Belvara

Legal

Data Processing Addendum

The terms governing Belvara’s Processing of Customer Personal Data on behalf of Customers.

Last updated: 5 October 2026 Version 1.0

DPA at a glance

A quick summary of the operating terms. The Data Processing Addendum below contains the complete legal terms.

Clear roles

Customer controls its business purposes and Belvara processes Customer Personal Data on documented instructions.

Security commitments

Belvara maintains technical and organisational measures appropriate to the Services and risks.

Customer control

Customers manage users, permissions, integrations, exports and their own legal responsibilities.

Global transfers

International Processing uses legally recognised transfer safeguards where required.

Customer instructions

Customer controls the purposes and means of its Processing. Belvara processes Customer Personal Data as Processor on documented instructions, subject to this DPA, the applicable agreement and Applicable Data Protection Law.

1.Purpose of this DPA

This Data Processing Addendum (“DPA”) forms part of the agreement between Belvara and the customer or organisation that has entered into an agreement with Belvara for use of the Services. This DPA governs Belvara’s Processing of Personal Data on behalf of Customer in connection with the Services. Belvara is based in Nairobi, Kenya and provides the Services internationally. This DPA operates as Belvara’s global processor agreement. Where Applicable Data Protection Law imposes additional mandatory requirements, those requirements apply to the extent legally applicable.

  • Define the responsibilities of Customer and Belvara when Belvara Processes Personal Data on Customer’s behalf.
  • Document Customer’s instructions to Belvara.
  • Establish requirements concerning confidentiality, security, subprocessors, rights requests, breaches, international transfers, deletion and return of Personal Data.
  • Satisfy applicable controller-processor, business-service-provider, responsible-party-operator or equivalent requirements.
  • Supplement the Belvara Terms of Service and other agreements governing the Services.

2.1.Applicable Data Protection Law

“Applicable Data Protection Law” means privacy, data protection, data security and related laws that legally apply to the Processing of Customer Personal Data under this DPA. Depending on the circumstances, this may include the Kenya Data Protection Act, 2019 and regulations, the EU GDPR, UK Data Protection Law, Swiss data-protection law, the CCPA, other United States state privacy laws, POPIA, Brazil’s LGPD, applicable Canadian, Australian or New Zealand laws and other mandatory privacy or data-protection laws. A law is included only to the extent it legally applies to the relevant Processing.

2.2.Controller

“Controller” means a person or entity that determines the purposes and means of Processing Personal Data, including a business, responsible party or equivalent role under Applicable Data Protection Law.

2.3.Customer Personal Data

“Customer Personal Data” means Personal Data contained in Customer Data that Belvara Processes on behalf of Customer as a Processor in connection with the Services. It does not include Personal Data for which Belvara independently determines the purposes and means of Processing, such as certain account administration, billing, security, fraud-prevention, legal-compliance or direct-relationship data described in the Belvara Privacy Policy.

2.4.Data Subject

“Data Subject” means an identified or identifiable natural person, consumer, household or other person or unit protected by Applicable Data Protection Law.

2.5.Personal Data

“Personal Data” means any information defined as personal data, personal information, personally identifiable information or a substantially equivalent term under Applicable Data Protection Law.

2.6.Personal Data Breach

“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data, to the extent the event constitutes a personal-data breach or substantially equivalent event under Applicable Data Protection Law. It does not include unsuccessful attempts or activity that does not result in unauthorised access, such as unsuccessful login attempts, port scans, blocked attacks or unsuccessful denial-of-service attempts.

2.7.Process or Processing

“Process” and “Processing” have the meanings given under Applicable Data Protection Law and include collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, transmission, disclosure, combination, restriction, erasure and destruction.

2.8.Processor

“Processor” means a person or entity that Processes Personal Data on behalf of a Controller, including a service provider, contractor, operator or equivalent role under Applicable Data Protection Law.

2.9.Services

“Services” means the Belvara products and services governed by the applicable agreement with Customer, including business-management software, dashboards, APIs, integrations and related functionality.

2.10.Subprocessor

“Subprocessor” means a third party engaged by Belvara to Process Customer Personal Data on behalf of Customer in connection with the Services.

