Data Processing Agreement
Effective: 29 May 2026
For Institutions (B2B)
This Data Processing Agreement ("DPA") is between mysmartaccesscard (mSAC), operated by Tekroin ("Processor") and the institution that registers an account on mysmartaccesscard.com ("Controller"). It governs the processing of personal data of the Controller's end-users (students, patients, staff, members) in compliance with the Nigeria Data Protection Act 2023 (NDPA) and applicable data protection laws.
Definitions
Personal Data — any information relating to an identifiable individual processed through the mysmartaccesscard platform on behalf of the Controller.
Controller — the institution (school, hospital, gym, or business) that determines the purposes and means of processing personal data.
Processor — mysmartaccesscard (Tekroin), which processes personal data on behalf of the Controller.
Data Subjects — students, patients, staff, members, and other individuals whose data is processed via the platform.
Sub-processors — Google Firebase (hosting, database, authentication), Paystack (payment processing), Resend (transactional email), PostHog (analytics).
Scope and Purpose of Processing
mysmartaccesscard processes personal data solely to deliver the services described in the Terms of Service. This includes:
- Digital identity verification via QR code and NFC tap
- Attendance recording and reporting
- Patient profile and visit history management (hospitals)
- Grade and academic performance recording (schools)
- Membership management and payment tracking (gyms)
- Staff payroll and salary calculation (businesses)
Processing is carried out only on documented instructions from the Controller and not for any other purpose.
Controller Responsibilities
The Controller agrees to:
- Obtain all necessary consents from Data Subjects before uploading their data to the platform
- Ensure the legal basis for processing personal data exists under NDPA 2023
- Provide Data Subjects with a privacy notice that references the use of mysmartaccesscard
- Respond to Data Subject rights requests (access, erasure, portability) within the statutory timeframe
- Notify mysmartaccesscard promptly if any Data Subject makes a rights request that requires Processor action
Processor Obligations
mysmartaccesscard commits to:
- Process personal data only on the Controller's documented instructions
- Ensure all personnel with access to personal data are bound by confidentiality obligations
- Implement appropriate technical and organisational security measures (encryption in transit and at rest, role-based access control, audit logs)
- Not transfer personal data outside Nigeria or Africa without appropriate safeguards, except to approved sub-processors who meet equivalent data protection standards
- Notify the Controller within 72 hours of becoming aware of a personal data breach
- Support the Controller in fulfilling Data Subject rights requests
- Delete or return all personal data upon termination of the service relationship
Sub-processors
The Controller authorises the use of the following sub-processors:
Google Firebase (Alphabet Inc.)
Database, file storage, authentication · USA (EU SCCs / adequate safeguards)
Paystack (Stripe, Inc.)
Payment processing · Nigeria / USA
Resend Inc.
Transactional email delivery · USA
PostHog Inc.
Anonymous product analytics · EU / USA
Railway Corp.
Backend server hosting · USA
mysmartaccesscard will inform the Controller of any planned changes to sub-processors with reasonable notice.
Security Measures
mysmartaccesscard implements the following security measures:
- All data in transit is encrypted using TLS 1.2+
- All data at rest is encrypted by Firebase (AES-256)
- NFC chips store only an opaque token ID — no personal data is written to physical devices
- Role-based access control ensures staff can only access data relevant to their role and institution
- Rate limiting and input validation on all API endpoints
- Audit logs for sensitive operations (patient access, role changes, NFC assignment)
Data Retention and Deletion
Personal data is retained for the duration of the service relationship. Upon account cancellation or termination:
- Data is accessible for 30 days for export purposes
- After 30 days, data is archived and permanently deleted within 90 days
- The Controller may request immediate deletion by contacting support@mysmartaccesscard.com
- Anonymised aggregate statistics may be retained indefinitely for service improvement
Data Subject Rights
Data Subjects have the following rights under NDPA 2023:
- Access — the right to know what data is held about them
- Rectification — the right to correct inaccurate data
- Erasure — the right to request deletion of their data
- Portability — the right to receive their data in a machine-readable format
- Objection — the right to object to certain types of processing
Controllers are primarily responsible for handling Data Subject requests. mysmartaccesscard will provide technical support (e.g., data export, deletion execution) within 5 business days of receiving a valid Controller request.
Governing Law
This DPA is governed by the laws of the Federal Republic of Nigeria, including the Nigeria Data Protection Act 2023 (NDPA) and its regulations. Any disputes shall be resolved through the Nigeria Data Protection Commission (NDPC) or competent Nigerian courts.
Acceptance
By registering an institution account on mysmartaccesscard.com and using the platform, the Controller accepts the terms of this Data Processing Agreement. No separate signature is required for standard institutional use.
Institutions requiring a signed DPA for procurement or compliance purposes should contact support@mysmartaccesscard.com with the subject line "DPA Request — [Institution Name]".
Data Protection Contact
For DPA requests, data breaches, or Data Subject rights support:
support@mysmartaccesscard.comWe respond within 2 business days for DPA and compliance matters.