Last updated: August 30, 2026

Effective Date: 16.07.2026
Last Updated: 16.07.2026

This Data Processing Agreement ("DPA") forms part of the agreement between FrameLaPay ("FrameLaPay", "Company", "we", "us or "our") and the applicable customer, business, merchant, partner or service provider ("Customer", "Client", "you" or "your") who engages FrameLaPay for services involving the processing of personal data.

This DPA governs the processing of personal data by FrameLaPay on behalf of a Customer where FrameLaPay acts as a Data Processor or Data Controller-to-Processor service provider, as applicable under relevant data-protection laws.

âš ī¸ Where FrameLaPay determines the purposes and means of processing independently, FrameLaPay may act as a Data Controller for that processing.

1. PURPOSE AND SCOPE

This DPA establishes the responsibilities of the parties concerning the processing and protection of personal data in connection with FrameLaPay's services.

It applies where FrameLaPay processes personal data on behalf of the Customer in connection with services including, where applicable:

  • payment processing;
  • payment collection;
  • transfers;
  • account management;
  • identity verification;
  • KYC;
  • fraud prevention;
  • AML/CFT monitoring;
  • transaction monitoring;
  • customer support;
  • merchant services;
  • financial technology services;
  • digital-asset services;
  • analytics;
  • communications; and
  • other services provided by FrameLaPay.

2. DEFINITIONS

For this DPA:

"Applicable Data Protection Law"

Means all applicable laws and regulations governing personal-data processing, privacy and data security, including applicable Nigerian data-protection legislation and, where applicable, laws governing customers or individuals in other jurisdictions.

"Personal Data"

Means information relating to an identified or identifiable natural person.

"Data Subject"

Means an identifiable individual to whom Personal Data relates.

"Controller"

Means the person or organisation determining the purposes and means of processing Personal Data.

"Processor"

Means a person or organisation processing Personal Data on behalf of a Controller.

"Processing"

Includes collecting, recording, organising, storing, accessing, retrieving, using, disclosing, transferring, modifying, analysing, deleting or otherwise handling Personal Data.

"Sub-Processor"

Means a third party engaged by FrameLaPay to process Personal Data on behalf of the Customer.

"Security Incident"

Means an actual or reasonably suspected breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access to Personal Data.

3. ROLE OF THE PARTIES

Depending on the particular service:

  • the Customer may act as Data Controller;
  • FrameLaPay may act as Data Processor;
  • FrameLaPay may act as Data Controller for certain independent processing activities; or
  • another regulated financial institution or service provider may act as Controller or Processor.

The parties' respective roles shall depend on the nature and purpose of the relevant processing.

4. PROCESSING INSTRUCTIONS

Where FrameLaPay acts as a Processor, FrameLaPay shall process Personal Data only:

  • according to the Customer's documented instructions;
  • as necessary to provide the agreed services;
  • as required by applicable law; or
  • as otherwise expressly permitted under the agreement.

FrameLaPay shall not knowingly process Personal Data for unrelated purposes without an appropriate legal basis.

5. LEGAL REQUIREMENTS

FrameLaPay shall comply with applicable data-protection laws when processing Personal Data.

Where FrameLaPay is required by law to process Personal Data beyond the Customer's documented instructions, FrameLaPay shall, where legally permitted, inform the Customer of that requirement.

6. CUSTOMER RESPONSIBILITIES

The Customer is responsible for:

  • determining the lawful purpose of processing;
  • identifying an appropriate legal basis;
  • providing appropriate privacy notices;
  • obtaining required consents where applicable;
  • ensuring Personal Data supplied to FrameLaPay is accurate;
  • ensuring that instructions provided to FrameLaPay are lawful; and
  • responding to Data Subject requests where the Customer acts as Controller.

7. DATA MINIMISATION

FrameLaPay shall seek to process only Personal Data reasonably necessary for the relevant service.

The categories of information processed may include, depending on the service:

  • name;
  • email address;
  • telephone number;
  • address;
  • date of birth;
  • identification information;
  • account information;
  • payment information;
  • transaction information;
  • device information;
  • IP address;
  • verification information;
  • beneficial ownership information;
  • KYC information;
  • fraud-risk information; and
  • other information necessary for the service.

