Data processing agreement
The standard terms on which Eigenstate Systems processes personal data on behalf of a client. The signed version for each engagement is attached as an annex to the statement of work.
About this document
This is the standard data processing agreement (the “DPA”) on which Eigenstate Systems processes personal data for its clients. It is published so that a client can review it before an engagement begins. It takes effect for an engagement only when attached, with the engagement-specific details, as an annex to the signed statement of work; where the signed annex differs from this page, the signed annex governs. This version is dated 13 September 2026.
1. Parties and roles
1.1 The parties are the client named in the statement of work (the “Controller”) and Eigenstate Systems of Harare, Zimbabwe (“Eigenstate”).
1.2 The Controller decides why and how personal data is processed. Eigenstate processes that data only on the Controller’s behalf and on its documented instructions. This is the relationship the Act describes as data controller and data processor.
Definitions
1.3 In this DPA:
- “Act” means the Cyber and Data Protection Act [Chapter 12:07] of Zimbabwe, Act No. 5 of 2021, together with any regulations made under it, each as amended from time to time.
- “Authority” means the Postal and Telecommunications Regulatory Authority of Zimbabwe (POTRAZ) in its role as the Data Protection Authority under the Act.
- “Personal data” means any information relating to an identified or identifiable natural person. Where the Act uses a different word for the same idea, the Act’s meaning applies.
- “Sensitive data” means the categories of personal data the Act singles out for stricter treatment, which include biometric and genetic data.
- “Biometric data” means personal data produced by technical processing of a person’s physical characteristics that allows that person to be identified, such as a facial recognition template.
- “Processing” means anything done with personal data, from collection to deletion.
- “Data subject” means the person the personal data is about.
- “Sub-processor” means any third party that Eigenstate engages to process personal data on the Controller’s behalf.
- “Personal data breach” means a breach of security that leads to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of, or access to, personal data.
- “Principal Agreement” means the statement of work, and any master services agreement, to which this DPA is annexed.
- “Services” means the systems Eigenstate builds, hosts, integrates, supports or operates for the Controller under the Principal Agreement.
2. Subject matter, duration, nature and purpose of processing
2.1 Subject matter. Eigenstate processes personal data to the extent needed to build, deploy, host, support and operate the Services.
2.2 Duration. Processing continues for the term of the Principal Agreement and the wind-down period in clause 10.
2.3 Nature and purpose. The nature of the processing depends on the Services ordered and is described in the statement of work. It may include capturing images and video from cameras, matching faces against stored templates for access control, recording the location of tagged people and assets on a site, recording vehicle position and driver behaviour, calculating hours worked and pay, handling customer and guest conversations through AI agents, and storing business documents. The purpose is the Controller’s operational purpose set out in the statement of work, and no other.
Categories of data subject
2.4 Depending on the Services, the people whose data is processed may include:
- employees, contractors and other workers of the Controller;
- visitors to the Controller’s sites;
- drivers of the Controller’s vehicles;
- customers and prospective customers of the Controller, resellers, and their staff;
- guests of the Controller’s hospitality premises;
- any other person who appears in camera footage at a monitored site.
Categories of personal data
2.5 Depending on the Services, the personal data processed may include:
- images and video from CCTV and access-control cameras, and biometric data in the form of facial recognition templates derived from them, which is sensitive data;
- location and telemetry data from BLE tags carried by people or fixed to assets, and vehicle GPS and driving-behaviour data, including driver risk scores;
- HR and payroll data, including clock-in records, hours, pay, tax details, bank details and approvals, some of which may be exchanged over WhatsApp;
- customer and guest communications over WhatsApp, email and SMS, and the related CRM records;
- hospitality guest records, including reservations, stays, folios and payment records;
- ordering and reseller data, including orders, reseller identities, commissions and payouts;
- personal data contained in documents, invoices and other business records.
2.6 Where the Services involve sensitive data, clause 4 also applies.
3. Eigenstate’s obligations as processor
3.1 Instructions. Eigenstate will process personal data only on the Controller’s documented instructions, including on any transfer of personal data outside Zimbabwe, unless the law requires otherwise. The Principal Agreement and this DPA are the Controller’s complete initial instructions; further instructions must be given in writing. Eigenstate will tell the Controller promptly if it believes an instruction would breach the Act.
