1. Scope and roles
This agreement applies whenever personal data is processed through the Griot platform on your behalf, and forms part of our Terms of Service.
For personal data inside your datasets, you are the controller and Griot is the processor: we process it only to run the platform for you. For account and billing data, Griot is the controller — see the Privacy Policy. Producers who publish datasets remain controllers of the personal data those datasets contain.
2. What we process, and how
Nature and purpose: storage, transformation, querying, masking, and serving of the data you place on the platform, under the data contracts you author. Duration: the life of your account plus the return period in section 10. Categories of data and of data subjects: whatever your datasets contain — you declare these in each dataset's contract, which serves as the processing record for that dataset.
3. We act only on instructions
We process your data only on your documented instructions. On Griot your instructions are not a PDF annex — they are the data contract itself: purpose, permitted questions, masking rules, retention. The platform executes exactly those instructions and refuses what falls outside them. If the law ever requires us to process beyond your instructions, we will tell you first unless the law forbids it.
4. Confidentiality
Everyone we authorise to touch customer data is bound by confidentiality obligations, and access is role-gated, purpose-checked, and logged — the same enforcement the platform applies to your own users.
5. Security
We protect data with encryption in transit and at rest, tenant isolation, contract enforcement at query time, masking of declared sensitive fields in the query path, signed certificates over validated datasets, and audit trails on every access.
6. Subprocessors
We use a small set of infrastructure subprocessors (hosting, email, payments), each bound by contract to obligations equivalent to this agreement, with Griot remaining responsible to you for their performance. We will notify account holders at least 30 days before adding or replacing a subprocessor; if you object on reasonable data-protection grounds and we cannot resolve it, you may terminate the affected service and be refunded unused prepaid fees.
7. If a breach happens
If we become aware of a breach affecting personal data we process for you, we will notify you without undue delay and within 48 hours, with what happened, what data and subjects are affected, and the measures taken — so you can meet your own 72-hour obligation to the Office of the Data Protection Commissioner. We will cooperate fully in your response.
8. We help you answer data subjects
Access, correction, deletion, objection, portability: where a data subject exercises rights over data in your datasets, the platform's contract records, audit trails, and query tools are how you answer them, and we will assist where you need more. Requests that reach us directly about your data will be forwarded to you.
9. Cross-border transfers
Each dataset's storage location is declared in its contract. We transfer personal data across borders only as the contract and the Kenya Data Protection Act permit: destinations with appropriate safeguards, contractual clauses providing equivalent protection, or your documented instruction.
10. Return and deletion
When your account closes, your data is available for export in open formats for 30 days. After that we delete it from live systems, and from backups on their rotation schedule. Audit records of past access are retained as governance records, as the Privacy Policy describes.
11. Audits
Once a year, on reasonable notice, you may verify our compliance with this agreement — first through our documentation and audit reports, and where those are genuinely insufficient, through an audit conducted with minimal disruption at your cost. The platform's own signed access records will answer most questions before an audit is needed — that is what they are for.
12. Liability and precedence
Liability under this agreement follows the cap in the Terms of Service. If this agreement conflicts with the Terms on a data-protection matter, this agreement wins.
13. Contact
brackly@griotdata.com — Griot Data Technologies, Nairobi, Kenya.