01
How reading it is recorded
Before accepting work through Asiri, an authorised representative of the practice must read and accept the published version of these terms. The acceptance record must identify the practice, the person accepting, the document version and the time of acceptance. A draft is not an accepted agreement. Material changes require a new acceptance; earlier acceptance records must be retained. Practice owners are responsible for making these requirements available to everyone working on client engagements.
02
Who it applies to
These requirements apply to DPCO firms, individual DPOs, their authorised representatives and personnel who use Asiri to deliver client services. Each practice remains responsible for its professional decisions, lawful authority and personnel. Before starting an engagement, agree its scope, responsibilities, data categories, purposes, duration and confidentiality requirements with the client. These platform terms do not replace the engagement-specific agreement or any applicable professional obligations.
03
What you record about the people it binds
For administration and accountability, Asiri records account identity, practice membership and permissions, the policy version accepted, acceptance time, and relevant actions recorded by the platform. Practices must keep their authorised personnel and contact details current. Access to these records must be limited to authorised purposes and handled under Asiri’s applicable privacy notice and retention rules. Client information must not be included in a public listing or acceptance record unless specifically required and authorised.
04
What they may do with customer data
Use client personal data only for the agreed engagement and documented instructions, with access limited to authorised personnel who need it. Apply confidentiality, secure access, appropriate storage and secure transfer arrangements. Before involving another provider or moving data to another jurisdiction, establish the required client authorisation and applicable safeguards. Help the client respond to requests, investigate incidents and demonstrate the agreed work. At the end of the engagement, return or delete client data as agreed, documenting any legally required retention and restricting further use.
05
What they must never do
Do not reuse client data for unrelated marketing, sell it, share account credentials, bypass access controls, fabricate evidence or claim an audit, licence, certification or Asiri verification that has not been issued. Identify and disclose actual or potential conflicts before accepting work and whenever circumstances change. In particular, disclose prior implementation or advisory work that may affect an independent assessment of the same work. Record the safeguards and client decision; decline or withdraw where independence cannot be maintained. Do not conceal material findings or allow commercial pressure to change professional conclusions.
06
What to do when something goes wrong
Promptly report suspected unauthorised access, loss, disclosure or misuse to the affected client’s agreed contact and notify Asiri at dpo@asiri.ng when the platform or an Asiri engagement is affected. Do not wait for every fact to be confirmed. Contain the issue where authorised, preserve relevant evidence, record what is known and provide updates as the investigation develops. Cooperate with the client on remedial action and any required notifications; do not make statements on the client’s behalf without authority. Report conflicts, inaccurate listing claims and suspected misuse through the same contact, without including unnecessary personal data.
Need something explained?
Ask us about these documents, your account or the way Asiri handles information.
Contact Asiri →