Data Processing Addendum (DPA)

Effective date: April 1, 2026

This Data Processing Addendum (“DPA”) forms part of and supplements the Hafinen Terms of Service (“Agreement”) entered into between Hafinen Limited (“Hafinen”, “Processor”, “we”, “us”) and the Customer (“Controller”).

This DPA applies where Hafinen processes Personal Data on behalf of Customer in connection with Hafinen’s Services.

If there is any conflict between this DPA and the Agreement regarding Personal Data processing, this DPA shall prevail.

1. Definitions

For purposes of this DPA:

“Applicable Data Protection Laws” means all applicable privacy and data protection laws, including but not limited to Kenya Data Protection Act 2019, General Data Protection Regulation (GDPR), UK GDPR, Data Protection Act 2018 (UK), California Consumer Privacy Act (CCPA) where applicable, South Africa POPIA, and any similar applicable laws.

“Personal Data” means any information relating to an identified or identifiable natural person processed by Hafinen on behalf of Customer.

“Data Subject” means the individual to whom Personal Data relates.

“Processing” means any operation performed on Personal Data.

“Subprocessor” means any third party engaged by Hafinen to process Personal Data.

“Security Incident” means unauthorized access, acquisition, disclosure, loss, alteration, or destruction of Personal Data.

2. Roles of the Parties

For Customer Data processed under the Services, Customer acts as Data Controller and Hafinen acts as Data Processor.

Customer determines the purposes of processing, categories of Personal Data, retention instructions, and access rights.

Hafinen shall process Personal Data only in accordance with documented instructions from Customer unless required by law.

3. Scope of Processing

A. Employee Data

Including names, contact information, employment records, job titles, department data, compensation records, attendance records, leave balances, performance records, training records, disciplinary records, and termination records.

B. Candidate Data

Including resumes, CVs, applications, interview records, assessments, recruiter notes, and hiring decisions.

C. Payroll Data

Including salaries, deductions, allowances, tax identifiers, payroll records, statutory contributions, and banking information.

D. Compliance Data

Including contracts, policies, acknowledgements, legal documents, and certifications.

E. Attendance and Biometric Data

Hafinen supports attendance events linked to fingerprint and facial recognition systems.

Hafinen does not store raw biometric images.

Integrated biometric systems store encrypted templates or tokens.

Hafinen may process timestamps, attendance logs, authentication outcomes, and employee-device linkage records.

F. Operational Data

Including workflow approvals, meeting records, task records, internal communication records, knowledge records, and analytics activity.

4. Nature and Purpose of Processing

Hafinen processes Personal Data for workforce administration, recruitment workflows, payroll processing, compliance tracking, attendance tracking, shift scheduling, employee lifecycle management, performance reviews, training programs, asset management, internal workflow management, analytics, reporting, API operations, integrations, customer support and security.

Future processing may include AI-assisted workflows.

5. Duration of Processing

Hafinen shall process Personal Data during the active subscription term, for up to ninety (90) days following termination, and longer only where legally required, necessary for disputes, fraud prevention, backups, or compliance.

6. Customer Obligations

Customer warrants that it has lawful authority to process Personal Data, it has provided legally required notices, it has obtained necessary consents where required, its instructions are lawful, its collection of biometric data complies with applicable law, and it will respond to Data Subject rights requests where acting as Controller.

Customer remains solely responsible for employment law compliance.

7. Processor Obligations

Hafinen shall process Personal Data only on Customer instructions, maintain confidentiality, implement security measures, assist with Data Subject rights requests, assist with compliance obligations where reasonably necessary, notify Customer of Security Incidents and manage Subprocessors responsibly.

8. Security Measures

Hafinen maintains appropriate technical and organizational measures, including encryption in transit, encrypted credential storage, role-based access controls, audit logging, DDoS protection, network segmentation, backup procedures, API authentication, webhook security controls, access monitoring, and vulnerability management.

Customer remains responsible for user access permissions, account credential management, and internal access governance.

9. Subprocessors

Customer authorizes Hafinen to engage Subprocessors in connection with providing the Services.

Hafinen maintains an up-to-date list of authorized Subprocessors, including the nature of processing performed and applicable processing regions, at:

https://www.hafinen.com/subprocessors

Hafinen shall ensure all Subprocessors are bound by written obligations that provide data protection standards materially equivalent to those contained in this DPA.

Where required by applicable law or contractual obligations, Hafinen will provide notice of material Subprocessor changes.

10. International Data Transfers

Customer acknowledges that Personal Data may be transferred internationally.

Where legally required, Hafinen shall implement appropriate safeguards including contractual protections, data transfer agreements, and equivalent lawful transfer mechanisms.

