01Roles & definitions
This agreement uses the standard data-protection roles. You are the controller; you decide why and how personal data is processed. Qoyla is the processor; we act on your documented instructions.
Terms like personal data, processing, data subject and supervisory authority carry the meaning given in the applicable law, including Nigeria's NDPR and, where relevant, the GDPR.
02Scope of processing
We process personal data only to provide the Qoyla service to you and your users, and only for as long as needed.
| Subject matter | Provision of the Qoyla financial advisor and related services. |
|---|---|
| Duration | For the term of the main agreement, plus the deletion window in section 09. |
| Data subjects | Your customers and authorised users. |
| Categories | Identity and contact details, account and transaction data, usage data, and approvals recorded in the Proof Record. |
03Our obligations
- Process personal data only on your documented instructions, including for international transfers.
- Ensure everyone who handles the data is bound by confidentiality.
- Help you respond to data-subject requests and to your own regulatory obligations.
- Make available the information needed to show compliance, and allow audits on reasonable notice.
04Security measures
We maintain technical and organisational measures appropriate to the risk, encryption in transit and at rest, least-privilege access, monitoring, and regular testing. The detail is in our Security overview, which is incorporated here by reference.
05Subprocessors
You give general authorisation for us to use the subprocessors listed on our Subprocessors page. We impose data-protection terms on each of them no less protective than this DPA, and we will give you advance notice of any new subprocessor so you can object on reasonable grounds.
06International transfers
Where personal data is transferred across borders, we rely on an approved transfer mechanism, such as standard contractual clauses, and on data residency where the law requires it. For Nigerian data subjects, see NDPR compliance.
07Data subject rights
We will promptly pass on any request we receive directly from a data subject, and assist you, by appropriate measures, in fulfilling your obligation to respond. Tooling for access, export and deletion is described under Your data rights.
08Breach notification
If we become aware of a personal-data breach affecting your data, we will notify you without undue delay, and within 72 hours where feasible, with the information you need to meet your own reporting duties.
09Return & deletion
On the end of the agreement, you can ask us to return or delete the personal data. Unless the law requires us to keep it, we will delete it, and existing copies, within 90 days, and confirm in writing.
10Review & sign
Ready to put this in place? You can countersign the DPA online, it is routed for signature through our e-signature provider, with a copy sent to both parties.
PDF · 14 pages · standard contractual clauses included