Last updated: August 30, 2026
Effective Date: 16.07.2026
Last Updated: 16.07.2026
This Data Processing Agreement ("DPA") forms part of the agreement between FrameLaPay ("FrameLaPay", "Company", "we", "us or "our") and the applicable customer, business, merchant, partner or service provider ("Customer", "Client", "you" or "your") who engages FrameLaPay for services involving the processing of personal data.
This DPA governs the processing of personal data by FrameLaPay on behalf of a Customer where FrameLaPay acts as a Data Processor or Data Controller-to-Processor service provider, as applicable under relevant data-protection laws.
â ī¸ Where FrameLaPay determines the purposes and means of processing independently, FrameLaPay may act as a Data Controller for that processing.
1. PURPOSE AND SCOPE
This DPA establishes the responsibilities of the parties concerning the processing and protection of personal data in connection with FrameLaPay's services.
It applies where FrameLaPay processes personal data on behalf of the Customer in connection with services including, where applicable:
- payment processing;
- payment collection;
- transfers;
- account management;
- identity verification;
- KYC;
- fraud prevention;
- AML/CFT monitoring;
- transaction monitoring;
- customer support;
- merchant services;
- financial technology services;
- digital-asset services;
- analytics;
- communications; and
- other services provided by FrameLaPay.
2. DEFINITIONS
For this DPA:
"Applicable Data Protection Law"
Means all applicable laws and regulations governing personal-data processing, privacy and data security, including applicable Nigerian data-protection legislation and, where applicable, laws governing customers or individuals in other jurisdictions.
"Personal Data"
Means information relating to an identified or identifiable natural person.
"Data Subject"
Means an identifiable individual to whom Personal Data relates.
"Controller"
Means the person or organisation determining the purposes and means of processing Personal Data.
"Processor"
Means a person or organisation processing Personal Data on behalf of a Controller.
"Processing"
Includes collecting, recording, organising, storing, accessing, retrieving, using, disclosing, transferring, modifying, analysing, deleting or otherwise handling Personal Data.
"Sub-Processor"
Means a third party engaged by FrameLaPay to process Personal Data on behalf of the Customer.
"Security Incident"
Means an actual or reasonably suspected breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access to Personal Data.
3. ROLE OF THE PARTIES
Depending on the particular service:
- the Customer may act as Data Controller;
- FrameLaPay may act as Data Processor;
- FrameLaPay may act as Data Controller for certain independent processing activities; or
- another regulated financial institution or service provider may act as Controller or Processor.
The parties' respective roles shall depend on the nature and purpose of the relevant processing.
4. PROCESSING INSTRUCTIONS
Where FrameLaPay acts as a Processor, FrameLaPay shall process Personal Data only:
- according to the Customer's documented instructions;
- as necessary to provide the agreed services;
- as required by applicable law; or
- as otherwise expressly permitted under the agreement.
FrameLaPay shall not knowingly process Personal Data for unrelated purposes without an appropriate legal basis.
5. LEGAL REQUIREMENTS
FrameLaPay shall comply with applicable data-protection laws when processing Personal Data.
Where FrameLaPay is required by law to process Personal Data beyond the Customer's documented instructions, FrameLaPay shall, where legally permitted, inform the Customer of that requirement.
6. CUSTOMER RESPONSIBILITIES
The Customer is responsible for:
- determining the lawful purpose of processing;
- identifying an appropriate legal basis;
- providing appropriate privacy notices;
- obtaining required consents where applicable;
- ensuring Personal Data supplied to FrameLaPay is accurate;
- ensuring that instructions provided to FrameLaPay are lawful; and
- responding to Data Subject requests where the Customer acts as Controller.
7. DATA MINIMISATION
FrameLaPay shall seek to process only Personal Data reasonably necessary for the relevant service.