3.1.Customer as Controller

Where Customer determines the purposes and means of Processing Customer Personal Data, Customer acts as the Controller. Customer retains control over whether to place Personal Data in the Services; what information is entered, uploaded, imported or connected; which features and integrations are enabled; which users are invited; what permissions they receive; how Customer uses information produced by the Services; when Customer exports information; and when Customer deletes information where deletion controls are available.

3.2.Belvara as Processor

Where Belvara Processes Customer Personal Data solely on Customer’s behalf, Belvara acts as Processor. Belvara will Process Customer Personal Data to provide the Services, on Customer’s documented instructions, as reasonably necessary to secure, maintain, support and operate the Services, as otherwise permitted by this DPA and the underlying agreement, or where Processing is required by applicable law.

3.3.Belvara as Independent Controller

This DPA does not govern Processing for which Belvara acts as an independent Controller. Belvara may act as an independent Controller for Personal Data reasonably required for account administration, billing, direct communications, security, fraud prevention, abuse prevention, legal compliance, protection of Belvara’s rights, corporate administration and other purposes described in the Belvara Privacy Policy. Such Processing is governed by that Privacy Policy and Applicable Data Protection Law.

3.4.Role Reclassification

If Applicable Data Protection Law characterises the parties differently for a particular Processing activity, the parties will be treated according to the legally applicable roles for that activity. Labels used in this DPA do not override mandatory legal classification.

4.1.Documented Instructions

Customer instructs Belvara to Process Customer Personal Data as reasonably necessary to provide, secure, maintain and support the Services in accordance with the agreement, this DPA, Customer’s use and configuration of the Services, settings, feature and integration selections, user and permission settings, support requests, API requests, written instructions and other documented actions taken through the Services. These constitute Customer’s documented instructions for purposes of Applicable Data Protection Law.

4.2.Product Configuration as Instruction

Importing Customer Data, entering Personal Data, syncing another platform, enabling a feature, connecting a payment provider, marketplace, ecommerce, tax or electronic-invoicing service, enabling fulfilment or pickup functionality, inviting an Authorised User, assigning permissions, requesting a report, exporting data, using an API, enabling AI or submitting information to support are instructions to Belvara to Process Customer Personal Data as reasonably necessary for the selected operation.

4.3.Instructions Outside the Services

If Customer requests Processing materially different from the Processing supported by the Services or this DPA, Belvara may decline, require an amendment, require additional technical or security review, require additional fees or legal terms, or agree separately. Belvara is not obligated to build custom Processing functionality merely because Customer requests it.

4.4.Unlawful Instructions

Belvara may notify Customer if it reasonably believes an instruction infringes Applicable Data Protection Law. Belvara may suspend or refuse affected Processing where reasonably necessary to avoid violating law, compromising security or materially affecting another person’s rights. Belvara is not required to follow an instruction that would require it to violate applicable law.

4.5.Processing Required by Law

If Belvara is legally required to Process Customer Personal Data other than according to Customer’s documented instructions, Belvara may do so. Where legally permitted, Belvara will inform Customer before the Processing and is not required to disclose information where law prohibits disclosure.

5.Details of Processing

The subject matter, duration, nature and purpose of Processing, categories of Data Subjects and types of Personal Data are described in Schedule 1 — Processing Details. Customer may determine additional Processing details through its configuration and use of the Services.

6.1.Customer Compliance

Customer is responsible for complying with its obligations under Applicable Data Protection Law and represents that it has and will maintain all rights, notices, permissions, lawful bases and consents required to collect, use and disclose Customer Personal Data to Belvara, instruct Belvara to Process it, use the Services, permit Authorised Users to access it, connect integrations and otherwise Process it through the Services.

6.2.Privacy Notices

Customer is responsible for providing privacy notices required for its Processing. Belvara’s Privacy Policy does not replace Customer’s obligation to provide its own notices to customers, employees, suppliers or other Data Subjects.

6.3.Lawful Basis

Customer is responsible for determining and documenting an appropriate lawful basis where Applicable Data Protection Law requires one. Belvara does not determine Customer’s lawful basis merely because it provides the Services.

