Effective date: June 18, 2026
At Andela, we take your privacy seriously. Please read this Privacy Policy (“Privacy Policy”) to learn how we treat your “Personal Data” as defined below. By using or accessing our Services, as defined in the Andela Terms of Use (“Terms of Use”), in any manner, you acknowledge that you accept the practices and policies outlined below, and you hereby consent that we will collect, use and disclose your Personal Data described in this Privacy Policy
Remember that your use of Andela’s Services is at all times subject to our Terms of Use which incorporates this Privacy Policy. Any terms we use in this Privacy Policy without defining them have the definitions given to them in the Terms of Use.
You may print a copy of this Privacy Policy by clicking here
We may need to change this Privacy Policy from time to time. Upon such changes, we will alert you to material changes by placing a notice on the Andela website, or by sending you an email and/or by some other means. Please note that if you’ve opted not to receive legal notice emails from us (or you haven’t provided us with your email address), those legal notices will still govern your use of the Services, and you are still responsible for reading and understanding them. If you use the Services after any changes to the Privacy Policy have been posted, that means you agree to all of the changes.
Andela's Privacy Policy
Effective date: June 18, 2026
At Andela, we take your privacy seriously. Please read this Privacy Policy (“Privacy Policy”) to learn how we treat your “Personal Data” as defined below. By using or accessing our Services, as defined in the Andela Terms of Use (“Terms of Use”), in any manner, you acknowledge that you accept the practices and policies outlined below, and you hereby consent that we will collect, use and disclose your Personal Data described in this Privacy Policy.
Remember that your use of Andela's Services is at all times subject to our Terms of Use which incorporates this Privacy Policy. Any terms we use in this Privacy Policy without defining them have the definitions given to them in the Terms of Use.
We may need to change this Privacy Policy from time to time. Upon such changes, we will alert you to material changes by placing a notice on the Andela website, or by sending you an email and/or by some other means. Please note that if you've opted not to receive legal notice emails from us (or you haven't provided us with your email address), those legal notices will still govern your use of the Services, and you are still responsible for reading and understanding them. If you use the Services after any changes to the Privacy Policy have been posted, that means you agree to all of the changes.
Privacy Policy Table of Contents
- What this Privacy Policy Covers
- Personal Data
- How We Disclose Your Personal Data
- Data Security
- Data Retention
- Personal Data of Children
- California Resident Rights
- California Employee Notice
- European Union, United Kingdom, and Swiss Data Subject Rights
- European Union and United Kingdom Personnel Notice
- Data Processing Agreement
- Contact Information
What this Privacy Policy Covers
This Privacy Policy covers how Andela collects and processes information that reasonably identifies or relates, directly or indirectly, to you (“Personal Data”). This Privacy Policy does not cover the practices of companies we don't own or control or people we don't manage, including if we process your Personal Data on behalf of Andela customers in connection with providing our Services.
Personal Data
Categories of Personal Data We May Collect.
Below are the categories of Personal Data that we may collect and may have collected over the past 12 months, depending on your relationship with us:
- Profile or Contact Data. In order to provide, customize, improve, and market the Services, as well as to correspond with you, we may collect profile or contact data such as first and last name, email, phone number, country, and unique identifiers.
- Device or Web Data. In order to provide, customize, improve, and market the Services, as well as to correspond with you, we may collect device or web data such as IP address, IP address-based location information, type of device/operating system/browser, web page interactions, referring webpage/source, log data, and statistics associated with your interactions with the Services.
- Demographic Data. In order to provide, customize, and improve the Services, as well as to correspond with you, we may collect certain demographic data such as age and/or date of birth, zip code, gender.
- Professional or Employment-Related Data. In order to provide, customize, improve, and market the Services, as well as to correspond with you, we may collect professional or employment-related data such as resume, job title, job history, employer, English proficiency, primary skills, years of experience, and other information about your professional background.
- Sensory Data. In order to provide, customize, improve, and market the Services, as well as to correspond with you, we may collect sensory data such as photos, videos, or recordings of you, and/or of your environment, and business call recordings where permissible.
- Categories of Data Considered “Sensitive” Under Applicable Privacy Laws. In order to provide, customize, and improve the Services, as well as to correspond with you, we may collect categories of data that are considered “Sensitive” under applicable data privacy and security rules and regulations (“Privacy Laws”) such as precise geolocation, gender identity, demographic information and personal identification numbers.
- Other Identifying Information that You Voluntarily Choose to Provide. In order to provide, customize, and improve the Services, as well as to correspond with you, we may collect other identifying information that you voluntarily choose to provide such as emails, letters, texts, or other communications you send us.
Our Commercial or Business Purposes for Collecting or Disclosing Personal Data.
- Providing, Customizing and Improving the Services
- Creating and managing your account or other user profiles.
- Processing orders or other transactions; billing.
- Providing you with the products, services or information you request.
- Meeting or fulfilling the reason you provided the information to us, including processing any job applications you submit.
- Providing support and assistance for the Services.
- Improving the Services, including testing, research, internal analytics and product development.
- Personalizing the Services, website content and communications based on your preferences.
- Fraud protection, security and debugging.
- As a collaborative tool for professional growth including the use of business call recordings, where permissible, to assist with training and development in the deliverance of Services.
- Carrying out other business purposes stated when collecting your Personal Data or as otherwise set forth in applicable Privacy Laws, such as the California Consumer Privacy Act, as amended by the California Privacy Rights Act of 2020 (the “CCPA”). For additional information, please see the “California Resident Rights” section.
- Marketing the Services
- Marketing and selling the Services.
- Showing you advertisements, including Interest-Based Advertisements.
- Corresponding with You
- Responding to correspondence that we receive from you, contacting you when necessary or requested, and sending you information about Andela or the Services.
- Sending emails and other communications according to your preferences.
Other Permitted Purposes for Processing Personal Data.
In addition, each of the above referenced categories of Personal Data may be collected, used, and disclosed with the government, including law enforcement, or other parties to meet certain legal requirements and enforcing legal terms including: fulfilling our legal obligations under applicable law, regulation, court order or other legal process, such as preventing, detecting and investigating security incidents and potentially illegal or prohibited activities; protecting the rights, property or safety of you, Andela or another party; enforcing any agreements with you; responding to claims that any posting or other content violates third-party rights; and resolving disputes.
We will not collect additional categories of Personal Data or use the Personal Data we collected for materially different, unrelated or incompatible purposes without providing you notice, or where required under applicable Privacy Laws obtaining your consent.
Categories of Sources of Personal Data
- From You. We collect Personal Data when you provide it directly to us (e.g., you create an account, join the Andela Talent Network, or otherwise contact us). We also collect certain Personal Data (such as device or web data) automatically when you use our Services (e.g., through Cookies – as defined in the “Cookie Settings” tab on the left-hand side of the page), or if you download or install an application as part of our Services.
- Third Parties. We may collect Personal Data from third parties such as:
- Vendors that provide analytics on how you interact and engage with our Services or that help provide you with customer support. We may also use Vendors to help generate leads.
- Advertising Partners who may assist us with marketing or promotional services related to how you interact with our websites, applications, products, Services, advertisements or communications.
- Third Party Credentials that you provide to us or use to sign-in to the Services, such as your social network account credentials, to us or otherwise sign in to the Services through a third-party site or service, some content and/or information in those accounts may be transmitted into your account with us.
How We Disclose Your Personal Data
We disclose your Personal Data to the categories of service providers and other parties listed in this section. Depending on state laws that may be applicable to you, some of these disclosures may constitute a “sale” or “sharing” of your Personal Data. For more information if you are a California resident, please refer to the “California Resident Rights” section below.
- Service Providers. These parties help us provide the Services or perform business functions on our behalf. We may disclose profile or contact data, payment data, device or web data, demographic data, professional or employment-related data, sensory data, categories of data considered “sensitive” under applicable Privacy Laws, and other identifying information you may choose to provide to our Service Providers, including hosting, technology and communication providers, analytics providers for web traffic or usage of our Services, security and fraud prevention consultants, support and customer service vendors, product fulfillment and delivery providers.
- Advertising Partners. These parties help us market our services and provide you with other offers that may be of interest to you such as ad networks, marketing providers, and analytics providers that assist with our Interest-Based Advertisements.
- Affiliate Partners. These parties' partner with us in offering various services. We may disclose profile or contact data, device or web data, demographic data, professional or employment-related data, sensory data, sensitive personal data, and other identifying information you may choose to provide to our Affiliate Partners, including businesses that you have a relationship with and companies that we partner with to provide promotional offers or other opportunities, including but not limited to Andela customers.
- Parties You Authorize, Access or Authenticate. At your direction, we may disclose your Personal Data to Parties You authorize, access or authenticate, including third parties you access through the Services, social media services, other users, and Andela customers.
Legal Obligations
We may disclose Personal Data that we collect with third parties in conjunction with any of the activities set forth under “Our Commercial or Business Purposes for Collecting or Disclosing Personal Data” section above.
Business Transfer
Your Personal Data may be provided or transferred to a third-party if we undergo a sale, merger, acquisition, bankruptcy or other transaction in which that third-party assumes control of our business (in whole or in part).
Data that is Not Personal Data
We may create aggregated, de-identified or anonymized data from the Personal Data we collect, including by removing information that makes the data personally identifiable to a particular user. We may use such aggregated, de-identified or anonymized data and disclose it with third parties for our lawful business purposes, including to analyze, build and improve the Services and promote our business, provided that we will not disclose such data in a manner that could identify you. We will not attempt to reidentify any aggregated, de-identified or anonymized data except to the extent permitted by applicable law (such as reidentification solely for the purpose of determining whether our de-identification processes satisfy the requirements of applicable law).
Data Security
We seek to protect your Personal Data from unauthorized access, use and disclosure using appropriate physical, technical, organizational and administrative security measures based on the type of Personal Data and how we are processing that Personal Data. You should also help protect your Personal Data by appropriately selecting and protecting your password and/or other sign-on mechanism; limiting access to your computer or device and browser; and signing off after you have finished accessing your account. Although we work to protect the security of your account and other data that we hold in our records, please be aware that no method of transmitting Personal Data over the internet or storing Personal Data is completely secure.
Data Retention
We retain Personal Data about you for as long as necessary to provide you with our Services or to perform our business or commercial purposes for collecting your Personal Data. When establishing a retention period for specific categories of Personal Data, we consider who we collected the Personal Data from, our need for the Personal Data, why we collected the Personal Data, and the sensitivity of the Personal Data. In some cases we retain Personal Data for longer, if doing so is necessary to comply with our legal obligations, resolve disputes or collect fees owed, or is otherwise permitted or required by applicable law, rule or regulation. We may further retain Personal Data in an anonymous or aggregated form where that information would not identify you personally.
Personal Data of Children
We do not knowingly collect or solicit Personal Data from children under 18 years of age; if you are a child under the age of 18, please do not attempt to register for or otherwise use the Services or send us any Personal Data. If we learn we have collected Personal Data from a child under 18 years of age, we will delete that information as quickly as possible. If you believe that a child under 18 years of age may have provided Personal Data to us, please contact us at [email protected].
California Resident Rights
If you are a California resident, you may have the rights set forth in this section. Please note that we may process certain Personal Data on behalf of business customers as part of our Services, in which case you may need to contact the entity that collected your Personal Data in the first instance to address your rights with respect to such Personal Data. Please note that the rights below are subject to certain conditions and exceptions under applicable law, which may permit or require us to deny your request. You can find more information on how to exercise your rights in the “Valid Requests under the CCPA” section below.
- Access. You may have the right to request certain information about our collection and use of your Personal Data, including the categories of Personal Data that we have collected about you, the categories of sources of such Personal Data, the business or commercial purpose for collecting or selling your Personal Data, the categories of third parties to whom we have disclosed your Personal Data, and the specific pieces of Personal Data that we have collected about you.
- Deletion. You may have the right to request that we delete the Personal Data that we have collected from you.
- Correction. You may have the right to request that we correct any inaccurate Personal Data we have collected about you.
