Back to Home

Data Processing Agreement (DPA)

This document is provided in English; the English text is authoritative.

This document sets out the roles, responsibilities and security measures that apply when we process personal data on your behalf.

Last Updated: September 22, 2026

1. Roles & Responsibilities

Under this Agreement, the Customer is the Data Controller and UPCOT is the Data Processor as defined by the General Data Protection Regulation (GDPR) (EU) 2016/679.

The Processor shall only process Personal Data on behalf of and in accordance with the documented instructions of the Controller. The Controller warrants that it has all necessary rights to provide the Personal Data to the Processor for the Processing to be performed in relation to the Services.

2. Details of Processing

The processing of Personal Data by the Processor shall involve the following:

  • Subject Matter: Provision of industrial structural analysis services as outlined in the Master Services Agreement.
  • Nature and Purpose: Storage, retrieval, and analysis of structural integrity data which may contain personnel identifiers.
  • Categories of Data: Contact information, employment details, system access logs.
  • Data Subjects: Employees, contractors, and authorized representatives of the Controller.

3. Security Measures

The Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:

Encryption

Encryption of personal data in transit and at rest using industry-standard protocols.

Access Control

Access to personal data is limited to the accounts that need it; credentials are held as encrypted secrets and never in this website's code.

4. Sub-processors

The Processor engages the following sub-processors. Each is bound by written terms imposing data-protection obligations no less protective than this Agreement. They operate globally, so personal data may be processed outside Rwanda.

  • Cloudflare — website hosting, database storage, and Turnstile bot protection for the quote form.
  • Google — spreadsheet storage of quote requests, reached by a single dedicated service account.
  • Telegram — delivery of quote-request notifications, including project details, to the workshop team.
  • Mailjet — transactional email to the Customer. Not currently active.

The Customer may object to a new sub-processor by writing to info@upcot.rw.

5. Data Breach Notification

The Processor shall notify the Customer without undue delay after becoming aware of a personal data breach affecting personal data processed under this Agreement.

That notification shall describe, so far as the Processor can establish at the time:

  • the nature of the breach, and the categories and approximate number of data subjects and records concerned;
  • the likely consequences of the breach;
  • the measures taken or proposed to address it and mitigate its effects; and
  • the contact point from which the Customer may obtain further information.

Where the Processor cannot supply all of this at once, it shall provide it in phases without further undue delay. The Processor shall also take reasonable steps to contain the breach and prevent its recurrence.

Notification is sent to the address the Customer has registered with us, or on request to info@upcot.rw.

Acceptance & Signature

To execute this agreement, send it to info@upcot.rw from an address your organisation controls, with the signatory details below. We will counter-sign and return a copy for your records. Nothing on this page is sent anywhere until you send that message.

Send Acceptance by Email