Tawala

Data Processing Agreement

Last updated: January 1, 2026

1. Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Tawala Systems Ltd ("Processor") and the Customer ("Controller") for the provision of Tawala's services.

2. Definitions

"Personal Data" means any information relating to an identified or identifiable natural person.

"Processing" means any operation performed on Personal Data, including collection, storage, use, and deletion.

"Sub-processor" means any third party engaged by Tawala to process Personal Data.

3. Scope of Processing

The Processor shall process Personal Data only:

  • On documented instructions from the Controller
  • For the purpose of providing the agreed services
  • In accordance with applicable data protection laws

4. Categories of Data

The following categories of Personal Data may be processed:

  • Customer and contact information
  • Employee records and payroll data
  • Transaction and financial data
  • Usage and log data

5. Security Measures

The Processor implements appropriate technical and organizational measures including:

  • Encryption of data in transit and at rest
  • Access control and authentication systems
  • Regular security assessments
  • Employee training and confidentiality agreements
  • Incident response procedures

6. Sub-processors

The Processor may engage Sub-processors to assist in providing services. Current Sub-processors include cloud infrastructure providers. The Controller will be notified of any new Sub-processors with 30 days notice.

7. Data Subject Rights

The Processor shall assist the Controller in responding to requests from data subjects exercising their rights under applicable law.

8. Data Breach Notification

The Processor shall notify the Controller without undue delay (and in any event within 72 hours) upon becoming aware of a Personal Data breach.

9. Data Deletion

Upon termination of services, the Processor shall delete or return all Personal Data within 30 days, unless retention is required by law.

10. Audits

The Processor shall make available all information necessary to demonstrate compliance and allow for audits upon reasonable request.

11. Contact

For DPA-related inquiries:
Email: dpa@tawala.co.tz
Phone: +255 759 702 766

Chat on WhatsApp