LEGAL
Data Processing Agreement
Nathan Digital Data Processing Agreement
1.Introduction
It is noted by the Parties that Personal Data may be required for Nathan Digital to perform the Services and in the event that Personal Data will be Processed by Nathan Digital for the purposes hereof, this Data Processing Agreement ("DPA") will apply.
This DPA reflects the Parties' agreement with respect to the Processing of Personal Data by Nathan Digital on behalf of the Subscriber in connection with the Services.
This DPA is supplemental to and forms an integral part of the SAAS Service Specific Terms. In case of any conflict or inconsistency with the terms of the SAAS Service Specific Terms, this DPA will take precedence over the terms of the SAAS Service Specific Terms to the extent of such conflict or inconsistency.
The term of this DPA will follow the term of the Order Form. Terms not otherwise defined in this DPA will have the meaning as set forth in the SAAS Service Specific Terms and Order Form.
2.Definitions and Interpretation
The following definitions and rules of interpretation shall apply:
- Authorised Users: the persons or categories of persons that the Subscriber authorises to give Nathan Digital Personal Data Processing instructions.
- Consent: means consent as defined under the Applicable Data Protection Laws from time to time.
- Data Subject: means data subject as defined under the Applicable Data Protection Laws from time to time.
- External Parties: means those parties as stated under Appendix A.
- Applicable Data Protection Laws: all applicable privacy and data protection laws applicable to the processing of Personal Data under the DPA, including any laws implementing or supplementing such legislation, as amended or replaced from time to time.
- Processor: means Processor as defined under the Applicable Data Protection Laws from time to time.
- Personal Data: means Personal Data as defined under the Applicable Data Protection Laws from time to time.
- Security Incident: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.
- Processing, processes and process: as defined under the Applicable Data Protection Laws.
- Controller: as defined in the Applicable Data Protection Laws.
- Services: the Subscription Services as set out under the SAAS Service Specific Terms.
- Subscriber: the Customer receiving the Subscription Services in terms of the SAAS Service Specific Terms.
The Appendices form part of this DPA and will have effect as if set out in full in the body of this DPA. Any reference to this DPA includes the Appendices.
A reference to writing or written includes electronic communications such as email and Nathan Digital electronic communication facility via its Services.
3.Personal Data Types and Processing Purposes
For the purposes of the Applicable Data Protection Laws, the Subscriber acts as the Controller and Nathan Digital acts as the Processor in relation to Customer Personal Data processed in connection with the Services. Processor may act as an independent Controller in relation to Personal Data relating to its own relationship management, billing and administration activities.
Appendix A describes the subject matter, duration, nature and purpose of processing and the Personal Data categories, Data Subject types in respect of which Processor may process to fulfil the Services of the SAAS Service Specific Terms and External Parties that may receive Personal Data on instructions from the Subscriber.
All instructions issued must be documented by both the Controller and the Processor. Instructions from the Controller that go beyond the performance agreed in the Order Form shall be treated as a request for a change in performance, which instructions shall be dealt with under the change control provisions of the SAAS Service Specific Terms between the Parties.
4.Subscriber Responsibilities
Within the scope of the SAAS Service Specific Terms and in its use of the Services, the Subscriber will be responsible for complying with all requirements that apply to it under Applicable Data Protection Laws with respect to its Processing of Personal Data and the Instructions it issues to Processor.
In particular but without prejudice to the generality of the foregoing, the Subscriber acknowledges and agrees that the Subscriber will be solely responsible for:
- the accuracy, quality, and legality of the Personal Data and the means by which the Subscriber acquired Personal Data;
- complying with all necessary transparency (openness) and lawfulness requirements under Applicable Data Protection Laws for the Processing of the Personal Data, including obtaining any necessary Consents and authorisations;
- ensuring the Subscriber has the right to grant Processor the right to Process Personal Data in accordance with the terms of the SAAS Service Specific Terms (including this DPA), including transfer of Personal Data to agreed External Parties;
- ensuring that the Subscriber's instructions to the Processor regarding the Processing of Personal Data comply with applicable laws, including Applicable Data Protection Laws;
- the appointment and authorisation of the Authorised Users to use the Services and Process Personal Data, and
- the actions and/or omissions of its Authorised Users.
