Legal

Data Processing Agreement

Last updated: 3 June 2026

1. Parties

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the subscribing school ("Controller") and NalieTech (Pvt) Ltd ("Processor"). Where the Controller's instructions conflict with the Terms, this DPA prevails for personal-data matters.

2. Subject matter and duration

The Processor processes personal data on behalf of the Controller solely to provide the NalieTech Schools platform, for the duration of the subscription and any post-termination export window.

3. Nature and purpose of processing

  • Hosting, storing and securing learner, staff, parent, alumni and supplier records.
  • Delivering communications (WhatsApp, SMS, email) on the Controller's instruction.
  • Generating AI-assisted insights, drafts and recommendations the Controller's authorised users explicitly invoke.
  • Producing statutory exports for MoPSE, ZIMSEC and ZIMRA.
  • Audit logging, security monitoring and backup.

4. Categories of data subjects

Learners (including minors), parents and guardians, teaching and non-teaching staff, board / SDC members, alumni, suppliers, visitors and applicants.

5. Categories of personal data

Identification, contact, academic, attendance, discipline, fees and financial, health (where the school enables it), biometric templates (where the school enables it and parents consent), communications metadata and content, audit-log records.

6. Processor obligations

  • Process personal data only on the Controller's documented instructions, including for cross-border transfers.
  • Ensure personnel processing the data are bound by confidentiality.
  • Implement appropriate technical and organisational measures (see Schedule A below).
  • Engage sub-processors only under written terms equivalent to this DPA, and notify the Controller of changes with reasonable opportunity to object.
  • Assist the Controller with data-subject rights (access, rectification, deletion, restriction, portability, objection).
  • Assist the Controller with data-protection impact assessments and prior consultations with POTRAZ where required.
  • Notify the Controller without undue delay (and in any case within 72 hours) of a personal-data breach, with information sufficient to meet the Controller's notification duties.
  • On termination, return or delete personal data per the Controller's choice, subject to the legal retention exceptions listed in our Privacy Policy.
  • Make available all information necessary to demonstrate compliance and submit to audits on reasonable notice.

7. Sub-processors

Current sub-processor categories: cloud infrastructure, transactional email, SMS gateway, WhatsApp Business API provider, payment processor, AI inference gateway. A current list is available on request.

8. International transfers

Where personal data is transferred outside Zimbabwe, the Processor relies on contractual safeguards equivalent to the standards required by the Cyber & Data Protection Act 2021. The Controller authorises these transfers subject to those safeguards.

9. Liability and indemnity

The Parties' liability arising out of or related to this DPA is subject to the limitations and exclusions in the Terms of Service. Nothing in this DPA limits a Party's liability to a data subject under applicable law.

10. Governing law

This DPA is governed by the laws of Zimbabwe.

Schedule A — Technical and organisational measures (summary)

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Row-level security scoped by school and role at the database layer.
  • Mandatory 2FA for staff with grade-edit, fee-waiver or export rights.
  • Hash-chained, tamper-evident audit logs retained for 7 years.
  • Encrypted nightly backups, point-in-time restore, daily restore drills.
  • Anomaly detection on bulk mark edits, fee waivers and unusual logins.
  • Vulnerability management with responsible-disclosure programme.

11. Contact

Data Protection Officer: tichremias@nalietech.com