Scope and roles
The agreement applies where a customer acts as controller and Certifiedge acts as processor for documented services. Certifiedge remains controller for its own security, billing, legal compliance and service-integrity processing.
Instructions
Certifiedge processes tenant data on documented instructions inherent in the service and contract, unless law requires otherwise.
Confidentiality and access
Authorized personnel are subject to confidentiality and least-privilege access. Administrative access is logged/governed.
Security
Certifiedge maintains proportionate technical and organizational security controls and documents known limitations rather than claiming independent certification it does not have.
Subprocessors
Subprocessors are recorded in the provider register with purpose, data, transfer context and change governance.
Rights assistance
Certifiedge supports controller obligations for access, correction, restriction, erasure and portability where the controller has verified the request and the product context allows it.
Incidents
Processor-to-controller incident notification follows applicable law and contract. Kenya’s Act provides a processor notification expectation within 48 hours where reasonably practicable for relevant personal-data breaches.
DPIAs and audits
Certifiedge provides reasonable information needed for DPIAs/compliance review and maintains internal assurance evidence without claiming external certification unless obtained.
Return/deletion
At termination, data is returned/deleted/anonymized according to the agreed schedule unless retention is legally or operationally required and documented.
Transfers
Cross-border processor activity requires recorded safeguards/transfer basis appropriate to the context.
Questions or requests
Use the Certifiedge contact, complaints or data-rights route appropriate to the issue. Internal policies do not remove rights or remedies available under applicable law.