Data Processing Agreement
Version 1.0 · Last updated 7 September 2026
Rentiwo is a product of The Technoids General Solutions Ltd, 432 Mengo Hill Road, Kampala – Uganda
1. Scope and Roles
1.1 This Data Processing Agreement ("DPA") forms part of, and is subject to, the Rentiwo Terms and Conditions ("Terms") between you ("Landlord") and The Technoids General Solutions Ltd ("Company", "we", "us"). It governs our processing of personal data relating to your tenants, prospective tenants, guarantors, and other individuals whose data you enter into the Platform ("Tenant Personal Data").
1.2 For Tenant Personal Data, the Landlord is the data controller and the Company is the data processor, as those terms are used in the Uganda Data Protection and Privacy Act, 2019 and the Data Protection and Privacy Regulations, 2021 (together, the "Data Protection Law").
1.3 For personal data about the Landlord's own account (name, email, phone, billing records), the Company is an independent data controller and its processing is described in the Privacy Policy, not this DPA.
1.4 If there is a conflict between this DPA and the rest of the Terms on the subject of data protection, this DPA prevails.
2. Subject Matter, Duration, Nature and Purpose
2.1 Subject matter: processing of Tenant Personal Data by the Company on behalf of the Landlord through the Platform.
2.2 Duration: for as long as the Landlord's account is active, plus the retention period in Section 9.
2.3 Nature and purpose: hosting and storage; recording rent, payments, and expenses; generating and sending SMS and email reminders on the Landlord's instruction; producing reports; facilitating mobile money payment requests; and providing support.
2.4 Types of personal data: names; phone numbers; email addresses; physical/unit addresses; national identification numbers (where entered by the Landlord); tenancy and lease details; rent amounts, due dates, balances; payment records and mobile money transaction references; and free-text notes entered by the Landlord.
2.5 Categories of data subjects: the Landlord's tenants, prospective tenants, guarantors, next-of-kin or emergency contacts, and any other individual whose data the Landlord chooses to enter.
3. Landlord Obligations
3.1 The Landlord warrants that it has a lawful basis under the Data Protection Law for the collection and processing of all Tenant Personal Data it enters, and that it has given tenants any notice and obtained any consent required.
3.2 The Landlord's documented instructions to the Company consist of the Terms, this DPA, the configuration and actions available in the Platform interface, and any written instruction the Landlord subsequently gives that the Company agrees in writing to follow.
3.3 The Landlord must not enter special categories of data (for example health, biometric, or genetic data) into free-text fields, as the Platform is not designed to safeguard such data.
4. Company (Processor) Obligations
The Company shall:
4.1 process Tenant Personal Data only on the Landlord's documented instructions, including as to transfers outside Uganda, unless required to do otherwise by Ugandan law (in which case it will inform the Landlord first, unless the law prohibits this on important grounds of public interest);
4.2 ensure that persons authorised to process Tenant Personal Data are bound by confidentiality obligations;
4.3 implement and maintain the technical and organisational security measures described in Schedule A;
4.4 respect the conditions in Section 5 for engaging sub-processors;
4.5 taking into account the nature of the processing, assist the Landlord by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights under the Data Protection Law;
4.6 assist the Landlord in ensuring compliance with its obligations relating to security, breach notification, and data protection impact assessments, taking into account the information available to the Company;
4.7 at the Landlord's choice, delete or return all Tenant Personal Data at the end of the provision of services, and delete existing copies unless Ugandan law requires storage (see Section 9); and
4.8 make available to the Landlord information reasonably necessary to demonstrate compliance with this Section, and allow for and contribute to audits as set out in Section 8.
5. Sub-processors
5.1 The Landlord gives the Company general authorisation to engage sub-processors to deliver the service. The current sub-processors are:
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloud hosting provider | Application and database hosting, backups | As stated on the Subscription/records page or notified to the Landlord |
| Twilio | SMS delivery and delivery-status reporting | United States / global |
| Email delivery provider | Transactional email delivery | Global |
| MTN Mobile Money | Payment request initiation and status | Uganda |
| Airtel Money | Payment request initiation and status | Uganda |
5.2 The Company shall impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains fully liable to the Landlord for a sub-processor's performance of those obligations.
5.3 The Company shall give the Landlord at least 30 days' prior notice (through the Platform or by email) of any intended addition or replacement of a sub-processor. If the Landlord has a reasonable data-protection objection, it may raise it in writing within that period; if the parties cannot resolve the objection, the Landlord may terminate the affected service and this DPA on written notice, as its sole remedy.
6. International Transfers
6.1 Some sub-processors (for example the SMS and email providers) process data outside Uganda. Where Tenant Personal Data is transferred outside Uganda, the Company shall ensure the transfer complies with the Data Protection Law, including by relying on a legally recognised transfer mechanism or the data subject's consent obtained by the Landlord, and by requiring the recipient to apply an adequate level of protection.
7. Personal Data Breach
7.1 The Company shall notify the Landlord without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Tenant Personal Data.
7.2 The notification shall describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Where information is not all available at once, it may be provided in phases without undue further delay.
7.3 The Company shall not make any public statement attributing a breach to the Landlord without the Landlord's prior written consent, except as required by law. Notification of a breach is not an admission of fault.
8. Audit
8.1 The Company shall, on the Landlord's written request and no more than once per calendar year (unless a competent authority requires otherwise or a breach has occurred), make available a summary of its security measures and answer reasonable written questions needed to confirm compliance with this DPA.
8.2 Any on-site audit must be requested in writing at least 30 days in advance, conducted during business hours, cause minimal disruption, respect the confidentiality and security of other customers' data, and be at the Landlord's cost. The parties may agree that an independent third party conducts the audit.
9. Return and Deletion
9.1 On expiry or termination of the Landlord's account, the Company shall retain Tenant Personal Data for 90 days to allow the Landlord to export it, and shall then permanently delete it, save that:
- payment transaction records may be retained for up to 7 years to meet Ugandan financial record-keeping obligations;
- backups are deleted on their normal rotation cycle; and
- data required to be kept by law or to establish, exercise, or defend legal claims may be retained for as long as necessary.
9.2 The Landlord may request earlier deletion at any time; the Company will action it within 30 days, subject to the exceptions above.
10. Liability
10.1 Each party's liability under or in connection with this DPA is subject to the limitations and exclusions in Section 10 (Limitation of Liability) and Section 11 (Indemnification) of the Terms.
10.2 Nothing in this DPA limits either party's liability that cannot be limited under the Data Protection Law.
Schedule A — Technical and Organisational Security Measures
- Encryption of all Platform traffic in transit using HTTPS/TLS
- Passwords stored using industry-standard one-way hashing (bcrypt); payment-provider credentials stored encrypted at rest
- Role-based access control isolating each landlord's data; caretakers limited to assigned properties
- Authentication controls including optional two-factor authentication for accounts
- Regular application updates and periodic security reviews
- Routine encrypted backups with defined restoration procedures
- Access, application, and change logging with retention as stated in the Privacy Policy
- Principle of least privilege for staff and contractor access, granted only as needed and revoked on role change or exit
Contact
The Technoids General Solutions Ltd — Privacy Team
432 Mengo Hill Road, Kampala – Uganda
Email: privacy@technoidslab.com