1. Parties
1.1 The Controller
BOREDOM TECHNOLOGIES NIGERIA LIMITED, a company incorporated in the Federal Republic of Nigeria under registration number RC 9476822, whose registered office is at 22a Ogbunike Street, Lekki Phase 1, Lagos, Nigeria ("Boredom", "we", "us", "our").
1.2 The Processor
The vendor business that has registered for and holds a Boredom vendor account ("Vendor", "you", "your").
The Vendor's identity, registered details, trading address and authorised representative are those recorded in the Vendor's Boredom vendor account at the time of acceptance. Those recorded details form part of this Agreement as though set out here in full, and the Vendor warrants under clause 5.2 that they are accurate.
1.3 Data Protection Officer
Boredom has appointed a Data Protection Officer in accordance with the NDPA:
Data Protection Officer Usman Jaji Boredom Technologies Nigeria Limited 22a Ogbunike Street, Lekki Phase 1, Lagos, Nigeria Email:
hello@boredomhq.com
Boredom is registered with the Nigeria Data Protection Commission as a data controller.
1.4 Group structure
Boredom Technologies Nigeria Limited is a subsidiary of Boredom Ltd, a company incorporated in England and Wales under company number 16548048, which acts as a holding company.
Boredom Technologies Nigeria Limited is the sole Controller of the Platform Personal Data disclosed to Vendors under this Agreement, and is the Vendor's sole counterparty. Boredom Ltd is not a party to this Agreement and the Vendor has no contractual claim against it under this Agreement. Where Platform Personal Data is made available to Boredom Ltd for group administration purposes, that disclosure is governed by an intra-group arrangement between the two companies and does not affect the Vendor's obligations here.
1.5 Agreed
This Agreement is made between the parties identified in clauses 1.1 and 1.2 and takes effect in accordance with clause 20.
2. Background
2.1 Boredom operates a platform connecting individuals with venues, activities and meetup events (the "Platform").
2.2 The Vendor is a business that lists on the Platform and receives bookings and orders through it.
2.3 To fulfil those bookings and orders, Boredom discloses personal data relating to Platform users to the Vendor. In doing so Boredom acts as Controller and the Vendor acts as Processor.
2.4 The Data Protection Laws require a written contract governing that processing. This Agreement is that contract.
3. Definitions and interpretation
3.1 Definitions
| Term | Meaning |
|---|---|
| Data Protection Laws | The NDPA, the NDPR, and any subsidiary legislation, regulation, directive, guidance note or code of practice issued by the NDPC, each as amended or replaced from time to time; and, where and to the extent it applies to a party, the UK GDPR |
| NDPA | The Nigeria Data Protection Act 2023 |
| NDPC | The Nigeria Data Protection Commission, and any successor authority |
| NDPR | The Nigeria Data Protection Regulation 2019 |
| UK GDPR | The retained EU General Data Protection Regulation as it forms part of the law of England and Wales, Scotland and Northern Ireland, together with the Data Protection Act 2018 |
| Controller, Processor, Data Subject, Personal Data, Processing, Sensitive Personal Data | As defined in the NDPA, and to be construed accordingly |
| Platform Personal Data | Personal Data relating to Platform users and their guests that Boredom makes available to the Vendor through the vendor dashboard, the Platform's application programming interfaces, notifications or email. Schedule 1 describes it |
| Vendor Own Data | Personal Data the Vendor collects independently of the Platform, including from walk-in customers and the Vendor's own loyalty or marketing programmes |
| Vendor Personnel | The Vendor's directors, officers, employees, agents, contractors and any individual holding a team sub-account under the Vendor's business on the Platform |
| Sub-Processor | Any third party engaged by the Vendor to process Platform Personal Data |
| Personal Data Breach | A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Platform Personal Data |
| Services | The services the Vendor provides to Platform users, being the fulfilment of bookings, orders and meetups at the Vendor's venue |
| Working Day | A day other than a Saturday, Sunday or public holiday in the Federal Republic of Nigeria |
3.2 Interpretation
(a) Clause and Schedule headings do not affect interpretation. (b) A reference to legislation is to that legislation as amended, extended or re-enacted from time to time. (c) "Including", "in particular" and similar expressions are illustrative and do not limit what precedes them. (d) The Schedules form part of this Agreement and have equal force. (e) Where a period is expressed in hours, it runs continuously and is not limited to Working Days. (f) The singular includes the plural and vice versa.
