Privacy

Data Processing Agreement

Controller/processor clauses for tenant-directed processing

Certifiedge Internally Approved — Deployment Activation PendingPublic activation is intentionally blocked until verified operator/provider details are configured.

Scope and roles

The agreement applies where a customer acts as controller and Certifiedge acts as processor for documented services. Certifiedge remains controller for its own security, billing, legal compliance and service-integrity processing.

Instructions

Certifiedge processes tenant data on documented instructions inherent in the service and contract, unless law requires otherwise.

Confidentiality and access

Authorized personnel are subject to confidentiality and least-privilege access. Administrative access is logged/governed.

Security

Certifiedge maintains proportionate technical and organizational security controls and documents known limitations rather than claiming independent certification it does not have.

Subprocessors

Subprocessors are recorded in the provider register with purpose, data, transfer context and change governance.

Rights assistance

Certifiedge supports controller obligations for access, correction, restriction, erasure and portability where the controller has verified the request and the product context allows it.

Incidents

Processor-to-controller incident notification follows applicable law and contract. Kenya’s Act provides a processor notification expectation within 48 hours where reasonably practicable for relevant personal-data breaches.

DPIAs and audits

Certifiedge provides reasonable information needed for DPIAs/compliance review and maintains internal assurance evidence without claiming external certification unless obtained.

Return/deletion

At termination, data is returned/deleted/anonymized according to the agreed schedule unless retention is legally or operationally required and documented.

Transfers

Cross-border processor activity requires recorded safeguards/transfer basis appropriate to the context.

Questions or requests

Use the Certifiedge contact, complaints or data-rights route appropriate to the issue. Internal policies do not remove rights or remedies available under applicable law.