- Limit the Use and Disclosure of Sensitive Personal Data. Consumers may have the right to request that we limit the use or disclosure of their Sensitive Personal Data (“Right to Limit”). However, since our use and disclosure of Sensitive Personal Data is limited to the purposes set forth in section 7027(m) of the CCPA regulations, including: 1) performing the services or providing the goods reasonably expected, 2) preventing, detecting, and investigating security incidents, 3) resisting malicious, deceptive, fraudulent, or illegal actions, 4) ensuring physical safety of natural persons, 5) for short-term transient use, 6) performing services on behalf of the business, 7) verifying or maintaining quality or safety of a product or service, and 8) collecting or processing Sensitive Personal Data but not for the purpose of inferring characteristics, we do not offer a way for you to submit such a request.
- Opt-Out from Sales/Shares. Under the CCPA, disclosing your Personal Data through third-party Cookies for Interest-Based Advertising may be considered “selling” or “sharing” of Personal Data; and as a result, we may “sell” or “share” Personal Data for these purposes. This includes the disclosure of profile or contact data and device or web data to our Advertising Partners. You may opt-out from our “selling” or “sharing” your Personal Data by: (1) accessing your "Cookie Preferences" at the bottom of our website, or (2) by implementing the Global Privacy Control or similar universal privacy control that is legally recognized by a government agency or industry standard and that complies with applicable Privacy Laws. The signal issued by the control must be initiated by your browser and applies to the specific device and browser you use at the time you cast the signal. Please note this does not include Do Not Track signals.
Valid Requests Under the CCPA
To exercise your CCPA rights, you or your Authorized Agent (as defined below) must send us a request that (1) provides sufficient information to allow us to verify that you are the person about whom we have collected Personal Data and (2) describes your request in sufficient detail to allow us to understand, evaluate and respond to it. Each request that meets both of these criteria will be considered a “Valid Request.” We may not respond to requests that do not meet these criteria. We will only use Personal Data provided in a Valid Request to verify your identity and complete your request. You do not need an account to submit a Valid Request.
We will work to respond to your Valid Request within the time period required by applicable Privacy Laws. We will not charge you a fee for making a Valid Request unless your Valid Request(s) is excessive, repetitive or manifestly unfounded. If we determine that your Valid Request warrants a fee, we will notify you of the fee and explain that decision before completing such request. You may submit a Valid Request for any rights afforded to you in this Privacy Policy by emailing us at [email protected].
You may also authorize an agent (an “Authorized Agent”) to exercise your rights on your behalf. To do this, you must provide your Authorized Agent with written permission to exercise your rights on your behalf, and we may request a copy of this written permission from your Authorized Agent when they make a request on your behalf.
Appealing a Denial
If we refuse to take action on your Valid Request within a reasonable period of time after receiving such Valid Request in accordance with this section, you may appeal our decision. In such appeal, you must (1) provide sufficient information to allow us to verify that you are the person about whom the original Valid Request pertains and to identify the original Valid Request, and (2) provide a description of the basis of your appeal. Please note that your appeal will be subject to your rights and obligations afforded to you under the CCPA. We will respond to your appeal within the time period required under the applicable law. You can submit a Valid Request to appeal by emailing us at [email protected] (title must include “CCPA Appeal”).
We Will Not Discriminate Against You for Exercising Your Rights Under the CCPA
We will not discriminate against you for exercising your rights under the CCPA. We will not deny you our goods or services, charge you different prices or rates, or provide you a lower quality of goods and services if you exercise your rights under the CCPA.
California Employee Notice
At Andela, we care about the privacy and security of your “Personal Data” (as defined below). This CA Employee Privacy Notice (“CA Employee Privacy Notice” or “Notice”) is provided by Andela and its affiliates (“Andela”, “we”, “our”, or “us”) and sets forth the policies for the collection, usage, storage, sharing, and protection of Personal Data in accordance with the California Consumer Privacy Act (“CCPA”). This Notice applies only to Andela employees who are residents of the State of California (“CA Persons”, “you”, “your”) and is intended to provide the requisite notice under the CCPA.
This CA Employee Privacy Notice will be updated in accordance with requirements under the CCPA and in accordance with Andela's policies and procedures. Please check back from time to time to review this Notice. Any updates will be indicated by a new effective date.
What Personal Data Do We Collect?
The Personal Data that Andela collects from CA Persons over the course of a CA Persons' employment (“Employment Services”) includes but is not limited to:
- First and last name, alias
- Date of birth
- Email address
- Home mailing address
- Work address
- Work title
- Home telephone number
- Cell phone number
- Work telephone number
- Account usernames
- Account passwords
- Your financial account information, personal financial information (PFI)
- Social security number
- Passport number, green card number
- Driver's license or other government issued identification
- Family and references information
- Emergency contact information
- Credit score and credit report information
- Race, ethnic background, gender, gender identity, sexual orientation, marital status, medical condition, military or veteran status, religious affiliation, age, nationality, and citizenship
- Biometric data including but not limited to your photograph and fingerprints, where required
- Your request for leave or request for leave for a family member
- Your medical condition including any disability
- Unique personal identifiers including browsing history, geo location, and search history (“Cookies”)
- Online activity as monitored through various online surveillance systems including keystroke dynamics
- Title, salary, education
- Audio, electronic, visual communications and recordings
- Criminal background history
How Do We Collect Your Personal Data?
We collect and process your Personal Data for a number of purposes related to your employment (“Employment Purposes”) including but not limited to:
- When you apply for a job with Andela including when you visit our websites and submit information when seeking employment,
- When you are hired by Andela and as part of the on-boarding processes,
- When using the applications and other operational services in the course of your employment with Andela including our computers and other electronic devices, and
- When using the applications on Andela's devices during the course of your employment.
How Do We Use Your Personal Data?
We use the Personal Data we collect from you for the following employment purposes (“Employment Processing Purposes”):
- to communicate with you, including via email, chat, text message, push notifications, and/or telephone calls in the provision of your Employment Services,
- to recruit employees and conduct employment related background screenings,
- to process payroll, reimburse you for authorized expenses and to administer other compensation related payments in the provision of your Employment Services,
- to administer benefits including but not limited to medical, dental, retirement, leave, insurance and other benefits offered as part of your Employment Services,
- to conduct performance related reviews as part of your Employment Services,
- to provide Employment Services which include utilization of software licensing,
- to contact you in accordance with our Business Continuity Plan and/or in the event of an emergency,
- to advise of delayed office openings or early closures,
- to provide HR management and support services,
- to monitor eligibility work requirements and ensure compliance with state and federal regulations governing such work eligibility,
- to ensure a safe working environment,
- to authenticate your identity,
- to fulfill legal and regulatory requirements; and
- to prevent fraud.
For additional information on Andela's use and collection of Personal Data for Employment Processing Purposes, please refer to Andela's Global Employee Hand Book.
How Do We Disclose Your Personal Data?
We may disclose your Personal Data for Employment Purposes including but not limited to:
- to fulfill your request or for the purpose explained when you provided the Personal Data
- to fulfil legal and regulatory requirements or comply with federal, state or local laws; civil, criminal or regulatory investigations, or disclose Personal Data to third parties if we reasonably believe that such action is necessary to (a) comply with the law and the reasonable requests of law enforcement; (b) to protect the security or integrity of our services; and/or (c) to exercise or protect the rights, property, or personal safety of Andela, our customers, visitors, or others;
- to operate, maintain, and provide the features and functionality of the Employment Services, and
- to help maintain the safety, security, and integrity of our Sites, Services, databases and other technology assets, and business; to diagnose or fix technology problems, and otherwise plan for and enhance our Services.
Your Privacy Rights
You may have the following rights with respect to your Personal Data:
- The right to know what Personal Data we have collected about you, including the categories of Personal Data, the categories of sources from which we collected Personal Data, the business or commercial purpose for collecting, selling, or sharing Personal Data (if applicable), the categories of third parties to whom we disclose Personal Data (if applicable), and the specific pieces of Personal Data we collected about you;
- The right to delete Personal Data that we collected from you, subject to certain exceptions;
- The right to correct inaccurate Personal Data that we maintain about you;
- If we sell or share Personal Data, the right to opt-out of the sale or sharing;
- If we use or disclose sensitive Personal Data for purposes other than those allowed by the CCPA and its regulations, the right to limit our use or disclosure; and
- The right not to receive discriminatory treatment by us for the exercise of privacy rights conferred by the CCPA.
For additional information on Andela's disclosure of your Personal Data for Employment Purposes please refer to Andela's Global Employee Hand Book.
European Union, United Kingdom, and Swiss Data Subject Rights
If you are a resident of the European Union (“EU”), United Kingdom (“UK”), Lichtenstein, Norway or Iceland, you may have additional rights under the EU or UK General Data Protection Regulation (the “GDPR”) with respect to your Personal Data, as outlined below. For this section, we use the terms “Personal Data” and “processing” as they are defined in the GDPR. Andela will be the controller of your Personal Data processed in connection with the Services; however, note that we may also process Personal Data of our customers' end users or employees in connection with our provision of certain services to customers, in which case we are the processor of Personal Data. If we are the processor of your Personal Data (i.e., not the controller), please contact the controller party in the first instance to address your rights with respect to such Personal Data. If you have any questions about this section or whether any of the following applies to you, please contact us at [email protected].
Personal Data Use and Processing Grounds
The “Our Commercial or Business Purposes for Collecting or Disclosing Personal Data” section above explains how we use your Personal Data. We will only process your Personal Data if we have a lawful basis for doing so. Lawful bases for processing include consent, contractual necessity and our “legitimate interests” or the legitimate interest of others, as further described below.
- Contractual Necessity. We process the following categories of Personal Data as a matter of “contractual necessity”: profile or contact data, payment data, demographic data, professional or employment-related data, sensory data, categories of Personal Data considered “Sensitive” under applicable Privacy Laws, and other identifying information that you voluntarily choose to provide. We need to process this Personal Data to perform under our Terms of Use with you, which enables us to provide you with the Services. When we process Personal Data due to contractual necessity, failure to provide such Personal Data will result in your inability to use some or all portions of the Services that require such Personal Data.
- Legitimate Interest. We process the following categories of Personal Data when we believe it furthers the legitimate interest of us or third parties: profile or contact data, payment data, device or web data, demographic data, professional or employment-related data, sensory data, categories of Personal Data considered “Sensitive” under applicable Privacy Laws, inferences drawn from other Personal Data collected, and other identifying information that you voluntarily choose to provide. We may also de-identify or anonymize Personal Data to further our legitimate interests. Examples of these legitimate interests include (as described in more detail above) providing, customizing and improving the Services, marketing the Services, corresponding with you, meeting legal requirements and enforcing legal terms, and completing corporate transactions.
- Consent. In some cases, we process Personal Data based on the consent you expressly grant to us at the time we collect such Personal Data. When we process Personal Data based on your consent, it will be expressly indicated to you at the point and time of collection.
- Other Processing Grounds. From time to time, we may also need to process Personal Data to comply with a legal obligation, if it is necessary to protect the vital interests of you or other Data Subjects, or if it is necessary for a task carried out in the public interest.
EU, UK and Swiss Data Subject Rights.
You have certain rights with respect to your Personal Data, including those set forth below. For more information about these rights, or to submit a request, please email us at [email protected]. Please note that in some circumstances, we may not be able to fully comply with your request, such as if it is frivolous or extremely impractical, if it jeopardizes the rights of others, or if it is not required by law, but in those circumstances, we will still respond to notify you of such a decision. In some cases, we may also need you to provide us with additional information, which may include Personal Data, if necessary to verify your identity and the nature of your request. Please note that your rights may be subject to certain conditions or exceptions in accordance with the GDPR.
- Access. You can request more information about the Personal Data we hold about you and request a copy of such Personal Data. You can also access certain of your Personal Data by logging into your Andela account.
- Rectification. If you believe that any Personal Data, we are holding about you is incorrect or incomplete, you can request that we correct or supplement such data. You can also correct some of this information directly by logging into your Andela account.
- Erasure. You can request that we erase some or all of your Personal Data from our systems.
- Withdrawal of Consent. If we are processing your Personal Data based on your consent (as indicated at the time of collection of such Personal Data), you have the right to withdraw your consent at any time. Please note, however, that if you exercise this right, you may have to then provide express consent on a case-by-case basis for the use or disclosure of certain of your Personal Data, if such use or disclosure is necessary to enable you to utilize some or all of our Services.