6.4.Data Minimisation

Customer will use reasonable efforts to limit Customer Personal Data submitted to the Services to information reasonably necessary for lawful business purposes and must not use free-text fields, notes, attachments, AI prompts or custom fields as a repository for unnecessary Sensitive Personal Data.

6.5.Accuracy

Customer is responsible for the accuracy and quality of Customer Personal Data under Customer’s control. Belvara does not independently verify its accuracy.

6.6.Sensitive Personal Data

Customer must not submit Sensitive Personal Data unless the relevant Service is designed to support it, Customer has a lawful basis, legally required safeguards are in place and the Processing is permitted under the agreement. Belvara may restrict categories of Sensitive Personal Data for particular Services.

6.7.Prohibited Data

Unless Belvara expressly agrees otherwise in writing, Customer must not use the Services to store or Process data subject to legal or industry requirements that the relevant Service is not designed to support. Belvara may publish product-specific restrictions concerning prohibited or restricted data.

7.1.Customer-Controlled Access

Customer may give employees, contractors, accountants, consultants, agents, business partners or other persons access to Customer Personal Data through features made available by Belvara. Customer controls whom it invites, roles, permissions, accessible locations and categories, permitted actions and when access is changed or revoked.

7.2.Customer Responsibility for Authorised Users

Customer is responsible for ensuring Authorised Users have a lawful reason to access Customer Personal Data, assigning appropriate permissions, applying least privilege where appropriate, reviewing access, promptly revoking access and ensuring users understand applicable confidentiality and privacy obligations.

7.3.Reliance on Permissions

Belvara may rely on permissions, roles and instructions configured by Customer or an authorised administrator unless it has reason to believe they are unauthorised, fraudulent, unlawful or materially unsafe. To the maximum extent permitted by law, Belvara is not responsible for unauthorised internal use caused by Customer granting access, assigning broad permissions, failing to remove a former user, sharing credentials, exporting and redistributing data or directing disclosure, except to the extent directly caused by Belvara’s breach of this DPA or an obligation that cannot legally be limited.

7.4.Access Logs

Where supported, Belvara may maintain logs concerning authentication, account access, user activity, role and permission changes, exports, integrations, administrative activity and relevant security events. Logs may be used for security, support, fraud prevention, compliance, troubleshooting and enforcement.

8.Belvara Personnel

Belvara will ensure that persons authorised to Process Customer Personal Data are subject to appropriate confidentiality obligations, will limit personnel access to persons who reasonably require access for legitimate purposes, and will take reasonable steps appropriate to its size, operations and risk profile to ensure relevant personnel are aware of applicable confidentiality and security obligations.

9.1.Appropriate Security Measures

Belvara will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access or other unlawful Processing. Measures take into account the state of the art, implementation costs, the nature and context of Processing, types of data, foreseeable risks and potential harm.

9.2.Security Measures

Belvara’s security measures may include access controls, authentication, role-based permissions, encryption in transit, encryption at rest where appropriate, secrets and credential management, network controls, logging and monitoring, vulnerability management, backup and recovery, software-development controls, change management, malware protection, incident response, vendor-risk controls, business continuity and availability measures. Additional details are described in Schedule 2.

9.3.Security Evolution

Security measures evolve over time. Belvara may modify them provided the modifications do not materially decrease the overall level of protection for Customer Personal Data during the applicable Service term.

9.4.Customer Security Responsibilities

Customer is responsible for account credentials, user management, administrator selection, role and permission configuration, connected third-party accounts, devices, Customer-controlled networks, exports, copies retained outside Belvara, API credentials and Authorised User actions.

10.1.Notification to Customer

If Belvara confirms a Personal Data Breach affecting Customer Personal Data, Belvara will notify Customer without undue delay and within any mandatory timeframe applicable to Belvara as Processor through an appropriate channel associated with Customer’s account or designated contact.

10.2.Information Provided

To the extent reasonably available and legally appropriate, notification may include the nature of the breach, categories of affected data and Data Subjects, likely consequences, measures taken or proposed to address it and mitigate effects, and a contact point for more information. Information may be provided in phases.

