Effective Date: August 6, 2026
Last Updated: August 6, 2026
Service Provider: EasyCity Systems Ltd.
1. Introduction
This Data Processing Agreement (DPA) is entered into between EasyCity Systems Ltd. ("Data Processor" or "we") and the entity or individual using Zolar ("Data Controller" or "you"). This DPA governs the processing of personal data on behalf of the Data Controller.
This DPA is intended to comply with the requirements of the General Data Protection Regulation (GDPR), the Nigeria Data Protection Regulation (NDPR), and other applicable data protection laws.
GDPR and NDPR Compliance
This DPA is designed to meet the requirements of Article 28 of the GDPR and similar provisions in the NDPR and other data protection laws.
2. Definitions
2.1 Key Terms
For purposes of this DPA:
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation or set of operations performed on personal data.
- "Data Controller" means the entity that determines the purposes and means of the processing of personal data.
- "Data Processor" means the entity that processes personal data on behalf of the Data Controller.
- "Data Subject" means the natural person to whom personal data relates.
- "Supervisory Authority" means the data protection authority responsible for overseeing compliance with data protection laws.
3. Scope of Processing
3.1 Subject Matter
This DPA covers the processing of personal data for the following purposes:
- Providing solar advisory services
- Facilitating marketplace transactions
- Managing user accounts and profiles
- Processing payments and transactions
- Providing customer support
- Communicating with users
3.2 Categories of Data
The categories of personal data processed include:
- Contact information (name, email, phone)
- Account credentials and authentication data
- Location data (with user consent)
- Energy usage data (with user consent)
- Transaction and payment data
- Communication data (messages, support tickets)
3.3 Categories of Data Subjects
Data subjects include:
- Platform users (consumers)
- Installers and dealers
- Website visitors
- Newsletter subscribers
4. Data Processor Obligations
4.1 Processing Instructions
We agree to:
- Process personal data only on your documented instructions
- Not process personal data for purposes other than those specified
- Ensure that authorized personnel process personal data
- Comply with all applicable data protection laws
4.2 Confidentiality
We agree to:
- Maintain confidentiality of all personal data
- Ensure that personnel are bound by confidentiality obligations
- Not disclose personal data except as required by law or your instructions
- Protect personal data from unauthorized disclosure
4.3 Security Measures
We implement appropriate technical and organizational measures including:
- Pseudonymization and encryption of personal data
- Ability to ensure confidentiality, integrity, availability, and resilience of processing systems
- Ability to restore availability and access to personal data in a timely manner
- Regular testing and evaluation of technical and organizational measures
5. Sub-Processing
5.1 Authorization
We may engage sub-processors for:
- Cloud hosting and infrastructure services
- Payment processing services
- Email and communication services
- Analytics and monitoring services
- Customer support services
5.2 Sub-Processor Requirements
We ensure that sub-processors:
- Provide adequate guarantees to implement appropriate technical and organizational measures
- Are bound by data protection obligations at least as restrictive as those in this DPA
- Comply with applicable data protection laws
5.3 Notice and Objection
We will:
- Provide you with notice of intended sub-processor appointments
- Allow you a reasonable period to object to sub-processor appointments
- Not use objected sub-processors unless we can demonstrate adequate safeguards
6. Data Subject Rights
6.1 Assistance
We agree to assist you in:
- Responding to data subject requests
- Facilitating the exercise of data subject rights
- Providing information to data subjects
- Correcting or erasing personal data
6.2 Data Subject Rights
Data subjects have the right to:
- Access their personal data
- Rectify inaccurate personal data
- Erase their personal data (right to be forgotten)
- Restrict processing of their personal data
- Data portability
- Object to processing
7. Data Breach Notification
7.1 Notification Obligations
We agree to:
- Notify you without undue delay of any personal data breach
- Provide sufficient information to enable you to meet your notification obligations
- Cooperate with you in the investigation and remediation of breaches
7.2 Notification Content
Breach notifications will include:
- Nature of the breach
- Categories and approximate number of data subjects concerned
- Categories and approximate number of personal data records concerned
- Likely consequences of the breach
- Measures taken to address the breach
8. Data Deletion and Return
8.1 Deletion or Return
Upon termination of this DPA:
- We will delete or return all personal data to you
- We will delete existing copies unless required by law to retain
- We will certify deletion upon request
8.2 Retention Period
We retain personal data for:
- The duration necessary to provide services
- As required by applicable laws
- As specified in our Privacy Policy
9. Audit and Compliance
9.1 Audit Rights
You may audit our compliance with this DPA by:
- Providing reasonable notice of audit requests
- Conducting audits during normal business hours
- Limiting audits to once per calendar year unless there is a specific concern
- Using independent third-party auditors with our consent
9.2 Compliance Certifications
We maintain:
- Regular security assessments
- Compliance with industry standards (e.g., ISO 27001)
- Documentation of security measures
- Records of processing activities
10. International Data Transfers
10.1 Data Transfers
We may transfer personal data to countries outside the European Economic Area (EEA) only if:
- The European Commission has issued an adequacy decision for the country
- Appropriate safeguards are in place (e.g., Standard Contractual Clauses)
- Specific derogations apply under applicable law
10.2 Safeguards
For international transfers, we ensure:
- Adequate protection of personal data
- Data subjects' rights are enforceable
- Data subjects have effective administrative and judicial remedies
11. Liability and Indemnification
11.1 Liability
We are liable to you for:
- Damages caused by our breach of this DPA
- Damages caused by our breach of data protection laws
- Damages caused by our unauthorized processing of personal data
11.2 Limitations
Our liability is limited to:
- Direct damages only
- Not exceeding the fees paid under the applicable service agreement in the 12 months preceding the breach
- Excluding indirect, consequential, or punitive damages
12. Term and Termination
12.1 Term
This DPA remains in effect:
- For the duration of our provision of services to you
- Until all personal data has been deleted or returned
- As required by applicable data protection laws
12.2 Termination
This DPA may be terminated by:
- Either party with 30 days written notice
- Immediately for material breach
- Automatically upon termination of the underlying service agreement
13. Governing Law and Jurisdiction
13.1 Governing Law
This DPA is governed by:
- The laws of the country where you are established
- GDPR for processing of personal data of EEA data subjects
- NDPR for processing of personal data of Nigerian data subjects
- Applicable data protection laws for other jurisdictions
13.2 Dispute Resolution
Disputes will be resolved by:
- Good faith negotiation
- Mediation if negotiation fails
- Courts of the jurisdiction where you are established
14. Updates to This DPA
14.1 Right to Modify
We reserve the right to modify this DPA to reflect changes in data protection laws or our practices. Changes will be effective 30 days after posting to the Platform.
14.2 Notification
We will notify you of material changes by:
- Emailing you at your registered email address
- Posting a notice on the Platform
- Updating the "Effective Date"
14.3 Continued Use
Your continued use of the Platform after changes to this DPA constitutes acceptance of the updated terms.
15. Contact Information
15.1 DPA Inquiries
For DPA-related inquiries, contact us at:
- Email: dpo@easycitysystems.com.ng
- Phone: [To be provided]
- Address: EasyCity Systems Ltd., [Full Address to be provided]
16. Related Policies
This DPA should be read together with our:
17. Acknowledgment
By using Zolar, you acknowledge that you have read, understood, and agreed to this Data Processing Agreement. You acknowledge that we act as a Data Processor on your behalf for the processing of personal data as described in this DPA.
This DPA may be updated from time to time, and your continued use of the Platform constitutes acceptance of any changes.