Back to home

Legal

Data Processing Addendum

Last updated: July 18, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Customer", the controller) and AfrikSafe HSE-HUB ("we", "us", the processor) for use of the Service, and applies where we process personal data on the Customer's behalf that is subject to applicable data-protection law (including the EU GDPR, UK GDPR, and, where relevant, U.S. state privacy laws). Where this DPA conflicts with the Terms of Service, this DPA controls for personal-data processing.

1. Definitions

Terms such as "controller", "processor", "data subject", "personal data", "processing", and "personal data breach" have the meanings given in Applicable Data Protection Law. "Customer Data" means the data the Customer and its users submit to the Service. "Sub-processor" means a third party engaged by us to process Customer Data. "SCCs" means the European Commission's Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum.

2. Roles & scope

For Customer Data, the Customer is the controller (or a processor acting on behalf of a controller) and we act as processor (or sub-processor). We process Customer Data only to provide and support the Service and as described in Annex 1.

3. Processing instructions

We will process Customer Data only on the Customer's documented instructions, including as set out in the Terms of Service, this DPA, and the Customer's configuration and use of the Service, unless required to do otherwise by law (in which case we will inform the Customer unless legally prohibited). We will promptly inform the Customer if, in our opinion, an instruction infringes Applicable Data Protection Law.

4. Confidentiality

We ensure that personnel authorized to process Customer Data are bound by appropriate confidentiality obligations and process Customer Data only as instructed.

5. Security

We implement appropriate technical and organizational measures to protect Customer Data as required by Article 32 GDPR, as summarized in Annex 2 and on our Security page. The Customer is responsible for its own use and configuration of the Service, including access management for its users.

6. Sub-processors

The Customer provides general authorization for us to engage sub-processors to process Customer Data, subject to this DPA. Our current sub-processors are listed in our Privacy Policy. We impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. We will give the Customer reasonable prior notice of the addition or replacement of a sub-processor; the Customer may object on reasonable data-protection grounds, and the parties will work in good faith to resolve the objection.

7. Data-subject requests

Taking into account the nature of the processing, we will assist the Customer by appropriate technical and organizational measures, insofar as possible, in responding to requests from data subjects to exercise their rights. The Service also provides self-service tools the Customer can use to access, correct, export, and delete Customer Data. If we receive a request directly from a data subject, we will (unless legally prohibited) refer them to the Customer.

8. Personal data breach

We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide information reasonably available to us to help the Customer meet its breach-notification obligations, and take reasonable steps to mitigate and remediate.

9. Impact assessments & consultation

Taking into account the nature of processing and information available to us, we will provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with supervisory authorities.

10. International transfers

Where our processing involves transferring personal data out of the EEA, UK, or Switzerland to a country without an adequacy decision, the parties agree that the SCCs (and the UK IDTA where applicable) are incorporated by reference and apply to such transfers, with the Customer as data exporter and us as data importer, completed by the details in the Annexes.

11. Return & deletion

Upon termination or expiry of the Service, and at the Customer's choice, we will delete or return Customer Data and delete existing copies, unless retention is required by law. Backups are deleted in the ordinary course of backup rotation.

12. Audits

We will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable confidentiality, scheduling, scope, and security constraints. Where available, we may satisfy audit requests by providing third-party reports or documentation.

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service.

14. Term

This DPA takes effect when the Customer begins using the Service and remains in force for as long as we process Customer Data on the Customer's behalf.

Annex 1 — Details of processing

  • Subject matter: provision of the AfrikSafe HSE-HUB Service.
  • Duration:the term of the Customer's subscription plus any retention period.
  • Nature & purpose: hosting, storage, transmission, and processing of Customer Data to operate, secure, and support the Service.
  • Types of personal data: account and profile data (name, work email, role, department); content submitted in reports, actions, comments, and attachments, which may include incident details and, depending on Customer use, sensitive data such as injury/health information; usage and log data.
  • Categories of data subjects:the Customer's personnel and users, and individuals referenced in Customer Data (e.g., persons involved in a reported event).

Annex 2 — Technical & organizational measures

Measures include: encryption in transit and at rest; database-level tenant isolation (Row-Level Security) enforced with a non-superuser application role; role-based access control and least privilege; time-boxed, audited administrative access with no standing cross-tenant access; an append-only audit log; short-lived pre-signed URLs for file access; input validation and output escaping; HTTP security headers; signed-webhook verification; health monitoring and backups; and a CI pipeline running automated security and isolation tests. See our Security page for details.

Contact

To request a signed copy of this DPA or discuss data-protection matters, contact privacy@hse-reporting-platform.com.