
Data Processing Addendum
Effective from 26th Aug, 2026
0. Introduction
This DATA PROCESSING ADDENDUM ("DPA"), as updated from time to time, supplements and its term and conditions are subject to Cloudvantage Limited's (its parent, subsidiaries, affiliates and/or brands) (collectively, "Company") Universal Terms of Use ("UToU"), which are incorporated herein by this reference, and governs Company's use of Customer's Data (as defined herein) (as a controller of such data). Company and Customer may be individually referred to as a "Party" or collectively, the "Parties."
1. Definitions
Unless otherwise defined in the Agreement (as defined herein), all capitalized terms used in this DPA will have the meanings given to them below:
- "Affiliate" means an entity that directly or indirectly controls, is controlled by or is under common control with an entity.
- "Agreement" means the UToU and all other written or electronic agreement(s) between Company and Customer, which govern use of the Website, Products, or Order Form (as applicable), as such terms or agreement may be updated from time to time. For the avoidance of doubt, all references to the "Agreement" shall also include the Standard Contractual Clauses (where applicable, as defined herein).
- "Consumer," "Business," "Sell," and/or "Service Provider" shall have the meanings given to them in the CCPA or CPRA (as applicable).
- "Company Network" means Company's data center facilities, servers, networking equipment, and software systems that are within Company's control and are used to serve and/or provide the Websites and Products.
- "Company Security Standards" means the security standards attached to this DPA as Annex 1.
- "Customer" means a Website visitor, user and/or the party set forth in the related Order Form.
- "Customer Data" means the personal data Company processes on behalf of Customer via the Website or Products, as more particularly described in this DPA.
- "Data Protection Laws" means all applicable Nigerian laws, regulations, and legislation relating to data protection and privacy related to processing of Customer Data under the Agreement, in each case as amended, repealed, consolidated or replaced from time to time.
- "Data Subject" is defined as the person associated with the Personal Data.
- "Europe" means the European Economic Area and its member states ("EEA"), Switzerland and the United Kingdom ("UK").
- "Personal Data" means any information about, or related to, an identifiable individual, which includes any information that can be linked to an individual or used to directly or indirectly identify an individual, natural person.
- "Processing" means any operation or set of operations that is performed upon Personal Data, whether or not by automatic means, such as collection, recording, securing, organization, storage, adaptation or alteration, access to, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure, or destruction. "Processes" and "Process" shall be construed accordingly.
- "Security Incident" means any unauthorized or unlawful breach of security that leads to the accidental or unlawful destruction, loss, or alteration of, or unauthorized disclosure of or access to, Customer Data on systems managed or otherwise controlled by Company.
- "Sensitive Data" means: (i) social security number, tax file number, passport number, driver's license number, Voter's card, National Identification Number, or similar identifier (or any portion thereof); (ii) credit or debit card number (other than the truncated (last four digits) of a credit or debit card); (iii) employment, financial, credit, genetic, biometric or health information; (iv) racial, ethnic, political or religious affiliation, trade union membership, information about sexual life or sexual orientation, or criminal record; (v) account passwords; or (vi) other information that falls within the definition of "special categories of data" under applicable Data Protection Laws.
- "Sub-processor" means any processor engaged by Company or its Affiliates to assist in fulfilling its obligations with respect to serving or providing the Website or Products pursuant to the Agreement or this DPA. Sub-processors may include third parties or Affiliates of Company but shall exclude Company's employees, contractors, or consultants.
Unless otherwise defined herein, the terms "personal data," "controller," "data subject," "processor" and "processing" shall have the meaning given to them under applicable Data Protection Laws or if not defined thereunder, the GDPR, and "process," "processes," and "processed," with respect to any Customer Data, shall be interpreted accordingly.
2. Data Processing
Scope and Roles
The Parties acknowledge and agree that with regard to the processing of Customer Data, this DPA applies when Customer Data is processed by Company. In this context, Company will act as "processor" to Customer who may act either as "controller" or "processor" with respect to Customer Data.