4. Status of the parties
4.1 In respect of Platform Personal Data, Boredom is the Controller and the Vendor is a Processor acting only on Boredom's documented instructions.
4.2 In respect of Vendor Own Data, the Vendor is an independent Controller. This Agreement does not apply to that data and Boredom has no responsibility for it.
4.3 The parties are not joint controllers. Neither party may hold itself out as having authority to bind the other in relation to any Data Subject.
4.4 If the Vendor at any time determines the purposes or means of processing Platform Personal Data, it becomes an independent Controller in respect of that processing, in breach of clause 5.2, and assumes all Controller obligations and liability for it. Nothing in this clause is to be read as permitting such processing.
5. The Vendor's obligations as Processor
The Vendor shall comply with the Data Protection Laws and with this clause 5.
5.1 Processing only on documented instructions
The Vendor shall process Platform Personal Data only on Boredom's documented instructions, including in relation to transfers outside Nigeria, unless required to do otherwise by law to which the Vendor is subject. Where a legal requirement compels other processing, the Vendor shall notify Boredom before processing unless that law prohibits notification on important grounds of public interest.
This Agreement, together with the Vendor's use of the Platform in accordance with its documentation, constitutes Boredom's complete documented instructions at the date of acceptance.
5.2 Purpose limitation
The Vendor shall process Platform Personal Data solely for the purposes set out in Schedule 1, and for no other purpose. In particular, and without limitation, the Vendor shall not:
(a) add any name, email address, telephone number or other contact detail obtained through the Platform to any marketing list, customer relationship management system, mailing list, loyalty scheme or database of the Vendor or of any third party;
(b) contact a Platform user otherwise than through the Platform's messaging function, except where strictly necessary to fulfil a specific booking or order that user has placed;
(c) sell, rent, license, publish, disclose or otherwise make available Platform Personal Data to any third party, except to a Sub-Processor engaged in compliance with clause 8;
(d) use Platform Personal Data to profile, score, segment, target or evaluate any Data Subject;
(e) combine Platform Personal Data with Vendor Own Data or with data from any other source, save to the minimum extent necessary to fulfil a specific booking or order;
(f) retain Platform Personal Data after the purpose for which it was disclosed has been fulfilled, except as clause 14 permits; or
(g) use Platform Personal Data to train, develop, test or improve any model, algorithm or system.
A Vendor wishing to market to a Platform user must obtain that user's consent directly and independently, record it, and be able to evidence it. Consent given to Boredom does not transfer to the Vendor and confers no marketing right on the Vendor.
5.3 Confidentiality
The Vendor shall ensure that every individual authorised to process Platform Personal Data:
(a) is subject to a binding duty of confidentiality, whether contractual or statutory, that survives the end of their engagement; (b) has been informed of the restrictions in clause 5.2 and of the sensitivity of the data before being granted access; and (c) processes Platform Personal Data only as necessary to perform their role.
5.4 Security
The Vendor shall implement and maintain the technical and organisational measures in Schedule 2, Part B, and such further measures as are appropriate to the risk, having regard to the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing.
5.5 Vendor Personnel and team sub-accounts
This clause is a material term of this Agreement.
The Platform permits the Vendor to create team sub-accounts, extending access to Platform Personal Data beyond the individual who registered the business. Accordingly the Vendor shall:
(a) grant access only to Vendor Personnel with a genuine operational need, and assign in each case the least-privileged role sufficient for that need;
(b) ensure, before issuing an invitation, that the individual is bound by confidentiality obligations meeting clause 5.3 and has been briefed on Schedule 2, Part B;
(c) remain fully liable to Boredom for every act and omission of every person holding a sub-account under the Vendor's business, as if they were the acts and omissions of the Vendor itself;
(d) revoke a sub-account within twenty-four (24) hours of the holder ceasing to require access, including immediately upon termination of their employment or engagement, or upon any change of role that removes the need;
(e) not permit any sharing of login credentials; each individual must hold their own sub-account;
(f) review the list of active sub-accounts at least once every six (6) months and revoke any that are no longer required, maintaining a record of each review; and
(g) satisfy itself, before assigning any role, which categories of Platform Personal Data that role exposes. Schedule 4 sets out the role permission matrix. The Vendor's attention is drawn in particular to the fact that the Read-only role grants visibility of customer bookings and is therefore not privacy-neutral.