11. Data Subject Rights

To the extent legally required, Hafinen shall reasonably assist Customer in responding to access requests, correction requests, deletion requests, restriction requests, portability requests, and objection requests.

Where Hafinen receives a request directly, Hafinen may redirect the request to Customer.

12. Security Incident Notification

Hafinen shall notify Customer without undue delay after becoming aware of a confirmed Security Incident affecting Customer Data.

Notification may include nature of incident, affected categories, likely consequences, and mitigation actions.

Notification does not constitute an admission of fault.

13. Audit Rights

Where required by applicable law or enterprise agreement, Customer may request reasonable information necessary to demonstrate compliance.

Audits shall occur no more than once annually unless required by law, be at Customer’s expense, avoid unreasonable disruption, and remain subject to confidentiality.

Third-party certifications and security reports may satisfy audit obligations.

14. Government Requests

Unless prohibited by law, Hafinen may notify Customer of legally binding government requests for Personal Data.

15. AI-Assisted Processing

Where AI-assisted features are enabled:

  • Hafinen may process Customer Data for AI-supported workflows solely for Customer benefit
  • AI outputs remain subject to Customer review
  • Hafinen shall not use Customer Personal Data to train generalized public AI models without explicit authorization

Aggregated and anonymized data may be used for product improvement.

Additional operational governance for AI-enabled features is governed by Hafinen’s AI Usage Policy.

16. Return or Deletion

Upon termination and Customer request:

Hafinen shall make Customer Data available for export.

After the retention period, Hafinen may delete Customer Data unless retention is required by law.

17. Liability

Liability under this DPA shall be governed by the liability limitations in the Agreement.

18. Governing Law

This DPA shall be governed by the laws of Kenya unless otherwise agreed in writing.

19. Contact

Hafinen Limited 107 Lower Kabete Road Westlands, Nairobi, Nairobi County Kenya Email: [email protected]

אתה יכול לבחור באילו עוגיות אופציונליות Hafinen עשוי להשתמש כדי לשפר את החוויה שלך. קובצי Cookie נחוצים ואבטחה מופעלים תמיד מכיוון שהם חיוניים לאימות, אבטחת פלטפורמה, מניעת הונאה ותפעול אמין של השירותים. אתה יכול לעדכן את ההעדפות שלך בכל עת.

קובצי Cookie נחוצים בהחלט

קובצי Cookie אלה חיוניים להפין לפעול בצורה מאובטחת ואמינה. הם תומכים באימות חשבון, הפעלות כניסה, הגנת CSRF, המשכיות הפעלה מאובטחת, איזון עומסים ופונקציונליות פלטפורמה מרכזית אחרת. מכיוון שקובצי Cookie אלה נדרשים כדי שהשירותים יפעלו, לא ניתן לבטל אותם.

עוגיות אבטחה

קובצי Cookie אלה עוזרים להגן על חשבונך והשירותים על ידי זיהוי פעילות חשודה, מניעת גישה בלתי מורשית, הפחתת שימוש לרעה, אימות בקשות API, תמיכה בהגבלת תעריפים ושמירה על שלמות הפלטפורמה. קובצי Cookie אלה נדרשים לצורך אבטחה ואינם ניתנים לביטול.

עוגיות פונקציונליות

עוגיות פונקציונליות זוכרות את ההעדפות שלך ומתאים אישית את החוויה שלך. הם עשויים לאחסן שפה, אזור זמן, ערכת נושא, הגדרות נגישות, התאמות אישיות של ממשק והעדפות לוח המחוונים כך שלא תצטרך להגדיר אותם בכל פעם שאתה משתמש בשירותים.

קובצי Cookie של אנליטיקה

קובצי Cookie של Analytics עוזרים לנו להבין כיצד נעשה שימוש בשירותים כדי שנוכל לשפר את השימושיות, הביצועים והאמינות. הם אוספים מידע כגון אימוץ תכונות, אינטראקציות עם עמודים, דפוסי ניווט, תאימות דפדפן, דוחות קריסה ומדדי ביצועים. במידת האפשר, מידע זה מצטבר או אנונימי.

קובצי Cookie של ביצועים

עוגיות ביצועים משפרות את המהירות, היציבות וההיענות של השירותים. הם תומכים בשמירת מטמון, אופטימיזציה של אספקת תוכן, איזון תנועה, טעינת נכסים וטכנולוגיות אחרות המסייעות לספק חווית משתמש עקבית ואמינה.

עוגיות תקשורת

קובצי Cookie לתקשורת תומכים באינטראקציות הקשורות לשירות, כגון משלוח הודעות, מעקב אחר אירועי דואר אלקטרוני, אישורי SMS וזרימות עבודה תפעוליות אחרות של תקשורת המשפרים את האופן שבו אנו מודיעים לך בזמן השימוש בשירותים.