Data Processing Agreement (DPA)
The standard contractual agreement governing the processing of personal data by Nura Mustapha Technologies Limited on behalf of SwiftPOS Merchants under the Nigeria Data Protection Act (NDPA) 2023.
Data Processing Agreement (DPA)
Incorporated into the SwiftPOS Terms of Service — Version 2.0This Data Processing Agreement (“DPA”) supplements the SwiftPOS Terms of Service entered into between Nura Mustapha Technologies Limited (operating “SwiftPOS”) and the business entity or individual registered as a merchant on the platform (“Merchant”). This DPA governs the processing of Personal Data uploaded, entered, or collected through the SwiftPOS Platform in compliance with the Nigeria Data Protection Act 2023 (NDPA) and the Nigeria Data Protection Commission (NDPC) General Application and Implementation Directive 2025 (GAID).
1 Background & Scope
1.1 In providing the SwiftPOS retail point of sale and inventory management software platform, SwiftPOS processes certain Personal Data relating to the Merchant’s retail customers and staff members on behalf of the Merchant.
1.2 This DPA applies to all processing of Personal Data carried out by SwiftPOS in its capacity as a Data Processor on behalf of the Merchant in its capacity as a Data Controller.
1.3 By accepting the SwiftPOS Terms of Service or using the Platform, the Merchant and SwiftPOS agree to be bound by the terms of this DPA.
2 Roles & Statutory Definitions
The terms used in this DPA have the meanings assigned below, aligned with the NDPA 2023:
- “Data Controller”: The Merchant, who determines the purposes and means of the processing of Customer Personal Data and Staff Personal Data stored in their tenant environment.
- “Data Processor”: Nura Mustapha Technologies Limited (“SwiftPOS”), who processes Personal Data on behalf of and strictly upon the documented instructions of the Data Controller.
- “Personal Data”: Any information relating to an identified or identifiable natural person, including end-customer names, telephone numbers, purchase histories, outstanding credit balances, and cashier employee credentials.
- “Data Subject”: The individual natural person to whom the Personal Data relates (including the Merchant’s retail shoppers and employees).
- “NDPA”: The Nigeria Data Protection Act 2023 and any subsidiary legislation, frameworks, or guidelines issued by the Nigeria Data Protection Commission (NDPC).
- “Sub-processor”: Any third party engaged by SwiftPOS to assist in delivering platform infrastructure, payments, AI features, communication, or analytics services.
3 Details of Processing
| Element | Specification |
|---|---|
| Subject Matter | Provision of cloud-based POS, inventory management, multi-branch operations, credit tracking, offline sales synchronization, and business intelligence. |
| Duration of Processing | Duration of the Merchant’s active subscription plus 90 days following cancellation or termination (unless statutory tax retention laws require longer retention of transaction logs). |
| Nature & Purpose | Recording retail sales transactions, managing stock levels, administering cashier permissions and transaction PINs, tracking customer credit receivables, generating operational reports, and executing AI-assisted queries. |
| Categories of Data Subjects | Merchant’s employees (cashiers, store managers, administrators) and Merchant’s retail customers/debtors. |
| Types of Personal Data | Customer names, telephone numbers, transaction receipt logs, debt ledgers, employee usernames, contact details, role permissions, hashed cashier PINs, and IP audit trails. |
4 Processor Obligations
SwiftPOS warrants and agrees that it shall:
- Process on Documented Instructions Only: Process Personal Data solely in accordance with the documented instructions of the Merchant (including instructions embodied in the Terms of Service and this DPA), unless required to do so by applicable Nigerian law;
- Staff Confidentiality: Ensure that all personnel, contractors, and agents authorized to process Personal Data have committed themselves to strict confidentiality;
- Tenant Isolation: Maintain logical multi-tenant isolation at the database level so that no Merchant Data can be accessed, viewed, or modified by any other tenant;
- No Secondary Monetization: Never sell, rent, lease, or commercialize Merchant Personal Data to any third party for advertising or marketing;
- Zero AI Model Training: Ensure that Merchant Data processed through the AI Business Assistant or product scanners is never submitted to public training sets or used to train third-party foundation models.
5 Technical & Organizational Security Measures
SwiftPOS implements state-of-the-art technical and organizational measures to ensure a level of security appropriate to the risk, in compliance with NDPA Section 39:
- Data Encryption in Transit: All HTTP traffic is protected by Transport Layer Security (TLS 1.3 / TLS 1.2) with enforced HSTS headers;
- Data Encryption at Rest: Database volumes, file assets, and automated daily backups are encrypted using AES-256 encryption;
- Credential Security: All user passwords and cashier authorization PINs are salted and hashed with robust algorithms (bcrypt / PBKDF2). No plaintext credentials are ever stored or accessible to SwiftPOS staff;
- Role-Based Access Control (RBAC): Granular permissions restricting cashier, manager, and admin actions, with cashier PIN gates for sales overrides and price modifications;
- Immutable Audit Logging: System event logging recording 24 distinct operational events (login, price edits, voids, discounts, stock adjustments) with timestamps and IP addresses, safeguarded from manual deletion or tampering;
- Offline Sync Integrity: Local cashier caching uses cryptographic UUID client identifiers to ensure transactions cannot be duplicated or corrupted during offline-to-online synchronization;
- Continuous Monitoring & Backups: Automated daily backups with multi-region redundancy, vulnerability monitoring, and anomaly detection.
