1. Who is who
This addendum applies when a business (“you”) uses MYLO, provided by DoubleU AI Africa Limited (RC 9689428) (“we”), to handle personal data about its own customers. You are the data controller of that data; we are your data processor.
It forms part of the MYLO Terms and takes effect when you accept them. Where it differs from the Terms on data protection, this addendum prevails.
2. What we process, and why
Purpose: to provide MYLO — your storefront, QR and chat ordering, order routing, receipts, payments and reporting.
Data subjects: your customers, and the staff you add.
Data: customer names, phone numbers, order contents, table or delivery addresses, uploaded payment receipts, chat messages and reviews; staff names, phone numbers and roles.
Duration: for as long as you use MYLO, and then as set out in section 10.
3. Your instructions
We process your customers’ data only to provide MYLO as you have set it up. How you configure your store, staff and settings is your instruction to us. We will tell you if we believe an instruction breaks data-protection law.
We do not sell your customers’ data, use it for our own marketing, or train AI models on it.
4. Confidentiality
Anyone at DoubleU who can access your data is bound to keep it confidential and accesses it only to run or support the service.
5. Security
Encryption in transit (HTTPS) for all traffic.
Encryption at rest (AES-256-GCM) for payment and integration keys you store with us.
Every record carries your business’s identifier, and every read and write is filtered by it, so one business cannot see another’s data.
Staff logins lock out after repeated wrong attempts.
Error monitoring with screen-session recording switched off.
6. Sub-processors
You authorise us to use the sub-processors listed at mylo.africa/subprocessors. Each is bound by data-protection terms at least as protective as this addendum.
We give you at least 14 days’ notice by email before adding a sub-processor. If you object on reasonable data-protection grounds and we cannot resolve it, you may end your subscription without penalty before the change takes effect.
7. Helping you
We help you answer your customers when they ask to see, correct, delete or move their data. You can export your orders, customers, products and staff from Settings, and we can erase a customer’s personal details on your request.
Where you need to assess a new kind of processing, we give you the information about MYLO that you reasonably need.
8. Breaches
If we become aware of a breach affecting your customers’ data, we tell you within 48 hours, with what we know and what we are doing about it, so that you can meet the Nigeria Data Protection Commission’s 72-hour notice where it applies.
9. International transfers
Our database is in Germany, and some sub-processors process data in the United States, Canada or the United Kingdom, as listed at mylo.africa/subprocessors. Transfers are made because providing MYLO requires them, under each provider’s data-protection terms.
10. When the service ends
You can export your data for 30 days after your account ends. We delete your account data within 90 days, except records the law requires us to keep, such as financial records.
11. Checking our compliance
We answer reasonable written questions about how we protect your data, and provide our documentation. An on-site audit is by agreement, with reasonable notice, at your cost.