This Data Processing Agreement ("DPA") forms part of, and is subject to, the Terms of Service (the "Agreement") between Agrexa Technologies Ltd. ("Agrexa", "Processor", "we", or "us") and the customer organisation that accepts the Agreement ("Customer", "Controller", or "you"). This DPA reflects the parties' agreement on the processing of Personal Data by Agrexa on behalf of the Customer in connection with the Agrexa SaaS platform (the "Platform").
This DPA is entered into in compliance with the Ghana Data Protection Act, 2012 (Act 843), the EU General Data Protection Regulation 2016/679 ("GDPR") where applicable, and other relevant data protection legislation (together, "Data Protection Laws"). Where there is any conflict between this DPA and the Agreement in respect of the processing of Personal Data, this DPA shall prevail.
1. Definitions
Capitalised terms not otherwise defined in this DPA have the meaning given to them in the Agreement. For the purposes of this DPA:
- "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", and "Processing" have the meanings given to them in the applicable Data Protection Laws.
- "Customer Personal Data" means any Personal Data that Agrexa processes on behalf of the Customer through the Platform, including data relating to farmers, field staff, and other individuals recorded by the Customer.
- "Sub-processor" means any third party engaged by Agrexa to process Customer Personal Data in connection with the Platform.
- "Standard Contractual Clauses" ("SCCs") means the standard data protection clauses adopted by the European Commission for the transfer of Personal Data to processors established in third countries.
2. Roles and Responsibilities of the Parties
2.1. The parties acknowledge and agree that, with regard to the Processing of Customer Personal Data, the Customer is the Controller and Agrexa is the Processor.
2.2. The Customer, as Controller, is responsible for the lawfulness of the collection of Customer Personal Data and for obtaining all necessary consents and notices required to enable the lawful Processing of Customer Personal Data by Agrexa in accordance with this DPA.
2.3. Agrexa, as Processor, shall process Customer Personal Data only on documented instructions from the Customer, including with regard to international transfers, unless required to do otherwise by applicable law, in which case Agrexa shall inform the Customer of that legal requirement before Processing, unless prohibited from doing so.
2.4. The Agreement, this DPA, and the Customer's configuration and use of the Platform constitute the Customer's complete and final documented instructions to Agrexa for the Processing of Customer Personal Data.
3. Scope and Purpose of Processing
The subject matter, nature, and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are described in Annex A to this DPA. Agrexa shall process Customer Personal Data solely to provide, maintain, secure, and improve the Platform in accordance with the Agreement, and shall not process Customer Personal Data for any other purpose, including its own commercial purposes, without the Customer's prior written consent.
4. Duration of Processing
Agrexa will process Customer Personal Data for the duration of the Agreement, unless otherwise agreed in writing. The provisions of this DPA shall continue to apply for as long as Agrexa processes Customer Personal Data and until such data is returned or deleted in accordance with Section 12.
5. Obligations of Agrexa as Processor
Agrexa shall:
- Process Customer Personal Data only on the documented instructions of the Customer, as set out in Section 2;
- Ensure that persons authorised to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
- Implement and maintain the technical and organisational security measures described in Annex C and Section 6;
- Respect the conditions set out in Section 7 for engaging Sub-processors;
- Assist the Customer, taking into account the nature of the Processing, in responding to requests from Data Subjects as set out in Section 9;
- Assist the Customer in ensuring compliance with its obligations relating to security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities;
- Make available to the Customer all information necessary to demonstrate compliance with the obligations set out in this DPA, and allow for and contribute to audits as set out in Section 13;
- Immediately inform the Customer if, in its opinion, an instruction from the Customer infringes applicable Data Protection Laws.
6. Security of Processing
6.1. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk to the rights and freedoms of Data Subjects, Agrexa shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.
6.2. These measures include, at a minimum, those described in Annex C, such as encryption of Personal Data in transit and at rest, ongoing confidentiality, integrity, availability, and resilience of processing systems, and a process for regularly testing and evaluating the effectiveness of such measures.
7. Sub-processors
7.1. The Customer provides a general authorisation for Agrexa to engage Sub-processors to process Customer Personal Data, subject to the conditions in this Section. A list of current Sub-processors is set out in Annex B.
7.2. Agrexa shall impose data protection obligations on each Sub-processor, by way of a written contract, that are no less protective than those set out in this DPA. Agrexa remains fully liable to the Customer for the performance of each Sub-processor's obligations.
7.3. Agrexa shall give the Customer prior written notice (which may be given via email or through the Platform) of the addition or replacement of any Sub-processor, thereby giving the Customer the opportunity to object to such changes within fourteen (14) days. If the Customer objects on reasonable data protection grounds, the parties shall work in good faith to resolve the objection.
8. International Data Transfers
8.1. Agrexa may transfer and process Customer Personal Data in jurisdictions outside the country of origin, including where its infrastructure providers and Sub-processors operate. Any such transfer shall be carried out only where an adequate level of protection is ensured.
8.2. Where a transfer of Customer Personal Data is made to a country that has not been recognised as providing an adequate level of protection, such transfer shall be governed by appropriate safeguards, including the Standard Contractual Clauses, which are incorporated into this DPA by reference and shall apply to such transfers.
