1. Roles
You ("Customer") are the Data Controller. Asiri is the Data Processor under NDPA 2023 s.2. Where Asiri sets means and purposes for its own operations (security, billing), it is an independent Controller for that processing.
NDPA 2023 s.29-aligned. Customers receive this DPA during the access and procurement workflow.
You ("Customer") are the Data Controller. Asiri is the Data Processor under NDPA 2023 s.2. Where Asiri sets means and purposes for its own operations (security, billing), it is an independent Controller for that processing.
Asiri processes Customer Personal Data to deliver the modules listed in the order form, for the duration of the agreement plus the deletion window in §10.
Customer’s employees, end users, applicants, patients, learners, account holders, and any other natural person whose data Customer chooses to process in Asiri.
Identifiers, contact details, employment data, financial identifiers (BVN/NIN where Customer enables), health data (where applicable), behavioural data, and any other data Customer uploads or generates.
Asiri will: process only on documented Customer instructions; ensure personnel are bound to confidentiality; implement the security measures at /company/trust-security; assist with DSRs, DPIAs, and breach notifications; delete or return data on termination; and make available all information needed to demonstrate compliance.
Customer authorises the sub-processors listed at /policy/sub-processors. Asiri gives 30 days’ notice of any addition; Customer may object on reasonable grounds and, if not resolved, terminate the affected service.
Where transfers leave Nigeria, Asiri relies on adequacy assessments, contractual safeguards, and transfer impact assessments under NDPA s.41. Transfer impact assessments are available on request and remain subject to DPCO or counsel review where required.
Documented encryption, transport security, SSO/SCIM, MFA enforcement, audit logging, tenant-isolation, and recovery target controls are described at /company/trust-security. Restore-test and DR evidence remains review-pending where applicable.
Asiri notifies Customer without undue delay (and in any event within 24 hours) of becoming aware of a personal data breach affecting Customer Data, providing the information Customer needs to meet the NDPC 72-hour clock under s.40.
Customer may, no more than once per 12 months and at its cost, review Asiri’s control posture through then-available assurance artifacts or a mutually agreed independent assessor under NDA, with 30 days’ notice. Enterprise customers may run an annual penetration test against a staging tenant.
On termination, Customer may export all Customer Data via the platform for 30 days. Thereafter, Asiri deletes it within 60 days, except where law requires retention. A deletion certificate is issued on request.
This DPA forms part of the Terms at /policy/terms. In any conflict on data protection, this DPA prevails. Liability remains as set out in the Terms.