This Data Processing Agreement ("DPA") forms part of our Terms of Service
and governs how Advantage Online LTD processes your data in compliance with the Kenya Data
Protection Act, 2019 and GDPR.
1. Definitions
- Data Controller: You (the customer) - determines purposes and means of
processing
- Data Processor: Advantage Online LTD - processes data on your behalf
- Personal Data: Any information relating to an identified or identifiable
natural person
- Processing: Any operation performed on personal data (collection, storage, use,
disclosure, deletion)
2. Scope & Purpose
We process personal data you provide solely to deliver SafariFlow services, including:
- Storing customer and booking information
- Processing payments through third parties
- Sending automated emails and notifications
- Generating reports and analytics
3. Your Obligations as Controller
As the Data Controller, you must:
- Ensure lawful basis for processing personal data
- Obtain necessary consents from your customers
- Comply with data subject rights requests (access, deletion, etc.)
- Provide clear privacy notices to your customers
- Only upload data you're authorized to process
4. Our Obligations as Processor
We commit to:
- Process data only per your documented instructions
- Maintain confidentiality of personal data
- Implement appropriate security measures
- Assist with data subject requests
- Notify you of data breaches within 72 hours
- Delete or return data upon termination
- Maintain records of processing activities
5. Sub-Processors
We engage the following sub-processors:
| Service |
Purpose |
Location |
| Lemon Squeezy |
Payment Processing |
USA (GDPR-compliant) |
| AWS/Cloud Provider |
Hosting & Storage |
Multiple regions |
| Email Service Provider |
Transactional Emails |
EU/USA |
We will notify you of changes to sub-processors. You may object within
30 days.
6. International Data Transfers
When transferring data outside Kenya or the EEA, we ensure:
- Use of Standard Contractual Clauses (SCCs)
- Transfers only to countries with adequacy decisions
- Appropriate safeguards per Kenya DPA and GDPR
7. Security Measures
We implement:
- Encryption in transit (SSL/TLS) and at rest
- Access controls and authentication
- Regular security audits
- Employee confidentiality agreements
- Incident response procedures
8. Data Breach Notification
In case of a personal data breach:
- We will notify you within 72 hours of discovery
- Provide details of the breach and affected data
- Describe mitigation measures taken
- Assist with your regulatory notification obligations
9. Assisting with Data Subject Rights
We will assist you in responding to requests from your customers for:
- Access to their personal data
- Rectification of inaccurate data
- Erasure ("right to be forgotten")
- Data portability
- Restriction of processing
10. Audits & Inspections
You may request:
- Annual security compliance reports
- Audit of our processing activities (with reasonable notice)
- Certifications (ISO 27001, SOC 2 if available)
11. Data Retention & Deletion
- Data is retained while your account is active
- Upon termination, you have 30 days to export data
- After 30 days, all personal data is permanently deleted
- Backups are deleted within 90 days
12. Liability & Indemnification
Each party is liable for compliance with its obligations under data protection laws. We are not
responsible for your instructions that violate applicable laws.
13. Term & Termination
This DPA remains in effect for the duration of our service agreement. Upon termination, we will
delete or return all personal data as instructed.
14. Contact