Data Processing Agreement
Standard Terms — Effective July 15, 2026
1. Application and Roles
This DPA forms part of the School SaaS Agreement. For School Data, the School is generally the controller or responsible institution and SMIK-Af is generally its processor or service provider, subject to the terminology and mandatory law of the School's country. SMIK-Af acts independently for account security, subscription administration, fraud prevention, legal compliance, and its own business records.
2. Processing Details
The subject matter is provision of the SMIK-Af service for the Agreement term plus authorised deletion and backup rotation. Processing includes collection, storage, organisation, retrieval, transmission, support, security, export, and deletion. Data subjects and categories are described in the Privacy Policy and include children, students, families, personnel, visitors, and other users, including sensitive academic, health, financial, location, disciplinary, and safeguarding information.
3. Documented Instructions
SMIK-Af will process School Data only on documented lawful instructions in the Agreement, configuration, authorised support requests, or applicable law. SMIK-Af will inform the School if an instruction appears unlawful unless prohibited from doing so. The School is responsible for lawful instructions, notices, legal bases, authorisations, and data accuracy.
4. Confidentiality and Access
Personnel with access must be bound by confidentiality, receive appropriate training, and access data only as necessary. SMIK-Af will use role-based controls and review privileged access proportionate to risk.
5. Security
SMIK-Af will maintain the Security Measures Schedule and may update safeguards without materially reducing overall protection. The School must secure its users, endpoints, credentials, exports, integrations, and role configuration.
6. Subprocessors
The School generally authorises providers listed in the Subprocessor List. SMIK-Af will impose data-protection obligations appropriate to each service and remains responsible for its processor obligations. Material new subprocessors will be announced where practicable. A School with a reasonable legal objection should contact SMIK-Af promptly; the parties will seek an alternative, and if none is feasible the affected service may be terminated.
7. Cross-Border Transfers
The parties will use safeguards required by the relevant African national law. These may include contractual clauses, regulator notification or approval, localisation, risk assessment, adequacy, or another lawful mechanism. The School must identify local restrictions during onboarding.
8. Rights Requests
SMIK-Af will provide reasonable assistance for verified access, correction, deletion, objection, restriction, portability, or complaint requests relating to School Data. Unless law requires direct action, SMIK-Af will refer the requester to the School. The School is responsible for the final legal response.
9. Security Incidents
After confirming unauthorised destruction, loss, alteration, disclosure of, or access to School Data, SMIK-Af will notify the School without undue delay and provide available information reasonably needed for risk assessment and legally required notifications. Notification is not an admission of fault. The School determines notifications for School Data unless law assigns responsibility otherwise.
10. Assessments and Consultation
SMIK-Af will reasonably assist with data-protection and child-rights impact assessments related to the service. The School must assess high-risk uses, including health data, live location, large-scale child records, monitoring, and new integrations.
11. Audit and Information
SMIK-Af will provide information reasonably necessary to demonstrate compliance, including available independent reports or questionnaires. On-site audits require reasonable notice, confidentiality, minimal disruption, qualified auditors, and allocation of cost unless a material breach or regulator requires otherwise.
12. Return and Deletion
At termination, SMIK-Af will return or delete School Data as selected by the School and permitted by law. Legal holds, security evidence, accounting records, and backups may be retained under restricted access for the applicable period.
13. Government Requests
SMIK-Af will review government demands for validity, disclose only what is legally required, and notify the School where permitted. Emergency disclosures will be limited to information reasonably necessary to protect life or safety.
14. Priority and Local Addenda
This DPA controls over conflicting general terms for processing School Data. A country-specific addendum controls where mandatory national law requires different terms.