Skip to main content
Data processing agreement

DPA-ready, without pretending we are enterprise-certified yet.

This page explains the contract controls 9jatesters can put in place for paid scopes: NDPA roles, permitted processing, sub-processor notice, deletion timelines, breach notice, and buyer approval gates.

Human contact: Chat on WhatsApp · [email protected]

NDPA
Nigeria Data Protection Act aligned
72h
Target breach notice where duties apply
30d
Sub-processor change notice target

Roles and lawful basis

For buyer projects, the buyer is normally the controller for its customer/product data and 9jatesters acts as processor. Tester account, payout, anti-fraud, and platform safety records are handled as 9jatesters controller records.

  • NDPA controller/processor role map included
  • Purpose limitation for each accepted brief
  • No reuse of buyer session data for model training

Processing scope

The DPA narrows processing to routing testers, collecting consented sessions, generating summaries, producing evidence packs, paying contributors, and handling support/security obligations.

  • Brief-specific categories documented before launch
  • AI-data projects require a separate data licence
  • Sensitive data is avoided unless expressly scoped

Sub-processors

The live sub-processor list is public. Larger-contract buyers receive notice before material changes involving personal data and can object on reasonable security or compliance grounds.

  • Public list at /subprocessors
  • Data residency detail at /trust/data-residency
  • Provider purpose, region, and data categories listed

Security incidents

Confirmed material incidents are triaged, logged, contained, and communicated to affected customers. NDPA-relevant breach notices target 72 hours after confirmation where notification duties apply.

  • Security disclosure path at /security
  • Affected-customer email notices
  • Internal audit log retained for forensics

Deletion and retention

Buyer data deletion follows the engagement terms. Tester account deletion follows the public privacy policy, with fraud-prevention audit records and verification hashes retained where Nigerian legal bases require it.

  • Operational PII redacted on account deletion
  • Recording blobs queued for deletion within stated timelines
  • Audit records retained for fraud, AML, and tax evidence

Honest certification status

9jatesters does not currently claim SOC 2 or ISO 27001 certification. The DPA is a contractual control pack for controlled pilots and larger scopes while managed production hardening continues.

  • No fake certification claims
  • Vendor questionnaire support available
  • Hosted-production roadmap available for serious buyers

What buyers can request

A DPA draft, processor list, privacy/security summary, sample audit-log fields, data-residency explanation, and project-specific deletion/retention schedule.

What still needs real contract work

Regulated buyers may require extra clauses, hosted-processing commitments, independent security review, or an NDA-gated architecture walk-through before production volume.

Need legal review before a pilot?

Send the use case and data categories. We will share the current DPA draft and flag anything that needs custom handling before payment.