Purpose Limitation and Customer Controls
Company shall process Customer Data, as further described in Annex A (Details of Data Processing) of this DPA, only in accordance with Customer's documented lawful instructions as set forth in this DPA, as necessary to comply with applicable law, or as otherwise agreed in writing ("Permitted Purposes"). The Website and Products provide Customer with a number of controls, including security features and functionalities, that Customer may use to retrieve, correct, delete or restrict Customer Data. Customer may use these controls as technical and organizational measures to assist it in connection with its obligations under the GDPR, CCPA, CPRA, and all other applicable Data Protection Laws, including its obligations relating to responding to requests from Data Subjects.
Prohibited Data
Customer will not provide (or cause to be provided) any Sensitive Data to Company for processing under the Agreement, and Company will have no liability whatsoever for Sensitive Data, whether in connection with a Security Incident or otherwise. For the avoidance of doubt, this DPA will not apply to Sensitive Data.
Compliance with Laws
Customer represents and warrants that:
- It has complied, and will continue to comply, with all applicable laws, including Data Protection Laws, in respect of its processing of Customer Data and any processing instructions it issues to Company; and
- It has provided, and will continue to provide, all notice and has obtained, and will continue to obtain, all consents and rights necessary under Data Protection Laws for Company to process Customer Data for the purposes described in the Agreement.
Customer shall have sole responsibility for the accuracy, quality, and legality of Customer Data and the means by which Customer acquired Customer Data. Without prejudice to the generality of the foregoing, Customer agrees that it shall be responsible for complying with all laws (including Data Protection Laws) applicable to any other content created, sent, or managed through the Website or Products, including those relating to obtaining consents (where required) to send emails, the content of the emails and its email deployment practices.
Company will comply with all laws, rules and regulations applicable to it and binding on it in the performance of this DPA.
3. Customer Instructions
The parties agree that the Agreement and this DPA, including the provision of instructions via configuration tools such as any Company management console and APIs made available by Company for the Website and Products, constitute Customer's documented instructions regarding Company's processing of Customer Data ("Documented Instructions"). Company will process Customer Data only in accordance with Documented Instructions. Additional instructions outside the scope of the Documented Instructions (if any) require prior written agreement between Customer and Company, including agreement on any additional fees payable by Customer to Company for carrying out such instructions. Customer is entitled to terminate this DPA and the Agreement if Company declines to follow instructions requested by Customer that are outside the scope of, or changed from, those given or agreed to be given in this DPA.
4. Confidentiality of Customer Data
Company will not access or use, or disclose to any third party, any Customer Data, except, in each case, as necessary to maintain or provide the Website or Products, or as necessary to comply with the law or a valid and binding order of a governmental body (such as a preservation request, warrant, subpoena or court order). To the extent applicable by law, if a governmental body sends a demand for Customer Data, Company will attempt to redirect the governmental body to request that data directly from Customer. As part of this effort, Company may provide Customer's basic contact information to the government body. If compelled to disclose Customer Data to a government body, then Company will give Customer reasonable notice of the demand to allow Customer to seek a protective order or other appropriate remedy unless Company is legally prohibited from doing so.
5. Confidentiality Obligations of Company Personnel
Company restricts its personnel from processing Customer Data without authorization by Company as described in the Company Security Standards. Company imposes appropriate contractual obligations upon its personnel, including relevant obligations regarding confidentiality, data protection and data security.
6. Security of Data Processing
Company shall implement and maintain appropriate technical and organizational security measures that are designed to protect Customer Data from Security Incidents and designed to preserve the security and confidentiality of Customer Data in accordance with Company's security standards described in Annex B ("Security Measures") of this DPA.
Company shall ensure that any person who is authorized by Company to process Customer Data (including its employees, agents, and subcontractors) shall be under an appropriate obligation of confidentiality (whether a contractual or statutory duty).