3.2 Confidentiality. Eigenstate will ensure that every person it authorises to process personal data is bound by a duty of confidentiality, under a contract of employment or a written agreement.
3.3 Security. Eigenstate will put in place and maintain technical and organisational measures appropriate to the risk. As a minimum: personal data is held inside the Controller’s own environment or in a dedicated tenant used only for the Controller; access to production systems is limited to the people who need it; and retention and access rules are agreed in writing before go-live. The specific measures for an engagement are described in the statement of work.
3.4 Data subject requests. Eigenstate will help the Controller respond to requests from data subjects exercising their rights under the Act, including the rights of access, rectification, erasure and objection, by providing the information and tools it holds. Eigenstate will pass any request it receives to the Controller without undue delay and will not respond to a data subject directly unless the Controller instructs it to.
3.5 Breach assistance and impact assessment. Eigenstate will help the Controller meet its obligations under the Act on security and breach notification (clause 7) and, where the Controller carries out a data protection impact assessment or consults the Authority about a processing operation, will provide the information about the Services that the Controller reasonably needs.
3.6 End of engagement. At the end of the Services, Eigenstate will delete or return the personal data as the Controller chooses under clause 10.
3.7 Demonstrating compliance. Eigenstate will keep a record of the processing it carries out for the Controller and will make available the information reasonably needed to show that it is meeting its obligations under this DPA.
3.8 Audits. Eigenstate will allow, and contribute to, audits by the Controller or an independent auditor it appoints, on reasonable written notice, during business hours, no more than once in any twelve-month period unless the Authority requires it or a personal data breach has occurred, and in a manner that does not compromise the security of other clients’ systems.
4. Sensitive data: biometric templates and CCTV
4.1 This clause applies wherever the Services involve facial recognition templates, face matching, or CCTV images and video of identifiable people.
4.2 Purpose limitation. Biometric templates and CCTV data are processed only for the specific purpose stated in the statement of work, for example access control at a named gate. They will not be processed for any other purpose.
4.3 No secondary use. Eigenstate will not use biometric templates, CCTV data or any other personal data of the Controller to train or improve models or services for its own benefit or for other clients, or to build profiles of individuals beyond the purpose instructed, and will not disclose it to anyone other than the Controller and the sub-processors authorised under clause 5.
4.4 Access logging. Access by Eigenstate staff to biometric templates and CCTV data is restricted to named people who need it to deliver the Services. Where the Services include an access log, Eigenstate will make it available to the Controller on request.
4.5 Retention. Biometric templates and CCTV data are retained for the periods the Controller instructs in writing before go-live and no longer. Where no period has been set for a category of data, Eigenstate will ask for one before processing begins.
4.6 Deletion on termination. On termination of the Services, or earlier on the Controller’s instruction, biometric templates are deleted from every system under Eigenstate’s control and the deletion is confirmed in writing under clause 10.
4.7 The Controller’s responsibilities for lawful basis, notices and consent in respect of biometric data are set out in clause 8.
5. Sub-processors
5.1 Eigenstate will not engage a sub-processor to process personal data without the Controller’s prior written authorisation. The statement of work lists the sub-processors authorised at the start of an engagement; the categories that may be used include hosting providers, messaging platforms and AI model providers.
5.2 Eigenstate will give the Controller written notice of any intended addition or replacement of a sub-processor, allowing a reasonable opportunity to object before the change takes effect. If the Controller objects on reasonable grounds and the parties cannot resolve the objection, the Controller may terminate the affected Services.
5.3 Eigenstate will impose on each sub-processor, by written contract, obligations that protect personal data to at least the standard of this DPA, and remains fully responsible to the Controller for each sub-processor’s performance.
5.4 The current list of sub-processors for an engagement is available on request to support@eigenstatesystems.com.
6. Cross-border transfers
6.1 The Act restricts the transfer of personal data outside Zimbabwe. Eigenstate will not transfer personal data outside Zimbabwe, and will not permit a sub-processor to do so, except with the Controller’s prior written authorisation and where the conditions the Act sets for such a transfer are met.
6.2 Before go-live, Eigenstate will disclose in the statement of work the country or countries in which each hosting location, backup location and sub-processor will hold or access the Controller’s personal data. Where the Services run inside the Controller’s own environment, the Controller is responsible for the location of that environment.
