Data Processing Agreement
Last updated: February 2026
This Data Processing Agreement ("DPA") forms part of the service agreement ("Principal Agreement") between the entity identified as the customer ("Controller") and Royalti Digital Music Solutions Limited ("Processor"), collectively referred to as the "Parties" and each a "Party".
This DPA sets out the terms on which the Processor will process Personal Data on behalf of the Controller in connection with the services provided through royalti.io and app.royalti.io (collectively, the "Services").
Disclaimer: This DPA is provided for organisational and informational purposes. It should be reviewed by qualified legal counsel before execution. This document does not constitute legal advice.
1. Definitions
In this DPA, unless the context requires otherwise, the following terms shall have the meanings set out below:
- "Controller" means the entity that determines the purposes and means of the Processing of Personal Data and that has entered into the Principal Agreement with the Processor.
- "Processor" means Royalti Digital Music Solutions Limited, a company registered in the Federal Republic of Nigeria, which processes Personal Data on behalf of the Controller.
- "Data Subject" means an identified or identifiable natural person whose Personal Data is processed under this DPA.
- "Personal Data" means any information relating to a Data Subject that is processed by the Processor on behalf of the Controller in connection with the Services.
- "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
- "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
- "Standard Contractual Clauses" ("SCCs") means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission pursuant to Regulation (EU) 2016/679.
- "Supervisory Authority" means an independent public authority established by a member state of the European Union pursuant to the GDPR, or the Nigeria Data Protection Commission ("NDPC") established under the NDPA 2023, as applicable.
- "GDPR" means the General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council.
- "NDPA 2023" means the Nigeria Data Protection Act 2023 and any subsidiary legislation, regulations, or guidelines issued thereunder, including the General Application and Implementation Directive (GAID) 2025.
- "Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.
2. Scope & Purpose
This DPA applies to the Processing of Personal Data by the Processor on behalf of the Controller in connection with the provision of the Services under the Principal Agreement. The Processor shall process Personal Data only as necessary to deliver the Services and in accordance with the Controller's documented instructions.
2.1 Types of Personal Data Processed
The following categories of Personal Data may be processed in connection with the Services:
- Identity data: names, email addresses, phone numbers, profile images, stage names, and other identifying information of artists, label administrators, and end users.
- Financial data: bank account details, payment information, royalty earnings, payout records, tax identification numbers, and invoicing details.
- Music metadata: song titles, ISRC codes, UPC codes, release dates, contributor credits, publishing splits, and catalogue information.
- Usage data: streaming statistics, download counts, platform analytics, login activity, feature usage patterns, and device/browser information.
2.2 Categories of Data Subjects
Personal Data processed under this DPA relates to the following categories of Data Subjects:
- Artists: musicians, performers, songwriters, and producers whose music is distributed or managed through the Services.
- Label administrators: individuals managing record labels, catalogues, or artist rosters within the platform.
- End users: individuals who access or interact with the Services, including collaborators, managers, and other authorised personnel.
2.3 Purpose of Processing
The Processor shall process Personal Data solely for the following purposes:
- Royalty management: calculating, tracking, and distributing royalty payments to artists and rights holders.
- Music distribution: delivering musical works to digital service providers and retail platforms on behalf of the Controller.
- Analytics and reporting: generating performance reports, streaming analytics, and financial summaries for the Controller.
- Account administration: managing user accounts, access permissions, and platform functionality.
- Communication: sending transactional emails, notifications, and support correspondence related to the Services.
3. Controller's Instructions
The Processor shall process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by applicable law. In such a case, the Processor shall inform the Controller of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
The Processor shall immediately inform the Controller if, in the Processor's opinion, an instruction from the Controller infringes the GDPR, the NDPA 2023, or other applicable data protection provisions. The Processor shall not be required to assess whether the Controller's instructions comply with applicable law, but shall act in good faith to notify the Controller of any obvious non-compliance that comes to the Processor's attention.
The Controller's instructions at the time of entering into this DPA are that the Processor shall process Personal Data only as necessary to provide the Services in accordance with the Principal Agreement. Any additional or alternative instructions must be agreed upon in writing between the Parties.