10.3.No Admission

Notification of a security incident or Personal Data Breach does not constitute an admission of fault, negligence, liability, applicability of a particular law or waiver of a defence.

10.4.Customer Notifications

Unless Applicable Data Protection Law requires Belvara to notify Data Subjects or authorities directly in its capacity as Processor, Customer is responsible for determining whether notification to Data Subjects, regulators, customers, insurers or others is required. Belvara will provide reasonable assistance as required by law.

10.5.Unsuccessful Security Events

Belvara is not required to notify Customer of unsuccessful attacks or security events that do not result in a Personal Data Breach unless notification is otherwise legally required.

11.Data Subject Requests

Customer is primarily responsible for responding to Data Subject requests concerning Customer Personal Data, including access, correction, deletion, restriction, objection, portability, opt-out, limitation of Processing and other rights. If Belvara receives a request relating to Customer Personal Data for which Customer is Controller, Belvara may redirect the Data Subject, notify Customer, provide Customer with the request or take another appropriate action. Taking into account the nature of Processing, Belvara will provide reasonable assistance through appropriate technical and organisational measures where required. Extraordinary assistance may be charged at reasonable rates unless law prohibits those charges.

12.Regulatory and Compliance Assistance

Taking into account the nature of Processing and information available to Belvara, Belvara will provide reasonable assistance where required concerning security obligations, Personal Data Breaches, data-protection impact assessments, prior consultations with supervisory authorities and other Processor-assistance obligations. Customer remains responsible for its own assessments, lawful bases, records, regulatory responses and compliance.

13.1.General Subprocessor Authorisation

Customer gives Belvara general written authorisation to engage Subprocessors to Process Customer Personal Data for providing, securing, maintaining, supporting and improving the operational reliability of the Services.

13.2.Subprocessor List

Belvara maintains a current Belvara Subprocessor List identifying active Subprocessors, their functions, relevant Processing locations or regions and other information reasonably necessary for Customer’s compliance assessment. The List forms part of Belvara’s data-processing transparency framework.

13.3.Subprocessor Obligations

Belvara will enter into written terms with a Subprocessor requiring data-protection obligations appropriate to the Processing and materially consistent with Belvara’s obligations where required. Belvara remains responsible for delegated Processor obligations to the extent required by Applicable Data Protection Law.

13.4.Changes to Subprocessors

Belvara may add, remove or replace Subprocessors as the Services evolve. Material changes will be published through the Subprocessor List and, where required, notified through an appropriate channel such as email, an account notice or legal update.

13.5.Objections

Where Applicable Data Protection Law gives Customer a right to object to a new Subprocessor, Customer must provide a written, reasonable and evidence-based objection within the applicable period, identify the Subprocessor and explain specific data-protection grounds.

13.6.Resolution of Subprocessor Objections

The parties will attempt in good faith to identify a commercially reasonable solution, which may include additional information or safeguards, an available configuration, disabling an optional feature or termination of the affected Service where no reasonable alternative exists. Belvara is not required to redesign its Services or maintain a separate infrastructure stack unless agreed or legally required.

14.International Data Transfers

Belvara may use infrastructure, personnel and Subprocessors in multiple countries. Where Applicable Data Protection Law restricts international transfers, Belvara will use an applicable legal mechanism where required, including adequacy decisions, standard contractual clauses, approved addenda, international transfer agreements, binding corporate rules, certifications, statutory derogations or another lawful mechanism. Where Kenyan law applies, Belvara will use required safeguards. Where EU, UK, Swiss or Brazilian law applies, the EU SCCs, UK IDTA or Addendum, Swiss modifications, ANPD clauses or another legally recognised mechanism will apply as required. Belvara may review, challenge or narrow government access requests where legally permitted and reasonably practicable.

