This Data Processing Addendum ("Addendum") supplements the BounceZero Data Processing Agreement ("Master DPA") and applies where the customer ("Controller", "you") submits for verification email addresses relating to data subjects in Nigeria. It sets out how BounceZero Ltd ("Processor", "we", "us") complies with the Nigeria Data Protection Act, 2023 ("NDPA") and the General Application and Implementation Directive ("GAID") of the Nigeria Data Protection Commission ("NDPC") when acting as a data processor on your behalf. In the event of any conflict, the more protective obligation prevails.
1. Introduction
This Addendum forms part of the Master DPA. The terms defined in the Master DPA apply to this Addendum unless stated otherwise. Under the NDPA, "controller" means you and "processor" means BounceZero (NDPA Sec. 65).
We process personal data on EU infrastructure (OVH, France). The NDPA has extra-territorial reach: it applies to processing outside Nigeria where the processing relates to the offering of goods or services to data subjects in Nigeria or the monitoring of their behaviour. Accordingly, BounceZero is directly subject to the NDPA in respect of Nigerian data subjects even though we are established in the United Kingdom, and this Addendum records how we comply.
2. Governing Law and Regulator
The processing described in this Addendum is governed, so far as the data subjects are in Nigeria, by the NDPA, its subordinate rules, and the GAID (effective 19 September 2025). The regulator is the Nigeria Data Protection Commission (NDPC). For material violations of the NDPA, the NDPC may impose a penalty of up to 10,000,000 naira or 2% of the annual gross revenue of the undertaking, whichever is greater (NDPA Sec. 48).
3. Role and Scope
For the email verification services described in the Master DPA, you act as the controller and we act as the processor (NDPA Sec. 65). The subject matter, nature, and purpose of the processing are the same as set out in Section 2 of the Master DPA: syntactic validation, DNS/MX lookup, SMTP probing, catch-all detection, deliverability scoring, and fraud/abuse checks of the email addresses you submit.
We process personal data only on your documented instructions and never for our own benefit, except where applicable law requires otherwise. Where the NDPA applies to our processing directly, we comply with the obligations it imposes on processors as well as on controllers.
4. Data Subject Rights
We will assist you in responding to requests from data subjects exercising their rights under the NDPA (Sec. 33), including the right to:
- Be informed of the processing of their personal data, including its purpose.
- Access their personal data and information about the processing.
- Object to processing in the circumstances set out in the Act.
- Request correction of inaccurate or incomplete personal data.
- Request deletion of personal data no longer needed, or processed unlawfully.
- Data portability, on your instruction.
- Not be subject to automated decision-making that produces significant legal effects, without appropriate safeguards.
If a data subject contacts us directly, we will forward the request to you without undue delay and comply with your reasonable instructions. You are responsible for the legal basis of the processing.
5. Breach Notification
We will notify you of any personal data breach affecting the personal data you submitted, without undue delay and in any event within 72 hours of becoming aware of it, consistent with the Master DPA and the notification window under NDPA Sec. 40 and the GAID. You, as the controller, are responsible for notifying the NDPC and affected data subjects as required. We will provide the information needed to support your notification.
6. Cross-Border Transfers
Personal data of Nigerian data subjects is processed on EU infrastructure. The NDPA permits transfers of personal data to a country or territory that provides an adequate level of protection, or subject to appropriate safeguards and the data subject rights set out in the Act (Sec. 42). To the extent any transfer relies on contractual safeguards, we rely on the Standard Contractual Clauses set out in the Master DPA. A copy is available on request at [email protected].
7. Additional Obligations
- DPIA support: the NDPA and GAID require a data protection impact assessment where processing is likely to result in a high risk to the rights of data subjects, including profiling or automated decision-making. Our email verification scoring involves automated analysis, so we will provide the information about our processing reasonably needed for you to complete any required DPIA.
- Registration support: controllers and processors are required to register with the NDPC under the GAID. We will provide the information about our processing reasonably needed for your registration.
- Consent records: we retain the evidence of lawful processing instructions you rely on as your legal basis, for accountability purposes.
- Security: we maintain the technical and organisational measures set out in Section 5 of the Master DPA, consistent with NDPA Sec. 39.
- Audit: we will co-operate with reasonable audits conducted by you or your authorised auditor, on reasonable prior written notice.
8. Contact
For enquiries about this Addendum or to exercise rights in respect of the processing described here, contact our Data Protection contact:
BounceZero Ltd66 Paul Street, London, EC2A 4NA, United Kingdom
Email: [email protected]
You may also refer to the Master DPA and its terms on sub-processors, security measures, retention, and liability at bouncezero.io/dpa.