- Portability. You can ask for a copy of your Personal Data in a machine-readable format. You can also request that we transmit the Personal Data to another controller where technically feasible.
- Objection. You can contact us to let us know that you object to the further use or disclosure of your Personal Data for certain purposes, such as for direct marketing purposes.
- Restriction of Processing. You can ask us to restrict further processing of your Personal Data.
- Right to File Complaint. You have the right to lodge a complaint about Andela's practices with respect to your Personal Data with the supervisory authority of your country or EU Member State. A list of Supervisory Authorities is available here: https://edpb.europa.eu/about-edpb/board/members_en.
Transfers of Personal Data.
The Services are hosted and operated in the United States (“U.S.”) through Andela and its service providers, and if you do not reside in the U.S., laws in the U.S. may differ from the laws where you reside. By using the Services, you acknowledge that any Personal Data about you, regardless of whether provided by you or obtained from a third-party, is being provided to Andela in the U.S. and will be hosted on U.S. servers, and you authorize Andela to transfer, store and process your Personal Data to and in the U.S., and possibly other countries. In some circumstances, your Personal Data may be transferred to the U.S. pursuant to a data processing agreement incorporating standard data protection clauses.
European Union and United Kingdom Personnel Notice
Introduction
Andela and its subsidiaries and affiliates (“Andela”, “Company” or “we”) operate in many different countries. Some of these countries have laws concerning the collection, use, transfer and disclosure of identifiable information (“Personal Data”) of natural persons. We take these obligations very seriously and we are committed to protecting the Personal Data of our current and former employees, and independent contractors (collectively “Personnel”).
This notice on the protection of Personal Data for Personnel within the EU and UK (“Notice”) is intended to provide personnel located in the territory of the EU or UK (“EU Personnel”, “UK Personnel”, or “you”) with the information required by data privacy security rules and regulations (“Data Protection Laws”), including but not limited to: the identity and contact details of the Data Controller (as that term is defined under Data Protection Laws), the categories of Personal Data collected by the Andela, the purposes and legal bases of the processing, the categories of recipients, the transfers of Personal Data to countries that do not provide an adequate level of protection, retention periods, and the rights of Personnel with regard to their Personal Data.
Andela is the Data Controller who determines the purposes and means of processing your Personal Data. In addition, Andela could be the Data Controller for some centralized human resources processing.
This Notice is not part of an employment contract and may be updated at any time. We will provide you with an amended Notice if it is updated. It is important that you read this Notice so that you know how and why we process your Personal Data.
Information about EU Personnel and UK Personnel that we process
Before, during and after the execution of an employment contract with the Company, we may collect and process Personal Data concerning EU Personnel and UK Personnel. This information is referred to in this Notice as “EU Personal Data” or “UK Personal Data”. We may collect the following EU Personal Data or UK Personal Data:
- Identification. Name, employee identification number, work and home contact information (email, phone numbers, physical address) language(s) spoken, gender, date of birth, national identification number, social security number, geolocation data, emergency contact details and biometric data, i.e. your photograph.
- Documentation required by immigration laws. Citizenship data and passport details, work permit or residence permit details.
- Remuneration and pay. Base salary, bonuses, type of remuneration, awarding of shares and other awards, currency, pay frequency, salary changes, bank details, records of periods spent at work (including annual leave and absences, the status of days of leave, the number of hours worked and usual hours of work within the department), payroll data and the date of termination of employment;
- Position. Description of the current position, job title, executive category, position code, salary plan, grade or level of pay, function(s) and sub-function(s), name and code of the company (employing legal entity), location of the branch/unit/department, status and type of employment, full time/part time, terms and conditions of employment, employment contract, career history, date(s) of hiring/rehiring and the termination of employment and the reasons for these, seniority, eligibility for retirement, promotions and disciplinary records, date of transfers and information concerning the hierarchical superior(s);
- Talent management information. Information contained in application letters and curriculum vitae (employment history, education, professional qualifications, language(s) spoken and other relevant skills, certification, certification expiry date), information necessary to conduct a background check, details of the performance appraisal methods provided by the management, scheduled and attended development programs, e-learning programs, performance review and skills development, possession of a driver's license, and information used for writing professional biographies;
- Data used in systems and applications. Information required to access the Company's systems and applications, such as the system username, the local network username, the email account, the instant messaging account, the mainframe username, the username of the previous employee, the username of the previous supervisor, the system passwords, the right of access of an employee, the country code, the contact details of the previous company, and the electronic content produced by you using the Company's systems;
- Sensitive data. Medical/health information, provided that it must be processed to perform the obligations, demonstrate legal compliance, and enable the exercise the rights of the Data Controller or the person concerned in matters of labor law, social security and social protection, to the extent that such treatment is authorized by Union law, by the law of a Member State or by a collective agreement concluded under the law of a Member State which provides for safeguards that adequately protect the fundamental rights and interests of the Data Subject, as that term is defined under Data Protection Law. This Personal Data may also be processed in order to take into account any specific request from you for the purpose of taking into account a circumstance requiring an adjustment to the execution of an employment contract.
The Personal Data referenced in this Section 2 will be processed for the “Personnel Management,” “Communications and Emergencies,” “Commercial Operations” and “Compliance” purposes as described in Section 4, “Purposes of the Processing”.
Sources of EU Personal Data and UK Personal Data
We collect EU Personal Data and UK Personal Data from the following sources:
- in person, online, by telephone, by written correspondence or through forms;
- third-party websites where you can apply for jobs at Andela or which allow you to take advantage of services or benefits made available to Personnel;
- previous employers in the form of professional references; in the context of a business acquisition or transfer of an employee from another group entity;
- information verification service providers as part of the hiring process;
- Placement agencies and recruiters;
- Providers of sanctions and “politically exposed persons” screening lists.
Use and disclosure of EU Personal Data and UK Personal Data
Legal basis and legitimate interest for processing your Personal Data
We will primarily use your Personal Data in the following circumstances:
- where we have a legal basis for processing your Personal Data
- when necessary for the execution of your employment contract
- where necessary to ensure compliance with the legal obligations to which we are subject (including, with regard to Sensitive Data, obligations under labor law); and
- when necessary for our legitimate interests (or those of a third-party) unless your interests or your fundamental rights and freedoms override those interests. For example, the Company has a legitimate interest in the processing and transferring Personal Data, at the group level, for internal business purposes, including to manage the centralization of data processing, to design efficient and operational business processes, to enable inter-company teams to work together and make business processes more efficient and cost-effective.
We may also use your Personal Data in the following situations:
- when necessary to safeguard your vital interests (or those of a third-party) (and, in the case of sensitive data, when you are unable to provide your consent); and
- when necessary for our defense, to initiate legal proceedings or file a complaint against you or a third-party.
Purposes of the processing
We process the EU Personal Data and UK Personal Data for the following purposes:
- Personnel management. To manage work activities and the staff in general, in particular as regards recruitment, appraisals, performance management, promotions and succession planning, re-hires, pay administration, administration and reviews of payments, salaries and other awards such as shares and bonuses, health care, pensions and savings plans, training, leave, sick leave management, promotions, transfers and secondments, observing other contractual benefits, providing professional references, loans, workforce analysis and scheduling, conducting employee surveys, background checks, management of disciplinary issues, grievances and dismissals, reviewing employment decisions, arranging for business travel, managing business expenses and reimbursements, scheduling and tracking training requirements and career and skills development activities, and creating and maintaining one or more internal employee directories;
- Communications and emergencies. To facilitate communication with you, ensure business continuity, provide references, protect the health and safety of Personnel and others, protect IT infrastructure, office equipment and other assets, and facilitate communications with your designated contacts in case of emergency;
- Commercial operations. For the operation and management of IT and communication systems, product and service management, product and service improvement, business asset management, business asset and human resources allocation, strategic planning, project management, business continuity, the compilation of audit trails and other reporting tools, keeping records of business activities up to date, budgeting, financial management and the preparation of reports, communications, the management of mergers, acquisitions, sales, reorganizations and integration activities with the buyer; and
- Compliance. To comply with legal and other requirements, particularly with respect to tax deductions and deductions under insurance plans, the requirements for record keeping and reporting, the conduct of audits, compliance with government inspections and the response to other requests from the government or other public authorities, the development of rights and remedies, the defense in case of disputes, the management of any internal complaints or claims, the conduct of investigations and proper compliance with internal policies and procedures.
There may be more than one purpose justifying our use of your Personal Data in a particular circumstance.
We will use your Personal Data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another purpose compatible with the original purpose. If we need to use your Personal Data for any other purpose unrelated to the original purpose, we will notify you in advance and provide you with any relevant information in accordance with the law.
If you fail to provide us with some of your Personal Data following our written request, we may not be able to execute your employment contract, or we may not be able to comply with our legal obligations (for example, to ensure the health and safety of our Personnel).
Disclosure to third parties
We may disclose the EU Personal Data and UK Personal Data to the following third parties:
- Professional advisors. Accountants, auditors, lawyers, insurers, bankers and other external professional advisors in all countries in which the Company operates;
- Service providers. Companies that provide products and services to the Company such as payroll, pension plan, social service providers, human resources services, occupational health services, performance management, training, expense management and computer systems providers and recruitment providers; third parties assisting with equity compensation programs, credit card companies, doctors or health professionals, professional groups and trade associations, adjusters, and hosting service providers;
- Public and governmental authorities. Entities that regulate or have jurisdiction over the Company, such as regulatory authorities, public bodies and judicial bodies, including to meet national security or law enforcement requirements;
- Third parties in corporate transactions. as part of any reorganization, merger, sale, joint venture, assignment, transfer or other proposed or actual liquidation of all or part of the business, assets or shares of the Company (including in bankruptcy or similar proceedings); and
- Future employers and their subcontractors.
Information we collect from our Personnel, including Personal Data, is a business asset. If we are acquired by a third party because of a transaction such as a merger, acquisition, or asset sale or if our assets are sold by a third-party in the event we go out of business or enter bankruptcy, some or all of our assets, including your Personal Data, will be disclosed or transferred to a third-party acquirer in connection with the transaction. The acquiring party will be bound by appropriate agreements or obligations and Data Protection Laws to process your Personal Data in a manner consistent with the use and disclosure provision of this Notice.
Transfer of Personal Data
Andela may transfer EU Personal Data and UK Personal Data to third countries that do not provide an adequate level of protection for such Personal Data. To ensure that your Personal Data is sufficiently protected in the event of a transfer outside the European Economic Area or the United Kingdom this transfer will take place within the framework of the standard contractual clauses (“Standard Contractual Clauses”) adopted by the European Commission and the Information Commissioner's Office respectively.
Personal Data will be stored in the United States on servers owned and operated by the Company. Personal Data stored on this server will be available to Company Personnel worldwide.
Further information regarding the Company's protective measures is available by contacting the IT team on Slack at #it.
Data security
Andela shall take appropriate measures to protect EU Personal Data and UK Personal Data in accordance with Data Protection Laws, including requiring that service providers take appropriate measures to ensure the confidentiality and the security of such data.
Access to the EU Personal Data and UK Personal Data within the Company will be limited to those who need to know this data for the purposes described above, including in particular your supervisors and their delegates, as well as staff members from various HR departments, the IT department, compliance officers, legal officers, and people working in the finance, accounting and internal audit departments. All of these people will generally have access to the business contact information of EU Personnel and UK Personnel such as name, job title, telephone number, mailing address and e-mail address.
The Company has established procedures to deal with any alleged breach of Personal Data and will, in accordance with Data Protection Laws, inform you and the relevant supervisory authority of any alleged violation of your Personal Data.
Data retention
The periods of retention of the EU Personal Data and UK Personal Data are determined by the Company according to its business needs and legal requirements. Andela retains EU Personal Data and UK Personal Data for no longer than is necessary for the purposes for which the Personal Data is collected, as described in this Notice and for any other purpose permitted by our Records Management Policy. For example, we may retain certain Personal Data in order to comply with the regulatory requirements applicable to the retention of such data, or in the event of ongoing litigation. When the purposes for which the EU Personal Data or UK Personal Data is processed have been fulfilled, we will irreversibly anonymize the data concerned (we may also retain and use this anonymous data) or erase this data safely.