15.United States Service Provider and Processor Terms

Where an applicable United States privacy law treats Belvara as a service provider, contractor, processor or equivalent role, Customer discloses Customer Personal Data only for the limited and specified purposes in this DPA, the agreement, Customer configuration and documented instructions. To the extent required, Belvara will not sell or share Customer Personal Data in that capacity, will not retain, use or disclose it outside those purposes, will provide equivalent privacy protection, and will cooperate with reasonable monitoring, remediation, cybersecurity-audit and risk-assessment requirements subject to confidentiality, security, privilege and trade-secret protections.

16.Audits and Compliance Information

Upon reasonable request and subject to confidentiality protections, Belvara will make available information reasonably necessary to demonstrate compliance with Processor obligations, which may include written security information, policies, compliance summaries, questionnaires, certifications, audit reports, penetration-test summaries or third-party assessments. Customer will first use generally available information, and any custom audit must be limited, reasonable, secure, non-disruptive and no more frequent than necessary. Customer bears its own audit costs and may be charged reasonable costs for extensive custom work unless prohibited by law. Nothing limits a regulator’s lawful authority.

17.Data Return, Export and Deletion

Customer may use available functionality to access, correct, export or delete Customer Personal Data where supported. Following termination or expiry, Belvara will delete or return Customer Personal Data in accordance with Customer’s documented instructions, available functionality, documented retention practices, the agreement, this DPA and Applicable Data Protection Law. Belvara may retain data for tax, accounting, fraud prevention, security, disputes, claims, regulatory requirements or legal holds. Data may remain in secure backups until the normal backup lifecycle completes, and technically isolated data may be restricted until deletion is feasible.

18.Customer Exports and Data After Disclosure

Belvara’s Processor obligations apply while Customer Personal Data is Processed by Belvara on Customer’s behalf. Once Customer exports or downloads data, sends it to another party, grants a third party direct access, sends it through a Customer-selected integration or otherwise causes it to leave Belvara-controlled Processing, Customer is responsible for the recipient, destination, security and lawful Processing of that copy, except to the extent Belvara independently remains responsible under Applicable Data Protection Law.

19.Third-Party Integrations

Connecting the Services to a third-party product or service is Customer’s instruction to transmit, receive or otherwise Process Customer Personal Data as reasonably necessary to operate that integration. An integration provider may act as Customer’s Processor, Customer’s independent Controller, Belvara’s Subprocessor or another legally recognised role. Customer is responsible for assessing selected providers, reviewing terms and practices, determining lawful basis, configuring permissions and ensuring disclosures are lawful.

20.AI-Enabled Processing

When Customer enables or uses an AI-enabled feature, Customer instructs Belvara to Process Customer Personal Data submitted to or made available to that feature as reasonably necessary. Approved AI model, hosting and infrastructure providers may act as Subprocessors. Belvara does not instruct an AI Subprocessor to use Customer Personal Data submitted through Belvara to train a general-purpose model for that provider’s independent purposes unless Customer expressly authorises it or a lawful arrangement is clearly disclosed. Customer must not submit restricted data unless the feature is designed for it, the Processing is lawful and the agreement permits it. Customer remains responsible for reviewing AI outputs.

21.Confidentiality of Customer Personal Data

Belvara will treat Customer Personal Data as confidential information subject to the confidentiality provisions of the applicable agreement. Belvara may disclose it where Customer instructs disclosure, disclosure is necessary to an authorised Subprocessor, disclosure is required by law, disclosure is reasonably necessary to protect security or prevent fraud where legally permitted or another lawful basis expressly permitted by the agreement applies.

22.Records and Accountability

Belvara will maintain records concerning its Processing activities where required by Applicable Data Protection Law. Customer will maintain its own records and accountability documentation where required. Neither party’s compliance documentation relieves the other of independent legal obligations.

23.Data Protection Officers and Representatives

Where Applicable Data Protection Law requires Belvara to appoint a Data Protection Officer, EU representative, UK representative, local privacy representative or another designated contact, Belvara will make the details available as legally required. Customer is independently responsible for determining whether it must make such appointments.

24.Regulatory Communications

If a supervisory authority contacts Belvara specifically concerning Customer’s Processing, Belvara may notify Customer where legally permitted. Customer will reasonably cooperate where its Processing is relevant to a regulatory inquiry involving Belvara. Belvara may communicate directly with regulators where legally required or appropriate.

