Legal
Data Processing Agreement
How Lineserve processes personal data on your behalf as a processor.
Last updated: 13 July 2026
1. Scope and roles
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the Customer and LINESERVE, INC. ("Lineserve") and applies where Lineserve processes personal data on the Customer's behalf in providing the Services. For such data, the Customer is the controller and Lineserve is the processor. Where the Customer is itself a processor, Lineserve acts as a sub-processor.
2. Details of processing
- Subject matter: provision of the Services (cloud, storage, and related infrastructure).
- Duration: for the term of the account and any agreed retention period.
- Nature and purpose: hosting, storage, transmission, and processing as configured by the Customer.
- Types of data: as determined and uploaded by the Customer.
- Data subjects: as determined by the Customer (e.g. the Customer's own users and customers).
3. Processor obligations
Lineserve will: process personal data only on the Customer's documented instructions (including these Terms); ensure personnel are bound by confidentiality; implement appropriate technical and organisational security measures; and not use the data for its own purposes.
4. Sub-processors
The Customer authorises Lineserve to engage sub-processors (e.g. infrastructure, payment, and communications providers) under written terms that impose data-protection obligations equivalent to those in this DPA. Lineserve remains responsible for its sub-processors and will make the current list available on request and give notice of intended changes.
5. Security
Lineserve maintains measures appropriate to the risk, including encryption in transit, access controls, network security, logging, and monitoring, as further described in our Privacy Policy and security practices.
6. Assistance
Taking into account the nature of processing, Lineserve will assist the Customer, by appropriate measures, to respond to data-subject requests and to meet its obligations regarding security, breach notification, and data-protection impact assessments.
7. Personal data breach
Lineserve will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, and provide information reasonably available to support the Customer's own notification obligations. Report suspected incidents to [email protected].
8. International transfers and residency
Lineserve offers in-country data residency in Nairobi, Dar es Salaam, and Lagos for eligible Services. Where personal data is transferred across borders, the parties will rely on an appropriate transfer mechanism as required by applicable law (including Kenya's Data Protection Act and the GDPR where relevant).
9. Audits
Lineserve will make available information reasonably necessary to demonstrate compliance with this DPA and allow for audits, subject to reasonable notice, confidentiality, and frequency limits, and in a manner that does not compromise the security of other customers.
10. Deletion or return
On termination, and at the Customer's choice, Lineserve will delete or return the Customer's personal data after the end of the Services, except where retention is required by law. Residual copies in backups are deleted in the ordinary course.
11. Precedence and contact
In the event of a conflict between this DPA and the Terms of Service on the subject of data protection, this DPA prevails. Requests under this DPA: [email protected].
This page is provided for information and does not constitute legal advice.