The categories of information processed may include, depending on the service:
- name;
- email address;
- telephone number;
- address;
- date of birth;
- identification information;
- account information;
- payment information;
- transaction information;
- device information;
- IP address;
- verification information;
- beneficial ownership information;
- KYC information;
- fraud-risk information; and
- other information necessary for the service.
8. SPECIAL CATEGORIES OF DATA
Where sensitive or specially protected Personal Data is processed, the parties shall implement appropriate safeguards required by applicable law.
Such information may include, where legally necessary:
- biometric information;
- identification information;
- financial information;
- authentication information; and
- information requiring enhanced protection.
9. DATA SUBJECT RIGHTS
Depending on applicable law, Data Subjects may have rights including:
- right to access;
- right to correction;
- right to deletion;
- right to restriction;
- right to object;
- right to data portability;
- right to withdraw consent where processing is based on consent; and
- other legally applicable rights.
10. DATA SUBJECT REQUESTS
Where FrameLaPay receives a Data Subject request relating to Personal Data processed on behalf of the Customer, FrameLaPay shall, where appropriate:
- notify the Customer;
- assist the Customer in responding;
- provide relevant information;
- correct information where instructed; or
- delete or restrict processing where legally required.
FrameLaPay may respond directly where required by applicable law.
11. CUSTOMER INSTRUCTIONS
The Customer may issue reasonable written instructions concerning:
- access;
- correction;
- deletion;
- restriction;
- export;
- retention; and
- other lawful processing requirements.
Instructions that materially change the agreed scope of services may be subject to additional technical or commercial requirements.
12. DATA SECURITY
FrameLaPay shall implement reasonable technical and organisational measures designed to protect Personal Data against:
- unauthorised access;
- accidental loss;
- destruction;
- alteration;
- disclosure;
- misuse;
- unauthorised processing; and
- other security threats.
13. TECHNICAL SECURITY MEASURES
Depending on the nature of the service, security controls may include:
- encryption;
- authentication;
- multi-factor authentication;
- access controls;
- role-based permissions;
- network security;
- vulnerability management;
- logging;
- monitoring;
- backups;
- secure development practices;
- endpoint protection;
- incident response procedures; and
- security testing.
14. ACCESS CONTROL
Access to Personal Data shall be limited to authorised personnel who require access for legitimate business purposes.
FrameLaPay may implement:
- least-privilege access;
- role-based access;
- privileged-account controls;
- authentication requirements;
- access logging; and
- periodic access reviews.
15. EMPLOYEE CONFIDENTIALITY
Personnel authorised to process Personal Data shall be subject to appropriate confidentiality obligations.
Access shall be limited according to business need.
16. DATA BREACHES
FrameLaPay shall maintain procedures designed to identify, investigate, contain and respond to Security Incidents.
Where FrameLaPay becomes aware of a Security Incident affecting Personal Data processed on behalf of the Customer, FrameLaPay shall notify the Customer without undue delay, subject to applicable legal restrictions.
17. SECURITY INCIDENT NOTICE
Where reasonably available, a Security Incident notification may include:
- nature of the incident;
- categories of affected data;
- approximate number of affected individuals;
- potential consequences;
- containment measures;
- remediation measures; and
- contact information for relevant personnel.
FrameLaPay may provide information progressively where all information is not immediately available.
18. CUSTOMER RESPONSIBILITY FOR BREACH NOTIFICATION
Where the Customer is the Controller, the Customer remains responsible for determining whether notification to:
- Data Subjects;
- regulators;
- customers;
- law-enforcement authorities; or
- other parties
is required under applicable law.
FrameLaPay shall reasonably assist the Customer where appropriate.
19. SUB-PROCESSORS
FrameLaPay may engage Sub-Processors to support its services.
Examples may include providers for:
- cloud hosting;
- identity verification;
- KYC;
- payment processing;
- fraud detection;
- transaction monitoring;
- blockchain analytics;
- customer communications;
- customer support;
- analytics;
- cybersecurity; and
- infrastructure.
