Purpose
This Data Processing Agreement ("DPA") forms part of the Terms of Service between DataRadius ("Processor") and the ISP Customer ("Controller"). It governs the processing of subscriber personal data by DataRadius on behalf of the Controller, in compliance with the Kenya Data Protection Act 2019 and applicable data protection laws.
Scope of Processing
DataRadius processes subscriber personal data solely to provide the platform services described in the Terms of Service. This includes: storing subscriber records; authenticating RADIUS sessions; processing payment transactions; generating billing reports; sending service notifications on behalf of the Controller.
Categories of Data
Subscriber names, phone numbers (MSISDN), email addresses, IP addresses, MAC addresses, RADIUS authentication and accounting records, payment transaction details, service plan assignments, and location data (where field operations features are used).
Data Subjects
End-user subscribers of the ISP Customer's internet service.
Processor Obligations
DataRadius shall: process subscriber data only on the Controller's documented instructions; ensure personnel with access are bound by confidentiality; implement appropriate technical and organizational security measures (encryption, tenant isolation, access controls, audit logging); assist the Controller in responding to data subject requests; notify the Controller without undue delay (and within 72 hours) of any personal data breach; delete or return all personal data upon termination, at the Controller's choice; make available information necessary to demonstrate compliance.
Security Measures
AES-256-GCM encryption at rest; TLS 1.2+ in transit; PostgreSQL Row-Level Security for tenant isolation; application-level encryption of sensitive credentials; TOTP-based multi-factor authentication; role-based access control; comprehensive audit trail; automated backups with tested restores; RPO 1 hour, RTO 30 minutes.
Sub-processors
DataRadius uses third-party sub-processors listed on the Sub-processors page. We will notify the Controller at least 14 days before adding a new sub-processor. The Controller may object to a new sub-processor within 14 days of notification.
International Transfers
Subscriber data may be transferred to and stored in the European Union (where our primary infrastructure is located) and processed by sub-processors in other jurisdictions. All transfers are governed by appropriate safeguards, including data processing agreements with each sub-processor.
Effect of Termination
Upon termination of the service agreement, DataRadius will delete all subscriber personal data within 30 days, unless longer retention is required by law. The Controller may request data export in standard formats before deletion.
Contact
For DPA-related enquiries, contact us at privacy@dataradius.net.