Data Processing Agreement
Your customers' data belongs to your business. This document is our written commitment about how we handle it on your behalf — and what we owe you if anything goes wrong.
Do you need to sign this? No. This DPA applies automatically to every SabiBot account from the moment you start processing customer data through the platform — you do not have to request it or countersign anything. If your own compliance team needs a signed copy on your paper, email hello@sabibot.ng and we will arrange it.
On this page
- Parties and roles
- Scope of processing
- Our obligations
- Your obligations
- Confidentiality
- Security measures
- Sub-processors
- International transfers
- Data subject requests
- Breach notification
- Audit and information rights
- Assistance with impact assessments
- Deletion and return on termination
- Liability
- Changes
- Annex A — processing details
1. Parties and roles
This Data Processing Agreement ("DPA") is between:
- You — the business holding a SabiBot account — acting as the Data Controller; and
- Pioneers ICT (RC 1033498), of Suite 1, No. 42, Gidan Saude, Beside First Bank, Zoo Road, Kano, Kano State, Nigeria — operator of SabiBot, acting as the Data Processor.
It forms part of, and is governed by, our Terms of Service. Where this DPA and the Terms conflict on the handling of personal data, this DPA prevails.
It is made under the Nigeria Data Protection Act 2023 ("NDPA") and, where your customers are in the European Economic Area or United Kingdom, is intended to satisfy the equivalent requirements of the GDPR.
What "controller" and "processor" mean in practice. You decide why and how your customers' data is used — that makes you the controller, and the responsibility sits with you. We only act on your instructions and never use that data for our own purposes — that makes us the processor. The distinction matters because it decides who your customer complains to, and who answers to the regulator.
2. Scope of processing
We process personal data only to provide the SabiBot service to you, as described in Annex A. Specifically, we will not:
- Use your customers' data for our own purposes, including marketing
- Sell, rent or otherwise disclose it, except to the sub-processors listed in section 7
- Combine it with data from other customers or other sources
- Use it to train artificial intelligence models — ours or anyone else's
3. Our obligations
We will:
- Process personal data only on your documented instructions, which include your use of the platform's settings and features, unless the law requires otherwise — in which case we will tell you before processing, unless the law forbids us from doing so.
- Tell you promptly if, in our opinion, an instruction you give us would breach the NDPA or other applicable data protection law.
- Implement and maintain the technical and organisational security measures in section 6.
- Assist you, as far as reasonably possible, with your own obligations under sections 9, 10, 11 and 12.
- Make available the information you reasonably need to demonstrate compliance.
4. Your obligations
As controller, you are responsible for:
- Having a lawful basis for collecting and processing your customers' personal data.
- Giving your customers clear notice that they are talking to an automated assistant, what data you collect, and how it is used — including that a technology provider processes it on your behalf. You may link to our Privacy Policy to support this.
- Obtaining consent where consent is the basis you rely on, particularly for marketing messages.
- Ensuring your instructions to us are lawful.
- Handling requests from your customers about their data, with our help under section 9.
- Not uploading special-category data — health, biometric, genetic, religious, political or sexual-life data — or children's data, unless you have told us in advance and we have agreed in writing that the platform is suitable for it.
A caution worth reading twice. A conversational bot invites people to type freely, and customers sometimes volunteer far more than you asked for — a medical reason for a cancellation, for instance. Configure Sabi not to request sensitive information, and review your conversation logs periodically. We can process what arrives, but you remain the controller of it.
5. Confidentiality
We ensure that anyone authorised to process personal data under this DPA is bound by an appropriate duty of confidentiality, is trained on their obligations, and is granted access strictly on a need-to-know basis. Access is role-based and removed promptly when no longer required.
6. Security measures
We maintain the following technical and organisational measures. These are not aspirations — they are what is implemented today:
| Area | Measure |
|---|---|
| Encryption in transit | All traffic served over HTTPS/TLS; plain HTTP requests are redirected. |
| Credential storage | Passwords stored as PBKDF2-SHA512 hashes with a unique per-user salt and 10,000 iterations. Plaintext passwords are never stored, logged or recoverable. |
| Tenant isolation | Every query is scoped to the account that owns the data. One business cannot read another's conversations, orders or customers. |
| Access control | Authenticated sessions with expiring tokens; role-based permissions with Owner and scoped-Administrator tiers. |
| Payment integrity | Inbound payment webhooks are cryptographically verified, and every payment is independently re-verified against the gateway — including the amount — before an order is marked paid. Unverifiable messages are rejected. |
| Card data | Never collected or stored. Card entry occurs on the gateway's PCI-DSS certified hosted page. |
| Abuse resistance | Rate limiting on authentication, chat and API endpoints. |
| Data minimisation | Analytics store a daily-rotating salted hash of the IP address, never the address itself, making long-term visitor tracking impossible by design. |
| Change control | An automated security and integrity test suite runs after every deployment and verifies that access controls still refuse what they are meant to refuse. |
| Resilience | Operational backups taken around system updates; multi-provider AI failover so a single provider outage does not stop service. |
We review these measures as the platform develops and may improve them, but will not materially reduce the overall level of protection during your subscription.
