DATA PROCESSING AGREEMENT
Mahhfaz School Management Platform
Between a subscribing School (as Data Controller) and Mahhfaz Group (as Data Processor)
Effective date: 1 July 2026
Last updated: 22 July 2026
Relationship to other documents. This Data Processing Agreement ("DPA") supplements and forms part of the Mahhfaz Terms of Service and the Mahhfaz Privacy Policy. Where this DPA conflicts with the Terms of Service or the Privacy Policy on the subject matter of data processing, this DPA prevails. Capitalised terms not defined here have the meaning given in the Terms of Service or the Privacy Policy.
1. Parties
1.1. The Controller: the School identified in the applicable subscription order or account record ("the School" or "Controller").
1.2. The Processor: Mahhfaz Group, a company incorporated in the Federal Republic of Nigeria with registration number 9612441 and registered office at No. 17, Kasuwan Yelwa Street, Palace Way, Jalingo, Taraba State, Nigeria ("Mahhfaz" or "Processor").
2. Definitions
2.1. "NDPA" means the Nigeria Data Protection Act 2023; "GAID" means the General Application and Implementation Directive 2025; "NDPC" means the Nigeria Data Protection Commission.
2.2. "Data Protection Laws" means the NDPA, the GAID, NDPC guidance, and, where applicable to a Data Subject, the GDPR.
2.3. "Controller", "Processor", "Data Subject", "Personal Data", "Sensitive Personal Data", "Processing", and "Personal Data Breach" have the meanings given in the NDPA.
2.4. "School Data" means the Personal Data described in Schedule 1 that Mahhfaz Processes on behalf of the School.
2.5. "Sub-processor" means a third party engaged by Mahhfaz to Process School Data.
2.6. "Platform" means the Mahhfaz School Management Platform.
3. Scope, Roles, and Instructions
3.1. This DPA applies to the Processing of School Data by Mahhfaz in providing the Platform.
3.2. The School is the Controller of School Data and Mahhfaz is the Processor. The subject matter, duration, nature, and purpose of Processing, the categories of Personal Data, and the categories of Data Subjects are set out in Schedule 1.
3.3. Mahhfaz will Process School Data only:
(a) on the School's documented instructions, including those given through configuration and use of the Platform and in this DPA and the Terms of Service;
(b) as necessary to provide, secure, support, and maintain the Platform; and
(c) as required by applicable law, in which case Mahhfaz will, unless prohibited, inform the School of that legal requirement before Processing.
3.4. Mahhfaz will inform the School if, in its opinion, an instruction infringes Data Protection Laws. Mahhfaz does not determine the School's lawful basis on the School's behalf.
3.5. Mahhfaz is a data controller/processor of major importance registered with the NDPC and has appointed a Data Protection Officer.
4. Controller Obligations
4.1. The School warrants that it has a valid lawful basis under the NDPA for the Processing it instructs, and that its instructions comply with Data Protection Laws.
4.2. The School is responsible for the accuracy, quality, and legality of School Data and for the means by which it acquired that data.
4.3. The School is responsible for obtaining and recording any consent required under the NDPA, including the consent of a parent or legal guardian for the Processing of a child's Personal Data (a child being any person under 18), and for verifying parental responsibility.
4.4. The School is responsible for providing any privacy notice required to Data Subjects.
5. Confidentiality
5.1. Mahhfaz will ensure that persons authorised to Process School Data are subject to an appropriate duty of confidentiality and Process School Data only as necessary to perform their duties.
5.2. Mahhfaz will limit access to School Data to personnel who require it to provide the Platform.
6. Security Measures
6.1. Mahhfaz will implement and maintain appropriate technical and organisational measures to protect School Data against unauthorised or unlawful Processing and against accidental loss, destruction, or damage, taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of Processing, and the heightened risk associated with Sensitive Personal Data and the data of minors.
6.2. The measures in place are described in Schedule 3. Mahhfaz may update them provided the level of protection is not materially reduced.
7. Sub-processing
7.1. The School authorises Mahhfaz to engage the Sub-processors listed in Schedule 2 to Process School Data.
7.2. Mahhfaz will impose on each Sub-processor, by contract, data-protection obligations no less protective than those in this DPA, and remains responsible to the School for each Sub-processor's performance.
7.3. Mahhfaz will give the School not less than 30 days' prior notice of the addition or replacement of a Sub-processor, during which the School may object on reasonable data-protection grounds. If the parties cannot resolve a reasonable objection in good faith, the School may suspend or terminate the affected Service.
8. Assistance with Data Subject Rights
8.1. Taking into account the nature of the Processing, Mahhfaz will assist the School by appropriate technical and organisational measures, so far as reasonably practicable, to respond to requests by Data Subjects to exercise their rights under the NDPA (and the GDPR where applicable), including access, rectification, erasure, restriction, objection, and portability.
8.2. If Mahhfaz receives a request directly from a Data Subject relating to School Data, it will not respond substantively but will, without undue delay, refer the request to the School.
9. Personal Data Breach
9.1. Mahhfaz will notify the School without undue delay after becoming aware of a Personal Data Breach affecting School Data.
9.2. The notification will include, to the extent available: a description of the nature of the breach, including the categories and approximate number of Data Subjects and records affected; the likely consequences; the measures taken or proposed to address it; and a contact point for further information.
9.3. Mahhfaz will assist the School in meeting the School's own obligation, as Controller, to notify the NDPC within 72 hours of becoming aware of a breach likely to result in a risk to the rights and freedoms of individuals, and, where required, to notify affected Data Subjects without undue delay.