5.6 Assistance with Data Subject rights
(a) The Vendor shall not respond directly to any request from a Data Subject concerning Platform Personal Data.
(b) The Vendor shall forward any such request to hello@boredomhq.com within three (3) Working Days of receipt, together with all information reasonably necessary to identify and respond to it.
(c) The Vendor shall provide such further assistance as Boredom reasonably requires, by appropriate technical and organisational measures and insofar as possible, to enable Boredom to respond within the time limits imposed by the Data Protection Laws.
5.7 Assistance with compliance
Taking into account the nature of processing and the information available to it, the Vendor shall assist Boredom in ensuring compliance with its obligations as to security, breach notification, data protection impact assessments, and prior consultation with the NDPC.
5.8 Records
The Vendor shall maintain a written record of all categories of processing carried out on Boredom's behalf, and shall make that record available to Boredom or to the NDPC promptly on request.
5.9 Notification of unlawful instructions
The Vendor shall inform Boredom immediately if, in its opinion, an instruction from Boredom infringes the Data Protection Laws. The Vendor may suspend performance of the affected instruction, but not of this Agreement generally, pending Boredom's response.
5.10 Sensitive Personal Data
Boredom does not intentionally disclose Sensitive Personal Data to the Vendor. Where a Data Subject volunteers such data in free-text (for example in a message or a meetup description), the Vendor shall treat it as strictly confidential, shall not record, extract, index or act upon it, and shall not disclose it to any person.
6. Boredom's obligations as Controller
Boredom shall:
6.1 ensure it has and maintains a lawful basis under the NDPA for disclosing Platform Personal Data to the Vendor, and that its published Privacy Policy fairly and accurately describes that disclosure;
6.2 issue only lawful and documented processing instructions;
6.3 apply the principle of data minimisation, disclosing to the Vendor only such Platform Personal Data as is necessary for the purposes in Schedule 1, and operate permission-scoped access so that Vendor Personnel see only what their assigned role requires;
6.4 act as first point of contact for Data Subject rights requests and respond within the period stated in its Privacy Policy;
6.5 maintain the technical and organisational measures in Schedule 2, Part A;
6.6 notify the Vendor of any material change to the Platform's processing that affects the Vendor's obligations; and
6.7 maintain its registration with the NDPC and the appointment of its Data Protection Officer for so long as required by the NDPA.
7. Personal Data Breach
7.1 Notification by the Vendor
The Vendor shall notify Boredom of any Personal Data Breach affecting Platform Personal Data without undue delay and in any event within twenty-four (24) hours of becoming aware of it, by email to hello@boredomhq.com with the subject line DATA BREACH — [Vendor business name].
The twenty-four hour period is deliberately shorter than the statutory notification period. Boredom as Controller must assess the breach and, where required, notify the NDPC within seventy-two (72) hours of its own awareness; it requires time to do so.
7.2 Contents
So far as known at the time, the notification shall describe:
(a) the nature of the breach, including the categories and approximate number of Data Subjects and of records concerned; (b) the name and contact details of a point of contact at the Vendor; (c) the likely consequences of the breach; and (d) the measures taken or proposed to address it, including to mitigate its adverse effects.
Where and to the extent information is not available at once, it may be provided in phases without further undue delay.
7.3 Containment and cooperation
The Vendor shall immediately take all reasonable steps to contain and remediate the breach, shall preserve all evidence relating to it, and shall cooperate fully and promptly with Boredom's investigation.
7.4 No unilateral communication
The Vendor shall not notify any Data Subject, supervisory authority, media outlet or other third party of a Personal Data Breach affecting Platform Personal Data, nor make any public statement about it, without Boredom's prior written agreement, unless and to the extent legally compelled — in which case it shall give Boredom as much prior notice as the law permits.
7.5 Boredom's obligations
Boredom shall assess each breach notified to it and, where required, notify the NDPC within seventy-two (72) hours of becoming aware, and shall notify affected Data Subjects where the breach is likely to result in a high risk to their rights and freedoms.
8. Sub-Processors
8.1 Boredom grants the Vendor a general authorisation to engage Sub-Processors, subject to this clause 8.
8.2 Before engaging any Sub-Processor the Vendor shall:
(a) carry out reasonable due diligence as to its ability to meet the obligations in this Agreement; (b) impose on it, by written contract, data protection obligations no less protective than those imposed on the Vendor by this Agreement, including as to security, confidentiality, breach notification and audit; and (c) satisfy itself that any transfer of Platform Personal Data to that Sub-Processor complies with clause 12.
