Legal
Data Processing Agreement
Last updated: June 2025
1. Scope
This Data Processing Agreement ("DPA") forms part of the service agreement between ZumaGrid Trust Infrastructure ("Processor") and the subscribing organisation ("Controller"). It governs the processing of personal data by ZumaGrid on behalf of the Controller in connection with the Platform services.
2. Definitions
- "Personal Data" — Any information relating to an identified or identifiable natural person processed through the Platform
- "Processing" — Any operation performed on personal data (collection, storage, retrieval, transmission, erasure)
- "Sub-processor" — A third party engaged by ZumaGrid to process personal data
- "Data Subject" — The individual whose personal data is processed
3. Processing Instructions
ZumaGrid processes personal data only on documented instructions from the Controller, unless required to do so by Nigerian law. The categories of data processed, purposes, and duration are defined in the service agreement schedule.
4. Security Measures
ZumaGrid implements appropriate technical and organisational measures including:
- AES-256 encryption at rest
- TLS 1.3 encryption in transit
- Role-based access control with principle of least privilege
- Regular vulnerability assessments
- Employee confidentiality obligations and security training
- Incident response procedures
- Data backup and disaster recovery
5. Sub-processors
ZumaGrid may engage sub-processors to deliver the Platform services. The Controller will be notified of any new sub-processor at least 14 days before engagement. Current sub-processors include:
- Cloud hosting infrastructure provider
- Payment processing (Paystack)
- Email delivery (SendGrid)
- SMS delivery (Africa's Talking)
6. Data Subject Rights
ZumaGrid will assist the Controller in responding to data subject requests (access, rectification, erasure, portability) within the timeframes required by NDPR/NDPA and GDPR. Requests received directly by ZumaGrid will be forwarded to the Controller without undue delay.
7. Breach Notification
ZumaGrid will notify the Controller of any personal data breach without undue delay and in any event within 48 hours of becoming aware of the breach. Notification will include:
- Nature of the breach and categories of data affected
- Approximate number of data subjects affected
- Measures taken or proposed to address the breach
- Contact point for further information
8. International Transfers
Where personal data is transferred outside Nigeria, ZumaGrid ensures compliance with NDPR requirements through Standard Contractual Clauses or equivalent mechanisms approved by the Nigeria Data Protection Commission.
9. Audit Rights
The Controller may audit ZumaGrid's compliance with this DPA upon 30 days written notice, no more than once per calendar year. ZumaGrid will provide reasonable cooperation and access to relevant documentation. Audits shall be conducted during normal business hours and must not disrupt Platform operations.
10. Term & Deletion
This DPA remains in effect for the duration of the service agreement. Upon termination, ZumaGrid will delete or return all personal data within 90 days, unless retention is required by law. The Controller may request a certificate of deletion.
To execute this DPA or request a signed copy, contact hello@zumagrid.app. See also our Privacy Policy.