6 Sub-processors
6.1 The Merchant grants general written authorization to SwiftPOS to engage the Sub-processors listed in Annexure A of this DPA to support platform infrastructure, payment processing, email/SMS notifications, and AI features.
6.2 SwiftPOS shall impose data protection terms on each Sub-processor that provide at least the same level of protection for Personal Data as those in this DPA.
6.3 SwiftPOS remains fully liable to the Merchant for the performance of each Sub-processor’s obligations.
6.4 SwiftPOS will notify Merchants of any intended appointment of new Sub-processors or replacements via in-app notices or email at least 14 days in advance.
7 Data Subject Rights Assistance
7.1 As the Data Controller, the Merchant is responsible for receiving and responding to requests from Data Subjects exercising their rights under the NDPA (including rights of access, rectification, erasure, restriction, and portability).
7.2 SwiftPOS provides self-service features in the Merchant Dashboard, including the SwiftPOS Export Center (providing full CSV export of customer lists, sales records, and ledger balances) and customer profile editing tools, enabling the Merchant to fulfill Data Subject requests directly.
7.3 If SwiftPOS receives a request directly from a Data Subject concerning data processed on behalf of a Merchant, SwiftPOS shall promptly notify the Merchant and advise the Data Subject to submit their request directly to the Merchant.
8 Personal Data Breach Notification
8.1 In the event of a confirmed Personal Data Breach affecting Merchant Personal Data, SwiftPOS shall notify the affected Merchant without undue delay, and in any event within 72 hours of becoming aware of the breach, in alignment with NDPA Section 40.
8.2 The notification shall describe:
- The nature of the personal data breach including categories and approximate number of Data Subjects and records concerned;
- The name and contact details of the Data Protection Officer or compliance lead;
- The likely consequences of the breach;
- Measures taken or proposed to address the breach and mitigate its potential adverse effects.
8.3 SwiftPOS shall cooperate with the Merchant to provide necessary documentation to support the Merchant’s reporting obligations to the NDPC and affected Data Subjects.
9 Deletion & Return of Data
9.1 Upon termination or expiry of the Merchant’s subscription, the Merchant may download a full export of their data via the Platform within 30 days.
9.2 After 90 days following account termination, SwiftPOS shall permanently delete or anonymize all Merchant Personal Data from active production databases, unless Nigerian statutory regulations (such as FIRS tax auditing requirements requiring 7-year transaction record retention) mandate continued archival storage.
10 Audits & Compliance Verification
10.1 SwiftPOS shall make available to the Merchant all information reasonably necessary to demonstrate compliance with the obligations laid down in this DPA and the NDPA 2023.
10.2 SwiftPOS conducts regular internal compliance assessments and collaborates with licensed Data Protection Compliance Organizations (DPCOs) for statutory compliance filings with the NDPC.
11 International & Cross-Border Transfers
Where the delivery of services involves the transfer of Personal Data outside the Federal Republic of Nigeria (such as hosting infrastructure or cloud LLM API routing), SwiftPOS ensures that such transfers comply with Part VIII of the NDPA 2023, utilizing standard contractual clauses, adequacy mechanisms, and enterprise service provider agreements.
12 Governing Law & Jurisdiction
This DPA is governed by and construed in accordance with the laws of the Federal Republic of Nigeria. The parties submit to the exclusive jurisdiction of Nigerian courts and the regulatory authority of the Nigeria Data Protection Commission (NDPC).
13 Annexure A: Approved Sub-processors
| Sub-processor | Service Type | Location | Data Handled |
|---|---|---|---|
| Cloud Hosting & Storage | Cloud Infrastructure & DB Hosting | Nigeria / Global Cloud | Encrypted database volumes & backups |
| Monnify (Moniepoint MFB) | Payment Gateway & Billing | Nigeria | Merchant subscription billing references |
| Transactional Email Provider | Automated Reports & Alerts | Global Cloud | Email addresses & operational digests |
| SMS Gateway | Customer SMS Notifications | Nigeria | Phone numbers & credit alert messages |
| Cloud AI API Providers (Gemini / OpenAI) | Conversational AI & Product Scanner | Global Cloud (Encrypted API) | Ephemeral prompt data & SKU recognition (no training) |
| Google Analytics (GA4) | Marketing Website Telemetry | Global Cloud | Anonymized website telemetry (swiftpos.ng only) |