Data Processing Addendum
When you use Otjetu HR, you put personal information about your employees into our system. In data-protection language, you are the controller — it is your data and your decisions — and we are the processor, acting on your instructions. This document sets out what we will and will not do with it, so you can satisfy yourself, your auditors and your staff.
It applies automatically to every customer. You do not need to sign anything. If your organisation requires a countersigned copy, email [email protected].
1. Parties and roles
This Addendum is between the Customer (the employer using Otjetu HR) and Octovia Nexus, registration number [registration number] (“Otjetu”).
| Role | Who | Meaning |
|---|---|---|
| Controller | The Customer | Decides what personal information is collected about its staff, why, and who may see it. |
| Processor | Otjetu | Stores and processes that information solely to provide the service, on the Customer's instructions. |
Otjetu acts as a controller only in respect of its own account and billing records — the account holder's contact details, invoices and the like. Those are covered by the Privacy Policy, not this Addendum.
2. Scope of processing
The subject matter, duration, nature, purpose, data categories and data subjects are set out in Annex A.
3. Our obligations
Otjetu will:
- Process employee personal information only on the Customer's documented instructions. Using the service is itself an instruction to process as needed to deliver it.
- Not sell that information, and not use it for advertising, profiling or training machine-learning models.
- Not use it for our own purposes, including product analytics. Where we measure how the product is used, we use operational and account-level data, not employee records.
- Apply the security measures in Annex B.
- Impose equivalent obligations on any sub-processor.
- Tell the Customer promptly if we consider an instruction would breach applicable law.
4. Your obligations
The Customer:
- Confirms it has a lawful basis to collect and hold the employee information it enters, and to have Otjetu process it.
- Is responsible for telling its employees how their information is used, as their employment contracts and Namibian law require.
- Is responsible for the accuracy of what it enters and for keeping access rights current — including removing access when a staff member leaves.
- Must not enter special-category information the service is not designed to hold. The fields for racial designation and disability status exist to support statutory reporting under the Affirmative Action (Employment) Act 29 of 1998 and should be used for that purpose.
5. Confidentiality and staff
Otjetu ensures that personnel authorised to process Customer data are bound by confidentiality obligations, and that access is limited to those who need it to operate or support the service. Access to production systems is restricted and logged.
6. Security measures
Otjetu implements appropriate technical and organisational measures, described in Annex B. We may update them as threats and technology change, provided protection is not materially reduced.
7. Sub-processors
The Customer authorises Otjetu to engage the sub-processors listed below. Each is bound to protect the data to a standard no less than this Addendum requires.
| Category | Function | Data accessed |
|---|---|---|
| Cloud hosting | Server and database hosting | All Customer data, at rest |
| Network & security | DNS, TLS termination, protection against attack and abusive traffic | Traffic in transit; connection metadata |
| Transactional email | Delivery of payslip notices, invites, invoices, password resets | Recipient name and email address; message content |
| Accounting integration (only if enabled by the Customer) | Xero integration | Payroll journal totals only — not individual employee records |
The current list of named sub-processors, including the entity and the jurisdiction in which each operates, is available on request — email [email protected]. Customers with procurement, audit or vendor-assessment requirements should ask for it, and we will provide it in writing.
We will give the Customer at least 30 days' notice before adding or replacing a sub-processor. If the Customer reasonably objects on data-protection grounds, it may raise this with us; if we cannot resolve it, the Customer may terminate the affected service without penalty and receive a pro-rata refund of any prepaid amount.
8. International transfer
Otjetu HR runs on managed cloud infrastructure provided by established commercial providers. As is the case with substantially all cloud software, that infrastructure and the networks carrying Customer traffic may be located outside Namibia.
Namibia does not presently restrict cross-border transfer of personal information by statute, as no comprehensive data protection law is in force. Otjetu nonetheless selects providers operating under recognised data-protection regimes and binds each of them contractually to protect Customer data and to process it only on our instructions.
If the Customer is subject to a requirement that data remain within Namibia or another specified jurisdiction, please raise this with us at [email protected] before signing up, so we can confirm in writing whether we can meet it.
