ONYI Data Processing Agreement (DPA)
Effective Date: August 18, 2026
Version: 1.0
Governing Regulation: Nigeria Data Protection Act (NDPA) & NDPR
1. Purpose & Scope
This Data Processing Agreement ("DPA") governs the processing of personal data by ONYI on behalf of the Customer in connection with the cloud services provided under the ONYI SaaS Customer Agreement.
2. Roles of the Parties
- The Customer (Church / Ministry): Acts as the Data Controller. The Customer determines the lawful basis, purpose, and scope of processing personal data of its members, donors, workers, and visitors.
- ONYI (MicroManageIT): Acts as the Data Processor. ONYI processes personal data solely on behalf of, and in accordance with the documented instructions of, the Data Controller.
3. Documented Processing Instructions
ONYI will process personal data strictly:
- To provide, maintain, and support the ONYI church management platform.
- In accordance with the Customer's documented administrative instructions.
- To maintain platform integrity, security, and fraud prevention.
- To comply with applicable statutory and regulatory obligations.
4. Categories of Data Processed
The personal data categories processed under this DPA include:
- Identity & Demographic Data: Full names, title, gender, date of birth, marital status, photograph, church branch affiliation, cell/PCF unit.
- Contact Data: Email addresses, mobile phone numbers, physical residential addresses.
- Financial & Giving Data: Tithe, offering, donation amounts, bank transfer narration, pledge records, vows, payment gateway transaction references.
- Church Life & Engagement Data: Service attendance, cell attendance logs, prayer requests, counseling notes, volunteer roles, leadership appointments.
- Technical & Access Data: IP addresses, login timestamps, user agents, audit log action trails.
5. Categories of Data Subjects
Data subjects may include:
- Church congregation members and attendees.
- First-time and recurring visitors.
- Pastors, ministers, cell leaders, and church departmental workers.
- Donors, pledge makers, and financial contributors.
- Authorized church system administrators.
6. Technical & Organisational Security Measures
ONYI implements and maintains appropriate technical and organisational safeguards, including:
- Least-Privilege RBAC: Rigid separation of church branch records; pastors only see authorized congregations.
- Authentication Safeguards: Secure password hashing, CSRF tokens, session timeouts, and rate-limiting.
- Audit Trails: Immutable audit logging of critical database reads, writes, exports, and permission alterations.
- Data Redundancy: Automated encrypted database backups with isolated cloud storage.
- Staff Confidentiality: All ONYI personnel with access to infrastructure are bound by strict non-disclosure obligations.
7. Authorized Subprocessors
The Customer grants general written authorization for ONYI to engage material subprocessors necessary to deliver cloud infrastructure, messaging, and payments. Current material subprocessors include:
- Cloud Hosting & Database Infrastructure: AWS / Hostinger Cloud (Secure hosting, encrypted storage).
- Payment Processing: Paystack Payments Limited, Flutterwave Technology Solutions (PCI-DSS compliant gateways).
- SMS & Telecommunications: Africa's Talking Limited (SMS notification gateway).
- Transactional Email Services: Resend / SMTP Gateways (System notification delivery).
ONYI maintains a live registry of material subprocessors and provides advance notice of material changes.
8. Data Breach Notification
ONYI will notify the Customer without undue delay (and in any event within 72 hours where feasible) upon becoming aware of a confirmed security incident or breach affecting Customer personal data. The notification will describe:
- Nature and scope of the security incident.
- Categories and approximate number of data records affected.
- Immediate containment and mitigation steps executed.
- Recommended precautionary steps for the Church.
9. Assistance with Data Subject Rights
ONYI provides the Customer with automated software tools (or manual operational assistance) to fulfill data subject requests under the NDPA/NDPR, including:
- Right of Access and Data Portability (Data Export tool).
- Right to Rectification (Member profile editing).
- Right to Erasure / Anonymization (Controlled deletion request queue).
10. Termination, Data Deletion & Audits
Upon termination of the Customer Agreement, ONYI will retain data for the defined grace period to permit Customer export, after which all customer personal data will be deleted or irreversibly anonymized in accordance with the Data Retention & Deletion Policy.
Questions about this agreement?
Our team is available to assist with any legal, compliance, or data protection questions.