📄

Scope and Application

This Data Processing Agreement forms part of the Terms of Service between NkapFin SAS (Processor) and the Client (Controller) and governs the processing of personal data by NkapFin on behalf of the Client in connection with financial infrastructure services.

This DPA applies where NkapFin processes personal data as a data processor on behalf of the Client. Where NkapFin processes data as an independent controller (e.g., for AML/CFT compliance), such processing is governed by our Privacy Policy.

  • Applies to all personal data processed through NkapFin APIs
  • Compliant with GDPR Article 28, NDPR, POPIA, and Kenya DPA
  • Incorporates Standard Contractual Clauses for international transfers
  • Automatically applies to all Clients without separate execution

Processing Instructions

NkapFin shall process personal data only on documented instructions from the Controller, unless required by applicable law. The Client's instructions are defined by the Services selected and configured through the NkapFin dashboard and API.

  • Subject matter: financial infrastructure services as described in Terms
  • Duration: term of service agreement plus retention periods
  • Purpose: payment processing, identity verification, fraud prevention
  • Data subjects: end users, beneficiaries, authorized representatives

Security Measures

NkapFin implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption, pseudonymization, access controls, and regular security testing.

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Pseudonymization and tokenization of sensitive financial data
  • Role-based access controls with multi-factor authentication
  • Regular penetration testing and security audits

Sub-Processors & International Transfers

The Client provides general authorization for NkapFin to engage sub-processors. We maintain a list of current sub-processors updated at least 30 days before any new sub-processor begins processing. International transfers are protected by Standard Contractual Clauses and data residency options.

  • 30-day advance notice of new sub-processor engagement
  • Right to object to new sub-processors within 14 days
  • Data residency options for CEMAC, Nigeria, Kenya, South Africa
  • Breach notification within 48 hours of discovery