7. Sub-processors
You give us general authorisation to appoint the sub-processors below. Each is bound by written terms imposing data protection obligations no less protective than those in this DPA, and we remain fully liable to you for their performance.
| Sub-processor | Purpose | Data categories | Location |
|---|---|---|---|
| OpenAI, L.L.C. | AI reply generation; voice-note transcription | Conversation content, bot configuration, voice audio | United States |
| Google LLC | Backup AI provider (automatic failover) | Conversation content, bot configuration | United States |
| Anthropic, PBC | Backup AI provider (automatic failover) | Conversation content, bot configuration | United States |
| Flutterwave | Payment processing and direct settlement to your account | Transaction amount and reference, customer contact details | Nigeria |
| Resend and/or Google Workspace | Transactional email delivery | Recipient address, email content | United States |
| Meta Platforms | WhatsApp Business messaging (where you enable it) | WhatsApp number, message content | United States / Ireland |
| Database Mart (DatabaseMart.com) | Server infrastructure the platform runs on | All data at rest | United States — Kansas City, Missouri |
Changes. We will notify account holders by email at least 30 days before adding or replacing a sub-processor. If you reasonably object on data protection grounds, tell us within 30 days and we will work with you to find an alternative. If none is workable, you may terminate the affected part of the service without penalty and receive a pro-rata refund of prepaid fees.
8. International transfers
As section 7 shows, personal data is transferred outside Nigeria — principally to the United States. Where we transfer data internationally, we do so on the basis of contractual safeguards with each recipient requiring protections comparable to those the NDPA requires, and, where relevant, because the transfer is necessary for the performance of the contract you have asked us to deliver.
For data subjects in the EEA or UK, we rely on the appropriate transfer mechanisms in our agreements with each sub-processor.
9. Data subject requests
If one of your customers asks to access, correct, delete, restrict, port or object to the processing of their data, that request is yours to answer — you are the controller.
We help in two ways:
- Self-service. Your dashboard lets you search, export and delete conversations, leads, orders and bookings directly. For most requests you will not need us at all.
- On request. Where the platform alone cannot satisfy a request, email us and we will assist without undue delay, and at no charge for reasonable volumes.
If a data subject contacts us directly about data we process for you, we will not respond substantively. We will tell them to contact you, and forward the request to you promptly.
10. Breach notification
If we become aware of a personal data breach affecting data we process for you, we will:
- Notify you without undue delay, and in any event within 48 hours of becoming aware of it.
- Tell you what we know: the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures we have taken or propose to take.
- Keep you updated as the investigation develops, including where the initial picture turns out to be wrong.
- Assist you in meeting your own obligation to notify the Nigeria Data Protection Commission and, where required, affected individuals.
We will not delay telling you because the picture is incomplete. A partial, promptly-delivered account is more useful to you than a polished one that arrives after your own 72-hour regulatory clock has run down.
11. Audit and information rights
On reasonable written request, and no more than once in any 12-month period unless a breach or a regulator requires otherwise, we will provide the information reasonably necessary to demonstrate our compliance with this DPA.
Where that is not sufficient for your regulatory obligations, we will co-operate with an audit conducted by you or an independent auditor you appoint, subject to reasonable notice, confidentiality undertakings, scheduling that does not disrupt our operations or other customers, and your bearing the reasonable cost.
12. Impact assessments and prior consultation
We will provide reasonable assistance with any data protection impact assessment you carry out relating to your use of SabiBot, and with any prior consultation with a supervisory authority arising from it — taking into account the nature of the processing and the information available to us.
13. Deletion and return on termination
When your account is terminated:
- Your data remains available for you to export for 30 days. We will not withhold it, and we will help you extract it if you ask.
- After that window we delete it from our active systems.
- Residual copies may persist in operational backups for a limited period until those backups are cycled out. While they exist they remain protected by the measures in section 6 and are not processed for any purpose.
- We may retain data where the law requires us to — for example billing records for tax purposes — and only for as long as that requirement lasts.
- On written request we will confirm deletion.
14. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in section 16 of the Terms of Service, except where the NDPA or other applicable law does not permit those limits to apply — for instance in respect of a data subject's own statutory claim.
15. Changes
We may update this DPA to reflect changes in law, regulatory guidance or our processing operations. Material changes are notified to account holders by email at least 30 days in advance. Changes will not reduce the protections given to data subjects.
Annex A — details of processing
Subject matter and duration
Provision of the SabiBot AI assistant platform, for the duration of your subscription plus the retention periods described in section 13.
Nature and purpose
Collection, recording, storage, retrieval, transmission and analysis of customer interaction data, for the purposes of: generating conversational replies; capturing and storing leads; recording and fulfilling orders; scheduling and reminding about bookings; producing quotes, invoices and receipts; initiating and confirming payments; sending notifications; and providing analytics to you.
Categories of data subject
- Your customers and prospective customers who interact with your bot
- Your own staff members you invite to the dashboard
Categories of personal data
| Category | Typical fields |
|---|---|
| Identity and contact | Name, phone number, email address, WhatsApp number |
| Conversation | Message content, session identifier, channel, detected language, timestamps |
| Commerce | Order contents, quantities, values, stated preferences, delivery details you collect |
| Booking | Service requested, appointment date and time, reminder status |
| Transaction | Payment reference, amount, currency, status, gateway. No card data. |
| Technical | User-agent string; daily-rotating salted IP hash. No raw IP addresses. |
| Voice | Audio submitted for transcription. Converted to text; audio not retained. |
Special categories of data
None requested or required by the platform. See the caution in section 4 regarding data volunteered by customers.
Frequency
Continuous, for as long as the service is active.
Related documents: Privacy Policy · Terms of Service
Need a signed copy, a security questionnaire completed, or a specific clause reviewed? Get in touch and choose "Privacy & data".