8.3 The Vendor shall give Boredom not less than thirty (30) days' written notice before appointing or replacing any Sub-Processor that will process Platform Personal Data. Boredom may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection in good faith, Boredom may suspend the affected processing or terminate this Agreement and the Vendor Agreement, in each case without liability.
8.4 The Vendor remains fully liable to Boredom for the acts and omissions of each Sub-Processor as if they were its own.
8.5 Boredom's own Sub-Processors are listed in Schedule 3. Boredom will update that Schedule and notify Vendors of material changes.
9. Audit
9.1 The Vendor shall make available to Boredom all information reasonably necessary to demonstrate compliance with this Agreement.
9.2 Boredom, or an independent auditor appointed by it who is not a competitor of the Vendor and who is bound by obligations of confidentiality, may inspect and audit the Vendor's processing of Platform Personal Data on fourteen (14) days' written notice, no more than once in any twelve (12) month period, during normal business hours, and in a manner that does not unreasonably disrupt the Vendor's business.
9.3 The frequency limit in clause 9.2 does not apply where:
(a) Boredom has reasonable grounds to suspect a breach of this Agreement; (b) a Personal Data Breach has occurred; or (c) the NDPC or another competent authority requires an audit.
9.4 Each party bears its own costs of an audit, save that where an audit reveals a material breach by the Vendor, the Vendor shall reimburse Boredom's reasonable costs.
10. Suspension
Boredom may suspend the Vendor's access to Platform Personal Data, in whole or in part and with immediate effect, where it reasonably believes the Vendor is in breach of this Agreement — in particular clause 5.2 or clause 5.5. Suspension may include disabling some or all team sub-accounts. Boredom shall notify the Vendor of the suspension and its grounds, and shall lift it promptly once the breach is remedied to Boredom's reasonable satisfaction. Suspension under this clause is without prejudice to Boredom's other rights.
11. Warranties
11.1 The Vendor warrants and undertakes that:
(a) it will comply at all times with the Data Protection Laws in respect of Platform Personal Data; (b) the details recorded in its Boredom vendor account, including its registered details and the identity of its authorised representative, are true, accurate and complete, and it will keep them so; (c) the individual accepting this Agreement is duly authorised to bind the Vendor; (d) it holds all licences, permits and registrations required to operate its business and to provide the Services; and (e) it has implemented and will maintain the measures in Schedule 2, Part B.
11.2 Boredom warrants that it has a lawful basis under the NDPA for the disclosures it makes to the Vendor under this Agreement.
12. Cross-border transfers
12.1 The Vendor shall not transfer Platform Personal Data outside the Federal Republic of Nigeria, nor permit any Sub-Processor to do so, without Boredom's prior written consent and a lawful transfer mechanism under section 43 of the NDPA.
12.2 Where such a transfer is authorised, the Vendor shall ensure that it is made only:
(a) to a jurisdiction the NDPC has determined provides an adequate level of protection; or (b) subject to an instrument, contractual clause, binding corporate rule, code of conduct or certification mechanism recognised by the NDPC as providing appropriate safeguards; or (c) on another basis expressly permitted by the NDPA,
and shall in each case carry out and document a transfer risk assessment.
12.3 Boredom's own transfers. The Vendor acknowledges that Boredom transfers Platform Personal Data outside Nigeria in the course of operating the Platform, principally to Google LLC in the United States for cloud infrastructure (Schedule 3). Boredom makes those transfers on the basis set out in its Privacy Policy and remains responsible for them. Nothing in this clause makes the Vendor responsible for Boredom's own transfers.
12.4 Where Platform Personal Data relates to a Data Subject in the United Kingdom, the parties shall additionally comply with the transfer provisions of the UK GDPR.
13. Liability and indemnity
13.1 The Vendor shall indemnify Boredom against all losses, liabilities, damages, fines, penalties, claims, demands, and reasonable costs and expenses (including reasonable legal fees) arising out of or in connection with:
(a) any breach by the Vendor of this Agreement; (b) any breach by the Vendor of the Data Protection Laws in respect of Platform Personal Data; or (c) any act or omission of Vendor Personnel or of any Sub-Processor which, if done by the Vendor, would be such a breach.