20. SUB-PROCESSOR RESPONSIBILITY
FrameLaPay shall seek to impose appropriate data-protection obligations on Sub-Processors.
FrameLaPay remains responsible for the performance of its contractual obligations relating to Personal Data processed through authorised Sub-Processors, subject to the terms of the applicable agreement and law.
21. SUB-PROCESSOR CHANGES
FrameLaPay may add or replace Sub-Processors where reasonably necessary to operate or improve its services.
Where legally required, customers may be provided with appropriate notice of material changes.
22. INTERNATIONAL DATA TRANSFERS
Personal Data may be processed or stored outside the country in which it was collected.
Where international transfers occur, FrameLaPay shall seek to implement appropriate safeguards required by applicable law.
23. CROSS-BORDER PROCESSING
Cross-border processing may be necessary where FrameLaPay uses:
- international cloud infrastructure;
- global payment networks;
- identity-verification providers;
- fraud-monitoring systems;
- customer-support platforms; or
- other international technology providers.
24. REGULATORY DISCLOSURES
FrameLaPay may disclose Personal Data where required by law or valid legal process.
Recipients may include:
- regulators;
- courts;
- law-enforcement authorities;
- financial-intelligence authorities;
- tax authorities;
- financial institutions; and
- other competent authorities.
25. FINANCIAL-CRIME COMPLIANCE
FrameLaPay may process Personal Data for:
- KYC;
- AML;
- CFT;
- sanctions screening;
- fraud prevention;
- transaction monitoring;
- suspicious-activity investigations; and
- regulatory reporting.
Such processing may be required by law and may therefore not depend on customer consent.
26. AUTOMATED PROCESSING
FrameLaPay may use automated technologies to assist with:
- fraud detection;
- identity verification;
- transaction monitoring;
- risk assessment;
- sanctions screening;
- security;
- account protection; and
- financial-crime detection.
Where applicable law provides rights concerning automated decision-making, FrameLaPay shall implement appropriate safeguards.
27. ARTIFICIAL INTELLIGENCE
FrameLaPay may use artificial intelligence or machine-learning technologies as part of its technology and risk-management infrastructure.
Such technologies may assist with:
- fraud detection;
- anomaly detection;
- transaction monitoring;
- customer support;
- cybersecurity;
- risk assessment; and
- operational analysis.
đ¤ AI systems shall not be used to circumvent applicable data-protection requirements.
28. DATA ACCURACY
The Customer shall take reasonable steps to ensure that Personal Data supplied to FrameLaPay is accurate and up to date.
FrameLaPay may rely on information provided by the Customer unless it has reason to believe that the information is inaccurate.
29. DATA RETENTION
FrameLaPay shall retain Personal Data for as long as reasonably necessary to:
- provide services;
- comply with legal obligations;
- meet regulatory requirements;
- resolve disputes;
- prevent fraud;
- maintain transaction records;
- enforce agreements; and
- protect legal rights.
30. LEGAL RETENTION REQUIREMENTS
Certain financial, transaction and KYC records may need to be retained for periods required by applicable law.
Deletion requests may therefore be subject to legal or regulatory retention requirements.
31. DELETION OR RETURN OF DATA
Upon termination of applicable services, FrameLaPay shall, subject to legal retention requirements:
- delete Personal Data;
- return Personal Data;
- anonymise Personal Data; or
- otherwise handle the information according to the Customer's lawful instructions.
32. BACKUPS
Personal Data may remain temporarily within secure backup systems after deletion.
Such information shall be subject to appropriate security controls and shall be deleted or overwritten according to applicable backup-retention procedures.
33. AUDIT RIGHTS
Where required by applicable law, the Customer may request reasonable information demonstrating FrameLaPay's compliance with applicable data-protection obligations.
Audits shall:
- occur on reasonable notice;
- avoid unreasonable disruption;
- respect confidentiality;
- not expose other customers' information; and
- take account of available independent audit or certification reports.
