1. Introduction
When Zodize develops software on behalf of a Client, we may process personal data belonging to the Client's end users as part of delivering that software. In these situations, the Client is the data controller (the entity that determines why and how data is processed), and Zodize acts as the data processor (the entity that processes data on the controller's instructions).
This Data Processing Policy explains how we approach those responsibilities and the obligations that apply in such engagements.
2. Scope
This policy applies when Zodize:
- Has access to, processes, or stores personal data belonging to a Client's end users during development, testing, or deployment.
- Operates or maintains hosted software on behalf of a Client that processes end user personal data.
- Integrates with the Client's existing systems that contain personal data.
This policy does not apply to personal data that Zodize collects about its own clients for its own operational purposes — that is governed by our Privacy Policy.
3. Our Obligations as a Data Processor
When acting as a data processor, Zodize commits to:
- Processing only on Client instructions — We will not process personal data for any purpose other than delivering the agreed services, unless required to do so by applicable law.
- Confidentiality — All Zodize personnel with access to Client data are bound by confidentiality obligations.
- Technical and organisational security measures — We implement appropriate security measures including encryption, access controls, and secure development practices to protect data we handle.
- Sub-processors — We will not engage sub-processors to handle Client personal data without the Client's prior written consent. Where sub-processors are used (e.g., cloud hosting providers), we ensure they are bound by equivalent data protection obligations.
- Data subject rights — We will assist the Client in responding to data subject rights requests as relevant to data processed by Zodize on the Client's behalf.
- Data breach notification — We will notify the Client without undue delay (and in any event within 72 hours where feasible) upon becoming aware of a personal data breach affecting Client data under our processing.
- Deletion or return of data — Upon completion of services or termination of the engagement, we will return or delete Client personal data as instructed, retaining only what is required by law.
- Audit cooperation — We will make available information reasonably necessary to demonstrate compliance with our data processing obligations.
4. Client Obligations as Data Controller
Clients using Zodize's development or hosting services to process their end users' personal data are responsible for:
- Having a lawful basis for processing the personal data of their end users.
- Providing adequate privacy notices to their end users.
- Ensuring the data they provide to Zodize for development or testing purposes complies with applicable data protection laws (e.g., not providing live production personal data for testing without anonymisation).
- Complying with applicable data protection regulations in their jurisdiction.
- Obtaining any necessary regulatory approvals or registrations (e.g., NITDA registration in Nigeria, ICO registration in the UK) independently.
5. Test Data
Zodize strongly advises clients not to use real personal data for development and testing purposes. We recommend using anonymised or synthetic test data. If real personal data must be used during testing for technical reasons, the Client must notify Zodize in advance and ensure appropriate legal justification exists. Zodize will ensure such data is handled securely and deleted promptly upon completion of the relevant testing.
6. Data Processing Agreement
Where required by applicable data protection law (including where the Client is subject to GDPR, NDPA, or equivalent regulations), Zodize can enter into a formal Data Processing Agreement (DPA) with the Client. This DPA will govern the terms of data processing in greater detail. Clients requiring a DPA should contact privacy@zodize.com.
7. International Transfers of Client Data
Where delivering services requires transferring Client personal data outside Nigeria or the EEA, Zodize will ensure that appropriate safeguards are in place, such as Standard Contractual Clauses or other mechanisms recognised under applicable law. We will inform the Client of any proposed international transfers of their data.
8. Security Incident Response
In the event of a suspected security incident involving Client data under Zodize's control or processing, Zodize will:
- Contain and assess the incident immediately.
- Notify the Client without undue delay with details of the incident, data affected, likely impact, and actions taken or proposed.
- Cooperate with the Client in investigating the incident and providing information needed for any regulatory notification.
- Take reasonable steps to prevent recurrence.
Contact Zodize
Data protection and processing enquiries:
Contact Zodize
If you have questions regarding this Data Processing Policy, you may contact Zodize through any of the following channels:
| General Enquiries | hello@zodize.com |
| Legal Matters | legal@zodize.com |
| Support | support@zodize.com |
| Billing | billing@zodize.com |
| Founder & CEO (David) | david@zodize.com |
| +234 816 860 8957 |
You may also reach us through our contact page. We aim to respond to all enquiries within 2 business days.