4. Processor Obligations
The Processor shall:
- Ensure that persons authorised to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. This obligation shall survive the termination of the individual's engagement with the Processor.
- Implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk of Processing, as further detailed in Section 5 (Security Measures) of this DPA.
- Assist the Controller, taking into account the nature of Processing and the information available to the Processor, in ensuring compliance with the Controller's obligations in respect of security of Processing, notification of Data Breaches, data protection impact assessments, and prior consultation with Supervisory Authorities.
- Assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests from Data Subjects exercising their rights under applicable data protection law.
- Make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller, subject to the terms of Section 11 (Audit Rights).
- Maintain a record of all categories of Processing activities carried out on behalf of the Controller, in accordance with Article 30(2) of the GDPR and the corresponding requirements of the NDPA 2023.
- Designate a Data Protection Officer ("DPO") who may be contacted at [email protected].
5. Security Measures
The Processor shall implement and maintain appropriate technical and organisational security measures to protect Personal Data against unauthorised or unlawful Processing and against accidental loss, destruction, or damage. These measures shall include, but not be limited to:
- Encryption: all Personal Data shall be encrypted at rest using AES-256 (or equivalent) encryption and in transit using TLS 1.2 or higher.
- Access controls: role-based access controls shall be implemented to ensure that Personal Data is accessible only to authorised personnel on a need-to-know basis. Multi-factor authentication shall be required for administrative access.
- Regular audits: the Processor shall conduct regular security assessments and vulnerability testing of its systems and infrastructure.
- Pseudonymisation: where feasible and appropriate to the nature of the Processing, the Processor shall apply pseudonymisation techniques to reduce the identifiability of Personal Data.
- Incident response: the Processor shall maintain a documented incident response plan that includes procedures for identifying, containing, assessing, and reporting Data Breaches.
- Backup and recovery: the Processor shall maintain regular backups of Personal Data and ensure the ability to restore availability and access to Personal Data in a timely manner in the event of a physical or technical incident.
- Employee training: all personnel with access to Personal Data shall receive regular training on data protection and security practices.
- Physical security: the Processor's data centre providers shall maintain appropriate physical security controls, including access restrictions, surveillance, and environmental protections.
The Processor shall regularly test, assess, and evaluate the effectiveness of these technical and organisational measures and shall update them as necessary to maintain an appropriate level of security.
6. Sub-processor Management
The Controller provides general written authorisation for the Processor to engage Sub-processors to assist in providing the Services, subject to the following conditions:
- The Processor shall provide the Controller with at least thirty (30) days' advance written notice of any intended addition or replacement of a Sub-processor, including the name of the Sub-processor, the nature of the Processing to be performed, and the location of Processing.
- The Controller shall have the right to object to the appointment of a new Sub-processor within fourteen (14) days of receiving notice. If the Controller objects on reasonable grounds related to the protection of Personal Data, the Parties shall discuss the Controller's concerns in good faith with a view to achieving a commercially reasonable resolution.
- If no resolution can be reached within thirty (30) days following the Controller's objection, the Controller may terminate the affected portion of the Services without penalty by providing written notice to the Processor.
- The Processor shall impose data protection obligations on each Sub-processor by way of a written contract that provides at least the same level of protection as this DPA. The Processor shall remain fully liable to the Controller for the performance of each Sub-processor's obligations.
6.1 Current Sub-processors
As of the date of this DPA, the Processor engages the following Sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | US / Global |
| Google Cloud Platform | Data storage & computing | US / EU |
| Resend | Transactional email | US |
| PostHog | Product analytics | US / EU |
| Intercom / Chatwoot | Customer support | US / Self-hosted |
| Verto | Currency conversion | UK |
An up-to-date list of Sub-processors may be requested at any time by contacting [email protected].
7. Data Subject Rights
The Processor shall assist the Controller in fulfilling its obligations to respond to Data Subject requests exercising their rights under the GDPR, the NDPA 2023, and other applicable data protection legislation. These rights include, but are not limited to:
- Right of access: the right to obtain confirmation as to whether Personal Data is being processed and, where that is the case, access to the Personal Data.
