Data Processing Policy
(hereinafter referred to as the “Processor”, which expression shall where the context admits include permitted successors, subcontractors approved under this Agreement, and authorised personnel).
The Controller and Processor may each be referred to as a “Party” and collectively as the “Parties”.
WHEREAS
• The Controller operates digital entertainment, competition, audience engagement, production, content, technology, payment, registration, verification, and platform services including activities associated with the FURY™ ecosystem.
• The Processor provides services which may involve receiving, accessing, collecting, storing, analysing, transmitting, hosting, verifying, processing, supporting, securing, or otherwise handling Personal Data on behalf of the Controller.
• The Parties wish to define their respective obligations regarding the lawful and secure processing of Personal Data.
• This Agreement supplements and forms part of any underlying services agreement, vendor agreement, procurement agreement, technology agreement, implementation agreement, consulting agreement, statement of work, or commercial engagement.
NOW IT IS AGREED as follows:
• PURPOSE AND APPLICATION
• This Agreement governs the Processor’s processing of Personal Data on behalf of the Controller.
• This Agreement applies wherever Personal Data is collected, stored, transmitted, viewed, analysed, hosted, transferred, accessed, deleted, matched, verified, exported, archived, monitored, or otherwise processed.
• This Agreement applies regardless of whether Personal Data is processed within Nigeria, cross-border, through cloud infrastructure, through subcontractors, through APIs, through production systems, through integrated software, or through manual processes.
• This Agreement shall prevail over conflicting data processing provisions unless expressly agreed otherwise in writing.
• Processing activities governed by this Agreement may include website hosting, platform development, cloud infrastructure, payment processing, identity verification, KYC operations, email delivery, customer support, analytics, marketing systems, security monitoring, content moderation, production operations, audience engagement systems, and competition administration.
• DEFINITIONS
• In this Agreement:
“Applicable Data Protection Laws” means all laws, regulations, directives, regulatory guidance, binding codes, standards, and legal requirements governing privacy, Personal Data, electronic communications, cybersecurity, information governance, and data processing applicable to the Services and Processing activities including, where applicable: • the Nigeria Data Protection Act, 2023 and regulations, directives, implementation frameworks, and guidance issued by the Nigeria Data Protection Commission; • applicable data protection and privacy laws of jurisdictions in which Data Subjects are located; • laws governing international transfers of Personal Data; • applicable sector-specific obligations affecting identity verification, payments, digital services, communications, and platform operations.
References to Applicable Data Protection Laws shall include any amendment, replacement, consolidation, reenactment, subsidiary instrument, or successor legislation.
“Controller” means the Party determining purposes and means of processing.
“Processor” means the Party processing Personal Data on behalf of the Controller.
“Data Subject” means an identified or identifiable natural person.
“Personal Data” means any information relating to an identified or identifiable individual.
“Sensitive Personal Data” means Personal Data requiring heightened protection including identity information, government identifiers, biometric information, financial information, account credentials, verification records, and other protected categories recognised under Applicable Data Protection Laws.
“Processing” includes collection, storage, access, organisation, use, disclosure, transfer, deletion, retrieval, consultation, analysis, alteration, transmission, restriction, or destruction.
“Subprocessor” means any third party engaged by the Processor to carry out processing activities.
“Security Incident” means actual or suspected unauthorised access, loss, destruction, disclosure, alteration, misuse, compromise, interruption, exfiltration, or inability to access Personal Data.
“Services” means activities performed under the underlying commercial engagement.
• PROCESSING DETAILS
• Subject Matter The Processor shall process Personal Data solely to perform the Services.
• Nature of Processing Processing may include hosting, storage, access management, transmission, identity verification, payment support, communications support, analytics processing, reporting, fraud monitoring, customer operations, and technical administration.
• Categories of Data Subjects Data Subjects may include users, contestants, voters, employees, contractors, vendors, investors, partners, website visitors, or support users.