13.2 The indemnity in clause 13.1 is not subject to any limitation or exclusion of liability in the Vendor Agreement or elsewhere, and applies in addition to any other remedy available to Boredom.
13.3 Nothing in this Agreement limits or excludes either party's liability for fraud or fraudulent misrepresentation, for death or personal injury caused by negligence, or for any liability that cannot lawfully be limited or excluded.
13.4 Nothing in this Agreement limits the rights of any Data Subject, or the powers of the NDPC.
14. Return and deletion
14.1 On termination or expiry of this Agreement, or at any time on Boredom's written request, the Vendor shall at Boredom's election either return to Boredom or securely and permanently delete all Platform Personal Data and all existing copies of it, and shall do so within thirty (30) days.
14.2 The Vendor may retain Platform Personal Data only to the extent, and for so long as, required by a law to which it is subject — for example, tax or accounting record-keeping requirements. Data so retained remains subject to clauses 5.2, 5.3, 5.4 and 12, and must be deleted as soon as the retention requirement ends.
14.3 The Vendor shall certify compliance with this clause 14 in writing within fourteen (14) days of Boredom's request, identifying any data retained under clause 14.2 and the legal basis for retaining it.
15. Term and termination
15.1 This Agreement takes effect on acceptance under clause 20 and continues for so long as the Vendor holds a Boredom vendor account or retains any Platform Personal Data, whichever ends later.
15.2 This Agreement terminates automatically on termination of the Vendor Agreement, save that clauses 5.2, 5.3, 7, 9, 13, 14, 16, 18 and 19 survive termination.
15.3 Termination does not affect any right or liability accrued before it.
16. Notices
16.1 Notices to Boredom shall be sent to hello@boredomhq.com, marked for the attention of the Data Protection Officer, and copied to the registered office in clause 1.1.
16.2 Notices to the Vendor shall be sent to the email address recorded in the Vendor's Boredom vendor account, or given through the vendor dashboard.
16.3 A notice sent by email is deemed given at the time of transmission, or if transmitted after 17:00 on a Working Day or on a day that is not a Working Day, at 09:00 on the next Working Day.
16.4 Clause 7.1 notifications may be given by email alone and take effect on transmission at any hour.
17. Order of precedence
Where there is any conflict or inconsistency, the following order of precedence applies, the earlier prevailing over the later:
- this Agreement;
- the Vendor Agreement;
- the Payment Terms;
- the Terms & Conditions and the Privacy Policy.
18. Variation
18.1 Boredom may vary this Agreement on thirty (30) days' written notice where required by a change in the Data Protection Laws, by NDPC guidance, or by a material change to the Platform.
18.2 Where a variation materially increases the Vendor's obligations or reduces its rights, the Vendor may terminate the Vendor Agreement without penalty by written notice given before the variation takes effect.
18.3 Continued use of the vendor dashboard after the effective date of a variation constitutes acceptance of it. Boredom records each Vendor's acceptance by version (clause 20.3).
18.4 No other variation is effective unless in writing and signed by or on behalf of both parties.
19. General
19.1 Entire agreement. This Agreement, together with the documents in clause 17, constitutes the entire agreement between the parties as to its subject matter and supersedes all prior arrangements relating to it.
19.2 Severability. If any provision is held invalid, illegal or unenforceable, it shall be severed and the remainder shall continue in full force. The parties shall negotiate in good faith a replacement provision achieving, so far as lawful, the intended commercial result.
19.3 Waiver. No failure or delay in exercising a right is a waiver of it, and no single or partial exercise prevents further exercise.
19.4 Assignment. The Vendor may not assign, transfer, charge or deal in any manner with this Agreement or any of its rights or obligations without Boredom's prior written consent. Boredom may assign or novate this Agreement to any member of its group or to a successor in title to its business on written notice.
19.5 No partnership. Nothing in this Agreement creates a partnership, joint venture, agency or employment relationship between the parties.
19.6 Third parties. A person who is not a party to this Agreement has no right to enforce any of its terms, save that nothing in this clause affects the rights of a Data Subject under the Data Protection Laws.
19.7 Counterparts. Where this Agreement is executed by signature, it may be executed in any number of counterparts, each of which is an original and all of which together constitute one agreement.
20. Acceptance and execution
20.1 Acceptance through the Platform
The Vendor accepts this Agreement, and it becomes binding on both parties, when an individual authorised to bind the Vendor confirms acceptance through the Boredom vendor registration process or the vendor dashboard.
