Last Updated: May 12, 2026
Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Vayva Technologies Ltd (BN9089966), with its registered office at 19 Princess Bola Kazem, Shangisha, Lagos, Nigeria ("Data Processor" or "Vayva"), and the merchant entity or individual using the Vayva Platform ("Data Controller" or "Merchant"). This DPA is entered into in compliance with the Nigeria Data Protection Act (NDPA) 2023 and the Nigeria Data Protection Regulation (NDPR) 2019.
In this DPA: "Personal Data," "Processing," "Data Subject," and "Data Controller" shall have the meanings ascribed to them in the NDPA 2023. "Data Breach" means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data. "Sub-Processor" means any third party engaged by Vayva to process Personal Data on behalf of the Merchant.
This DPA applies to all Personal Data processed by Vayva on behalf of the Merchant in connection with the provision of the Vayva Platform services, including storefront management, payment processing, wallet and DVA operations, order fulfillment, customer management, analytics, and AI-powered features. The purpose of processing is to enable the Merchant to operate their B2B commerce business through the Platform.
The following categories of Personal Data are processed: Customer identity data (names, email addresses, phone numbers, delivery addresses), transaction data (order details, payment amounts, product descriptions), communication data (support tickets, chat logs), and analytics data (browsing behavior, device information). Data Subjects include the Merchant's customers, website visitors, and end users of the Merchant's storefront.
Vayva shall: process Personal Data only on the documented instructions of the Merchant, except as required by Nigerian law; ensure that all personnel authorized to process Personal Data are bound by confidentiality obligations; implement and maintain appropriate technical and organizational security measures including AES-256 encryption at rest, TLS 1.3 in transit, role-based access control (RBAC), and multi-factor authentication (MFA); assist the Merchant in responding to Data Subject requests within the 30-day period mandated by the NDPR 2019; notify the Merchant without undue delay (and in any event within 24 hours) upon becoming aware of any Data Breach; assist the Merchant with Data Protection Impact Assessments (DPIAs) where required; and delete or return all Personal Data upon termination of services within 90 days, unless retention is required by law.
This Section 5 applies specifically to storefront end-customer data — that is, personal data collected from the end-customers of the Merchant's storefront (including during checkout, account creation, and any other interaction with the Merchant's store) — where the Merchant is the data controller and Vayva is the data processor. The Merchant shall: determine the purposes and means of processing Personal Data through the Platform; ensure that Personal Data collected is accurate, complete, and up to date; obtain all necessary consents from Data Subjects before their data is submitted to the Platform; provide a privacy notice to Data Subjects that discloses Vayva's role as Data Processor; comply with all applicable data protection laws, including all obligations imposed on data controllers under the NDPA 2023; and instruct Vayva only through the Platform's documented functionality. For the avoidance of doubt, this DPA (and the Merchant's role as Data Controller hereunder) does not apply to personal data collected by Vayva directly from merchants for account registration, KYC, billing, and platform administration purposes — in respect of such data, Vayva is the data controller as set out in the Privacy Policy.
The Merchant provides general written authorization for Vayva to engage the Sub-Processors listed in our Sub-Processor List (available at https://vayva.ng/legal/sub-processors). Vayva shall ensure that each Sub-Processor is bound by written agreements imposing data protection obligations no less protective than this DPA. Vayva shall notify the Merchant of any changes to the Sub-Processor list with at least 30 days' advance notice.
Upon discovering a confirmed Data Breach, Vayva shall: notify the Merchant within 24 hours; provide a detailed description of the breach including the nature, categories, and approximate number of Data Subjects affected; take immediate remedial action to contain and mitigate the breach; cooperate with the Merchant in fulfilling NDPC breach notification requirements within 72 hours; and provide a final incident report within 30 days.
Vayva shall not transfer Personal Data outside the Federal Republic of Nigeria without the Merchant's prior written consent and unless adequate safeguards are in place as required by the NDPA 2023, including NDPC-approved Standard Contractual Clauses or an adequacy decision.
The Merchant may audit Vayva's compliance with this DPA once per calendar year, upon 30 days' written notice, during normal business hours, and at the Merchant's expense. Vayva shall cooperate reasonably and provide all necessary information and access.
Each party's liability arising from breach of this DPA shall be subject to the limitation of liability provisions in the Terms of Service, except that nothing in this DPA shall limit liability for data breaches caused by a party's gross negligence or willful misconduct. The Merchant acknowledges and agrees that: (a) Vayva shall not be liable for data breaches caused by the Merchant's failure to implement appropriate security measures; (b) Vayva shall not be liable for data processing instructions provided by the Merchant that violate applicable law; (c) Vayva's liability for data breaches caused by Sub-Processors shall be limited to Vayva's failure to exercise reasonable care in selecting and supervising such Sub-Processors; and (d) Vayva shall not be liable for any indirect, incidental, or consequential damages arising from data processing activities.
The Merchant shall indemnify, defend, and hold harmless Vayva from and against any claims, damages, or liabilities arising from: (a) the Merchant's failure to comply with data protection laws as data controller; (b) the Merchant's failure to obtain proper consents from data subjects; (c) the Merchant's processing of personal data for purposes not authorized by this DPA; (d) the Merchant's failure to respond to data subject requests within required timelines; or (e) the Merchant's negligence or willful misconduct.
Data Protection Officer: privacy@vayva.ng | Legal: legal@vayva.ng | Phone: +234 913 700 0140.