Data processing agreement
This agreement applies when an institution (a ministry, agency, primary health care board, partner organization or similar) arranges for its staff to use Mataki and signs it with Scalentric Limited, alone or as part of a master service agreement. It is the written agreement between a data controller and a data processor that section 29(2) of the Nigeria Data Protection Act 2023 (the Act) requires.
1. Parties and roles
The Institution is the data controller of the personal data described in Schedule 1. Scalentric Limited (the Processor), the provider of Mataki, processes that data on the Institution’s behalf. Scalentric Limited stays the controller of the records it keeps only to secure the service as a whole: firewall records of refused requests, fault records and timing records. Its privacy notice at usemataki.app/privacy describes them.
2. Instructions
The Processor processes the personal data only to provide Mataki to the Institution’s staff as described in Schedule 1, and on the Institution’s other documented instructions. The Institution’s use of Mataki’s settings (for example approving or disabling accounts, or configuring single sign-on) counts as an instruction. The Processor tells the Institution at once if it believes an instruction breaks the Act, and may then decline to follow it.
3. What stays outside this agreement
Assessments, analyses and notes made in Mataki stay on the device that made them, encrypted under a key derived from the user’s password or data passphrase, and are never sent to the Processor. Tracking-link summaries and updates reach the server encrypted with keys the Processor never receives, so the Processor stores them without being able to read them. Mataki is designed for aggregate programme data, and the Institution undertakes that its staff will not enter the names or identifiers of patients, caregivers or health workers.
4. Confidentiality
The Processor allows only the people who need it to run, secure or support Mataki to reach the personal data, and binds each of them to confidentiality.
5. Security
The Processor applies the technical and organizational measures in Schedule 2, which are designed to meet section 39 of the Act. It may improve them at any time, provided the overall level of protection does not fall.
6. Sub-processors
The Institution authorizes the sub-processors in Schedule 3. The Processor gives the Institution at least 30 days’ written notice before adding or replacing one. The Institution may object on reasonable data protection grounds within that period, and if the parties cannot resolve the objection the Institution may end this agreement and the service without penalty. The Processor places the same data protection obligations on each sub-processor by written contract and stays responsible to the Institution for each sub-processor’s performance.
7. Transfers outside Nigeria
Mataki’s server is hosted by Hostinger, and Hostinger may process the data outside Nigeria. The Processor transfers personal data outside Nigeria only on a basis permitted by sections 41 to 43 of the Act, including the data protection terms in its contract with Hostinger, and tells the Institution on request where the server is located.
8. Rights of data subjects
Mataki lets each user see, correct and delete their own account, and gives a data report on deletion. For any other request under sections 34 to 38 of the Act (access, rectification, erasure, restriction, objection and portability), the Processor forwards to the Institution any request it receives about the Institution’s staff within 5 working days, and helps the Institution answer it.
9. Personal data breaches
- The Processor notifies the Institution without undue delay, and within 24 hours of becoming aware, of any personal data breach affecting the Institution’s data, as section 40(1) of the Act requires of a processor.
- The notice describes what happened, the data and the number of people affected as far as known, the likely consequences, what the Processor has done and proposes to do, and a contact. Information not yet known follows as soon as it is.
- The Processor gives the Institution what it needs to notify the Nigeria Data Protection Commission within 72 hours under section 40(2), and to inform the people affected under section 40(3) where the breach is likely to put their rights and freedoms at high risk.
- The Processor keeps a record of every breach, its effects and the remedial action taken.
10. Impact assessments and the Commission
The Processor gives the Institution the information it reasonably needs for a data privacy impact assessment under section 28 of the Act, and cooperates with the Nigeria Data Protection Commission on request.
11. Return and deletion
When the service ends, the Processor gives the Institution, within 30 days and on request, a machine-readable export of the account data of the Institution’s staff, and then erases that data from the server. Erasure follows Mataki’s standard process: the account, its sign-ins, its tracking links and its outgoing emails are deleted, and its email and account key are replaced in every log, so nothing that names the person remains. Users can still delete assessments from their own devices. Where the law requires the Processor to keep any data longer, it keeps only that data, protects it under this agreement, and deletes it when the requirement ends.
12. Information and audits
The Processor makes available the information needed to show that it meets this agreement and section 29 of the Act. Once a year, or after a personal data breach, the Institution may audit the Processor, by written questions or by an inspection carried out by the Institution or an independent auditor bound by confidentiality, with 30 days’ notice and during working hours. Each party bears its own costs unless the audit finds a material breach by the Processor.
13. Term, liability and law
This agreement lasts as long as the Processor processes personal data for the Institution. Each party’s liability under it is subject to the limits in the parties’ master service agreement, if they have one. It is governed by the laws of the Federal Republic of Nigeria. If it conflicts with any other agreement between the parties on the protection of personal data, this agreement prevails.
Schedule 1: Description of the processing
- Data subjects: the Institution’s staff, contractors and partners who hold Mataki accounts, and the administrators who approve them.
- Personal data: name, email address, job title and institution if given, the level and place each account works at, approval and account status; for each sign-in a random identifier, a one-way hash of its secret, the device name the browser reports and its dates; salted one-way hashes of the networks the account signed in from; audit log entries of sign-ins, account actions and tracking-link changes with who acted; for single sign-on, the identity provider’s issuer and the stable identifier it gives for the person.
- Special categories: none. Mataki is not designed to process health data about individuals, and the Institution’s staff must not enter it.
- Purpose: to create, confirm, approve and secure accounts; to sign users in, including through the Institution’s identity provider; to relay encrypted tracking updates; to keep an audit trail; and to send account emails.
- Duration: for as long as the account exists. Unconfirmed registrations are erased after 48 hours; accounts the super administrator deletes are kept for 60 days for possible restoration and then erased; a user who deletes their own account is erased at once. Logs keep their most recent entries and drop the oldest.
Schedule 2: Security measures
- Encryption in transit with https only, HTTP Strict Transport Security with preloading, and passwords additionally sealed in the browser to the server’s public key (ECDH P-256 and AES-256-GCM) before they are sent.
- Passwords kept only as bcrypt hashes; sign-in secrets kept only as one-way hashes, replaced at least hourly, with a copied secret ending the sign-in.
- Sign-ins limited to 90 days and three devices per account, and ended at once by sign-out, password change, deletion or an administrator.
- Accounts work only after email confirmation and approval by an administrator for their place; administrators see only their own area.
- Single sign-on per institution through OpenID Connect (with state, nonce and PKCE, and verified signatures) or SAML 2.0 (with signed assertions), with callbacks fixed to registered addresses.
- Rate limits on sign-in, registration, confirmation and single sign-on; account lockout after repeated wrong passwords; a firewall that blocks common attack patterns and bans networks that probe the service.
- Administrative functions only at an unguessable address, only for verified sessions with administrator rights, and every administrative view and action recorded in the audit log.
- Server data kept outside the public web folder where the host allows, and server errors shown to users without any technical detail.
- Faults recorded centrally with a reference number; an incident response plan with emergency controls to end every sign-in, pause registration and rotate keys.
- Erasure that removes the account and replaces its email and account key in every log.
Schedule 3: Sub-processors
- Hostinger (Hostinger International Ltd and its affiliates): hosting of the Mataki server and its files, and outgoing account email when Hostinger’s mail service is used. Location: may be outside Nigeria.
- The Institution’s own identity provider, used for single sign-on, is the Institution’s service and is not a sub-processor of Scalentric Limited.