Data Processing Addendum (template)
A standard-form addendum for enterprise customers whose legal team requires one before data processing begins. Template pending execution and, where a specific engagement requires it, counsel customisation.
Last updated: 8 June 2026
1. What this is
This is a template Data Processing Addendum ("DPA"), made available so prospective enterprise customers and their legal teams can review our standard data-processing terms ahead of a commercial agreement. It is not, by itself, an executed contract. A DPA becomes binding only when incorporated by reference into, or signed alongside, a separate services agreement between Kerdos Analytics Limited ("Processor") and a customer ("Controller").
To request an editable copy or begin execution, contact privacy@kerdosanalytics.ng.
2. Roles of the parties
Where a customer submits personal data to us for processing in connection with a product or service, the customer acts as the data controller (or, under the CCPA/CPRA, the "business") and Kerdos Analytics acts as the data processor (or "service provider"), except where the parties agree otherwise in writing.
3. Subject matter and duration
The subject matter, duration, nature and purpose of processing, the types of personal data, and the categories of data subjects are as described in the applicable services agreement and its order forms or statements of work. Processing continues for the term of that agreement, unless terminated earlier in accordance with its terms.
4. Processor obligations
- Process personal data only on the controller’s documented instructions, including regarding international transfers, unless required to do otherwise by law.
- Ensure persons authorised to process the data are subject to confidentiality obligations.
- Implement appropriate technical and organisational measures, as described in our Security page.
- Engage sub-processors only under a written contract imposing equivalent data-protection obligations, and make the current list of sub-processor categories available on request.
- Assist the controller in responding to data-subject requests and in meeting its own obligations relating to security, breach notification, and data-protection impact assessments, to the extent reasonably required.
- Notify the controller without undue delay after becoming aware of a personal data breach affecting the controller’s data.
- At the controller’s choice, delete or return all personal data at the end of the engagement, except where retention is required by law.
- Make available information reasonably necessary to demonstrate compliance with this addendum, and allow for audits by the controller or an appointed auditor on reasonable notice.
5. International transfers
Where personal data is transferred outside the country in which it was collected, we apply appropriate safeguards required by the NDPA and, where relevant, the GDPR — such as transfers to jurisdictions with adequate protection or contractual protections including standard contractual clauses, incorporated by reference where applicable law requires them.
6. Liability and precedence
Liability under this addendum is governed by the limitation-of-liability terms of the underlying services agreement. In the event of a conflict between this addendum and the services agreement regarding the processing of personal data, this addendum controls.
7. Contact
Questions about this template, or to begin execution for a specific engagement: privacy@kerdosanalytics.ng.