Data Processing Agreement
Koklo Nya is a product of logNsec LLC. Last updated: 23 July 2026.
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer ("Customer", "Controller") and logNsec LLC ("logNsec", "Processor"). It applies where logNsec processes personal data on the Customer's behalf through the Koklo Nya service. It is drafted to meet the obligations of Ghana's Data Protection Act, 2012 (Act 843) and, where applicable, the GDPR (Article 28). Where this DPA conflicts with the Terms on data protection, this DPA prevails.
1. Roles of the parties
For personal data that the Customer and its Authorised Users enter into Koklo Nya (for example about the Customer's employees, contractors, and contacts), the Customer is the data controller and logNsec is the data processor. The Customer is responsible for having a lawful basis to collect and use that data and for the accuracy of its instructions. Separately, logNsec is the controller of the limited account and website data described in our Privacy Policy; that is not covered by this DPA.
2. Scope and instructions
logNsec will process personal data only to provide and support the Service, and only on the Customer's documented instructions — which include these Terms, the Customer's configuration and use of the Service, and any written instructions the Customer gives. If logNsec believes an instruction breaks data-protection law, it will inform the Customer. If the law requires logNsec to process data otherwise, it will tell the Customer first unless the law forbids it.
3. Confidentiality
logNsec ensures that people authorised to process the personal data are bound by confidentiality and are trained appropriately, and limits access to those who need it to provide the Service.
4. Security
logNsec maintains appropriate technical and organisational measures to protect personal data, including encryption in transit and at rest, least-privilege and role-based access, tenant isolation, multi-factor authentication, and audit logging. Our security posture is summarised at koklonya.com/security. Measures may evolve, provided the level of protection is not reduced.
5. Sub-processors
The Customer authorises logNsec to engage sub-processors to provide the Service. Each is bound by data-protection obligations no less protective than this DPA. Our current sub-processors are:
- Supabase — database, authentication, and file storage.
- Cloudflare — hosting, content delivery, and edge security.
- Hetzner — application server hosting.
- Resend — transactional email delivery.
- Sentry — error and performance diagnostics (configured not to transmit personal data by default).
- Google Firebase Cloud Messaging — push-notification delivery (mobile apps).
logNsec will give the Customer reasonable prior notice of any new or replacement sub-processor and a chance to object on reasonable data-protection grounds.
6. Assisting the Controller
Taking into account the nature of the processing, logNsec will assist the Customer, by appropriate technical and organisational measures, to: respond to requests from data subjects to exercise their rights; and meet the Customer's obligations around security, breach notification, data-protection impact assessments, and prior consultation. Koklo Nya provides self-service data export and deletion tools to help the Customer respond to such requests directly.
7. Data-subject requests
If logNsec receives a request directly from a data subject relating to Customer Data, it will not respond except on the Customer's instruction, and will promptly forward the request to the Customer, unless legally required to act.
8. Personal-data breaches
logNsec will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Data, and will provide information reasonably needed to help the Customer meet its own notification duties (including to the Data Protection Commission of Ghana and affected individuals, where required).
9. International transfers
Personal data may be processed on infrastructure in the European Union and the United States (see the Privacy Policy). Where personal data is transferred across borders, logNsec relies on appropriate safeguards, such as contractual protections with its sub-processors.
10. Return and deletion
On termination of the Service, or on the Customer's request, logNsec will delete or return Customer personal data in line with the retention and erasure process described in the Privacy Policy and the account-deletion guide. Financial, tax, and certain statutory records are retained for their legally required periods (for example 6 years for financial records under Ghana's Companies Act, 2019, and 8–12 years for certain poultry-operational records), detached from the individual, then deleted.
11. Audit and demonstrating compliance
logNsec will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it appoints, on reasonable prior notice, during business hours, no more than once per year (unless a regulator requires otherwise), and subject to confidentiality and to not compromising other customers' security.
12. Liability and governing law
Each party's liability under this DPA is subject to the limitations in the Terms of Service. This DPA is governed by the laws of the Republic of Ghana, and disputes are subject to the exclusive jurisdiction of the courts of Ghana.
Annex — details of the processing
Subject-matter: provision of the Koklo Nya farm-management service to the Customer.
Duration: the term of the Customer's subscription, plus the retention periods described in the Privacy Policy.
Nature and purpose: hosting, storing, and processing Customer Data to operate the Service's features (flock, feed, sales, HR and payroll, accounting, and related modules).
Categories of data subjects: the Customer's employees, contractors, job applicants, and business contacts.
Categories of personal data: names and contact details; statutory identifiers (for example SSNIT, TIN, Ghana Card numbers); employment, payroll, leave, and loan records; and financial records. Special-category or sensitive data only to the extent the Customer chooses to enter it.