Data Processing Agreement
Effective date: July 2026. This DPA governs Imhotep's processing of personal data on behalf of our customers.
Definitions
"Personal Data," "Processing," "Controller," "Processor," "Subprocessor," and "Data Subject" have the meanings given under applicable data protection law, including Rwanda's Law No. 058/2021 and, where applicable, the EU GDPR or other relevant regimes.
Scope and roles
Imhotep processes personal data solely as a processor on behalf of the Controller, strictly for the purpose of providing the Services as described in the underlying agreement, and in accordance with the Controller's documented instructions, except where otherwise required by law.
Nature and purpose of processing
The specific categories of data subjects (e.g., Controller's employees, customers, end users), categories of personal data processed (e.g., contact details, transactional data, operational data from edge devices), and the purpose (e.g., providing workflow automation, business operations tooling, AI-driven analytics) will be described in the applicable order form, schedule, or deployment documentation, since they vary by customer and deployment.
Confidentiality
Imhotep ensures that personnel authorized to process personal data are bound by confidentiality obligations.
Security measures
Imhotep implements appropriate technical and organizational measures to protect personal data, including encryption, access controls, network security, and incident response procedures, consistent with the sensitivity of the data processed and the nature of the deployment, including for critical-industry and government use cases where heightened controls may be contractually required.
Subprocessors
Imhotep may engage subprocessors to support the Services. Imhotep will maintain a current list of subprocessors available on request, and will notify the Controller of material changes to that list, providing an opportunity to object on reasonable grounds. Imhotep remains responsible for subprocessor compliance with data protection obligations equivalent to those in this DPA.
Data subject rights
Imhotep will assist the Controller, insofar as reasonably possible, in responding to requests from data subjects seeking to exercise their rights, taking into account the nature of the processing.
Personal data breach notification
Imhotep will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, and will provide reasonably requested information to help the Controller meet its own notification obligations.
Data protection impact assessments
Where required, Imhotep will provide reasonable assistance to the Controller in connection with data protection impact assessments and consultations with supervisory authorities.
International transfers
Where personal data is transferred outside the jurisdiction in which it was collected, Imhotep will ensure appropriate safeguards are in place consistent with applicable law. Government and critical-industry clients may require data to remain within Rwanda or a specific region; such requirements will be specified in the applicable enterprise agreement.
Audit rights
Upon reasonable request and subject to confidentiality protections, Imhotep will make available information reasonably necessary to demonstrate compliance with this DPA, and will allow for audits, including inspections, conducted by the Controller or an appointed auditor, subject to reasonable notice and scope limitations.
Deletion or return of data
On termination of the Services, Imhotep will, at the Controller's choice, delete or return all personal data processed on its behalf, except where retention is required by law.
Liability
Liability under this DPA is subject to the limitations set out in the underlying agreement between the parties, except where applicable law prohibits limiting liability for data protection violations.
Governing law
This DPA is governed by the same governing law as the underlying agreement between the parties, unless applicable data protection law requires otherwise.