34. SECURITY ASSESSMENTS
FrameLaPay may maintain security assessments and documentation concerning:
- information-security controls;
- access controls;
- vulnerability management;
- incident response;
- data protection;
- business continuity; and
- third-party risk.
35. CONFIDENTIALITY
Each party shall protect confidential information received from the other party.
Confidential information shall not be disclosed except:
- to authorised personnel;
- to approved service providers;
- as required by law; or
- with the other party's permission.
36. DATA PROCESSING INSTRUCTIONS
Where FrameLaPay believes an instruction violates applicable data-protection law, FrameLaPay may notify the Customer.
FrameLaPay may decline an unlawful instruction where required by law.
37. DATA PROTECTION OFFICER
Where required by applicable law, FrameLaPay may appoint a Data Protection Officer or designated privacy professional.
Contact information may be published in the FrameLaPay Privacy Policy or on the FrameLaPay website.
38. DATA PROTECTION IMPACT ASSESSMENTS
Where appropriate, FrameLaPay may conduct or assist with Data Protection Impact Assessments ("DPIAs") for processing activities presenting significant privacy risks.
39. PRIVACY BY DESIGN
FrameLaPay seeks to incorporate privacy and security considerations into the design of its technology and services.
This may include:
- data minimisation;
- access restrictions;
- encryption;
- retention controls;
- privacy settings; and
- secure development practices.
40. DATA PROTECTION BY DEFAULT
Where reasonably practicable, FrameLaPay seeks to configure systems to limit Personal Data access and processing to what is necessary for the relevant service.
41. CUSTOMER DATA OWNERSHIP
Except where otherwise agreed, the Customer retains its rights in Personal Data supplied to FrameLaPay.
đ This DPA does not transfer ownership of Customer Personal Data to FrameLaPay.
42. FRAMELAPAY'S INDEPENDENT PROCESSING
Nothing in this DPA prevents FrameLaPay from processing information independently where such processing is necessary for:
- fraud prevention;
- AML/CFT;
- sanctions compliance;
- regulatory reporting;
- cybersecurity;
- legal compliance;
- dispute resolution;
- service security; or
- other lawful purposes.
In such circumstances, FrameLaPay may act as an independent Controller.
43. AGGREGATED AND ANONYMISED DATA
FrameLaPay may create aggregated or anonymised information that does not reasonably identify individuals.
Where permitted by law, FrameLaPay may use such information for:
- analytics;
- research;
- product improvement;
- security;
- business intelligence; and
- service development.
44. PAYMENT DATA
Where payment services are provided, Personal Data may be shared with:
- banks;
- payment processors;
- card networks;
- financial institutions;
- merchants;
- payment gateways; and
- other relevant service providers.
Only information reasonably necessary for the relevant transaction should be disclosed.
45. KYC DATA
KYC information may be shared with authorised financial institutions, identity-verification providers and other service providers where necessary to:
- verify identity;
- comply with AML requirements;
- prevent fraud;
- comply with regulatory requirements; or
- provide the requested service.
46. DATA SECURITY INCIDENT COOPERATION
The parties shall reasonably cooperate in investigating and responding to Security Incidents affecting Personal Data.
Cooperation may include:
- sharing relevant information;
- identifying affected systems;
- containing incidents;
- investigating root causes;
- implementing remediation; and
- supporting legally required notifications.
47. BUSINESS CONTINUITY
FrameLaPay may maintain business-continuity and disaster-recovery procedures designed to protect the availability and integrity of systems containing Personal Data.
48. DATA RECOVERY
Where appropriate, FrameLaPay may use backups and disaster-recovery systems to restore data following:
- system failures;
- cybersecurity incidents;
- infrastructure failures;
- accidental deletion; or
- other operational disruptions.
49. TERMINATION
This DPA shall remain effective for as long as FrameLaPay processes Personal Data on behalf of the Customer.
