Loading...
Search Now!
Contact Info
Location Lagos, Nigeria
Follow Us

Data Processing Addendum

Data Processing Addendum Haven International Limited

Effective date: August 1, 2026  ·  Last updated: August 1, 2026  ·  Version 1.0

This Data Processing Addendum ("DPA") forms part of the agreement between Haven International Limited ("Haven") and business clients ("Controller") who share personal data with Haven in the course of using Haven's platform or services.

This DPA applies where Haven acts as a data processor on behalf of the Controller in connection with GDPR, UK GDPR, or NDPR obligations.

To request a signed DPA: Email privacy@youfoundhaven.com with your company name and details. Haven will provide a signed copy within 10 business days.

1. Definitions

  • "Controller" — the business client who determines the purposes and means of processing personal data.
  • "Processor" — Haven International Limited, which processes personal data on behalf of the Controller.
  • "Personal Data" — any information relating to an identified or identifiable natural person.
  • "Processing" — any operation performed on personal data including collection, storage, use, disclosure, and deletion.
  • "Data Subject" — the individual whose personal data is being processed.
  • "Supervisory Authority" — NITDA for Nigerian data, a relevant EU data protection authority for EU data, or the ICO for UK data.

2. Scope and Purpose

This DPA applies when the Controller shares personal data with Haven for the purpose of Haven delivering its platform services. Haven will only process personal data in accordance with the Controller's documented instructions and this DPA.

Haven will not process personal data for any purpose other than delivering the agreed services unless required by law.

3. Haven's Obligations as Processor

Haven agrees to:

  • Process personal data only on documented instructions from the Controller
  • Ensure that all personnel with access to personal data are bound by confidentiality obligations
  • Implement appropriate technical and organisational security measures
  • Assist the Controller in responding to data subject rights requests
  • Notify the Controller without undue delay of any personal data breach
  • Delete or return all personal data to the Controller upon termination of services
  • Provide all information necessary to demonstrate compliance with this DPA

4. Controller's Obligations

The Controller agrees to:

  • Ensure there is a lawful basis for sharing personal data with Haven
  • Provide Haven with clear and documented processing instructions
  • Ensure data subjects have been informed about the processing
  • Notify Haven immediately of any changes to processing instructions
  • Comply with all applicable data protection laws in its jurisdiction

5. Subprocessors

Haven uses third-party subprocessors to deliver its platform services. By agreeing to this DPA, the Controller provides general authorisation for Haven to engage subprocessors listed in Haven's Subprocessors page.

Haven will notify the Controller of any intended changes to its subprocessors at least 30 days in advance. The Controller may object to new subprocessors within 14 days of notification.

6. International Transfers

Where Haven transfers personal data outside Nigeria, the EU, or the UK, Haven ensures appropriate safeguards are in place including standard contractual clauses or other approved transfer mechanisms under applicable law.

7. Security Measures

Haven implements appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include encryption, access controls, regular security testing, and staff training.

Full details of Haven's security practices are in the Security Policy.

8. Data Breach Notification

Haven will notify the Controller without undue delay and within 72 hours of becoming aware of a personal data breach affecting Controller data. The notification will include all information required by applicable law including the nature of the breach, categories of data affected, and steps taken to address it.

9. Data Deletion and Return

Upon termination of the services or at the Controller's request, Haven will delete or return all personal data processed under this DPA within 30 days, unless retention is required by applicable law.

10. Audit Rights

The Controller may audit Haven's compliance with this DPA by providing 30 days written notice. Haven will provide all information reasonably necessary to demonstrate compliance. Audits will be conducted at the Controller's expense and must not unreasonably disrupt Haven's operations.

11. Contact

For DPA requests, compliance questions, or data protection enquiries:

  • Email: privacy@youfoundhaven.com
  • Post: Haven International Limited, Block 271, Flat 2, Zone F, Iba Housing Estate, Ojo, Lagos, Nigeria

This Data Processing Addendum was prepared for Haven International Limited. It is not legal advice. Please consult a qualified legal adviser for specific data protection questions.