Last Updated: 07.20.2026.
Version: 1.0 Effective Date: [07.25.2026] Last Updated: [07.20.2026]
Document Purpose
This Data Processing Addendum ("DPA") supplements the Terms of Service and Privacy Policy with respect to the processing of Personal Information by NaijaAssets on behalf of its Users, enterprise customers, school partners, and other data controllers. It sets forth the rights, obligations, and safeguards applicable to such processing.
Contact Information
DPA Inquiries: legal@legal.naijaassets.com Primary Website: https://naijaassets.com
Table of Contents
- Definitions
- Scope and Application
- Processing of Personal Data
- Data Controller and Data Processor
- Processor Obligations
- Data Subject Rights
- Sub-Processing
- International Data Transfers
- Security Measures
- Data Breach Notification
- Data Deletion and Return
- Audit Rights
- Liability
- Term and Termination
- Governing Law
- Changes to This DPA
- Contact
1. Definitions
Capitalized terms used in this DPA have the meanings set forth in the Terms of Service unless otherwise defined below.
"Controller" means the entity that determines the purposes and means of the processing of Personal Data.
"Data Subject" means the identified or identifiable natural person to whom Personal Data relates.
"Personal Data" means any information relating to an identified or identifiable natural person, as defined under applicable data protection laws.
"Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means.
"Processor" means the entity that processes Personal Data on behalf of the Controller.
"Sub-Processor" means any Processor engaged by NaijaAssets to process Personal Data on behalf of the Controller.
"Applicable Data Protection Laws" means all laws and regulations applicable to the Processing of Personal Data under this DPA, including but not limited to the General Data Protection Regulation (GDPR) (EU) 2016/679, the UK GDPR, the Nigerian Data Protection Regulation (NDPR), the California Consumer Privacy Act (CCPA), and any other applicable privacy or data protection laws.
2. Scope and Application
2.1 Application
This DPA applies where NaijaAssets Processes Personal Data on behalf of a Controller in connection with the provision of the Platform and Services.
2.2 Controller Determination
The Controller determines the purposes and means of Processing. NaijaAssets acts as a Processor or Sub-Processor, as applicable, Processing Personal Data only on documented instructions from the Controller.
2.3 Incorporation
This DPA is incorporated into and forms part of the Terms of Service. By using the Platform in a capacity that involves the Processing of Personal Data by NaijaAssets on your behalf, you agree to the terms of this DPA.
3. Processing of Personal Data
3.1 Nature and Purpose
The nature and purpose of Processing is the provision of the Platform and Services, including educational content delivery, AI Features, analytics, account management, and related support services.
3.2 Data Categories
Personal Data processed under this DPA may include:
- Names, email addresses, and contact information
- Academic information and educational records
- Learning progress and assessment results
- Usage data and platform interaction data
- Device information and IP addresses
- Communications and support correspondence
- AI Feature inputs and outputs
3.3 Data Subjects
Data Subjects may include:
- Students and their parents or legal guardians
- Teachers
- Affiliates
- Authorized users of enterprise or school accounts
- Other individuals whose Personal Data is provided to NaijaAssets by the Controller
3.4 Duration
Processing continues for the duration of the agreement between the Controller and NaijaAssets, unless otherwise agreed.
4. Data Controller and Data Processor
4.1 Controller Responsibilities
The Controller represents, warrants, and agrees that:
- It has obtained all necessary consents, rights, and authorizations to provide Personal Data to NaijaAssets for Processing under this DPA
- Its instructions to NaijaAssets comply with Applicable Data Protection Laws
- It has provided appropriate notice to Data Subjects regarding the Processing of their Personal Data
- It will respond to Data Subject requests and inquiries regarding their Personal Data
4.2 Processor Responsibilities
NaijaAssets shall:
- Process Personal Data only on documented instructions from the Controller, unless required to do otherwise by applicable law
- Ensure that personnel authorized to Process Personal Data have committed themselves to confidentiality
- Implement appropriate technical and organizational security measures
- Assist the Controller in fulfilling its obligations regarding Data Subject rights
- Notify the Controller of any Personal Data breach without undue delay
5. Processor Obligations
5.1 Processing Instructions
NaijaAssets Processes Personal Data only in accordance with the Controller's documented instructions, which include the Terms of Service, this DPA, and the Controller's use of the Platform features and functionality.
5.2 Confidentiality
NaijaAssets ensures that all personnel authorized to Process Personal Data are bound by appropriate confidentiality obligations.
5.3 Assistance
NaijaAssets provides reasonable assistance to the Controller in:
- Responding to Data Subject requests
- Conducting data protection impact assessments
- Complying with obligations regarding data security and breach notification
- Demonstrating compliance with Applicable Data Protection Laws
6. Data Subject Rights
6.1 Controller Obligations
The Controller is primarily responsible for responding to Data Subject requests regarding their Personal Data.
6.2 Processor Assistance
NaijaAssets shall, taking into account the nature of the Processing, assist the Controller by implementing appropriate technical and organizational measures to facilitate the Controller's response to Data Subject requests.