Accuracy of the Personal Data
Andela will take reasonable steps to ensure that the EU Personal Data and UK Personal Data is reliably processed for the intended use of the data, and to ensure that it is accurate and complete to achieve the objectives described in this Notice. The Company shall ensure that Personal Data that is inaccurate, with respect to the purposes for which it is processed is erased or rectified without delay.
Automated individual decisions
Andela may use or rely on automated processing (such as profiling) to make business decisions that may have a material effect on you. Andela takes all appropriate measures to safeguard your rights and freedoms as well as your legitimate interests.
Consequence of not providing your Personal Data
If you choose to not provide certain Personal Data when requested, we may not be able to perform the contract that we have entered into with you (such as paying you or providing a benefit), or the Company may be prevented from complying with our legal obligations (such as ensuring your health and safety). You may also have to have to provide the Company with Personal Data to exercise your statutory rights, such as statutory leave requirements. Failure to provide the Personal Data may mean that you are unable to exercise your statutory rights.
Your rights
You may have the right to object at any time, for reasons related to your particular situation, to the processing of your Personal Data. You can exercise this right by contacting the IT Team. You also may have the right to access your Personal Data, correct your inaccurate Personal Data, obtain the erasure of your Personal Data, restrict the processing of your Personal Data, receive the Personal Data you have provided to the Company in a commonly used electronic format (unless you request otherwise), and object to being the subject of an automated individual decision. If you wish to exercise any of these rights, please contact the IT Team.
Unless you are unable to identify yourself, we will provide you with information on the measures taken as a result of your request made regarding any of the aforementioned rights within one (1) month of receipt of the request. This period may be extended by two (2) months, given the complexity and the number of requests.
Any refusal to respond to your request will be reasoned and notified within one month from receipt of the request. You can also file a complaint with your local data protection supervisory authority.
Contact information is provided on the following websites:
https://www.edpb.europa.eu/about-edpb/about-edpb/members_en
https://ico.org.uk/make-a-complaint/
Your obligations
You are required to keep your Personal Data up-to-date and inform us of any material changes to your Personal Data. You further agree to comply with applicable laws and Company policies, standards and procedures that are brought to your attention when processing any EU Personal Data or UK Personal Data that may be accessed by you in connection with your relationship with the Company. In particular, you will not access or use any EU Personal Data or UK Personal Data for purposes other than those related to your work with the Company, and to the extent necessary for the proper performance of this work.
Questions or complaints
Please contact the IT Department on Slack at #it for any questions or complaints regarding this Notice or the Company's privacy practices.
If you are located in the EU or UK, you may use the following information to contact our EU or UK Member Representatives:
EU Member Representative
VeraSafe Netherlands BV
Keizersgracht 555
1017 DR Amsterdam
Netherlands
Phone: +420 228 881 031
Webform: https://verasafe.com/public-resources/contact-data-protection-representative
UK Member Representative
VeraSafe United Kingdom Ltd.
37 Albert Embankment
London SE1 7TL
United Kingdom
Phone: +44 (20) 4532 2003
Webform: https://verasafe.com/public-resources/contact-data-protection-representative
Data Processing Agreement
Last Updated: 06/08/2026
This Data Processing Addendum (“DPA”) supplements and is incorporated by reference into the Master Services Agreement (the “Agreement”) entered into by and between the client entity that is party to the Agreement (“Client”) and Andela, Inc. (“Andela” and, together with Client, the “Parties”). This DPA incorporates the terms of the Agreement. Andela may update this DPA from time to time, and will provide reasonable notice of any such updates. Any terms not defined in this DPA shall have the meaning set forth in the Agreement.
- Definitions
- “Authorized Subprocessor” means a third-party entity engaged by Andela to “Process” (as defined herein) “Personal Data” (as defined herein) in order to provide the Services and that has been approved by Client in accordance with Section 6.
- “Andela Account Data” means Personal Data that relates to Andela's relationship with Client, including the names or contact information of individuals authorized by Client to access Client's account and billing information of individuals that Client has associated with its account.
- “Andela Usage Data” means Services usage Personal Data collected and processed by Andela in connection with the provision of the Services, including without limitation Personal Data used to identify the source and destination of a communication, activity logs, and similar Personal Data.
- “Data Privacy Framework” means, as applicable, EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and/or the Swiss-U.S. Data Privacy Framework.
- “Data Subject” means a natural person whose Personal Data is protected by Privacy Laws. For the avoidance of doubt, “Data Subject” includes the term “Consumer” under Privacy Laws.
- “Data Subject Request” means a request from a Data Subject to exercise their rights over Personal Data afforded pursuant to Privacy Laws.
- “EU SCCs” means standard contractual clauses approved by the European Commission in Commission Decision 2021/914 dated 4 June 2021, for transfers of personal data to countries not otherwise recognized as offering an adequate level of protection for personal data by the European Commission (as amended and updated from time to time), as modified by Section 9 of this DPA.
- “ex-EEA Transfer” means the transfer of Personal Data subject to the GDPR from the European Economic Area (the “EEA”) to a country where the transfer is not governed by an adequacy decision made by the European Commission in accordance with the relevant provisions of the GDPR.
- “ex-UK Transfer” means the transfer of Personal Data subject to Chapter V of the UK GDPR from outside the United Kingdom (the “UK”) where such transfer is not governed by an adequacy decision made by the Secretary of State in accordance with the relevant provisions of the UK GDPR and the Data Protection Act 2018.
- “Personal Data” means any information provided to Andela by or on behalf of Client in connection with the Services that relates to an identified or identifiable Data Subject and constitutes “personal data,” “personal information,” or equivalent term under Privacy Laws.
- “Privacy Laws” means any applicable laws and regulations in any relevant jurisdiction relating to the Processing of Personal Data including, each to the extent applicable (i) the General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”) and the EU GDPR as it forms part of the law of England and Wales by virtue of section 3 of the European Union (Withdrawal) Act 2018 (the “UK GDPR”) (together, collectively, the “GDPR”), (ii) the Swiss Federal Act on Data Protection, (iii) the UK Data Protection Act 2018, (iv) the Privacy and Electronic Communications (EC Directive) Regulations 2003, and (v) the California Consumer Privacy Act, as amended by the California Privacy Rights Act of 2020 (the “CCPA”); in each case, as updated, amended or replaced from time to time. The terms “affiliates,” “business purpose,” “Controller,” “Processor,” “sell,” “share,” or “supervisory authority,” shall have the meanings set forth for those or equivalent terms under Privacy Laws. For the avoidance of doubt, the terms “Controller” and “Processor” include “Business” and “Service Provider,” respectively, as defined in the CCPA.
- “Process” (and its derivatives) means any operation or set of operations which is performed upon Personal Data, whether or not by automatic means, such as collection, recording, securing, organization, storage, adaptation or alteration, access to, retrieval, consultation, use, disclosure by transmission, dissemination, sale, transfer, or otherwise making available, alignment or combination, blocking, erasure, or destruction.
- “Standard Contractual Clauses” means, as applicable, the EU SCCs and the UK SCCs.
- “UK Addendum” means the template International Data Transfer Addendum issued by the Information Commissioner and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022 (as may be amended from time to time), as completed by Exhibit D.
- “UK SCCs” means the EU SCCs, as amended by the UK Addendum.
- Role of the Parties; Description of Processing.
- Except as expressly set forth in this DPA or the Agreement, with respect to Personal Data, Client is the Controller and Andela is a Processor of Client Personal Data, or to the extent Client is a Processor to a third-party Controller, Andela is a subprocessor.
- Andela shall Process Personal Data only (i) for purposes set forth in the Agreement, (ii) in a manner consistent with the documented instructions provided by Client, which shall include the Agreement and this DPA, and (iii) as required by Privacy Laws or a supervisory authority; in such case, Andela shall inform Client of that legal requirement before Processing to the extent legally permitted. The subject matter, nature, purpose, and duration of this Processing, as well as the types of Personal Data collected and categories of Data Subjects involved, are described in Exhibit A to this DPA.
- Compliance with Privacy Laws.
- Client shall, in its use of the Services, at all times Process Personal Data, and provide written instructions for the Processing of Personal Data, in compliance with Privacy Laws. Client represents and warrants that it has obtained and documented all necessary consents, permissions, and rights to disclose the Personal Data and that the Personal Data and Andela's use thereof as permitted by this Agreement will not infringe or misappropriate any intellectual property; violate any moral, literary, privacy, publicity, or other right of any consumer or entity; Privacy Laws, or violate Client's own policies, or applicable law. Client shall ensure that the Processing of Personal Data in accordance with Client's instructions will not cause Andela to be in breach of the Privacy Laws. Client is solely responsible for the accuracy, quality, and legality of (i) the Personal Data provided to Andela by or on behalf of Client, (ii) the means by which Client acquired any such Personal Data, and (iii) the instructions it provides to Andela regarding the Processing of such Personal Data. Client shall not provide or make available to Andela any Personal Data in violation of the Agreement or otherwise inappropriate for the nature of the Services and shall indemnify Andela from all claims and losses in connection therewith. Andela shall promptly notify Client if an instruction, in Andela's opinion, infringes Privacy Laws or instruction of a supervisory authority.
- Use of Personal Data
- Andela shall not: (i) sell or share Personal Data; (ii) retain, use, or disclose Personal Data outside of Andela's direct business relationship with Client or for any purpose other than for a business purpose under the CCPA on behalf of Client or as necessary to perform the Services for Client pursuant to the Agreement, except as otherwise permitted in the Agreement or by Privacy Laws; and (iii) combine Personal Data received from, or on behalf of, Client with personal data that it receives from, or on behalf of, another party or person, except as necessary to provide the Services or as otherwise instructed by Client.
- Audit
- Andela shall maintain records sufficient to demonstrate its compliance with its obligations under this DPA. Upon Client's written request at reasonable intervals, and subject to reasonable confidentiality controls, Andela shall, either (i) make available for Client's review copies of certifications or reports demonstrating Andela's compliance with prevailing data security standards applicable to the Processing of Client Personal Data, or (ii) if the provision of reports or certifications pursuant to (i) is not reasonably sufficient under Privacy Laws, allow Client's independent third-party representative to conduct an audit or inspection of Andela's data security infrastructure and procedures that is sufficient to demonstrate Andela's compliance with its obligations under Privacy Laws, provided that (a) Client provides reasonable prior written notice of any such request for an audit and such inspection shall not be unreasonably disruptive to Andela's business; (b) such audit shall only be performed during business hours and occur no more than once per calendar year; and (c) such audit shall be restricted to Personal Data relevant to Client. Client shall be responsible for the costs of any such audits or inspections, including without limitation a reimbursement to Andela for any time expended for on-site audits. If Client and Andela have entered into Standard Contractual Clauses as described in Section 9 (Transfers of Personal Data), the Parties agree that the audits described in Clause 8.9 of the EU SCCs shall be carried out in accordance with this Section 5.
- Authorized Subprocessors.
- Client acknowledges and agrees that Andela may (1) engage its affiliates as well as the Authorized Subprocessors listed in Exhibit B to this DPA to Process Personal Data in connection with the Services and (2) from time to time engage additional subprocessors for the purpose of providing the Services, including without limitation the Processing of Personal Data pursuant to Section 6.2. By way of this DPA, Client provides general written authorization to Andela to engage subprocessors as necessary to perform the Services.
- A list of Andela's current Authorized Subprocessors (the “List”) will be made available to Client upon written request and such List may be updated by Andela from time to time. Client acknowledges that certain subprocessors are essential to providing the Services and that objecting to the use of a subprocessor may prevent Andela from offering the Services to Client.
- If Client reasonably objects to an engagement of a new subprocessor in accordance with Privacy Laws, and Andela cannot provide a commercially reasonable alternative within a reasonable period of time, Client may discontinue the use of the affected Services by providing written notice to Andela. Discontinuation shall not relieve Client of any fees owed to Andela under the Agreement.
