Data Processing Agreement (DPA)

Data Processing Agreement (DPA)

Last updated : July 10, 2026

This Data Processing Agreement (the "DPA") governs the processing of personal data carried out by Drwintech LTD (the "Processor") on behalf of a business customer (the "Controller") when it uses Zana to manage its deliveries. It is entered into under Law N°058/2021 of 13/10/2021 and forms an integral part of the MSA and the Terms of Use.

1. Roles and purpose

For the data of its recipients and end customers, the Customer is the Controller and Zana is the Processor. For data whose purposes the Processor itself determines (accounts, riders, security), it acts as controller and the Privacy Policy applies.

2. Definitions

The terms "personal data", "processing", "controller", "processor", "data subject" and "data breach" have the meaning given to them by Law N°058/2021.

3. Duration of processing

Processing lasts for as long as the Customer uses the service, then during the return/deletion period set out in section 12.

4. Nature and purpose of processing

The Processor processes the data to provide the service: delivery creation and dispatch, GPS tracking, recipient notifications (SMS/WhatsApp/email), Mobile Money collection, invoicing, support and reporting.

5. Categories of data and data subjects

Data subjects: delivery recipients, the Customer's contacts and Users, assigned riders.

  • Identification and contact: name, phone number, delivery address;

  • Order and delivery data: declared contents, status, proof of delivery;

  • Location: GPS coordinates related to the execution of the delivery;

  • Minimal technical data necessary to provide the service.

6. Documented instructions

The Processor processes the data only on the Controller's documented instructions (the configuration and use of the service constituting instructions), unless required by law, in which case it informs the Controller to the extent permitted.

7. Confidentiality of personnel

The Processor ensures that persons authorised to process the data are bound by confidentiality and access it only on a need-to-know basis.

8. Security of processing

The Processor implements appropriate technical and organisational measures, in particular:

  • encryption in transit (TLS 1.3) and at rest (AES-256), column-level encryption for sensitive data;

  • role-based access control and PostgreSQL Row-Level Security, multi-factor authentication for administrative accounts;

  • audit logs, encrypted backups and point-in-time recovery, periodic access reviews;

  • assessment and contractual framing of sub-processors.

9. Sub-processors

The Controller authorises the use of the sub-processors below, framed by written agreements and standard contractual clauses. The Processor informs the Controller of any change so as to allow it to object on legitimate grounds.

  • Supabase (AWS) — hosting, database, authentication, storage, functions (EU: Ireland / Germany);

  • Resend — transactional email delivery;

  • Africa's Talking — SMS / WhatsApp / OTP delivery (Kenya);

  • SandPay and pawaPay — Mobile Money payment aggregators (MTN MoMo, Airtel Money);

  • Google Maps Platform — mapping, geocoding and routing;

  • Traccar / Flespi — telematics and GPS tracker position ingestion.

MTN Mobile Money Rwanda and Airtel Money are the payment rails, accessed via the aggregators. The up-to-date list is provided by the DPO on request.

10. Transfers outside Rwanda

Some sub-processors are established outside Rwanda. Such transfers are framed by appropriate safeguards (standard contractual clauses or equivalent) and, where applicable, by NCSA authorisations under Articles 48 and 50 of Law N°058/2021.

11. Assistance to the Controller

Taking into account the nature of the processing, the Processor assists the Controller in responding to data-subject requests and in meeting its security, breach-notification and data-protection-impact-assessment (DPIA) obligations.

12. Breach notification

The Processor notifies the Controller of any data breach affecting it without undue delay, targeting 72 hours after becoming aware, with the information needed to enable the Controller to meet its own obligations.

13. Deletion or return

At the end of the service, the Processor deletes or returns the personal data at the Controller's choice, unless legally required to retain it. Deletion may be performed by cryptographic erasure.

14. Audit

The Processor makes available the information necessary to demonstrate compliance with this DPA and allows reasonable audits, while protecting the confidentiality and security of other customers.

15. Liability and precedence

The MSA's liability limitations apply to this DPA. In case of conflict regarding data processing, the DPA prevails over the MSA.

16. Contact

Data Protection Officer — Drwintech LTD: dpo@getzana.africa (tel. +250 790 291 209). NCSA Data Controller registration No. 001/2481/0626.

This document is provided for information purposes. In case of conflict, the mandatory provisions of Rwandan law prevail.