WASID Data Processing Agreement (DPA)
Between: the Customer identified on the applicable order form ("Customer") and Boldstep Productions Ltd, Accra, Ghana ("Boldstep"). Incorporates: the Terms of Use (Terms of Service) or, where signed, the MSA (Master Services Agreement). Last updated: 2026-07-28
This DPA matters mostly for EU/EEA/UK enterprise customers, whose procurement and legal teams will require it before sending any personal data (even just account contacts) to a Ghana-based provider. It is deliberately honest about how little personal data WASID actually processes.
1. What WASID processes — and does not
WASID's product data is event data about places (incidents, coordinates, severity, confidence), deliberately engineered not to be personal data: source text is PII-scrubbed before storage, and measurement feeds are place-aggregates (see Privacy Policy §2). The personal data Boldstep processes for a Customer is therefore narrow:
| Data | Subjects | Purpose |
|---|---|---|
| Account contact details (name, business email, role) | Customer's staff | Account management, support, billing, notices |
| API usage records tied to keys | Customer's staff (indirectly) | Abuse prevention, plan enforcement, security |
| Asset/route labels the Customer registers (Watch tier) | None by design — labels should describe places, not people | Proximity alerting |
Customer must not put personal data into asset names, route labels, or other free-text fields; the Service is not designed to hold it there (AUP §1, §3).
2. Roles
For the data in §1, Customer is the controller and Boldstep is the processor (GDPR terms), or the equivalent under Ghana's Act 843 and other applicable law. For Boldstep's own billing, security, and legal records, Boldstep is an independent controller under its Privacy Policy.
3. Processor obligations
Boldstep will:
- process personal data only on the Customer's documented instructions (this DPA, the Terms/MSA, and configuration through the Service), unless required by law — in which case Boldstep informs Customer unless legally barred;
- ensure persons authorised to process the data are bound by confidentiality;
- apply the technical and organisational measures in Annex II and not degrade them materially during the term;
- engage sub-processors only per §5;
- assist Customer, taking into account the nature of processing, with data-subject requests and with GDPR Arts. 32–36 / Act 843 security and breach obligations;
- notify Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal-data breach affecting Customer personal data;
- at termination, delete or return Customer personal data (Customer's choice) within 30 days, except copies required by law;
- make available information reasonably necessary to demonstrate compliance, and allow audits per §7.
4. International transfers
Ghana holds no EU adequacy decision. For EU/EEA personal data, the parties incorporate the EU Standard Contractual Clauses (Module 2: controller → processor) into this DPA, with Customer as data exporter and Boldstep as data importer; for UK data, the UK Addendum. The completed SCC annexes track Annexes I–III of this DPA. Where hosting is EU-region (the Frankfurt database), storage stays in the EU; the transfer being safeguarded is remote access from Ghana and any non-EU processing.
5. Sub-processors
Customer gives general written authorisation for the sub-processors listed in Annex III. Boldstep will give 30 days' notice of additions or replacements, during which Customer may object on reasonable data-protection grounds; if unresolved, Customer may terminate the affected service pro-rata.
6. Data-subject requests
Boldstep forwards to Customer, without undue delay, any request it receives directly from Customer's data subjects and does not respond on the merits except on Customer's instruction or where legally required.
7. Audit
Boldstep answers reasonable written security questionnaires and makes available existing audit artefacts. On-site or third-party audits: at most once per 12 months, on 30 days' notice, at Customer's cost, scoped to Customer personal data, without access to other customers' data.
8. Liability and order of precedence
Liability under this DPA is subject to the liability caps of the Terms/MSA, except where the SCCs require otherwise for data-subject claims. If this DPA conflicts with the Terms/MSA on data-protection matters, this DPA controls; the SCCs control over everything.
Annex I — Processing description: subject matter, duration, nature/purpose, data categories and subjects as per §1; frequency: continuous during the subscription term.
Annex II — Security measures: salted one-way hashing of API keys (no plaintext key storage); automated PII/credential scrubbing of ingested source text before storage, in irreversible mode; append-only audit trail for all verification decisions; role-gated internal console behind a dedicated password with hardened session cookies (HttpOnly, SameSite=Lax, Secure in production); TLS for data in transit; encrypted storage at rest per the hosting provider; security headers and CSP on the console surface; per-plan API rate limiting.
Annex III — Sub-processors: | Entity | Role | Location | |---|---|---| | Render | Cloud hosting of the API and database | EU (Frankfurt region) for the production database | | Anthropic | AI model provider used to triage/structure PII-scrubbed public-source candidate text (no Customer personal data sent) | US/EU | | Alert-delivery provider | SMS/email delivery of Watch-tier alerts — named here before push delivery ships | — | | Payment processor | Billing — named here before paid billing goes live | — |
© 2026 Boldstep Productions Ltd.