9.4. Mahhfaz will document Personal Data Breaches and its response, and make relevant records available to the School on reasonable request.
10. Data Protection Impact Assessments
10.1. Taking into account the nature of the Processing and the information available to it, Mahhfaz will provide reasonable assistance to the School with any data protection impact assessment and any prior consultation with the NDPC that the School is required to carry out under the NDPA and GAID, including in respect of large-scale processing of minors' Sensitive Personal Data.
11. International Transfers
11.1. Mahhfaz will not transfer School Data outside Nigeria except as necessary to provide the Platform through the Sub-processors and infrastructure described in Schedule 2, and will ensure any such transfer complies with the cross-border transfer provisions of the NDPA (sections 41–43) and GAID Schedule 5 — relying on an NDPC adequacy determination where available, or otherwise appropriate contractual safeguards or another permitted basis.
12. Return and Deletion
12.1. On termination or expiry of the subscription, and at the choice of the School, Mahhfaz will return or delete School Data in accordance with the Terms of Service and the retention schedule in the Privacy Policy. As part of offboarding, examination results and transcripts are made available for download before deletion.
12.2. Mahhfaz may retain School Data to the extent, and for as long as, required by law (including the six-year statutory retention of financial and payroll records) or as necessary to establish, exercise, or defend legal claims, and will continue to protect it under this DPA for as long as it is retained.
12.3. Deletion extends to backups within 90 days.
13. Records and Audit
13.1. Mahhfaz will maintain records of its Processing of School Data sufficient to demonstrate compliance with this DPA.
13.2. Mahhfaz will make available to the School information reasonably necessary to demonstrate compliance and will allow for and contribute to audits, including inspections, conducted by the School or an auditor it mandates, subject to reasonable prior notice, a frequency of not more than once per year (save where required by the NDPC or following a Personal Data Breach), confidentiality, and protection of other Schools' data and Mahhfaz's security. A current independent security report may be provided to satisfy routine audit requests.
14. Liability
14.1. The liability of each party under or in connection with this DPA is subject to the limitations and exclusions set out in the Terms of Service, to the extent permitted by applicable law and save for any statutory liability under the NDPA that cannot lawfully be limited.
15. Term, Governing Law, and Precedence
15.1. This DPA takes effect on the effective date and continues for as long as Mahhfaz Processes School Data.
15.2. This DPA is governed by the laws of the Federal Republic of Nigeria, and disputes are resolved in accordance with the dispute-resolution provisions of the Terms of Service.
15.3. In case of conflict on the subject matter of data processing, the order of precedence is: (1) this DPA; (2) the Privacy Policy; (3) the Terms of Service.
Schedule 1 — Details of Processing
Item
Detail
Subject matter
Processing of Personal Data to provide the Mahhfaz School Management Platform to the School
Duration
For the term of the subscription and any legally required retention period thereafter
Nature of Processing
Collection, storage, organisation, retrieval, use, transmission, disclosure to Sub-processors, and deletion, by automated means within the Platform
Purpose
School administration: admissions/applicants, student records, academics, attendance, examinations and results, health/clinic records, hostel, library, transport, staff records and payroll, messaging, and fee collection
Categories of Data Subjects
Students; applicants; parents/guardians; school staff
Categories of Personal Data
Student: full name, date of birth, passport photograph, admission/registration number, class, uploaded documents (e.g. birth certificate), attendance, exam scores and results, hostel allocation. Parent/guardian: names, phone numbers, emails. Staff: name, email, phone, staff ID, department, next of kin, passport photograph, bank account number, payslips, leave and attendance. Technical: activity/audit logs including IP addresses; message-delivery logs
Sensitive Personal Data
Student blood group; student health/clinic records; staff next-of-kin details
Data of minors
Yes — student and applicant data includes children under 18; parental/guardian consent obligations apply (Clause 4.3)
Schedule 2 — Approved Sub-processors
Sub-processor
Function
Hosting region
DPA in place
Paystack (Paystack Payments Limited)
Payment processing and split settlement
Nigeria
Yes
Termii
SMS delivery
Nigeria
Yes
Resend
Email delivery
United States
Yes
Laravel Cloud
Hosting and PostgreSQL database
European Union (eu-west-1, Ireland)
Yes
Amazon Web Services (AWS S3)
File and media storage
European Union (eu-west-1, Ireland)
Yes
Cloudflare, Inc.
Marketing website and content delivery
Global edge network
Yes
Schedule 3 — Technical and Organisational Security Measures
1. Access control: role-based access aligned to Platform roles; least-privilege; access to Sensitive Personal Data (health) and payroll data (bank details) restricted to roles with a legitimate need.
2. Tenant isolation: logical separation of each School's data.
3. Encryption: Personal Data encrypted in transit and at rest using industry-standard encryption.
4. Authentication: enforced unique credentials with a mandatory password change on first login; optional two-factor sign-in (a one-time code sent by email) available to all user accounts.
5. Audit logging: activity and audit logs, including IP addresses, retained per the Privacy Policy.
6. Backups: regular automated backups with periodic restoration testing.
7. Breach response: documented detection, investigation, and notification procedures (Clause 9).
8. Sub-processor management: contractual data-protection obligations flowed down to Sub-processors.
9. Data minimisation and retention: retention and deletion in accordance with the Privacy Policy schedule.
10. Operational security: patch management, vulnerability monitoring, periodic access reviews, and staff data-protection training.