Ránṣẹ́
DocsSign inStart free
On this page
  1. Definitions
  2. Roles & scope
  3. Processing instructions
  4. Confidentiality
  5. Security measures
  6. Sub-processors
  7. Data subject rights
  8. Personal data breaches
  9. Assistance & impact assessments
  10. International transfers
  11. Return & deletion
  12. Audits
  13. Liability & term
  14. Annex I — Details of processing
  15. Annex II — Technical & organisational measures
  16. Annex III — Sub-processors
Legal · Data Processing Agreement

Data Processing Agreement

Last updated: 2 July 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Servicebetween you (the “Customer”, acting as controller) and Ránṣẹ́ (acting as processor). It applies whenever Ránṣẹ́ processes personal data on the Customer’s behalf in providing the Service, and reflects the requirements of the Nigeria Data Protection Act 2023 and, where applicable, Article 28 of the GDPR.

01Definitions

“Applicable Data Protection Law” means the Nigeria Data Protection Act 2023 and any other data-protection or privacy law that applies to the processing, including the GDPR where applicable. “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, and “Sub-processor” have the meanings given in Applicable Data Protection Law. “Customer Personal Data” means personal data contained in Customer Content that Ránṣẹ́ processes on the Customer’s behalf.

02Roles & scope

The Customer is the controller and Ránṣẹ́ is the processor of Customer Personal Data. Where the Customer is itself a processor for a third-party controller, Ránṣẹ́ acts as a sub-processor. The subject matter, nature, purpose, and duration of processing, the types of personal data, and the categories of data subjects are described in Annex I.

03Processing instructions

Ránṣẹ́ will process Customer Personal Data only on the Customer’s documented instructions, including as set out in the Terms and as necessary to provide the Service, unless required by law. The Customer’s use of the Service’s features constitutes its instructions. If Ránṣẹ́ believes an instruction violates Applicable Data Protection Law, it will inform the Customer.

04Confidentiality

Ránṣẹ́ ensures that persons authorised to process Customer Personal Data are bound by confidentiality obligations and access it only as needed to provide the Service.

05Security measures

Ránṣẹ́ implements appropriate technical and organisational measures to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, or damage, as described in Annex II. Measures may evolve provided the overall level of protection is not reduced.

06Sub-processors

The Customer provides general authorisation for Ránṣẹ́ to engage the sub-processors listed in Annex III. Ránṣẹ́ imposes data-protection obligations on each sub-processor that are substantially the same as those in this DPA, and remains responsible for its sub-processors’ performance.

Ránṣẹ́ will give notice of the addition or replacement of a sub-processor. If the Customer reasonably objects on data-protection grounds, the parties will work in good faith to resolve the concern; if it cannot be resolved, the Customer may terminate the affected part of the Service.

07Data subject rights

Taking into account the nature of the processing, Ránṣẹ́ will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights. Where a request reaches Ránṣẹ́ directly regarding Customer Personal Data, Ránṣẹ́ will direct it to the Customer.

08Personal data breaches

Ránṣẹ́ will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help the Customer meet its own notification obligations under Applicable Data Protection Law.

09Assistance & impact assessments

Taking into account the nature of processing and information available to it, Ránṣẹ́ will provide reasonable assistance to the Customer with data-protection impact assessments and prior consultations with a supervisory authority, where required.

10International transfers

Where providing the Service involves transferring Customer Personal Data across borders, Ránṣẹ́ will ensure such transfers are subject to appropriate safeguards as required by Applicable Data Protection Law.

11Return & deletion

On termination of the Service, or on the Customer’s written request, Ránṣẹ́ will delete or return Customer Personal Data, at the Customer’s choice, and delete existing copies unless retention is required by law. Standard operational backups are cycled out on a rolling basis.

12Audits

Ránṣẹ́ will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable notice, confidentiality, and limitations to protect the security and confidentiality of other customers’ data.

13Liability & term

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms. This DPA takes effect when the Customer accepts the Terms and continues for as long as Ránṣẹ́ processes Customer Personal Data.

14Annex I — Details of processing

Subject matterProvision of the Ránṣẹ́ email API and dashboard.
DurationThe term of the Terms and until deletion of Customer Personal Data.
Nature & purposeTransmission of email and related processing: queuing, sending, delivery-event tracking, suppression management, and template rendering.
Types of personal dataRecipient email addresses; sender details; and any personal data the Customer includes in message subject, body, headers, or template variables.
Categories of data subjectsThe Customer’s recipients, users, customers, and contacts, as determined by the Customer.

15Annex II — Technical & organisational measures

  • Encryption of data in transit (TLS).
  • Secrets such as API keys are stored only as salted hashes, never as plaintext.
  • Role-based access control and tenant isolation between customer workspaces.
  • Signed webhooks (HMAC) so customers can verify event authenticity.
  • Least-privilege API keys (send-only and domain-scoped) available to customers.
  • Automatic suppression of hard bounces and complaints to limit unnecessary processing.
  • Logging and monitoring for security and abuse detection.

16Annex III — Sub-processors

Sub-processorPurpose
PaystackPayment processing for subscriptions and billing.
Cloud hosting & email-delivery infrastructure providerHosting of the platform and transmission of outbound email.

Note. This list identifies the categories and, where customer-facing, the names of sub-processors that process Customer Personal Data. Contact legal@raanse.com for the current, itemised list or to request a countersigned copy of this DPA.

© 2026 Ránṣẹ́. All rights reserved.
HomeTermsPrivacyDPA