Compliance with Data Protection Act, 2019
Both parties shall comply with all applicable obligations under the Data Protection Act, 2019 (Kenya), the Data Protection (General) Regulations, 2021, and any other applicable data protection legislation.
How Convergly protects Customer Data, complies with Kenya's Data Protection Act, and operates as a trusted processor for your association.
The following provisions govern how Convergly processes Customer Data as a service provider under applicable Kenyan data protection law.
Both parties shall comply with all applicable obligations under the Data Protection Act, 2019 (Kenya), the Data Protection (General) Regulations, 2021, and any other applicable data protection legislation.
For the purposes of this Agreement:
The Provider's primary database and platform infrastructure is hosted on Supabase, a managed cloud database and backend provider. The primary database is located in the West EU (Ireland) region, operating on Amazon Web Services infrastructure in the eu-west-1 zone. All Customer Data is stored within this infrastructure environment. The Provider shall notify the Customer in writing not less than thirty (30) days in advance of any material change to the hosting provider or the geographic location of primary data storage.
The Provider uses the following categories of standard infrastructure sub-processors to deliver the Service:
The Customer acknowledges and consents to the engagement of the above sub-processors. Where the Provider proposes to engage any additional or replacement sub-processor, it shall notify the Customer in writing not less than fourteen (14) days in advance, and the Customer may object in writing within that period if the proposed sub-processor would result in a material change to the data processing arrangements.
The Provider shall:
The AI Admin Assistant feature operates solely by querying the Customer's own data within the Service to generate responses for authorised users. The Provider warrants that:
The Customer's prior written consent is required before Customer Data may be used for any purpose beyond the provision of the Service.
The Customer shall:
Customer Data will be retained for the duration of the active subscription. Upon termination, Customer Data will be available for export for thirty (30) days from the termination date. The Provider shall make Customer Data available for export in the following standard formats: CSV, Microsoft Excel (.xlsx), and PDF, as applicable by data type. After the thirty (30) day export window, Customer Data will be securely deleted from the Provider's systems within a further thirty (30) days, unless longer retention is required by applicable Kenyan law.
Upon written request from the Customer made prior to or within the export window, the Provider shall provide reasonable technical cooperation and migration assistance to facilitate the Customer's transition to an alternative provider, at no additional charge for standard data extraction.
The Provider warrants that it maintains automated backup systems and disaster recovery infrastructure adequate to protect and restore Customer Data in the event of system failure or operational disruption. Specifically:
The Provider shall maintain reasonable security measures including, but not limited to:
The Customer shall have the right, upon not less than thirty (30) days' written notice and no more than once per calendar year, to request written confirmation and evidence of the Provider's compliance with its security and data protection obligations under this Agreement. The Provider shall respond to such requests within fifteen (15) business days and shall provide reasonable documentary evidence of its security controls, backup systems, and data processing arrangements. Where the parties agree, such audit rights may be satisfied by the Provider supplying a current third-party security assessment or equivalent compliance attestation.
Upon discovery of a personal data breach or security incident affecting Customer Data, the Provider shall, in addition to the notification obligation in Clause 4:
The following provisions govern payment processing and settlement for payments collected through the Service via the Paystack integration.
The Provider utilises Paystack (operated by Paystack Payments Limited, a company licensed and regulated as a payment service provider under the laws of Nigeria and operating in Kenya in compliance with the Central Bank of Kenya's National Payment System Act, 2011) as the exclusive licensed payment processor for all subscription and transactional payments processed through the Service. CBK identifies Paystack Payments Kenya Limited as the Kenyan licensed entity.
Two categories of fee apply to payments processed through the Service:
Paystack Processing Fee: All transaction and processing fees charged by Paystack in connection with payments processed through the Service shall be borne exclusively by the Customer and shall be deducted by Paystack from the gross transaction amount at the point of settlement in accordance with Paystack's standard fee schedule. The Provider shall not add any markup or surcharge on top of Paystack's published processing fees.
