Legal
Data Processing Addendum
How we handle the personal data inside your workspace, as your processor.
Last updated 14 September 2026
This addendum forms part of the Terms of Service and applies whenever Noria Technologies LTD processes personal data on your behalf. It is written against the Data Protection Act, 2019. Where it conflicts with the terms, this addendum wins on data protection matters.
1. Who is what
You are the controller of the personal data in your workspace. You decide what goes in, why, and for how long.
We are your processor. We hold and handle that data to provide the service and for nothing else.
Where you are yourself processing on behalf of somebody else, you confirm you have the authority to appoint us as a sub-processor and that our processing is within what that arrangement allows.
2. Our instructions
We process personal data only on your documented instructions. Your instructions are: these terms, the configuration of your workspace, and what your users do in the application.
We will tell you if we believe an instruction breaks data protection law, and we may pause that processing until it is resolved.
If the law requires us to process data in a way you have not asked for, we will tell you before we do unless the law forbids us to.
3. Confidentiality
Everyone we let near your data is bound by a duty of confidence and is told what they may do with it. Access is limited to the people who need it to do their job, and is removed when they no longer need it.
4. Security
We keep security measures appropriate to the risk, covering at least:
- controlling who can reach your data, and recording who reached it
- separating each customer’s data from every other customer’s
- encrypting data in transit and at rest
- keeping backups, and testing that they restore
- reviewing access and removing it when a person changes role or leaves
- a documented process for handling an incident
Annex II sets these out in more detail. We describe what we commit to rather than how each control is built: a published blueprint of a defence is most useful to the reader you least want.
We may change a measure, and will not change one in a way that materially reduces the protection of your data.
5. Sub-processors
You give us general authorisation to use sub-processors. The categories we use, and what each category touches, are at sub-processors. The current list naming each company is given to you on request at [email protected] rather than published, for the reason that page sets out.
Before we add one or replace one, we will tell you at least 30 days beforehand, naming the company joining or leaving. If you object on reasonable data protection grounds within that period, we will try to offer you an alternative. If we cannot, you may end the affected part of the service without penalty for the unused period.
Each sub-processor is under written terms no less protective than this addendum, and we stay responsible to you for what they do.
6. Helping you with requests from individuals
If somebody contacts us directly about data in your workspace, we will not answer on your behalf. We will tell them to contact you, and tell you that they came to us.
The application lets you find, correct, export and delete records yourself. Where a request needs more than that, we will help you within a reasonable period, and may charge for work that goes well beyond routine assistance.
7. Helping you with your obligations
Taking into account what we know and what we do, we will help you with impact assessments, prior consultation with a regulator, and demonstrating compliance, as far as those relate to our processing.
8. Breach notification
If we become aware of a personal data breach affecting your data, we will tell you without undue delay and in any event within 48 hours of becoming aware, which is the period section 43 of the Data Protection Act, 2019 gives a processor. That leaves you the rest of the 72 hours the same section gives you for telling the Data Commissioner.
We will tell you what happened, which categories and roughly how many records and people are affected, the likely consequences, and what we are doing about it. Where we do not have all of that at first, we will send what we have and follow up.
Notifying regulators and affected individuals is your decision as controller. We will give you what you need to make it.
9. Deletion and return
While your workspace is open you can export your data at any time, in a structured, commonly used, machine readable format.
When the agreement ends, we keep your data for 30 days so you can export it, then delete it from the live service. It remains in backups until those backups age out, within 30 days, and the obligations in this addendum keep applying to it until it is gone.
You may ask us to delete sooner, and we will, unless the law requires us to keep it.
10. Audit
We will give you the information you reasonably need to show that we are meeting this addendum, and will answer a written security questionnaire once in any twelve month period.
Where that is not enough for a regulator or for your own obligations, you may audit us, or appoint an independent auditor who is not our competitor, on reasonable notice, no more than once in any twelve month period unless a regulator or a breach requires otherwise. An audit must not disrupt the service or expose another customer’s data, and each party carries its own costs.
11. Transfers
Where a sub-processor holds data outside Kenya, we rely on the safeguards the Data Protection Act, 2019 requires for a transfer out. The sub-processors page names where each one holds data.
12. Liability
Liability under this addendum is subject to the limits in the Terms of Service.
Annex I: details of the processing
Subject matter. Provision of the Noria CRM service.
Duration. For as long as the agreement is in force, plus the retention window in section 9.
Nature and purpose. Storing, organising, retrieving, transmitting, analysing and deleting personal data so that your team can record and manage customer relationships, exchange messages with contacts, request payments, and read reports about their own work.
Types of personal data.
- Identifiers: name, job title, employer
- Contact details: phone number, email address, physical address
- Relationship records: notes, activities, call and visit outcomes, tasks, deal history
- Message content: WhatsApp and SMS messages sent and received through the service, and their delivery status
- Voice recordings and their transcripts, where your reps capture notes by speaking
- Consent records: what a contact agreed to, when, through whom, and any withdrawal
- Payment references: the request, the amount, the reference, and the result, but not card or account credentials
- Anything else your users choose to type into a record
Categories of data subject.
- Your staff who use the service
- Your customers and prospective customers, and the individuals who work for them
- Your resellers and partners, and the individuals who work for them
Special category data. Not required by the service and not expected. If your use involves it, tell us before you start so we can agree whether and how.
Annex II: security measures
Access. Access to production data is restricted to named individuals who need it, requires multi-factor authentication, and is reviewed periodically and on any change of role.
Separation. Every request is scoped to a single workspace, and that scoping is enforced rather than left to any one piece of code to remember.
Encryption. Data is encrypted in transit and at rest. Credentials and keys are held apart from the application that uses them.
Logging. Administrative and privileged actions are recorded with who, what and when, and those records are kept separately from the data they describe.
Resilience. Data is backed up on a schedule, backups are encrypted, and restores are tested.
Development. Changes are reviewed before release, automated checks run on every change, and dependencies are monitored for known vulnerabilities.
People. Staff are bound by confidentiality obligations and receive data protection guidance appropriate to their role.
Incidents. A documented procedure covers detection, containment, assessment, notification and review.
Deletion. Deletion requests are carried out on the live service promptly, and follow through to backups as those expire.