- Right to rectification: the right to obtain the rectification of inaccurate Personal Data.
- Right to erasure: the right to obtain the erasure of Personal Data where certain conditions are met.
- Right to data portability: the right to receive Personal Data in a structured, commonly used, and machine-readable format.
- Right to restriction: the right to obtain restriction of Processing in certain circumstances.
- Right to object: the right to object to Processing of Personal Data in certain circumstances.
Upon receiving a request from a Data Subject, or upon being notified of such a request by the Controller, the Processor shall respond promptly and in any event within ten (10) business days. The Processor shall not respond directly to a Data Subject request unless authorised to do so by the Controller or required to do so by applicable law.
If the Processor receives a request directly from a Data Subject, the Processor shall promptly forward the request to the Controller and shall not take any further action without the Controller's instructions.
8. Data Breach Notification
The Processor shall notify the Controller of any confirmed Data Breach without undue delay and in any event within forty-eight (48) hours of becoming aware of such breach. This notification timeline is stricter than the seventy-two (72) hour period specified in Article 33 of the GDPR, providing the Controller with additional time to assess and report the breach to the relevant Supervisory Authority where required.
The notification to the Controller shall include, to the extent available at the time of notification:
- A description of the nature of the Data Breach, including where possible the categories and approximate number of Data Subjects concerned, and the categories and approximate number of Personal Data records concerned.
- The name and contact details of the Processor's Data Protection Officer or other contact point where further information can be obtained.
- A description of the likely consequences of the Data Breach.
- A description of the measures taken or proposed to be taken by the Processor to address the Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.
Where it is not possible to provide all information simultaneously, the Processor shall provide the information in phases without undue further delay. The Processor shall cooperate with the Controller and take all reasonable steps to assist in the investigation, mitigation, and remediation of the Data Breach.
The Processor shall document all Data Breaches, including the facts relating to the breach, its effects, and the remedial action taken, and shall make this documentation available to the Controller and any relevant Supervisory Authority upon request.
9. International Data Transfers
The Controller acknowledges that the Processor is established in the Federal Republic of Nigeria and that the provision of the Services may involve the transfer of Personal Data to Nigeria and to other countries where the Processor's Sub-processors are located.
For transfers of Personal Data from the European Economic Area ("EEA") to Nigeria or other third countries that have not received an adequacy decision from the European Commission, the Parties agree to the following safeguards:
- Standard Contractual Clauses: the Parties shall enter into the European Commission's Standard Contractual Clauses (Module Two: Controller to Processor or Module Three: Processor to Processor, as applicable) as annexed to this DPA. Where SCCs are required, they shall be deemed incorporated by reference and shall prevail over any conflicting terms of this DPA.
- Transfer Impact Assessment: the Processor shall conduct and maintain a Transfer Impact Assessment ("TIA") evaluating the laws and practices of each destination country to determine whether they provide an adequate level of protection for Personal Data. The Processor shall make the results of such assessments available to the Controller upon request.
- Supplementary measures: where the TIA identifies risks that are not adequately addressed by the SCCs alone, the Processor shall implement supplementary technical, organisational, or contractual measures, including but not limited to encryption of data in transit and at rest, strict access controls, and pseudonymisation of Personal Data.
For transfers of Personal Data subject to the NDPA 2023, the Processor shall comply with the cross-border transfer provisions set out in the NDPA 2023 and the General Application and Implementation Directive (GAID) 2025, including any requirements for adequacy assessments or the adoption of appropriate safeguards as prescribed by the Nigeria Data Protection Commission.
The Processor shall not transfer Personal Data to any country outside Nigeria or the EEA unless adequate safeguards are in place in accordance with this Section 9.
10. Data Retention & Deletion
Upon termination or expiry of the Principal Agreement, or upon the Controller's written request, the Processor shall, at the Controller's election:
- Return all Personal Data to the Controller in a structured, commonly used, and machine-readable format; or
- Delete all Personal Data, including all existing copies, unless applicable law requires further storage of the Personal Data.
