Data Processing Agreement
Data Processing Agreement
Version 1.0. Effective August 2026.
1. Background
This Data Processing Agreement ("DPA") forms part of, and is subject to, the Merchant Agreement between Technest Limited ("Technest", "we", "us", or "our") and the merchant that accepts it (the "Merchant", "you", or "your"). It sets out how each party handles personal data in connection with the services provided under the Merchant Agreement.
Where this DPA and the Merchant Agreement conflict on a matter of data protection, this DPA prevails. Capitalised terms that are not defined here have the meaning given to them in the Merchant Agreement.
2. Definitions
For the purposes of this DPA:
- "Data Protection Law" means the Nigeria Data Protection Act 2023, the Nigeria Data Protection Regulation 2019, any subsidiary legislation, regulation, or guidance issued by the Nigeria Data Protection Commission, and any other data protection or privacy law that applies to a party in respect of the processing carried out under the Merchant Agreement.
- "Data Controller", "Data Processor", "Data Subject", "Personal Data", "Processing", and "Personal Data Breach" have the meanings given to them, or the closest equivalent meanings, in the Nigeria Data Protection Act 2023.
- "NDPC" means the Nigeria Data Protection Commission or any successor authority.
- "Sub-Processor" means a third party engaged by a party acting as a Data Processor to process Personal Data on its behalf.
- "Shared Personal Data" means the Personal Data that the parties process in connection with the services, described in Annex A.
3. Roles of the parties
The parties acknowledge that, in connection with the services:
- Technest acts as an independent Data Controller in respect of the Personal Data it processes to meet its own legal and regulatory obligations as a licensed International Money Transfer Operator, including know-your-customer, customer-due-diligence, sanctions-screening, transaction-monitoring, record-keeping, and regulatory-reporting obligations. Technest determines the purposes and means of that processing.
- The Merchant acts as a Data Controller in respect of the Personal Data of its own customers and the senders and Beneficiaries whose details it submits to Technest.
- To the extent that one party processes Personal Data solely on the documented instructions of the other and for no independent purpose of its own, that party acts as a Data Processor for the other in respect of that processing, and clauses 6, 7, 10, 11, and 12 apply to it in that capacity.
Each party is responsible for its own compliance with Data Protection Law in respect of the Personal Data it processes.
4. Scope and instructions
Each party will process Shared Personal Data only for the purposes described in Annex A, or as otherwise required by Data Protection Law or by a regulator. Where a party acts as a Data Processor for the other, it will process the relevant Personal Data only on the other party's documented instructions, unless it is required to process it by a law that applies to it, in which case it will, where lawful, inform the other party of that requirement before processing.
If a party considers that an instruction from the other infringes Data Protection Law, it will inform the other party without undue delay.
5. Each party's obligations as a Controller
Each party, when acting as a Data Controller, will:
- ensure it has a lawful basis for the Processing it carries out and for any disclosure of Personal Data to the other party;
- provide the fair-processing information and notices required by Data Protection Law to the Data Subjects whose Personal Data it discloses to the other party, and, where required, obtain any necessary consent;
- ensure that the Personal Data it discloses is accurate and limited to what is necessary for the purposes in Annex A; and
- respond to the exercise of Data Subject rights in respect of the Personal Data for which it is the Controller.
The Merchant confirms that it is entitled to disclose to Technest the Personal Data it submits, and that it has provided the notices and obtained the consents required for Technest to process that Personal Data for the purposes in Annex A.
6. Security
Each party will implement appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, having regard to the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the Processing, as well as the risk to Data Subjects. Technest's measures are summarised in Annex B.
Each party will ensure that the personnel who process Personal Data are subject to a duty of confidentiality and are trained appropriately.
7. Sub-Processors
Where a party acts as a Data Processor for the other, the Merchant gives Technest general authorisation to engage Sub-Processors to process Personal Data, provided that Technest:
- imposes on each Sub-Processor data-protection obligations that are, in substance, no less protective than those in this DPA;
- remains responsible to the Merchant for the acts and omissions of its Sub-Processors; and
- maintains a list of the categories of Sub-Processor it uses, described in Annex C, and makes an up-to-date list available to the Merchant on request.
Technest will give the Merchant reasonable notice of the intended addition or replacement of a category of Sub-Processor, and the Merchant may object on reasonable data-protection grounds. Where an objection cannot be resolved, either party may terminate the affected service.
8. Cross-border transfers
The parties acknowledge that the provision of cross-border remittance services necessarily involves transferring Personal Data to partners and Sub-Processors located outside Nigeria. Each party will make such transfers only where a lawful transfer mechanism under Data Protection Law applies, which may include a transfer to a jurisdiction or recipient that provides an adequate level of protection, a transfer subject to appropriate safeguards, or a transfer that satisfies one of the conditions permitted by Data Protection Law, including that the transfer is necessary for the performance of the contract with, or in the interest of, the Data Subject.
9. Personal Data Breaches
A party that becomes aware of a Personal Data Breach affecting Shared Personal Data will notify the other party without undue delay, and in any event within the time required by Data Protection Law, and will provide the other party with the information reasonably necessary to meet its own notification obligations to the NDPC and to affected Data Subjects. Each party is responsible for making the notifications required of it by Data Protection Law.