6.3 Where a transfer is authorised, the parties will put in place the safeguards the Act requires for it, and Eigenstate will cooperate with any notification to, or approval by, the Authority that the Act requires.
7. Personal data breach
7.1 Eigenstate will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s personal data, and in any event within a period that allows the Controller to meet its own notification obligations under the Act.
7.2 The notification will describe, so far as is known at the time, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point at Eigenstate. Information not available at first notification will follow as it becomes available.
7.3 The Controller is responsible for notifying the Authority and data subjects where and when the Act requires. Eigenstate will not notify the Authority or data subjects on the Controller’s behalf unless the Controller instructs it to in writing.
7.4 Eigenstate will take reasonable steps to contain the breach and reduce its effects, and will cooperate with the Controller’s investigation.
8. Controller’s obligations
8.1 Lawful basis. The Controller is responsible for ensuring that it has a lawful basis under the Act for each processing operation it instructs, including for any processing of sensitive data.
8.2 Notices and consent. The Controller is responsible for giving data subjects the information the Act requires, including signage where cameras are used, and for obtaining consent where the Act requires it, in particular before biometric data is collected from workers, visitors or drivers.
8.3 Accuracy. The Controller is responsible for the accuracy of the personal data it provides or causes to be collected, and for instructing Eigenstate to correct or delete data that is inaccurate.
8.4 Lawful instructions. The Controller will not give instructions that would cause Eigenstate to breach the Act, and will not use the Services to process personal data outside the purpose in the statement of work.
8.5 Licensing and data protection officer. The Controller is responsible for any licensing with the Authority, and any appointment of a data protection officer, that the Act requires of it as data controller, and will tell Eigenstate who that officer is.
9. Liability and indemnity
9.1 Each party is liable to the other for loss caused by its own breach of this DPA or of the Act.
9.2 Each party will indemnify the other against fines, penalties and third-party claims, and the reasonable costs of dealing with them, to the extent that they arise from the indemnifying party’s breach of this DPA or of the Act.
9.3 The limitations and exclusions of liability in the Principal Agreement apply to this DPA, except that nothing in this DPA limits or excludes liability that the Act does not allow to be limited or excluded.
10. Term, termination, return and deletion
10.1 This DPA takes effect when the Principal Agreement to which it is annexed is signed, and continues for as long as Eigenstate processes personal data on the Controller’s behalf.
10.2 Termination of the Principal Agreement terminates this DPA, except that the obligations in this clause and in clauses 3.2, 4 and 9 continue after termination.
10.3 After the end of the Services, and within the period agreed in the statement of work, Eigenstate will, at the Controller’s choice, return all personal data in a commonly used format or delete it, and will delete any remaining copies, unless the law requires Eigenstate to keep some of it. Where the data lives in the Controller’s own environment, Eigenstate’s obligation is to remove its own access and delete any copies it holds elsewhere.
10.4 Eigenstate will confirm deletion in writing on request.
11. South Africa: POPIA
11.1 Where the Controller is subject to the Protection of Personal Information Act 4 of 2013 of South Africa (“POPIA”) in respect of any processing under this DPA, Eigenstate acts as an “operator” and the Controller as a “responsible party” under POPIA for that processing.
11.2 In that case the parties will, before the processing begins, execute the additional written terms that POPIA requires between a responsible party and an operator, covering in particular confidentiality, security measures and notification of security compromises, and Eigenstate will give the Controller the cooperation it needs to meet its obligations to the Information Regulator of South Africa and to data subjects.
11.3 Where both POPIA and the Act apply to the same processing, Eigenstate will comply with whichever requirement is stricter.
12. Governing law, precedence and version
12.1 This DPA is governed by the laws of Zimbabwe, and the courts of Zimbabwe have jurisdiction, subject to any dispute resolution procedure in the Principal Agreement.
12.2 If this DPA conflicts with the Principal Agreement on a matter concerning personal data, this DPA prevails.
12.3 This is the version dated 13 September 2026. Eigenstate may publish updated versions on this page; the version that applies to an engagement is the one annexed to its signed statement of work.
12.4 Questions about this DPA may be sent to Eigenstate’s data protection contact at support@eigenstatesystems.com.
Tell us what runs your operation
A mine site, a workshop, a lodge, a haulage fleet. A 15-minute discussion to understand the problem, the infrastructure you already have, and the automation opportunity.