Data Processing Agreement
Last updated: May 5, 2026
This DPA applies automatically to all Business Owners using the Turtle Rewards platform. No separate signature is required.
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Turtle Rewards Limited (“Processor”), a company registered in Kenya (PVT-3QUDQB5J) and registered with the Office of the Data Protection Commissioner (ODPC ID: 268-0990-5797), and the Business Owner (“Controller”) who uses the Turtle Rewards platform. This DPA is entered into pursuant to the Kenya Data Protection Act, 2019 (“KDPA”) and, where applicable, the EU General Data Protection Regulation (“GDPR”).
1. Definitions
- “Controller” means the Business Owner who determines the purposes and means of processing customer personal data through the platform.
- “Processor” means Turtle Rewards Limited, which processes personal data on behalf of the Controller.
- “Personal Data” means any information relating to an identified or identifiable natural person, as defined by the KDPA.
- “Customer Data” means personal data of the Controller's customers that is processed through the platform, including names, phone numbers, email addresses, transaction history, loyalty points, and engagement data.
- “Sub-processor” means any third party engaged by the Processor to process Customer Data.
2. Scope and Purpose of Processing
The Processor processes Customer Data solely to provide the Turtle Rewards platform services, including:
- Managing customer enrolment and loyalty profiles
- Processing loyalty point transactions, stamps, and offers
- Delivering transactional and marketing communications (SMS, WhatsApp, email, push)
- Generating analytics and business insights
- Fraud detection and security monitoring
- Providing customer support tools
The categories of data subjects are the Controller's customers. The types of personal data processed include names, phone numbers, email addresses, transaction records, location data (from QR scans), device tokens, and behavioural data (visit frequency, points activity).
3. Processor Obligations
The Processor shall:
- Process Customer Data only on the Controller's documented instructions, unless required by law.
- Ensure that persons authorised to process Customer Data have committed themselves to confidentiality.
- Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including encryption in transit, access controls, audit logging, and regular security assessments.
- Not engage another processor (sub-processor) without prior written authorisation of the Controller. The current list of sub-processors is set out in Section 5.
- Assist the Controller in responding to data subject requests (access, rectification, erasure, portability) through the platform's built-in tools.
- Assist the Controller in ensuring compliance with data security, breach notification, and data protection impact assessment obligations.
- At the Controller's choice, delete or return all Customer Data upon termination of the Service, and delete existing copies within 30 days unless retention is required by law.
- Make available to the Controller all information necessary to demonstrate compliance with this DPA.
4. Controller Obligations
The Controller shall:
- Ensure there is a lawful basis for processing Customer Data, including obtaining appropriate consent where required.
- Provide clear privacy notices to their customers explaining how data is processed through the Turtle Rewards platform.
- Not submit any special categories of personal data (health, biometric, political, religious data) through the platform.
- Ensure that marketing campaigns sent through the platform comply with applicable anti-spam and consumer protection laws.
- Notify the Processor immediately if they receive a data subject request that relates to Customer Data processed through the platform.
5. Sub-processors
The Controller authorises the Processor to engage the following sub-processors. Each sub-processor is bound by a written agreement that imposes data-protection obligations substantially equivalent to those in this DPA.
5.1 Current sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloud-hosting providers | Application hosting, managed Postgres, managed Redis, S3-compatible file storage | Multi-region (specified per customer on request) |
| Pesapal Holdings | Payment processing (KE / UG / TZ / RW — cards and mobile money) | Kenya |
| Safaricom PLC (M-Pesa Daraja) | M-Pesa STK push and B2C disbursements | Kenya |
| Stripe, Inc. | International card payments | United States |
| Gupshup | WhatsApp Business message delivery | India / United States |
| HostPinnacle | SMS message delivery (Kenya) | Kenya |
| Resend | Transactional email delivery | United States |
| Firebase Cloud Messaging (Google) | Push notification delivery | United States |
| OpenAI, OpCo, LLC | WhatsApp customer-support bot, AI offer suggestions | United States |
| Anthropic, PBC | AI customer-segmentation and churn-prediction insights | United States |
| Functional Software, Inc. (Sentry) | Error tracking and performance monitoring | United States |
5.2 Adding or changing sub-processors
The Processor will notify the Controller in writing (by email to the registered Business Owner email and via the platform notice area) at least 14 daysbefore adding or replacing a sub-processor that processes the Controller's personal data.
The Controller may object to a new or replacement sub-processor on reasonable data-protection grounds within the 14-day notice period. The parties will work together in good faith to resolve the objection — for example, by proposing an alternative sub-processor or restricting the processing in question. If no resolution is reached within a further 14 days:
- the Controller may terminate the affected service for convenience, in which case the Processor will refund any pre-paid fees for the unused portion of the current billing period; or
- the Processor may, at its discretion, decline to engage the proposed sub-processor and continue under the existing arrangement.
Emergency replacement (for example, where an existing sub-processor suffers a security incident or ceases trading) may be made on shorter notice. In that case, the Processor will notify the Controller as soon as reasonably practicable and the same objection / termination rights will apply on a best-efforts timeframe.
6. International Transfers
Where Customer Data is transferred outside Kenya (to sub-processors in the United States or India), the Processor ensures appropriate safeguards are in place as required by the KDPA, including contractual clauses requiring the sub-processor to maintain data protection standards equivalent to those required under Kenyan law.
7. Data Breach Notification
The Processor will notify the Controller without undue delay (and in any event within 48 hours) after becoming aware of a personal data breach affecting Customer Data. The notification will include: the nature of the breach; the categories and approximate number of data subjects affected; the likely consequences; and the measures taken or proposed to address the breach. The Controller is responsible for notifying the ODPC within 72 hours and informing affected data subjects as required by the KDPA.
8. Data Retention and Deletion
Upon termination of the Controller's subscription, the Processor will retain Customer Data for 30 days to allow the Controller to export their data. After 30 days, Customer Data will be deleted or anonymised, except where retention is required by law (e.g., transaction records retained for 7 years for tax compliance). The Controller may request immediate deletion by contacting legal@turtlerewards.club.
9. Audits
The Processor will make available to the Controller, upon reasonable request and with 30 days' notice, information necessary to demonstrate compliance with this DPA. The Controller may conduct an audit (or appoint an independent auditor), subject to confidentiality obligations, at the Controller's expense, no more than once per calendar year.
10. Term and Governing Law
This DPA remains in effect for the duration of the Controller's use of the Turtle Rewards platform and survives termination until all Customer Data has been deleted or returned. This DPA is governed by the laws of the Republic of Kenya.
Contact
Turtle Rewards Limited
Data Processor — ODPC ID: 268-0990-5797
Beach Road Complex, Beach Road, Nyali
Kisauni District, Mombasa County, Kenya
Email: legal@turtlerewards.club