Neither party will make a public statement that identifies the other in connection with a Personal Data Breach without the other's prior written consent, unless it is required to do so by law or by a regulator.
10. Assisting each other
Each party will provide the other with reasonable assistance, at the other's cost, to enable the other to:
- respond to requests from Data Subjects to exercise their rights under Data Protection Law;
- carry out data-protection impact assessments and prior consultations with the NDPC where required; and
- respond to enquiries, audits, or investigations by the NDPC or another competent authority.
Where a party receives a Data Subject request that relates to Personal Data for which the other party is the Controller, it will forward the request to the other party without undue delay and will not respond to it directly except to acknowledge receipt or as required by law.
11. Records and audit
Each party will keep records of its Processing of Shared Personal Data as required by Data Protection Law. Where a party acts as a Data Processor for the other, it will make available to the other, on reasonable request and no more than once a year unless a regulator or a Personal Data Breach requires otherwise, the information reasonably necessary to demonstrate its compliance with this DPA. Any audit will be conducted on reasonable notice, during business hours, in a manner that does not disrupt the audited party's operations, and subject to confidentiality.
12. Return and deletion
On termination of the Merchant Agreement, each party will, in respect of the Personal Data it holds as a Data Processor for the other, return or delete that Personal Data at the other party's choice, except to the extent that it is required to retain it by a law that applies to it or for the establishment, exercise, or defence of legal claims. Personal Data that a party holds as a Data Controller is retained and deleted in accordance with that party's own retention obligations under Data Protection Law.
13. Liability
Each party's liability under or in connection with this DPA is subject to the limitations and exclusions in the liability section of the Merchant Agreement. Each party is responsible for, and will indemnify the other against, losses arising from its own breach of Data Protection Law or of this DPA, to the extent provided in the Merchant Agreement.
14. Term
This DPA takes effect when the Merchant Agreement takes effect and continues for as long as either party processes Shared Personal Data in connection with the services. The provisions that by their nature should survive termination continue in force.
15. General
Order of precedence. On a matter of data protection, this DPA prevails over the body of the Merchant Agreement. On all other matters, the Merchant Agreement prevails.
Changes. We may update this DPA from time to time to reflect changes in Data Protection Law, in the services, or in our operations, in the manner set out in the Merchant Agreement for changes to that agreement.
Governing law. This DPA is governed by the laws of the Federal Republic of Nigeria, and the dispute-resolution provisions of the Merchant Agreement apply to it.
Notices. Notices under this DPA are given in the manner set out in the Merchant Agreement. You may contact us at compliance@the-technest.com.
Annex A: Details of the Processing
Subject matter. The provision of cross-border remittance, foreign-exchange, and disbursement services under the Merchant Agreement.
Duration. For the term of the Merchant Agreement and any period thereafter during which Personal Data is retained in accordance with Data Protection Law.
Nature and purpose. Onboarding and verification of the Merchant and its representatives; know-your-customer and customer-due-diligence checks; sanctions screening and transaction monitoring; execution, settlement, and reconciliation of transactions; disbursement of funds to Beneficiaries; fraud prevention and financial-crime controls; regulatory reporting and record-keeping; customer support; and the exercise or defence of legal claims.
Types of Personal Data. Identification and contact details (such as name, date of birth, address, email, and telephone number); identification-document and verification data; Bank Verification Number and Tax Identification Number where applicable; account and payment details of senders and Beneficiaries; transaction data; and, in respect of the Merchant's representatives and beneficial owners, the equivalent identification and verification data.
Categories of Data Subject. The Merchant's representatives, directors, and beneficial owners; the Merchant's customers and the senders of funds; and Beneficiaries of transactions.
Annex B: Technical and organisational security measures
Technest maintains a documented information-security programme that includes, in summary:
- access controls that limit access to Personal Data to personnel who need it for the purposes in Annex A, with individual authentication and role-based permissions;
- encryption of Personal Data in transit and, where appropriate, at rest;
- segregation of environments, network controls, and logging and monitoring of access to systems that process Personal Data;
- secure storage of sensitive fields and credentials, and management of secrets;
- change management, vulnerability management, and regular review of the security programme;
- staff confidentiality obligations and periodic data-protection and security training;
- backup and recovery arrangements; and
- an incident-response process for the identification, investigation, and notification of Personal Data Breaches.
Technest reviews and updates these measures as its services and the risk environment evolve. The measures in force at any time are those that meet the standard in clause 6.
Annex C: Categories of Sub-Processor
Where Technest acts as a Data Processor, it engages Sub-Processors within the following categories:
- banking and payment partners that execute collection, settlement, foreign-exchange, and disbursement;
- identity-verification, know-your-customer, and sanctions- and adverse-media-screening providers;
- cloud-hosting and infrastructure providers;
- communications providers used to send notices and one-time passcodes; and
- fraud-prevention and analytics providers.
An up-to-date list identifying the Sub-Processors within each category is available to the Merchant on request.
Technest Limited
8 Providence Street, Lekki Phase 1, Lagos State, Nigeria
Email: compliance@the-technest.com