6.3 Direct Requests
If NaijaAssets receives a direct request from a Data Subject regarding their Personal Data, NaijaAssets shall promptly inform the Controller and provide reasonable assistance in responding to the request.
7. Sub-Processing
7.1 Authorized Sub-Processors
The Controller acknowledges that NaijaAssets may engage Sub-Processors to Process Personal Data. Current categories of Sub-Processors include:
- Cloud infrastructure providers
- Payment processors
- AI model and API providers
- Analytics and monitoring services
- Customer support platforms
- Email and communication services
7.2 Sub-Processor Engagement
NaijaAssets shall:
- Enter into written agreements with Sub-Processors that impose data protection obligations no less protective than those in this DPA
- Remain liable for the acts and omissions of Sub-Processors
- Provide notice of changes to Sub-Processors through the Platform or direct communication
7.3 Objection Right
The Controller may object to the engagement of a Sub-Processor on reasonable grounds relating to data protection. If the objection cannot be resolved, the Controller may terminate the applicable Services in accordance with the Terms of Service.
8. International Data Transfers
8.1 Transfer Mechanisms
Where Personal Data is transferred to countries that do not provide an adequate level of data protection as determined by Applicable Data Protection Laws, NaijaAssets implements appropriate transfer mechanisms, including:
- Standard Contractual Clauses (EU or UK, as applicable)
- Binding Corporate Rules
- Other legally recognized transfer mechanisms
8.2 Transfers by Controller
The Controller represents that it has provided appropriate notice and obtained necessary consents or authorizations for the transfer of Personal Data to NaijaAssets and its Sub-Processors.
9. Security Measures
9.1 Technical and Organizational Measures
NaijaAssets maintains appropriate technical and organizational security measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include:
- Encryption of data in transit and at rest
- Access controls based on the principle of least privilege
- Regular security assessments and vulnerability testing
- Incident response procedures
- Audit logging and monitoring
- Personnel training and confidentiality obligations
- Physical security controls for data centers
9.2 Updates
NaijaAssets may update its security measures from time to time, provided that such updates do not materially reduce the overall level of security.
10. Data Breach Notification
10.1 Notification
NaijaAssets shall notify the Controller without undue delay upon becoming aware of a Personal Data breach affecting Personal Data processed under this DPA.
10.2 Information
The notification shall include, to the extent known and available:
- A description of the nature of the breach
- The categories and approximate number of Data Subjects and Personal Data records affected
- The likely consequences of the breach
- Measures taken or proposed to address the breach
- Contact information for further information
10.3 Controller Obligations
The Controller is responsible for notifying relevant supervisory authorities and affected Data Subjects as required by Applicable Data Protection Laws.
11. Data Deletion and Return
11.1 Deletion at Termination
Upon termination of the Services or upon the Controller's request, NaijaAssets shall delete or return all Personal Data processed under this DPA, unless retention is required by applicable law.
11.2 Deletion Procedures
Deletion shall be carried out in accordance with NaijaAssets' data deletion practices, which provide for secure deletion of Personal Data from production systems within a reasonable period.
11.3 Certification
Upon request, NaijaAssets shall provide certification that Personal Data has been deleted in accordance with this DPA.
12. Audit Rights
12.1 Documentation
NaijaAssets shall make available to the Controller all information necessary to demonstrate compliance with this DPA, including security documentation, audit reports, and certifications.
12.2 Audits
Where required by Applicable Data Protection Laws, the Controller or an independent auditor appointed by the Controller may conduct audits of NaijaAssets' compliance with this DPA, subject to:
- Reasonable notice and coordination
- Confidentiality obligations
- Restrictions to avoid disruption to NaijaAssets' operations
- The Controller bearing the costs of the audit
12.3 Alternative
To the extent permitted by law, NaijaAssets may satisfy its audit obligations by providing SOC 2 reports, ISO 27001 certifications, or equivalent independent audit reports.
13. Liability
13.1 Liability Cap
The liability of each party under this DPA is subject to the limitations of liability set forth in the Terms of Service.
13.2 Direct Liability
Nothing in this DPA limits the direct liability of NaijaAssets to the Controller for damages arising from NaijaAssets' breach of this DPA.
14. Term and Termination
14.1 Term
This DPA takes effect upon the Controller's use of the Platform in a capacity involving the Processing of Personal Data and continues until termination of the underlying agreement.
14.2 Termination
Termination of the Terms of Service or the Controller's account results in termination of this DPA, subject to the survival of provisions necessary for the continued protection of Personal Data.
15. Governing Law
This DPA is governed by the same law that governs the Terms of Service, subject to any mandatory provisions of Applicable Data Protection Laws that require the application of different law.
16. Changes to This DPA
We may update this DPA to reflect changes in legal requirements, our practices, or the Platform. Where material changes are made, we will provide notice through the Platform or by direct communication. Continued Processing after changes take effect constitutes acceptance of the updated DPA.
17. Contact
Email: legal@legal.naijaassets.com Website: https://naijaassets.com
*This Data Processing Addendum was last updated on 07.20.2026.*
