RelilQ Legal
Data Processing Addendum
Effective date: 20 September 2026
Last updated: 20 September 2026
This Data Processing Addendum (“DPA”) forms part of the RelilQ Terms of Service when a customer organisation uses RelilQ to process personal data about employees, applicants, or other individuals.
It is designed for practical NDPA-aligned B2B use. It does not claim certifications RelilQ has not obtained.
1. Parties and roles
The Customer is the organisation that owns the RelilQ workspace. RelilQ is the service provider. For personal data the Customer uploads or generates in RelilQ about its workforce or applicants, the Customer typically determines the purposes of processing and RelilQ processes that data to provide the service on the Customer’s documented instructions (these Terms, product configuration, and support requests).
RelilQ may process limited personal data as an independent controller for account administration, security, billing, and product improvement that does not sell personal data, as described in the Privacy Policy.
2. Processing on documented instructions
RelilQ will process Customer personal data only to provide RelilQ features the Customer enables, including attendance, workforce indicators, recruitment intake, notifications, exports, and related support — unless required by law to process otherwise.
3. Confidentiality
RelilQ ensures personnel who process Customer personal data are bound by confidentiality obligations.
4. Security
RelilQ implements appropriate security measures for a multi-tenant SaaS platform, including access controls, tenant-oriented isolation and RLS where implemented, encryption of Face Match reference embeddings, and audit logging. Security is not absolute.
5. Subprocessors
Customer authorises RelilQ to use infrastructure and service providers reasonably needed to operate RelilQ (hosting, database/auth/storage, email, payments, optional identity verification, optional AI, optional push, face-inference workers, and connected Google Gmail services when the Customer connects them). RelilQ remains responsible for subprocessors it engages to the extent required by applicable law.
[LEGAL REVIEW REQUIRED] Publish a maintained public subprocessor list with notice mechanics if counsel requires formal advance-notice rights.
6. Assistance with data-subject requests
Taking into account the nature of processing, RelilQ will provide reasonable assistance to the Customer in responding to data-subject requests using product features (for example exports, access controls, Face Match revoke) and support via privacy@relilq.com.
7. Personal data incidents
RelilQ will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data, and will provide information reasonably available to help the Customer meet its own notification duties.
[LEGAL REVIEW REQUIRED] Confirm contractual notification timelines (for example 72 hours) with counsel.
8. Return and deletion
During the subscription, Customers may export many operational datasets through RelilQ export tools. Soft-close of a business retains records by design. Hard deletion of all historical data across backups may not be instantaneous.
- Customers can revoke Face Match reference enrolments in-product.
- Customers can Disconnect recruitment inboxes to delete stored OAuth tokens (and best-effort Google revoke).
9. Information and audits
Upon reasonable written request, RelilQ will provide information available to demonstrate compliance with this DPA, subject to confidentiality and security constraints. RelilQ does not currently offer on-demand onsite audits as a standard self-serve feature.
10. International transfers
Customer acknowledges that RelilQ and its providers may process data outside Nigeria. RelilQ will use appropriate safeguards consistent with the Privacy Policy.
11. Customer obligations
Customer warrants it has a lawful basis to process personal data in RelilQ, will configure access appropriately, and will not instruct RelilQ to process data unlawfully.
12. Sensitive and biometric information
If Customer enables Face Match or stores sensitive documents, Customer is responsible for heightened notices/permissions required by law. RelilQ will process such data only for the enabled verification and records features, with the safeguards described in the Privacy Policy and Biometric Notice.
Related documents
Privacy and rights requests: privacy@relilq.com