• Categories of Personal Data Processing may involve identity information, contact information, account information, device information, payment records, verification records, transaction information, usage data, communications, technical logs and security information.
• Sensitive Processing Where Sensitive Personal Data is involved, the Processor shall apply enhanced protections appropriate to the nature and sensitivity of the information.
• PROCESSOR OBLIGATIONS
• The Processor shall process Personal Data only on documented instructions from the Controller.
• The Processor shall not determine independent purposes of processing, sell Personal Data, share Personal Data for unrelated commercial purposes, combine datasets for independent profiling, use data to train artificial intelligence systems unless expressly authorized or retain unnecessary copies.
• The Processor shall maintain policies, procedures, governance controls, and technical safeguards proportionate to processing risk.
• The Processor shall immediately notify the Controller where an instruction appears unlawful or materially inconsistent with Applicable Data Protection Laws.
• The Processor shall ensure that personnel accessing Personal Data receive appropriate training, operate under confidentiality obligations, have restricted access, and follow documented procedures.
• CONTROLLER INSTRUCTIONS
• Instructions may be provided through, the master services agreement, written operational instructions, platform documentation, approved workflows, ticketing systems, written correspondence, or authorised operational requests.
• Instructions materially affecting risk, security, retention, transfers, or data subject rights shall be documented.
• The Processor shall not materially change processing activities without written approval.
• CONFIDENTIALITY AND PERSONNEL CONTROLS
• The Processor shall ensure that all personnel authorised to process Personal Data are subject to legally enforceable obligations of confidentiality.
• Access to Personal Data shall be limited strictly to individuals whose access is necessary for performance of the Services.
• The Processor shall maintain internal access governance measures designed to ensure that access rights are granted, reviewed, modified, and withdrawn appropriately.
• The Processor shall implement reasonable onboarding and offboarding procedures for personnel with access to Personal Data.
• The Processor shall remain responsible for acts and omissions of its personnel and authorised representatives relating to processing activities.
• The Processor shall implement measures designed to reduce risks arising from insider threats, unauthorised viewing, credential misuse, and improper disclosure.
• INFORMATION SECURITY REQUIREMENTS
• The Processor shall maintain appropriate administrative, organisational, technical, and physical safeguards designed to protect Personal Data.
• Such safeguards shall take into account the nature of the Services, processing risks, state of available technology, implementation costs, volume and sensitivity of Personal Data, and risk to Data Subjects.
• Security measures shall be designed to support confidentiality, integrity, availability, resilience, recoverability, and accountability.
• Without limiting the Processor’s obligations, security measures should reasonably address identity and access management, credential governance, least privilege access, logging and monitoring, environment segregation, secure transmission controls, vulnerability management, malware protection, backup procedures, secure deletion controls, business continuity, and incident response.
• Encryption should be implemented where reasonably appropriate having regard to the sensitivity of Personal Data and operational context.
The Processor shall maintain documented security policies and review security practices periodically.
• SUBPROCESSORS
• The Processor shall not appoint a Subprocessor without prior written authorisation from the Controller.
• Approval may be specific approval for identified Subprocessors, or general approval subject to advance notice procedures.
• The Processor shall remain fully responsible for all processing activities performed by approved Subprocessors.
• Before engaging a Subprocessor, the Processor shall conduct reasonable diligence appropriate to security posture, privacy controls, technical capability, compliance maturity, and operational reliability.
• The Processor shall ensure that Subprocessors are bound by written obligations providing protection materially equivalent to this Agreement.
• The Processor shall maintain an accurate and current list of approved Subprocessors and provide updates upon reasonable request.
• Engagement of Subprocessors shall not reduce the Processor’s accountability under this Agreement.
• INTERNATIONAL DATA TRANSFERS
• The Processor shall not transfer Personal Data outside approved jurisdictions except in accordance with Applicable Data Protection Laws and documented instructions.
• Where cross-border transfers occur, the Processor shall implement safeguards appropriate to the transfer mechanism and applicable jurisdiction.
