Last updated: May 27, 2026

Data Processing Agreement

Last updated: May 27, 2026

1. Parties & Definitions

This Data Processing Agreement ("DPA") forms part of the Terms of Service between:

  • Data Controller — the church organisation (Tenant) that determines the purposes and means of processing personal data of its members
  • Data Processor — ONYI (operator of Onyi), which processes personal data solely on behalf of and under the documented instructions of the Data Controller

This DPA is governed by the Nigeria Data Protection Regulation (NDPR) 2019 and, where applicable, the EU General Data Protection Regulation (GDPR).

2. Scope of Processing

Onyi processes the following categories of personal data on behalf of the church:

  • Identity Data: names, profile photographs, dates of birth
  • Contact Data: email addresses, phone numbers
  • Location Data: GPS coordinates captured during cell/PCF attendance check-ins
  • Financial Data: donation amounts, pledge records, payment gateway reference IDs
  • Engagement Data: attendance records, prayer requests, notice board interactions
  • Communication Data: push notification tokens, SMS opt-in status

3. Processor Obligations

As Data Processor, ONYI/Onyi agrees to:

  • Process personal data only on documented instructions from the Controller (the church) and not for any other purpose
  • Ensure all persons authorised to process the data are bound by confidentiality
  • Implement appropriate technical and organisational security measures as specified in Section 5
  • Not engage sub-processors without prior written authorisation from the Controller, except those listed in Section 6
  • Assist the Controller in fulfilling data subject rights requests (access, erasure, portability) within 30 days
  • Delete or return all personal data upon termination of the service agreement
  • Make available all information necessary to demonstrate compliance with this DPA

4. Controller Obligations

As Data Controller, the church organisation agrees to:

  • Ensure a valid legal basis exists for processing each category of member data
  • Obtain informed consent from members where required by applicable law
  • Ensure accuracy of the data provided to the platform
  • Not instruct Onyi to process data in a manner that would violate applicable privacy laws
  • Handle member data subject rights requests and escalate as needed to Onyi support

5. Technical & Organisational Security Measures

Onyi implements the following security controls to protect processed data:

  • Encryption in Transit: All data transmission uses TLS 1.2+ (HTTPS)
  • Password Security: All passwords hashed with bcrypt; plaintext passwords are never stored
  • Tenant Isolation: All database queries are scoped by church_group_id, preventing cross-tenant data access
  • Session Management: Encrypted, database-backed sessions with configurable lifetime
  • Access Controls: Role-based access control (RBAC) with separate authentication guards for admins and users
  • Audit Logging: Administrative actions are recorded in an immutable audit log
  • Database Backups: Regular automated backups with encryption at rest
  • GPS Data Handling: Location coordinates are validated server-side and not stored permanently beyond session verification

6. Authorised Sub-Processors

The following third-party sub-processors are authorised to handle specific data categories:

  • Paystack (Lagos, Nigeria) — Payment processing; handles transaction data
  • Flutterwave (Lagos, Nigeria) — Payment processing; handles transaction data
  • Africa's Talking (Nairobi, Kenya) — SMS gateway; handles phone numbers for delivery
  • Hostinger (Lithuania) — Cloud infrastructure hosting; handles all platform data at rest

All sub-processors are contractually required to implement equivalent data protection standards.

7. Personal Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals:

  • Onyi will notify the affected Controller within 72 hours of becoming aware of the breach
  • Notification will include the nature of the breach, categories of data affected, likely consequences, and measures taken or proposed
  • The Controller is responsible for notifying the appropriate supervisory authority (NITDA in Nigeria) and affected data subjects as required

8. International Data Transfers

Where data is processed by sub-processors located outside Nigeria, Onyi ensures that appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or equivalent mechanisms as recognised under the NDPR.

9. Term & Termination

This DPA remains in effect for the duration of the subscription agreement. Upon termination:

  • Onyi will cease all processing of the Controller's personal data
  • All personal data will be deleted within 30 days unless a data export was requested
  • A written confirmation of deletion will be provided upon request

10. Contact for Data Protection Enquiries

For DPA-related enquiries, please contact: support@onyi.name.ng