Convergly Platform Fee: The Provider shall charge a platform fee of one percent (1%) of each transaction value processed through the Service. This fee is levied by the Provider for the maintenance of the payment infrastructure, technical integration, and security controls that facilitate payment processing on the platform. The Convergly platform fee shall be borne by the payer at the point of transaction and shall be collected automatically at the time of payment processing before settlement of the net amount to the Customer. The Provider shall itemise the Convergly platform fee separately in all reconciliation reports issued under Clause 12.4 so that it is clearly distinguishable from Paystack's processing fees and from the amounts settled to the Customer.
For the avoidance of doubt, this Agreement and the payment processing arrangements set out in this Schedule apply solely to payments collected through the Service via the Paystack integration. Payments made by the Customer's members or any other party directly to the Customer by cheque, bank transfer, cash, or any other method outside the Service are entirely outside the scope of this Agreement. The Provider has no entitlement, interest, visibility, or involvement in such payments, and no fees, charges, reconciliation obligations, or settlement requirements under this Agreement shall apply to them.
All funds collected through the Service on behalf of the Customer shall settle directly into the Customer's designated bank account within three (3) business days of the transaction being confirmed and cleared by Paystack, unless a shorter settlement period is agreed in writing between the parties. The Provider shall ensure that the Customer's settlement account details are correctly registered with Paystack and shall not redirect, hold, commingle, or otherwise delay the settlement of funds beyond the agreed period without the Customer's prior written consent. Where settlement is delayed beyond the agreed period for any reason within the Provider's control, the Provider shall notify the Customer in writing within twenty-four (24) hours of becoming aware of the delay and shall take all reasonable steps to expedite settlement.
The Provider maintains a real-time reconciliation dashboard accessible to the Customer's authorised administrators within the Service at all times. The dashboard displays, for each transaction processed through the Service: the gross amount collected, the Convergly platform fee deducted, Paystack processing fees deducted, the net amount settled to the Customer, the date and reference number of each settlement transfer, and the status of any transactions held, reversed, or flagged. The Customer may access this dashboard at any time without the need to request a separate report.
Where the Customer requires clarification on any individual transaction appearing in the dashboard, the Customer may raise a query through the Provider's support channels and the Provider shall respond within five (5) business days.
Refunds of payments made through Paystack shall be processed only upon the Customer's written authorisation. The Provider shall not issue refunds unilaterally without the Customer's prior written consent, except where required by applicable Kenyan law or by Paystack's mandatory operating rules. Where a refund is authorised, it shall be processed within five (5) business days of authorisation and the Provider shall update the reconciliation records accordingly. Refund amounts shall be sourced from the Provider's operational funds and shall not cause a reduction in the settlement amounts otherwise due to the Customer unless the Customer expressly directs otherwise in writing.
In the event that a chargeback is initiated against any transaction processed through the Service, the Provider shall notify the Customer in writing within forty-eight (48) hours of receiving notice of the chargeback from Paystack. The Provider shall, with the Customer's cooperation and written approval, contest the chargeback where there are reasonable grounds to do so. Responsibility for chargeback losses shall be allocated as follows: where the chargeback arises from a technical error, fraud, or negligence on the part of the Provider or Paystack, the Provider shall bear the full financial loss. Where the chargeback arises from a dispute initiated by a member of the Customer or a customer in respect of a service or product delivered by the Customer, the Customer shall bear the financial loss. Where liability is disputed between the parties, the matter shall be escalated in accordance with the dispute resolution procedure in Section 14 of this Agreement.
The Provider shall be responsible for any loss of funds arising from: unauthorised access to the Paystack integration, misconfiguration of settlement account details, failure to notify the Customer of settlement delays within the required period, or any act or omission of the Provider or its personnel in the administration of the payment processing arrangement. The Customer shall be responsible for any loss arising from incorrect settlement account details provided by the Customer, or from the Customer's own instructions that result in misdirected payments. Neither party shall be liable for losses caused solely by Paystack system failures beyond their respective control, provided that the affected party has taken all reasonable steps to mitigate such losses and has notified the other party promptly.
The Provider shall not replace or supplement Paystack with an alternative payment processor without the Customer's prior written consent. Where a change of processor is proposed, the Provider shall provide the Customer with not less than sixty (60) days' written notice, together with details of the proposed replacement processor's licensing status, fee structure, and settlement terms.
Questions about this policy?
Contact us at info@convergly.app for data protection enquiries.
Back to home