Plain-English summary
A DPA aligned with Kenya's Data Protection Act, 2019. We act as Data Processor for the personal data you upload; you remain the Data Controller. Sub-processors are disclosed up front, with transfer safeguards in place where needed.
Legal · DPA
Data Processing Agreement
Last reviewed 2026-05-01 · version 1.0
> Launch placeholder — pending legal review. This document is a good-faith placeholder prepared for the 2026 launch of Gwinto Cloud. It has not yet been reviewed by a qualified legal professional and should be validated against the laws of the Republic of Kenya before being relied on.
Parties
Between the Customer ("Data Controller") and Gwinto ("Data Processor"), for processing of personal data described in Annex 1. This DPA is intended to align with Kenya's Data Protection Act, 2019.
1. Subject and duration
The Data Processor processes personal data on behalf of the Data Controller strictly to provide the Gwinto Cloud Service per the underlying [Terms of Service](/legal/terms). This DPA applies for the duration of the Service agreement and survives termination for the period required to delete Customer Data.
2. Nature and purpose of processing
To operate the Service, including storage, backup, security, support, and incident response.
3. Categories of data subjects + data
See Annex 1. Typically: the Customer's staff and authorised users, and the end customers whose data is processed through the apps the Customer runs on the platform.
4. Obligations of the Data Processor
- Process personal data only on documented instructions from the Data
Controller (using the Service is itself such an instruction).
- Ensure persons authorised to process the data are bound by
confidentiality.
- Implement appropriate technical and organisational measures —
detailed in our [Security posture](/security).
- Engage sub-processors only with prior authorisation; current list
at [/legal/subprocessors](/legal/subprocessors). We give 30 days' notice before adding a new sub-processor; you may object in writing.
- Assist the Data Controller in responding to data-subject requests.
- Make available all information necessary to demonstrate compliance.
- Notify the Data Controller of personal data breaches without undue
delay (target: within 24 hours of detection), consistent with the notification duties under the Data Protection Act, 2019.
5. International transfers
Where personal data is transferred outside Kenya, the Data Processor relies on an appropriate transfer safeguard required by the Data Protection Act, 2019 and any guidance issued by the Office of the Data Protection Commissioner (ODPC). The applicable mechanism for each sub-processor is recorded in the [sub-processor list](/legal/subprocessors).
6. Return or deletion of personal data
On termination of the Service agreement, the Data Processor returns or deletes all personal data within 30 days, unless retention is required by applicable Kenyan law (in which case the data remains encrypted and inaccessible until lawful deletion).
7. Audits
The Data Controller may audit the Data Processor's compliance with this DPA on reasonable advance notice, no more than once per twelve-month period unless triggered by a notified incident. Where the Data Processor can satisfy the request with an existing third-party audit report (ISO 27001, SOC 2, etc.) that is preferred.
Annex 1 — processing details
- Subject: provision of the Gwinto Cloud Service
- Duration: term of the Service agreement
- Nature: storage, structured database operations, transfer to
configured sub-processors (payments, e-commerce, email, AI)
- Purpose: operate the Customer's applications on the platform
- Categories of data subjects: the Customer's staff and authorised
users, and the Customer's own end customers
- Categories of personal data: name, email, phone, postal address,
transaction identifiers, IP and device data
A signed copy of this DPA in PDF is available on request from [legal@gwinto.com](mailto:legal@gwinto.com).
Questions about this policy? Email legal@gwinto.com or use the contact form.