ECOSYS360 LEGAL
Ecosys360 Ecosys360 — Retail & Ops Suite
Sign up

Documents

  • Overview
  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Data Processing Addendum

Legal · v2026-09-29

Data Processing Addendum

Processor terms when you store customer or staff data in Ecosys360.

Last updated 29 September 2026

1. Purpose and incorporation

This Data Processing Addendum (“DPA”) forms part of the agreement between your organisation (“Customer”, “you”) and Flakes Digital Solutions (“Processor”, “we”, “us”) for use of Ecosys360 Retail & Ops Suite (the “Service”).

It sets out how we process personal data on your behalf, as required by the Kenya Data Protection Act, 2019 (the “Act”) and the Data Protection (General) Regulations, 2021. Where the EU or UK GDPR also applies to your processing, we will meet its processor requirements too.

If this DPA conflicts with other terms about personal data, this DPA prevails.

2. Roles and definitions

For personal data you put into or create in your Ecosys360 workspace — for example customer, employee, supplier or shopper records — you are the data controller and we are the data processor.

For platform account data (such as login emails, membership details and our billing records for you), we are an independent controller, as described in the Privacy Policy.

“Personal data”, “sensitive personal data”, “processing”, “data controller”, “data processor”, “data subject” and “personal data breach” have the meanings given in the Act. “Customer Personal Data” means personal data we process for you in the Service.

3. Subject matter, duration, nature and purpose

Subject matter: hosting and processing Customer Personal Data in the modules you enable (such as POS, catalog, HR, payroll, ecommerce and logistics).

Duration: for as long as you use the Service, plus the return and deletion period in section 12.

Nature and purpose: storing, retrieving, displaying, transmitting, backing up and securing data so we can provide, support and maintain the Service according to your configuration and instructions.

Data subjects may include your staff users, employees, retail and wholesale customers, suppliers, online shoppers and anyone else whose data you choose to store.

Types of data depend on your use and may include identity and contact details, KRA PINs, NSSF and SHIF numbers, bank and M-Pesa details, salaries and deductions, purchase history, branch associations and uploaded files.

4. Your responsibilities as controller

You are responsible for having a lawful basis under the Act for the data you store, for telling the people concerned how you use their data (section 29), for obtaining any consents you rely on, and for registering with the Office of the Data Protection Commissioner if the law requires you to.

Before recording sensitive personal data (for example staff medical or sick-leave details) or data about children, you must meet the extra conditions in sections 33 and 44 to 46 of the Act.

You must not instruct us to process data you are not entitled to process.

5. How we process your data

We will process Customer Personal Data only: (a) to provide the Service; (b) on your documented instructions, which include your configuration, API calls and admin actions in the product; and (c) where Kenyan law requires it, in which case we will tell you first unless the law forbids it.

We will not use Customer Personal Data for our own purposes, sell it, or use it to market to your customers or staff.

If we believe an instruction breaks the Act, we will tell you promptly and may decline to follow it.

6. Confidentiality

Everyone we authorise to process Customer Personal Data is bound by a duty of confidentiality.

Our staff access your workspace only as needed for support, security or operations, or when you ask us to (for example to troubleshoot). Such access is logged.

7. Security

As section 41 of the Act requires, we build data protection into the Service and apply technical and organisational measures appropriate to the risk, including:

  • Encryption of data in transit (HTTPS/TLS) and encrypted storage of payment-provider and AI API credentials
  • Authentication, role-based permissions and branch-level access controls in the application
  • Separation between workspaces, so one customer’s data is not exposed to another
  • Password hashing and protection of session credentials
  • Backups, logging and monitoring to detect abuse and security incidents
  • Limiting staff access to what each person needs

8. Sub-processors

You authorise us to use sub-processors to host the Service, deliver email and notifications, process payments, provide analytics and answer AI-assistant requests. Current sub-processors include Contabo (hosting), PostHog (product analytics), Safaricom, Paystack, UMS Pay and KCB (payments), email and push-notification delivery providers, OpenStreetMap (maps), and the AI model providers configured for your workspace.