9. Breach notification
If Otjetu becomes aware of a personal data breach affecting Customer data, we will:
- Notify the Customer without undue delay, and in any event within 72 hours of becoming aware of it.
- Describe the nature of the breach, the categories and approximate volume of records involved, the likely consequences, and the measures taken or proposed.
- Assist the Customer in meeting any notification duty it owes to employees or an authority.
Notifying the Customer is not an admission of fault by Otjetu.
10. Assisting you with employee requests
Employees will sometimes ask to see, correct or delete their record. Because the Customer controls that record, such requests should be directed to the Customer.
If an employee contacts Otjetu directly, we will not action the request ourselves. We will tell them to approach their employer and, where we can identify the employer, let the Customer know. Otjetu will provide reasonable assistance — including access to export tools — to help the Customer respond.
11. Audit and information
On reasonable written request, and no more than once a year unless required by an authority or following a breach, Otjetu will provide the information reasonably necessary to demonstrate compliance with this Addendum.
Otjetu does not currently hold a third-party certification such as ISO 27001 or SOC 2. Where an on-site or technical audit is required, the parties will agree scope and timing in advance so as not to compromise the security or confidentiality of other customers' data. The Customer bears the cost of any audit it requests.
12. Return and deletion
- The Customer may export its data at any time while the account is active.
- On termination, the Customer may request deletion of its workspace. Deletion removes the business and its employee records permanently and irreversibly.
- Where no deletion request is made, we retain the data for a reasonable period to allow export, then delete it.
- Backups may retain copies briefly after deletion until overwritten in the normal cycle.
- Otjetu may retain invoices and payment records as tax and company law requires. These contain no employee records.
13. Liability
Liability under this Addendum is subject to the limitations in clause 15 of the Terms of Service.
14. Governing law
This Addendum is governed by the laws of the Republic of Namibia, and the courts of Namibia have exclusive jurisdiction. If it conflicts with the Terms of Service in respect of the processing of employee personal information, this Addendum prevails.
Annex A — Details of processing
| Subject matter | Provision of HR and payroll software to the Customer. |
|---|---|
| Duration | For as long as the Customer's account is active, plus any retention period in clause 12. |
| Nature and purpose | Storage, organisation, retrieval, calculation and transmission of employee records for HR administration, payroll processing, leave and time management, statutory reporting and document generation. |
| Categories of data subject | The Customer's employees and former employees; job applicants where recruitment is used; the Customer's own users of the system. |
| Categories of personal data |
Identity and contact details (name, date of birth, gender, nationality, national ID or passport number, address, phone, email, photo). Employment details (job title, department, location, manager, dates, status and status history). Financial details (salary or rate, allowances, deductions, overtime, expenses, loans, bonuses, payslips, bank account details). Tax and statutory identifiers (tax reference, Social Security number, work permit details). Leave, attendance and timesheet records. Documents uploaded by the Customer to an employee's file. Performance goals and reviews, where used. |
| Special categories | Racial designation and disability status, collected to support statutory workforce reporting under the Affirmative Action (Employment) Act 29 of 1998. Both are optional fields. |
| Frequency | Continuous for the duration of the agreement. |
Annex B — Security measures
| Measure | Implementation |
|---|---|
| Tenant isolation | Each Customer's records are separated at the database level by row-level security, enforced by the database itself rather than only by application code. A query running for one Customer cannot return another Customer's rows. |
| Encryption in transit | HTTPS/TLS on all connections. HTTP Strict Transport Security instructs browsers to refuse insecure connections. |
| Authentication | Passwords stored as one-way hashes and never recoverable in plain text. Optional two-factor authentication. Session cookies are HTTP-only and secure. |
| Request protection | Cross-site request forgery protection on all state-changing requests. Rate limiting on sign-in and registration to curb automated abuse. |
| Access control | Role-based permissions configurable by the Customer, so payroll and personal data can be restricted to specific staff. |
| Auditability | Changes to records are written to an immutable audit log recording who changed what and when, visible to the Customer. |
| Internal access | Production access limited to personnel who require it to operate or support the service. |
| Backups | Regular database backups, held in the same hosting environment. |
| Security headers | Protections against clickjacking, content-type sniffing and referrer leakage are set on all responses. |