• Such safeguards may include contractual transfer mechanisms, adequacy determinations, supplementary technical measures, organisational safeguards, or approved certification frameworks.
• The Processor shall maintain reasonable visibility over locations where Personal Data is stored, hosted, replicated, accessed, or backed up.
• The Processor shall notify the Controller before introducing material transfer changes which may significantly affect privacy or regulatory exposure.
• SECURITY INCIDENT MANAGEMENT
• The Processor shall maintain documented procedures for identifying, managing, investigating, containing, and remediating Security Incidents.
• The Processor shall notify the Controller without undue delay after becoming aware of a Security Incident affecting Personal Data.
• Initial notification shall include available information concerning, nature of the incident, categories of affected data, estimated scope, known or anticipated consequences, and initial remediation measures.
• The Processor shall continue providing updates as additional information becomes available.
• The Processor shall not communicate directly with affected Data Subjects, regulators, media organisations, or third parties regarding incidents unless authorised or legally required.
• The Processor shall preserve relevant evidence and cooperate fully with investigations and remediation activities.
• ASSISTANCE WITH DATA SUBJECT RIGHTS
• Taking into account the nature of processing, the Processor shall assist the Controller in responding to requests relating to access, correction, deletion, restriction, objection, withdrawal of consent, portability, and complaints. • Where a request is received directly by the Processor, the Processor shall promptly notify the Controller unless prohibited by law.
• The Processor shall not independently fulfil requests except where authorised.
• Assistance shall be provided within commercially reasonable timelines.
• ASSISTANCE WITH COMPLIANCE OBLIGATIONS
• The Processor shall provide reasonable cooperation necessary to support the Controller’s compliance obligations.
• Assistance may include support relating to privacy assessments, risk evaluations, regulatory inquiries, security assessments, documentation requests, incident response, or data governance reviews.
• The Processor shall make available information reasonably necessary to demonstrate compliance.
• Without prejudice to broader obligations under Applicable Data Protection Laws, the Parties acknowledge that the Controller operates within Nigeria and may process Personal Data subject to the Nigeria Data Protection Act, 2023 (NDPA). Accordingly:
• the Processor shall implement measures reasonably necessary to support the Controller’s compliance obligations under the NDPA;
• the Processor shall cooperate with reasonable requests connected with compliance reviews, privacy assessments, audit exercises, regulatory engagement, breach response, and lawful inquiries by the Nigeria Data Protection Commission;
• where Processing activities materially affect compliance obligations under Nigerian law, the Processor shall promptly notify the Controller and cooperate in implementing corrective measures.
• PRIVACY IMPACT ASSESSMENTS
• Where required under Applicable Data Protection Laws, the Processor shall provide reasonable information necessary to support privacy impact assessments or similar evaluations.
• Cooperation shall be proportionate to the Services and processing risks.
• Nothing in this clause requires disclosure of unrelated proprietary information.
• RECORDS OF PROCESSING
• The Processor shall maintain records reasonably necessary to demonstrate compliance with this Agreement.
• Such records should reasonably describe processing activities, categories of Personal Data, categories of recipients, retention practices, security measures, and cross-border processing arrangements.
• Records shall be retained for periods reasonably necessary to demonstrate compliance and satisfy legal obligations.
• REGULATORY COOPERATION
• The Processor shall notify the Controller promptly upon becoming aware of: • regulatory requests; • inspection notices; • enforcement inquiries; • governmental access requests; • compliance investigations; • inquiries, audits, notices, investigations, directives, complaints, enforcement actions, or requests issued by the Nigeria Data Protection Commission or any competent privacy regulator, where disclosure is legally permitted.
• The Processor shall cooperate in good faith with lawful regulatory processes affecting Personal Data processed under this Agreement.
• Unless legally prohibited, the Processor shall provide reasonable opportunity for the Controller to participate in responses affecting its data.
• AUDIT AND COMPLIANCE VERIFICATION
• The Controller shall have the right, acting reasonably and upon prior notice, to verify the Processor’s compliance with this Agreement.
