Effective date: July 2026

How Prymo Ltd collects, uses and protects your personal information

Prymo Ltd operates the One4all platform — airtime and data top-up, mobile money collections and disbursements, SMS and USSD services, gift vouchers and promotional PINs. To provide these services we must process your mobile number and transaction details. We use your information to complete your transactions, meet our legal duties under Ghanaian payments and anti-money-laundering law, protect against fraud, and support you. We do not sell your personal information. You can contact us, or complain to the Data Protection Commission, at any time.

1. About This Notice

This Notice explains what personal information Prymo Ltd (“Prymo”, “we”, “us”, “our”) collects about you, why we collect it, who we share it with, how long we keep it, and the rights you have. It applies to visitors to one4all.com.gh, to users of our USSD short codes, mobile app, web portals and APIs, to dealers, retailers, agents and merchants in our network, and to anyone who contacts us.

It is written to meet the requirements of the Data Protection Act, 2012 (Act 843) of Ghana — including the specific matters we must make you aware of under Section 27(2) — and international standards including the EU and UK General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA/CPRA).

2. Who We Are and How to Contact Us

Data controller: Prymo Ltd (operating the One4all platform).

Registered address: 23 Santana Street, Abelenkpe, opposite Obed Memorial House, Accra, Greater Accra Region, Ghana. Ghana Post GPS: GA-093-8615.

Postal address: P.O. Box CT 1254, Cantonments, Accra, Ghana.

Data Protection Officer: Data Protection Supervisor — prymodpo@one4all.com.gh.

General enquiries: customercare@one4all.com.gh — +233 55 614 5937.

Security and ISMS: isms.support@one4all.com.gh.

For most services we are the data controller — we decide why and how your information is used. For some services we act as a data processor on behalf of a business client: for example, when we deliver a promotional PIN campaign, run a fundraising collection, or operate a corporate airtime portal for an employer. In those cases, the client is the controller and you should also read their privacy notice.

3. What We Collect

While using our Service, we collect several categories of personal information for the purposes explained in this Notice:

3.1. Identity data. Name, date of birth, national identification (Ghana Card) number and business registration details — collected from dealers, retailers, agents and merchants, not from ordinary top-up users.

3.2. Contact data. Mobile number (MSISDN), email address, postal address, GhanaPost GPS address.

3.3. Account and wallet data. Virtual wallet identifier and balance, retailer or merchant code, account status, and authentication credentials (which we store only in encrypted or hashed form).

3.4. Transaction data. Top-up amounts, the number topped up, network operator, date, time, channel used, transaction references, e-value transfers and commissions.

3.5. Mobile money data. Your mobile money wallet number, the provider, payment references and status. We do not receive or store your mobile money PIN.

3.6. USSD and session data. The short code dialled, menu selections, session identifiers and timestamps.

3.7. Messaging data. SMS delivery records and metadata. Where we transmit messages for a business client, we handle content strictly on that client's instructions.

3.8. Technical and usage data. IP address, device and browser type, operating system, app version, pages visited and approximate location derived from your IP address or network.

3.9. Communications data. Your correspondence with customer care, complaint records and, where calls are recorded, call recordings (you are told at the start of the call).

3.10. Marketing data. Your preferences and consent records.

We do not seek special category data — information about health, religion, ethnicity, political opinions, or similar. Please do not include such information in messages to us. Biometric or identity-document data is collected only where anti-money-laundering law requires us to verify a dealer, agent or merchant.

4. Why We Use It, and Our Legal Basis

Prymo uses the collected data for various purposes, on the following lawful bases:

4.1. Completing your top-up, transfer, voucher or payment transaction. Data used: contact, transaction, wallet, mobile money. Lawful basis: performance of a contract.

4.2. Verifying the identity of dealers, retailers, agents and merchants. Data used: identity, contact, business. Lawful basis: legal obligation — Anti-Money Laundering Act, 2020 (Act 1044) and Payment Systems and Services Act, 2019 (Act 987).

4.3. Preventing, detecting and investigating fraud and financial crime. Data used: transaction, technical, identity. Lawful basis: legal obligation and legitimate interests.

4.4. Keeping transaction and accounting records. Data used: transaction, identity. Lawful basis: legal obligation — tax, company law and payments regulation.

4.5. Providing customer support and resolving complaints. Data used: contact, transaction, communications. Lawful basis: contract and legitimate interests.

4.6. Securing our platform and networks. Data used: technical, usage. Lawful basis: legitimate interests and legal obligation — Cybersecurity Act, 2020 (Act 1038).

4.7. Improving our services and reporting to business clients. Data used: usage, transaction (aggregated or pseudonymised). Lawful basis: legitimate interests.

4.8. Sending you marketing about our services. Data used: contact, marketing. Lawful basis: consent — you may withdraw at any time.

4.9. Non-essential cookies and analytics. Data used: technical, usage. Lawful basis: consent.

Where we rely on legitimate interests, we have carried out a balancing assessment to confirm that our interest does not override your rights, and you may object at any time using the contact details above.

5. Is Providing Your Information Mandatory?

Providing your information is voluntary — but some of it is necessary. Your mobile number and transaction details are required to complete a top-up or payment: without them the transaction simply cannot be executed. For dealers, retailers, agents and merchants, identity verification information is required by law, and we cannot onboard you without it. Marketing preferences, optional profile details and non-essential cookies are entirely optional, and declining them has no effect on the service you receive.