In assessing the appropriate level of security, Company shall take account in particular of the risks that are presented by Processing, in particular from a Personal Data breach.
Customer is responsible for reviewing the information made available by Company relating to data security and making an independent determination as to whether such meets Customer's requirements and legal obligations under Data Protection Laws. Customer acknowledges that the Security Measures are subject to technical progress and development and that Company may update or modify the Security Measures from time to time, provided that such updates and modifications do not result in the degradation of the overall security of the Website or Products provided to Customer.
Upon becoming aware of a Security Incident, Company shall use commercially reasonable efforts to:
- Notify Customer without undue delay, and where feasible, within forty-eight (48) hours of awareness.
- Provide timely information relating to the Security Incident as it becomes known or as is reasonably requested by Customer; and
- Promptly take reasonable steps to contain and investigate any Security Incident.
Company's notification of or response to a Security Incident under this Section shall not be construed as an acknowledgment by Company of any fault or liability with respect to the Security Incident.
Notwithstanding the above, Customer agrees that except as provided by this DPA, Customer is responsible for its secure use of the Website and Products, including securing Customer Account authentication credentials, protecting the security of Customer Data when in transit to and from the Website or Product, and taking any appropriate steps to securely encrypt or backup any Customer Data uploaded to the Website or Products.
7. Security Reports and Audits
Subject to this Section, Company shall make available to Customer on written request all information necessary to demonstrate compliance with this Agreement, and shall allow for and contribute to audits, including inspections, by Customer or an auditor mandated by Customer in relation to the Processing of Customer Data. Information and audit rights of Customer only arise under this Section to the extent that the Agreement or this DPA does not otherwise give them information and audit rights meeting the relevant requirements of Data Protection Law. Company shall respond to all reasonable written requests for information made by Customer to confirm Company's compliance with this DPA, including responses to information security, due diligence, and audit questionnaires, by making additional information available regarding its information security program upon Customer's written request to Company provided that Customer shall not exercise this right more than once per calendar year. By submitting a request Customer agrees to the terms of the Privacy Policy regarding Customer's personally identifiable information.
8. Sub-Processing
Authorized Sub-processors
Customer acknowledges, understands and agrees that Company may use sub-processors to fulfill its contractual obligations under this DPA or to provide certain services on its behalf, such as providing tracking or support services. Company has engaged Sub-processors to carry out processing activities on Customer Data on behalf of Customer, as amended by Company. Company shall notify Customer if it adds or removes Sub-processors prior to any such changes. Company may update the Sub-processor list and may provide Customer with a mechanism to obtain notice of that update. Customer consents to Company's use of Sub-processors as described in this Section. Except as set forth in this Section, or as Customer may otherwise authorize, Company will not permit any Sub-processor to carry out processing activities on Customer Data on behalf of Customer.
Sub-processor Obligations
Company shall:
- Enter into a written agreement with each Sub-processor containing data protection obligations that provide at least the same level of protection for Customer Data as those in this DPA, to the extent applicable to the nature of the service provided by such Sub-processor; and
- Remain responsible for such Sub-processor's compliance with the obligations of this DPA and for any acts or omissions of such Sub-processor that cause Company to breach any of its obligations under this DPA.
Customer acknowledges and agrees that, where applicable, Company fulfills its obligations under clause of the Controller-to-Processor Clauses and Processor-to-Processor Clauses (as applicable) by complying with this Section and that Company may be prevented from disclosing Sub-processor agreements to Customer due to confidentiality restrictions but Company shall, upon request, use reasonable efforts to provide Customer with all relevant information it reasonably can in connection with Sub-processor agreements.
