Skip to content
DataRadius
  • Product
  • Pricing
  • Customers
  • Docs
  • Blog
Log inStart free trial
DataRadius

Workspaces run on dataradius.co.ke

Product

  • Hotspot billing
  • PPPoE & RADIUS
  • Fiber & GPON
  • Router management
  • Field operations

Company

  • About
  • Customers
  • Contact
  • Security

Resources

  • Docs
  • Blog
  • Changelog
  • System status

Legal

  • Terms of service
  • Privacy policy
  • Data processing
  • Acceptable use

© 2026 DataRadius. All rights reserved.

LanguageEnglish/Kiswahili
  1. Home
  2. /Legal
  3. /Data Processing Agreement

Data Processing Agreement

Updated 5 October 2026

  • Terms of Service
  • Privacy Policy
  • Data Processing Agreement
  • Acceptable Use Policy
  • Sub-processors
⚠

This document is pending legal counsel review and is not yet in effect.

Purpose

This Data Processing Agreement ("DPA") forms part of the Terms of Service between DataRadius ("Processor") and the ISP Customer ("Controller"). It governs the processing of subscriber personal data by DataRadius on behalf of the Controller, in compliance with the Kenya Data Protection Act 2019 and applicable data protection laws.

Scope of Processing

DataRadius processes subscriber personal data solely to provide the platform services described in the Terms of Service. This includes: storing subscriber records; authenticating RADIUS sessions; processing payment transactions; generating billing reports; sending service notifications on behalf of the Controller.

Categories of Data

Subscriber names, phone numbers (MSISDN), email addresses, IP addresses, MAC addresses, RADIUS authentication and accounting records, payment transaction details, service plan assignments, and location data (where field operations features are used).

Data Subjects

End-user subscribers of the ISP Customer's internet service.

Processor Obligations

DataRadius shall: process subscriber data only on the Controller's documented instructions; ensure personnel with access are bound by confidentiality; implement appropriate technical and organizational security measures (encryption, tenant isolation, access controls, audit logging); assist the Controller in responding to data subject requests; notify the Controller without undue delay (and within 72 hours) of any personal data breach; delete or return all personal data upon termination, at the Controller's choice; make available information necessary to demonstrate compliance.

Security Measures

AES-256-GCM encryption at rest; TLS 1.2+ in transit; PostgreSQL Row-Level Security for tenant isolation; application-level encryption of sensitive credentials; TOTP-based multi-factor authentication; role-based access control; comprehensive audit trail; automated backups with tested restores; RPO 1 hour, RTO 30 minutes.

Sub-processors

DataRadius uses third-party sub-processors listed on the Sub-processors page. We will notify the Controller at least 14 days before adding a new sub-processor. The Controller may object to a new sub-processor within 14 days of notification.

International Transfers

Subscriber data may be transferred to and stored in the European Union (where our primary infrastructure is located) and processed by sub-processors in other jurisdictions. All transfers are governed by appropriate safeguards, including data processing agreements with each sub-processor.

Effect of Termination

Upon termination of the service agreement, DataRadius will delete all subscriber personal data within 30 days, unless longer retention is required by law. The Controller may request data export in standard formats before deletion.

Contact

For DPA-related enquiries, contact us at privacy@dataradius.net.