The Subscriber will inform the Processor without undue delay if it is not able to comply with its responsibilities under this clause.
The Processor shall not be liable for the Subscriber's non-compliance under this clause.
5.The Processor's Obligations
The Processor will only process Personal Data to the extent, and in such a manner, as is necessary for the Services in accordance with the Subscriber's Authorised Users' written instructions or such automated instructions as may be received from the Subscriber. The Processor will not process Personal Data for any other purpose or in a way that does not comply with the SAAS Service Specific Terms or the Applicable Data Protection Laws. The Processor will (but not obliged to) notify the Subscriber if, in its opinion, the Subscriber's instruction would not comply with the Applicable Data Protection Laws.
The Processor shall comply with any reasonable Subscriber request or instruction requiring the Processor to amend, transfer, delete or otherwise process the Personal Data of the Authorised Users, or to stop, mitigate or remedy any unauthorised processing.
The Processor will maintain the confidentiality of all Personal Data and will not disclose Personal Data to third parties unless:
- the Subscriber or the SAAS Service Specific Terms or this DPA specifically authorises the disclosure thereof, or
- as required by law. If a law, court, regulator, or supervisory authority requires the Processor to process or disclose Personal Data, the Processor must first inform the Subscriber of the legal or regulatory requirement and give the Subscriber an opportunity to object or challenge the requirement, unless the law prohibits such notice.
The Processor will reasonably assist the Subscriber with meeting the Subscriber's compliance obligations under the Applicable Data Protection Laws, taking into account the nature of the Processor's processing and the information available to the Processor, including in relation to Data Subject rights, Data protection impact assessments and reporting to and consulting with supervisory authorities under the Applicable Data Protection Laws.
The Processor will notify the Subscriber of any changes to Applicable Data Protection Laws that may adversely affect the Processor's performance of this DPA or any agreement.
The Subscriber is responsible for providing any notices and obtaining any consents or other lawful bases required under Applicable Data Protection Laws.
6.The Processor Employees
The Processor will ensure that all employees:
- are informed of the confidential nature of the Personal Data and are bound by confidentiality obligations and use restrictions in respect of the Personal Data;
- have undertaken training on the Applicable Data Protection Laws relating to handling Personal Data and how it applies to their particular duties; and
- are aware of both of the Processor's duties and their personal duties and obligations under the Applicable Data Protection Laws and the SAAS Service Specific Terms.
7.Security
The Parties agree to implement appropriate technical and organisational measures against unauthorised or unlawful processing, access, disclosure, copying, modification, storage, reproduction, display, or distribution of Personal Data, and against accidental or unlawful loss, destruction, alteration, disclosure, or damage of Personal Data.
The Processor will implement such measures to ensure a level of security appropriate to the risk involved, including as appropriate:
- the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
- the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident; and
- a process for regularly testing, assessing, and evaluating the effectiveness of security measures.
The Processor shall implement security measures to ensure the confidentiality and integrity of Subscriber Data. All persisted data, whether at rest or during transmission, shall be encrypted using industry-standard encryption algorithms and practices.
Where any security changes or enhancements or additional security features are requested by the Subscriber that are not standard security deliverables acceptable to other similar subscribers as the Subscriber, costs associated with said changes or enhancements, where the Processor has agreed to it in writing, shall be for the account of the Subscriber.
The Processor shall maintain appropriate technical and organisational measures designed to ensure a level of security appropriate to the risks presented by the Processing.
8.Security Incident
The Processor will, without undue delay, notify the Subscriber if any Personal Data is lost or destroyed or becomes damaged, corrupted, or unusable.
The Processor will, without undue delay and where reasonably possible, within 24 (twenty-four) hours, notify the Subscriber if it becomes aware of:
- any accidental, unauthorised, or unlawful processing of the Personal Data; or
- any Security Incident.
