How ClinPlacer processes personal data on behalf of Schools and Facilities acting as data controllers — sub-processors, security, and breach notification.
When your Institution is the controller of student and staff data, this Agreement sets out exactly how ClinPlacer processes that data as your processor.
This Data Processing Agreement ("DPA") describes how ClinPlacer processes personal data on behalf of Schools and Facilities when they act as data controllers using the ClinPlacer platform.
This DPA is incorporated into, and forms part of, our Terms of Service for every Institution using the Services. It applies automatically — a separate signature is not required for the terms below to take effect.
Need a countersigned copy?
If your Institution's procurement process requires a signed, standalone DPA for your records, email legal@clinplacer.com and we will provide one reflecting these same terms.
Terms used in this DPA take the meanings given in the Kenya Data Protection Act, 2019, unless defined otherwise below:
For personal data submitted to the Platform, the Institution acts as the data controller and ClinPlacer acts as the data processor, processing that data only to deliver the Services and on the Institution's instructions as set out in the Terms of Service and this DPA.
Where ClinPlacer determines the means and purposes of processing information it collects to operate and improve the Platform itself (such as account and billing information), ClinPlacer acts as controller for that data — this is addressed in our Privacy Policy.
Processing under this DPA covers the following:
As processor, ClinPlacer agrees to:
ClinPlacer engages a limited number of sub-processors to help deliver the Services:
| Sub-Processor | Purpose | Processing Role |
|---|---|---|
| Cloud hosting provider | Hosts the Platform's infrastructure and databases | Storage & processing |
| Tidio | Powers the live chat support widget | Support communications |
| Payment providers (e.g. M-Pesa, banking partners) | Processes subscription payments | Billing |
ClinPlacer remains responsible for each sub-processor's compliance with data protection obligations equivalent to those in this DPA. We will provide notice before adding a new sub-processor that will process personal data covered by this DPA, and Institutions may object on reasonable data protection grounds.
ClinPlacer maintains technical and organizational measures appropriate to the sensitivity of the data processed, including encryption, role-based access control, and monitoring. These measures are described in full on our Security & Trust page, which forms part of this DPA by reference.
If ClinPlacer becomes aware of a breach affecting personal data processed on the Controller's behalf, we will notify the affected Institution without undue delay, and provide the information reasonably available to us to help the Institution meet its own notification obligations under the Kenya Data Protection Act, 2019.
Where personal data is processed or stored outside Kenya — for example, by a cloud hosting or sub-processor with infrastructure in another jurisdiction — ClinPlacer will ensure appropriate safeguards are in place consistent with the requirements of the Kenya Data Protection Act, 2019 for cross-border data transfers.
On reasonable written notice, an Institution may request information reasonably necessary to demonstrate ClinPlacer's compliance with this DPA, such as a summary of security practices or relevant policy documentation.
On-site audits are not offered as a standard feature of the Services but may be discussed directly with our legal team for Institutions with specific regulatory requirements.
On termination of an Institution's subscription, personal data is handled as described in our Terms of Service, Section 17 (Suspension & Termination): the Institution may export its data within 30 days, after which it is permanently deleted from production systems, subject to any legal retention obligations.
This DPA remains in effect for as long as ClinPlacer processes personal data on the Institution's behalf under the Terms of Service. Liability relating to this DPA is governed by the limitation of liability set out in our Terms of Service, Section 18.
We may update this DPA to reflect changes in our processing activities, sub-processors, or applicable law.
For questions about this DPA, or to request a countersigned copy for your Institution's records, reach out through the following channels:
Legal Email
legal@clinplacer.comGeneral Support
info@clinplacer.comBusiness Contact
+254 118 193 750We're glad to provide a countersigned copy of this Agreement, or answer any questions your legal or IT team has before you formalize a subscription.