25.Customer Warranties Concerning Instructions

Customer warrants that its documented instructions comply with Applicable Data Protection Law, do not require Belvara to violate law, are within Customer’s legal authority, do not infringe another person’s rights and are consistent with Customer’s notices, consents and lawful bases. Customer is responsible for claims arising from unlawful instructions, subject to the applicable agreement.

26.Liability

The liability exclusions, limitations, caps, indemnities and dispute-resolution provisions in the applicable Belvara Terms of Service or other governing agreement apply to this DPA unless this DPA expressly states otherwise or Applicable Data Protection Law prohibits their application. This DPA does not create liability beyond non-waivable legal liability or liability expressly accepted in the applicable agreement. To the maximum extent permitted by law, Belvara is not responsible for incidents caused by Customer’s unlawful instructions, unsecured credentials, misconfigured permissions, failure to revoke access, insecure devices or networks, exports, disclosures, independent integrations, misuse or Authorised Users, except to the extent Belvara independently caused or contributed to the incident.

27.Indemnification

Indemnification obligations relating to Customer Personal Data are governed by the applicable Terms of Service or other agreement. Customer remains responsible, to the extent provided in that agreement and permitted by law, for third-party claims arising from unlawful collection, missing notices, lack of lawful basis, unlawful instructions or disclosures, unlawful use of the Services or Authorised Users.

28.Conflicts

If this DPA conflicts with another agreement, an applicable mandatory transfer mechanism controls for matters governed by it; this DPA controls matters specifically concerning Belvara’s Processor Processing; a negotiated written agreement expressly overriding this DPA controls to the extent it clearly identifies the provision; and the Terms of Service or other governing agreement controls other matters.

29.Term

This DPA becomes effective when Customer becomes subject to an agreement incorporating it or the parties otherwise agree it applies. It remains in effect for as long as Belvara Processes Customer Personal Data on behalf of Customer, including legally required retention.

30.Termination

Termination of the underlying Services does not terminate provisions that by their nature must continue while Belvara retains Customer Personal Data. Confidentiality, security, legal retention, transfer safeguards, liability, regulatory cooperation and deletion provisions survive to the extent necessary.

31.Changes to this DPA

Belvara may update this DPA where reasonably necessary to reflect changes in law, regulatory guidance, transfer mechanisms, Services, features, subprocessors, security practices, legal structure or compliance needs. Belvara will provide notice of material changes where required and will not use an update to materially reduce mandatory data-protection obligations during an existing contractual commitment.

32.Electronic Acceptance

This DPA may be accepted electronically. Customer’s acceptance of an agreement incorporating this DPA constitutes acceptance. Electronic records may evidence acceptance, account identity, version, date, instructions and other contractual matters to the extent permitted by law.

33.Governing Law and Disputes

Except where an applicable transfer mechanism or mandatory privacy law requires otherwise, this DPA is governed by the governing-law and dispute-resolution provisions of the applicable Terms of Service or other governing agreement. Nothing restricts a supervisory authority’s non-waivable jurisdiction.

34.Contacts

Belvara, Nairobi, Kenya. Privacy and data protection: privacy@belvara.co.ke. Security incidents and vulnerability reports: security@belvara.co.ke. Formal legal notices: legal@belvara.co.ke. Customer support: support@belvara.co.ke. General enquiries: hello@belvara.co.ke.

35.Publication Status

This is Belvara’s production Data Processing Addendum for Customers whose use of the Services involves Belvara Processing Customer Personal Data on their behalf. Current production Subprocessors are identified in the Belvara Subprocessor List. Belvara may update this DPA where necessary to reflect changes in Applicable Data Protection Law, approved transfer mechanisms, the Services or Belvara’s data-processing practices. Material changes will be handled in accordance with the applicable agreement and law.