Where the Processor becomes aware of either of the above events, it shall, without undue delay, also provide the Subscriber with the following information:
- description of the nature of the event, including the categories and approximate number of both Data Subjects and Personal Data records concerned, and the likely known consequences; and
- description of the measures taken or proposed to be taken to address the event, including measures to mitigate its possible adverse effects.
Immediately following any unauthorised or unlawful Personal Data processing or Security Incident, the Parties will coordinate with each other to investigate the matter. The Processor will reasonably cooperate with the Subscriber in the Subscriber's handling of the matter, including:
- assisting with any investigation;
- providing the Subscriber with reasonable access to any facilities and operations affected;
- facilitating interviews with the Processor's employees, former employees and others involved in the matter;
- making available all relevant records, logs, files, data reporting and other materials required to comply with all Applicable Data Protection Laws or as otherwise reasonably required by the Subscriber (subject to confidentiality); and
- taking reasonable and prompt steps to mitigate the effects and to minimise any damage resulting from the Security Incident or unlawful Personal Data processing.
The Processor will not inform any third-party of any Security Incident without first obtaining the Subscriber's prior written consent, except when required to do so by law.
The Processor agrees that the Subscriber has the sole right to determine:
- whether to provide notice of the Security Incident to any Data Subjects, supervisory authorities, regulators, law enforcement agencies or others, as required by law or regulation or in the Subscriber's discretion, including the contents and delivery method of the notice; and
- whether to offer any type of remedy to affected Data Subjects, including the nature and extent of such remedy.
The Processor will cover all reasonable direct expenses associated with the performance of the notification, information and cooperation obligations above, pertaining to the role of a Processor, unless the matter arose from the Subscriber's specific instructions, negligence, wilful default or breach of the SAAS Service Specific Terms or any contract or any third-party actions outside the reasonable control of the Processor, in which case the Subscriber will cover all reasonable expenses.
9.Cross-Border Transfers of Personal Data
Where Personal Data is transferred internationally, the Parties shall implement appropriate safeguards and transfer mechanisms required by the Applicable Data Protection Laws, including adequacy decisions, standard contractual clauses, approved codes of conduct, certification mechanisms or other recognised transfer mechanisms.
10.Subprocessors
The Processor may only authorise a third-party (subprocessor) to process the Personal Data if:
- the Processor enters into a written contract with the subprocessor that contains terms substantially the same as those set out in this DPA, in particular, in relation to requiring appropriate technical and organisational data security measures, and, upon the Subscriber's written request, provides the Subscriber with copies of such contracts;
- the Processor maintains control over all Personal Data it entrusts to the subprocessor; and
- the subprocessor's contract terminates all Personal Data related to the Subscriber on termination of the SAAS Service Specific Terms for any reason.
The Processor agrees to select subprocessors carefully according to their suitability and reliability and update the subprocessors list (as per Appendix A) on the appointment of a subprocessor.
Where the subprocessor fails to fulfil its obligations under such written agreement, the Processor remains fully liable to the Subscriber for the subprocessor's performance of its agreement obligations.
The Processor undertakes to ensure that all subprocessors who process Personal Data of Data Subjects shall not amend, modify, merge, or combine such Personal Data and Process the same as per instructions from the Processor.
Where the Subscriber requires the use of any particular subprocessor (recommended subprocessor), the following will apply:
- the requirements set out above for authorising a subprocessor will apply accordingly;
- the recommended subprocessor will have to comply with all the Processor technological and organisational measurements as made available from time to time by the Processor, before transfer of any Personal Data to said subprocessor;
- where the subprocessor fails to fulfil its obligations under such written agreement, the Processor will notify the Subscriber, however, will not be liable to the Subscriber for the subprocessor's performance of its agreement obligations.
