Data Processing Agreement

555DIRECT LIMITED · Registered in Kenya · Tudor, Mombasa

Contact: [email protected]

Version 1.0 — DRAFT · Prepared 22 September 2026

This is a draft and has not yet been reviewed by an advocate. It is written to be read by one: the structure, the obligations and the annexes follow what the Kenyan Data Protection Act 2019 and the Tanzanian Personal Data Protection Act 2022 require of a processor. Have it checked before you rely on it with a customer.

1. Why this document exists

When a clearing agent puts their clients, drivers and consignees into Managix, those records contain other people's personal data — names, phone numbers, ID and KRA PIN numbers, vehicle and licence details.

Under Kenyan and Tanzanian law that makes two separate roles:

The law requires that relationship to be written down. That is what this is. It is not optional and it is not a formality: a controller who hands personal data to a processor without a written agreement is in breach whatever the processor does.

2. What this covers

ItemDetail
Subject matterProviding the Managix logistics management service
DurationFor as long as your subscription is active, plus the retention period in clause 8
Nature and purposeStoring, organising, displaying, backing up and transmitting your business records so that you and your staff can run your clearing, cargo and fleet work
Categories of data subjectYour clients and their contacts; your staff and drivers; consignees and transporters named on your jobs
Categories of personal dataNames, phone numbers, email addresses, postal and physical addresses, KRA/TRA PIN and tax identifiers, national ID or passport numbers where you enter them, driving licence details, vehicle registrations, and job and payment records that relate to an identifiable person
Special categoriesNone requested and none required. Managix has no field for health, biometric, religious, political or similar data. If you enter such data into a free-text field you do so as controller and on your own assessment

3. What we will and will not do

We will:

We will not:

4. Sub-processors

We use these, and only these. Each is engaged under terms no weaker than this agreement.

WhoWhat they doWhere
SupabaseThe database and authentication holding your recordsCloud hosting, region as stated in your account
CloudflareServing the website and application; DNSGlobal edge network
ResendSending service email — sign-up confirmations, password resetsCloud hosting
Payment providerTaking subscription payments. We never see or store card numbers — card entry happens on the provider's own pageAs disclosed at checkout

We will give you 30 days' written notice before adding or replacing a sub-processor. If you object on reasonable data-protection grounds and we cannot resolve it, you may terminate and receive a pro-rata refund of the unused term.

5. Transfers out of Kenya and Tanzania

Some of the providers above hold data outside East Africa. Where that happens we rely on the safeguards permitted by section 49 of the Kenyan Data Protection Act 2019 and the equivalent Tanzanian provisions — including the provider's own contractual protections and, where applicable, your consent given by using the service. You should satisfy yourself that this is acceptable for your own clients before entering their data.

6. Security

See Annex A. In summary: every company's records are separated at the database level, not by application code; staff see only the categories and the money they are cleared for; and every change is written to a tamper-evident log.

7. If something goes wrong

If we become aware of a personal data breach affecting your records we will tell you without undue delay and in any case within 48 hours, with what we know: what happened, which data and roughly how many people are affected, what we have done, and what we suggest you do. Reporting to the Office of the Data Protection Commissioner is your duty as controller; we will give you everything you need to do it.

8. Deletion and return

9. Helping you answer your own clients

If one of your clients asks you to show, correct, delete or hand over their data, that request is yours to answer. If they come to us instead, we will point them to you and tell you. We will help you answer within the time the law gives you, at no charge for anything reasonable.

10. Audit

You may ask, once a year, for written confirmation of how we meet this agreement, and we will answer within 30 days. If your own regulator requires an inspection we will cooperate, on reasonable notice and during business hours.

11. Liability and precedence

This agreement forms part of the Terms of Service. Where this document and the Terms conflict on the handling of personal data, this document wins. On everything else, the Terms win.

Annex A — Security measures

MeasureHow
Separation between companiesEnforced by row-level security in the database itself, so one company's records are invisible to another even if the application is bypassed entirely
Access controlFive clearance levels. Financial figures are withheld by the server from staff not cleared to see them — they are not merely hidden on screen
Separation of lines of businessClearing, cargo and fleet records are walled from one another per user
EncryptionHTTPS in transit; encryption at rest by the hosting provider
AuthenticationEmail and password with confirmation; password reset by emailed link; sessions expire
Card dataNever touched. Card details are entered only on the payment provider's own hosted page. Managix stores no card number and no card token that could be used to charge
Audit trailEvery change records who, what and when, in a hash-chained log that shows if an entry is altered or removed
BackupsHeld by the database provider; rolled off within 90 days
Staff accessLimited to those who need it to operate or support the service, each bound to confidentiality

Annex B — Signature

This agreement takes effect when you start using Managix and continues for as long as we hold your records. If your own compliance requires a signed copy, write to [email protected] and we will sign and return one naming your company.

In one sentence: your clients' details are yours, we hold them only to run the service you pay for, we do not look at them or sell them, and you can take them back or have them deleted whenever you want.