Data Processing Agreement (DPA)

Introduction

This Data Processing Agreement (DPA) defines how Data Pavilion Ltd processes personal and organisational data on behalf of clients.

 

It ensures compliance with applicable data protection regulations, including the Nigeria Data Protection Regulation (NDPR) principles.


1. Purpose of Processing

Data is processed strictly for:

  • Data backup and recovery
  • Data storage and management
  • Data restoration and migration
  • Technical support services

2. Roles and Responsibilities

  • The client is the Data Controller
  • Data Pavilion Ltd is the Data Processor

We process data only according to the client’s instructions.


3. Confidentiality

All personnel handling client data are bound by strict confidentiality obligations. Data is never disclosed without authorisation.


4. Security Measures

We implement appropriate safeguards, including:

  • Secure storage systems
  • Access control mechanisms
  • Encryption and monitoring systems
  • Restricted administrative access

5. Sub-Processors and Affiliation

Where necessary, we may involve trusted affiliates, including Space-Era Data Services (SpEDATAS), to support service delivery.

All affiliated processing is governed by strict confidentiality and data protection standards.


6. Data Breach Handling

In the event of a data breach:

  • We will take immediate containment action
  • Conduct internal investigation
  • Notify affected clients where required by law

7. Data Retention

Data is retained only for the duration necessary to complete services or meet legal obligations, after which it is securely deleted.


8. Client Rights

Clients retain full rights over their data, including:

  • Access
  • Correction
  • Deletion requests (where applicable)

9. Compliance

This agreement is designed to align with:

  • Nigeria Data Protection Regulation (NDPR)
  • International best practices in data protection

 

Read our Privacy Policy  |  Terms & Service Conditions  |  About us