
How we collect, protect, and use your personal information
SureNett is an intelligent health insurance platform developed and operated by CoreNett Limited ("CoreNett," "we," "our," or "us"). CoreNett Limited is a systems infrastructure company incorporated in the Republic of Ghana, with its principal place of business at House #134 University Farm Road, Accra, Ghana.
This Privacy Policy describes how SureNett collects, uses, stores, shares, and protects personal information when you: (a) visit or interact with our website at www.surenett.com (the "Website"); (b) engage with us for business or procurement purposes; (c) access or use the SureNett platform; or (d) contact us for any other reason.
We are committed to processing personal data responsibly, transparently, and in compliance with applicable law — including the Data Protection Act, 2012 (Act 843) of Ghana, the regulations of the Data Protection Commission of Ghana, and other applicable data protection and privacy frameworks to the extent they apply to our operations.
Please read this Policy carefully. By accessing or using the Website or our services, you acknowledge that you have read and understood this Policy.
This Policy applies to:
Where SureNett processes personal data on behalf of an enterprise client (e.g., claims data or beneficiary records), the enterprise client is the data controller and SureNett acts as a data processor. In those cases, the client's own privacy notice governs end-users' rights, and SureNett's obligations are governed by the applicable data processing agreement.
For personal data collected directly through the Website and corporate interactions, CoreNett Limited is the data controller:
Legal Name: CoreNett Limited
Product: SureNett
Registration: Incorporated in the Republic of Ghana
Address: House #134 University Farm Road, Accra, Ghana
SureNett collects personal information only where it is necessary and proportionate to the purposes described in this Policy.
When you visit or interact with our Website, we may collect:
In the course of a business relationship, we may collect:
Where SureNett is deployed on behalf of an insurer, health maintenance organisation, or scheme administrator, personal data processed may include:
This data is processed on behalf of the enterprise client (the controller). SureNett does not use this data for its own commercial purposes beyond operating the contracted service.
Health information processed through the SureNett platform constitutes sensitive personal data under the Ghana Data Protection Act. We apply heightened security and access controls to such data and process it only on the basis of explicit consent, contractual necessity, or legal obligation.
SureNett does not:
SureNett processes personal data on the following legal grounds under the Ghana Data Protection Act, 2012 (Act 843) and, where applicable, equivalent provisions of international frameworks:
| Legal Basis | When It Applies |
|---|---|
| Consent | When you voluntarily submit information, subscribe to marketing communications, or grant permission for non-essential cookies or analytics. |
| Contract | When processing is necessary to respond to an enquiry, enter into or perform a contract with you or your organisation, or provide a requested service. |
| Legal Obligation | When processing is required to comply with the Ghana Data Protection Act, National Health Insurance Authority regulations, or other applicable law. |
| Legitimate Interests | When SureNett has a genuine business interest (e.g., website security, fraud prevention, analytics, product improvement) that does not override your fundamental rights and interests. |
| Vital Interests | In exceptional circumstances where processing is necessary to protect the life, health, or safety of an individual. |
We use cookies and similar tracking technologies on our Website. A cookie is a small text file placed on your device to help us provide a better user experience. We distinguish between the following categories:
| Category | Purpose | Can You Opt Out? |
|---|---|---|
| Strictly Necessary | Core website functionality: session management, security, form submission. | No — required for the site to function. |
| Performance / Analytics | Anonymised measurement of page visits, traffic sources, and user journeys to improve the Website. | Yes — via cookie consent settings. |
| Functional | Remembering preferences (language, form field data) to enhance your experience. | Yes — via cookie consent settings. |
| Marketing / Targeting | Tracking interactions to enable relevant advertising and measure campaign effectiveness. Used only with explicit consent. | Yes — disabled by default; enabled only with consent. |
You can manage cookie preferences at any time through your browser settings or our cookie preference centre on the Website. Disabling cookies may affect certain Website functions.
SureNett does not sell, rent, or trade your personal information. We may share data only in the following circumstances:
We engage trusted third-party vendors who process data on our behalf under written data processing agreements that require them to maintain equivalent data protection standards. Categories include:
Where SureNett acts as a data processor on behalf of an enterprise client, data may be shared back with that client or other processors they have authorised, strictly as directed by the client and within the scope of the data processing agreement.
We may disclose personal data where required to do so by law, court order, or regulatory directive — including to the Data Protection Commission, the National Health Insurance Authority (NHIA), or any other competent authority with jurisdiction.
