1. Definitions
Terms such as personal data, data subject, processing, data controller, data processor, sub-processor, sensitive (or special-category) personal data and personal data breach have the meanings given in Kenya's Data Protection Act, 2019 and its Regulations (the "Act"), and, where it applies to the Controller, the EU General Data Protection Regulation ("GDPR").
Controller Personal Data means personal data that OI processes on the Controller's behalf under the Agreement, including survey responses, media and uploaded datasets.
Data Protection Law means the Act and any other data protection law applicable to the processing, including the GDPR where it applies.
2. Structure, scope and precedence
This DPA applies only to OI's processing of Controller Personal Data as a processor. OI's processing of personal data for which OI is itself the controller (for example account, billing, security and support data) is governed by the Privacy Policy, not this DPA.
Schedule 1 sets out the details of the processing. Schedule 2 sets out the technical and organisational security measures. Schedule 3 sets out the approved sub-processors.
For any conflict on a matter concerning the processing of Controller Personal Data, this DPA prevails over the Terms of Service and any Order, unless a negotiated agreement signed by both parties expressly states otherwise.
3. Roles of the parties
The Controller is the data controller and OI is the data processor in respect of Controller Personal Data.
The Controller is responsible for the lawfulness of the personal data it collects and processes through Sabasi, including having a lawful basis, providing data subjects with any required notice, obtaining any required consent, and meeting the additional conditions for sensitive personal data and children's data.
4. Controller instructions and obligations
The Controller instructs OI to process Controller Personal Data only as necessary to provide, secure, maintain and support the Platform in accordance with the Agreement, this DPA, the Controller's documented use of the Platform, and the Controller's other documented instructions, and as required by law.
The Controller warrants that its instructions comply with Data Protection Law and that it has the authority and lawful basis to have OI process the Controller Personal Data.
If OI considers that an instruction infringes Data Protection Law, it will inform the Controller. If OI is required by law to process personal data other than on the Controller's instructions, it will inform the Controller before processing unless the law prohibits it.
5. OI's processing obligations
OI shall:
- process Controller Personal Data only on the Controller's documented instructions, including as to international transfers, unless required otherwise by law;
- not use Controller Personal Data for its own independent purposes, and not sell it;
- ensure that persons authorised to process Controller Personal Data are bound by appropriate confidentiality obligations;
- implement and maintain the security measures in clause 6 and Schedule 2;
- engage sub-processors only in accordance with clause 7;
- assist the Controller as set out in clauses 8, 9 and 10; and
- delete or return Controller Personal Data as set out in clause 12.
6. Security
OI shall implement appropriate technical and organisational measures to protect Controller Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, appropriate to the risk. The measures in place as at the effective date are described in Schedule 2.
OI may update its security measures provided the level of protection is not materially reduced.
OI does not publish detailed security architecture. Further information may be provided to the Controller under confidentiality where reasonably required for the Controller's due diligence or compliance.
7. Sub-processors
The Controller authorises OI to engage the sub-processors listed in Schedule 3, and generally authorises OI to engage further sub-processors to help provide the Platform, subject to this clause.
Where OI engages a sub-processor, it shall impose data-protection obligations on the sub-processor that are substantially equivalent to those in this DPA, and OI remains responsible for the sub-processor's performance of those obligations.
OI shall maintain a current list of sub-processors and shall give the Controller notice of any intended addition or replacement, giving the Controller a reasonable opportunity to object on reasonable data-protection grounds. Where the Controller objects and the parties cannot resolve the matter, the Controller may terminate the affected part of the service.
Sub-processors are distinct from destinations, integrations or third-party services that the Controller or its users independently select, for which the Controller is responsible.
8. Data subject rights
Taking into account the nature of the processing, OI shall assist the Controller by appropriate technical and organisational measures, insofar as reasonably possible, to respond to requests by data subjects to exercise their rights under Data Protection Law.
Where OI receives a request from a data subject relating to Controller Personal Data, it shall not respond directly except on the Controller's instruction or as required by law, and shall forward the request to the Controller without undue delay.
9. Assistance to the Controller
Taking into account the nature of the processing and the information available to OI, OI shall provide reasonable assistance to the Controller with:
- keeping Controller Personal Data secure;
- notifying personal data breaches to the relevant authority and affected data subjects;
- carrying out data protection impact assessments; and
- prior consultation with the relevant supervisory authority where required.
10. Personal data breaches
OI shall notify the Controller without undue delay, and where the Act applies within 48 hours, after becoming aware of a personal data breach affecting Controller Personal Data, so that the Controller can meet its own notification obligations, including the 72-hour obligation to the Office of the Data Protection Commissioner.
The notification shall include the information reasonably available to OI at the time and shall be supplemented as more information becomes available. OI shall not delay an initial notification while investigating.
