Data Processing Agreement (DPA)
Version 1.0 ยท effective 02/10/2026
This agreement is between the business using WithOpp ("you", the data controller) and Avitus Kashangaki Alex, an individual operating WithOpp while its company registration is completed ("WithOpp", the data processor), about the personal data your business enters about other people. It complements the Terms of Service and the Privacy Policy.
This is a working version awaiting review by a Tanzanian advocate. It describes how WithOpp works today. Liability, governing law and disputes are covered by the Terms of Service.
1. Who is who
Example: ABC Pharmacy uses WithOpp. John is an ABC customer.
- ABC is the controller: it decides to record John's details, and why.
- WithOpp is the processor: it stores and processes them only on ABC's behalf.
- WithOpp's providers (section 6) are sub-processors.
2. Your instructions
- We process this data only to provide WithOpp to you - as you and your team use and configure it.
- We do not use it for our own purposes, do not sell it, and do not contact your customers.
- If we believe an instruction breaks the law, we will tell you.
3. Processing details
Duration
Details: While your account is active, plus the periods in section 10.
Nature of processing
Details: Storing, organising, displaying, calculating reports and insights, exporting and deleting.
People concerned
Details: Your business's customers; suppliers and their contact persons; your team members; people you pay expenses to.
Categories of data
Details: Names, phone numbers, addresses, notes, credit limits, balances, purchases and payments, payment reference numbers, and each team member's activity in WithOpp.
Sensitive data
Details: Not requested or needed. Please do not record health or other sensitive details in notes.
Location
Details: European Union (section 7).
4. Confidentiality
WithOpp staff open a business's data only when needed for support, security or billing. Every time they do, it is recorded in our internal log.
5. Security measures in place
Business isolation
How it works: Every request is limited inside the database to one business. No business can see another's data.
Role permissions
How it works: Every action is checked inside the database against the user's role (for example, a cashier cannot see cost prices).
Encryption in transit
How it works: All traffic uses HTTPS.
Passwords
How it works: Stored hashed by our sign-in provider; WithOpp cannot see them.
Audit log
How it works: Changes are recorded with who made them. These records cannot be changed or deleted.
Stopping misuse
How it works: We can restrict an account to read-only (Acceptable Use Policy); the owner can suspend a team member instantly.
6. Sub-processors
Supabase
Purpose: Database, sign-in and account emails
Location: Ireland (European Union)
Railway
Purpose: Runs the WithOpp application servers
Location: European Union (EU West region)
We add providers to this list before we start using them. If you have concerns about a new provider, contact us.
7. Transfers outside Tanzania
Data is stored in the European Union. The Personal Data Protection Act, 2022 requires a permit from the Personal Data Protection Commission (PDPC) for this transfer.
That permit has not yet been issued to WithOpp.
8. Security incidents
If we discover that your business's data was leaked or accessed without permission, we will tell you without undue delay - aiming for within 72 hours - explaining what happened, which data was affected and what we have done, so you can meet your own duties as controller.
9. Helping with people's requests
- You can correct or delete a customer's or supplier's details directly in WithOpp, and download all data (Settings โ Your data).
- If one of your customers contacts us directly, we pass the request to you and do not answer it ourselves without your instruction, unless the law requires us to.
10. Returning and deleting data
- You can download all your data at any time, even after the subscription ends or the business is closed.
- If you ask for the business to be deleted, we verify the request, then the data is hidden and locked for 30 days (restorable), then permanently deleted.
11. Information and assurance
If you need more information to show that the processing complies with the law, write to withopp.bis@gmail.com; we reply within 30 days. WithOpp does not currently hold independent security certifications.