This Data Processing Agreement (“DPA”) applies where a business (“Customer,” “Controller”) uses NGPage to process personal data of the Customer's own customers, and forms part of the agreement between the Customer and NGPage Dotcom Limited (“Processor”). It's primarily relevant to businesses with their own NDPR or GDPR compliance obligations who need a formal processor agreement in place.
1. Parties & Definitions
- Controller — the Customer, who determines the purposes and means of processing personal data collected through their NGPage website or listing (e.g. customer enquiries submitted via a contact form).
- Processor — NGPage Dotcom Limited, which processes that data on the Controller's behalf as part of operating the Service.
- Personal Data has the meaning given under the NDPR.
2. Scope & Purpose of Processing
NGPage processes personal data submitted through the Controller's website or listing (such as names, emails, and messages from contact forms) solely to provide the Service — hosting the website, delivering form submissions, and related platform functionality. NGPage does not use this data for its own marketing purposes.
3. Processor Obligations
- Process personal data only on the Controller's documented instructions, as reflected in this DPA and the Terms of Service.
- Ensure personnel with access to personal data are bound by confidentiality obligations.
- Implement appropriate technical and organisational security measures.
- Assist the Controller in responding to data subject requests, to the extent reasonably possible.
- Delete or return personal data at the end of the relationship, except where retention is required by law.
4. Sub-Processors
NGPage may engage sub-processors (e.g. cloud hosting, storage, or email/SMS delivery providers) to support the Service. Each sub-processor is bound by data protection terms no less protective than those in this DPA.
[Attach or link a current sub-processor list here.]
5. Data Subject Rights
Where NGPage receives a request from a data subject relating to data processed on the Controller's behalf, NGPage will forward that request to the Controller and provide reasonable assistance in responding, since the Controller is best placed to fulfil the request.
6. Security Measures
NGPage maintains security measures appropriate to the risk, including encryption in transit, access controls, and regular security reviews. Details of specific measures are available on request.
7. Breach Notification
NGPage will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, providing available details to help the Controller meet its own notification obligations.
8. International Transfers
Where personal data is transferred outside Nigeria (for example, to a cloud hosting provider), NGPage will ensure the transfer is subject to appropriate safeguards consistent with NDPR requirements.
9. Audit Rights
On reasonable request, NGPage will provide information reasonably necessary to demonstrate compliance with this DPA. [Define specifics here — e.g. frequency, notice period, and format of audits, if you intend to offer them.]
10. Term & Termination
This DPA remains in effect for as long as NGPage processes personal data on the Controller's behalf under the underlying agreement, and terminates automatically when that agreement ends.
11. Liability
Liability under this DPA is subject to the limitations set out in the Terms of Service.
12. Governing Law
This DPA is governed by the laws of the Federal Republic of Nigeria.
13. Contact
Businesses needing a signed copy of this DPA can request one at legal@ngpage.com.