Data Processing Agreement
Last updated: 2 July 2026
01Definitions
“Applicable Data Protection Law” means the Nigeria Data Protection Act 2023 and any other data-protection or privacy law that applies to the processing, including the GDPR where applicable. “Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, and “Sub-processor” have the meanings given in Applicable Data Protection Law. “Customer Personal Data” means personal data contained in Customer Content that Ránṣẹ́ processes on the Customer’s behalf.
02Roles & scope
The Customer is the controller and Ránṣẹ́ is the processor of Customer Personal Data. Where the Customer is itself a processor for a third-party controller, Ránṣẹ́ acts as a sub-processor. The subject matter, nature, purpose, and duration of processing, the types of personal data, and the categories of data subjects are described in Annex I.
03Processing instructions
Ránṣẹ́ will process Customer Personal Data only on the Customer’s documented instructions, including as set out in the Terms and as necessary to provide the Service, unless required by law. The Customer’s use of the Service’s features constitutes its instructions. If Ránṣẹ́ believes an instruction violates Applicable Data Protection Law, it will inform the Customer.
04Confidentiality
Ránṣẹ́ ensures that persons authorised to process Customer Personal Data are bound by confidentiality obligations and access it only as needed to provide the Service.
05Security measures
Ránṣẹ́ implements appropriate technical and organisational measures to protect Customer Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, or damage, as described in Annex II. Measures may evolve provided the overall level of protection is not reduced.
06Sub-processors
The Customer provides general authorisation for Ránṣẹ́ to engage the sub-processors listed in Annex III. Ránṣẹ́ imposes data-protection obligations on each sub-processor that are substantially the same as those in this DPA, and remains responsible for its sub-processors’ performance.
Ránṣẹ́ will give notice of the addition or replacement of a sub-processor. If the Customer reasonably objects on data-protection grounds, the parties will work in good faith to resolve the concern; if it cannot be resolved, the Customer may terminate the affected part of the Service.
07Data subject rights
Taking into account the nature of the processing, Ránṣẹ́ will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights. Where a request reaches Ránṣẹ́ directly regarding Customer Personal Data, Ránṣẹ́ will direct it to the Customer.
08Personal data breaches
Ránṣẹ́ will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help the Customer meet its own notification obligations under Applicable Data Protection Law.
09Assistance & impact assessments
Taking into account the nature of processing and information available to it, Ránṣẹ́ will provide reasonable assistance to the Customer with data-protection impact assessments and prior consultations with a supervisory authority, where required.
10International transfers
Where providing the Service involves transferring Customer Personal Data across borders, Ránṣẹ́ will ensure such transfers are subject to appropriate safeguards as required by Applicable Data Protection Law.
11Return & deletion
On termination of the Service, or on the Customer’s written request, Ránṣẹ́ will delete or return Customer Personal Data, at the Customer’s choice, and delete existing copies unless retention is required by law. Standard operational backups are cycled out on a rolling basis.
12Audits
Ránṣẹ́ will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable notice, confidentiality, and limitations to protect the security and confidentiality of other customers’ data.
13Liability & term
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms. This DPA takes effect when the Customer accepts the Terms and continues for as long as Ránṣẹ́ processes Customer Personal Data.
14Annex I — Details of processing
| Subject matter | Provision of the Ránṣẹ́ email API and dashboard. |
|---|---|
| Duration | The term of the Terms and until deletion of Customer Personal Data. |
| Nature & purpose | Transmission of email and related processing: queuing, sending, delivery-event tracking, suppression management, and template rendering. |
| Types of personal data | Recipient email addresses; sender details; and any personal data the Customer includes in message subject, body, headers, or template variables. |
| Categories of data subjects | The Customer’s recipients, users, customers, and contacts, as determined by the Customer. |
15Annex II — Technical & organisational measures
- Encryption of data in transit (TLS).
- Secrets such as API keys are stored only as salted hashes, never as plaintext.
- Role-based access control and tenant isolation between customer workspaces.
- Signed webhooks (HMAC) so customers can verify event authenticity.
- Least-privilege API keys (send-only and domain-scoped) available to customers.
- Automatic suppression of hard bounces and complaints to limit unnecessary processing.
- Logging and monitoring for security and abuse detection.
16Annex III — Sub-processors
| Sub-processor | Purpose |
|---|---|
| Paystack | Payment processing for subscriptions and billing. |
| Cloud hosting & email-delivery infrastructure provider | Hosting of the platform and transmission of outbound email. |
Note. This list identifies the categories and, where customer-facing, the names of sub-processors that process Customer Personal Data. Contact legal@raanse.com for the current, itemised list or to request a countersigned copy of this DPA.