Data Processing Agreement
Version 2026-06-24 · last updated 24 June 2026
This DPA governs how Pula Books (Pty) Ltd, which operates the LedgerIQ service ("Processor"), processes personal data on behalf of your organisation ("Controller") when you use LedgerIQ. It forms part of the terms you accept at signup. Both parties are bound by the Botswana Data Protection Act 2018.
1. What we process
The Processor processes the personal data the Controller and the Controller's users enter into the LedgerIQ service: customer and vendor records, employee records (including PAYE and identifier data), invoices, payslips, ledger entries, KYC / AML profiles, audit trail entries, and the operational metadata necessary to deliver the service.
2. What we DO NOT do
The Processor will not access, read, sell, share, lease or licence the Controller's data for any purpose other than delivering the service as instructed by the Controller. We will not use the Controller's data to train AI models.
3. Sub-processors
The Processor engages the sub-processors listed in the published Privacy Notice (current version 2026-06-24). The Controller authorises this list at signup. When we add or change a sub-processor we will publish the change at least 14 days before it takes effect; if the Controller objects, they may terminate the agreement and we will return their data on request.
4. Cross-border transfers (DPA 2018 s.48)
Some sub-processors operate outside Botswana — currently the EEA (Cloudflare R2, Vercel, Neon) and the United States (Clerk, Anthropic, Resend, GitHub Actions). The safeguard for these transfers is the sub-processor's own contractual commitments to data protection equivalent to DPA 2018, plus the Processor's independent age-encrypted backups whose decryption key never leaves Botswana.
5. Security measures
The Processor maintains: encryption in transit (TLS) for all connections; encryption at rest provided by the database host; row-level tenant isolation enforced in code and on every query; append-only audit log; role-based access control with explicit CompanyMembership for multi-company tenants; nightly age-encrypted backups to immutable Cloudflare R2 Object Lock storage retained for seven years; mandatory multi-factor authentication for privileged roles. The full posture is documented in the public Privacy Notice and the LedgerIQ security commitments.
6. Personnel
Only personnel with a documented operational need are permitted access to Controller data, and only for the limited purpose required. All access is recorded in the audit trail.
7. Controller rights and the Processor's assistance
On the Controller's reasonable instruction, the Processor will (at the Controller's cost where the request is excessive): produce a Data Subject Access export (DPA 2018 s.18) within 30 days; delete specific data subject records consistent with statutory retention; cooperate with any investigation by the Information and Data Protection Commissioner.
8. Breach notification
The Processor will notify the Controller without undue delay — and in any event within 72 hours — of becoming aware of a personal data breach affecting the Controller's data, providing the nature of the breach, the categories and approximate number of data subjects affected, contact details, likely consequences and the mitigations in place or planned.
9. Retention and deletion at termination
On termination of the subscription the Processor will, at the Controller's choice: return the Controller's data (per-tenant export); or delete the live records while preserving the retention-bound copies for the periods required by Companies Act 2003 (7 years), Income Tax Act (5 years) and Financial Intelligence Act 2022 (5 years). Statutory retention takes precedence over an erasure request.
10. Audits
The Controller may, on 30 days' written notice and not more than once per year, request that the Processor provide a written attestation of its security and processing controls. The Processor may rely on its internal audit reports and the published Privacy Notice as the response, except in the case of a documented incident.
11. Governing law
This DPA is governed by the laws of the Republic of Botswana. Disputes are subject to the exclusive jurisdiction of the courts of Botswana.
12. Acceptance
The Controller accepts this DPA at signup by clicking through. The TenantConsent record we create at that moment — including the version above, the email of the person who clicked, the timestamp, IP address and user agent — is the evidence of acceptance and is produced on request to the Information and Data Protection Commissioner.
Pula Books (Pty) Ltd · Gaborone, Botswana · privacy@ledgeriq.africa