9. Assistance with Data Subject Rights
9.1. Taking into account the nature of the Processing, Agrexa shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests from Data Subjects exercising their rights of access, rectification, erasure, restriction, portability, and objection.
9.2. If Agrexa receives a request directly from a Data Subject relating to Customer Personal Data, it shall, unless legally prohibited, promptly notify the Customer and shall not respond to the request itself other than to confirm receipt, unless authorised by the Customer to do so.
10. Personal Data Breach Notification
10.1. Agrexa shall notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.
10.2. Such notification shall, to the extent known, describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Agrexa shall cooperate with the Customer and take reasonable steps as directed by the Customer to assist in the investigation, mitigation, and remediation of the breach.
11. Data Protection Impact Assessments
Agrexa shall provide reasonable assistance to the Customer with any data protection impact assessments and prior consultations with supervisory authorities that the Customer is required to carry out under applicable Data Protection Laws, in each case solely in relation to the Processing of Customer Personal Data by Agrexa and taking into account the nature of the Processing and the information available to Agrexa.
12. Return and Deletion of Data
12.1. Upon termination or expiry of the Agreement, Agrexa shall, at the choice of the Customer, delete or return all Customer Personal Data and delete existing copies, unless applicable law requires storage of the Personal Data.
12.2. The Customer may export Customer Personal Data in a structured, machine-readable format (CSV or JSON) through the Platform at any time during the term of the Agreement and for a period of thirty (30) days following termination. After this period, Agrexa shall delete or irreversibly anonymise Customer Personal Data in accordance with its data retention policy, save where retention is required by law.
13. Audits and Inspections
13.1. Agrexa shall make available to the Customer, upon reasonable request, all information necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer.
13.2. To the extent available, Agrexa may satisfy its obligations under this Section by providing the Customer with copies of relevant third-party certifications, audit reports, or summaries thereof. Audits shall be conducted during normal business hours, with reasonable advance notice, and subject to appropriate confidentiality obligations, and shall not unreasonably interfere with Agrexa's business operations.
14. Liability
The liability of each party under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement. Nothing in this DPA limits or excludes either party's liability where such limitation or exclusion is not permitted under applicable Data Protection Laws.
15. Governing Law and Jurisdiction
This DPA is governed by and construed in accordance with the laws of the Republic of Ghana, without regard to its conflict of laws provisions, and is subject to the dispute resolution and jurisdiction provisions of the Agreement. Where the GDPR applies to the Processing, the governing law and jurisdiction of the applicable Standard Contractual Clauses shall apply to matters arising under those clauses.
Annex A — Details of Processing
| Element | Description |
|---|---|
| Subject matter | Provision of the Agrexa SaaS agricultural supply chain platform to the Customer. |
| Nature of processing | Collection, storage, organisation, retrieval, transmission, analysis, and deletion of Personal Data as part of platform operation. |
| Purpose | Farmer management, contract and delivery tracking, payment processing, analytics, and related services under the Agreement. |
| Categories of Data Subjects | Farmers, farmer group members, Customer staff and users, and other individuals whose data the Customer records on the Platform. |
| Types of Personal Data | Identification data, contact details, farm and location data, financial and payment data, and technical usage data, as described in the Privacy Policy. |
| Duration | The term of the Agreement plus applicable retention and deletion periods set out in Section 12. |
Annex B — Authorised Sub-processors
Agrexa engages the following categories of Sub-processors to support the delivery of the Platform:
| Sub-processor | Purpose | Data Categories |
|---|---|---|
| Payment providers (Paystack, Flutterwave, Hubtel) | Disbursement and reconciliation of payments to farmers | Name, phone number, payment amount, transaction reference |
| Cloud infrastructure providers | Hosting, storage, and delivery of the Platform | All Customer Personal Data (encrypted at rest) |
| AI service providers (OpenAI, Anthropic) | Model inference for yield, credit, risk, and quality features | Anonymised and aggregated agricultural data only |
| Communications providers (SMS, email, WhatsApp) | Delivery of transactional notifications | Name, phone number, email address, message content |
Annex C — Technical and Organisational Security Measures
Agrexa implements and maintains the following technical and organisational measures to protect Customer Personal Data:
- Encryption of all data in transit using TLS 1.2 or higher and encryption of data at rest using AES-256
- Password hashing using bcrypt with 12 rounds of salting and support for two-factor authentication
- Role-based access control (RBAC) with defined roles and granular permissions, enforced on a least-privilege basis
- Multi-tenant data isolation ensuring each organisation's data is logically segregated
- Webhook signature verification for payment provider callbacks and rate limiting on authentication and API endpoints
- Comprehensive audit logging of data access and modifications, retained for five (5) years
- Regular security assessments, vulnerability scanning, and patch management
- Documented incident response and personal data breach notification procedures
- Secure backup and disaster recovery processes to maintain availability and resilience
Contact Information
For questions about this Data Processing Agreement, or to exercise any rights or obligations under it, please contact our Data Protection Officer:
Data Protection Officer
Agrexa Technologies Ltd.
14 Independence Avenue, Ridge
Accra, Ghana
Email: dpo@agrexa.com
Phone: +233 (0) 30 123 4567