In the event of a merger, acquisition, restructuring, or sale of all or part of CoreNett's business, personal data may be transferred as part of that transaction. We will provide notice and ensure appropriate safeguards are maintained.
We may share data with third parties where you have given explicit, informed consent for a specific purpose not otherwise covered by this Policy.
The SureNett platform embeds artificial intelligence, machine learning, and automated decision-support capabilities. We are committed to responsible AI governance, including:
Where a decision produces a significant legal or equivalent effect and is based solely on automated processing, individuals have the right to:
To exercise these rights, contact enquiries@corenett.com. In many cases, the relevant enterprise client (not SureNett) is the controller responsible for responding to such requests.
SureNett is headquartered in Ghana and primarily processes data within Ghana. Where it is necessary to transfer personal data to service providers or infrastructure located outside Ghana, we ensure appropriate safeguards are in place, which may include:
We do not transfer data to jurisdictions that we assess as presenting an unacceptable risk to the rights and freedoms of data subjects without additional safeguards.
SureNett implements a layered security architecture to protect personal data against unauthorised access, loss, disclosure, or destruction:
No method of data transmission or storage is completely secure. While we take rigorous measures, we cannot guarantee absolute security. If you believe your personal data has been compromised, please notify us promptly at enquiries@corenett.com.
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of affected individuals, SureNett will:
We retain personal data only for as long as is necessary for the purposes for which it was collected, or as required by applicable law or contract. Key retention considerations include:
When data is no longer required, we securely delete or anonymise it in accordance with our data destruction standards.
Under the Ghana Data Protection Act, 2012 (Act 843) and applicable regulations, you have the following rights in relation to your personal data:
| Right | What It Means |
|---|---|
| Right of Access | You may request confirmation of whether we hold your personal data and obtain a copy of it. |
| Right to Rectification | You may request correction of inaccurate or incomplete personal data. |
| Right to Erasure | You may request deletion of your personal data where it is no longer needed for the original purpose, or where you withdraw consent. |
| Right to Restriction | You may ask us to restrict processing of your data in certain circumstances (e.g., while accuracy is contested). |
| Right to Object | You may object to processing based on legitimate interests, including for direct marketing. |
| Right to Portability | You may request your data in a structured, machine-readable format for transfer to another controller. |
| Right to Withdraw Consent | Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing. |
| Right to Complain | You have the right to lodge a complaint with the Data Protection Commission of Ghana (www.dataprotection.org.gh). |
To exercise any of these rights, please submit a written request to enquiries@corenett.com. We will respond within 30 days (extendable to 60 days for complex requests, with notice). We may need to verify your identity before processing your request.
Note: Where SureNett processes data as a data processor on behalf of an enterprise client, please direct your rights request to that organisation (the data controller) in the first instance. SureNett will cooperate with and assist the controller in responding.
The SureNett Website and platform are not directed to, or intended for use by, children under the age of 18 without the involvement of a parent, guardian, or authorised adult representative.
Where our platform processes data relating to minors (e.g., paediatric insurance beneficiaries), this is done solely on behalf of and under the instructions of the enterprise client (the controller), which is responsible for ensuring appropriate parental or guardian consent has been obtained.
If we become aware that we have inadvertently collected personal data from a child without proper authorisation, we will promptly delete that data and notify the relevant enterprise client.
The Website may contain links to third-party websites, and our platform may integrate with external services (such as healthcare providers, laboratory information systems, or insurance administrator portals). This Policy does not apply to those third-party sites or services.
We encourage you to review the privacy policies of any third-party services you access. SureNett is not responsible for the data practices of third parties.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or operational circumstances. When we make material changes, we will:
Continued use of the Website or our services after the effective date of any update constitutes your acceptance of the revised Policy.
If you have questions, concerns, or requests relating to this Privacy Policy or the processing of your personal data, please contact our Privacy Office:
Privacy Office: CoreNett Limited (SureNett)
Email: enquiries@corenett.com
Postal Address: House #134 University Farm Road, Accra, Ghana
Telephone: +233 554 252 948
Website: www.surenett.com/privacy-policy
If you are not satisfied with our response, you have the right to lodge a complaint with the Data Protection Commission of Ghana:
Authority: Data Protection Commission of Ghana
Website: www.dataprotection.org.gh
Address: PMB CT 108, Cantonments, Accra, Ghana
This Privacy Policy is effective as of 3 June 2026 and supersedes all prior versions.