About this document
This Addendum forms part of the agreement between Identro and a Business Customer where the customer is controller and Identro processes Personal Data on its documented instructions.
1. Scope and precedence
This Addendum applies only to processing for which the Customer is Controller and Identro is Processor. Identro’s independent Controller activities, including account administration, security, fraud prevention, billing, audit, legal compliance, service integrity and dispute management, are governed by the Privacy Policy.
If this Addendum conflicts with the general Terms on Processor obligations, this Addendum prevails. A signed negotiated DPA prevails over this standard Addendum.
2. Processing details
Subject matter: provision of identity, business, biometric, address, AML, fraud, decision-support, digital-service and related API or dashboard Services. Duration: the agreement term plus any lawful retention or transition period. Nature: collection, transmission, matching, validation, retrieval, storage, analysis, return, deletion and related operations required for the requested Service.
Data subjects may include the Customer’s applicants, users, customers, staff, directors, beneficial owners, agents, beneficiaries and other authorised verification subjects. Data may include identity, contact, government identifiers, business information, bank or settlement details, facial images, liveness data, address, technical metadata, fraud or risk indicators, transaction details and consent evidence.
3. Customer instructions and responsibilities
Identro shall process Personal Data only on documented Customer instructions embodied in the agreement, API request, dashboard action or written instruction, unless law requires otherwise. Identro shall inform the Customer where an instruction appears unlawful, unless prohibited by law.
The Customer warrants that it has a lawful basis, has provided required notices, has obtained valid consent where required, will not submit excessive data, and will use results lawfully and fairly. The Customer remains responsible for final decisions and for responding to individuals, except where Identro is directly responsible under law.
4. Confidentiality and personnel
Identro shall ensure that authorised personnel are bound by confidentiality, receive appropriate training and access Personal Data only on a need-to-know basis. Access shall be reviewed and removed when no longer required.
5. Security measures
Identro shall implement risk-appropriate technical and organisational measures, including access control, MFA for privileged access, encryption in transit, encryption at rest where appropriate, logging, monitoring, secrets management, secure development, vulnerability management, backups, incident response, business continuity and vendor controls.
On reasonable request, Identro shall provide relevant security summaries, certifications, audit reports or questionnaires, subject to confidentiality, security and third-party restrictions.
6. Sub-processors
The Customer gives general authorisation for Identro to appoint sub-processors required to deliver the Services. Identro shall impose written data-protection obligations materially equivalent to those in this Addendum and remains responsible for their Processor obligations to the extent required by law.
Identro shall make a current sub-processor list available on request and provide notice of a material new sub-processor where required by the agreement. A reasonable, documented objection based on data-protection risk shall be discussed in good faith; if no reasonable alternative exists, either party may terminate the affected Service.
7. International transfers
Identro shall not transfer Personal Data internationally without a mechanism recognised by applicable law and appropriate safeguards. The parties shall execute or incorporate required transfer instruments and cooperate with reasonable transfer assessments.
8. Data-subject requests
Identro shall promptly notify the Customer of a request relating to Customer-controlled data unless prohibited by law. Taking account of the nature of processing, Identro shall provide reasonable assistance through available technical and organisational measures. The Customer remains responsible for the substantive response.
9. Breach notification
Identro shall notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer-controlled data. The notice shall include available information about the nature of the breach, affected data and individuals, likely consequences, measures taken or proposed, and a contact point. Information may be supplied in phases as it becomes available.
Notification is not an admission of fault. The Customer is responsible for regulatory and individual notifications concerning its Controller obligations, with reasonable assistance from Identro.
10. DPIAs and regulatory cooperation
Identro shall provide reasonable information and assistance for Customer DPIAs and prior consultations relating to the Services, taking account of the information available and the nature of processing. Each party shall cooperate with competent authorities as required by law.
11. Audit and compliance information
Identro shall make available information reasonably necessary to demonstrate compliance. Audits shall first rely on independent reports, certifications and questionnaires. On-site inspection may occur only where legally required or where available evidence is reasonably insufficient after a material incident, subject to reasonable notice, confidentiality, security, non-disruption and allocation of reasonable costs.
Audit rights do not permit access to another customer’s data, source code, security-sensitive information or information that would create disproportionate risk.
12. Return, deletion and retention
At termination or on lawful instruction, Identro shall delete or return Customer-controlled Personal Data within a reasonable period, except where retention is required by law or permitted for security, billing, fraud, audit or legal claims in Identro’s independent Controller capacity. Residual backups shall remain isolated and expire through normal rotation.
13. Liability and indemnity
Liability under this Addendum is subject to the liability framework in the governing agreement, except to the extent applicable law requires otherwise. Each party is responsible for its own acts, omissions and statutory obligations. The Customer shall indemnify Identro for third-party claims arising from unlawful instructions, absence of lawful basis or consent, or unlawful use of results, except to the extent caused by Identro’s breach.
14. Governing law and contact
This Addendum is governed by Nigerian law unless a signed agreement provides otherwise. Data-protection contact: info@identro.ng (Attention: Data Protection Officer). Security incident contact: security@identro.ng.
Questions, complaints or rights requests
Contact Identro at support@identro.ng. Security incidents should be sent to security@identro.ng. Identro, Ihesiaba Court, Ishaya Shekari Crescent, Gwarinpa, Abuja, FCT, Nigeria.