Data Processing Agreement
Last updated: May 27, 2026
1. Parties & Definitions
This Data Processing Agreement ("DPA") forms part of the Terms of Service between:
- Data Controller — the church organisation (Tenant) that determines the purposes and means of processing personal data of its members
- Data Processor — ONYI (operator of Onyi), which processes personal data solely on behalf of and under the documented instructions of the Data Controller
This DPA is governed by the Nigeria Data Protection Regulation (NDPR) 2019 and, where applicable, the EU General Data Protection Regulation (GDPR).
2. Scope of Processing
Onyi processes the following categories of personal data on behalf of the church:
- Identity Data: names, profile photographs, dates of birth
- Contact Data: email addresses, phone numbers
- Location Data: GPS coordinates captured during cell/PCF attendance check-ins
- Financial Data: donation amounts, pledge records, payment gateway reference IDs
- Engagement Data: attendance records, prayer requests, notice board interactions
- Communication Data: push notification tokens, SMS opt-in status
3. Processor Obligations
As Data Processor, ONYI/Onyi agrees to:
- Process personal data only on documented instructions from the Controller (the church) and not for any other purpose
- Ensure all persons authorised to process the data are bound by confidentiality
- Implement appropriate technical and organisational security measures as specified in Section 5
- Not engage sub-processors without prior written authorisation from the Controller, except those listed in Section 6
- Assist the Controller in fulfilling data subject rights requests (access, erasure, portability) within 30 days
- Delete or return all personal data upon termination of the service agreement
- Make available all information necessary to demonstrate compliance with this DPA
4. Controller Obligations
As Data Controller, the church organisation agrees to:
- Ensure a valid legal basis exists for processing each category of member data
- Obtain informed consent from members where required by applicable law
- Ensure accuracy of the data provided to the platform
- Not instruct Onyi to process data in a manner that would violate applicable privacy laws
- Handle member data subject rights requests and escalate as needed to Onyi support
5. Technical & Organisational Security Measures
Onyi implements the following security controls to protect processed data:
- Encryption in Transit: All data transmission uses TLS 1.2+ (HTTPS)
- Password Security: All passwords hashed with bcrypt; plaintext passwords are never stored
- Tenant Isolation: All database queries are scoped by
church_group_id, preventing cross-tenant data access - Session Management: Encrypted, database-backed sessions with configurable lifetime
- Access Controls: Role-based access control (RBAC) with separate authentication guards for admins and users
- Audit Logging: Administrative actions are recorded in an immutable audit log
- Database Backups: Regular automated backups with encryption at rest
- GPS Data Handling: Location coordinates are validated server-side and not stored permanently beyond session verification
6. Authorised Sub-Processors
The following third-party sub-processors are authorised to handle specific data categories:
- Paystack (Lagos, Nigeria) — Payment processing; handles transaction data
- Flutterwave (Lagos, Nigeria) — Payment processing; handles transaction data
- Africa's Talking (Nairobi, Kenya) — SMS gateway; handles phone numbers for delivery
- Hostinger (Lithuania) — Cloud infrastructure hosting; handles all platform data at rest
All sub-processors are contractually required to implement equivalent data protection standards.
7. Personal Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals:
- Onyi will notify the affected Controller within 72 hours of becoming aware of the breach
- Notification will include the nature of the breach, categories of data affected, likely consequences, and measures taken or proposed
- The Controller is responsible for notifying the appropriate supervisory authority (NITDA in Nigeria) and affected data subjects as required
8. International Data Transfers
Where data is processed by sub-processors located outside Nigeria, Onyi ensures that appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or equivalent mechanisms as recognised under the NDPR.
9. Term & Termination
This DPA remains in effect for the duration of the subscription agreement. Upon termination:
- Onyi will cease all processing of the Controller's personal data
- All personal data will be deleted within 30 days unless a data export was requested
- A written confirmation of deletion will be provided upon request
10. Contact for Data Protection Enquiries
For DPA-related enquiries, please contact: support@onyi.name.ng