Data Processing Agreement

Version 1.0 — September 2026

This Data Processing Agreement (DPA) forms part of the Terms of Service. It governs the processing of personal data where the Nigeria Data Protection Act 2023 (NDPA) applies and DMflux processes personal data on a Customer’s behalf. It reflects DMflux’s actual processing roles: processor for campaign measurement data, and independent controller for security, fraud prevention, and platform-operation data.

1. Parties and agreement

This DPA is between the Customer (the subscriber to the DMflux service, as defined in the Terms of Service) and Qorv LTD (“DMflux”, “we”, “us”). Together the “parties” or individually a “party”.

This DPA supplements the Terms of Service and is incorporated into it by reference. Where this DPA and the Terms conflict regarding the processing of personal data, this DPA prevails.

2. Definitions

  • “NDPA” means the Nigeria Data Protection Act 2023 and its subsidiary instruments, including the General Application and Implementation Directive (GAID) 2025.
  • “Customer Data” means personal data that the Customer collects via its campaigns and that DMflux processes to provide the Service — including click records (pseudonymous hashes, device and browser type, coarse location, timestamps) and campaign configuration.
  • “Service Data” means personal data DMflux processes as an independent controller: fraud and abuse detection records, security logs, and platform-operation records, as described in the Privacy Policy.

3. Roles of the parties

  • For Customer Data, the Customer is the data controller and DMflux is the data processor. The Customer determines the purposes of campaign measurement; DMflux processes Customer Data only on the Customer’s documented instructions.
  • For Service Data, DMflux is an independent data controller and determines the purposes and means of processing in accordance with the Privacy Policy.
  • Each party complies with its own obligations under the NDPA, including registration obligations with the NDPC where applicable.

4. Purpose, location, and scope of processing

  • Purpose: providing campaign analytics, duplicate-click detection, and reporting to the Customer through the DMflux service.
  • Location: Customer Data is hosted in the EU (Ireland) on Supabase, with edge processing on the global Cloudflare and Vercel networks, and support attachments on Backblaze in the EU (Amsterdam). Sub-processors and their locations are listed on the Sub-processors page.
  • Scope: this DPA covers the processing of Customer Data in connection with the Service; it does not limit either party’s independent processing of its own business data.

5. Lawful basis

Each party ensures that the personal data it is responsible for is processed on a lawful basis under the NDPA. The Customer must have a lawful basis (such as consent or legitimate interest) for collecting and directing the processing of the personal data that enters the Service, including notices owed to visitors who click tracking links.

6. Processor obligations

  • Process Customer Data only for the purpose of providing the Service, and only on documented instructions from the Customer (including with regard to transfers), unless required by law.
  • Notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and provide information reasonably required for the Customer’s own regulatory obligations.
  • Ensure persons authorized to process Customer Data are bound by confidentiality.
  • Assist the Customer with data subject requests relating to click records, noting that click records are pseudonymous and can only be deleted in aggregate with a campaign’s history.
  • Make available information reasonably necessary to demonstrate compliance, directly or via the Security Practices page and the SQL assertion suites.
  • Engage sub-processors only under written contracts imposing the same obligations; maintain the public sub-processor list and give notice of material additions.

7. Technical and organisational measures

DMflux maintains the technical and organisational measures described on the Security Practices page, including TLS in transit, encryption at rest, row-level security on the database, staff access controls, and an append-only staff audit log.

These measures are subject to the Security Practices page, which DMflux keeps accurate and updates as the platform evolves.

8. Data protection impact assessment (DPIA)

Where the Customer is required to carry out a DPIA for its use of the Service, DMflux will, on request and to the extent feasible, provide information about the Service reasonably needed to support that assessment, including details of processing operations, the measures described on the Security Practices page, and this DPA.

9. Risks and residual risks

DMflux has assessed the risks to data subjects arising from its processing. Residual risks are limited and managed: click records are pseudonymous hashes rather than raw IP addresses, deduplication records expire within minutes, and access to customer data is restricted to authorised staff under an audited access model.

10. Confidentiality

Each party will keep confidential any personal data and non-public information it receives from the other party under this DPA, and will only disclose it to those who need it to perform the obligations in this DPA or as required by law.

11. Term and deletion

This DPA applies for the term of the Customer’s subscription. On termination, Customer Data is handled per the retention rules in the Privacy Policy, including deletion of account data within 90 days of a deletion request and the handling of campaign click history as described there.

12. International transfers

Customer Data is hosted in the EU (Ireland) with global edge processing as listed on the Sub-processors page. Where personal data is transferred outside Nigeria, the parties rely on adequacy mechanisms, standard contractual clauses, or other lawful transfer grounds under the NDPA.

13. Liability and indemnity

Nothing in this DPA limits or excludes liability that cannot be limited or excluded under the NDPA or other applicable law. Subject to the Terms of Service’s limitation of liability, each party is liable for loss arising from its own breach of this DPA. The Customer indemnifies DMflux against claims arising from the Customer’s instructions or from the Customer’s unlawful collection or use of personal data.

14. Insurance

Each party maintains appropriate insurance cover (including cyber liability or equivalent business insurance) proportionate to the risks arising from its processing activities under this DPA.

15. Force majeure

Neither party is liable for delay or failure to perform obligations under this DPA to the extent caused by events beyond its reasonable control, including natural disasters, war, terrorism, strikes, or failures of third-party infrastructure, provided the affected party takes reasonable steps to mitigate the impact.

16. Governing law and dispute resolution

This DPA is governed by the laws of the Federal Republic of Nigeria. The parties will first attempt to resolve any dispute informally; failing that, disputes are subject to the exclusive jurisdiction of the courts of Nigeria, consistent with the Terms of Service.

17. Changes and acceptance

DMflux may update this DPA to reflect changes in law or the Service, with notice to the Customer. Continued use of the Service after notice constitutes acceptance. This DPA is available at dmflux.app/dpa.