Legal
Data Processing Addendum
This Data Processing Addendum (“DPA”) applies when Asiedu Development Hub (“Processor”, “we”) processes personal data on behalf of a Novend customer organization (“Controller”, “you”) in providing the Novend Service. It supplements the Terms of Service and Privacy Policy.
Effective September 18, 2026
1. Roles
You are the controller (or equivalent) of personal data you and your staff enter into Novend about your customers, employees, and business contacts.
We act as processor (or equivalent) for that customer content when we host, sync, back up, and process it to provide the Service. We act as an independent controller for account administration data, billing, security logs, and product telemetry as described in the Privacy Policy.
2. Subject matter and duration
Subject matter: cloud hosting and processing of POS, inventory, staff, customer, and related business records in Novend, including offline sync and support.
Duration: for the term of your subscription or access, and for any retention period required for backups, legal holds, dispute resolution, or statutory obligations after closure.
3. Nature and purpose of processing
We process personal data only to provide, secure, maintain, support, and improve the Service; to prevent abuse; and to comply with law — not for unrelated advertising profiles of your end customers.
Processing includes storage, transmission, backup, indexing for search, and display to authorized users of your organization.
4. Types of personal data and data subjects
Depending on how you configure and use Novend, data may include names, phone numbers, emails, role and branch assignments, device identifiers, sale and return records, and similar business operations data about staff, customers, and suppliers.
You must not instruct us to process special-category or highly regulated data unless Novend expressly supports that use and you have a lawful basis.
5. Controller instructions
We process customer content according to your documented instructions: use of the product features, configuration, exports/imports you initiate, and written instructions consistent with the Terms.
If an instruction appears unlawful, we will inform you unless law prohibits that notice.
6. Confidentiality and security
We require personnel with access to customer content to maintain confidentiality and limit access on a need-to-know basis.
We implement commercially reasonable technical and organizational measures appropriate to the risk, including access controls, encryption in transit for cloud connections, and monitoring for abuse. No method of transmission or storage is perfectly secure.
7. Subprocessors
You authorize us to engage subprocessors reasonably needed to operate Novend (for example cloud hosting, authentication, email delivery, error monitoring, and payment processing).
We remain responsible for subprocessors’ performance insofar as they process customer content for us. We will impose data-protection terms no less protective than this DPA in material respects.
A current high-level list of infrastructure categories is available on request at the contact below. We will provide reasonable notice of material subprocessor changes where required by applicable law or contract.
8. International transfers
Customer content may be processed in countries where we or our subprocessors operate. Where required, we use appropriate transfer mechanisms or contractual safeguards.
9. Assistance with rights and assessments
Taking into account the nature of processing, we will provide reasonable assistance so you can respond to data-subject requests, security incidents affecting customer content, and documented DPIA/risk assessments you are legally required to perform — via product features (export, user deactivation, organization closure) and support.
You are responsible for verifying the identity of requesters who contact you about your customers.
10. Breach notification
If we become aware of a personal-data breach affecting your customer content in our systems, we will notify you without undue delay and provide information reasonably available to help you meet your own notification duties.
11. Return and deletion
During the subscription you may export many records through product features. After organization closure or termination, we delete or de-identify customer content from active systems within a commercially reasonable period, except copies retained in encrypted backups for a limited rolling window or where law requires retention.
Certified deletion timelines may vary by storage layer; contact support for status after closure.
12. Audits
Upon reasonable written request no more than once per year (unless a supervisory authority or confirmed incident requires more), we will provide information reasonably necessary to demonstrate compliance with this DPA, such as security summaries. On-site audits require mutual agreement on scope, timing, confidentiality, and cost.
13. Liability and order of precedence
Liability under this DPA is subject to the limitations in the Terms of Service unless mandatory law provides otherwise.
If this DPA conflicts with the Terms on data-processing topics, this DPA controls for those topics. Enterprise DPAs or SCCs signed separately control where they conflict with this online DPA.
14. Contact
Privacy and DPA contact: asiedudev.hub@gmail.com.
Asiedu Development Hub — Sunyani, Bono Region, Ghana.