The Processor shall complete the return or deletion of Personal Data within thirty (30) days of receiving the Controller's instructions. Upon the Controller's request, the Processor shall provide written certification confirming that all Personal Data has been deleted or returned in accordance with this section.
Where applicable law requires the Processor to retain certain Personal Data beyond the termination of the Principal Agreement, the Processor shall:
- Inform the Controller of any such legal requirement, unless prohibited by law from doing so.
- Retain only the minimum Personal Data necessary to comply with the legal obligation.
- Continue to protect the retained Personal Data in accordance with the security measures set out in this DPA.
- Delete the retained Personal Data as soon as the legal obligation has been satisfied.
11. Audit Rights
The Controller, or an independent third-party auditor appointed by the Controller, shall have the right to audit the Processor's compliance with this DPA, subject to the following conditions:
- The Controller shall provide at least thirty (30) days' written notice of its intention to conduct an audit.
- Audits shall be conducted during the Processor's normal business hours and shall not unreasonably interfere with the Processor's business operations.
- The scope of any audit shall be reasonable and limited to verifying the Processor's compliance with the obligations set out in this DPA.
- The Controller and its auditor shall maintain the confidentiality of all information obtained during the audit and shall not disclose such information to any third party without the Processor's prior written consent, except as required by law or a Supervisory Authority.
- The Controller shall bear the costs of any audit, unless the audit reveals material non-compliance by the Processor, in which case the Processor shall bear the reasonable costs of the audit.
As an alternative to an on-site audit, the Controller may accept the Processor's provision of a current SOC 2 Type II report, ISO 27001 certification, or equivalent third-party security certification that covers the systems and processes used to process Personal Data under this DPA. The Processor shall make such reports or certifications available to the Controller upon request, subject to confidentiality obligations.
12. Liability & Indemnification
Each Party shall be liable for the damage caused by Processing that infringes the GDPR, the NDPA 2023, or the terms of this DPA, in accordance with Article 82 of the GDPR and the corresponding provisions of the NDPA 2023.
- The Controller shall be liable for damage caused by Processing that does not comply with its obligations as Controller under the GDPR, the NDPA 2023, or this DPA.
- The Processor shall be liable for damage caused by Processing where it has not complied with obligations of the GDPR or the NDPA 2023 specifically directed to processors, or where it has acted outside of or contrary to the Controller's lawful instructions.
- A Party shall be exempt from liability if it proves that it is not in any way responsible for the event giving rise to the damage.
Each Party agrees to indemnify and hold harmless the other Party from and against any and all regulatory fines, penalties, damages, costs, and expenses (including reasonable legal fees) arising from or in connection with:
- The indemnifying Party's breach of this DPA or applicable data protection law.
- Any Data Breach caused by the indemnifying Party's failure to comply with its obligations under this DPA.
- Any claim by a Data Subject or Supervisory Authority arising from the indemnifying Party's non-compliance with this DPA.
Any limitation of liability set out in the Principal Agreement shall apply to the Parties' liability under this DPA, except that nothing in this DPA or the Principal Agreement shall limit either Party's liability to Data Subjects under Article 82 of the GDPR or the corresponding provisions of the NDPA 2023.
13. Term & Termination
This DPA shall come into effect on the date on which the Controller begins using the Services and shall remain in effect for so long as the Processor processes Personal Data on behalf of the Controller under the Principal Agreement. This DPA is co-terminous with the Principal Agreement, and any termination of the Principal Agreement shall automatically terminate this DPA.
Notwithstanding the termination of this DPA, the obligations of the Processor with respect to:
- Data retention and deletion (Section 10) shall survive until all Personal Data has been returned or deleted in accordance with the Controller's instructions.
- Confidentiality obligations shall survive indefinitely with respect to any Personal Data retained by the Processor.
- Liability and indemnification (Section 12) shall survive termination.
- Cooperation with Supervisory Authorities and Data Subject requests relating to Processing that occurred during the term of this DPA shall survive termination.
