Data Processing Agreement

Version 2.3 - Last updated Aug 10, 2026

Product: TestServes
Legal operator: BIG H MULTIDYNAMIC VENTURE
Contact: Contact Us
WhatsApp: 08083019506
Website: https://testserves.com
TestServes is a digital product operated by BIG H MULTIDYNAMIC VENTURE, a Nigerian sole proprietorship registered with the Corporate Affairs Commission under BN 7829006. Its registered principal place of business is No. 1, Awori Street, off First Gate, LASU-Isheri Road, Ojo, Lagos State, Nigeria.

PART F - SCHOOL DATA PROCESSING AGREEMENT

This Data Processing Agreement ("DPA") forms part of the agreement between the subscribing school identified during onboarding ("School" or "Controller") and BIG H MULTIDYNAMIC VENTURE, BN 7829006, operator of TestServes ("TestServes" or "Processor").

1. Scope and roles

The School determines the purposes and essential means of processing school personal data. TestServes processes that data on the School's documented instructions to provide the contracted services. Each party remains independently responsible for processing it controls outside this DPA.

2. Processing details

Subject matter: hosting and operating a school portal, CBT, assessment, results, learning, user management, support and related contracted functions.

Duration: contract term plus the two-month post-deactivation or post-deletion support-access period, backup lifecycle and any legally required retention.

Nature: collection, recording, organisation, storage, retrieval, transmission, scoring, display, restriction, deletion and support access as instructed.

Purposes: providing, securing, supporting and maintaining the subscribed TestServes services.

Data subjects: students, applicants, parents or guardians, staff, contractors and authorised school contacts.

Data categories: identity, contact, account, role, class, attendance, examination, response, score, result, lesson, exercise, support, device and security data; limited sensitive data only where necessary and authorised.

3. School instructions

TestServes will process school personal data only on documented instructions, including those inherent in the agreement and authorised use of features, unless Nigerian law requires otherwise. Where legally permitted, TestServes will inform the School before legally required processing.

TestServes will inform the School if an instruction appears to infringe applicable data-protection law and may pause the affected processing while the parties resolve the issue.

4. School obligations

The School warrants that its instructions are lawful and that it has provided appropriate notices, identified lawful bases, limited collection, maintained accuracy and obtained verifiable parental or guardian consent wherever consent is required. The School will not require unnecessary sensitive data and will assign permissions proportionately.

5. Confidentiality and personnel

TestServes will restrict access to personnel who need it for authorised duties and who are subject to confidentiality obligations and appropriate privacy and security instruction. Privileged access will be reviewed and removed when no longer required.

6. Security

TestServes will maintain measures appropriate to risk, taking into account current technology, implementation cost, processing nature and potential harm. The minimum verified schedule should address:

encryption in transit and secure credential storage;

role-based and least-privilege access;

logical separation of school environments;

secure development, change and vulnerability management;

logging and monitoring of relevant administrative and security events;

backup, restoration and availability controls;

incident detection, escalation and response;

vendor assessment and contractual controls;

data minimisation, retention and secure deletion; and

periodic testing and review.

The parties will document the final technical and organisational measures in Schedule 2 without exposing information that would weaken security.

7. Subprocessors

The School gives general authorisation for TestServes to use subprocessors listed in the current register. TestServes will give reasonable advance notice of a new subprocessor that will materially process school personal data, allowing the School to object on reasonable data-protection grounds.

TestServes will impose written data-protection obligations providing materially equivalent protection and remains responsible for subprocessor performance to the extent required by law. If a reasonable objection cannot be resolved, the parties will seek an alternative or permit termination of the affected service without penalty for the unused prepaid portion.

8. Google Gemini and processing outside Nigeria

TestServes operates from Nigeria and uses the Google Gemini API for optional AI-assisted content generation. Google may process API information on systems outside Nigeria. Schools must not place student names, account information, answers, results or unnecessary sensitive information into the AI feature. TestServes will minimise information transmitted and use a lawful transfer basis and appropriate safeguards where personal data is involved.

9. Data-subject requests

TestServes will promptly notify the School of a request concerning school-controlled data unless prohibited. Taking account of the nature of processing, TestServes will provide reasonable technical and organisational assistance with access, correction, deletion, objection, restriction, portability and automated-decision rights. TestServes will not independently alter school academic records unless authorised or legally required.

10. Breaches

TestServes will notify the School without undue delay after confirming a personal-data breach affecting school personal data. Available notice will describe the nature, affected categories and approximate numbers, likely consequences, mitigation, contact point and information needed for the School's assessment and notification duties. Initial notice may be supplemented as investigation continues.

The School is responsible for regulator and individual notification as controller, except where TestServes has a separate legal duty. TestServes will provide reasonable assistance and preserve relevant records.

11. DPIAs, consultation and compliance

TestServes will provide information reasonably necessary for the School's data-protection impact assessment, prior consultation, compliance enquiry and demonstration of processor compliance, considering confidentiality, security and proportionality.

12. Audit and evidence

On reasonable written request, TestServes will provide relevant policies, summaries, certifications or questionnaires sufficient to demonstrate compliance. If those are insufficient after a substantiated concern, the School may conduct or commission a proportionate audit no more than once annually, unless a breach or regulator requires more. Audits must protect other customers, security and confidentiality and avoid unreasonable disruption. Allocation of exceptional audit cost should be agreed fairly.

13. Return and deletion

TestServes does not currently offer self-service export. A deactivated or deleted School may contact support during the two-month retention period to request access to or recovery of its data. TestServes will verify the requester and provide reasonable assistance where technically possible. After two months, school personal data will normally be deleted or irreversibly de-identified unless law, an active dispute or a documented legal hold requires retention. Backup copies will expire through the same two-month lifecycle and will not be restored for ordinary use after deletion.

14. Records and regulator cooperation

Each party will maintain records required for its role. TestServes will cooperate reasonably with the NDPC and notify the School of a regulator request specifically concerning school data unless prohibited.

15. Liability and term

Liability under this DPA is subject to the agreement except where applicable law requires otherwise. This DPA begins with the service agreement and survives until school personal data has been returned or deleted.

Schedule 1 - Processing particulars

The processing particulars are determined by the modules enabled for the School, including school portal administration, user management, CBT, tests, lesson notes, exercises, attendance, results, support and payment workflows where applicable.

Schedule 2 - Technical and organisational measures

TestServes applies technical and organisational measures appropriate to the service, including identity and access management, encryption in transit, secure credential storage, school-level logical separation, logging of relevant events, secure development practices, backup and restoration controls, incident response, retention and deletion controls, vendor management and confidentiality expectations for authorised personnel.

Electronic acceptance

This DPA is accepted electronically when the School's authorised account user accepts the TestServes Terms of Service and Data Processing Agreement during registration, onboarding or plan activation. TestServes will retain the applicable policy version, accepting account and acceptance timestamp. No handwritten signature page is required within the app.

WA