11.Complaints, Data Subject Requests and Third-Party Rights
The Processor shall take such technical and organisational measures as may be appropriate, and promptly provide such information to the Subscriber as the Subscriber may reasonably require, to enable the Subscriber to comply with:
- the rights of Data Subjects under the Applicable Data Protection Laws, including subject access rights, the rights to rectify and erase Personal Data, object to the processing and automated processing of Personal Data, to transfer Personal Data, and restrict the processing of Personal Data; and
- information or assessment notices served on the Subscriber by any supervisory authority under the Applicable Data Protection Laws.
The Processor will notify the Subscriber immediately if it receives any complaint, notice or communication that relates directly or indirectly to the processing of the Personal Data or to either Party's compliance with the Applicable Data Protection Laws. The Processor will notify the Subscriber within 2 (two) Business Days if it receives a request from a Data Subject for access to their Personal Data or to exercise any of their related rights under the Applicable Data Protection Laws.
The Processor will give the Subscriber its full cooperation and assistance in responding to any complaint, notice, communication or Data Subject request and the Subscriber shall remunerate the Processor for any reasonable costs that the Processor may incur as a result of said request. The Processor shall not be liable for the Subscriber's non-compliance of any Data Subject requests.
The Processor must not disclose the Personal Data to any Data Subject or to a third-party other than at the Subscriber's request or instruction, as provided for in the SAAS Service Specific Terms or as required by law.
The Subscriber will cover all reasonable direct expenses associated with the performance of the obligations under this clause.
12.Term (For Purposes of This DPA)
The provision of the DPA will remain in full force and effect as long as:
- the SAAS Service Specific Terms remain in effect, or
- the Processor retains any Personal Data related to the SAAS Service Specific Terms in its possession or control as agreed to under the SAAS Service Specific Terms (Term).
Any provision of this DPA that expressly or by implication should come into or continue in force on or after termination of the SAAS Service Specific Terms in order to protect Personal Data will remain in full force and effect.
If a change in any Applicable Data Protection Laws prevents either Party from fulfilling all or part of its SAAS Service Specific Terms obligations, the Parties will suspend the processing of Personal Data until that processing complies with the new requirements. If the Parties are unable to bring the Personal Data processing into compliance with the Applicable Data Protection Laws within 30 (thirty) days, they may terminate the SAAS Service Specific Terms on written notice to the other Party.
13.Data Return and Destruction
At the Subscriber's request and subject to the Processor's then request for Personal Data procedures, the Processor will give the Subscriber a copy of or access to all or part of the Subscriber's Data in its possession or control in the format and on the media reasonably specified by the Subscriber.
On termination of the SAAS Service Specific Terms for any reason or expiry of its term, the Processor will securely delete or destroy or, if directed in writing by the Subscriber, return and not retain, all or any Subscriber Data related to the SAAS Service Specific Terms in its possession or control, except for
- one copy that it may retain and use for 1 (one) year for audit and operational purposes only or
- where any applicable law requires the Processor to retain the Subscriber Data (as part of a record or not) for a longer period or
- information that have been de-identified, or
- to Subscriber Data the Processor has archived on back-up systems, which data the Processor will securely isolate and protect from any further Processing and delete in accordance with its deletion practices.
If any law, regulation, or government or regulatory body requires the Processor to retain any documents or materials that the Processor would otherwise be required to return or destroy, it will notify the Subscriber in writing of that retention requirement, giving details of the documents or materials that it must retain, the legal basis for retention, and establishing a specific timeline for destruction once the retention requirement ends.
14.Records
The Processor shall maintain records and information reasonably necessary to demonstrate its compliance with this DPA and Applicable Data Protection Laws, taking into account the nature of the Processing and the information available to the Processor.
Such records may include information relating to:
- the categories of Processing activities carried out on behalf of the Controller;
- the categories of Personal Data and Data Subjects involved;
- transfers of Personal Data and applicable safeguards;
- the technical and organisational measures implemented to protect Personal Data; and
- the Processor's use of approved subprocessors.
The Processor shall retain such records for so long as required by Applicable Data Protection Laws or its internal record retention policies, whichever period is longer.
