Legal

Data Processing Addendum

The processor terms that apply when a logistics provider processes end-customer personal data through the OhShip platform. Published in full so providers can rely on them without a separate negotiation.

Last updated 5 August 2026

1. Scope and roles

This addendum applies between Nextplace Technologies Limited (RC 1813382) ("Nextplace", the Processor) and a logistics provider using the OhShip platform (the Controller). It forms part of our Terms of Service and of any signed Platform Services Agreement.

In respect of end-customer personal data processed through the platform, the logistics provider is the data controller and Nextplace is the data processor under the Nigeria Data Protection Act 2023 (NDPA) and the General Application and Implementation Directive 2025.

account_tree

Where we are the controller instead

For data about the provider itself and its staff — account records, billing, support correspondence, KYC — we act as controller in our own right. That processing is governed by our Privacy Policy, not by this addendum.

2. Processing instructions

We process end-customer personal data only on the Controller's documented instructions, which comprise: this addendum, the Terms of Service, the configuration the Controller sets in the platform, and the actions its users take in the dashboard and API.

We will not process that data for our own purposes. We will not sell it, use it for our own marketing, use it to train models for third parties, or disclose it to another provider on the platform. If we consider an instruction to breach the NDPA, we will tell the Controller promptly.

Where we are legally compelled to process or disclose data, we will inform the Controller beforehand unless the law prohibits us from doing so.

3. Your duties as controller

The Controller is responsible for:

  • establishing and documenting a lawful basis for the processing it instructs;
  • providing a privacy notice to its end customers and obtaining any consent required;
  • responding to data-subject requests from its end customers, with our assistance under section 9;
  • the accuracy and lawfulness of the data it uploads or instructs us to process;
  • appointing a Data Protection Officer and completing NDPC registration or audit filings where it qualifies as a data controller of major importance; and
  • controlling access within its own organisation, including provisioning and de-provisioning its staff accounts.

4. Our duties as processor

  • process personal data only on documented instructions, as set out in section 2;
  • ensure that personnel authorised to process the data are bound by confidentiality obligations;
  • implement and maintain the technical and organisational measures in section 5;
  • engage sub-processors only under section 7, and remain responsible for their performance;
  • assist the Controller with data-subject requests, breach notification, data protection impact assessments and NDPC engagement, so far as reasonable;
  • make available the information reasonably needed to demonstrate compliance with this addendum; and
  • return or delete the data on termination, as set out in section 10.

5. Security measures

We maintain technical and organisational measures appropriate to the risk, including:

  • encryption of data in transit using TLS;
  • passwords stored only as salted cryptographic hashes, and token-based authentication with expiry;
  • logical tenant isolation, so one provider cannot read or write another provider's data;
  • role-based access control, with internal access limited to what a role requires;
  • no storage of full card numbers or CVVs — card details are captured by a CBN-licensed payment provider, and a saved card is held only as that provider's token with a masked number, expiry and brand;
  • logging of administrative actions, plus continuous error and availability monitoring;
  • managed, access-controlled cloud infrastructure; and
  • regular backups, with restoration procedures for availability incidents.

We may change specific measures over time provided the overall level of security is not reduced.

6. Breach notification

On becoming aware of a personal data breach affecting the Controller's data, we will notify the Controller without undue delay so that it can meet its own 72-hour notification duty to the NDPC. Our notification will describe, so far as known at the time: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. We will provide updates as the investigation progresses and cooperate with the Controller's own notifications.

7. Sub-processors

The Controller gives general authorisation for us to engage the sub-processors below. Each is bound by data protection obligations no less protective than this addendum.

Sub-processorPurposeLocation
Paystack Payments LimitedCard and bank payment processing, settlement splits, and dedicated virtual accountsNigeria
Monnify (Moniepoint Inc.)Alternative payment processing and bank account verificationNigeria
Smile IdentityIdentity and document verification (KYC) checksNigeria and United States
Amazon Web ServicesCloud hosting, database storage, file storage and content deliveryOutside Nigeria
NovuDelivery of transactional notifications (in-app and email)Outside Nigeria
SentryApplication error monitoring and diagnosticsOutside Nigeria
Carrier partnersFulfilment of shipments — pickup, transport, customs clearance and delivery. Includes DHL, FedEx, UPS, Aramex, Fez Delivery and Terminal Africa, depending on the carriers your provider has enabled.Varies by carrier and route

We will give the Controller notice before adding or replacing a sub-processor in a way that materially affects the processing. Where the Controller reasonably objects on data protection grounds, the parties will discuss a resolution in good faith; if none is found, the Controller may terminate the affected service.

8. International transfers

Some sub-processors operate outside Nigeria, so personal data may be transferred and stored abroad. We rely on the transfer conditions in Part VIII of the NDPA, including contractual safeguards requiring an adequate level of protection, processing limited to our documented instructions, and appropriate security and confidentiality undertakings.

9. Assistance and audit

  • Data-subject requests. Where an end customer contacts us directly, we will not respond substantively but will refer the request to the Controller and confirm we have done so. Where the Controller needs data to answer a request, the dashboard and export tools provide it; we assist further where reasonably required.
  • Records and information. On reasonable written request, and no more than once a year unless a regulator or a breach requires otherwise, we will provide information sufficient to demonstrate compliance with this addendum.
  • Audit. Where an audit is required by the NDPC or by law, we will cooperate on reasonable notice, during business hours, subject to confidentiality and to not disrupting the platform or exposing another provider's data. The Controller bears its own audit costs.

10. Return and deletion

The Controller may request a complete export of its data in a commonly usable format at any time, not only on termination. On termination we make an export available on request for 30 days.

On the Controller's request, and on discontinuation of the service, we will permanently delete the Controller's data from our live systems and confirm deletion in writing. This is subject only to routine backup rotation, where copies cycle out on our ordinary schedule, and to records we are required by law to retain.

11. Term and precedence

This addendum takes effect when the Controller first accesses the platform and continues for as long as we process personal data on its behalf. Where it conflicts with the Terms of Service or a Platform Services Agreement on a data protection matter, this addendum prevails. A Controller that requires a countersigned copy can request one at support@ohship.africa.

Annex — processing details

Subject matter and duration

Provision of the OhShip white-label logistics platform, for the duration of the Controller's subscription plus the retention periods in section 10.

Nature and purpose of processing

Collection, storage, structuring, retrieval, use, transmission to carriers and payment providers, and erasure of personal data, for the purpose of quoting, booking, paying for, fulfilling, tracking and supporting shipments under the Controller's brand.

Categories of data subjects

  • End customers of the Controller who book shipments.
  • Senders and recipients named on shipments.
  • Staff of the Controller who use the admin dashboard.

Categories of personal data

  • Identity and contact data — names, email addresses, phone numbers.
  • Address data — pickup and delivery addresses, and delivery instructions.
  • Shipment data — parcel descriptions, weights, dimensions, declared values, waybill and tracking numbers, status history.
  • Transaction data — amounts, references, payment status, wallet balances, settlement account details.
  • Verification data — identity and business registration details submitted for KYC, and the verification result.
  • Technical data — IP addresses, device and browser information, request logs.

Sensitive personal data

The platform is not designed for sensitive personal data as defined in the NDPA, and the Controller should not submit it except where identity-verification documents require it.