Data Processing Agreement
The agreement that governs how Noetic Labs handles the personal data your business puts into Metlha — including your employees' payroll and HR records. It reflects Botswana's Data Protection Act, 2024.
- Effective:
- 10 July 2026
- Last updated:
- 10 July 2026
1. How this agreement works
This Data Processing Agreement (“DPA”) is between Noetic Labs (Pty) Ltd(“Noetic Labs”, “we”, “us”, the Processor) and the business that uses Metlha (“you”, “the Customer”, the Controller). It forms part of, and is governed by, our Terms & Conditions. Where this DPA and the Terms conflict on the handling of personal data, this DPA prevails. Words defined in the Terms have the same meaning here.
It exists because Botswana’s Data Protection Act, 2024 requires a binding written contract between a controller and its processor. It applies for as long as we process personal data on your behalf.
2. Definitions
- Personal data — information about an identified or identifiable person.
- Sensitive personal data — data that gets extra protection under the Act, such as health information (for example, a medical certificate attached to a leave request).
- Controller— the party that decides why and how personal data is processed. For your employees’ data, that is you.
- Processor— the party that processes personal data on the controller’s behalf. That is us.
- Data subject — the person the data is about (for example, one of your employees).
- Sub-processor — another provider we use to help deliver the service (see Annex B).
- The Act — the Data Protection Act, 2024 of Botswana, and any law that replaces or amends it.
3. Roles of the parties
For the personal data you load into Metlha about your employees and your business — the “Customer Data” — you are the controller and we are the processor. You are responsible for having a lawful basis to collect and use that data, for the accuracy of what you enter, and for informing your employees how their data is used. We are responsible for processing it only as this DPA allows.
The details of the processing — its subject matter, duration, nature, purpose, the types of data, and the categories of data subjects — are set out in Annex A.
4. Our processing is limited to your instructions
We will process Customer Data only to provide and support the service, and only on your documented instructions — which include your use of the product’s features and the settings you choose. We will not use it for our own purposes, sell it, or share it except as this DPA allows. If we believe an instruction breaks the Act, we will tell you.
5. Confidentiality
We keep Customer Data confidential. We limit access to the staff who need it to run the service and support you, and those people are bound by confidentiality obligations. See our Privacy Policy for who at Noetic Labs can access data and why.
6. Security
We apply appropriate technical and organisational measures to protect Customer Data, taking account of the risks — especially for sensitive data such as health-related leave records. Our measures are listed in Annex C, and include encryption in transit and at rest, access controls, separation of each customer’s data, and regular backups. We keep these measures under review as the service evolves.
7. Sub-processors
You authorise us to use the sub-processors listed in Annex B to help deliver the service. We remain responsible to you for what they do. Each is bound to protect the data to a standard consistent with this DPA. If we add or change a sub-processor that handles personal data, we will update Annex B and, in our Privacy Policy, give you a way to learn of the change so you can raise a reasonable objection.
8. Helping you meet your obligations
Taking account of the nature of the processing, we will help you:
- Respond to requests from your employees to access, correct, object to, or delete their data — using the tools in the app, or by assisting you where you ask.
- Meet your own duties around security, breach handling, and — where you carry one out — a data protection impact assessment.
If one of your employees contacts us directly about their data, we will not respond on your behalf; we will refer them to you as the controller, unless you have instructed us otherwise.
9. If there is a data breach
If we become aware of a breach affecting your Customer Data, we will notify you without undue delay, and give you the information you reasonably need — what happened, the likely consequences, and what we are doing about it. This matters because you, as the controller, may have to notify the Information and Data Protection Commission of Botswana within 72 hours, and you can only do that if we tell you quickly.
10. Sending data outside Botswana
Some of our sub-processors are located outside Botswana. We will only transfer Customer Data outside Botswana under safeguards the Act allows — principally by using destinations the Information and Data Protection Commission of Botswana recognises as providing adequate protection, and contractual protections such as Standard Contractual Clauses where needed. Where a transferred copy must also be kept inside Botswana during processing, we will arrange that. The current locations of your data are described in our Privacy Policy.
11. Giving your data back and deleting it
You can export your Customer Data using the tools in the app at any time while your subscription is active. When our agreement ends, at your choice we will return or delete your Customer Data, and delete existing copies, within the timeframe set out in our Privacy Policy — unless the law requires us to keep certain records for longer. Residual copies in our encrypted backups are overwritten in the normal backup cycle.
12. Showing we comply
We will make available to you the information you reasonably need to show that we are meeting our obligations under this DPA, and will cooperate with a reasonable audit request — on reasonable notice, no more than once a year unless required by the Act or a regulator, at your cost, and in a way that does not compromise the security or data of our other customers.
13. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms & Conditions. Nothing in this DPA limits any liability that cannot be limited under the Act.
14. Duration and governing law
This DPA takes effect when you accept the Terms and continues for as long as we process Customer Data on your behalf. It is governed by the laws of Botswana, and disputes are handled as set out in the Terms.
15. Annex A — Details of the processing
Subject matter and duration
Processing of Customer Data to provide the Metlha service, for as long as your subscription and this DPA are in force.
Nature and purpose
Hosting, storing, organising, displaying, calculating, generating documents from, and otherwise processing Customer Data so you can run payroll, HR, and (where used) projects, documents and meetings.
Types of personal data
- Identity and contact data — names, national identity (Omang) numbers, dates of birth, gender, nationality, addresses, phone and email.
- Financial and payroll data — salaries, allowances, deductions, loans, bank account details, tax and pension-fund numbers, payslips.
- Employment records — roles, contracts, leave, termination, disciplinary and grievance records.
- Sensitive personal data — health-related information that may appear in leave reasons or attachments (for example, medical or maternity certificates).
- Content you create — projects, tasks, documents, comments and meeting notes, which may contain incidental personal data.
Categories of data subjects
Your employees and workers, and — where you record them — their dependants; and your own staff who use the app.
16. Annex B — Approved sub-processors
The sub-processors we use to deliver the service, and what each does:
| Sub-processor | Role | Location |
|---|---|---|
| MongoDB Atlas (MongoDB, Inc.) | Primary database — stores your account and business records, including HR and payroll data. | Cape Town (AWS af-south-1), South Africa |
| Google Cloud Run (Google LLC) | Runs the Metlha application. This is stateless compute — it processes your requests but does not store your data at rest. | Johannesburg (africa-south1), South Africa |
| Google Cloud Storage (Google LLC) | Stores files you upload — attachments, payslip PDFs, and documents such as medical or maternity certificates. | Johannesburg (africa-south1), South Africa |
| Resend (Resend, Inc.) | Sends transactional and notification email (invites, billing notices, alerts). | Ireland (eu-west-1), European Union |
| Cloudflare, Inc. | Hosts and serves this marketing website (metlha.com), and provides privacy-friendly, cookieless visitor analytics across our website and app — it sets no cookies and collects no personal data. | Global content-delivery network |
| AI processing provider (Google Gemini or Anthropic Claude) | Generates meeting summaries and suggested action items from meeting and task content, when you use those features. | Outside Botswana |
17. Annex C — Security measures
The technical and organisational measures we apply include:
- Encryption of data in transit (HTTPS) and at rest with our providers.
- Role-based access controls, so people only reach the data their role allows.
- Separation of each customer’s data, so one customer cannot access another’s.
- Authentication managed by a specialist provider; we never store your passwords.
- Rate limiting and input validation to resist abuse and attacks.
- Regular database backups, hosted in South Africa.
- Access to customer data limited to the staff who need it, under confidentiality obligations.