Data Processing Addendum

The terms under which Zedapex processes your customers' personal data on your behalf when you use Replyvoo.

Last updated

This is a draft prepared for review by a qualified lawyer before publication.

This Data Processing Addendum ("DPA") forms part of the Terms of Service between Zedapex Limited, based in Lagos, Nigeria ("Zedapex", "we" or "Processor"), and the business customer using Replyvoo ("Customer", "you" or "Controller").

It applies whenever we process personal data on your behalf through Replyvoo. It is designed to meet the requirements of the Nigeria Data Protection Act 2023 ("NDPA") and, where applicable, the EU General Data Protection Regulation and the UK GDPR (together, "GDPR"). It applies automatically when you accept the Terms. If you need a signed copy, contact [email protected].

If this DPA conflicts with the Terms, this DPA takes priority on data protection matters.

1. Definitions

  • Personal data, processing, controller, processor, data subject and personal data breach have the meanings given in the NDPA or GDPR, as applicable.
  • Customer Personal Data means personal data in Customer Content that we process on your behalf, mainly data about your own customers and contacts ("End-Users").
  • Sub-processor means a third party we engage to process Customer Personal Data.
  • Data Protection Laws means the NDPA, regulations and guidance issued by the Nigeria Data Protection Commission ("NDPC"), and, where applicable, GDPR and other data protection laws that apply to the processing.

2. Roles

  • You are the controller of Customer Personal Data. You decide why and how it is processed.
  • We are a processor of Customer Personal Data, processing it only on your behalf.
  • For account, billing, referral and usage data about you and your team, we act as an independent controller, as described in our Privacy Policy. This DPA does not apply to that data.

3. Details of the processing

Subject matter: providing the Replyvoo Service, including AI Closers, the inbox, lead scoring, Blasts, payment links and Juno.

Duration: for as long as you use the Service, plus the deletion period in section 11.

Nature and purpose:

  • receiving, storing and displaying messages from connected channels such as Telegram;
  • generating AI replies, summaries and lead scores using AI model providers;
  • sending messages and broadcasts on your instructions;
  • creating and tracking payment links;
  • providing support, security, backups and troubleshooting.

Types of personal data:

  • names, usernames, profile photos and platform user IDs;
  • phone numbers and email addresses where shared;
  • message content, attachments, images, voice notes and documents;
  • conversation metadata such as timestamps and delivery status;
  • lead scores, tags, notes and custom fields you add;
  • payment-link status and limited transaction details.

Special categories of data: we do not require any. You should not instruct AI Closers to collect sensitive data, such as health, biometric, religious or similar data, unless you have a lawful basis and have configured your use accordingly. End-Users may still volunteer such data in chats.

Data subjects: your End-Users, leads and contacts, and any other people who message your connected channels or are included in your broadcasts.

4. Your instructions

  • We will process Customer Personal Data only on your documented instructions. These Terms, this DPA, and your configuration and use of the Service are your instructions.
  • If we believe an instruction breaks Data Protection Laws, we will tell you, and we may decline to follow it.
  • If the law requires us to process Customer Personal Data in another way, we will tell you before doing so, unless the law prohibits it.

5. Your responsibilities

You confirm that:

  • you have a lawful basis to collect and process Customer Personal Data and to have us process it;
  • you have given End-Users all required privacy notices, including that you use AI and third-party providers;
  • you have obtained any consents needed, including for marketing messages and broadcasts;
  • you disclose the use of AI or automation to End-Users where required;
  • your instructions comply with Data Protection Laws and our Acceptable Use Policy.

6. Confidentiality

We make sure that anyone we authorise to process Customer Personal Data, including staff and contractors, is bound by confidentiality obligations and only accesses the data as needed to provide the Service, support you, or keep the Service secure.

7. Security measures

We implement appropriate technical and organisational measures to protect Customer Personal Data, taking into account the nature of the data and the risks involved. These include:

  • Encryption: TLS encryption for data in transit; encryption at rest where supported by our hosting provider; encrypted storage of channel tokens and API keys.
  • Access control: role-based access, least-privilege permissions, strong authentication for staff access to production systems, and prompt removal of access when no longer needed.
  • Workspace isolation: logical separation of each customer's data.
  • Monitoring: logging of access and security events, and alerts for unusual activity.
  • Resilience: regular backups, and recovery procedures.
  • Secure development: code review, dependency updates and testing before release.
  • Vendor management: due diligence and contractual protections with sub-processors.
  • Staff: confidentiality commitments and data protection awareness.

