Comiine
Legal

Comiine Data Processing Agreement

How Comiine processes personal data on behalf of a customer who is the controller of it.

Last updated
29 August 2026
Version
1.0

This Data Processing Agreement ("DPA") supplements and forms part of the agreement between Comiine and the customer organisation for use of the Comiine Service (the "Agreement"). It takes effect on the date the Agreement takes effect, or on the date the parties sign this DPA, whichever is earlier.

The parties are:

  • Millyjoy & Co (Proprietary) Limited, company registration BW00009256082, of Plot 7414, Mogoditshane, Botswana, trading as Comiine (the "Processor"); and
  • the customer organisation that has agreed to the Agreement (the "Customer", the "Controller").

This DPA records the parties' obligations under the Data Protection Act, 2024 (Act No. 18 of 2024) ("the Act") for personal data Comiine processes on the Customer's behalf. It is drafted to satisfy GDPR Article 28 as a stricter benchmark. South Africa's POPIA operator provisions will be applied when we operate in South Africa.

This DPA was prepared in-house and has not yet been reviewed by a legal practitioner admitted in Botswana. Comiine offers it for signature; it is not a signed agreement until both parties sign it.


1. Definitions

Terms not defined here have the meaning given in the Act.

Customer Personal Data means personal data within Customer Data, as defined in the Agreement, that Comiine processes on the Customer's behalf.

Sub-processor means a third party engaged by Comiine to process Customer Personal Data.

2. Roles of the parties

2.1 For Customer Personal Data, being the operational and workforce records the Customer and its Authorised Users keep in Comiine, including the personal data of the Customer's employees and contractors, the Customer is the Controller and Comiine is the Processor. Comiine processes that data only on the Customer's documented instructions.

2.2 Comiine is an independent Controller, and not a processor, for:

(a) the account and identity data of Authorised Users needed to provide and secure access to the Service;

(b) Comiine's own device and diagnostic data, being consent-based crash reporting, and Comiine's business operations; and

(c) pseudonymous product usage events, being the event name, timestamp, organisation, a pseudonymous user identifier, platform, app version and typed non-free-text properties, used solely to measure activation and improve the Service, at organisation and cohort level, and never to profile an individual for Comiine's own purposes.

That controller processing is governed by Comiine's Privacy Policy, not by this DPA.

2.3 The same usage events also power the Customer's own adoption and data quality features inside the Service. For that purpose the Customer is the Controller under clause 2.1 and Comiine is the Processor.

3. Details of the processing

The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.

4. The Customer's obligations as Controller

4.1 The Customer warrants that it has a valid lawful basis under section 26 of the Act for the processing it instructs, that its instructions are lawful, and that it has given the notices and obtained any authorisations a controller is required to give or obtain.

4.2 Lawful basis for workforce data. For personal data about the Customer's own employees and contractors, being names, worker identifiers, roles, work records, inspection sign-offs, signatures, chat entries and photographs of work, the Customer should not rely on employee consent as the basis for core workforce processing. In an employment relationship consent is generally not freely given, and consent that is not necessary for the contract or service is not a sound basis where another basis applies. The bases that usually fit are:

  • performance of the employment contract;
  • compliance with a legal obligation, for example the mining, occupational health and safety and record-keeping duties that require inspection, lock-out tag-out, job safety analysis and maintenance records to be kept. The Customer should identify with its own advisers exactly which of those duties apply to it and what they require; and
  • the legitimate interests of the Customer or a third party, for example asset reliability, safety and operational management, subject to a balancing assessment.

Consent should be reserved for processing that is genuinely optional. This clause is drafting guidance and is not a substitute for the Customer's own legal advice.

4.3 The Customer is responsible for the accuracy of its instructions, and for telling its data subjects about the processing and their rights.

5. Comiine's obligations as Processor

Comiine will, in respect of Customer Personal Data:

(a) process only on the Customer's documented instructions, including this DPA and the Customer's configuration of the Service, and tell the Customer if, in Comiine's opinion, an instruction breaches the Act;

(b) make sure the people authorised to process Customer Personal Data are under an appropriate duty of confidentiality;

(c) implement and maintain the technical and organisational security measures in Annex 2;

(d) engage Sub-processors only in accordance with clause 6;

(e) taking account of the nature of the processing, help the Customer respond to data subject requests, by appropriate technical and organisational measures;

(f) help the Customer meet its own security, breach notification, impact assessment and prior consultation duties, taking account of the information available to Comiine;

(g) at the Customer's choice, delete or return all Customer Personal Data at the end of the provision of services, and delete existing copies, except where the law requires retention. See the Data Retention and Deletion Policy and clause 10; and

(h) make available to the Customer the information reasonably necessary to demonstrate compliance with this clause, and allow for and contribute to audits under clause 9.

6. Sub-processors

6.1 The Customer gives general authorisation for Comiine to engage the Sub-processors listed in the Sub-processor List and in Annex 3, each under a written contract imposing data protection obligations no less protective than this DPA.

6.2 Comiine will give the Customer 30 days' prior notice of any intended addition or replacement of a Sub-processor, by updating the Sub-processor List and by notice to the Customer's nominated contact. During those 30 days the Customer may object on reasonable data protection grounds, and the parties will work in good faith to resolve the objection. If it cannot be resolved, the Customer may terminate the affected part of the Service without penalty.

6.3 Comiine remains liable to the Customer for its Sub-processors' performance of the obligations in this DPA.

7. Transfers outside Botswana

7.1 Comiine and its Sub-processors process Customer Personal Data outside Botswana. The current processing locations are set out in the Sub-processor List and summarised here: the primary database, authentication and file storage run on Supabase in the United States, region us-east-1. Error monitoring, web hosting, and app build and update services also process limited data outside Botswana.

