This Data Processing Agreement ("DPA") forms part of the agreement between Eniena Technologies Limited(trading as "Comutte"), 10 Aviation Road, Airport Residential Area, Accra, Ghana ("Processor") and the bus operator or customer using the Comutte platform ("Controller"), collectively the "Parties".
This DPA governs the processing of personal data that the Controller makes available to the Processor through the Comutte platform, in compliance with the Ghana Data Protection Act, 2012 (Act 843).
1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person processed through the Platform.
- "Processing" means any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, and deletion.
- "Data Subject" means the individual whose Personal Data is processed (passengers and their contacts).
- "Sub-processor" means a third party engaged by the Processor to process Personal Data on the Controller's behalf.
2. Scope of Processing
The Processor processes Personal Data on behalf of the Controller for the following purposes:
- Facilitating seat reservations and bookings on the Controller's trips.
- Collecting and remitting payments from passengers to the Controller.
- Generating trip manifests and boarding records.
- Sending booking confirmations and ticket information to passengers.
- Providing booking analytics and reporting to the Controller.
3. Categories of Data
Personal Data processed under this DPA includes:
- Passenger identity: full name, email address, phone number.
- Booking details: trip selection, seat count, booking reference, booking status.
- Payment records: transaction amounts, payment method (card or MoMo), payment status. Card numbers are never stored by the Processor.
- Communication data: WhatsApp messages exchanged with the booking assistant (where applicable).
4. Obligations of the Processor
The Processor shall:
- Process Personal Data only on documented instructions from the Controller and as necessary to provide the Platform services.
- Implement appropriate technical and organisational security measures, including encryption in transit (TLS), encryption at rest (AES-256), row-level security policies, and parameterised queries.
- Ensure that persons authorised to process Personal Data are bound by confidentiality obligations.
- Not engage a Sub-processor without prior written consent of the Controller. Current Sub-processors are listed in Section 7.
- Assist the Controller in responding to Data Subject requests (access, correction, deletion, portability) within the timeframes required by Act 843.
- Notify the Controller without undue delay (and in any event within 48 hours) upon becoming aware of a Personal Data breach.
- Delete or return all Personal Data to the Controller upon termination of the agreement, unless retention is required by law.
- Make available to the Controller all information necessary to demonstrate compliance with this DPA.
5. Obligations of the Controller
The Controller shall:
- Ensure a lawful basis exists for the processing of passenger Personal Data and that appropriate privacy notices are provided to Data Subjects.
- Provide accurate and complete information to the Processor as needed for the Platform services.
- Notify the Processor promptly of any Data Subject requests or complaints received directly.
- Not instruct the Processor to process Personal Data in violation of the Ghana Data Protection Act.
6. Data Retention
The Processor retains Personal Data for 180 days from the date of the last booking or account activity. After this period, data is permanently deleted unless retention is required by Ghanaian law (e.g. financial transaction records). The Controller may request earlier deletion subject to the same legal constraints.
7. Sub-processors
The Processor currently engages the following Sub-processors. The Controller consents to the use of these Sub-processors by entering into this DPA:
| Sub-processor | Purpose | Location |
|---|
| Supabase Inc. | Database, authentication | AWS (US) |
| Vercel Inc. | Application hosting | US East + global edge |
| Paystack (Stripe) | Card payment processing | Nigeria |
| Meta Platforms | WhatsApp messaging | Global |
| Anthropic PBC | AI booking assistant | US |
8. Data Breach Notification
In the event of a Personal Data breach, the Processor shall notify the Controller within 48 hours of becoming aware of the breach. The notification shall include: (a) a description of the breach; (b) the categories and approximate number of Data Subjects affected; (c) the likely consequences; and (d) measures taken or proposed to address the breach.
9. International Data Transfers
Where Personal Data is transferred outside Ghana (to Sub-processors listed in Section 7), the Processor ensures that adequate safeguards are in place, including data processing agreements with each Sub-processor that provide a level of protection consistent with the Ghana Data Protection Act.
10. Term and Termination
This DPA remains in effect for the duration of the Controller's use of the Comutte platform. Upon termination, the Processor will delete all Personal Data within 30 days unless retention is required by law.
11. Governing Law
This DPA is governed by the laws of the Republic of Ghana, including the Data Protection Act, 2012 (Act 843).
12. Contact
- Data Protection Contact: support@bookcomutte.com
- Phone: 020 324 2649
- Address: 10 Aviation Road, Airport Residential Area, Accra, Ghana
See also our Privacy Policy and Terms and Conditions.