๐Ÿ‡ฌ๐Ÿ‡ญ Statutory Data Governance StandardGhana Act 843 Compliant๐Ÿ”’ TLS 1.3 / AES-256

Institutional Privacy & Data Protection Policy

Knights of St. John International โ€ข St. Margaret-Mary Commandery No. 500, Dansoman. Governing the sacred collection, storage, operational insulation, and protection of member records in accordance with the Ghana Data Protection Act, 2012 (Act 843).

โ† Back to Login
๐Ÿ›๏ธ Act 843 ยง18

1. Data Controller & Processing Scope

Institutional boundaries and exclusive fraternal purpose of all collected member data.

Data Controller: St. Margaret-Mary Commandery No. 500, Knights of St. John International, P.O. Box DS 1234, Dansoman, Accra, Ghana.

Scope of Member Records Processed:

  • Personal Identification: Fraternal titles, full legal names, photos, dates of birth, mobile telephone numbers, and email addresses.
  • Sacramental & Knighthood Progression: Initiation cohort dates, Uniform Exemplification, 4th Degree Chapter honors (Chevalier), and 5th Degree Temple elevations (Noble).
  • Governance & Leadership Records: Elective, appointive, and committee tenures across Commandery, Chapter, Temple, and Board of Trustees.
  • Welfare & Family Protection: Spouses, children, and designated next-of-kin for fraternal welfare scheme benefits and bereavement assistance.
  • Treasury & Financial Ledgers: Annual membership dues assessments, payment transaction receipts, and welfare contribution logs.
๐Ÿšซ Absolute Commercial Prohibition: Under no circumstances is member data, telephone directories, or financial records sold, leased, rented, shared, or monetized with any commercial, political, or marketing third party. All processing is solely for authentic fraternal administration.
โš–๏ธ Lawful Ground

2. Lawful Basis & Member Consent

Legitimate Fraternal Interest under Ghana law and constitutional fraternal obligations.

Under Section 18 of the Ghana Data Protection Act, 2012 (Act 843), data processing is grounded in Legitimate Fraternal Interest necessary for administering membership, voting rights, and constitutional duties under the Supreme Constitution of the Knights of St. John International.

๐Ÿ“ฃ Permitted Automated Communications:

Brothers consent to official fraternal SMS and email broadcasts exclusively for: official meeting notices, annual dues assessments, welfare benefit updates, emergency fraternity appeals, and bereavement announcements. Carrier-grade rate-limiting (3 SMS/min) is enforced to ensure spam-free, compliant message delivery.

๐Ÿ•ฏ๏ธ Fraternal Tradition

3. Archival Retention Policy ("The Right to Fraternal History")

Permanent preservation of deceased members paired with strict operational billing insulation.

The Commandery balances statutory privacy principles with sacred fraternal tradition:

๐Ÿ•Š๏ธ Permanent Honor Roll & Historical Archival
Deceased members are never deleted from the database. Their names, initiation cohorts, exemplifications, offices held, and biographical narratives are permanently preserved in the Master Roll and Historical Archive to honor their lifelong service to God and Church.
๐Ÿ›ก๏ธ Strict Operational & Billing Insulation
Deceased, dismissed, and transferred members are strictly excluded from annual dues billing, delinquency collection trackers, automated SMS broadcasts, active welfare subscriber metrics, and active Board of Trustees rosters.
๐Ÿ”’ TLS 1.3 / AES-256

4. Technical Infrastructure & Data Security

Enterprise cloud hosting, cryptographic encryption, and Row-Level Security.
๐ŸŒ
Encryption in Transit
Enforced via modern TLS 1.3 cryptographic protocols with HSTS preloading.
๐Ÿ”
Encryption at Rest
All relational database volumes and storage snapshots encrypted with AES-256.
๐Ÿ›ก๏ธ
Row-Level Security (RLS)
PostgreSQL policies restrict brothers to strictly viewing their own record.
๐Ÿชช
Sanitized Public QR Verification
Public verify links only show rank and good-standing seal; financials and contacts are hidden.

Our underlying database infrastructure is hosted on enterprise cloud data centers holding certified ISO/IEC 27001, SOC 2 Type II, and PCI DSS compliance.

๐Ÿ’พ Automated Cron

5. Automated Disaster Recovery & Backups

Weekly scheduled cryptographic snapshots across all 27 relational database tables.

Data resiliency and long-term continuity are governed by an automated serverless cron engine:

  • Automated Heartbeat: Triggers every Sunday at 00:00 UTC via secure cron to capture a full relational database dump.
  • Cryptographic Checksum: Every snapshot archive is verified with an immutable SHA-256 hash to prevent silent corruption or tampering.
  • Gzip Compression & Encrypted Vault: Snapshots are encrypted and deposited in private storage vaults with time-limited signed URLs, accompanied by an encrypted email digest to the Commandery Registrar disaster recovery inbox.
๐Ÿ‘ค Member Rights

6. Member Rights & Data Subject Access

Transparency, self-service profile rectification, and portable good-standing records.

In compliance with Act 843 Section 26, every initiated brother in good standing retains the right to:

๐Ÿ‘๏ธ
Right to Access:
Directly inspect your personal profile, initiation cohort roster, dues ledger, and exemplification records 24/7 via the /me self-service portal.
โœ๏ธ
Right to Rectification:
Submit immediate corrections to telephone numbers, residential addresses, occupation, and next-of-kin through the self-service record update form.
๐Ÿ“„
Right to Portable Proof of Good Standing:
Generate and download tamper-evident digital ID cards, official good-standing certificates, and payment receipts with verifiable QR codes.
๐Ÿ›ก๏ธ
Commandery Data Protection & Privacy Oversight
Questions regarding data protection, record rectification, or privacy rights should be directed to the Commandery Registrar Desk or Worthy President.
Official Registry Address: St. Margaret-Mary Catholic Church, Dansoman, Accra, Ghana.
Legal Status
โœ… Fully Certified & In Force
Effective: February 2026 โ€ข Commandery #500