Application, definitions, and roles
This DPA is between the Customer identified in the account or order and ServicesGrid OS (“ServicesGrid”). Capitalised terms not defined here have the meanings in the Terms. “Personal Data”, “controller”, “processor”, and “processing” have the meanings given by applicable data-protection law.
At the effective date, ServicesGrid OS is an owner-operated remote online business based in Ghana. It is not yet registered as a business name or company and does not maintain a public office.
Customer is the controller of Personal Data placed in its workspace and ServicesGrid is its processor. Each party remains an independent controller for information it determines how and why to use, such as its own account contacts, personnel, security records, and legal records.
Documented instructions and processing limits
ServicesGrid will process Personal Data only to provide, secure, support, and maintain the Service; follow Customer's documented use and configuration of the Service; comply with the agreement; and meet applicable law. The Terms, this DPA, an order, support requests, and actions taken by authorised users are Customer's documented instructions.
We will notify Customer if we reasonably believe an instruction violates applicable data-protection law and may pause the affected processing while the parties address it. If law requires processing outside Customer's instructions, we will inform Customer before processing unless law prohibits notice.
Customer duties
Customer will:
- provide lawful instructions and process Personal Data fairly and lawfully;
- give required notices and obtain any consent or other lawful basis needed for the processing;
- limit Personal Data to what is appropriate for the enabled features and business purpose;
- configure roles, permissions, retention, exports, and integrations responsibly;
- respond to data subjects and regulators as controller; and
- apply suitable safeguards before entering children's data, health information, identity records, or other sensitive information.
Personnel and confidentiality
ServicesGrid will restrict Personal Data access to personnel and contractors who need it to perform the Service. Those people must be bound by confidentiality duties, receive appropriate privacy and security guidance, and access Personal Data only as authorised.
Technical and organisational security measures
Taking account of the state of the art, implementation cost, processing context, and risk, ServicesGrid will maintain reasonable safeguards designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
- encrypted network transport for supported production connections;
- password hashing, MFA and passkey support, and session-management controls;
- role-based and workspace-scoped access controls;
- rate limiting, anti-abuse checks, audit events, and security monitoring;
- encrypted storage for selected application secrets and restricted support access; and
- backup, recovery, patching, and incident-response measures appropriate to the active deployment.
Additional public detail is available on the Security page. Customer is responsible for its devices, networks, user access, credentials, exports, and integration choices.
Subprocessors and international transfers
Customer gives general authorisation for ServicesGrid to use subprocessors to provide the Service. ServicesGrid will impose data-protection obligations appropriate to each subprocessor's work and remains responsible for its obligations under this DPA.
The current provider list and change-notice process appear on the Subprocessors page. Customer may reasonably object to a new subprocessor on documented data-protection grounds within 15 days after notice. The parties will work in good faith on a commercially reasonable alternative; if none is available, either party may terminate only the affected feature.
Personal Data may be processed in Ghana and other countries where approved providers operate. Where required by applicable law, ServicesGrid will use an appropriate transfer mechanism and supplementary safeguards.
Data-subject requests and compliance assistance
Taking account of the nature of processing and information available to us, ServicesGrid will provide reasonable assistance with data-subject requests, security assessments, breach obligations, consultations, and regulator enquiries concerning Customer Data. If we receive a request directly about Customer Data, we will direct the requester to Customer or notify Customer unless law prohibits it. Customer remains responsible for verifying and responding to the request.
Assistance beyond standard Service functionality may require reimbursement of reasonable costs where permitted by law and agreed in advance.
Personal-data incidents
ServicesGrid will notify Customer without undue delay after confirming a breach of security that causes accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data. The notice will include information reasonably available to help Customer meet applicable reporting duties and will be supplemented as the investigation progresses.
ServicesGrid will take reasonable steps to contain, investigate, and remediate the incident. Notice is not an admission of fault or liability. Customer is responsible for notifications it must make as controller, with our reasonable assistance.
Return and deletion
Customer may export data made available through the Service while its workspace is accessible. When a workspace owner requests deletion through the Service, access is suspended and a 30-day restoration period begins. After that period, the workspace becomes eligible for scheduled deletion from active application systems. Primary application-database records are ordinarily removed during the next successful purge cycle, and linked local files are removed where supported.
Protected backups, caches, and third-party systems follow their applicable deletion or rotation lifecycle, so complete removal may take longer. ServicesGrid may retain limited information where required by law or reasonably necessary for security, fraud prevention, accounting, or legal claims. Any retained Customer Personal Data remains protected by this DPA and will not be used for another purpose.
Compliance information and audits
On reasonable request, ServicesGrid will provide information necessary to demonstrate compliance with this DPA. Customer must first use available policies, security information, and independent reports. If those are insufficient, Customer may request one audit in a 12-month period, unless a regulator or confirmed incident reasonably requires another.
Audits require reasonable advance notice, must avoid disrupting the Service or exposing another customer's information, and are subject to confidentiality and security controls. Customer bears its audit costs unless the audit identifies a material breach by ServicesGrid. Liability and dispute terms in the Terms apply to this DPA. If this DPA conflicts with the Terms about processing Customer Personal Data, this DPA controls.
Schedule: details of processing
Subject matter and duration
Processing needed to provide the subscribed ServicesGrid features for the subscription term and the deletion periods described above.
Nature and purpose
Collection, organisation, storage, retrieval, display, transmission, reporting, support, protection, export, and deletion of data used for business operations such as bookings, accommodation, customer relationships, memberships, orders, POS, inventory, staff access, communications, and payments.
Data subjects
Customer's users, staff, applicants, members, guests, customers, dependants, guardians, emergency contacts, suppliers, and other people whose information Customer submits.
Types of Personal Data
Identity and contact details; account, role, authentication, and device information; bookings, stays, attendance, orders, memberships, communications, transactions, preferences, notes, and other records selected by Customer. Sensitive or children's data is processed only when Customer chooses to submit it and has appropriate authority.