Termination of the primary service agreement shall not automatically eliminate obligations relating to:
- confidentiality;
- data security;
- legal retention;
- regulatory compliance; or
- unresolved Security Incidents.
50. SURVIVAL
Provisions concerning:
- confidentiality;
- security;
- data retention;
- legal compliance;
- liability;
- dispute resolution; and
- other provisions intended to survive
shall continue after termination where applicable.
51. LIABILITY
Each party shall remain responsible for its obligations under applicable data-protection law.
Nothing in this DPA shall exclude liability that cannot legally be excluded.
52. CHANGES TO THIS DPA
FrameLaPay may update this DPA where reasonably necessary to reflect:
- changes in law;
- regulatory requirements;
- technological developments;
- changes to FrameLaPay's services;
- changes to Sub-Processors; or
- changes to data-processing practices.
Where required, customers will receive appropriate notice.
53. CONFLICT WITH OTHER AGREEMENTS
If there is a conflict between this DPA and another agreement concerning the same Personal Data processing activity, the parties shall interpret the documents to give effect to applicable data-protection requirements.
Where applicable law requires a specific provision to prevail, that legal requirement shall apply.
54. GOVERNING LAW
This DPA shall be governed by applicable law and, subject to mandatory legal requirements, the laws of the Federal Republic of Nigeria.
Where a customer is located in another jurisdiction and mandatory data-protection law applies, the parties may enter into additional provisions or transfer mechanisms required by that jurisdiction.
55. CONTACT INFORMATION
FrameLaPay
Email: contact.us@framelapay.com
Phone: +234 706 609 9909
Address:
2, Barracks Road,
Car wash bus stop off Abule-Odu,
Egbeda Isheri-Olofin,
Lagos State, Nigeria.
SCHEDULES
SCHEDULE 1 â DESCRIPTION OF PROCESSING
Subject Matter
Processing of Personal Data necessary to provide FrameLaPay's technology and financial services.
Duration
For the duration of the applicable customer relationship and any additional period required by applicable law.
Nature of Processing
Processing may include:
- collection;
- verification;
- storage;
- retrieval;
- analysis;
- transmission;
- monitoring;
- authentication;
- fraud detection;
- payment processing;
- transaction monitoring;
- customer support; and
- deletion.
Purpose
Personal Data may be processed for:
- account administration;
- payment processing;
- identity verification;
- KYC;
- AML/CFT;
- fraud prevention;
- security;
- customer support;
- regulatory compliance;
- transaction processing; and
- service delivery.
SCHEDULE 2 â CATEGORIES OF DATA SUBJECTS
Depending on the services provided:
- customers;
- prospective customers;
- merchants;
- business representatives;
- account holders;
- beneficiaries;
- payers;
- recipients;
- employees;
- directors;
- shareholders;
- beneficial owners;
- authorised representatives; and
- other individuals whose information is necessary for the service.
SCHEDULE 3 â CATEGORIES OF PERSONAL DATA
Depending on the service:
- identification data;
- contact information;
- address information;
- account information;
- financial information;
- transaction information;
- KYC/KYB information;
- device information;
- IP information;
- authentication information;
- fraud-risk information;
- business information;
- biometric information where legally permitted and necessary; and
- communications with FrameLaPay.
SCHEDULE 4 â SUB-PROCESSORS
FrameLaPay may maintain a current list of material Sub-Processors.
The list may include providers responsible for:
| Category | Purpose |
|---|---|
| Cloud hosting | Infrastructure and data storage |
| Identity verification | KYC |
| Business verification | KYB |
| Payment processing | Payment execution |
| Fraud detection | Fraud prevention |
| AML monitoring | Financial-crime compliance |
| Blockchain analytics | Digital-asset risk monitoring |
| Communications | Email/SMS/notifications |
| Customer support | Customer service |
| Cybersecurity | Security monitoring |
| Analytics | Service performance |
FrameLaPay may update this list as its technology infrastructure changes.