Data Processing Addendum
Last updated: 28 September 2026
This Data Processing Addendum ("DPA") is incorporated into the Master Terms of Service or the applicable statement of work between Azly Software ("Processor") and the customer identified in the signature block ("Controller"). It applies where Azly processes personal data on the Controller's behalf.
1. Roles and scope
The Controller determines the purposes and means of processing; Azly processes personal data only on the Controller's documented instructions, as set out in the Terms, the applicable SOW, or the configuration of the relevant module. The subject matter is the provision of modules and Services; the duration is the term of the underlying agreement; the nature and purpose are described in the Privacy Policy; and the categories of data subjects include the Controller's customers, contacts, and end users.
2. Compliance with Kenyan and EU law
Azly processes personal data in compliance with the Kenya Data Protection Act 2019 and, where the GDPR applies to the Controller, as a processor within the meaning of Article 28 GDPR. Where the two regimes impose different requirements, Azly complies with the stricter.
3. Confidentiality
Personnel with access to personal data are bound by confidentiality obligations and receive data protection training appropriate to their role. Access is limited to personnel who need it to deliver the services.
4. Security measures
Azly maintains technical and organizational measures including: encryption in transit (TLS) for all data movement; least-privilege access control with credential rotation; secrets held in managed environment stores rather than code; scoped API tokens limited to the module's required permissions; dependency and vulnerability auditing on every release; and documented incident response with breach notification duties as set out in clause 6.
5. Sub-processors
Azly uses the sub-processors listed in the Privacy Policy (hosting, email delivery, and the platform and gateway APIs inherent to the service). Azly remains responsible for their performance, gives the Controller thirty days' advance notice of any new sub-processor, and provides a right to object on reasonable data-protection grounds.
6. Personal data breach
Azly notifies the Controller without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting the Controller's data, with the nature of the breach, the categories and approximate number of records and data subjects affected, likely consequences, and measures taken or proposed. Azly assists the Controller with any statutory notification (including within 72 hours to the ODPC or a GDPR supervisory authority).
7. Data subject rights
Azly promptly informs the Controller of any data subject request it receives directly and does not respond except on the Controller's instructions. Azly provides reasonable assistance, taking into account the nature of the processing, so the Controller can fulfil rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.
8. International transfers
Azly processes data in Kenya and through sub-processors that may transfer data abroad. Any transfer of personal data out of Kenya complies with sections 48 to 53 of the DPA, and any transfer subject to the GDPR is protected by Standard Contractual Clauses adopted by the European Commission or by an adequacy decision.
9. Return and deletion
On termination of the underlying agreement, Azly deletes or returns the Controller's personal data within 90 days, except where Kenyan law requires retention of specific records (for example tax invoices), which are deleted when the statutory retention period ends.
10. Audit
Azly makes available the information necessary to demonstrate compliance and allows for audits, no more than once per year unless triggered by an incident, conducted at the Controller's expense and with reasonable notice, in a manner that does not compromise other customers' confidentiality or security.
11. Execution
This DPA takes effect, without a separate signature, when the underlying Terms or SOW takes effect. To execute a countersigned copy, email hello@azly.io.