- Andela will enter into a written agreement with Authorized Subprocessors imposing on the Authorized Subprocessors data protection obligations comparable to those imposed on Andela under this DPA with respect to the protection of Personal Data. In case an Authorized Subprocessor fails to fulfill its data protection obligations under such written agreement with Andela, Andela will remain liable to Client for the performance of the Authorized Subprocessor's obligations under such agreement.
- If Client and Andela have entered into Standard Contractual Clauses as described in Section 9 (Transfers of Personal Data), (i) the above authorizations will constitute Client's prior written consent to the subcontracting by Andela of the Processing of Personal Data if such consent is required under the Standard Contractual Clauses, and (ii) the Parties agree that the copies of the agreements with Authorized Subprocessors that must be provided by Andela to Client pursuant to Clause 9(c) of the EU SCCs may have commercial information, or information unrelated to the Standard Contractual Clauses or their equivalent, removed by Andela beforehand, and that such copies will be provided by Andela only upon written request by Client.
- Confidentiality; Security of Personal Data.
- Andela shall ensure that any person it authorizes to Process Personal Data has agreed to protect Personal Data in accordance with Andela's confidentiality obligations in the Agreement. Client agrees that Andela may disclose Personal Data to its advisers, auditors or other third parties as reasonably required in connection with the performance of its obligations under this DPA, the Agreement, or the provision of Services to Client.
- Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Andela shall maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk of Processing Personal Data, as described in Exhibit C.
- Personal Data Security Incident.
- In the event of a confirmed breach of security leading to the unauthorized disclosure of, or access to Client Personal Data Processed by Andela or its Authorized Subprocessors under the Agreement (“Personal Data Security Incident”), Andela shall, without undue delay, inform Client of the Personal Data Security Incident and take such steps as Andela in its sole discretion deems necessary and reasonable to remediate such Personal Data Security Incident, to the extent that remediation is within Andela's reasonable control.
- In the event of a Personal Data Security Incident, Andela shall, taking into account the nature of the Processing and the information available to Andela, provide Client with reasonable cooperation and assistance necessary for Client to comply with its obligations under Privacy Laws with respect to notifying (i) the relevant supervisory authority or regulatory agency and (ii) Data Subjects affected by such Personal Data Security Incident without undue delay.
- The obligations described in Sections 8.1 and 8.2 shall not apply in the event that a Personal Data Security Incident results from the actions or omissions of Client. Andela's obligation to report or respond to a Personal Data Security Incident under Sections 8.1 and 8.2 will not be construed as an acknowledgement by Andela of any fault or liability with respect to the Personal Data Security Incident.
- Transfers of Personal Data.
- The Parties agree that Andela may transfer Personal Data processed under this DPA outside the EEA, the UK, or Switzerland as necessary to provide the Services. Client acknowledges that the transfer of Personal Data to the United States is necessary for the provision of the Services to Client. If Andela transfers Personal Data processed under this DPA to a jurisdiction for which the European Commission has not issued an adequacy decision, Andela will ensure that appropriate safeguards have been implemented for the transfer of Personal Data in accordance with Privacy Laws.
- Ex-EEA Transfers. The Parties agree that ex-EEA Transfers shall either be made pursuant to (i) the Data Privacy Framework to the extent the recipient of the ex-EEA Transfer is certified accordingly, or (ii) the EU SCCs, which are deemed entered into (and incorporated into this herein by reference) and completed as follows:
- Module One (Controller to Controller) of the EU SCCs applies when Andela is processing Personal Data as a controller pursuant to Section 9 of this DPA.
- Module Two (Controller to Processor) of the EU SCCs applies when Client is a controller and Andela is a processor of Personal Data in accordance with Section 2 of this DPA.
- Module Three (Processor to Subprocessor) of the EU SCCs applies when Client is a processor and Andela is a subprocessor of Personal Data in accordance with Section 2 of this DPA.
- For each module, where applicable the following applies:
- The optional docking clause in Clause 7 does not apply.
- In Clause 9, Option 2 (general written authorization) applies, and the minimum time period for prior notice of subprocessor changes shall be 30 days.
- In Clause 11, the optional language does not apply.
- All square brackets in Clause 13 are hereby removed.
- In Clause 17 (Option 1), the EU SCCs will be governed by the laws of the Republic of Ireland.
- In Clause 18(b), disputes will be resolved before the courts of the Republic of Ireland.
- Exhibit B to this DPA contains the information required in Annex I of the EU SCCs.
- Exhibit C to this DPA contains the information required in Annex II of the EU SCCs.
- By entering into this DPA, the Parties are deemed to have signed the EU SCCs incorporated herein, including their Annexes.
- Ex-UK Transfers. The Parties agree that ex-UK Transfers shall either be made pursuant to (i) the Data Privacy Framework to the extent that recipient of the ex-UK Transfer is certified accordingly, or (ii) the UK SCCs, which are deemed entered into and incorporated herein by reference. The UK Addendum (including the EU SCCs incorporated into it) is (1) governed by the laws of England and Wales and (2) any dispute arising from it is resolved by the courts of England and Wales.
- Transfers from Switzerland. The Parties agree that transfers from Switzerland shall either be made pursuant to (i) the Data Privacy Framework to the extent that recipient of the transfer from Switzerland is certified accordingly, or (ii) the EU SCCs with the following modifications:
- The terms “General Data Protection Regulation” or “Regulation (EU) 2016/679” as utilized in the EU SCCs shall be interpreted to include the Federal Act on Data Protection of 19 June 1992 (the “FADP,” and as revised as of 25 September 2020, the “Revised FADP”) with respect to data transfers subject to the FADP.
- Clause 13 of the EU SCCs is modified to provide that the Federal Data Protection and Information Commissioner (“FDPIC”) of Switzerland shall have authority over data transfers governed by the FADP and the appropriate EU supervisory authority shall have authority over data transfers governed by the GDPR. Subject to the foregoing, all other requirements of Clause 13 shall be observed.
- The term “EU Member State” as utilized in the EU SCCs shall not be interpreted in such a way as to exclude Data Subjects in Switzerland from exercising their rights in their place of habitual residence in accordance with Clause 18(c) of the EU SCCs.
- Supplementary Measures. In respect of any transfer of Personal data made pursuant to the Standard Contractual Clauses, the following supplementary measures shall apply:
- If Andela receives a formal legal request from any government intelligence or security service/agencies in the country to which the Client Personal Data is being exported, for access to (or for copies of) such Personal Data (each, a “Government Agency Request"), Andela shall attempt to redirect the Government Agency Request to Client. As part of this effort, Andela may provide Client's basic contact information to the government agency. If Andela is compelled to disclose Client Personal Data, to the extent legally permitted, Andela shall notify Client of the demand and reasonably cooperate to allow Client to seek a protective order or other appropriate remedy. Andela shall not voluntarily disclose Client Personal Data to any law enforcement or government agency. The Parties shall determine whether all or any transfers of Client Personal Data pursuant to this DPA should be suspended in light of such a Government Agency Request.
- The Parties will confer as appropriate to consider whether: (i) the protection afforded by the laws of the country of Andela to Data Subjects whose Personal Data is being transferred is sufficient to provide broadly equivalent protection to that afforded in the EEA or the UK, as applicable; (ii) additional measures are reasonably necessary for the transfer to comply with Privacy Laws; and (iii) it is still appropriate for Personal Data to be transferred to the relevant jurisdiction; Andela, taking into account all relevant information available, including guidance by supervisory authorities, to the Parties.
- If either (i) any of the means of legitimizing a transfer cease to be valid or (ii) any supervisory authority requires transfers of Personal Data pursuant to those means to be suspended, the Parties agree to amend the means of legitimizing transfers in accordance with Privacy Laws. To the extent necessary to ensure the enforceability of the Standard Contractual Clauses, the Parties shall execute the Standard Contractual Clauses as a separate agreement.
- Data Protection Assessments.
- Taking into account the nature of Andela's Processing and the information available to Andela, Andela shall reasonably cooperate with Client to conduct any data protection or privacy impact assessments as required by Privacy Laws, including by providing Client with information and documents necessary for such assessments that Client cannot otherwise obtain without Andela's assistance. Notwithstanding the foregoing, Client and Andela each remain responsible only for the measures respectively allocated to them under Privacy Laws pertaining to any such assessment.
- Data Subject Request.
- Andela shall, to the extent permitted by Privacy Laws, notify Client upon receipt of a Data Subject Request. If Andela receives a Data Subject Request in relation to Personal Data, Andela will advise the Data Subject to submit their request to Client and Client will be responsible for responding to such request, including, where necessary, by using the functionality of the Services. Client is solely responsible for ensuring that Data Subject Requests communicated to Andela, and, if applicable, for ensuring that a record of consent to Processing, are maintained with respect to each Data Subject.
- Andela shall, at the written request of Client, and taking into account the nature of the Processing applicable to any Data Subject Request, apply appropriate technical and organizational measures to assist Client in complying with Client's obligation to respond to such Data Subject Request and/or in demonstrating such compliance, where possible, provided that (i) Client is itself unable to respond without Andela's assistance and (ii) Andela is able to do so in accordance with all applicable laws, rules, and regulations. Client shall be responsible to the extent legally permitted for any costs and expenses arising from any such assistance by Andela.
- Return or Destruction of Personal Data.
- Upon the termination or expiration of the Agreement, at Client's choice, Andela shall return or delete Personal Data, unless further storage of such Personal Data is required or authorized by applicable law. If return or destruction is impracticable or prohibited by law, rule or regulation, Andela shall take measures to block such Personal Data from any further processing (except to the extent necessary for its continued hosting or processing required by law, rule or regulation) and shall continue to appropriately protect the Personal Data remaining in its possession, custody, or control. If Client and Andela have entered into Standard Contractual Clauses as described in Section 9 (Transfers of Personal Data), the Parties agree that the certification of deletion of Personal Data that is described in Clause 8.1(d) and Clause 8.5 of the EU SCCs (as applicable) shall be provided by Andela to Client only upon Client's written request. Notwithstanding the foregoing, Andela may retain Personal Data in accordance with Andela's records retention and digital archival back-up policies (“Records Management Policy”) provided such retention remains subject to the terms of the Agreement and provided further that such Personal Data is destroyed in due course in accordance with Andela's Records Management Policy.
- Andela's Role as a Controller.
- The Parties acknowledge and agree that with respect to Andela Account Data and Andela Usage Data, Andela is an independent controller, not a joint controller with Client. Andela will Process Andela Account Data and Andela Usage Data as a controller (i) to manage the relationship with Client; (ii) to carry out Andela's core business operations, such as accounting, audits, tax preparation and filing and compliance purposes; (iii) to monitor, investigate, prevent and detect fraud, security incidents and other misuse of the Services, and to prevent harm to Client; (iv) for identity verification purposes; (v) to comply with legal or regulatory obligations applicable to the Processing of Personal Data to which Andela is subject; and (vi) as otherwise permitted under Privacy Laws and in accordance with this DPA and the Agreement. Andela may also Process Andela Usage Data as an independent controller to provide, optimize, and maintain the Services, to the extent permitted by Privacy Laws. Any Processing by Andela as an independent controller shall be in accordance with Andela's Privacy Policy.
- Miscellaneous
- In the event of any conflict or inconsistency among the following documents, the order of precedence will be: (1) the applicable terms in the Standard Contractual Clauses; (2) the terms of this DPA; (3) the Agreement, and (4) Andela's privacy policy. Any claims brought in connection with this DPA will be subject to the Agreement, including, but not limited to, the exclusions and limitations set forth in the Agreement.
Exhibit A
Details of Processing
- Nature and Purpose of Processing: Andela will Process Personal Data as necessary to provide the Services under the Agreement, for the purposes specified in the Agreement and this DPA, and in accordance with Client's written instructions as set forth in the Agreement and this DPA. The nature of Processing includes, without limitation:
- Receiving Personal Data, including collection, accessing, retrieval, recording, and data entry
- Holding Personal Data, including storage, organization and structuring
- Using Personal Data, including analysis, consultation, and testing
- Updating Personal Data, including correcting, adaptation, alteration, alignment and combination
- Protecting Personal Data, including restricting, encrypting, and security testing
- Disclosing Personal Data, including dissemination, allowing access or otherwise making available
- Returning Personal Data to the data exporter or Data Subject
- Erasing Personal Data, including destruction and deletion
- Duration of Processing: Andela will Process Personal Data as long as required (i) to provide the Services to Client under the Agreement; (ii) for Andela's legitimate business needs; or (iii) by applicable law or regulation. Andela Account Data and Andela Usage Data will be Processed and stored as set forth in Andela's privacy policy.