8. SPECIAL CATEGORIES OF DATA

Where sensitive or specially protected Personal Data is processed, the parties shall implement appropriate safeguards required by applicable law.

Such information may include, where legally necessary:

  • biometric information;
  • identification information;
  • financial information;
  • authentication information; and
  • information requiring enhanced protection.

9. DATA SUBJECT RIGHTS

Depending on applicable law, Data Subjects may have rights including:

  • right to access;
  • right to correction;
  • right to deletion;
  • right to restriction;
  • right to object;
  • right to data portability;
  • right to withdraw consent where processing is based on consent; and
  • other legally applicable rights.

10. DATA SUBJECT REQUESTS

Where FrameLaPay receives a Data Subject request relating to Personal Data processed on behalf of the Customer, FrameLaPay shall, where appropriate:

  • notify the Customer;
  • assist the Customer in responding;
  • provide relevant information;
  • correct information where instructed; or
  • delete or restrict processing where legally required.

FrameLaPay may respond directly where required by applicable law.

11. CUSTOMER INSTRUCTIONS

The Customer may issue reasonable written instructions concerning:

  • access;
  • correction;
  • deletion;
  • restriction;
  • export;
  • retention; and
  • other lawful processing requirements.

Instructions that materially change the agreed scope of services may be subject to additional technical or commercial requirements.

12. DATA SECURITY

FrameLaPay shall implement reasonable technical and organisational measures designed to protect Personal Data against:

  • unauthorised access;
  • accidental loss;
  • destruction;
  • alteration;
  • disclosure;
  • misuse;
  • unauthorised processing; and
  • other security threats.

13. TECHNICAL SECURITY MEASURES

Depending on the nature of the service, security controls may include:

  • encryption;
  • authentication;
  • multi-factor authentication;
  • access controls;
  • role-based permissions;
  • network security;
  • vulnerability management;
  • logging;
  • monitoring;
  • backups;
  • secure development practices;
  • endpoint protection;
  • incident response procedures; and
  • security testing.

14. ACCESS CONTROL

Access to Personal Data shall be limited to authorised personnel who require access for legitimate business purposes.

FrameLaPay may implement:

  • least-privilege access;
  • role-based access;
  • privileged-account controls;
  • authentication requirements;
  • access logging; and
  • periodic access reviews.

15. EMPLOYEE CONFIDENTIALITY

Personnel authorised to process Personal Data shall be subject to appropriate confidentiality obligations.

Access shall be limited according to business need.

16. DATA BREACHES

FrameLaPay shall maintain procedures designed to identify, investigate, contain and respond to Security Incidents.

Where FrameLaPay becomes aware of a Security Incident affecting Personal Data processed on behalf of the Customer, FrameLaPay shall notify the Customer without undue delay, subject to applicable legal restrictions.

17. SECURITY INCIDENT NOTICE

Where reasonably available, a Security Incident notification may include:

  • nature of the incident;
  • categories of affected data;
  • approximate number of affected individuals;
  • potential consequences;
  • containment measures;
  • remediation measures; and
  • contact information for relevant personnel.

FrameLaPay may provide information progressively where all information is not immediately available.

18. CUSTOMER RESPONSIBILITY FOR BREACH NOTIFICATION

Where the Customer is the Controller, the Customer remains responsible for determining whether notification to:

  • Data Subjects;
  • regulators;
  • customers;
  • law-enforcement authorities; or
  • other parties

is required under applicable law.

FrameLaPay shall reasonably assist the Customer where appropriate.

19. SUB-PROCESSORS

FrameLaPay may engage Sub-Processors to support its services.

Examples may include providers for:

  • cloud hosting;
  • identity verification;
  • KYC;
  • payment processing;
  • fraud detection;
  • transaction monitoring;
  • blockchain analytics;
  • customer communications;
  • customer support;
  • analytics;
  • cybersecurity; and
  • infrastructure.

