Kasamo
TermsPrivacyData deletion
Kasamo
TermsPrivacyData deletion

Privacy Policy

Last updated 7 October 2026

This policy explains what personal data Kasamo collects when you use it, why, who it is shared with, and the choices and rights you have. It applies to the Kasamo web application at https://kasamo.net.

On this page

  1. Who we are
  2. Information we collect
  3. Data from connected social networks
  4. How we use information
  5. Why we're allowed to use it
  6. Who we share it with
  7. Cookies and local storage
  8. How we protect it
  9. How long we keep it
  10. Your rights
  11. Where data is stored
  12. Children
  13. Changes to this policy
  14. Contact us

1. Who we are

Kasamo is a social media management service operated by Kasamo (“we”, “us”). We are the data controller for the account and usage data described here.

For content that workspaces create and publish (posts, media, comments), the business that owns the workspace decides what is collected and published. We process that content on its behalf to provide the service.

2. Information we collect

Information you give us

  • Account details: your name, email address and password. Passwords are stored only as a salted one-way hash, never in readable form.
  • Profile and preferences: your preferred time zone and the workspace you last opened.
  • Workspace information: workspace and business names, industry, time zone, logo, team members and their roles, and the email addresses of people you invite.
  • Content: posts and their text, links and schedules, images and videos you upload, comments, approval decisions, campaigns, and notes you add.
  • Support messages you send us.

Information created when you use the service

  • Sign-in sessions: the IP address and browser (user agent) of each signed-in session, used to keep your account secure.
  • Activity history: a log of actions in each workspace (for example who scheduled or approved a post), visible to the workspace's team.
  • Publishing records: when each post was published or failed, the network's post ID and link, and error messages.
  • Security and diagnostics: IP addresses are used briefly to limit repeated sign-in attempts. Server logs record errors and technical events. Passwords, access tokens and other secrets are removed from logs.

Payments

When paid plans are offered, payments are processed by our payment providers (Paystack and/or Hubtel). We never receive or store full card numbers or mobile money PINs. We keep the transaction reference, amount, currency, status and the plan purchased.

3. Data from connected social networks

When you connect a social account (for example a Facebook Page), you sign in with that network and choose what to share with Kasamo. We receive and store only what we need to publish and report on your posts:

  • the ID, name, username, profile picture and link of each Page or account you choose to connect;
  • the permissions you granted;
  • access tokens that let Kasamo publish on your behalf. They are encrypted (AES-256-GCM) before storage and are never shown to anyone;
  • the IDs and links of posts published through Kasamo;
  • engagement counts for those posts (for example reactions, comments and shares). These are refreshed for 30 days after publishing to show analytics.

Facebook: we request access to the Pages you select (permissions such as pages_show_list, pages_manage_posts, pages_read_engagement and publish_video). We use them only to list the Pages you manage, publish the posts you or your team schedule, and read engagement counts for those posts. We do not read your personal profile, friends, private messages or other people's data. We do not sell Facebook data, use it for advertising, or share it with anyone except as needed to provide the service.

Disconnecting an account in Kasamo deletes its access tokens immediately. You can also remove Kasamo's access from the network's own settings at any time. See Data deletion.

4. How we use information

  • To provide the service: create accounts and workspaces, store and schedule content, publish it to the networks you choose, and show analytics.
  • To send service emails: email verification, password resets, invitations, and notifications about approvals, comments and publishing results.
  • To keep the service secure: authenticate you, limit abuse, investigate problems, and keep audit records of administrative actions.
  • To support you and respond to requests.
  • To meet legal obligations, and to enforce our Terms of Service.

We do not sell personal data, show advertising, or use your content or social network data to train artificial intelligence models.

5. Why we're allowed to use it

We process personal data in line with Ghana's Data Protection Act, 2012 (Act 843) and, where it applies, similar laws such as the EU GDPR. We rely on:

  • Contract: to provide the service you or your organisation signed up for.
  • Consent: when you connect a social account. You can withdraw it at any time by disconnecting the account.
  • Legitimate interests: to keep the service secure and working, prevent abuse and improve reliability.
  • Legal obligation: where the law requires us to keep or disclose information.

6. Who we share it with

  • Your team: members of a workspace can see its content, activity and connected accounts, according to their role.
  • Social networks you choose: the content you publish is sent to those networks and becomes subject to their own privacy policies.
  • Service providers who run parts of the service for us under confidentiality and data-protection obligations: our hosting provider (servers and storage), our email delivery provider, file storage providers if used, and payment providers when you pay.
  • Legal reasons: when required by law, court order or a valid request from authorities, or to protect the rights and safety of users and the public.
  • Business transfers: if Kasamo is involved in a merger, acquisition or sale of assets. You will be told before your data becomes subject to a different policy.

7. Cookies and local storage

We use only what the service needs to work:

  • Session cookie (strictly necessary): keeps you signed in. It is secure and HTTP-only, and expires after 30 days or when you sign out.
  • Preferences: a cookie remembering whether the sidebar is open, and your light/dark theme choice saved in your browser.

We don't use advertising cookies or third-party tracking or analytics scripts.

8. How we protect it

  • All traffic is encrypted in transit with HTTPS.
  • Passwords are hashed, and social network tokens and stored credentials are encrypted at rest.
  • Access within a workspace is controlled by roles. Platform administrators' actions are recorded in an audit log.
  • Sign-in and other sensitive actions are rate-limited. Email addresses must be verified before an account can be used.
  • The database is backed up daily, and each backup is checked so it can be restored.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the relevant authorities as the law requires.

9. How long we keep it

  • Account and workspace data: for as long as the account or workspace exists.
  • Deleted posts are hidden immediately, and erased permanently when the workspace or account is deleted at your request (see Data deletion).
  • Social network access tokens: until you disconnect the account, then deleted immediately.
  • Read notifications: 90 days. Invitations expire after 7 days. Expired sessions and sign-in links are purged automatically.
  • Database backups: kept for 14 days, so deleted data disappears from backups within 14 days.
  • Payment records: as long as tax and accounting law requires.

10. Your rights

Under Act 843 and similar laws you can:

  • ask for a copy of the personal data we hold about you;
  • correct it. You can update your name and time zone yourself in Account settings;
  • ask us to delete it;
  • object to, or ask us to restrict, certain processing;
  • withdraw consent for a connected social account by disconnecting it;
  • complain to the Data Protection Commission of Ghana (dataprotection.org.gh) or your local data protection authority.

To make a request, email office@kasamo.net from the email address on your account. We may need to confirm your identity first. We aim to respond within 30 days.

11. Where data is stored

Our servers may be located outside Ghana. Social networks and some service providers process data in their own countries. Where data leaves Ghana, we use providers that offer appropriate safeguards, as Act 843 requires.

12. Children

Kasamo is a business tool and is not intended for anyone under 18. We do not knowingly collect data from children.

13. Changes to this policy

We will update this page when our practices change, and change the “Last updated” date. If the changes are significant, we will tell account owners by email or in the app before they take effect.

14. Contact us

Questions or requests about privacy: office@kasamo.net.