Legal document
Data Processing Agreement
Version 1.0
Version: 1.0
Parties:
- Customer (Controller): The organization registering for Indusflo
- Processor: [Your legal entity name], United Republic of Tanzania
This DPA forms part of the Terms of Service and applies when Customer processes personal data through Indusflo.
1. Subject matter
Processor provides multitenant industry management software. Customer determines purposes and means of processing personal data entered into the system (e.g. employees, contacts).
2. Duration
From acceptance until deletion of Customer’s tenant data per the offboarding policy (6-month archive unless restored).
3. Nature and purpose of processing
Hosting, storage, backup, display, export, email notifications, and support of Customer’s operational and workforce data.
4. Types of personal data
Identification data, contact data, employment and attendance data, and other data Customer uploads.
5. Categories of data subjects
Customer’s employees, contractors, customers, and suppliers as entered by Customer.
6. Processor obligations
Processor shall:
1. Process only on documented instructions (Terms + Customer configuration)
2. Ensure confidentiality of personnel
3. Implement appropriate technical and organizational measures (encryption, access control, tenant isolation)
4. Assist with data subject requests where feasible
5. Notify Customer without undue delay of personal data breaches
6. Delete or return data after termination (subject to retention law and 6-month archive)
7. Make available information necessary to demonstrate compliance
8. Use subprocessors only with safeguards; list available on request
7. Customer obligations
Customer shall:
- Have lawful basis to upload data
- Configure roles and access appropriately
- Not upload unlawful or excessive data
- Notify Processor of instructions conflicting with law
8. Subprocessors
Authorized subprocessors may include: cloud hosting, email delivery, payment (Lipa), error monitoring. Processor remains liable for subprocessors’ performance.
9. Security measures (summary)
- Dedicated database per tenant
- HTTPS, hashed passwords, audit logs
- Role-based access; support impersonation logged where enabled
- Daily backups
10. International transfers
Where processing occurs outside Tanzania, Processor ensures appropriate safeguards consistent with applicable law.
11. Audit
Customer may request a summary security questionnaire annually. On-site audits for Enterprise plans by mutual schedule.
12. Liability
Limited as in the Terms of Service. Nothing limits liability where it cannot be limited by law.
13. Governing law
Laws of the United Republic of Tanzania.
14. Acceptance
Acceptance via checkbox at registration constitutes agreement to this DPA version 1.0.