14. NDPA 2023 Compliance
In addition to the general obligations set out in this DPA, the Processor warrants and undertakes the following with respect to compliance with the Nigeria Data Protection Act 2023 and its subsidiary instruments:
- Registration with the Nigeria Data Protection Commission (NDPC): the Processor shall maintain its registration with the NDPC as required under the NDPA 2023 and shall provide evidence of such registration to the Controller upon request.
- Data Protection Officer: the Processor has appointed a Data Protection Officer in accordance with the requirements of the NDPA 2023. The DPO may be contacted at [email protected].
- General Application and Implementation Directive (GAID) 2025: the Processor shall comply with the GAID 2025 as issued by the NDPC, including any requirements relating to the Processing of Personal Data, data protection impact assessments, registration of data controllers and processors, and reporting obligations.
- Cross-border transfer provisions: where Personal Data is transferred outside Nigeria, the Processor shall ensure that adequate safeguards are in place as required by the NDPA 2023, including but not limited to the adoption of binding corporate rules, contractual clauses, or other mechanisms approved by the NDPC.
- Lawful basis: the Processor shall process Personal Data only where there is a lawful basis for such Processing under the NDPA 2023, as determined by the Controller. The Processor shall not independently determine the lawful basis for Processing.
- Data protection impact assessment: where the Processing is likely to result in a high risk to the rights and freedoms of Data Subjects under the NDPA 2023, the Processor shall assist the Controller in conducting a data protection impact assessment and, where necessary, consulting with the NDPC prior to commencing such Processing.
15. GDPR-Specific Provisions
Where the Processing of Personal Data is subject to the GDPR, the following additional provisions shall apply:
- Lawful bases for Processing: the Controller is responsible for determining and documenting the lawful basis for Processing under Article 6 of the GDPR. The Processor shall process Personal Data solely in accordance with the lawful basis determined by the Controller and shall not process Personal Data for any purpose beyond what is necessary to provide the Services.
- Data Protection Impact Assessment (DPIA) assistance: the Processor shall provide reasonable assistance to the Controller in conducting DPIAs where required under Article 35 of the GDPR, taking into account the nature of the Processing and the information available to the Processor.
- Records of Processing activities: the Processor shall maintain a record of all categories of Processing activities carried out on behalf of the Controller in accordance with Article 30(2) of the GDPR, including the name and contact details of the Processor, the categories of Processing carried out on behalf of each Controller, transfers to third countries, and a general description of the technical and organisational security measures.
- EU Representative: where required under Article 27 of the GDPR, the Processor shall appoint a representative in the European Union. Details of the EU Representative shall be made available to the Controller and to Data Subjects upon request. The Controller may contact [email protected] for current EU Representative details.
- Cooperation with Supervisory Authorities: the Processor shall cooperate, on request, with any Supervisory Authority in the performance of its tasks in accordance with Article 31 of the GDPR.
16. Governing Law
This DPA shall be governed by and construed in accordance with the laws of the Federal Republic of Nigeria, without regard to its conflict of law provisions.
To the extent that the Processing of Personal Data is subject to the GDPR, the provisions of this DPA that relate to GDPR compliance shall be governed by the law of the EU member state in which the Controller is established, or, where the Controller is not established in an EU member state, by the law of the EU member state in which the Controller's EU Representative is established.
Where the Standard Contractual Clauses apply, the governing law of the SCCs shall be as specified in the SCCs themselves and shall take precedence over any conflicting provisions of this DPA.
Any dispute arising out of or in connection with this DPA shall be resolved in accordance with the dispute resolution provisions set out in the Principal Agreement. Where no such provisions exist, or where the dispute relates solely to the Processor's obligations under the GDPR, the dispute shall be submitted to the exclusive jurisdiction of the courts of Lagos, Nigeria, or, where the GDPR applies, the courts of the EU member state in which the Controller is established.
For questions about this DPA or to exercise any rights under it, please contact our Data Protection Officer at [email protected].
This DPA supplements our Terms of Use, Privacy Policy, and Subscription Agreement.