← Back to Privacy Policy

Data Processing Agreement

AskBiz Ltd · Last updated: 16 June 2026

1. Roles of the Parties

This Data Processing Agreement ("DPA") forms part of the agreement between AskBiz Ltd ("AskBiz", "we", "Processor") and the business customer that uses AskBiz ("you", "Controller").

When you use AskBiz to handle your own customers' personal data — for example their names, phone numbers, purchase history, parcel details, or photographs — you act as the data controller and AskBiz acts as a data processor on your behalf. You decide what data is collected and why; we process it only to provide the service.

For data about your own account (your name, email, billing), AskBiz is the controller — that processing is covered by our Privacy Policy.

2. Subject Matter & Duration

Subject matter: AskBiz's processing of personal data on your behalf to provide the AskBiz POS and business-intelligence platform.

Duration: Processing continues for as long as your account is active, and thereafter only as required to comply with legal obligations (e.g. tax records are retained for up to 7 years; see Section 7).

3. Nature & Purpose of Processing

  • Recording sales, transactions, and inventory
  • Storing customer records and managing loyalty / consent preferences
  • Sending receipts and notifications to your customers (subject to their consent)
  • AI scanning of images you capture (products, receipts, documents, vehicle plates)
  • Logistics: parcel tracking, vehicle inspections, and driver location for fleet management
  • Generating reports and analytics for your business

4. Types of Data & Data Subjects

Categories of data subjects: your customers, your staff, and (for logistics) your drivers and parcel recipients.

Categories of personal data: names, phone numbers, email addresses, transaction and purchase history, staff roles and PINs (hashed), photographs (e.g. parcels, vehicle inspections, scanned documents), and driver GPS location. We do not require special-category data; please do not upload it.

5. Our Obligations as Processor

  • Documented instructions: we process personal data only on your documented instructions, which include your use of the platform's features.
  • Confidentiality: personnel authorised to process data are bound by confidentiality.
  • Security: we apply appropriate technical and organisational measures — encryption in transit, encryption of integration credentials at rest, hashed staff PINs, row-level security isolating each business's data, and access controls.
  • Assistance with data-subject requests: the platform provides tools to export and erase/anonymise customer records so you can fulfil access and erasure requests.
  • Breach notification: we will notify you without undue delay after becoming aware of a personal-data breach affecting your data.
  • Deletion / return: on termination, we delete or return personal data, subject to legal retention requirements.

6. Sub-processors

You authorise AskBiz to engage the sub-processors listed below to help deliver the service. Each is bound by data-protection obligations consistent with this DPA. We will give you notice of any intended changes to this list so you may object.

Note: customer data — including images you scan — is processed by Anthropic in the United States for AI features. International transfers rely on appropriate safeguards such as Standard Contractual Clauses (SCCs).

Sub-processorPurposeRegion
SupabaseDatabase, authentication, and file storage (PostgreSQL)EU / US
Anthropic (Claude API)AI processing of camera images and text — receipt, product, document, and number-plate scanningUnited States
VercelApplication hosting and serverless computeGlobal edge / US
StripeCard payment processingUS / EU
PaystackPayment processing (Africa)Nigeria / South Africa
GoCardlessBank debit payment processingEU / UK
PayPalPayment processingUS / EU
M-Pesa (Safaricom Daraja)Mobile money payment processingKenya
Twilio / WhatsApp (Meta)Customer SMS and WhatsApp messaging (receipts, notifications)United States
ResendTransactional email deliveryUnited States
TavilyWeb search for business intelligence queries (no customer PII)United States

7. Retention & Deletion

Customer records that become inactive are anonymised, and driver GPS location pings are purged, on an automated retention schedule. Transaction records are retained in anonymised form for up to 7 years to meet tax obligations. You may trigger erasure or export of an individual customer's data at any time from the customer management screen.

8. International Transfers

Some sub-processors process data outside the EU/UK (notably in the United States — see Section 6). Where this occurs, transfers are made under appropriate safeguards, principally the EU Standard Contractual Clauses and the UK International Data Transfer Addendum.

9. Contact

Questions about this DPA, or to request a counter-signed copy: dpa@askbiz.co · privacy@askbiz.co