ggwintocloud
HomeFeaturesPricingAboutContact
Sign inBook a demo
Back to gwinto.com

Plain-English summary

A DPA aligned with Kenya's Data Protection Act, 2019. We act as Data Processor for the personal data you upload; you remain the Data Controller. Sub-processors are disclosed up front, with transfer safeguards in place where needed.

Legal · DPA

Data Processing Agreement

Last reviewed 2026-05-01 · version 1.0

> Launch placeholder — pending legal review. This document is a good-faith placeholder prepared for the 2026 launch of Gwinto Cloud. It has not yet been reviewed by a qualified legal professional and should be validated against the laws of the Republic of Kenya before being relied on.

Parties

Between the Customer ("Data Controller") and Gwinto ("Data Processor"), for processing of personal data described in Annex 1. This DPA is intended to align with Kenya's Data Protection Act, 2019.

1. Subject and duration

The Data Processor processes personal data on behalf of the Data Controller strictly to provide the Gwinto Cloud Service per the underlying [Terms of Service](/legal/terms). This DPA applies for the duration of the Service agreement and survives termination for the period required to delete Customer Data.

2. Nature and purpose of processing

To operate the Service, including storage, backup, security, support, and incident response.

3. Categories of data subjects + data

See Annex 1. Typically: the Customer's staff and authorised users, and the end customers whose data is processed through the apps the Customer runs on the platform.

4. Obligations of the Data Processor

  • Process personal data only on documented instructions from the Data

Controller (using the Service is itself such an instruction).

  • Ensure persons authorised to process the data are bound by

confidentiality.

  • Implement appropriate technical and organisational measures —

detailed in our [Security posture](/security).

  • Engage sub-processors only with prior authorisation; current list

at [/legal/subprocessors](/legal/subprocessors). We give 30 days' notice before adding a new sub-processor; you may object in writing.

  • Assist the Data Controller in responding to data-subject requests.
  • Make available all information necessary to demonstrate compliance.
  • Notify the Data Controller of personal data breaches without undue

delay (target: within 24 hours of detection), consistent with the notification duties under the Data Protection Act, 2019.

5. International transfers

Where personal data is transferred outside Kenya, the Data Processor relies on an appropriate transfer safeguard required by the Data Protection Act, 2019 and any guidance issued by the Office of the Data Protection Commissioner (ODPC). The applicable mechanism for each sub-processor is recorded in the [sub-processor list](/legal/subprocessors).

6. Return or deletion of personal data

On termination of the Service agreement, the Data Processor returns or deletes all personal data within 30 days, unless retention is required by applicable Kenyan law (in which case the data remains encrypted and inaccessible until lawful deletion).

7. Audits

The Data Controller may audit the Data Processor's compliance with this DPA on reasonable advance notice, no more than once per twelve-month period unless triggered by a notified incident. Where the Data Processor can satisfy the request with an existing third-party audit report (ISO 27001, SOC 2, etc.) that is preferred.

Annex 1 — processing details

  • Subject: provision of the Gwinto Cloud Service
  • Duration: term of the Service agreement
  • Nature: storage, structured database operations, transfer to

configured sub-processors (payments, e-commerce, email, AI)

  • Purpose: operate the Customer's applications on the platform
  • Categories of data subjects: the Customer's staff and authorised

users, and the Customer's own end customers

  • Categories of personal data: name, email, phone, postal address,

transaction identifiers, IP and device data

A signed copy of this DPA in PDF is available on request from [legal@gwinto.com](mailto:legal@gwinto.com).

Related

  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Acceptable Use Policy
  • Service Level Agreement
  • Subprocessors
  • Company details
  • Refund + cancellation policy
  • Accessibility statement

Questions about this policy? Email legal@gwinto.com or use the contact form.

g

gwinto

cloud for african business

A managed cloud platform for African businesses and entrepreneurs — payments, e-commerce, household management, email, AI, and custom apps, billed in KES.

We send a short monthly update — product news only. Unsubscribe anytime. Privacy Policy.

Product

  • Features
  • Pricing
  • Security
  • Roadmap
  • Changelog

Products

  • Gwinto Household System
  • Reava Pay · Payments
  • E-commerce
  • Custom Scripts
  • AI as a Service
  • Email Service
  • Hosting & Domains

Company

  • About
  • Contact
  • Partners
  • Support

Legal

  • Terms of Service
  • Privacy Policy
  • DPA
  • Cookie policy
  • Imprint· Impressum

© 2026 Gwinto · All rights reserved

in𝕏ghgwinto.com
Skip to content