The parties agree that such acceptance:
(a) constitutes execution of this Agreement by the Vendor; (b) has the same legal effect as a manuscript signature; and (c) is intended by both parties to create legally binding relations.
20.2 Authority
The individual accepting warrants that they are duly authorised to bind the Vendor. Boredom is entitled to rely on that warranty without further enquiry.
20.3 Record of acceptance
Boredom records, against the Vendor's account, the version of this Agreement accepted, the date and time of acceptance, and the identity of the accepting account. That record is admissible as evidence of acceptance and, in the absence of manifest error, is conclusive as to which version the Vendor accepted.
20.4 Execution by signature
A Vendor may instead request a countersigned copy. Where this Agreement is executed by signature, the following applies.
EXECUTED as an agreement.
| For and on behalf of BOREDOM TECHNOLOGIES NIGERIA LIMITED (RC 9476822) | |
|---|---|
| Signature | ............................................................ |
| Name | ............................................................ |
| Position | ............................................................ |
| Date | ............................................................ |
| For and on behalf of the VENDOR | |
|---|---|
| Business name | ............................................................ |
| Registration number | ............................................................ |
| Signature | ............................................................ |
| Name | ............................................................ |
| Position | ............................................................ |
| Date | ............................................................ |
21. Governing law and jurisdiction
21.1 This Agreement and any dispute or claim arising out of or in connection with it or its subject matter (including non-contractual disputes or claims) are governed by and construed in accordance with the laws of the Federal Republic of Nigeria.
21.2 The parties irrevocably submit to the exclusive jurisdiction of the courts of the Federal Republic of Nigeria.
21.3 Before commencing proceedings, a party shall give the other written notice of the dispute and the parties shall attempt in good faith to resolve it within thirty (30) days. This clause does not prevent either party from seeking urgent interim relief.
21.4 Nothing in this clause limits the right of a Data Subject to bring proceedings, or to complain to the NDPC or to another competent supervisory authority, in their own jurisdiction.
---
Schedule 1 — Details of the processing
Required by the NDPA. Derived from the Platform as built; code references are given so this Schedule can be re-verified when the Platform changes.
1. Subject matter
The processing by the Vendor of Platform Personal Data disclosed through the Boredom vendor dashboard for the purpose of fulfilling bookings, orders and meetups placed through the Platform.
2. Duration
For the term of this Agreement, as determined by clause 15.
3. Nature and purpose
The Vendor may process Platform Personal Data only for the following purposes:
| # | Purpose |
|---|---|
| 1 | Order fulfilment — preparing and serving orders placed through the Platform, including split-bill and pay-at-venue orders |
| 2 | Booking and meetup management — confirming, preparing for and hosting meetups at the Vendor's venue, including admission of named attendees and guest counts |
| 3 | Customer support — responding to messages sent by Platform users through the Platform's messaging function |
| 4 | Review responses — publicly replying to reviews concerning the Vendor |
| 5 | Safety incident response — receiving and acting on safety or panic incidents raised at the Vendor's venue |
| 6 | Cancellations and refunds — processing cancellations in accordance with the Platform's refund policy |
Any other processing requires Boredom's prior written instruction.
4. Categories of Data Subject
| Category | Description |
|---|---|
| Platform users | Individuals who book meetups, place orders or attend events at the Vendor's venue |
| Meetup hosts | Users who create a meetup at the Vendor's venue |
| Guests | Additional attendees included in a booking's guest count |
5. Categories of Platform Personal Data
| Category | Data | Source |
|---|---|---|
| Identity | Name, profile photograph, occupation | Attendee — web/src/features/booking/types/types.ts |
| Contact | Email address, telephone number | Attendee, OrderContact — same file |
| Transaction | Order number, date, items, quantities, prices, total, guest count, payment method (payFull / splitBill / payAtVenue), refund status |
Order — same file |
| Meetup | Title, description, location, date and time, attendee list, private/public flag | Meetup — same file |
| Communications | Content of messages between the user and the Vendor | web/src/features/message/ |
| Reviews | Review text, rating, reviewer identity | web/src/features/reviews/ |
| Safety | Safety and panic incident reports raised at the Vendor's venue | safety.view permission |
6. Sensitive Personal Data
Not intentionally disclosed. Clause 5.10 governs any that is volunteered by a Data Subject in free text.
