Data Processing Agreement
The AfriScore Data Processing Agreement template for institutional partners.
The AfriScore Data Processing Agreement (DPA) governs the processing of personal data by AfriScore on behalf of institutional customers. It defines the scope, purpose, and duration of processing; the security measures applied; the rights of data subjects; and the obligations of both parties.
The current DPA template is available for download below. It is intended for institutional partners under pilot or commercial agreement.
Download
The DPA is currently issued as a Word document. A signed PDF version is generated per partner during onboarding and returned to the institution for countersignature.
To request the current DPA template, contact legal@afriscore.africa.
Structure of the agreement
The DPA follows the standard structure used by financial institutions operating under GDPR-inspired frameworks in Africa.
1. Parties
The agreement is between the institution (the "Data Controller") and AfriScore (the "Data Processor").
2. Subject matter and duration
- Subject matter: Processing of applicant data for the purpose of producing a credit decision
- Duration: The term of the pilot or commercial agreement, plus the retention period specified in the agreement
- Nature and purpose: Scoring, explainability generation, and audit logging
3. Categories of personal data
- Mobile money transaction metadata
- Airtime purchase patterns
- Device metadata
- Applicant-identified information submitted by the institution
AfriScore does not process special categories of personal data. We do not process data revealing racial or ethnic origin, political opinions, religious beliefs, health data, or biometric data for identification purposes.
4. Categories of data subjects
- Loan applicants
- Borrowers of the institution
5. Processor obligations
- Process personal data only on documented instructions from the institution
- Ensure persons authorized to process personal data have committed to confidentiality
- Implement appropriate technical and organizational security measures
- Assist the institution in responding to data subject rights requests
- Assist the institution with security breach notifications
- Delete or return personal data at the end of the processing period
- Make available all information necessary to demonstrate compliance
6. Subprocessors
The DPA authorizes the subprocessors listed on the Subprocessors page and requires AfriScore to notify the institution of any intended change.
7. International transfers
Where personal data is transferred outside the institution's jurisdiction, appropriate safeguards apply. On-premise deployments eliminate cross-border transfers entirely.
8. Security measures
Security measures are documented in detail on the Security page and are incorporated by reference into the DPA.
9. Data subject rights
AfriScore assists the institution in fulfilling its obligations to respond to data subject rights requests, including access, rectification, erasure, restriction, portability, and objection.
10. Breach notification
AfriScore notifies the institution within 72 hours of becoming aware of a personal data breach.
11. Audit rights
The institution may audit AfriScore's compliance with the DPA, either directly or through an appointed auditor, subject to reasonable notice and confidentiality obligations.
12. Termination
Upon termination, AfriScore deletes or returns all personal data in accordance with the institution's instructions, unless retention is required by law.
Governing law
The DPA is governed by the law of the jurisdiction where the institution is incorporated, unless the parties agree otherwise. For CEMAC-based institutions, this is typically the OHADA Uniform Act and the national law of the institution's country.
Questions
For questions about the DPA, or to request a copy for review, contact legal@afriscore.africa.
For security-related questions about the DPA, contact security@afriscore.africa.