Data Processing Agreement
Effective Date: January 1, 2024 | Last Updated: September 27, 2026
This page is a summary, not the contract
The binding Data Processing Agreement is the one signed with you, and it takes priority over anything on this page. This page exists so you can see our processing position before you ask for the full document. If your legal team needs the executed version, ask for it and we will send it.
1. When this applies
Where Intelisav Africa builds, hosts or maintains a system that stores personal data about your people — your customers, your staff, your patients — you are the controller and we are the processor. The signed agreement then sets out how we are permitted to handle that data on your instructions.
Where we run a service for our own purposes, such as operating this website or running our own products, we are the controller and the Privacy Policy applies instead.
2. Our processing commitments
The signed agreement commits us to the following. Each is a commitment we can be held to, not an aspiration.
- Process only on your instructions. We do not sell your data, use it for our own purposes, or use it to train any model.
- Documented purposes only. Each system we build has a written purpose and data inventory. Data is not collected because a field was convenient.
- Least-privilege access. Access to client data in production is limited to named engineers who need it, is individually attributable, and is reviewed.
- Traceable actions. Operations that change data or configuration are logged, so you can see what happened and when.
- No unapproved subprocessing. We confirm the applicable list of sub-processors with you before work begins, and we notify you before adding or replacing one.
- Security that is designed in. Controls are built into the development process rather than added afterwards. This is a claim about our engineering method, not a certification — we hold no ISO 27001 or SOC 2 certification, and we do not represent otherwise.
- Deletion on exit. On termination we return or delete your data in the format and timescale set out in the agreement, and confirm it in writing.
- Breach notification. We tell you without undue delay if we become aware of a breach affecting your data, with the facts we have, and we cooperate with your investigation.
3. International transfers
We aim to keep client data in the region agreed in your contract. Where a transfer outside that region is unavoidable — for example, a subprocessor operating a global CDN — we rely on a lawful transfer mechanism and document it in the agreement. Where you require processing to stay in a specific jurisdiction, tell us before we start, because that is a design constraint rather than a configuration setting.
4. Your rights
Data-subject requests (access, correction, deletion, portability) are handled by you as controller. We assist you to respond rather than handling requests directly, because the decision about an individual is yours to make. We will not respond to a data subject directly about your data except on your instruction or where the law requires it.
5. Requesting the agreement
Email info@intelisav.com with the subject line "DPA request" and tell us which system it relates to. We will send the current template, and we will mark up any clause your legal team wants changed rather than treating the template as non-negotiable.
6. Contact
Email: info@intelisav.com
Phone: +254 182 463 743
Post: St. Ellis House, Wabera Street, Nairobi, Kenya