Edhafu Legal

Data Processing Agreement

Version
1.0
Effective
Applies to
Edhafu Payroll and Edhafu Ledgers

You are reading the archived text of version 1.0. See the current version.

This Data Processing Agreement forms part of the Terms of Service and is accepted at the same time.

3.1Roles

The Subscriber is the data controller of Customer Data. Edhafu Technologies is the data processor and processes Customer Data only on the Subscriber's documented instructions, which are these Terms and the Subscriber's use of the Service.

3.2Scope of processing

Item Edhafu Payroll Edhafu Ledgers
Data subjects Employees, directors, casuals Members, officials, guarantors, next of kin
Personal data Name, ID/passport number, KRA PIN, NSSF and SHA numbers, salary, deductions, bank/M-Pesa details, contact details Name, ID number, phone, contributions, shares, loans, guarantors, statements
Purpose Payroll computation, payslips, statutory returns Member records, contributions, loans, statements, reporting
Duration Term of subscription plus the export and deletion window Same

3.3Processor obligations

Edhafu Technologies will:

  1. Process Customer Data only for the purposes above, never for its own marketing or sale.
  2. Ensure staff and contractors with access are bound by confidentiality.
  3. Apply the security measures in 3.6.
  4. Use sub-processors only as listed in the Privacy Policy, under written terms at least as protective as this DPA, and give 30 days' notice of any new sub-processor. The Subscriber may object and terminate if the objection cannot be resolved.
  5. Help the Subscriber respond to data subject requests (access, correction, deletion, portability) through export and edit features, and by support where needed.
  6. Notify the Subscriber of a personal data breach affecting Customer Data without undue delay, and within 48 hours of becoming aware, so the Subscriber can meet its 72-hour duty to the ODPC.
  7. Assist with data protection impact assessments where reasonably required.
  8. Make available information needed to show compliance, and allow one reasonable audit per year on 30 days' notice, at the Subscriber's cost.
  9. At the end of the Service, let the Subscriber export Customer Data, then delete it as set out in the Terms, unless the law requires retention.

3.4Subscriber obligations

The Subscriber will:

  1. Have a lawful basis for all Customer Data uploaded, and give data subjects its own privacy notice.
  2. Upload only data needed for payroll or member administration.
  3. Control who its Authorised Users are and remove access promptly when people leave.
  4. Register with the ODPC where the law requires it.

3.5International transfers

Customer Data may be stored with sub-processors outside Kenya, in the European Union (Edhafu Payroll in Ireland, eu-west-1; Edhafu Ledgers in Frankfurt, eu-central-1). Edhafu Technologies relies on the safeguards permitted under sections 48 to 50 of the Data Protection Act and the providers' contractual and certified security commitments.

3.6Security measures

  • Encryption in transit (TLS) and at rest.
  • Row-level security so each organisation sees only its own records.
  • Role-based permissions inside each organisation.
  • Multi-factor authentication for all platform administrators.
  • Append-only audit trail of changes to financial records.
  • Daily automated backups with tested restore.
  • Secrets and API keys (including M-Pesa Daraja credentials) held in server-side environment variables, never in the browser.
  • Access to production data limited to named administrators and logged.

3.7Liability

Liability under this DPA is subject to the limitation of liability in the Terms of Service.