Data Processing Agreement

This Data Processing Agreement (“Agreement”) forms part of any contract, collaboration, or service relationship between:

Controller:
Chifen Nji Sama / nji.io
Haren (EMS), Germany
Email: mail@nji.io Phone: +49 163 194 2484

and

Processor:
The partner, client, institution, or service provider engaging with nji.io (“Processor”).

This Agreement ensures compliance with the EU General Data Protection Regulation (GDPR) and other applicable data protection laws.

1. Definitions

  • Controller: The entity determining the purposes and means of processing personal data (nji.io).
  • Processor: The entity processing personal data on behalf of the Controller.
  • Personal Data: Any information relating to an identified or identifiable natural person.
  • Processing: Any operation performed on personal data (collection, storage, use, deletion, etc.).
  • Sub‑processor: Any third party engaged by the Processor to assist in processing personal data.
  • GDPR: Regulation (EU) 2016/679.

2. Subject Matter of the Agreement

The Processor will process personal data on behalf of nji.io for the following purposes:

  • Delivery of engineering education services
  • Course registration and certification
  • Workshop and training management
  • Communication with learners and partners
  • Technical consulting and project collaboration
  • Hosting, analytics, or support services
    This aligns with the Learn Hub and your operational activities.

3. Duration

This Agreement remains in effect for the duration of the collaboration or service relationship and until all personal data has been deleted or returned to the Controller.

4. Nature and Purpose of Processing

Processing activities may include:

  • Collecting learner information
  • Managing course progress and certification
  • Providing technical support
  • Hosting digital content
  • Processing workshop attendance
  • Managing communication channels

5. Types of Personal Data

The Processor may handle:

  • Names
  • Email addresses
  • Phone numbers
  • Organization or school affiliation
  • Course progress and certification results
  • Technical submissions (projects, assignments)
  • Device and usage data (analytics)
    No sensitive data is processed unless explicitly agreed.

6. Categories of Data Subjects

  • Learners
  • Workshop participants
  • School or NGO representatives
  • Technical partners
  • Website visitors

7. Obligations of the Processor

The Processor agrees to:

  1. Process personal data only on documented instructions from the Controller.
  2. Ensure confidentiality of all personnel involved in processing.
  3. Implement appropriate technical and organizational security measures.
  4. Assist the Controller in fulfilling GDPR obligations (access, deletion, correction).
  5. Notify the Controller of any data breach without undue delay.
  6. Maintain records of processing activities.
  7. Cooperate with supervisory authorities when required.

8. Sub‑processors

The Processor may not engage sub‑processors without prior written authorization from the Controller.
Authorized sub‑processors must:

  • Comply with GDPR
  • Provide adequate security
  • Sign a written agreement mirroring this DPA

9. International Transfers

If personal data is transferred outside the EU (e.g., Cameroon or Ecuador), the Processor must ensure:

  • Adequate safeguards
  • Standard Contractual Clauses (SCCs)
  • GDPR‑compliant processing

10. Security Measures

The Processor must implement:

  • Encryption
  • Access controls
  • Secure hosting
  • Regular audits
  • Incident response procedures
    These align with your engineering background (DevOps, distributed systems, cloud).

11. Data Subject Rights

The Processor must assist the Controller in responding to:

  • Access requests
  • Correction requests
  • Deletion requests
  • Restriction requests
  • Objections
  • Data portability requests

12. Data Breach Notification

In case of a breach, the Processor must:

  • Notify the Controller immediately
  • Provide details of the breach
  • Assist in mitigation
  • Support communication with authorities

13. Return or Deletion of Data

Upon termination of services, the Processor must:

  • Delete all personal data or
  • Return all personal data to the Controller
    Unless law requires retention.

14. Audits

The Controller may audit the Processor’s compliance with this Agreement:

  • Through documentation
  • Through remote assessments
  • Through on‑site audits (with reasonable notice)

15. Liability

Both parties remain liable under applicable data protection laws. The Processor is responsible for damages caused by non‑compliance.

16. Governing Law

This Agreement is governed by:

  • EU GDPR
  • German law (current operational base)
    Once nji.io is registered in Cameroon or Ecuador, this section can be updated.

17. Signatures

Controller:
Chifen Nji Sama / nji.io
Signature: __
Date: ___

Processor:
Name: ___
Organization: ____
Signature: __ Date: ___