Legal

Data Processing Agreement

Version 1.0Published 20 Jul 2026

Effective Date: April 21, 2026

1. Introduction This Data Processing Agreement ("DPA") forms part of the Terms of Use between SyncD Group Africa Limited T/A Brandefy Creative Studio ("Processor") and the Client ("Controller"). It outlines the obligations of both parties regarding the processing of Personal Data under the Kenya Data Protection Act, 2019 (KDPA) and the EU General Data Protection Regulation (GDPR).

2. Scope and Roles

  • When Brandefy provides services such as website hosting, digital marketing, or database management that involve the handling of the Client's customer data, the Client acts as the Data Controller and Brandefy acts as the Data Processor.

  • The Processor shall only process Personal Data on behalf of and in accordance with the Controller’s documented instructions.

3. Processing Details

  • Subject Matter: The processing of Personal Data to provide the Services outlined in the Statement of Work.

  • Nature and Purpose: Storage, retrieval, organization, and transmission of data to execute web development, hosting, and marketing services.

  • Types of Personal Data: May include names, contact details, user behavior, and other data collected by the Controller.

4. Processor Obligations

  • Confidentiality: The Processor shall ensure that personnel authorized to process Personal Data have committed themselves to confidentiality.

  • Security: The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.

  • Sub-processors: The Controller authorizes the Processor to engage sub-processors (e.g., AWS, Vercel, Google Cloud). The Processor shall ensure that sub-processors are bound by the same data protection obligations.

5. Data Subject Rights The Processor shall assist the Controller, insofar as this is possible, in responding to requests from Data Subjects exercising their rights under the KDPA and GDPR.

6. Personal Data Breaches In the event of a Personal Data breach, the Processor shall notify the Controller without undue delay (and no later than 48 hours) after becoming aware of the breach, to assist the Controller in meeting its statutory notification obligations (which require notification to the ODPC within 72 hours).

7. Deletion or Return of Data Upon termination of the Services, the Processor shall, at the choice of the Controller, delete or return all Personal Data to the Controller, and delete existing copies unless applicable law requires storage of the Personal Data.