- Categories of Data Subjects: Client employees and/or contractors; Talent on behalf of Client as Agent on Record.
- Categories of Personal Data: Andela Processes Personal Data contained in Andela Account Data, Andela Usage Data, and any Personal Data provided by Client (including any Personal Data Client collects from its end users and processes through its use of the Services) to provide the Services or as otherwise set forth in the Agreement or this DPA. Categories of Personal Data include name, location, email address, phone or fax number, address
- Sensitive Data or Special Categories of Data: Solely to the extent provided or instructed by the Client in accordance with Privacy Laws. Talent payment data, demographic data, and resume or other professional or employment related data.
Exhibit B
The following includes the information required by Annex I and Annex III of the EU SCCs, and Table 1, Annex 1A, and Annex 1B of the UK Addendum.
- The Parties
- Data exporter(s):
Name: Client
Address: As designated within the Client's account
Signature and Date: By entering into the Agreement, Client is deemed to have signed these Standard Contractual Clauses incorporated herein, as of the date that Client entered into the Agreement.
Role C: As provided in Section 2 of this DPA. - Data importer(s):
Name: Andela Inc.
Address: 169 Madison Avenue, STE 15766, New York, New York 10016
Contact: Mrs. Kirsten Canton, General Counsel, [email protected].
Signature and date: By entering into the Agreement, Data Importer is deemed to have signed these Standard Contractual Clauses incorporated herein, as of the Effective Date of the Agreement.
Role Controller/Processor: As provided in Section 2 and Section 13 of the DPA.
- Data exporter(s):
- Description of the Transfer
.avif)
- Competent Supervisory Authority
- The supervisory authority shall be the supervisory authority of the Data Exporter, as determined in accordance with Clause 13 of the EU SCCs. The supervisory authority for the purposes of the UK Addendum shall be the UK Information Commissioner's Officer.
- List of Authorized Subprocessors
- Client can request the List of Andela's current Authorized Subprocessors by emailing [email protected].
Exhibit C
Description of the Technical and Organisational Security Measures implemented by the Data Importer
The following includes the information required by Annex II of the EU SCCs and Appendix II of the UK Addendum.
- Confidentiality. Andela maintains electronic access control designed to prevent unauthorized access to or use of Andela's Personal Data Processing and Personal Data storage systems, including through the use of secure passwords, automatic blocking/locking mechanisms, two-factor authentication, and encryption of data carriers/storage media. Andela's employees and contractors are bound by written confidentiality agreements, receive training on privacy and security obligations, and are only permitted to Process Personal Data in accordance with the obligations under the Agreement, including this DPA, and Client's documented instructions.
- Internal Access Controls. Andela has implemented permission-based access controls designed to prevent unauthorized access to, modification of, or deletion of Personal Data through a central management system.
- Isolation Control. Andela segregates Personal Data depending on the purpose for collection, including but not limited to logical segregation on a per client basis.
- Pseudonymisation. Where appropriate, and taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of the Processing, Andela employs pseudonymization to protect Personal Data.
- Data Entry Control. Andela has policies in place designed to provide a process for verification of modification to or deletion of Personal Data, including but not limited to logging of changes and document management
- Availability Control. Andela has implemented policies designed to prevent the accidental destruction or loss of Personal Data, such as through the use of regular backups, a “UPS” or uninterruptible power supply, virus protection, firewalls, reporting procedures, and contingency planning.
- Vendor Controls. Andela has implemented procedures for vendor diligence, contracting, onboarding, and order management designed to provide necessary oversight for Andela's vendors to mitigate the risk of unauthorized Processing.
Exhibit D
UK Addendum
International Data Transfer Addendum to the EU Commission Standard Contractual Clauses
Part 1: Tables
- Table 1: Parties

- Table 2: Selected SCCs, Modules and Selected Clauses

- Table 3: Appendix Information
.avif)
- Table 4: Ending this UK Addendum when the Approved UK Addendum Changes

Part 2: Mandatory Clauses
The Mandatory Clauses of the UK Addendum are incorporated herein by reference.
Contact Information
If you have any questions or comments about this Privacy Policy, the ways in which we collect and use your Personal Data or your choices and rights regarding such collection and use, please do not hesitate to contact us at:
By email at
[email protected]
By mail at
Andela Inc.
169 Madison Avenue, Suite 15766
New York, New York 10016
If you are located in the EU or UK, you may use the following information to contact our EU or UK Member Representatives:
EU Member Representative
VeraSafe Netherlands BV
Keizersgracht 555
1017 DR Amsterdam
Netherlands
Phone: +420 228 881 031
Webform: https://verasafe.com/public-resources/contact-data-protection-representative
UK Member Representative
VeraSafe United Kingdom Ltd.
37 Albert Embankment
London SE1 7TL
United Kingdom
Phone: +44 (20) 4532 2003
Webform: https://verasafe.com/public-resources/contact-data-protection-representative
This Privacy Policy covers how Andela collects and processes information that reasonably identifies or relates, directly or indirectly, to you (“Personal Data”). This Privacy Policy does not cover the practices of companies we don’t own or control or people we don’t manage, including if we process your Personal Data on behalf of Andela customers in connection with providing our Services.
Categories of Personal Data We May Collect.
Below are the categories of Personal Data that we may collect and may have collected over the past 12 months, depending on your relationship with us:
- Profile or Contact Data. In order to provide, customize, improve, and market the Services, as well as to correspond with you, we may collect profile or contact data such as first and last name, email, phone number, country, and unique identifiers.
- Device or Web Data. In order to provide, customize, improve, and market the Services, as well as to correspond with you, we may collect device or web data such as IP address, IP address-based location information, type of device/operating system/browser, web page interactions, referring webpage/source, log data, and statistics associated with your interactions with the Services.
- Demographic Data. In order to provide, customize, and improve the Services, as well as to correspond with you, we may collect certain demographic data such as age and/or date of birth, zip code, gender.
- D. Professional or Employment-Related Data. In order to provide, customize, improve, and market the Services, as well as to correspond with you, we may collect professional or employment-related data such as resume, job title, job history, employer, English proficiency, primary skills, years of experience, and other information about your professional background.
- Sensory Data. In order to provide, customize, improve, and market the Services, as well as to correspond with you, we may collect sensory data such as photos, videos, or recordings of you, and/or of your environment, and business call recordings where permissible.
- Categories of Data Considered “Sensitive” Under Applicable Privacy Laws. In order to provide, customize, and improve the Services, as well as to correspond with you, we may collect categories of data that are considered “Sensitive” under applicable data privacy and security rules and regulations (“Privacy Laws”) such as precise geolocation, gender identity, demographic information and personal identification numbers.
- Other Identifying Information that You Voluntarily Choose to Provide. In order to provide, customize, and improve the Services, as well as to correspond with you, we may collect other identifying information that you voluntarily choose to provide such as emails, letters, texts, or other communications you send us.
Our Commercial or Business Purposes for Collecting or Disclosing Personal Data.
- Providing, Customizing and Improving the Services
- Creating and managing your account or other user profiles.
- Processing orders or other transactions; billing.
- Providing you with the products, services or information you request.
- Meeting or fulfilling the reason you provided the information to us, including processing any job applications you submit.
- Providing support and assistance for the Services.
- Improving the Services, including testing, research, internal analytics and product development.
- Personalizing the Services, website content and communications based on your preferences.
- Fraud protection, security and debugging.
- As a collaborative tool for professional growth including the use of business call recordings, where permissible, to assist with training and development in the deliverance of Services.
- Carrying out other business purposes stated when collecting your Personal Data or as otherwise set forth in applicable Privacy Laws, such as the California Consumer Privacy Act, as amended by the California Privacy Rights Act of 2020 (the “CCPA”). For additional information, please see the “California Resident Rights” section.
- Marketing the Services
- Marketing and selling the Services.
- Showing you advertisements, including Interest-Based Advertisements.
- Corresponding with You
- Responding to correspondence that we receive from you, contacting you when necessary or requested, and sending you information about Andela or the Services.
- Sending emails and other communications according to your preferences.
- From You. We collect Personal Data when you provide it directly to us (e.g., you create an account, join the Andela Talent Network, or otherwise contact us). We also collect certain Personal Data (such as device or web data) automatically when you use our Services (e.g., through Cookies – as defined in the “Cookie Settings” tab on the left-hand side of the page), or if you download or install an application as part of our Services.
- Third Parties. We may collect Personal Data from third parties such as:
- Vendors that provide analytics on how you interact and engage with our Services or that help provide you with customer support. We may also use Vendors to help generate leads.
- Advertising Partners who may assist us with marketing or promotional services related to how you interact with our websites, applications, products, Services, advertisements or communications.
- Third Party Credentials that you provide to us or use to sign-in to the Services, such as your social network account credentials, to us or otherwise sign in to the Services through a third-party site or service, some content and/or information in those accounts may be transmitted into your account with us.
We disclose your Personal Data to the categories of service providers and other parties listed in this section. Depending on state laws that may be applicable to you, some of these disclosures may constitute a “sale” or “sharing” of your Personal Data. For more information if you are a California resident, please refer to the “California Resident Rights” section below.
- Service Providers. These parties help us provide the Services or perform business functions on our behalf. We may disclose profile or contact data, payment data, device or web data, demographic data, professional or employment-related data, sensory data, categories of data considered “sensitive” under applicable Privacy Laws, and other identifying information you may choose to provide to our Service Providers, including hosting, technology and communication providers, analytics providers for web traffic or usage of our Services, security and fraud prevention consultants, support and customer service vendors, product fulfillment and delivery providers.
- Advertising Partners. These parties help us market our services and provide you with other offers that may be of interest to you such as ad networks, marketing providers, and analytics providers that assist with our Interest-Based Advertisements.
- Affiliate Partners. These parties’ partner with us in offering various services. We may disclose profile or contact data, device or web data, demographic data, professional or employment-related data, sensory data, sensitive personal data, and other identifying information you may choose to provide to our Affiliate Partners, including businesses that you have a relationship with and companies that we partner with to provide promotional offers or other opportunities, including but not limited to Andela customers.
- Parties You Authorize, Access or Authenticate. At your direction, we may disclose your Personal Data to Parties You authorize, access or authenticate, including third parties you access through the Services, social media services, other users, and Andela customers.
We seek to protect your Personal Data from unauthorized access, use and disclosure using appropriate physical, technical, organizational and administrative security measures based on the type of Personal Data and how we are processing that Personal Data. You should also help protect your Personal Data by appropriately selecting and protecting your password and/or other sign-on mechanism; limiting access to your computer or device and browser; and signing off after you have finished accessing your account. Although we work to protect the security of your account and other data that we hold in our records, please be aware that no method of transmitting Personal Data over the internet or storing Personal Data is completely secure.
If you are a California resident, you may have the rights set forth in this section. Please note that we may process certain Personal Data on behalf of business customers as part of our Services, in which case you may need to contact the entity that collected your Personal Data in the first instance to address your rights with respect to such Personal Data. Please note that the rights below are subject to certain conditions and exceptions under applicable law, which may permit or require us to deny your request. You can find more information on how to exercise your rights in the “Valid Requests under the CCPA” section below.
- Access. You may have the right to request certain information about our collection and use of your Personal Data, including the categories of Personal Data that we have collected about you, the categories of sources of such Personal Data, the business or commercial purpose for collecting or selling your Personal Data, the categories of third parties to whom we have disclosed your Personal Data, and the specific pieces of Personal Data that we have collected about you.
- Deletion. You may have the right to request that we delete the Personal Data that we have collected from you.
- Correction. You may have the right to request that we correct any inaccurate Personal Data we have collected about you.