We bind each sub-processor by written contract to data-protection obligations at least as protective as this DPA, and we remain responsible to you for their performance.

We will give you at least 14 days’ notice of a new or replacement sub-processor that processes Customer Personal Data. You may object on reasonable data-protection grounds by emailing app.flakescapital@gmail.com. If we cannot address your objection, you may end the affected part of the Service without penalty.

9. Transfers outside Kenya

Some sub-processors store or process data outside Kenya (for example hosting in Europe and analytics and AI providers in the United States).

We transfer Customer Personal Data out of Kenya only in line with sections 48 to 50 of the Act: to recipients that give appropriate safeguards (such as written data-protection terms), where the transfer is necessary to provide the Service you have contracted for, or as otherwise permitted. We will give you or the Data Protection Commissioner proof of those safeguards on request.

Sensitive personal data is transferred out of Kenya only where the Act allows, which includes obtaining the data subject’s consent — you are responsible for obtaining that consent for sensitive data you store. Where Kenyan law requires particular data to be processed in Kenya, you must not store it in the Service unless we have agreed a Kenyan hosting arrangement with you in writing.

10. Helping you meet data-subject requests

We will help you, using the product’s features and reasonable additional support, to respond to people who exercise their rights under the Act — to access, correct, delete, restrict, object to or port their data.

If a data subject contacts us directly about Customer Personal Data, we will pass the request to you promptly (normally within 3 working days) and will not answer it ourselves unless you ask us to or the law requires it. You remain responsible for replying within the time limits in the Data Protection (General) Regulations, 2021.

11. Personal data breaches

If we become aware of a personal data breach affecting Customer Personal Data, we will notify you without delay and, where reasonably practicable, within 48 hours, as section 43 of the Act requires of processors. This lets you meet your own duty to notify the Data Protection Commissioner within 72 hours and to tell affected people.

Our notice will include, as far as we know them: what happened, the categories and approximate number of people and records affected, the likely consequences, and the steps we have taken or propose to take. We will send further details as we learn them.

We will cooperate with your investigation and any notification to the Data Protection Commissioner or to affected people. Notifying you is not an admission of fault.

12. Return and deletion

While you use the Service you can export your data with the product’s export and report features.

When your workspace closes, you will have at least 30 days to export your data. After that we will delete Customer Personal Data from active systems within 90 days, and from backups as they rotate, unless Kenyan law requires us to keep it. Anything we must keep remains confidential and is used only for that legal purpose.

You are responsible for keeping any records you are legally required to retain, such as tax records and employee records, for the periods Kenyan law requires. Export them before your workspace closes.

13. Impact assessments, records and audits

We will give you reasonable help with data protection impact assessments under section 31 of the Act and with any consultation with the Data Protection Commissioner about processing in the Service.

We keep records of the processing we carry out for you and will make available the information you reasonably need to show compliance with this DPA, such as security summaries or questionnaire answers, on written request up to once a year (more often after a breach or if required by the Data Protection Commissioner).

On-site audits need reasonable notice, must protect other customers’ data and confidentiality, and are at your cost unless they reveal a material breach of this DPA.

14. Liability

Each party’s liability under this DPA is subject to the limits in the Terms of Service, except where the Act or other law does not allow liability to be limited.

15. Changes

We may update this DPA to reflect changes in the law or in how the Service works. We will give you notice of material changes before they take effect, in the same way as for the Terms of Service.

Last updated: 29 September 2026.

16. Contact

Data protection contact: app.flakescapital@gmail.com, phone +254 717 053 207, Westend Towers, Chiromo Lane, Westlands, Nairobi, Kenya.

Regulator: Office of the Data Protection Commissioner (ODPC), https://www.odpc.go.ke.