Legal
Data Processing Agreement
Version 1 · Effective 6 October 2026
This Data Processing Agreement (the “Agreement”) forms part of the Terms of Service between Derick ArchiTech Studio Limited (“DAS”, the processor) and each business that uses DAS POS (the “Business”, the controller). It applies to personal data about the Business's customers, patients and staff that the Business submits to DAS POS (“Business Personal Data”), and it is accepted together with the Terms.
1. Roles and instructions
For the purposes of the Data Protection and Privacy Act, 2019 of Uganda and its Regulations (the “Act”), the Business is the data controller and DAS is its data processor. DAS processes Business Personal Data only to provide, secure and support the Service as described in the Terms, and otherwise only on the Business's documented instructions, which the Business gives by using and configuring the Service. Where the law requires DAS to process data otherwise, DAS will inform the Business beforehand, unless the law prohibits it.
2. Scope of processing
Names, contact details, purchase, payment and wallet records, staff records and, for health businesses, health information, which is special personal data under the Act. Processing continues for as long as the Business uses the Service and as provided in section 9.
3. Confidentiality
Access to Business Personal Data is limited to DAS personnel who need it to operate or support the Service, each bound by a duty of confidentiality. Support access to a Business's account is limited in time and recorded in an audit log.
4. Security
DAS maintains appropriate technical and organisational measures, including a separate database for each Business, encrypted connections, protected password storage, optional sign in verification, access based on each person's role, automatic locking of inactive sessions, request limits, monitoring with alerts, and daily backups stored away from the server together with procedures to restore them. DAS reviews these measures regularly and may enhance them, but will not reduce the overall level of protection.
5. Sub processors
The Business authorises the sub processors listed on our sub processors page. DAS binds each of them to written obligations no less protective than this Agreement and remains responsible for their performance. DAS gives at least 30 days' notice before adding or replacing a sub processor. If the Business objects on reasonable data protection grounds and the matter cannot be resolved, the Business may terminate the Terms and receive a proportionate refund of fees paid for the unused period.
6. International transfers
Business Personal Data is hosted in the European Union, in Germany, whose law protects personal data at least as well as the Act. Some sub processors operate in other countries, as listed. DAS transfers personal data outside Uganda only as permitted by section 19 of the Act.
7. Assistance to the Business
DAS will assist the Business, through the Service's own tools where available and otherwise on reasonable request, in responding to individuals exercising their rights of access, correction, deletion and objection, in carrying out data protection impact assessments, and in consulting the Personal Data Protection Office. Any request DAS receives directly concerning Business Personal Data will be forwarded to the Business without undue delay.
8. Personal data breaches
DAS will notify the Business without undue delay, and in any event within 48 hours of becoming aware of a breach affecting Business Personal Data, with the information then available, and will keep the Business informed. Where the Act and Regulation 33 place the obligation on DAS, DAS will notify the Personal Data Protection Office, and it will assist the Business in meeting its own notification duties.
9. End of processing
When the Business's account ends, the Owner may download its data using the Service's export, or request it from us, for 30 days. DAS then deletes Business Personal Data, including from backups as they expire, except where the law requires DAS to retain it.
10. Audits
On reasonable written request, and no more than once a year unless a breach has occurred or a regulator requires it, DAS will answer the Business's questions about its compliance with this Agreement and make available the information reasonably necessary to demonstrate it. DAS does not hold, and does not claim to hold, any third party security certification.
11. Artificial intelligence
DAS does not use Business Personal Data or Business Data to train artificial intelligence or machine learning models, and will not do so without the Business's explicit and separate consent.
12. Order of precedence
If this Agreement conflicts with the Terms concerning Business Personal Data, this Agreement prevails. Liability under this Agreement is subject to the limitations in the Terms, except where the law does not permit such limitation.
Derick ArchiTech Studio Limited, P.O. Box 204567, Nakawa, Kampala, Uganda. Email: archderick@gmail.com.