Schedule 1.Processing Details

Subject matter: Belvara Processes Customer Personal Data to provide, operate, secure, maintain and support the Services selected and configured by Customer. Duration: Processing continues while Customer uses the relevant Services, data remains in the Services, Belvara is required or permitted to retain it or another period is required by the agreement or Applicable Data Protection Law. Nature and purposes: Processing may include collection, receipt, recording, organisation, storage, hosting, retrieval, display, calculation, analysis, matching, reconciliation, transmission, synchronisation, report and document generation, AI-assisted processing, restriction, export and deletion to provide functionality, maintain business records, support authorised collaboration, operate integrations, provide support, secure the Services, prevent fraud and meet legal obligations. Data Subjects may include owners, directors, employees, contractors, Authorised Users, administrators, customers, buyers, recipients, payers, suppliers, merchants, fulfilment contacts, business partners and other individuals lawfully processed by Customer. Data may include identity and contact data, addresses, orders, purchases, products, prices, returns, refunds, balances, payment references and status, CRM and supplier records, roles, permissions, logs, tax records, support communications, AI prompts, files, context, outputs and feedback. Belvara’s ordinary Services are not intended to require mobile-money PINs, online-banking passwords or full payment-card authentication credentials.

Schedule 2.Technical and Organisational Measures

Belvara maintains measures designed to provide security appropriate to the risks associated with the Services and Customer Personal Data. These include access control and least privilege; credential security and secrets management; encryption in transit and at rest where appropriate; infrastructure security and environment separation; secure development, code review, dependency and vulnerability management; logging and monitoring; malware and threat protection; backup, recovery and business continuity; incident response; personnel confidentiality and awareness; vendor and Subprocessor management; data minimisation and retention controls; physical security provided by third-party infrastructure providers where applicable; and materially equivalent or stronger substitutions as Belvara’s architecture evolves.

Schedule 3.Subprocessing

Customer authorises Belvara to use Subprocessors as described in Section 13. Current production Subprocessors are maintained in the Belvara Subprocessor List rather than hard-coded into this DPA. The List may provide provider name, service category, Processing purpose, Processing location where reasonably appropriate and other information needed for Customer’s compliance assessment. Belvara may update the List as providers change and will provide notice of material changes where legally or contractually required.

Schedule 4.International Transfer Terms

This Schedule applies where Applicable Data Protection Law requires an approved transfer mechanism. EU transfers use the EU SCCs as described in Section 14, with roles determining the applicable module and annex information drawn from this DPA, Schedule 1, Schedule 2, the Subprocessor List, Customer account information and order documents. UK, Swiss and Brazil transfer mechanisms apply as described in Section 14. Where another jurisdiction requires contractual safeguards, a legally recognised mechanism may be incorporated to the minimum extent necessary.

Schedule 5.Regional Terms

Where Kenyan law applies, Customer and Belvara perform their Controller and Processor obligations, Belvara follows instructions, maintains Processor security, provides breach notification within applicable timeframes and uses required cross-border safeguards. Where EU GDPR, UK law, CCPA, another U.S. state law, POPIA, LGPD, Canadian, Australian, New Zealand or other mandatory law applies, the parties perform the mandatory obligations legally applicable to their roles, including Article 28 terms, assistance, Subprocessor controls, audit rights, service-provider restrictions, responsible-party/operator duties and transfer safeguards. Nothing voluntarily subjects Belvara to a law that would not otherwise apply.

Schedule 6.Order of Responsibility

Customer decides why Customer Personal Data is used, what data is placed in Belvara, which Data Subjects are recorded, which users receive access, permissions, integrations, reports and exports, communications, lawful basis, retention requirements subject to functionality and law, and business decisions. Belvara decides how the Services are engineered and operated, which infrastructure and Subprocessors are used subject to this DPA, how security is implemented, how Services are maintained, how technical systems perform supported instructions and how Belvara Processes Personal Data where it independently acts as Controller.

Schedule 7.Contact Channels

Privacy and Data Protection: privacy@belvara.co.ke. Security: security@belvara.co.ke. Legal: legal@belvara.co.ke. Support: support@belvara.co.ke. General: hello@belvara.co.ke. Belvara, Nairobi, Kenya.

Something better is coming

is coming as we build Belvara. Explore the waitlist to see what’s next.

Explore the waitlist