20. SUB-PROCESSOR RESPONSIBILITY

FrameLaPay shall seek to impose appropriate data-protection obligations on Sub-Processors.

FrameLaPay remains responsible for the performance of its contractual obligations relating to Personal Data processed through authorised Sub-Processors, subject to the terms of the applicable agreement and law.

21. SUB-PROCESSOR CHANGES

FrameLaPay may add or replace Sub-Processors where reasonably necessary to operate or improve its services.

Where legally required, customers may be provided with appropriate notice of material changes.

22. INTERNATIONAL DATA TRANSFERS

Personal Data may be processed or stored outside the country in which it was collected.

Where international transfers occur, FrameLaPay shall seek to implement appropriate safeguards required by applicable law.

23. CROSS-BORDER PROCESSING

Cross-border processing may be necessary where FrameLaPay uses:

  • international cloud infrastructure;
  • global payment networks;
  • identity-verification providers;
  • fraud-monitoring systems;
  • customer-support platforms; or
  • other international technology providers.

24. REGULATORY DISCLOSURES

FrameLaPay may disclose Personal Data where required by law or valid legal process.

Recipients may include:

  • regulators;
  • courts;
  • law-enforcement authorities;
  • financial-intelligence authorities;
  • tax authorities;
  • financial institutions; and
  • other competent authorities.

25. FINANCIAL-CRIME COMPLIANCE

FrameLaPay may process Personal Data for:

  • KYC;
  • AML;
  • CFT;
  • sanctions screening;
  • fraud prevention;
  • transaction monitoring;
  • suspicious-activity investigations; and
  • regulatory reporting.

Such processing may be required by law and may therefore not depend on customer consent.

26. AUTOMATED PROCESSING

FrameLaPay may use automated technologies to assist with:

  • fraud detection;
  • identity verification;
  • transaction monitoring;
  • risk assessment;
  • sanctions screening;
  • security;
  • account protection; and
  • financial-crime detection.

Where applicable law provides rights concerning automated decision-making, FrameLaPay shall implement appropriate safeguards.

27. ARTIFICIAL INTELLIGENCE

FrameLaPay may use artificial intelligence or machine-learning technologies as part of its technology and risk-management infrastructure.

Such technologies may assist with:

  • fraud detection;
  • anomaly detection;
  • transaction monitoring;
  • customer support;
  • cybersecurity;
  • risk assessment; and
  • operational analysis.

🤖 AI systems shall not be used to circumvent applicable data-protection requirements.

28. DATA ACCURACY

The Customer shall take reasonable steps to ensure that Personal Data supplied to FrameLaPay is accurate and up to date.

FrameLaPay may rely on information provided by the Customer unless it has reason to believe that the information is inaccurate.

29. DATA RETENTION

FrameLaPay shall retain Personal Data for as long as reasonably necessary to:

  • provide services;
  • comply with legal obligations;
  • meet regulatory requirements;
  • resolve disputes;
  • prevent fraud;
  • maintain transaction records;
  • enforce agreements; and
  • protect legal rights.

30. LEGAL RETENTION REQUIREMENTS

Certain financial, transaction and KYC records may need to be retained for periods required by applicable law.

Deletion requests may therefore be subject to legal or regulatory retention requirements.

31. DELETION OR RETURN OF DATA

Upon termination of applicable services, FrameLaPay shall, subject to legal retention requirements:

  • delete Personal Data;
  • return Personal Data;
  • anonymise Personal Data; or
  • otherwise handle the information according to the Customer's lawful instructions.

32. BACKUPS

Personal Data may remain temporarily within secure backup systems after deletion.

Such information shall be subject to appropriate security controls and shall be deleted or overwritten according to applicable backup-retention procedures.

33. AUDIT RIGHTS

Where required by applicable law, the Customer may request reasonable information demonstrating FrameLaPay's compliance with applicable data-protection obligations.

Audits shall:

  • occur on reasonable notice;
  • avoid unreasonable disruption;
  • respect confidentiality;
  • not expose other customers' information; and
  • take account of available independent audit or certification reports.