- Limit the Use and Disclosure of Sensitive Personal Data. Consumers may have the right to request that we limit the use or disclosure of their Sensitive Personal Data (“Right to Limit”). However, since our use and disclosure of Sensitive Personal Data is limited to the purposes set forth in section 7027(m) of the CCPA regulations, including: 1) performing the services or providing the goods reasonably expected, 2) preventing, detecting, and investigating security incidents, 3) resisting malicious, deceptive, fraudulent, or illegal actions, 4) ensuring physical safety of natural persons, 5) for short-term transient use, 6) performing services on behalf of the business, 7) verifying or maintaining quality or safety of a product or service, and 8) collecting or processing Sensitive Personal Data but not for the purpose of inferring characteristics, we do not offer a way for you to submit such a request.
- Opt-Out from Sales/Shares. Under the CCPA, disclosing your Personal Data through third-party Cookies for Interest-Based Advertising may be considered “selling” or “sharing” of Personal Data; and as a result, we may “sell” or “share” Personal Data for these purposes. This includes the disclosure of profile or contact data and device or web data to our Advertising Partners. You may opt-out from our “selling” or “sharing” your Personal Data by: (1) accessing your "Cookie Preferences" at the bottom of our website, or (2) by implementing the Global Privacy Control or similar universal privacy control that is legally recognized by a government agency or industry standard and that complies with applicable Privacy Laws. The signal issued by the control must be initiated by your browser and applies to the specific device and browser you use at the time you cast the signal. Please note this does not include Do Not Track signals.
If we refuse to take action on your Valid Request within a reasonable period of time after receiving such Valid Request in accordance with this section, you may appeal our decision. In such appeal, you must (1) provide sufficient information to allow us to verify that you are the person about whom the original Valid Request pertains and to identify the original Valid Request, and (2) provide a description of the basis of your appeal. Please note that your appeal will be subject to your rights and obligations afforded to you under the CCPA. We will respond to your appeal within the time period required under the applicable law. You can submit a Valid Request to appeal by emailing us at [email protected] (title must include “CCPA Appeal”).
We will not discriminate against you for exercising your rights under the CCPA. We will not deny you our goods or services, charge you different prices or rates, or provide you a lower quality of goods and services if you exercise your rights under the CCPA.
At Andela, we care about the privacy and security of your “Personal Data” (as defined below). This CA Employee Privacy Notice (“CA Employee Privacy Notice” or “Notice”) is provided by Andela and its affiliates (“Andela”, “we”, “our”, or “us”) and sets forth the policies for the collection, usage, storage, sharing, and protection of Personal Data in accordance with the California Consumer Privacy Act (“CCPA”). This Notice applies only to Andela employees who are residents of the State of California (“CA Persons”, “you”, “your”) and is intended to provide the requisite notice under the CCPA.
This CA Employee Privacy Notice will be updated in accordance with requirements under the CCPA and in accordance with Andela’s policies and procedures. Please check back from time to time to review this Notice. Any updates will be indicated by a new effective date.
The Personal Data that Andela collects from CA Persons over the course of a CA Persons’ employment (“Employment Services”) includes but is not limited to:
- First and last name, alias
- Date of birth
- Email address
- Home mailing address
- Work address
- Work title
- Home telephone number
- Cell phone number
- Work telephone number
- Account usernames
- Account passwords
- Your financial account information, personal financial information (PFI)
- Social security number
- Passport number, green card number
- Driver’s license or other government issued identification
- Family and references information
- Emergency contact information
- Credit score and credit report information
- Race, ethnic background, gender, gender identity, sexual orientation, marital status, medical condition, military or veteran status, religious affiliation, age, nationality, and citizenship
- Biometric data including but not limited to your photograph and fingerprints, where required
- Your request for leave or request for leave for a family member
- Your medical condition including any disability
- Unique personal identifiers including browsing history, geo location, and search history (“Cookies”)
- Online activity as monitored through various online surveillance systems including keystroke dynamics
- Title, salary, education
- Audio, electronic, visual communications and recordings
- Criminal background history
We collect and process your Personal Data for a number of purposes related to your employment (“Employment Purposes”) including but not limited to:
- When you apply for a job with Andela including when you visit our websites and submit information when seeking employment,
- When you are hired by Andela and as part of the on-boarding processes,
- When using the applications and other operational services in the course of your employment with Andela including our computers and other electronic devices, and
- When using the applications on Andela’s devices during the course of your employment.
We use the Personal Data we collect from you for the following employment purposes (“Employment Processing Purposes”):
- to communicate with you, including via email, chat, text message, push notifications, and/or telephone calls in the provision of your Employment Services,
- to recruit employees and conduct employment related background screenings,
- to process payroll, reimburse you for authorized expenses and to administer other compensation related payments in the provision of your Employment Services,
- to administer benefits including but not limited to medical, dental, retirement, leave, insurance and other benefits offered as part of your Employment Services,
- to conduct performance related reviews as part of your Employment Services,
- to provide Employment Services which include utilization of software licensing,
- to contact you in accordance with our Business Continuity Plan and/or in the event of an emergency,
- to advise of delayed office openings or early closures,
- to provide HR management and support services,
- to monitor eligibility work requirements and ensure compliance with state and federal regulations governing such work eligibility,
- to ensure a safe working environment,
- to authenticate your identity,
- to fulfill legal and regulatory requirements; and
- to prevent fraud.
For additional information on Andela’s use and collection of Personal Data for Employment Processing Purposes, please refer to Andela’s Global Employee Hand Book.
We may disclose your Personal Data for Employment Purposes including but not limited to:
- to fulfill your request or for the purpose explained when you provided the Personal Data
- to fulfil legal and regulatory requirements or comply with federal, state or local laws; civil, criminal or regulatory investigations, or disclose Personal Data to third parties if we reasonably believe that such action is necessary to (a) comply with the law and the reasonable requests of law enforcement; (b) to protect the security or integrity of our services; and/or (c) to exercise or protect the rights, property, or personal safety of Andela, our customers, visitors, or others;
- to operate, maintain, and provide the features and functionality of the Employment Services, and
- to help maintain the safety, security, and integrity of our Sites, Services, databases and other technology assets, and business; to diagnose or fix technology problems, and otherwise plan for and enhance our Services.
You may have the following rights with respect to your Personal Data:
- The right to know what Personal Data we have collected about you, including the categories of Personal Data, the categories of sources from which we collected Personal Data, the business or commercial purpose for collecting, selling, or sharing Personal Data (if applicable), the categories of third parties to whom we disclose Personal Data (if applicable), and the specific pieces of Personal Data we collected about you;
- The right to delete Personal Data that we collected from you, subject to certain exceptions;
- The right to correct inaccurate Personal Data that we maintain about you;
- If we sell or share Personal Data, the right to opt-out of the sale or sharing;
- If we use or disclose sensitive Personal Data for purposes other than those allowed by the CCPA and its regulations, the right to limit our use or disclosure; and
- The right not to receive discriminatory treatment by us for the exercise of privacy rights conferred by the CCPA.
For additional information on Andela’s disclosure of your Personal Data for Employment Purposes please refer to Andela’s Global Employee Hand Book.
If you are a resident of the European Union (“EU”), United Kingdom (“UK”), Lichtenstein, Norway or Iceland, you may have additional rights under the EU or UK General Data Protection Regulation (the “GDPR”) with respect to your Personal Data, as outlined below. For this section, we use the terms “Personal Data” and “processing” as they are defined in the GDPR. Andela will be the controller of your Personal Data processed in connection with the Services; however, note that we may also process Personal Data of our customers’ end users or employees in connection with our provision of certain services to customers, in which case we are the processor of Personal Data. If we are the processor of your Personal Data (i.e., not the controller), please contact the controller party in the first instance to address your rights with respect to such Personal Data. If you have any questions about this section or whether any of the following applies to you, please contact us at [email protected].
The “Our Commercial or Business Purposes for Collecting or Disclosing Personal Data” section above explains how we use your Personal Data. We will only process your Personal Data if we have a lawful basis for doing so. Lawful bases for processing include consent, contractual necessity and our “legitimate interests” or the legitimate interest of others, as further described below.
- Contractual Necessity. We process the following categories of Personal Data as a matter of “contractual necessity”: profile or contact data, payment data, demographic data, professional or employment-related data, sensory data, categories of Personal Data considered “Sensitive” under applicable Privacy Laws, and other identifying information that you voluntarily choose to provide.We need to process this Personal Data to perform under our Terms of Use with you, which enables us to provide you with the Services. When we process Personal Data due to contractual necessity, failure to provide such Personal Data will result in your inability to use some or all portions of the Services that require such Personal Data.
- Legitimate Interest. We process the following categories of Personal Data when we believe it furthers the legitimate interest of us or third parties: profile or contact data, payment data, device or web data, demographic data, professional or employment-related data, sensory data, categories of Personal Data considered “Sensitive” under applicable Privacy Laws, inferences drawn from other Personal Data collected, and other identifying information that you voluntarily choose to provide. We may also de-identify or anonymize Personal Data to further our legitimate interests.Examples of these legitimate interests include (as described in more detail above) providing, customizing and improving the Services, marketing the Services, corresponding with you, meeting legal requirements and enforcing legal terms, and completing corporate transactions.
- Consent. In some cases, we process Personal Data based on the consent you expressly grant to us at the time we collect such Personal Data. When we process Personal Data based on your consent, it will be expressly indicated to you at the point and time of collection.
- Other Processing Grounds. From time to time, we may also need to process Personal Data to comply with a legal obligation, if it is necessary to protect the vital interests of you or other Data Subjects, or if it is necessary for a task carried out in the public interest.
- Access. You can request more information about the Personal Data we hold about you and request a copy of such Personal Data. You can also access certain of your Personal Data by logging into your Andela account.
- Rectification. If you believe that any Personal Data, we are holding about you is incorrect or incomplete, you can request that we correct or supplement such data. You can also correct some of this information directly by logging into your Andela account.
- Erasure. You can request that we erase some or all of your Personal Data from our systems.
- Withdrawal of Consent. If we are processing your Personal Data based on your consent (as indicated at the time of collection of such Personal Data), you have the right to withdraw your consent at any time. Please note, however, that if you exercise this right, you may have to then provide express consent on a case-by-case basis for the use or disclosure of certain of your Personal Data, if such use or disclosure is necessary to enable you to utilize some or all of our Services.
- Portability. You can ask for a copy of your Personal Data in a machine-readable format. You can also request that we transmit the Personal Data to another controller where technically feasible.
- Objection. You can contact us to let us know that you object to the further use or disclosure of your Personal Data for certain purposes, such as for direct marketing purposes.
- Restriction of Processing. You can ask us to restrict further processing of your Personal Data.
- Right to File Complaint. You have the right to lodge a complaint about Andela’s practices with respect to your Personal Data with the supervisory authority of your country or EU Member State. A list of Supervisory Authorities is available here: https://edpb.europa.eu/about-edpb/board/members_en.
The Services are hosted and operated in the United States (“U.S.”) through Andela and its service providers, and if you do not reside in the U.S., laws in the U.S. may differ from the laws where you reside. By using the Services, you acknowledge that any Personal Data about you, regardless of whether provided by you or obtained from a third-party, is being provided to Andela in the U.S. and will be hosted on U.S. servers, and you authorize Andela to transfer, store and process your Personal Data to and in the U.S., and possibly other countries. In some circumstances, your Personal Data may be transferred to the U.S. pursuant to a data processing agreement incorporating standard data protection clauses.
Andela and its subsidiaries and affiliates (“Andela”, “Company” or “we”) operate in many different countries. Some of these countries have laws concerning the collection, use, transfer and disclosure of identifiable information (“Personal Data”) of natural persons. We take these obligations very seriously and we are committed to protecting the Personal Data of our current and former employees, and independent contractors (collectively “Personnel”).
This notice on the protection of Personal Data for Personnel within the EU and UK (“Notice “) is intended to provide personnel located in the territory of the EU or UK (“EU Personnel”, “UK Personnel”, or “you”) with the information required by data privacy security rules and regulations (“Data Protection Laws”), including but not limited to: the identity and contact details of the Data Controller (as that term is defined under Data Protection Laws), the categories of Personal Data collected by the Andela, the purposes and legal bases of the processing, the categories of recipients, the transfers of Personal Data to countries that do not provide an adequate level of protection, retention periods, and the rights of Personnel with regard to their Personal Data.