6. Who We Share It With

We may disclose personal information that we collect, or you provide:

6.1. Telecommunications operators and e-value providers — to route and fulfil your top-up or data purchase.

6.2. Mobile money providers, banks and payment partners — to collect or disburse funds.

6.3. Business clients — where we operate a corporate portal, promotional campaign or fundraising collection for them, and only within the scope of that arrangement.

6.4. Merchants — limited voucher validation data when you redeem a UGift voucher.

6.5. Service providers — hosting, messaging, analytics and support providers, bound by written contracts requiring confidentiality and security.

6.6. Regulators and authorities — the Data Protection Commission, Bank of Ghana, National Communications Authority, Financial Intelligence Centre, tax authorities, the Cyber Security Authority, courts and law enforcement, where required by law or valid legal order.

6.7. Professional advisers and, in a business sale, a purchaser — subject to confidentiality, and we will tell you before your data becomes subject to a different privacy notice.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

7. Sending Information Outside Ghana

Prymo's platform is deployed in Ghana and in the Democratic Republic of Congo, and we intend to expand across Africa but we do not share your information. Some of our service providers also process data outside Ghana. Where personal information leaves Ghana, we ensure one of the following: the destination provides an adequate level of protection; appropriate contractual safeguards are in place, such as standard contractual clauses; or the transfer is otherwise permitted under Act 843.

8. How Long We Keep It

8.1. Transaction and payment records: 6 years, for tax, company and payments-regulation record-keeping.

8.2. Dealer, agent and merchant identity records: 6 years after the relationship ends. Anti-money-laundering law requires a minimum of 5 years; we apply 6 for consistency.

8.3. Account and wallet data: 6 years after account closure, for dispute resolution and statutory records.

8.4. USSD and session logs: 12 months, for troubleshooting and fraud investigation.

8.5. Customer care records: 24 months, for service quality and complaint handling.

8.6. Marketing preferences: until you withdraw, or 24 months of inactivity, for consent-based processing.

8.7. Website analytics: 12 months, proportionate to the purpose.

8.8. Security logs: 12 months, for security monitoring.

9. How We Protect It

Prymo has adopted ISO/IEC 27001 and operates an Information Security Management System. Our measures include encryption of data in transit and at rest, role-based access control on a need-to-know basis, multi-factor authentication for administrative access, network segregation and monitoring, secure development practices, staff confidentiality obligations and training, and contractual security requirements on our suppliers. No system is completely secure, but we review and strengthen our controls continuously. If a personal data breach is likely to place your rights at risk, we will notify the Data Protection Commission and, where required, you — without undue delay.

10. Your Rights

In certain circumstances, you have the following data protection rights:

10.1. Be informed: to know how we use your information — which this Notice provides.

10.2. Access: to ask for a copy of the personal information we hold about you.

10.3. Rectification: to have inaccurate or incomplete information corrected.

10.4. Erasure: to ask us to delete your information, subject to records we must keep by law.

10.5. Restriction: to ask us to pause processing while a concern is resolved.

10.6. Object: to object to processing based on legitimate interests, and to direct marketing at any time.

10.7. Portability: to receive your data in a structured, commonly used, machine-readable format.

10.8. Withdraw consent: to withdraw consent at any time, without affecting processing already carried out.

10.9. Automated decisions: not to be subject to a decision based solely on automated processing that significantly affects you, and to ask for human review.

10.10. Complain: to complain to us, and to the Data Protection Commission or your local supervisory authority.

To exercise any right, contact prymodpo@one4all.com.gh. We respond free of charge within thirty days, and will tell you if we need longer because a request is complex. We may ask you to verify your identity first, to protect your information.

11. Cookies

Our website uses cookies to keep the site working, remember your preferences and understand how the site is used. On your first visit you can accept or reject non-essential cookies; strictly necessary cookies are always active because the site cannot function without them. You can also manage cookies in your browser settings. Full details are in our Cookie Policy at one4all.com.gh/cookies.

12. Children

Our services are not directed at children, and we do not knowingly collect the personal information of anyone under 18 without the consent of a parent or guardian. If you believe a child has provided us with personal information, contact prymodpo@one4all.com.gh and we will delete it promptly.

13. Complaints

If you are unhappy with how we have handled your information or need to exercise your data protection rights, please contact our Data Protection Officer first via prymodpo@one4all.com.gh so that we can put it right or address your concerns. You also have the right to complain directly to the regulator:

Data Protection Commission, Information Services Department, Third Floor, Accra, Ghana. Telephone: +233 256 301 533. Email: info@dataprotection.org.gh. Website: dataprotection.org.gh.

14. Changes to This Notice

We may update this Notice as our services, technology or the law change. The current version is always published at one4all.com.gh/privacy, with its effective date. Where a change is significant, we will give you prominent notice before it takes effect, and where a change requires your consent, we will ask for it.

Prymo Ltd, 23 Santana Street, Abelenkpe, Accra, P.O. Box CT 1254, Cantonments, Accra, Ghana. prymodpo@one4all.com.gh | customercare@one4all.com.gh | +233 55 614 5937.