34. SECURITY ASSESSMENTS

FrameLaPay may maintain security assessments and documentation concerning:

  • information-security controls;
  • access controls;
  • vulnerability management;
  • incident response;
  • data protection;
  • business continuity; and
  • third-party risk.

35. CONFIDENTIALITY

Each party shall protect confidential information received from the other party.

Confidential information shall not be disclosed except:

  • to authorised personnel;
  • to approved service providers;
  • as required by law; or
  • with the other party's permission.

36. DATA PROCESSING INSTRUCTIONS

Where FrameLaPay believes an instruction violates applicable data-protection law, FrameLaPay may notify the Customer.

FrameLaPay may decline an unlawful instruction where required by law.

37. DATA PROTECTION OFFICER

Where required by applicable law, FrameLaPay may appoint a Data Protection Officer or designated privacy professional.

Contact information may be published in the FrameLaPay Privacy Policy or on the FrameLaPay website.

38. DATA PROTECTION IMPACT ASSESSMENTS

Where appropriate, FrameLaPay may conduct or assist with Data Protection Impact Assessments ("DPIAs") for processing activities presenting significant privacy risks.

39. PRIVACY BY DESIGN

FrameLaPay seeks to incorporate privacy and security considerations into the design of its technology and services.

This may include:

  • data minimisation;
  • access restrictions;
  • encryption;
  • retention controls;
  • privacy settings; and
  • secure development practices.

40. DATA PROTECTION BY DEFAULT

Where reasonably practicable, FrameLaPay seeks to configure systems to limit Personal Data access and processing to what is necessary for the relevant service.

41. CUSTOMER DATA OWNERSHIP

Except where otherwise agreed, the Customer retains its rights in Personal Data supplied to FrameLaPay.

📌 This DPA does not transfer ownership of Customer Personal Data to FrameLaPay.

42. FRAMELAPAY'S INDEPENDENT PROCESSING

Nothing in this DPA prevents FrameLaPay from processing information independently where such processing is necessary for:

  • fraud prevention;
  • AML/CFT;
  • sanctions compliance;
  • regulatory reporting;
  • cybersecurity;
  • legal compliance;
  • dispute resolution;
  • service security; or
  • other lawful purposes.

In such circumstances, FrameLaPay may act as an independent Controller.

43. AGGREGATED AND ANONYMISED DATA

FrameLaPay may create aggregated or anonymised information that does not reasonably identify individuals.

Where permitted by law, FrameLaPay may use such information for:

  • analytics;
  • research;
  • product improvement;
  • security;
  • business intelligence; and
  • service development.

44. PAYMENT DATA

Where payment services are provided, Personal Data may be shared with:

  • banks;
  • payment processors;
  • card networks;
  • financial institutions;
  • merchants;
  • payment gateways; and
  • other relevant service providers.

Only information reasonably necessary for the relevant transaction should be disclosed.

45. KYC DATA

KYC information may be shared with authorised financial institutions, identity-verification providers and other service providers where necessary to:

  • verify identity;
  • comply with AML requirements;
  • prevent fraud;
  • comply with regulatory requirements; or
  • provide the requested service.

46. DATA SECURITY INCIDENT COOPERATION

The parties shall reasonably cooperate in investigating and responding to Security Incidents affecting Personal Data.

Cooperation may include:

  • sharing relevant information;
  • identifying affected systems;
  • containing incidents;
  • investigating root causes;
  • implementing remediation; and
  • supporting legally required notifications.

47. BUSINESS CONTINUITY

FrameLaPay may maintain business-continuity and disaster-recovery procedures designed to protect the availability and integrity of systems containing Personal Data.

48. DATA RECOVERY

Where appropriate, FrameLaPay may use backups and disaster-recovery systems to restore data following:

  • system failures;
  • cybersecurity incidents;
  • infrastructure failures;
  • accidental deletion; or
  • other operational disruptions.

49. TERMINATION

This DPA shall remain effective for as long as FrameLaPay processes Personal Data on behalf of the Customer.