7. Payment data
Vendors receive no card or full payment instrument data. Payments are processed by a payment service provider licensed by the Central Bank of Nigeria. Vendors see transaction amounts and payment method only.
8. Frequency
Continuous, through the vendor dashboard, for the term of this Agreement.
Schedule 2 — Technical and organisational measures
Part A — Boredom's measures (Controller)
| Measure | Implementation |
|---|---|
| Access control | Firestore security rules; role-based access control over a defined permission catalogue, enforced in the client interface, server routes, cloud functions and automated rules tests |
| Least privilege | Money- and identity-sensitive permissions (payout details, verification documents) excluded from all default operational roles |
| Data segregation | Contact and payout personal data held in owner-restricted sub-collections rather than in generally readable records |
| Encryption | TLS in transit; encryption at rest by the infrastructure provider |
| Authentication | Managed identity provider; application attestation on client requests |
| Resilience | Point-in-time recovery (7 days), daily backups (7 days), and deletion protection enabled on the production database |
| Disaster recovery | Weekly off-site export to a separate recovery project |
| Audit logging | Administrative actions written to an append-only audit log |
| Incident response | Documented procedure including regulatory notification within 72 hours |
| Team limits | Maximum of five active members per vendor business |
| Invitation security | Single-use, time-limited, email-bound invitation codes; membership records writable only server-side |
Part B — The Vendor's measures (Processor)
The Vendor shall, as a minimum:
- Use a unique, strong password for each dashboard account, not reused on any other service, and enable multi-factor authentication wherever offered.
- Never share login credentials. Each individual must use their own sub-account.
- Access the dashboard only from devices protected by a password, PIN or biometric lock, and never from shared or public computers on which a session may persist.
- Log out of any communal or shared venue device after each use.
- Not export, screenshot, photograph, print or otherwise copy Platform Personal Data out of the dashboard except to the minimum extent strictly necessary to fulfil a specific order, and securely destroy any such copy immediately once used.
- Not transmit Platform Personal Data over personal messaging applications, personal email accounts, or any consumer file-sharing service.
- Brief every individual before granting them a sub-account, on clause 5.2, clause 5.3 and this Part B.
- Revoke access within twenty-four (24) hours of an individual leaving or changing role.
- Maintain a record of who holds a sub-account, the role assigned, and the date of the last six-monthly review.
- Report any suspected compromise immediately in accordance with clause 7.
Schedule 3 — Boredom's Sub-Processors
| Sub-Processor | Purpose | Location |
|---|---|---|
| Google LLC (Firebase) | Cloud infrastructure — database, authentication, file storage, serverless functions, messaging, analytics | United States; European Union (europe-west2) |
| Paystack | Payment processing | Nigeria (CBN-licensed) |
| Twilio SendGrid | Transactional email — verification, team invitations, notifications | United States |
| Apple Inc. / Google LLC / Meta Platforms | Optional third-party authentication, where a user chooses social sign-in | United States |
Boredom will notify Vendors of material changes to this Schedule.
Schedule 4 — Role permission matrix
The roles available to a Vendor when assigning a team sub-account, and the categories of Platform Personal Data each exposes. Derived from the Platform's permission catalogue (web/src/lib/permissions.ts).
| Role | Customer bookings | Customer messages | Safety incidents | Business bank / payout details |
|---|---|---|---|---|
| Owner | Yes | Yes | Yes | Yes |
| Manager | Yes | Yes | Yes | No |
| Staff | Yes | Yes | No | No |
| Finance | No | No | No | Yes |
| Read-only | Yes | No | Yes | No |
Notes for the Vendor.
- Read-only is not privacy-neutral. It grants visibility of customer bookings and therefore of customer personal data.
- Finance is the only role that exposes no customer personal data, but it is the only default role that exposes the business's bank and payout details.
- Assign the least-privileged role sufficient for the individual's role (clause 5.5(a)).
Version history
| Version | Date | Change |
|---|---|---|
| 2.0 | 28 July 2026 | In force. Execution-ready. Controller corrected to Boredom Technologies Nigeria Limited (RC 9476822); governing law Nigeria; registration numbers inserted; electronic acceptance and execution provisions added; warranties, notices, precedence, variation and general provisions added; registered office inserted; open points resolved except verification of the clause 12 transfer mechanism. |
| 1.0 | 25 July 2026 | Initial draft. Superseded. |
