Legal & Trust Center

Data Processing Agreement (DPA)

Version 1.0 ยท effective 02/10/2026

This agreement is between the business using WithOpp ("you", the data controller) and Avitus Kashangaki Alex, an individual operating WithOpp while its company registration is completed ("WithOpp", the data processor), about the personal data your business enters about other people. It complements the Terms of Service and the Privacy Policy.

This is a working version awaiting review by a Tanzanian advocate. It describes how WithOpp works today. Liability, governing law and disputes are covered by the Terms of Service.

1. Who is who

Example: ABC Pharmacy uses WithOpp. John is an ABC customer.

  • ABC is the controller: it decides to record John's details, and why.
  • WithOpp is the processor: it stores and processes them only on ABC's behalf.
  • WithOpp's providers (section 6) are sub-processors.

2. Your instructions

  • We process this data only to provide WithOpp to you - as you and your team use and configure it.
  • We do not use it for our own purposes, do not sell it, and do not contact your customers.
  • If we believe an instruction breaks the law, we will tell you.

3. Processing details

  • Duration

    Details: While your account is active, plus the periods in section 10.

  • Nature of processing

    Details: Storing, organising, displaying, calculating reports and insights, exporting and deleting.

  • People concerned

    Details: Your business's customers; suppliers and their contact persons; your team members; people you pay expenses to.

  • Categories of data

    Details: Names, phone numbers, addresses, notes, credit limits, balances, purchases and payments, payment reference numbers, and each team member's activity in WithOpp.

  • Sensitive data

    Details: Not requested or needed. Please do not record health or other sensitive details in notes.

  • Location

    Details: European Union (section 7).

4. Confidentiality

WithOpp staff open a business's data only when needed for support, security or billing. Every time they do, it is recorded in our internal log.

5. Security measures in place

  • Business isolation

    How it works: Every request is limited inside the database to one business. No business can see another's data.

  • Role permissions

    How it works: Every action is checked inside the database against the user's role (for example, a cashier cannot see cost prices).

  • Encryption in transit

    How it works: All traffic uses HTTPS.

  • Passwords

    How it works: Stored hashed by our sign-in provider; WithOpp cannot see them.

  • Audit log

    How it works: Changes are recorded with who made them. These records cannot be changed or deleted.

  • Stopping misuse

    How it works: We can restrict an account to read-only (Acceptable Use Policy); the owner can suspend a team member instantly.

6. Sub-processors

  • Supabase

    Purpose: Database, sign-in and account emails

    Location: Ireland (European Union)

  • Railway

    Purpose: Runs the WithOpp application servers

    Location: European Union (EU West region)

We add providers to this list before we start using them. If you have concerns about a new provider, contact us.

7. Transfers outside Tanzania

Data is stored in the European Union. The Personal Data Protection Act, 2022 requires a permit from the Personal Data Protection Commission (PDPC) for this transfer.

That permit has not yet been issued to WithOpp.

8. Security incidents

If we discover that your business's data was leaked or accessed without permission, we will tell you without undue delay - aiming for within 72 hours - explaining what happened, which data was affected and what we have done, so you can meet your own duties as controller.

9. Helping with people's requests

  • You can correct or delete a customer's or supplier's details directly in WithOpp, and download all data (Settings โ†’ Your data).
  • If one of your customers contacts us directly, we pass the request to you and do not answer it ourselves without your instruction, unless the law requires us to.

10. Returning and deleting data

  • You can download all your data at any time, even after the subscription ends or the business is closed.
  • If you ask for the business to be deleted, we verify the request, then the data is hidden and locked for 30 days (restorable), then permanently deleted.

11. Information and assurance

If you need more information to show that the processing complies with the law, write to withopp.bis@gmail.com; we reply within 30 days. WithOpp does not currently hold independent security certifications.