Note: The effective date and governing law of the execution copy will be as recorded by the parties.
PARTIES TO THIS AGREEMENT
CONTROLLER: The Client engaging Rowville Consulting for accounting services, as detailed in the Master Services Agreement (the "Client").
PROCESSOR: Rowville Consulting (Pty) Ltd, a company registered in Botswana with its principal place of business at Gaborone, Botswana, operating through its website at https://rowvilleconsulting.co.bw (the "Processor").
This DPA is incorporated into and forms part of the Master Services Agreement between the Parties. In case of conflict, this DPA prevails regarding data protection matters.
DEFINITIONS
| Term | Definition |
|---|---|
| UK GDPR | The General Data Protection Regulation as incorporated into UK law by the Data Protection Act 2018. |
| EU GDPR | Regulation (EU) 2016/679 as applicable in Ireland, alongside the Irish Data Protection Act 2018. |
| Personal Data | Any information relating to an identified or identifiable natural person processed under the Agreement. |
| Processing | Any operation performed on Personal Data (collection, recording, storage, etc.). |
| Sub-processor | A third party engaged by Processor to process Personal Data. |
| Data Subject | An individual whose Personal Data is processed (employees, customers, etc. of Controller). |
| Security Incident | Breach of security leading to accidental or unlawful destruction, loss, alteration, or access to Personal Data. |
DETAILS OF PROCESSING
Subject Matter & Duration
Processing of Personal Data necessary to provide the accounting and finance services described in the Master Services Agreement. Duration matches the term of the Agreement plus applicable statutory retention periods.
Nature & Purpose
Processing includes: preparation of management accounts, financial statements, tax computations, payroll processing, bookkeeping, and related finance-support activities expressly described in the service schedule.
Types of Personal Data
May include: Employee details (name, salary, contact info), customer/vendor information, financial transaction data, and any other data provided by Controller for accounting purposes.
Categories of Data Subjects
Controller's employees, directors, shareholders, customers, suppliers, and other individuals whose data is included in financial records provided to Processor.
PROCESSOR OBLIGATIONS
Instructions & Compliance
Processor shall only process Personal Data on documented instructions from Controller, unless required by applicable law. Processor shall immediately inform Controller if, in its opinion, an instruction infringes applicable UK or EEA data-protection law.
Confidentiality
Processor ensures persons authorised to process Personal Data are subject to confidentiality obligations (contractual or statutory) that survive termination of their engagement.
Security Measures
Processor implements and maintains technical and organisational measures described in Appendix 1.
Sub-processing
Controller grants general authorisation for Processor to engage Sub-processors listed in the execution copy. Processor shall provide 30 days' notice of intended changes, giving Controller opportunity to object.
Data Subject Rights
Processor shall assist Controller in responding to Data Subject requests by appropriate technical and organisational measures.
Security Incident Notification
Processor shall notify Controller without undue delay (and in any event within 48 hours) upon becoming aware of a Security Incident. Notifications shall include available details and proposed mitigation steps.
Deletion/Return of Data
At Controller's choice, Processor shall delete or return all Personal Data after termination of services, and delete existing copies unless applicable law requires storage.
Audit Rights
Upon reasonable notice, Processor shall make available to Controller (or its independent auditor) information necessary to demonstrate compliance. Audits shall be conducted at Controller's expense, no more than annually, subject to confidentiality agreements, and with the following exceptions:
- Material security incidents requiring follow-up verification
- Regulator requirements or orders
- Evidence of serious non-compliance identified through other means
CONTROLLER OBLIGATIONS
Controller warrants that it has lawful basis for processing and necessary notices/consents for Processor to process Personal Data as described herein.
Controller shall provide clear instructions and any necessary cooperation for Processor to perform its obligations.
Controller is responsible for responding to Data Subject requests regarding data processed by Processor.
INTERNATIONAL TRANSFERS
Controller acknowledges that Processor's primary processing operations are in Botswana.
Where UK or EEA Personal Data is transferred to Botswana, such transfer shall be governed by an appropriate transfer mechanism.
UK transfers: The UK International Data Transfer Agreement or EU Standard Contractual Clauses with the UK Addendum may be used, subject to completion of the relevant annexes and a transfer risk assessment.
EEA transfers: EU Standard Contractual Clauses may be used, subject to completion of the relevant annexes and a transfer impact assessment.
Implementation: The execution copy of this DPA will specify the transfer mechanism(s) selected for the engagement and shall incorporate the completed clauses or refer to them as an appendix.
Processor shall not transfer Personal Data to any third country not covered by adequacy regulations without Controller's prior written consent and the appropriate safeguard.
APPENDICES
APPENDIX 1: TECHNICAL AND ORGANISATIONAL MEASURES
The measures set out below are maintained by Rowville in respect of its own systems and personnel. Additional measures may be agreed for specific engagements.
| Security Area | Rowville Baseline Measures |
|---|---|
| Access Control | Role-based access, Multi-factor authentication, Unique user IDs, Regular access reviews, Principle of least privilege |
| Encryption | Encryption at rest (AES-256 equivalent) and in transit (TLS 1.3) where supported by the systems used; encrypted backups where applicable |
| Physical Security | Managed through secure cloud providers with industry-standard access controls; measures described during due diligence |
| Network Security | Firewalls, secure access controls and VPN for remote access; managed via approved platforms and providers |
| Incident Response | Documented response plan, escalation procedures, breach notification within 48 hours of awareness |
| Business Continuity | Backup and recovery procedures appropriate to the service scope, reviewed and tested periodically |
| Personnel Security | Confidentiality agreements, role-appropriate training and access removal on departure or reassignment |
Client-approved subprocessors and cloud platforms may operate additional controls, which are disclosed during onboarding.
APPENDIX 2: SUBPROCESSORS (EXECUTION COPY)
The execution copy of this DPA will list each subprocessor that will process Client Personal Data in connection with the services.
Controller will be notified 30 days before Rowville engages a new Subprocessor for Client Personal Data.
AGREED AND ACCEPTED
FOR AND ON BEHALF OF CONTROLLER
Company Name: ________________________________
Signature: ____________________________________
Name (Print): _______________________________
Title: _______________________________________
Date: ________________________________________
FOR AND ON BEHALF OF PROCESSOR
Rowville Consulting (Pty) Ltd
Gaborone, Botswana
Registration number and tax details supplied in the execution copy
Signature: ____________________________________
Name (Print): _______________________________
Title: _______________________________________
Date: ________________________________________
