Mlatho / Afrikan e-Bank Financial Technologies LLC

Data Processing Agreement

Draft template · July 2026 · mlatho.com/security

Download Markdown Back to Security
This is a draft template for discussion and counsel review. It is not an executed agreement and is not legal advice. For a signed or customized DPA, email data@mlatho.com.

This Data Processing Agreement (“DPA”) forms part of the services agreement between:

Effective date: _______________

1. Purpose and scope

1.1 Processor provides managed AI data services (including annotation, labeling, transcription, content moderation, evaluation, and related human-in-the-loop work) as described in the applicable statement of work or pilot proposal (“Services”).

1.2 This DPA applies only to personal data that Controller provides to Processor, or that Processor processes on Controller’s documented instructions, in connection with the Services (“Client Personal Data”).

1.3 Marketplace end-user personal data processed through app.mlatho.com under Mlatho’s own Privacy Policy is outside the scope of this DPA unless expressly included in a statement of work.

2. Roles

2.1 Controller determines the purposes and means of processing Client Personal Data.

2.2 Processor processes Client Personal Data only as a processor (or equivalent under applicable law) on Controller’s documented instructions, unless required by law.

3. Controller instructions

3.1 Controller instructs Processor to process Client Personal Data solely to deliver the Services, including quality assurance, training of assigned workers on project guidelines, and reporting agreed metrics.

3.2 Processor shall not sell Client Personal Data or use it to train Processor’s own general-purpose models unless the parties agree in writing.

3.3 Additional or changed instructions must be in writing (email acceptable) and may require a change order if they materially expand scope or cost.

4. Confidentiality and personnel

4.1 Processor ensures that persons authorized to process Client Personal Data are bound by confidentiality obligations (contractual or statutory).

4.2 Access is limited on a need-to-know basis using role-based task assignment and project scoping.

4.3 Where required by the statement of work, Processor will put project-specific NDAs in place with assigned workers or subcontractors.

5. Security measures

Processor implements appropriate technical and organizational measures, which may include:

Details of current practices are summarized at mlatho.com/security. Processor may update measures without reducing overall protection.

6. Subprocessors

6.1 Controller authorizes Processor to use subprocessors reasonably required to deliver the Services (for example hosting, email, payment, or workforce delivery partners).

6.2 Processor remains responsible for subprocessors’ performance of obligations under this DPA.

6.3 On written request, Processor will provide a then-current list of material subprocessors used for the engagement.

7. International transfers

7.1 Client Personal Data may be accessed or processed by personnel and systems in the United States, Africa, and other locations as needed to deliver the Services.

7.2 Where a transfer mechanism is required by applicable law (for example standard contractual clauses or equivalent), the parties will execute the appropriate addendum.

8. Assistance with data-subject rights

Taking into account the nature of processing, Processor will reasonably assist Controller in responding to requests to access, correct, delete, or restrict Client Personal Data, or other rights under applicable law, insofar as such data is under Processor’s control.

9. Breach notification

Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Client Personal Data, and will provide information reasonably available to help Controller meet legal notification duties.

10. Retention and deletion

10.1 Processor retains Client Personal Data only for the duration needed to provide the Services and as required by the statement of work or law.

10.2 Upon termination or Controller’s written request, Processor will delete or return Client Personal Data within a mutually agreed period, except copies retained as required by law or for reasonable backup retention then securely deleted.

11. Audits and questionnaires

11.1 Processor maintains a security and compliance program aligned with SOC 2, ISO 27001, and GDPR expectations, and will share current practices, complete reasonable questionnaires, and pursue formal attestations as the program matures.

11.2 Processor will complete reasonable security questionnaires and, where mutually agreed, provide evidence of controls relevant to the Services.

12. Liability and term

Liability caps, indemnities, governing law, and dispute resolution follow the main services agreement unless this DPA expressly states otherwise. This DPA remains in force for as long as Processor processes Client Personal Data under the Services.

13. Signatures

Controller

Name: _________________ Title: _________________ Date: _________

Signature: _________________

Processor — Afrikan e-Bank Financial Technologies LLC

Name: _________________ Title: _________________ Date: _________

Signature: _________________