Termination of the primary service agreement shall not automatically eliminate obligations relating to:

  • confidentiality;
  • data security;
  • legal retention;
  • regulatory compliance; or
  • unresolved Security Incidents.

50. SURVIVAL

Provisions concerning:

  • confidentiality;
  • security;
  • data retention;
  • legal compliance;
  • liability;
  • dispute resolution; and
  • other provisions intended to survive

shall continue after termination where applicable.

51. LIABILITY

Each party shall remain responsible for its obligations under applicable data-protection law.

Nothing in this DPA shall exclude liability that cannot legally be excluded.

52. CHANGES TO THIS DPA

FrameLaPay may update this DPA where reasonably necessary to reflect:

  • changes in law;
  • regulatory requirements;
  • technological developments;
  • changes to FrameLaPay's services;
  • changes to Sub-Processors; or
  • changes to data-processing practices.

Where required, customers will receive appropriate notice.

53. CONFLICT WITH OTHER AGREEMENTS

If there is a conflict between this DPA and another agreement concerning the same Personal Data processing activity, the parties shall interpret the documents to give effect to applicable data-protection requirements.

Where applicable law requires a specific provision to prevail, that legal requirement shall apply.

54. GOVERNING LAW

This DPA shall be governed by applicable law and, subject to mandatory legal requirements, the laws of the Federal Republic of Nigeria.

Where a customer is located in another jurisdiction and mandatory data-protection law applies, the parties may enter into additional provisions or transfer mechanisms required by that jurisdiction.

55. CONTACT INFORMATION

FrameLaPay

Email: contact.us@framelapay.com

Phone: +234 706 609 9909

Address:

2, Barracks Road,
Car wash bus stop off Abule-Odu,
Egbeda Isheri-Olofin,
Lagos State, Nigeria.

SCHEDULES

SCHEDULE 1 — DESCRIPTION OF PROCESSING

Subject Matter

Processing of Personal Data necessary to provide FrameLaPay's technology and financial services.

Duration

For the duration of the applicable customer relationship and any additional period required by applicable law.

Nature of Processing

Processing may include:

  • collection;
  • verification;
  • storage;
  • retrieval;
  • analysis;
  • transmission;
  • monitoring;
  • authentication;
  • fraud detection;
  • payment processing;
  • transaction monitoring;
  • customer support; and
  • deletion.

Purpose

Personal Data may be processed for:

  • account administration;
  • payment processing;
  • identity verification;
  • KYC;
  • AML/CFT;
  • fraud prevention;
  • security;
  • customer support;
  • regulatory compliance;
  • transaction processing; and
  • service delivery.

SCHEDULE 2 — CATEGORIES OF DATA SUBJECTS

Depending on the services provided:

  • customers;
  • prospective customers;
  • merchants;
  • business representatives;
  • account holders;
  • beneficiaries;
  • payers;
  • recipients;
  • employees;
  • directors;
  • shareholders;
  • beneficial owners;
  • authorised representatives; and
  • other individuals whose information is necessary for the service.

SCHEDULE 3 — CATEGORIES OF PERSONAL DATA

Depending on the service:

  • identification data;
  • contact information;
  • address information;
  • account information;
  • financial information;
  • transaction information;
  • KYC/KYB information;
  • device information;
  • IP information;
  • authentication information;
  • fraud-risk information;
  • business information;
  • biometric information where legally permitted and necessary; and
  • communications with FrameLaPay.

SCHEDULE 4 — SUB-PROCESSORS

FrameLaPay may maintain a current list of material Sub-Processors.

The list may include providers responsible for:

Category Purpose
Cloud hosting Infrastructure and data storage
Identity verification KYC
Business verification KYB
Payment processing Payment execution
Fraud detection Fraud prevention
AML monitoring Financial-crime compliance
Blockchain analytics Digital-asset risk monitoring
Communications Email/SMS/notifications
Customer support Customer service
Cybersecurity Security monitoring
Analytics Service performance

FrameLaPay may update this list as its technology infrastructure changes.

2, Barracks Road, Egbeda Isheri-Olofin, Lagos