This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the customer (the “Controller”) and Kletraq (“Kletraq”, the “Processor”) and governs Kletraq’s processing of personal data contained in Customer Data. It reflects the obligations of a data processor under the NDPA 2023 and Article 28 of the GDPR/UK GDPR. A signed, counter-executed DPA is available on request at hello@kletraq.com.
1. Roles & scope
The Controller determines the purposes and means of processing; Kletraq processes personal data only as a Processor on the Controller’s documented instructions, being the provision of the Service under the Terms and the Controller’s use of it. Subject-matter, duration, nature, purpose, data categories, and data-subject categories are as described in the Terms and the Controller’s configuration, and specifically:
- Nature & purpose: providing the Kletraq compliance-management platform (frameworks, controls, evidence, policies, vendor and transaction monitoring, and audit-ready export) to the Controller.
- Duration: the term of the Controller’s subscription, plus the limited post-termination export/deletion window in §9.
- Categories of data subjects: the Controller’s authorised platform users, and the individuals whose personal data appears in the compliance records the Controller uploads (e.g. the Controller’s employees, contractors, vendors, and — where applicable — its own customers).
- Types of personal data: account and contact identifiers (name, work email, role, organisation, authentication/MFA data), usage and device data, and any personal data contained in the evidence, policies, vendor records, and screening results the Controller submits. The Controller controls what it uploads and should not submit special-category data except where its own configuration and lawful basis permit.
2. Processing on instructions
Kletraq processes personal data only on the Controller’s documented instructions, including for international transfers, unless required to act by applicable law (in which case we inform the Controller unless legally prohibited). We will tell the Controller if, in our opinion, an instruction infringes the NDPA or GDPR.
3. Confidentiality
Personnel authorized to process personal data are bound by confidentiality obligations and access it on a least-privilege, need-to-know basis.
4. Security
Kletraq implements appropriate technical and organizational measures, including encryption in transit and at rest, role-based access control, mandatory MFA on privileged roles, tenancy isolation, logging and monitoring, and routine security assessment — as detailed on the Trust page.
5. Sub-processors
The Controller authorizes Kletraq to engage the sub-processors listed on the Trust page, each bound by written terms imposing data-protection obligations equivalent to this DPA. We give prior notice of any intended addition or replacement of a sub-processor so the Controller may object on reasonable data-protection grounds; Kletraq remains liable for its sub-processors’ performance.
6. Assistance with data-subject requests
Taking into account the nature of the processing, Kletraq assists the Controller with appropriate technical and organizational measures — and via Service functionality — to respond to data-subject requests to exercise rights of access, rectification, erasure, restriction, portability, and objection.
7. Assistance with compliance
Kletraq assists the Controller in ensuring compliance with security, breach-notification, and data-protection-impact-assessment obligations, taking into account the information available to us.
8. Personal-data breach
Kletraq notifies the Controller without undue delay after becoming aware of a personal-data breach affecting Customer Data, with the information the Controller reasonably needs to meet its own notification obligations (including the NDPA’s 72-hour NDPC notification requirement where applicable).
9. Deletion & return
On termination, and at the Controller’s choice, Kletraq deletes or returns Customer Data (and deletes existing copies) except where retention is required by law. Export is available for a limited period before deletion.
10. Audit
Kletraq makes available the information necessary to demonstrate compliance with this DPA and, on reasonable request and subject to confidentiality, supports audits — including via third-party reports and the Trust page — while protecting other customers’ confidentiality and platform security.
11. International transfers
Where processing involves a transfer outside Nigeria or the EEA/UK, Kletraq relies on an adequacy decision or appropriate safeguards (such as Standard Contractual Clauses) with supplementary measures.
12. Precedence
In the event of a conflict between this DPA and the Terms regarding the processing of personal data, this DPA prevails.