Legal document

Data Processing Agreement

Version 1.0

Version: 1.0

Parties:

  • Customer (Controller): The organization registering for Indusflo
  • Processor: [Your legal entity name], United Republic of Tanzania

This DPA forms part of the Terms of Service and applies when Customer processes personal data through Indusflo.

1. Subject matter

Processor provides multitenant industry management software. Customer determines purposes and means of processing personal data entered into the system (e.g. employees, contacts).

2. Duration

From acceptance until deletion of Customer’s tenant data per the offboarding policy (6-month archive unless restored).

3. Nature and purpose of processing

Hosting, storage, backup, display, export, email notifications, and support of Customer’s operational and workforce data.

4. Types of personal data

Identification data, contact data, employment and attendance data, and other data Customer uploads.

5. Categories of data subjects

Customer’s employees, contractors, customers, and suppliers as entered by Customer.

6. Processor obligations

Processor shall:

1. Process only on documented instructions (Terms + Customer configuration)

2. Ensure confidentiality of personnel

3. Implement appropriate technical and organizational measures (encryption, access control, tenant isolation)

4. Assist with data subject requests where feasible

5. Notify Customer without undue delay of personal data breaches

6. Delete or return data after termination (subject to retention law and 6-month archive)

7. Make available information necessary to demonstrate compliance

8. Use subprocessors only with safeguards; list available on request

7. Customer obligations

Customer shall:

  • Have lawful basis to upload data
  • Configure roles and access appropriately
  • Not upload unlawful or excessive data
  • Notify Processor of instructions conflicting with law

8. Subprocessors

Authorized subprocessors may include: cloud hosting, email delivery, payment (Lipa), error monitoring. Processor remains liable for subprocessors’ performance.

9. Security measures (summary)

  • Dedicated database per tenant
  • HTTPS, hashed passwords, audit logs
  • Role-based access; support impersonation logged where enabled
  • Daily backups

10. International transfers

Where processing occurs outside Tanzania, Processor ensures appropriate safeguards consistent with applicable law.

11. Audit

Customer may request a summary security questionnaire annually. On-site audits for Enterprise plans by mutual schedule.

12. Liability

Limited as in the Terms of Service. Nothing limits liability where it cannot be limited by law.

13. Governing law

Laws of the United Republic of Tanzania.

14. Acceptance

Acceptance via checkbox at registration constitutes agreement to this DPA version 1.0.