Data Processing Agreement

Version 1.0Effective 11 July 2026

The agreement, required under the Gambia Data Protection Act 2021, that governs how Janteh (as processor) handles personal data on behalf of the School (as controller), including security, sub-processors, breach notification, and deletion.

1. Parties and Roles

This Data Processing Agreement ("DPA") forms part of the Terms of Service between [Janteh — registered legal entity name] ("Processor", "Janteh") and the School ("Controller"). It applies to the processing of Personal Data that the Processor carries out on behalf of the Controller through the Service.

The Controller determines the purposes and means of processing the Personal Data it submits. The Processor processes that Personal Data only on the Controller’s documented instructions, which include the Terms of Service, this DPA, and the Controller’s use of the Service.

2. Subject Matter and Duration

The subject matter of the processing is the provision of the Service. Processing continues for the duration of the Controller’s subscription and until data is deleted or returned in accordance with this DPA.

3. Nature and Purpose of Processing

The Processor processes Personal Data to host, store, transmit, and make available the school-management functions of the Service, including enrolment, attendance, grading, reporting, fees, communication, and related features, and to secure and support the Service.

4. Categories of Data Subjects and Personal Data

Data subjects include the Controller’s administrators, staff, students (including minors), and parents/guardians. Categories of Personal Data are described in Annex A.

5. Processor Obligations

  • process Personal Data only on the Controller’s documented instructions, including for international transfers, unless required to act otherwise by law (in which case it will inform the Controller where legally permitted);
  • ensure that persons authorised to process the data are bound by confidentiality;
  • implement appropriate technical and organisational security measures (Annex C);
  • respect the conditions for engaging sub-processors set out in this DPA;
  • assist the Controller, taking into account the nature of the processing, in responding to data-subject requests and in meeting its security, breach-notification, and impact-assessment obligations;
  • delete or return Personal Data at the end of the provision of the Service as set out below;
  • make available information necessary to demonstrate compliance with these obligations.

6. Controller Obligations

  • establish a lawful basis for the processing and, for students under 18, obtain parental or guardian consent before their data is stored;
  • ensure the accuracy of the Personal Data it submits;
  • issue only lawful instructions and use the Service in accordance with the Terms and applicable law;
  • respond to data-subject requests as the controller, with the Processor’s assistance.

7. Sub-processors

The Controller authorises the Processor to engage the sub-processors listed in Annex B to provide the Service. The Processor imposes data-protection obligations on each sub-processor that are no less protective than those in this DPA and remains responsible for their performance. The Processor will inform the Controller of any intended addition or replacement of a sub-processor, giving the Controller the opportunity to object on reasonable data-protection grounds.

8. Security

The Processor implements and maintains the technical and organisational measures described in Annex C, appropriate to the risk, to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.

9. Personal Data Breach

The Processor will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller’s Personal Data, and will provide information reasonably available to it to help the Controller meet its obligation to notify the relevant authority within 72 hours of discovery under the Gambia Data Protection Act 2021.

10. Assistance with Data-Subject Rights

Taking into account the nature of the processing, the Processor will assist the Controller by appropriate technical and organisational measures, insofar as possible, to fulfil the Controller’s obligation to respond to requests to exercise data-subject rights, including access, correction, deletion, and portability. The Service provides the Controller with the ability to export its data in structured formats (CSV and JSON).

11. Audits

The Processor will make available to the Controller information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality and security arrangements and reasonable notice.

12. Deletion or Return of Data

On termination of the Service, and at the Controller’s choice, the Processor will delete or return all Personal Data and delete existing copies, unless retention is required by law. The Controller may export its data before deletion using the Service’s export functions during a reasonable window after termination.

13. International Transfers

Personal Data is hosted in the European Union (Frankfurt, Germany region). Any transfer of Personal Data outside The Gambia is carried out with appropriate safeguards consistent with the Gambia Data Protection Act 2021.

14. Liability and Governing Law

Liability under this DPA is subject to the limitations in the Terms of Service. This DPA is governed by the laws of the Republic of The Gambia.

Annex A — Categories of Personal Data

  • Identity and contact data of staff, administrators, parents, and students;
  • Student records: date of birth, gender, photo, class, enrolment, attendance, grades, report cards, and fees;
  • Content submitted by users: homework, messages, and social posts;
  • Authentication and technical data: credentials (stored securely), IP addresses, and log data.

Annex B — Sub-processors

  • Supabase — database and file storage (EU, Frankfurt, Germany);
  • Render — backend application hosting;
  • Vercel — web application hosting;
  • Resend — transactional email delivery.

Annex C — Security Measures

  • Per-school data isolation with database row-level security;
  • Authenticated access with mandatory two-factor authentication for administrators;
  • Private file storage served only via short-lived signed links;
  • Encryption of sensitive secrets at rest and encryption of traffic in transit (HTTPS);
  • An immutable audit log of sensitive actions;
  • Rate limiting and account-lockout protections against abuse.

Contact

Questions about this DPA can be sent to legal@ijanteh.com.

Last updated: 11 July 2026.

Data Processing Agreement — Janteh