15.Audit and Information Rights
The Processor shall make available to the Controller such information as is reasonably necessary to demonstrate compliance with this DPA and Applicable Data Protection Laws.
The Processor may satisfy this obligation by providing, where available:
- independent third-party audit reports;
- certifications and attestations relating to information security or privacy compliance;
- responses to reasonable security or privacy questionnaires; and
- summaries of its technical and organisational measures.
Where the information provided above is insufficient for the Controller to satisfy a specific legal or regulatory obligation, the Controller may, upon giving not less than thirty (30) days' prior written notice, conduct or appoint an independent third-party auditor to conduct an audit of the Processor's compliance with this DPA, provided that:
- such audit is limited to matters directly relevant to the Processing of Personal Data under this DPA;
- the audit is conducted during normal business hours and in a manner designed to minimise disruption to the Processor's business operations;
- the auditor is subject to appropriate confidentiality obligations;
- the Controller shall not exercise its audit rights more than once in any twelve (12) month period, unless required by Applicable Data Protection Laws or following a Security Incident materially affecting Personal Data;
- the audit shall not provide access to information relating to other customers, trade secrets or confidential information unrelated to the Services; and
- the Processor may satisfy reasonable requests through remote inspection, documentation review or interviews in lieu of granting physical access where appropriate.
Each Party shall bear its own costs in connection with any audit, save that the Controller shall reimburse the Processor for its reasonable costs incurred in supporting an audit requested by the Controller, unless the audit reveals a material breach of this DPA by the Processor.
Nothing in this clause shall require the Processor to disclose information where such disclosure would:
- violate Applicable Laws;
- compromise the security or confidentiality of other customers or third parties; or
- reveal the Processor's trade secrets or proprietary information, provided that the Processor shall use reasonable efforts to provide alternative information sufficient to demonstrate compliance.
16.Warranties
The Processor warrants and represents that:
- its employees, subprocessors, agents and any other person or persons accessing Personal Data on its behalf are reliable and trustworthy and have received the required training on the Applicable Data Protection Laws relating to the Personal Data;
- each Party shall comply with the Applicable Data Protection Laws applicable to it in connection with the Processing of Personal Data under this DPA; and
- it has no reason to believe that the Applicable Data Protection Laws prevents it from providing any of the Services.
The Subscriber warrants and represents that:
- the Processor's expected use of the Personal Data for the Services and as specifically instructed by the Subscriber will comply with the Applicable Data Protection Laws;
- where the Processor has not collected the Data Subjects' Personal Data on behalf of the Subscriber, all Data Subject Personal Data made available by the Subscriber to the Processor has been obtained in accordance with the Applicable Data Protection Laws.
17.Limitation of Liability
Each Party's liability, taken in aggregate, arising out of, or related to this DPA, whether in contract, delict or under any other theory of liability, will be subject to the limitations and exclusions of liability set out in the 'Limitation of Liability' section of the SAAS Service Specific Terms and any reference in such section to the liability of a Party means aggregate liability of that Party under the SAAS Service Specific Terms (including this DPA).
18.Variation
No variation of this DPA shall be effective unless it is in writing and signed by an authorised representative of the Parties.
19.Appendix A: Personal Data Processing Purposes and Details
19.aSubject Matter
Processing necessary for the provision of the Services.
19.bDuration
For the term of the DPA and thereafter only for as long as required to comply with legal obligations and retention requirements.
19.cNature of Processing
Collection, storage, organisation, retrieval, consultation, use, transmission, combination, restriction, deletion and destruction.
19.dPurpose
Provision, support and improvement of the Services and fulfilment of obligations under the DPA.
19.eCategories of Data Subjects
- Customer personnel;
- authorised users;
- customers and end users;
- suppliers and business contacts;
- employees and contractors.
19.fCategories of Personal Data
- identification data;
- contact information;
- account credentials;
- transactional data;
- device and usage information;
- communications data;
- support records.
19.gSpecial Categories of Personal Data
Not intentionally processed unless expressly agreed.
