Legal

Data Processing Agreement

How ReConnect handles your customers' personal data on your business's behalf. Your business's owner accepts it in ReConnect (Settings → Privacy & data), alongside our Terms of Service and Privacy Policy.

Last updated 26 Sept 2026 · version 1.0

1.Parties

This Data Processing Agreement ("DPA") is between:

  • The Business: the business that has an account on ReConnect and accepts this DPA through its owner (the "Controller" for the Customer Data described below); and
  • ReConnect: RECONNECT HUB (RC 9890503), which operates ReConnect (the "Processor" for that Customer Data).

It forms part of the ReConnect Terms of Service. If the two conflict on the processing of Customer Data, this DPA applies.

2.Roles

The Business decides why and how its customers' personal data is used in ReConnect: which customers it adds, what it records about them, and what it sends them. For that data, the Business is the controller and ReConnect processes it on the Business's behalf.

ReConnect is a controller for the data it needs to run its own service: accounts, logins, billing, security, support and the improvement of ReConnect. That data is covered by the ReConnect Privacy Policy, not this DPA.

3.Subject matter, duration, nature and purpose

  • Subject matter: ReConnect's customer follow-up, messaging, orders and delivery, sales, invoicing, reporting and Google Business Profile features.
  • Duration: for as long as the Business has a ReConnect account, and afterwards only as described in section 11.
  • Nature: storing, organising, displaying, searching, sending (on the Business's instruction), importing and exporting Customer Data, and deleting it.
  • Purpose: to provide ReConnect to the Business under the Terms of Service.

4.Types of personal data and data subjects

Data subjects: the Business's customers and leads, the people who receive its deliveries, the people it chats with on WhatsApp, the riders it adds, and anyone else whose details the Business puts into ReConnect.

Types of personal data (Customer Data): names, phone numbers, email addresses, delivery addresses and instructions, birthdays (day and month), gender where the customer chose to share it, purchase, order, payment and delivery history, WhatsApp messages, notes the Business's team writes, communication preferences and consent records, and review requests.

The Business must not use ReConnect for special categories of personal data or other sensitive data (for example health, religion or government identification numbers) unless ReConnect has agreed in writing that the necessary safeguards are in place.

5.The Business's instructions

ReConnect processes Customer Data only on the Business's documented instructions, which are: this DPA, the Terms of Service, and the Business's use and settings of ReConnect. ReConnect will tell the Business if it believes an instruction breaks the Nigeria Data Protection Act 2023 or other applicable law, unless the law prevents it from saying so.

The Business is responsible for having a lawful basis for its processing, for giving its customers the information the law requires, and for the accuracy of the data it enters.

6.Confidentiality

ReConnect makes sure that the people it authorises to process Customer Data are bound by confidentiality and only access it when needed to provide, secure or support the service. ReConnect's support team can see a business's customer data only when the Business's owner turns on support access, for a limited time, and those views are logged.

7.Security

ReConnect uses technical and organisational measures appropriate to the risk, including: encryption in transit (HTTPS), separation of each business's data, role-based access within each business, encryption of stored WhatsApp and Google access tokens, hashed passwords and session tokens, rate limiting, audit logging, and backups. The measures are described in ReConnect's security documentation and may improve over time, but will not fall below the level described there.

8.Subprocessors

The Business authorises ReConnect to use the subprocessors listed in ReConnect's Privacy Policy under "Who we share data with" (for example hosting, database, email delivery, payment processing and, where the Business connects them, Meta's WhatsApp Business Platform and Google). ReConnect will give notice of new subprocessors, and the Business may object on reasonable data-protection grounds. ReConnect remains responsible for its subprocessors' processing of Customer Data.

9.International transfers

Some subprocessors may process Customer Data outside Nigeria. ReConnect will only transfer Customer Data outside Nigeria where the Nigeria Data Protection Act 2023 and applicable NDPC regulations allow it, and records the destination, purpose and safeguard for each transfer in its transfer register.

10.Assistance

Taking into account the nature of the processing, ReConnect helps the Business to:

  • Answer data subject requests (access, correction, deletion, restriction, objection, data export), through ReConnect's privacy request tools;
  • Handle personal data breaches: ReConnect will notify the Business without undue delay after becoming aware of a personal data breach affecting its Customer Data, with the information then available, and will cooperate with the Business's investigation;
  • Carry out data protection impact assessments and consultations with the regulator, where required and reasonable.

11.Deletion or return

The Business can export its data at any time. When the Business closes its account, ReConnect keeps its data for a grace period during which the Business can reopen or download it, then deletes it. Copies in backups are removed as those backups expire under ReConnect's backup schedule. ReConnect may keep data longer only where the law requires it.

12.Audits and cooperation

ReConnect will make available the information reasonably needed to show compliance with this DPA, and will cooperate with reasonable audits by the Business or an auditor it appoints, with reasonable notice, at reasonable intervals, and subject to confidentiality.

13.Term and termination

This DPA lasts as long as ReConnect processes Customer Data for the Business. Sections that by their nature should continue (confidentiality, deletion) survive termination.

14.Liability and law

Liability under this DPA is subject to the limits in the Terms of Service, except where the law does not allow those limits. This DPA is governed by the laws of the Federal Republic of Nigeria.