Between [ROPLE LEGAL ENTITY NAME] ("Processor", "Rople") and the Customer ("Controller"). This DPA forms part of the Terms of Service and applies wherever Rople processes personal data on the Customer's behalf. Primary framework: the Nigeria Data Protection Act 2023. Where the GDPR applies to a Customer, the additional terms in §12 apply.
1. Roles
The Customer is controller of personal data in its workspace and determines the purposes and means of processing. Rople is processor and acts only on the Customer's documented instructions. Use of the platform as configured by the Customer constitutes those instructions.
Rople is an independent controller for account authentication, billing, support and product-analytics data — that processing is governed by the Privacy Policy, not this DPA.
If Rople believes an instruction breaches data protection law, it will inform the Customer without undue delay and may pause that processing.
2. Subject matter and details of processing
| Subject matter | Provision of the Rople platform |
| Duration | The term of the Terms of Service, plus the retention periods in §9 |
| Nature and purpose | Hosting, storing, structuring, displaying, transmitting, backing up and deleting Customer Data; generating AI-assisted drafts and summaries at the Customer's direction |
| Categories of data subject | The Customer's employees, contractors and workspace users; and, where the Customer uses CRM-style modules, the Customer's own clients and leads |
| Categories of personal data | Identity and contact details; employment details — job title, department, manager, seat; performance content — goals, check-ins, feedback, reviews, development and improvement plans; uploaded files; usage and audit records; and any personal data the Customer chooses to enter into custom modules |
| Special category data | Not requested and not permitted without a prior written agreement |
| Frequency | Continuous, for the duration of the term |
3. Rople's obligations
Rople will:
- Process personal data only on the Customer's instructions and for the purposes above.
- Implement the technical and organisational measures in §4.
- Ensure personnel with access are bound by confidentiality and trained.
- Not sell personal data, and not use Customer Data to train third-party AI models.
- Assist the Customer with data subject requests (§6), breach notification (§7), and data protection impact assessments, at the Customer's reasonable request.
- Make available the information needed to demonstrate compliance, and allow audit as set out in §10.
- Delete or return personal data on termination as set out in §9.
4. Security measures
Rople maintains measures appropriate to the risk, including:
- Tenant isolation. Every tenant-scoped table carries an organisation identifier; Postgres row-level security policies prevent one workspace's queries from returning another's rows; module access is gated per workspace by entitlement.
- Encryption. TLS 1.2+ in transit; AES-256 at rest for database and object storage.
- Access control. Role- and seat-based authorisation within a workspace; least privilege for Rople staff; elevated authentication for administrative surfaces.
- Authentication. Managed authentication with bcrypt password hashing; single-use, expiring tokens for owner claim and team invite flows; httpOnly session cookies.
- File storage. Private buckets, no public read, access only via short-lived signed URLs after an authorisation check.
- Auditability. An immutable audit log of significant actions, readable by the Customer for its own workspace.
- Resilience. Managed Postgres with point-in-time recovery and encrypted backups retained [35] days.
- Change management. Version control, peer-reviewed changes, ledgered database migrations, automated tests including cross-tenant isolation tests, and a staging environment.
- Monitoring. Error and performance monitoring, with input text masked in analytics by default.
Current detail, including work in progress, is in SECURITY_OVERVIEW.md. Rople may change specific measures provided the overall level of protection is not reduced.
5. Sub-processors
The Customer gives general authorisation for the sub-processors listed in SUB_PROCESSORS.md. Rople will:
- Impose data protection obligations on each sub-processor no less protective than this DPA, and remain liable for their performance.
- Give at least [30] days' notice before adding or replacing a sub-processor.
- Allow the Customer to object on reasonable data protection grounds within that period. If the objection cannot be resolved, the Customer may terminate the affected service and receive a pro-rata refund of prepaid fees.
6. Data subject requests
Where Rople receives a request directly from a data subject about workspace content, it will not respond substantively but will forward it to the Customer within [3] business days.
Rople will assist the Customer in responding, including by providing export, correction and deletion capability in-product, and will do so within the Customer's statutory deadline (30 days under the NDPA). Standard assistance is included in the fees; disproportionate or repeated manual effort may be charged at [RATE].
7. Personal data breach
Rople will notify the Customer without undue delay and in any event within 48 hours of confirming a personal data breach affecting the Customer's data, using the workspace owner's email address.
The notification will describe the nature of the breach, the categories and approximate number of records and data subjects affected, the likely consequences, the measures taken or proposed, and a contact point. Where full detail is not available, information will be provided in phases without further undue delay.
Rople will assist the Customer with its own notification obligations — to the NDPC within 72 hours where required, and to affected data subjects.
Rople will not notify the Customer's data subjects or the NDPC on the Customer's behalf unless instructed to in writing, or unless Rople is separately required to as controller of its own data.
8. International transfers
Data is hosted in [REGION — e.g. eu-west-1]. Some sub-processors are outside Nigeria. Where personal data is transferred out of Nigeria, Rople relies on an adequacy determination where one exists, and otherwise on contractual safeguards equivalent to the NDPA's transfer requirements. For GDPR-scope Customers, the EU Standard Contractual Clauses are incorporated by reference; Rople is the data importer under Module 2 or 3 as applicable. A copy of the transfer mechanism for any sub-processor is available on request.
9. Return and deletion
During the term, the Customer may export its data at any time in a structured, machine-readable format.
On termination, the Customer may export for [30] days. After that period Rople will delete the workspace and its contents from live systems within [30] days, and from encrypted backups within a further [35] days as backups roll off.
Rople may retain personal data where legally required — for example billing and tax records for 6 years — and will continue to protect it under this DPA for as long as it is held. On request, Rople will certify deletion in writing.
Full detail is in DATA_RETENTION_AND_DELETION.md.
10. Audit
On reasonable written notice, and no more than once per 12 months unless required by a regulator or following a breach, the Customer may request information reasonably necessary to verify compliance with this DPA. Rople will respond with its security documentation and, where that is insufficient, will co-operate with a proportionate audit conducted under confidentiality, during business hours, in a manner that does not disrupt other customers. Audits of shared infrastructure are satisfied by the relevant sub-processor's own reports.
11. Liability
Liability under this DPA is subject to the limitations and exclusions in the Terms of Service.
12. GDPR-specific terms
Where the GDPR applies to the Customer's processing, references in this DPA to the NDPA are read as including Articles 28 and 32–36 GDPR, "NDPC" includes the Customer's lead supervisory authority, and the breach notification timing in §7 supports the Customer's 72-hour Article 33 obligation. The Standard Contractual Clauses referenced in §8 prevail over this DPA to the extent of any conflict.
13. Order of precedence
This DPA prevails over the Terms of Service in respect of the processing of personal data. An executed order form prevails over this DPA where it expressly says so.
Data protection contact: [DPO NAME], [DPO EMAIL] Rople: [ROPLE LEGAL ENTITY NAME], [REGISTERED ADDRESS], RC [NUMBER]