This Data Processing Agreement forms part of the Terms of Service and is accepted at the same time.
3.1Roles
The Subscriber is the data controller of Customer Data. Edhafu Technologies is the data processor and processes Customer Data only on the Subscriber's documented instructions, which are these Terms and the Subscriber's use of the Service.
3.2Scope of processing
| Item | Edhafu Payroll | Edhafu Ledgers |
|---|---|---|
| Data subjects | Employees, directors, casuals | Members, officials, guarantors, next of kin |
| Personal data | Name, ID/passport number, KRA PIN, NSSF and SHA numbers, salary, deductions, bank/M-Pesa details, contact details | Name, ID number, phone, contributions, shares, loans, guarantors, statements |
| Purpose | Payroll computation, payslips, statutory returns | Member records, contributions, loans, statements, reporting |
| Duration | Term of subscription plus the export and deletion window | Same |
3.3Processor obligations
Edhafu Technologies will:
- Process Customer Data only for the purposes above, never for its own marketing or sale.
- Ensure staff and contractors with access are bound by confidentiality.
- Apply the security measures in 3.6.
- Use sub-processors only as listed in the Privacy Policy, under written terms at least as protective as this DPA, and give 30 days' notice of any new sub-processor. The Subscriber may object and terminate if the objection cannot be resolved.
- Help the Subscriber respond to data subject requests (access, correction, deletion, portability) through export and edit features, and by support where needed.
- Notify the Subscriber of a personal data breach affecting Customer Data without undue delay, and within 48 hours of becoming aware, so the Subscriber can meet its 72-hour duty to the ODPC.
- Assist with data protection impact assessments where reasonably required.
- Make available information needed to show compliance, and allow one reasonable audit per year on 30 days' notice, at the Subscriber's cost.
- At the end of the Service, let the Subscriber export Customer Data, then delete it as set out in the Terms, unless the law requires retention.
3.4Subscriber obligations
The Subscriber will:
- Have a lawful basis for all Customer Data uploaded, and give data subjects its own privacy notice.
- Upload only data needed for payroll or member administration.
- Control who its Authorised Users are and remove access promptly when people leave.
- Register with the ODPC where the law requires it.
3.5International transfers
Customer Data may be stored with sub-processors outside Kenya, in the European Union (Edhafu Payroll in Ireland, eu-west-1; Edhafu Ledgers in Frankfurt, eu-central-1). Edhafu Technologies relies on the safeguards permitted under sections 48 to 50 of the Data Protection Act and the providers' contractual and certified security commitments.
3.6Security measures
- Encryption in transit (TLS) and at rest.
- Row-level security so each organisation sees only its own records.
- Role-based permissions inside each organisation.
- Multi-factor authentication for all platform administrators.
- Append-only audit trail of changes to financial records.
- Daily automated backups with tested restore.
- Secrets and API keys (including M-Pesa Daraja credentials) held in server-side environment variables, never in the browser.
- Access to production data limited to named administrators and logged.
3.7Liability
Liability under this DPA is subject to the limitation of liability in the Terms of Service.