This Data Processing Addendum ("DPA") supplements the Terms of Service between Crimson Strande ("Processor") and the Customer ("Controller") where Crimson Strande processes personal data on the Controller's behalf, for example when a corporate customer submits service requests on behalf of its employees or tenants.
1. Subject matter and duration
Processing is limited to what is necessary to deliver the Service, for the duration of the Terms.
2. Nature and purpose
Storing service requests, contact details, attachments, invoices, and communications; sending transactional emails; providing access to authorised users.
3. Categories of data & data subjects
- Contact details of the Controller's staff (name, email, phone).
- Site addresses and location details for service delivery.
- Content the Controller uploads (photos, videos, PDFs).
4. Processor obligations
- Process only on documented instructions from the Controller.
- Impose confidentiality on personnel with access.
- Apply appropriate technical and organisational measures (see the Trust page).
- Assist the Controller with data subject requests and DPIAs where reasonably required.
- Notify the Controller without undue delay after becoming aware of a personal data breach.
- Delete or return personal data at end of processing, subject to statutory retention.
5. Subprocessors
The Controller authorises the subprocessors listed on our Trust page. We will give at least 30 days' notice of new subprocessors so the Controller can object on reasonable grounds.
6. International transfers
Where personal data is transferred outside Nigeria, we rely on Standard Contractual Clauses or equivalent safeguards.
7. Requesting a signed copy
Corporate customers who need an executed copy of this DPA should email privacy@crimsonstrande.com with their entity name, jurisdiction, and signatory.