• Verification may occur through written compliance questionnaires, security attestations, document reviews, certification evidence, virtual reviews, independent audit reports, and reasonable inspection procedures.
• Physical inspections shall only occur where reasonably necessary having regard to the nature of processing and subject to security and confidentiality safeguards.
• The Processor shall provide reasonable cooperation necessary to demonstrate compliance.
• Audit rights shall not be exercised in a manner intended to access unrelated confidential information, disrupt operations, or expose information relating to other customers.
• Where independent audit reports are available and reasonably sufficient, the Controller may rely upon such reports instead of conducting additional audits.
• RETENTION, RETURN, AND DELETION OF PERSONAL DATA
• The Processor shall not retain Personal Data longer than necessary for the Services or applicable legal obligations.
• Upon completion, expiry, termination, or written request, the Controller may instruct the Processor to return Personal Data, delete Personal Data, destroy stored copies, export data in a structured format.
• The Processor shall complete such actions within a commercially reasonable period unless retention is legally required.
• Where deletion occurs, the Processor shall provide written confirmation upon request.
• Backup copies maintained through routine operational systems may remain subject to restricted access and continuing confidentiality obligations until overwritten or deleted in accordance with standard retention cycles.
• The Processor shall not continue using retained Personal Data for analytics, commercial activities, training systems, benchmarking, product development, or unrelated purposes.
• BUSINESS CONTINUITY AND RESILIENCE
• The Processor shall maintain appropriate business continuity and recovery measures proportionate to the Services.
• Such measures should be reasonably designed to support continuity of processing and minimise disruption.
• The Processor shall maintain procedures addressing service interruption, loss of availability, system failure, disaster recovery, restoration activities, and incident escalation.
• Material disruptions affecting Personal Data shall be communicated promptly to the Controller.
• USE OF AUTOMATED TOOLS, AI, AND ANALYTICS
• The Processor shall not use Personal Data for development, training, testing, tuning, or optimisation of artificial intelligence, machine learning, automated decision systems, behavioural profiling systems, or internal product enhancement activities unless expressly authorised in writing.
• The Processor shall not create derivative datasets from Controller Personal Data except where required to perform the Services.
• Any authorised analytics activities shall remain limited to the documented processing purposes.
• Aggregation or anonymisation activities shall not permit re-identification of individuals.
• The Processor shall maintain reasonable safeguards designed to prevent unintended exposure through automated processing environments.
• LIABILITY
• Each Party shall remain responsible for its own acts, omissions, personnel, and compliance obligations.
• The Processor shall be responsible for losses directly arising from processing outside instructions, security failures attributable to the Processor, unauthorised disclosure, unapproved Subprocessor activity, or material breach of this Agreement.
• The Controller shall remain responsible for lawfulness of collection, lawful instructions, privacy notices, consent mechanisms where applicable, and determination of processing purposes.
• Nothing in this Agreement excludes liability for fraud, wilful misconduct, unlawful processing, intentional misuse of Personal Data, or gross negligence.
• INDEMNITY
• Subject to applicable law, the Processor shall indemnify and hold harmless the Controller from losses directly arising from material breach of this Agreement by the Processor.
• Recoverable losses may include reasonable costs associated with incident management, regulatory response, investigation, remediation, legal advisers, notification obligations, and technical recovery.
• Each Party shall take reasonable steps to mitigate recoverable losses.
• TERM AND TERMINATION
• This Agreement shall become effective on execution.
• This Agreement shall continue for so long as the Processor processes Personal Data on behalf of the Controller.
• Termination of the underlying commercial agreement shall not automatically extinguish obligations relating to Personal Data.
• The Controller may suspend or terminate processing instructions where continued processing would create material legal, regulatory, security, or operational risk.
• Upon termination or expiry of this Agreement, or upon cessation of the Services for any reason, the Processor shall immediately cease all Processing activities except to the extent retention or continued Processing is required under Applicable Laws.