The Controller is responsible for notifying the relevant supervisory authority and affected data subjects where required, unless the parties agree otherwise or the law provides otherwise. OI's breach handling is governed internally by the Sabasi Data Breach & Incident Response Policy.
11. International transfers
OI shall not transfer Controller Personal Data outside Kenya, or outside the country in which it was collected, except as necessary to provide the Platform and in accordance with the Controller's instructions and Data Protection Law.
Where a transfer occurs, OI shall ensure an appropriate transfer mechanism and safeguards are in place, which may include contractual protections, recognised adequacy mechanisms, transfer assessments or consent where legally required. Sensitive personal data is transferred outside Kenya only where the additional requirements applicable to such transfers under the Act have been satisfied.
Where Data Protection Law requires specified processing to occur within Kenya, or a serving copy to be maintained within Kenya, the parties shall ensure that requirement is met.
12. Deletion and return
On termination of the Agreement, or earlier at the Controller's request, OI shall, at the Controller's choice, return or delete Controller Personal Data.
The Controller may export Controller Personal Data using available functionality for a period of 30 days after termination. Deletion begins after the applicable export or return period and then follows the Sabasi Data Retention & Deletion Policy, including its active-system and backup timelines, so that residual backup copies expire within 90 days.
OI may retain Controller Personal Data to the extent, and for as long as, required by law, in which case it continues to protect it under this DPA and processes it only as required by that law.
13. Records and demonstrating compliance
OI shall maintain records of its processing sufficient to demonstrate compliance with this DPA and shall make available to the Controller information reasonably necessary to demonstrate that compliance.
Where the Controller reasonably requires an audit to verify compliance, the parties shall first rely on any available certifications, reports or summaries. Where these are insufficient, OI shall allow and contribute to an audit, conducted on reasonable prior notice, during business hours, no more than once a year except where required by a supervisory authority or following a breach, subject to confidentiality and to not compromising the security or data of OI or other customers, and at the Controller's cost.
14. Liability
Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Terms of Service or the applicable Order, except to the extent Data Protection Law does not permit those limitations to apply.
Each party is responsible for any administrative fine or regulatory penalty imposed on it to the extent it results from that party's own breach of Data Protection Law.
15. Term and termination
This DPA takes effect on the effective date and continues for as long as OI processes Controller Personal Data under the Agreement. Clauses that by their nature should survive termination, including those on deletion and return, confidentiality and liability, survive.
16. General
This DPA is governed by the laws of Kenya. Disputes are resolved as provided in the Agreement.
Notices under this DPA are given as provided in the Agreement. Where the Controller has designated a data-protection contact, notices concerning this DPA may be sent to that contact.
Except as stated in this DPA, the terms of the Agreement remain in full force.
Schedule 1 — Details of the processing
Subject matter: provision of the Sabasi Platform to the Controller under the Agreement.
Duration: the term of the Agreement and until deletion or return of Controller Personal Data under clause 12.
Nature and purpose: hosting, storage, collection, organisation, structuring, analysis, visualisation, publication (where the Controller chooses), transmission and deletion of Controller Personal Data, as necessary to provide the Platform and as instructed by the Controller.
Types of personal data: as determined by the Controller through its configuration and use of the Platform, which may include names, contact details, identifiers, location, dates, responses to survey questions, media, files and signatures, and any sensitive personal data the Controller chooses to collect (such as health data).
Categories of data subjects: as determined by the Controller, which may include survey respondents, the Controller's staff, members and enumerators, and other individuals whose data the Controller includes.
Special-category / sensitive data: processed only where the Controller collects it and has met the applicable conditions.
Schedule 2 — Technical and organisational measures
As at the effective date, OI maintains measures including, where appropriate:
- role-based and least-privilege access controls, and restricted administrative access;
- secure authentication and session management, with multi-factor authentication for appropriate privileged access;
- encryption of personal data in transit and at rest;
- tenant and account isolation;
- logging, monitoring and auditable administrative access;
- secure backup and recovery controls;
- secure development and change-management practices, and vulnerability management;
- malware and abuse controls, including bot and abuse protection on public endpoints (Cloudflare Turnstile on sign-in, registration, one-time-password resend and survey submission);
- incident detection and response, aligned to the Data Breach & Incident Response Policy; and
- periodic review of security controls.
Detailed architecture and configuration are maintained in restricted internal documentation and are not published.
Schedule 3 — Approved sub-processors
The following sub-processors are approved as at the effective date. A current list is maintained and made available to the Controller, and changes are notified under clause 7.
| Sub-processor | Purpose |
|---|---|
| Cloud hosting and storage provider | Hosting, storage and infrastructure for the Platform |
| Live-chat provider (Tawk.to) | Support chat functionality |
| Email delivery provider | Transactional and notification email |
| Security and network provider (Cloudflare) | Content delivery, security, and bot/abuse protection (Turnstile) |
| AI service provider(s) | Assistive AI features (translation, mapping, assistant) |