9. Data Subject Requests
Taking into account the nature of the Processing, processor may assist the Company by implementing appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Company obligations, as reasonably understood by Company, to respond to requests to exercise Data Subject rights under the Data Protection Laws. In the event that any such request is made to Company directly, Company shall not respond to such communication directly except as appropriate (for example, to direct the Data Subject to contact Customer) or legally required, without Customer's prior authorization. If Company is required to respond to such a request, Company shall, where Customer is identified or identifiable from the request, promptly notify Customer and provide Customer with a copy of the request unless Company is legally prohibited from doing so. For the avoidance of doubt, nothing in the Agreement (including this DPA) shall restrict or prevent Company from responding to any Data Subject or data protection authority requests in relation to personal data for which Company is a controller.
10. Data Protection Impact Assessment
To the extent required under applicable Data Protection Laws, Company shall (considering the nature of the processing and the information available to Company) provide all reasonably requested information regarding the Website or Products to enable Customer to carry out data protection impact assessments or prior consultations with data protection authorities as required by Data Protection Laws. Company shall comply with the foregoing by:
- Complying with Section 7 (Security Reports and Audits).
- Providing the information contained in the Agreement, including this DPA; and
- If the foregoing sub-sections are insufficient for Customer to comply with such obligations, upon request, providing additional reasonable assistance (at Customer's sole expense).
11. Security Breach Notification
Company shall notify Customer without undue delay upon Company becoming aware of a Personal Data breach affecting Customer's Personal Data, providing Customer with sufficient information to allow Customer to meet any obligations to report or inform Data Subjects of the Personal Data breach under the Data Protection Laws.
Company shall co-operate with Customer and take reasonable commercial steps as directed by Customer to assist in the investigation, mitigation and remediation of each such Personal Data breach.
12. Return or Deletion of Data on Termination
Upon termination or expiration of the Agreement, Company shall (at Customer's election) delete or return to Customer all Customer Data (including copies) in its possession or control, except that this requirement shall not apply to the extent Company is required by applicable law to retain some or all of Customer Data, or to Customer Data it has archived on back-up systems, which Customer Data Company shall securely isolate, protect from any further processing and eventually delete in accordance with Company's deletion or retention policies, except to the extent required by applicable law. The Parties agree that the certification of deletion of Customer Data shall be provided by Company to Customer only upon Customer's written request.
13. Jurisdiction-Specific Terms
To the extent Company processes Customer Data originating from and protected by Data Protection Laws in one of the jurisdictions listed in Annex C, then the terms specified in Annex C with respect to the applicable jurisdiction(s) ("Jurisdiction-Specific Terms") apply in addition to the terms of this DPA. In the event of any conflict or ambiguity between the Jurisdiction-Specific Terms and any other terms of this DPA, the applicable Jurisdiction-Specific Terms will take precedence, but only to the extent of the Jurisdiction-Specific Terms' applicability to Company.
14. Termination of the DPA
This DPA shall remain in effect for as long as Company carries out Customer Data processing operations on behalf of Customer or until termination of the Agreement.
15. Limitation of Liability
Each Party's and all of its Affiliates' liability taken together in the aggregate arising out of or related to this DPA shall be subject to the exclusions and limitations of liability set forth in the Agreement.
Any claims made against Company or its Affiliates under or in connection with this DPA shall be brought solely by Customer.
In no event shall any Party limit its liability with respect to any individual's data protection rights under this DPA or otherwise.
16. Duties to Inform
Where Customer Data becomes subject to confiscation during bankruptcy or insolvency proceedings, or similar measures by third parties while being processed by Company, Company will inform Customer without undue delay. Company will, without undue delay, notify all relevant parties in such action (e.g., creditors, bankruptcy trustee) that any Customer Data subjected to those proceedings is Customer's property and area of responsibility and that Customer Data is at Customer's sole disposition.
17. Entire Agreement; Conflict
The Parties agree that this DPA shall replace any existing data processing agreement or similar document that the Parties may have previously entered into in connection with the Website or Products. In the event of any conflict or inconsistency between this DPA and the UToU, the provisions of the following documents (in order of precedence) shall prevail: this DPA; and then the UToU.
18. Modification
Except for any changes made by this DPA, the Agreement remains unchanged and in full force and effect.