• Subject to the Controller’s written instructions, the Processor shall within thirty (30) days after termination:
• securely return Personal Data to the Controller in a structured, commonly used, and commercially reasonable format;
• securely delete or permanently destroy all copies of Personal Data under its control;
• discontinue all active access, synchronisation, indexing, replication, and operational use of such Personal Data;
• provide written certification confirming completion of return or deletion activities where reasonably requested.
• Where Applicable Laws require retention of Personal Data after termination:
• the Processor may retain only the minimum information legally required;
• retained information shall remain subject to confidentiality and security obligations under this Agreement;
• retained information shall not be used for any independent operational, commercial, analytics, profiling, training, development, or marketing purpose.
• For a reasonable transition period following termination, not exceeding sixty (60) days unless otherwise agreed in writing, the Processor shall provide reasonable cooperation to facilitate orderly migration, continuity of operations, and secure transfer of Personal Data and associated processing activities.
• Termination of this Agreement shall not relieve the Processor of obligations relating to confidentiality, information security, regulatory cooperation, incident notification, deletion requirements, audit support where reasonably required in connection with prior Processing activities, cross-border transfer safeguards, and liability for prior acts or omissions.
• Survival of Rights
• Termination of this Agreement shall be without prejudice to rights, remedies, liabilities, indemnities, investigations, audit rights, or obligations which accrued before the effective date of termination.
• Obligations relating to confidentiality, security, retention, regulatory cooperation, audit, liability, indemnity, deletion obligations and cross-border safeguards, shall survive termination to the extent necessary to give effect to their purpose.
24. NOTICES
• Notices under this Agreement shall be in writing.
• Notices may be delivered personally, by recognised courier, or electronically to the designated addresses of the Parties.
• Notices shall be deemed received on delivery where personally delivered, two business days after courier dispatch or on transmission where sent electronically without failure notification.
• GOVERNING LAW AND DISPUTE RESOLUTION
• This Agreement shall be governed by and construed in accordance with the laws of the Federal Republic of Nigeria.
• Any dispute arising out of or relating to this Agreement shall first be addressed through good faith discussions.
• Where the dispute remains unresolved within fourteen (14) days after written notification, the matter shall be referred to mediation administered through the Lagos Multi Door Courthouse.
• If mediation does not resolve the dispute within thirty (30) days after commencement, either Party may refer the matter to a court of competent jurisdiction in Lagos State, Nigeria.
• Nothing in this clause prevents the Company from seeking urgent protective relief where necessary to preserve rights, protect intellectual property, prevent misuse, maintain operational integrity, prevent fraud, enforce Platform rules, or comply with legal obligations.
• GENERAL PROVISIONS
• This Agreement constitutes the entire understanding between the Parties with respect to the subject matter herein. It supersedes all prior agreements, negotiations, and understandings whether written or oral.
• No amendment to this Agreement shall be valid unless made in writing and signed by both Parties.
• Failure by either Party to enforce any provision shall not constitute a waiver of that provision. Any waiver must be in writing.
• If any provision of this Agreement is held to be invalid or unenforceable, the remaining provisions shall remain in full force and effect. The Parties shall replace such invalid provision with a valid one that reflects the original intent as closely as possible.
• Each Party shall execute all documents and take all steps necessary to give full effect to this Agreement.
• Provisions relating to confidentiality, intellectual property, transfer restrictions, dispute resolution, and any other provisions intended by their nature to survive shall remain in effect notwithstanding termination.
• This Agreement may be executed electronically and in counterparts, each of which shall be deemed an original.
IN WITNESS WHEREOF the Parties have executed this Agreement on the date first above written.
SIGNED, by the within-named “PROCESSOR”
SCHEDULE 1
PROCESSING DETAILS
SCHEDULE 2
SECURITY REQUIREMENTS
To be completed depending on vendor category and risk profile.
SCHEDULE 3
APPROVED SUBPROCESSOR REGISTER
To be updated from time to time.
SCHEDULE 4
INCIDENT CONTACT DETAILS