20.Approved Subprocessors
The Processor does not, as at the Effective Date of this Data Processing Addendum, engage any sub-processors to process Personal Data on behalf of the Controller in connection with the Services.
The Processor reserves the right to appoint sub-processors in the future where reasonably required for the provision, maintenance, support, security, hosting, or enhancement of the Services. Should the Processor appoint any sub-processor, the Processor shall:
- provide the Controller with prior written notice of the proposed appointment, including details of the processing activities to be performed by the sub-processor;
- ensure that a written agreement is entered into with the sub-processor imposing data protection obligations that are no less protective than those set out in this Addendum and as required by applicable Data Protection Laws;
- remain fully responsible for the acts, omissions, and compliance of the sub-processor in relation to the processing of Personal Data; and
- where required by applicable Data Protection Laws, provide the Controller with a reasonable opportunity to object to the appointment of a sub-processor on legitimate data protection grounds.
The Processor shall maintain and make available to the Controller, upon reasonable request, an up-to-date list of authorised sub-processors engaged in connection with the Services.
Where the appointment of a sub-processor involves an international transfer of Personal Data, the Processor shall ensure that appropriate safeguards are implemented in accordance with applicable Data Protection Laws, including, where applicable, the execution of approved transfer mechanisms.
For the avoidance of doubt, the Controller acknowledges and agrees that the Processor may update this Addendum and its sub-processor list from time to time in accordance with this clause.
21.International Transfer Mechanisms
The Parties acknowledge that the provision of the Services may require the transfer of Personal Data across national borders.
Neither Party shall transfer Personal Data to a country or jurisdiction that does not provide an adequate level of protection unless such transfer is permitted under Applicable Data Protection Laws and is subject to appropriate safeguards.
Where required by Applicable Data Protection Laws, the Parties shall implement an approved transfer mechanism, including but not limited to:
- the European Commission Standard Contractual Clauses ("SCCs");
- Binding Corporate Rules;
- approved certification mechanisms or codes of conduct; or
- any other lawful transfer mechanism recognised under the GDPR, POPIA, the Kenya Data Protection Act, 2019, or other Applicable Data Protection Laws.
Where SCCs are required, the applicable SCC module(s) shall be deemed incorporated into and form part of this Agreement by reference and shall prevail in relation to the relevant transfer to the extent of any inconsistency with this Agreement.
Each Party shall implement appropriate technical and organisational measures and, where required by law, conduct any transfer impact assessments or similar evaluations necessary to support such transfers.
If any transfer mechanism relied upon under this Agreement is amended, repealed, invalidated, or otherwise ceases to provide a lawful basis for international transfers, the Parties shall cooperate in good faith to implement an alternative lawful transfer mechanism. Such replacement mechanism shall automatically supplement and form part of this Agreement upon execution and shall provide a level of protection that is not materially less protective than the mechanism it replaces.
22.Technical and Organisational Measures
The Processor shall implement and maintain appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data, taking into account the nature, scope, context, and purposes of the Processing, as well as the risks to the rights and freedoms of Data Subjects.
The Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:
- The pseudonymisation and encryption of personal data;
- The ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
- The ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;
- A process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.
The Processor shall provide physical security to prevent unauthorized access to areas where personal information is stored. The Processor shall furthermore ensure that necessary access controls to all personal data and relevant IT-systems are established. Access must be based on the employees' need for access, taking into account the relevant work tasks.
Electronically stored information that contains personal information shall be protected with passwords and other similar technical security measures to ensure that electronically stored information is neither available to unauthorized personnel nor that there is any risk of undesirable alteration to deletion of data. The security must meet generally recognized methods, or better.
The Processor may update or modify its technical and organisational measures from time to time, provided that such changes do not materially diminish the overall level of security afforded to Personal Data under this Agreement.
Upon reasonable written request, the Processor shall make available information reasonably necessary to demonstrate compliance with this Clause, subject to confidentiality obligations and the protection of the Processor's security-sensitive information.