19. Successors and Assignees
No one other than a Party to this DPA, its successors and permitted assignees shall have any right to enforce any of its terms.
20. Governing Law and Jurisdiction
This DPA shall be governed by and construed in accordance with the governing law and jurisdiction of Nigeria.
21. Effective Date
This DPA is entered into with effect from the earlier date of use of the Website or Products or the signature on the applicable Order Form.
22. Annex 1 — Company Security Standards
Capitalized terms not otherwise defined in this document have the meanings assigned to them in the Agreement or DPA.
Information Security Program
Company will maintain an information security program (including the adoption and enforcement of internal policies and procedures) designed to:
- Help Company secure Customer Data against accidental or unlawful loss, access or disclosure.
- Identify reasonably foreseeable and internal risks to security and unauthorized access to the Company Network; and
- Minimize security risks, including through risk assessment and regular testing.
Company will designate one or more employees to coordinate and be accountable for the information security program. The information security program will include the following measures: The Company Network will be electronically accessible to employees, contractors and any other person as necessary to provide the Website and Products. Company will maintain access controls and policies to manage what access is allowed to the Company Network from each network connection and user, including the use of firewalls or functionally equivalent technology and authentication controls. Company will maintain corrective action and incident response plans to respond to potential security threats.
Continued Evaluation
Company will conduct periodic reviews of the security of Company's Network and adequacy of Data Processor's information security program as measured against industry security standards and its policies and procedures. Company will continually evaluate the security of Company's Network to determine whether additional or different security measures are required to respond to new security risks or findings generated by the periodic reviews.
The Security Measures implemented by the data importer are as described in Annex 1 to the DPA (Company Security Standards).
23. Annex A — Details of Data Processing
Categories of Data Subjects
The categories of Data Subjects whose Personal Data is Processed include:
- A user or visitor to the Website.
- Customer (i.e., an individual with access to a Customer Account); and
- A Customer user, visitor, customer, subscriber, end-user and other individual about whom Customer has given Company information or has otherwise interacted with Customer via the Website or Products (collectively, a "Customer End-User").
Categories of Personal Data
Customer or Customer End-Users may upload, submit, or otherwise provide certain Personal Data via the Website or Products, the extent of which is typically determined and controlled by Customer in its sole discretion, and may include the following types of Personal Data:
- Identification and contact data (name, address, title, contact details, username); financial information (credit card details, account details, payment information); employment details (employer, job title, geographic location, area of responsibility).
- Identification and contact data (name, date of birth, gender, general, occupation or other demographic information, address, title, contact details, including email address); personal interests or preferences (including purchase history, marketing preferences and publicly available social media profile information); IT information (IP addresses, usage data, cookies data, online navigation data, location data, browser data); financial information (credit card details, account details, payment information).
Sensitive Data Processed (if applicable)
Company does not want to, nor does it intentionally, collect or process any Sensitive Data in connection with the Website or Products.
Frequency of Processing
Continuous and as determined by Customer.
Subject Matter and Nature of the Processing
Company provides hosted private cloud services, as more particularly described on the Agreement, Website, Products or Order Form. The subject matter of the data processing under this DPA is the Customer Data. Customer Data will be processed in accordance with the Agreement (including this DPA) and may be subject to the following processing activities: storage and other processing necessary to provide, maintain and improve the Website and Products provided to Customer pursuant to the Agreement.
Purpose of the Processing
Company shall only process Customer Data for the Permitted Purposes, which shall include:
- Processing as necessary to provide the Website and Products in accordance with the Agreement.
- Processing initiated by Customer in its use of the Website and Products; and
- Processing to comply with any other reasonable instructions provided by Customer (e.g., via email or support tickets) that are consistent with the terms of the Agreement.
Duration of Processing and Retention
Company will process Customer Data as outlined in Section 12 (Return or Deletion of Data on Termination) of this DPA.
24. Annex B — Security Measures
The Security Measures implemented by the data importer are as described in Annex 1 to the DPA (Company Security Standards).