THIS DATA PROCESSING AGREEMENT (the “Agreement” or “DPA”) governs the processing of personal data carried out by SMA on behalf of the Client in connection with the delivery of marketing, branding, website development, technologies, analytics, consulting, AI and automation, dashboard access, and other related digital services. It forms part of, and is incorporated into, any service agreement, proposal, contract, statement of work, or Terms of Use (collectively, the "Service Agreement") entered into between:
SELLABLE MARKETING AGENCY (hereinafter the “Processor”, “Service Provider”, “SMA”, “we”, “our”, or “us”), which expression shall, where the context so admits, mean and include its agents, assigns, legal representatives, privies, successors-in-title and such other person and/or entity acting under its express or implied mandate) of the ONE PART;
AND
The Client (hereinafter the “Processor”, “Controller”, “Client”, "you", or "your"), which expression shall, where the context so admits, mean and include your assigns, legal representatives, privies, successors-in-title) of the OTHER PART.
SMA and the CLIENT are hereinafter referred to collectively as the “Parties” and individually as the “Party”.
The purpose of this Agreement is to establish the respective rights and obligations of the parties regarding the processing of Personal Data and to ensure compliance with applicable data protection and privacy laws, including, where applicable, the UK General Data Protection Regulation (UK GDPR), the EU General Data Protection Regulation (EU GDPR), and any other applicable data protection legislation.
For this Agreement, the following words shall have the meaning as set out hereunder:
- "Personal Data"
- means any information relating to an identified or identifiable natural person, including, without limitation, names, email addresses, telephone numbers, IP addresses, device identifiers, customer information, marketing data, business data, usage data, and similar information.
- "Processing"
- means any operation or set of operations performed on Personal Data, whether by automated means or otherwise, including collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure, transfer, restriction, deletion, or destruction.
- "Controller"
- means the party which determines the purposes and means of processing Personal Data.
- "Processor"
- means the party which processes Personal Data on behalf of the Controller.
3.1. The Processor shall process Personal Data solely for the purpose of providing the services requested by the Client, including but not limited to:
- Marketing campaign management;
- CRM implementation and management;
- Lead generation;
- Email marketing;
- Digital advertising services;
- Website and landing page development;
- Dashboard and portal access and administration;
- Analytics and reporting;
- Technology infrastructure;
- Automation workflows;
- Customer communications;
- Technical support; and
- Performance optimisation.
3.2. The Processor shall process Personal Data only on the documented instructions of the Client, unless otherwise required by applicable law.
4.1 Depending on the services provided, the Processor may process the following:
- Contact information;
- Business information;
- Customer and prospect data;
- Website visitor information;
- Marketing and analytics data;
- User account and login credentials;
- Uploaded documents and files;
- Communication records;
- Payment-related metadata; and
- Employee or contractor information provided by the Client.
5.1 Personal Data subjects may include:
- Customers;
- Prospective Customers;
- Employees;
- Contractors;
- Website visitors;
- Business representatives;
- Subscribers; and
- Users of the Client’s platforms, products, or services.
6.1 The Client represents and warrants that:
- It has lawful grounds to collect, process and share the Personal Data with the Processor;
- All appropriate privacy notices and consents have been obtained where required;
- Instructions have been provided to the Processor to comply with applicable laws; and
- The Client remains the Controller of all Personal Data processed under this Agreement, unless otherwise agreed in writing.
6.2. The Client shall remain solely responsible for the accuracy, quality, legality, and integrity of all Personal Data provided to the Processor, including compliance with any legal obligations relating to consent management and data protection.
The Processor shall:
- Process Personal Data only in accordance with the Client’s documented instructions and the provisions of this Agreement;
- Ensure that persons authorised to process Personal data are bound by confidentiality obligations;
- Implement appropriate technical and organisational security measures;
- Restrict access to Personal Data to authorised personnel who require such access for the performance of the services;
- Notify the Client without undue delay upon becoming aware of a confirmed Personal Data breach affecting the Client’s Personal Data; and
- Provide reasonable assistance to the Client in fulfilling its obligations under applicable data protection laws, where such assistance is reasonably required.
8.1. The Processor shall maintain reasonable administrative, technical, and organisational safeguards designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or unauthorised access. Such safeguards may include, where appropriate:
- Role-based access controls;
- Authentication and password protection;
- Encrypted communications where applicable;
- Secure hosting infrastructure;
- Access monitoring and logging;
- Restricted staff permissions; and
- Backup and disaster recovery procedures.
8.2. The Client acknowledges that no electronic storage system, cloud platform, or method of internet transmission can be guaranteed to be completely secure.
9.1. The Client authorises the Processor to engage third-party service providers (the “Subprocessors”) where reasonably necessary for the provision of the services.
9.2. Such Subprocessors may include providers of cloud hosting infrastructure, CRM systems, analytics platforms, payment processing services, communication platforms, email delivery services, automation software, advertising platforms, and related technology services.
