Skip to main content
Back to Home

Data Processing Agreement

FlowAfric Ltd, Registered in Nigeria

Last updated: August 2026

Data Processing Agreement

This Data Processing Agreement describes the data protection obligations applicable where FLOWAFRIC LIMITED engages a third party to process personal data on FlowAfric's behalf in connection with the FlowAfric platform and related services.

1. Scope and Purpose

FlowAfric may engage third-party service providers to process personal data for purposes necessary to operate, secure, and provide FlowAfric services.

Such processing may include:

  • Cloud hosting and infrastructure
  • Identity verification
  • Financial and payment processing
  • Fraud prevention
  • AML and sanctions screening
  • Security monitoring
  • Communication infrastructure
  • Blockchain and cryptocurrency infrastructure
  • Analytics and technical services
  • Customer support
  • Other services necessary to operate the FlowAfric platform

The applicable services and processing activities may vary depending on the service provider and the services provided.

2. Roles of the Parties

Where this DPA applies:

FlowAfric acts as the data controller or other applicable responsible party in relation to personal data processed for its purposes.

The relevant service provider acts as a data processor where it processes personal data on FlowAfric's documented instructions.

The parties shall comply with their respective obligations under applicable data protection laws.

Where a service provider independently determines the purposes and means of processing for a particular activity, that provider may have separate responsibilities under applicable law.

3. Categories of Personal Data

Depending on the services provided, personal data processed on behalf of FlowAfric may include:

  • Identity and account information
  • Contact information
  • Financial and transaction information
  • Verification and compliance information
  • Device and technical information
  • Security and fraud-monitoring information
  • Communication metadata
  • Location information where applicable
  • Other personal data necessary for the agreed services

Sensitive or specially protected personal data may be processed where necessary and permitted by applicable law.

4. Processing Instructions

Service providers shall process personal data only:

  • For agreed and documented purposes
  • To provide the contracted services
  • In accordance with FlowAfric's lawful instructions
  • As required by applicable law

A service provider should not use personal data for unrelated purposes unless authorized by FlowAfric or otherwise permitted or required by applicable law.

5. Confidentiality

Persons authorized to process personal data on behalf of FlowAfric shall be subject to appropriate confidentiality obligations.

Service providers shall take reasonable measures to prevent unauthorized access, disclosure, use, alteration, or loss of personal data.

6. Security Measures

FlowAfric and applicable service providers shall implement appropriate technical and organizational measures designed to protect personal data.

Depending on the nature of processing, such measures may include:

  • Encryption
  • Access controls
  • Authentication mechanisms
  • Least-privilege access
  • Security monitoring
  • Logging
  • Backup and recovery measures
  • Vulnerability management
  • Incident response procedures
  • Appropriate personnel security controls

Security measures should be proportionate to the nature, scope, context, and risks associated with the processing.

7. Sub-Processors

A service provider may use another service provider to process personal data on its behalf where permitted by the applicable agreement and applicable law.

Where required, appropriate contractual and data-protection obligations should be imposed on such sub-processors.

Service providers remain responsible for the processing activities of their authorized sub-processors to the extent required by applicable law and contractual arrangements.

8. International Data Transfers

Certain FlowAfric service providers or their sub-processors may process or store personal data outside Nigeria.

Where personal data is transferred internationally, the parties shall implement appropriate safeguards and comply with applicable Nigerian data protection requirements relating to cross-border transfers.

Depending on the circumstances, safeguards may include contractual protections, organizational measures, technical security measures, or other lawful transfer mechanisms.

9. Assistance With Data-Subject Requests

Where reasonably necessary and applicable to the service being provided, processors should assist FlowAfric in responding to lawful requests from data subjects relating to their personal data.

Such requests may include requests concerning:

  • Access
  • Correction
  • Deletion
  • Restriction
  • Objection
  • Data portability
  • Other applicable data-protection rights

Processors should promptly refer data-subject requests to FlowAfric where FlowAfric is responsible for responding to the request, unless otherwise required by law.

10. Security Incidents and Data Breaches

A service provider that becomes aware of a personal data security incident affecting personal data processed for FlowAfric should notify FlowAfric without undue delay and provide reasonably available information necessary to assist FlowAfric in assessing and responding to the incident.

Where appropriate, information may include:

  • The nature of the incident
  • Categories of affected data
  • Potential impact
  • Measures taken to contain or mitigate the incident
  • Available information regarding affected systems or individuals

FlowAfric may take reasonable steps to investigate, contain, mitigate, and address personal data security incidents.

11. Data Retention and Deletion

Personal data should not be retained longer than reasonably necessary for the agreed processing purposes unless a longer period is required or permitted by applicable law.

Where the relevant processing relationship ends, personal data should be returned, deleted, or otherwise handled in accordance with the applicable agreement and legal requirements.

A service provider may retain information where required by applicable law, provided the retained information remains appropriately protected.

12. Regulatory and Legal Compliance

FlowAfric and applicable service providers shall comply with applicable data protection and privacy laws relevant to their respective roles.

This may include applicable Nigerian data protection requirements and lawful regulatory obligations.

Nothing in this DPA requires a party to breach a legal or regulatory obligation.

13. Audit and Compliance Information

Where required by applicable law or contractual arrangements, a service provider may be required to provide reasonable information demonstrating compliance with applicable data-protection and security obligations.

Any audit or assessment shall be conducted in a manner that:

  • Protects confidential information
  • Avoids unnecessary disruption
  • Respects security requirements
  • Takes into account relevant third-party confidentiality obligations

14. Government and Law-Enforcement Requests

A service provider should notify FlowAfric of a legally binding request for access to FlowAfric personal data where legally permitted to do so.

Where notification is prohibited by law, the service provider may comply with the applicable legal requirement without providing such notice.

Service providers should disclose only the information legally required where permitted.

15. Data Protection and Confidentiality

The parties shall maintain appropriate confidentiality and security measures for personal data throughout the processing relationship.

The obligations in this DPA are intended to supplement, and not replace, any broader confidentiality, security, or data-protection obligations contained in the applicable commercial agreement.

16. Relationship With Other FlowAfric Policies

This DPA is separate from the FlowAfric Privacy Policy.

The Privacy Policy explains how FlowAfric processes personal information relating to users and other individuals.

This DPA governs applicable data-processing relationships between FlowAfric and relevant service providers or other contractual parties.

17. Changes to This DPA

FlowAfric may update this DPA where reasonably necessary to reflect changes in:

  • Applicable laws
  • Regulatory requirements
  • Security practices
  • Technology
  • Processing activities
  • FlowAfric services
  • Contractual requirements

Where this DPA forms part of a specific contractual relationship, amendments may be subject to the terms of the applicable agreement.

18. Contact Us

Questions regarding this DPA or FlowAfric's data-processing practices may be directed to:

FLOWAFRIC LIMITED

Email: support@flowafric.com

Website: www.flowafric.com

FlowAfric — Connect • Call • Pay

Questions about Data Processing?

If you have any questions about our Data Processing Agreement or data-processing practices, please contact us.

Contact Support