7.2 Botswana designated a list of countries as offering adequate protection in the Data Protection (Transfer of Personal Data) Order, 2022, issued on 29 July 2022. The United States is not on that list. Comiine therefore does not claim an adequacy basis for its United States hosting. Comiine relies on the data protection terms and contractual safeguards it holds with each Sub-processor, on full disclosure of processing locations to the Customer, and on the measures in Annex 2. The Customer accepts that disclosure as part of agreeing to this DPA.

7.3 Comiine is seeking confirmation from a legal practitioner admitted in Botswana on the correct transfer basis and on whether the Act requires a copy of personal data to be kept inside Botswana. Comiine does not keep a copy inside Botswana and does not claim to. Comiine will tell the Customer, and update the Sub-processor List, when that position changes.

7.4 If the Customer is required to complete its own transfer assessment, Comiine will provide the information it holds that the Customer reasonably needs for it.

8. Personal data breach

8.1 Comiine will notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Customer Personal Data. That commitment is set so the Customer can meet its own duty to notify the Information and Data Protection Commission within 72 hours of becoming aware of the breach.

8.2 The notification will describe, so far as known, the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. Comiine will cooperate with the Customer and take reasonable steps to mitigate the breach and its effects.

8.3 As Controller, the Customer is responsible for notifying the Commission and, where required, the affected data subjects.

8.4 Comiine will not make a public statement identifying the Customer in connection with a breach without the Customer's consent, unless the law requires it.

9. Audit

9.1 Comiine will make available the information reasonably necessary to demonstrate compliance with this DPA.

9.2 The Customer, or an independent auditor the parties agree on, may audit that compliance once in any 12-month period, on 30 days' written notice, and additionally where a regulator requires it or following a personal data breach affecting the Customer Personal Data.

9.3 An audit will first be satisfied by documentation, written responses and, where useful, a remote session. An on-site inspection may follow if the documentary route does not reasonably answer the Customer's questions.

9.4 Audits take place during business hours, must not unreasonably disrupt Comiine's business, are subject to confidentiality, and must not compromise the security or data of any other customer. Each party bears its own costs, except that the Customer bears Comiine's reasonable costs for a second or later audit in the same 12-month period, unless that audit finds material non-compliance.

10. Deletion and return

10.1 On expiry or termination of the Agreement, Comiine will, at the Customer's choice, return and delete Customer Personal Data as set out in the Data Retention and Deletion Policy.

10.2 The Customer acknowledges the offline-first nature of the Service. Copies of data held on Authorised Users' devices persist until those devices synchronise the deletion, or until the app data is cleared or the device is wiped. The Customer is responsible for its own device management.

10.3 Data deleted from the live system remains in existing backups until those backups age out on the ordinary backup cycle. Comiine does not edit historic backups, and does not restore a backup in order to recover deleted personal data.

11. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement.

12. Governing law

This DPA is governed by the laws of the Republic of Botswana and is subject to the dispute resolution and jurisdiction provisions of the Agreement.


Annex 1: Details of the processing

ItemDetail
Subject matterProvision of the Comiine maintenance management Service to the Customer
DurationThe term of the Agreement, plus the return and deletion period in clause 10
Nature and purposeHosting, storing, transmitting, synchronising and displaying Customer Data so the Customer can manage maintenance, reliability and safety
Types of personal dataIdentifiers of employees and contractors, being name, worker identifier, role or trade and work email; work order and inspection content; chat and checklist entries; digital signatures; photographs, which may incidentally show people; device and synchronisation metadata
Categories of data subjectsThe Customer's employees, contractors and other Authorised Users
Special categoriesComiine does not ask for, and does not require, health or other special category data. However, safety records can capture it: an incident, injury or fitness-for-work note recorded in a free text field, or a photograph of an injury, is health data. The Customer decides what its people record. Where the Customer instructs processing that includes special category data, the Customer is responsible for identifying the additional conditions that apply to it and for instructing Comiine accordingly.
FrequencyContinuous, for the term of the Agreement
RetentionAs set out in the Data Retention and Deletion Policy and in the Customer's own instructions

Annex 2: Technical and organisational measures

These are the measures Comiine has in place today. Nothing that is not in place is listed.

  • Encryption in transit. TLS for all communication between the apps and our servers.
  • Organisation-scoped access control. Row-level security on the server database, so an organisation can reach only its own data. Role-based write permissions are enforced at the database, not only in the app.
  • Least privilege. Service credentials are scoped to the minimum needed. Secrets are held in environment and secret stores, never in source code.
  • Credential storage on devices. Authentication tokens are held in the operating system's secure key store, not in ordinary app storage.
  • Audit integrity. Sign-off and audit records are written to an append-only, hash-chained log, designed so undetected alteration is evident. Once a record is signed off, the signed fields are frozen at the database level.
  • Storage encryption is provided by the cloud infrastructure provider at the storage layer.
  • Access to production is limited to Comiine personnel who need it, under a duty of confidentiality.

Known limitation. The local database on an Authorised User's device is not separately encrypted by the Comiine app. It relies on the operating system's app sandbox and the device lock. Customers should require device passcodes and use mobile device management where available.

Not claimed. Comiine holds no SOC 2 report, no ISO 27001 certification and no independent security certification, and none is claimed here. Comiine has not been the subject of an independent security audit.

Annex 3: Authorised Sub-processors

The Sub-processor List is incorporated into this DPA by reference. It names each Sub-processor, what it does, the personal data it handles and where it processes it.


Signature

ComiineCustomer
EntityMillyjoy & Co (Proprietary) Limited t/a Comiine
Name
Position
Date
Signature

Data protection contact at Comiine: privacy@comiine.com.