a contract; legitimate interests that are not overridden by your rights (for example, securing our systems or measuring website performance); consent where required (for example, certain marketing cookies or non-essential communications); and legal obligations.
Ghanaian clients & local expectations
For clients and users in Ghana, we recognise the importance of lawful processing, purpose limitation, data minimisation, and accountability under the Ghana Data Protection Act, 2012 (Act 843). We apply reasonable organisational and technical measures consistent with international good practice, adapted to the nature of our work and the sensitivity of the data we handle.
Where we process personal data on behalf of a Ghanaian organisation, our client typically determines the purposes of processing; we follow documented instructions and assist with appropriate safeguards as agreed in writing.
International transfers & safeguards
Because we operate remotely and use cloud tooling, personal data may be processed in Ghana and in other countries where our subprocessors operate (including the United States, the European Union, and the United Kingdom).
Where transfers require additional safeguards, we use mechanisms appropriate to the circumstances—such as standard contractual clauses, UK addenda, or other lawful transfer tools—and we assess high-risk processing where required. Copies of relevant safeguards may be available on request subject to confidentiality.
Retention
We retain personal data only as long as necessary for the purposes described in this policy, including to satisfy legal, accounting, or reporting requirements. Retention periods vary by data category and contract.
When data is no longer needed, we delete or anonymise it where feasible, subject to backup and archival constraints.
Security
We implement administrative, technical, and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, or destruction. No method of transmission or storage is completely secure; we encourage clients to use secure channels for sensitive materials.
Your rights
Depending on your location and the role we play (controller vs processor), you may have rights to access, rectify, erase, restrict processing, object to certain processing, withdraw consent where processing is consent-based, and request portability where applicable. You may also have the right to lodge a complaint with a supervisory authority.
Where we process data as a processor for a client, we may need to direct your request to that client, who is responsible for responding. We will assist our clients as required by contract and law.
Third parties & subprocessors
We use service providers for hosting, email, analytics, productivity, customer support, payments (where applicable), and similar functions. We select vendors with reasonable security practices and appropriate contractual protections where required.
A current summary of categories of subprocessors can be provided on request for enterprise clients under NDA.
Children
Our services are directed to businesses and professionals. We do not knowingly collect personal data from children without appropriate authority. If you believe we have collected data from a child inappropriately, contact us and we will take appropriate steps.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated through reasonable means (for example, posting an updated policy with a revised “Last updated” date, or emailing clients where appropriate).
Legal reservations
This policy is provided for transparency and does not create rights for third parties. It is not legal advice. If any provision is held unenforceable, the remainder remains in effect.
Nothing in this policy limits our ability to disclose information where required by law, court order, or lawful government request, subject to applicable review where permitted.