Last Updated: 2026-08-22
Vayva Technologies Ltd Sub-Processor List
In accordance with the Nigeria Data Protection Act (NDPA) 2023 and our Data Processing Agreement, this document lists all sub-processors engaged by Vayva Technologies Ltd (BN9089966), 19 Princess Bola Kazem, Shangisha, Lagos, Nigeria, for the processing of personal data in connection with our B2B commerce platform services. Each sub-processor is bound by a written data processing agreement that imposes obligations no less protective than those in our DPA.
Purpose: Payment processing, card tokenization, settlement, and disbursement. Data Processed: Payment card details (tokenized), bank account details, transaction amounts, customer names and emails. Location: Lagos, Nigeria. Safeguards: PCI-DSS Level 1 certified, NDPC registered, CBN-licensed Payment Solutions Service Provider.
Purpose: Transactional and marketing email delivery. Data Processed: Email addresses, email content, delivery status. Location: United States (with EU adequacy safeguards). Safeguards: Standard Contractual Clauses (SCCs), SOC 2 Type II compliant.
Purpose: Content delivery network (CDN), DDoS protection, WAF, and DNS services. Data Processed: IP addresses, HTTP request headers, browser fingerprints. Location: Global (Anycast network). Safeguards: SOC 2 Type II, ISO 27001 certified.
Purpose: Cloud infrastructure hosting, data storage, and compute services. Data Processed: All platform data (encrypted at rest with AES-256). Location: Africa (Cape Town) region with CDN edge locations in Nigeria. Safeguards: ISO 27001, SOC 1/2/3, PCI-DSS, HIPAA compliant.
Purpose: Web analytics, performance monitoring, and crash reporting. Data Processed: IP addresses (anonymized), page views, session data, device identifiers. Location: United States. Safeguards: Standard Contractual Clauses, EU-US Data Privacy Framework.
Purpose: Supplementary cloud computing and AI/ML services. Data Processed: Processing data for AI features (anonymized where possible). Location: Africa regions. Safeguards: ISO 27001, SOC 1/2/3, EU Model Clauses.
Purpose: Push notification delivery and application logging. Data Processed: Device tokens, event logs, error reports. Location: Various. Safeguards: Data processing agreements with all providers.
Purpose: Identity verification services — BVN verification against CBN records, NIN verification against NIMC records, and bank account name resolution. Data Processed: Bank Verification Numbers (BVN), National Identification Numbers (NIN), bank account numbers, account holder names. Location: Lagos, Nigeria. All data processed within Nigerian jurisdiction. Safeguards: CBN-licensed Payment Solutions Service Provider (PSSP), NDPC registered, data never leaves Nigeria.
Vayva will notify merchants at least 30 days before adding or replacing any sub-processor. Merchants may object to new sub-processors within the notice period. The current list is always available at https://vayva.ng/legal/sub-processors.
Sub-processor relationships do not constitute endorsements, partnerships, or joint ventures. Vayva does not assume liability for the acts or omissions of sub-processors beyond Vayva's contractual obligations under the DPA. Each sub-processor operates independently and is responsible for its own data protection practices. Vayva's engagement of a sub-processor does not constitute a representation or warranty regarding that sub-processor's security practices, compliance posture, or operational reliability.
The listing of a sub-processor does not guarantee that the sub-processor's services will be available at all times. Sub-processor service interruptions do not constitute a breach of the DPA or these terms, provided Vayva has made reasonable efforts to maintain alternative processing arrangements.
Vayva reserves the right to change sub-processors at any time in accordance with Section 9. Vayva may engage additional sub-processors for specific processing activities without obtaining individual merchant consent, provided the 30-day notice requirement is met.
Merchants acknowledge that some sub-processors are located outside Nigeria, including in the United States. International data transfers involve inherent risks, including exposure to foreign surveillance laws (e.g., FISA Section 702 in the United States). Vayva has implemented appropriate safeguards (Standard Contractual Clauses, data processing agreements) but cannot guarantee the security of data transferred to jurisdictions with different data protection standards.
Merchants are responsible for reviewing and understanding the sub-processor list before using the Platform. If you have concerns about any sub-processor's data protection practices, please contact privacy@vayva.ng before engaging Vayva's services.
Data Protection Officer: privacy@vayva.ng | Privacy: privacy@vayva.ng | Phone: +234 913 700 0140.