9.3. The Processor shall use reasonable efforts to ensure that each authorised Subprocessor is contractually required to maintain appropriate data protection and confidentiality standards.
10.1. The Client acknowledges that Paid service checkout/invoice acceptance / onboardingPaid service checkout/invoice acceptance / onboardingPersonal Data may be transferred or processed in jurisdictions outside the Client’s country of residence.
10.2. Where applicable, the Processor shall implement reasonable safeguards for such transfers, including recognised contractual or other lawful transfer mechanisms.
11.1. In the course of providing the Services, the Processor may receive, access, process, or otherwise become aware of Personal Data and other confidential or proprietary information belonging to the Client or its affiliates (the "Confidential Information"). For this Agreement, Confidential Information includes, without limitation, Personal Data, customer and prospect information, business records, marketing and sales strategies, financial information, pricing, trade secrets, business methods, technical documentation, software, databases, reports, analytics, operational processes, research, product information, know-how, and any other information disclosed by or on behalf of the Client that is identified as confidential or that ought reasonably to be understood to be confidential by its nature or the circumstances of its disclosure.
11.2. The Processor shall keep all Confidential Information strictly confidential and shall not, except as expressly permitted under this Agreement or with the Client's prior written consent, disclose, copy, use, reproduce, or permit access to such Confidential Information for any purpose other than the performance of the services. The obligations contained in this clause shall apply throughout the term of this Agreement and shall continue after its termination or expiry for so long as the Confidential Information remains confidential or is otherwise protected by applicable law.
11.3. The obligations of confidentiality shall not apply to Confidential Information that:
- Is or becomes publicly available through no breach of this Agreement;
- Was lawfully in the Processor's possession before its disclosure by the Client;
- Is lawfully received from a third party without restriction on disclosure; or
- Is required to be disclosed pursuant to applicable law, regulation, or a valid order of a court or governmental authority, provided that, where legally permissible, the Processor gives the Client prompt written notice of such requirement and discloses only the minimum information required.
11.4. The Processor shall ensure that all employees, contractors, agents, and authorised subprocessors with access to Confidential Information are bound by confidentiality obligations no less protective than those contained in this Agreement and shall remain responsible for their compliance.
12.1. The Processor shall retain Personal Data only for so long as reasonably necessary to provide the contracted services, comply with legal or regulatory obligations, maintain business, accounting, and financial records, resolve disputes, or protect its legitimate legal interests.
12.2. Upon termination, cancellation or completion of the Service Agreement, the Processor may retain Client data for a period not exceeding twelve (12) months for backup, administrative, legal, security, audit, recovery, or dispute resolution purposes.
12.3. Upon expiry of the retention period, the Processor shall securely delete or irreversibly anonymise the applicable Personal Data, unless a longer retention period is required by applicable law.
12.4. The Client is responsible for requesting or downloading any data, reports, files, or other materials before the expiration of the retention period. The Processor shall not be liable for any loss of data resulting from deletion carried out in accordance with this Agreement.
13.1. Where applicable, the Processor shall provide reasonable assistance to the Client in responding to requests relating to:
- Access and deletion requests;
- Rectification requests;
- Restriction of processing;
- Data portability; and
- Other rights available under applicable data protection laws.
13.2. The Client remains primarily responsible for handling and responding to such requests.
14.1. Upon becoming aware of a confirmed Personal Data Breach affecting the Client's Personal Data, the Processor shall:
- Investigate the incident;
- Take reasonable measures to contain and mitigate its effects;
- Notify the Client without undue delay where required by applicable law; and
- Provide available information reasonably necessary for the Client to comply with its legal obligations.
15.1. To the fullest extent permitted by law, the Processor shall not be liable for any indirect, incidental, consequential, special, punitive, or exemplary damages arising out of or relating to the processing of Personal Data.
15.2. The Client acknowledges that internet-based services, cloud platforms, third-party software, automation tools, and digital infrastructure may be subject to interruptions, delays, vulnerabilities, or failures beyond the Processor's reasonable control.
15.3. Nothing in this Agreement shall exclude or limit liability where such exclusion or limitation is prohibited by applicable law.
16.1. This Agreement shall take effect on the commencement of the Service Agreement and shall remain in force for as long as the Processor processes Personal Data on behalf of the Client.
16.2. Termination of this Agreement shall not affect any rights, liabilities, or obligations accrued before the effective date of termination.
This Agreement shall be governed by and interpreted in accordance with the laws of the Federal Republic of Nigeria, unless otherwise required by applicable data protection laws.
Questions relating to privacy, security, or data processing should be directed to us via:
- Website
- www.sellablemarketing.com
By using our services, platforms, dashboards, websites, or systems, the Client acknowledges and agrees to this Data Processing Agreement.
