Data Processing Agreement
Draft for legal review. Last updated 3 October 2026. This agreement has been prepared for review by a Nigerian lawyer and is not yet final. Text in [square brackets] still needs to be filled in.
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Quantum S2 Ltd (RC 1806209, No 8, Thomas Salako Street, Agege, Lagos) ("we", "us") and the business using Quantum - SalesMaster ("the Customer"). Quantum - SalesMaster is a product of Quantum S2 Ltd, not a separate company. Under the NDPA the Customer is the data controller of Customer Personal Data and we are its data processor. This DPA applies whenever we process personal data on the Customer's behalf, and is intended to meet the requirements of the Nigeria Data Protection Act 2023 ("NDPA") and the Nigeria Data Protection Commission's General Application and Implementation Directive 2025 ("GAID").
Words such as "personal data", "processing", "data controller", "data processor", "data subject" and "personal data breach" have the meanings given in the NDPA.
1. Roles
- The Customer is the data controller of the personal data it and its users put into its Quantum - SalesMaster workspace ("Customer Personal Data"). We are its data processor.
- The Customer is responsible for having a lawful basis for that data, for giving the people concerned the information the NDPA requires, and for registering with the Nigeria Data Protection Commission where it is a data controller of major importance.
2. Details of the processing
| Item | Details |
|---|---|
| Subject matter | Providing the Quantum - SalesMaster service under the Terms of Service |
| Duration | For as long as the Customer's workspace exists, plus the deletion period in section 9 |
| Nature and purpose | Hosting, storing, displaying, backing up and transmitting data so the Customer's staff can plan routes, record visits, orders and payments, manage customers and products, and see reports; providing support when the Customer asks |
| Data subjects | The Customer's staff who use the app; the Customer's customers and prospects (shops, their owners and contact people) |
| Types of personal data | Names, work emails, roles; shop names, contact names, phone numbers, addresses, landmarks and map locations; orders, visits, payments and notes linked to them; photos taken in the app; location of the phone at certain moments when the user allows it |
| Special categories | None expected. The Customer must not put sensitive personal data (such as health, religion or biometric data) into the service |
3. Our obligations
We will:
- process Customer Personal Data only on the Customer's documented instructions, which are the Terms of Service, this DPA and the Customer's use of the service's features, unless Nigerian law requires otherwise (in which case we will tell the Customer first, unless the law forbids it);
- tell the Customer if we believe an instruction breaks the NDPA;
- make sure everyone at Quantum S2 Ltd who can access Customer Personal Data is bound by confidentiality;
- keep appropriate technical and organisational security measures in place, as described in section 5;
- help the Customer, taking into account the nature of the processing, to answer requests from data subjects exercising their NDPA rights, to carry out data protection impact assessments, and to consult the Commission where required;
- not sell Customer Personal Data or use it for our own purposes, except in a form that does not identify any person to run and improve the service.
4. Sub-processors
The Customer gives general authorisation for us to use sub-processors. Our current sub-processors are:
Sub-processor Service Location Supabase, Inc. Database, authentication and file storage [REGION] Vercel Inc. Application hosting Global; United States Resend (Plus Five Five, Inc.) Transactional email United States We will give the Customer at least 30 days' notice by email before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds; if we cannot resolve the objection, the Customer may end the agreement and receive a refund of any prepaid fees for the unused period.
We will put a written contract in place with each sub-processor giving at least the same protection as this DPA, and we remain responsible to the Customer for them.
5. Security
Our measures include:
- encryption of data in transit (HTTPS) and at rest by our hosting providers;
- separation of each Customer's data inside the database by row-level security, so one Customer's users cannot see another's;
- role-based access within each workspace, including keeping product cost prices visible to administrators only;
- two-step sign-in for platform administrators, and no use of database master keys in the public-facing app;
- regular backups held by our database provider;
- limiting our own staff's access to what is needed to run and support the service, and keeping a record of administrative actions.
We may update these measures as long as the overall level of protection does not go down.
6. Personal data breaches
We will tell the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. We will give the information the Customer needs to meet its own duty under the NDPA to notify the Nigeria Data Protection Commission within 72 hours and, where required, the people affected, and we will take reasonable steps to contain the breach.
7. Transfers outside Nigeria
Some sub-processors process data outside Nigeria. We will only transfer Customer Personal Data out of Nigeria in line with the NDPA: to a country the Commission recognises as giving adequate protection, or under appropriate safeguards such as binding contract terms, or on another basis the NDPA allows.
8. Audits
We will make available to the Customer the information reasonably needed to show that we meet this DPA, including answering reasonable security questionnaires once a year. Where that is not enough, the Customer may, at its own cost and with at least 30 days' notice, have an independent auditor bound by confidentiality inspect our relevant records, no more than once a year, in a way that does not disrupt our business or put other Customers' data at risk.
9. Return and deletion
When the Customer's workspace is closed, we will, at the Customer's choice, return Customer Personal Data in a common electronic format (if asked within 30 days) and delete it within 90 days, unless Nigerian law requires us to keep it. Data in backups is overwritten in the normal backup cycle and is not restored except to recover the service.
10. Liability and order of precedence
Each party's liability under this DPA is subject to the limits in the Terms of Service, except where the NDPA does not allow those limits. If this DPA and the Terms of Service conflict about personal data, this DPA applies.
11. Governing law
This DPA is governed by the laws of the Federal Republic of Nigeria, and the courts of Lagos State have jurisdiction.
12. Contact
Data Protection Officer, Quantum S2 Ltd, No 8, Thomas Salako Street, Agege, Lagos. Email: [DPO EMAIL].