We may update these measures over time, as long as the overall level of protection is not reduced. We do not claim any formal security certification.

8. Sub-processors

You give us general authorisation to engage sub-processors. Our current categories of sub-processors are:

  • AI model providers, for example Anthropic, to generate AI replies, summaries and lead scores;
  • messaging platforms you connect, for example Telegram, and, when launched, Meta (for WhatsApp and Instagram) and TikTok;
  • payment processors, for example Paystack, Flutterwave and a crypto payment processor for USDT, for payment links and billing;
  • cloud hosting and database providers, to host and store the Service and its data;
  • email delivery providers, for notifications and account emails;
  • monitoring and support tools, for error tracking and customer support.

Messaging platforms you choose to connect also act under their own terms with you. Their processing of data on their own platforms is outside our control.

We will:

  • impose data protection terms on each sub-processor that offer at least the same level of protection as this DPA;
  • remain responsible to you for our sub-processors' performance of their obligations;
  • provide a current list of named sub-processors on request at [email protected];
  • give you at least 14 days' notice, by email or in the app, before adding or replacing a sub-processor that processes Customer Personal Data.

You may object to a new sub-processor on reasonable data protection grounds within that notice period. We will then work with you in good faith to find a solution. If we cannot, you may terminate the affected part of the Service and receive a refund of prepaid fees for the unused period.

9. International transfers

Customer Personal Data may be processed outside Nigeria, and outside the EU or UK, by us or our sub-processors, including in the United States. When this happens, we will make sure an appropriate transfer mechanism is in place, such as:

  • a country recognised as having adequate data protection;
  • standard contractual clauses approved under GDPR, or equivalent contractual safeguards recognised under the NDPA;
  • any other lawful transfer mechanism.

10. Helping you meet your obligations

Taking into account the nature of the processing, we will provide reasonable help to you to:

  • respond to data subject requests, such as access, correction or deletion. The Service lets you view, export and delete conversations and contacts. If we receive a request directly from one of your End-Users, we will pass it to you without undue delay and will not respond ourselves unless you tell us to or the law requires it;
  • carry out data protection impact assessments and prior consultations with regulators, where required;
  • meet your security and breach notification obligations.

We may charge a reasonable fee for help that goes beyond normal Service functionality, where the law allows.

11. Personal data breaches

If we become aware of a personal data breach affecting Customer Personal Data, we will:

  • notify you without undue delay, and in any event within 72 hours of becoming aware of it;
  • provide, as information becomes available, a description of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed;
  • take reasonable steps to contain the breach, reduce its effects and prevent it from happening again;
  • cooperate with you in any notifications you must make to the NDPC, other regulators or affected people.

Our notification is not an admission of fault or liability.

12. Deletion and return on termination

When your account is closed or the Service ends:

  • you may export Customer Personal Data for 30 days using the export tools or by asking [email protected];
  • after that, we will delete Customer Personal Data from our live systems within a further 30 days;
  • copies in backups will be overwritten in line with our backup cycle, normally within 90 days, and will be kept secure and not actively used in the meantime;
  • we may keep data where the law requires us to, in which case we will continue to protect it under this DPA.

You can also delete individual conversations, contacts or workspaces at any time.

13. Audits and information

  • On written request, we will provide information reasonably needed to show that we comply with this DPA, such as a summary of our security measures, policies and sub-processor list.
  • If that information is not enough, or a regulator requires it, you may request an audit. Audits must be on at least 30 days' written notice, during normal business hours, no more than once a year (unless following a breach or regulator request), at your cost, and carried out by you or an independent auditor bound by confidentiality.
  • Audits must not unreasonably disrupt our business or give access to other customers' data. We may charge reasonable costs for staff time spent on audits.

14. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except where the law does not allow this.

15. EU and UK customers

Where GDPR applies to your processing, the parties agree that this DPA contains the terms required by Article 28 of the GDPR. Where a restricted transfer of Customer Personal Data takes place from the EU or UK to us, the relevant standard contractual clauses (Module Two, controller to processor, and the UK Addendum where applicable) are incorporated by reference, with Nigerian law as governing law where permitted, or the law of the relevant EU member state or England and Wales where required. A completed copy is available on request at [email protected].

16. Changes and term

This DPA lasts for as long as we process Customer Personal Data for you. We may update it to reflect changes in law, regulator guidance or our services. We will tell you about material changes in advance, and changes will not reduce the overall level of protection for Customer Personal Data.

17. Contact

Data protection questions about this DPA:

Zedapex Limited, Lagos, Nigeria

Email: [email protected]