Andela is the Data Controller who determines the purposes and means of processing your Personal Data. In addition, Andela could be the Data Controller for some centralized human resources processing.
This Notice is not part of an employment contract and may be updated at any time. We will provide you with an amended Notice if it is updated. It is important that you read this Notice so that you know how and why we process your Personal Data.
Before, during and after the execution of an employment contract with the Company, we may collect and process Personal Data concerning EU Personnel and UK Personnel. This information is referred to in this Notice as “EU Personal Data” or “UK Personal Data”. We may collect the following EU Personal Data or UK Personal Data:
- Identification. Name, employee identification number, work and home contact information (email, phone numbers, physical address) language(s) spoken, gender, date of birth, national identification number, social security number, geolocation data, emergency contact details and biometric data, i.e. your photograph.
- Documentation required by immigration laws. Citizenship data and passport details, work permit or residence permit details.
- Remuneration and pay. Base salary, bonuses, type of remuneration, awarding of shares and other awards, currency, pay frequency, salary changes, bank details, records of periods spent at work (including annual leave and absences, the status of days of leave, the number of hours worked and usual hours of work within the department), payroll data and the date of termination of employment;
- Position. Description of the current position, job title, executive category, position code, salary plan, grade or level of pay, function(s) and sub-function(s), name and code of the company (employing legal entity), location of the branch/unit/department, status and type of employment, full time/part time, terms and conditions of employment, employment contract, career history, date(s) of hiring/rehiring and the termination of employment and the reasons for these, seniority, eligibility for retirement, promotions and disciplinary records, date of transfers and information concerning the hierarchical superior(s);
- Talent management information. Information contained in application letters and curriculum vitae (employment history, education, professional qualifications, language(s) spoken and other relevant skills, certification, certification expiry date), information necessary to conduct a background check, details of the performance appraisal methods provided by the management, scheduled and attended development programs, e-learning programs, performance review and skills development, possession of a driver’s license, and information used for writing professional biographies;
- Data used in systems and applications. Information required to access the Company’s systems and applications, such as the system username, the local network username, the email account, the instant messaging account, the mainframe username, the username of the previous employee, the username of the previous supervisor, the system passwords, the right of access of an employee, the country code, the contact details of the previous company, and the electronic content produced by you using the Company’s systems;
- Sensitive data. Medical/health information, provided that it must be processed to perform the obligations, demonstrate legal compliance, and enable the exercise the rights of the Data Controller or the person concerned in matters of labor law, social security and social protection, to the extent that such treatment is authorized by Union law, by the law of a Member State or by a collective agreement concluded under the law of a Member State which provides for safeguards that adequately protect the fundamental rights and interests of the Data Subject, as that term is defined under Data Protection Law. This Personal Data may also be processed in order to take into account any specific request from you for the purpose of taking into account a circumstance requiring an adjustment to the execution of an employment contract.
The Personal Data referenced in this Section 2 will be processed for the “Personnel Management,” “Communications and Emergencies,” “Commercial Operations” and “Compliance” purposes as described in Section 4, “Purposes of the Processing”.
We collect EU Personal Data and UK Personal Data from the following sources:
- in person, online, by telephone, by written correspondence or through forms;
- third-party websites where you can apply for jobs at Andela or which allow you to take advantage of services or benefits made available to Personnel;
- previous employers in the form of professional references; in the context of a business acquisition or transfer of an employee from another group entity;
- information verification service providers as part of the hiring process;
- Placement agencies and recruiters;
- Providers of sanctions and “politically exposed persons” screening lists.
Legal basis and legitimate interest for processing your Personal Data
- where we have a legal basis for processing your Personal Data
- when necessary for the execution of your employment contract
- where necessary to ensure compliance with the legal obligations to which we are subject (including, with regard to Sensitive Data, obligations under labor law); and
- when necessary for our legitimate interests (or those of a third-party) unless your interests or your fundamental rights and freedoms override those interests. For example, the Company has a legitimate interest in the processing and transferring Personal Data, at the group level, for internal business purposes, including to manage the centralization of data processing, to design efficient and operational business processes, to enable inter-company teams to work together and make business processes more efficient and cost-effective.
- when necessary to safeguard your vital interests (or those of a third-party) (and, in the case of sensitive data, when you are unable to provide your consent); and
- when necessary for our defense, to initiate legal proceedings or file a complaint against you or a third-party.
- Personnel management. To manage work activities and the staff in general, in particular as regards recruitment, appraisals, performance management, promotions and succession planning, re-hires, pay administration, administration and reviews of payments, salaries and other awards such as shares and bonuses, health care, pensions and savings plans, training, leave, sick leave management, promotions, transfers and secondments, observing other contractual benefits, providing professional references, loans, workforce analysis and scheduling, conducting employee surveys, background checks, management of disciplinary issues, grievances and dismissals, reviewing employment decisions, arranging for business travel, managing business expenses and reimbursements, scheduling and tracking training requirements and career and skills development activities, and creating and maintaining one or more internal employee directories;
- Communications and emergencies. To facilitate communication with you, ensure business continuity, provide references, protect the health and safety of Personnel and others, protect IT infrastructure, office equipment and other assets, and facilitate communications with your designated contacts in case of emergency;
- Commercial operations. For the operation and management of IT and communication systems, product and service management, product and service improvement, business asset management, business asset and human resources allocation, strategic planning, project management, business continuity, the compilation of audit trails and other reporting tools, keeping records of business activities up to date, budgeting, financial management and the preparation of reports, communications, the management of mergers, acquisitions, sales, reorganizations and integration activities with the buyer; and
- Compliance. To comply with legal and other requirements, particularly with respect to tax deductions and deductions under insurance plans, the requirements for record keeping and reporting, the conduct of audits, compliance with government inspections and the response to other requests from the government or other public authorities, the development of rights and remedies, the defense in case of disputes, the management of any internal complaints or claims, the conduct of investigations and proper compliance with internal policies and procedures.
There may be more than one purpose justifying our use of your Personal Data in a particular circumstance.
We will use your Personal Data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another purpose compatible with the original purpose. If we need to use your Personal Data for any other purpose unrelated to the original purpose, we will notify you in advance and provide you with any relevant information in accordance with the law.
If you fail to provide us with some of your Personal Data following our written request, we may not be able to execute your employment contract, or we may not be able to comply with our legal obligations (for example, to ensure the health and safety of our Personnel).
We may disclose the EU Personal Data and UK Personal Data to the following third parties:
- Professional advisors. Accountants, auditors, lawyers, insurers, bankers and other external professional advisors in all countries in which the Company operates;
- Service providers. Companies that provide products and services to the Company such as payroll, pension plan, social service providers, human resources services, occupational health services, performance management, training, expense management and computer systems providers and recruitment providers; third parties assisting with equity compensation programs, credit card companies, doctors or health professionals, professional groups and trade associations, adjusters, and hosting service providers;
- Public and governmental authorities. Entities that regulate or have jurisdiction over the Company, such as regulatory authorities, public bodies and judicial bodies, including to meet national security or law enforcement requirements;
- Third parties in corporate transactions. as part of any reorganization, merger, sale, joint venture, assignment, transfer or other proposed or actual liquidation of all or part of the business, assets or shares of the Company (including in bankruptcy or similar proceedings); and
- v. Future employers and their subcontractors.
Information we collect from our Personnel, including Personal Data, is a business asset. If we are acquired by a third party because of a transaction such as a merger, acquisition, or asset sale or if our assets are sold by a third-party in the event we go out of business or enter bankruptcy, some or all of our assets, including your Personal Data, will be disclosed or transferred to a third-party acquirer in connection with the transaction. The acquiring party will be bound by appropriate agreements or obligations and Data Protection Laws to process your Personal Data in a manner consistent with the use and disclosure provision of this Notice.
Andela may transfer EU Personal Data and UK Personal Data to third countries that do not provide an adequate level of protection for such Personal Data. To ensure that your Personal Data is sufficiently protected in the event of a transfer outside the European Economic Area or the United Kingdom this transfer will take place within the framework of the standard contractual clauses (“Standard Contractual Clauses”) adopted by the European Commission and the Information Commissioner’s Office respectively.
Personal Data will be stored in the United States on servers owned and operated by the Company. Personal Data stored on this server will be available to Company Personnel worldwide.
Further information regarding the Company’s protective measures is available by contacting the IT team on Slack at #it.
Andela shall take appropriate measures to protect EU Personal Data and UK Personal Data in accordance with Data Protection Laws, including requiring that service providers take appropriate measures to ensure the confidentiality and the security of such data.
Access to the EU Personal Data and UK Personal Data within the Company will be limited to those who need to know this data for the purposes described above, including in particular your supervisors and their delegates, as well as staff members from various HR departments, the IT department, compliance officers, legal officers, and people working in the finance, accounting and internal audit departments. All of these people will generally have access to the business contact information of EU Personnel and UK Personnel such as name, job title, telephone number, mailing address and e-mail address.
The Company has established procedures to deal with any alleged breach of Personal Data and will, in accordance with Data Protection Laws, inform you and the relevant supervisory authority of any alleged violation of your Personal Data.
The periods of retention of the EU Personal Data and UK Personal Data are determined by the Company according to its business needs and legal requirements. Andela retains EU Personal Data and UK Personal Data for no longer than is necessary for the purposes for which the Personal Data is collected, as described in this Notice and for any other purpose permitted by our Records Management Policy. For example, we may retain certain Personal Data in order to comply with the regulatory requirements applicable to the retention of such data, or in the event of ongoing litigation. When the purposes for which the EU Personal Data or UK Personal Data is processed have been fulfilled, we will irreversibly anonymize the data concerned (we may also retain and use this anonymous data) or erase this data safely.
Andela will take reasonable steps to ensure that the EU Personal Data and UK Personal Data is reliably processed for the intended use of the data, and to ensure that it is accurate and complete to achieve the objectives described in this Notice. The Company shall ensure that Personal Data that is inaccurate, with respect to the purposes for which it is processed is erased or rectified without delay.
Andela may use or rely on automated processing (such as profiling) to make business decisions that may have a material effect on you. Andela takes all appropriate measures to safeguard your rights and freedoms as well as your legitimate interests.
If you choose to not provide certain Personal Data when requested, we may not be able to perform the contract that we have entered into with you (such as paying you or providing a benefit), or the Company may be prevented from complying with our legal obligations (such as ensuring your health and safety). You may also have to have to provide the Company with Personal Data to exercise your statutory rights, such as statutory leave requirements. Failure to provide the Personal Data may mean that you are unable to exercise your statutory rights.
You may have the right to object at any time, for reasons related to your particular situation, to the processing of your Personal Data. You can exercise this right by contacting the IT Team. You also may have the right to access your Personal Data, correct your inaccurate Personal Data, obtain the erasure of your Personal Data, restrict the processing of your Personal Data, receive the Personal Data you have provided to the Company in a commonly used electronic format (unless you request otherwise), and object to being the subject of an automated individual decision. If you wish to exercise any of these rights, please contact the IT Team.
Unless you are unable to identify yourself, we will provide you with information on the measures taken as a result of your request made regarding any of the aforementioned rights within one (1) month of receipt of the request. This period may be extended by two (2) months, given the complexity and the number of requests.
Any refusal to respond to your request will be reasoned and notified within one month from receipt of the request. You can also file a complaint with your local data protection supervisory authority.
Contact information is provided on the following websites:
https://www.edpb.europa.eu/about-edpb/about-edpb/members_en
https://ico.org.uk/make-a-complaint/
You are required to keep your Personal Data up-to-date and inform us of any material changes to your Personal Data. You further agree to comply with applicable laws and Company policies, standards and procedures that are brought to your attention when processing any EU Personal Data or UK Personal Data that may be accessed by you in connection with your relationship with the Company. In particular, you will not access or use any EU Personal Data or UK Personal Data for purposes other than those related to your work with the Company, and to the extent necessary for the proper performance of this work.
Please contact the IT Department on Slack at #it for any questions or complaints regarding this Notice or the Company’s privacy practices.
If you are located in the EU or UK, you may use the following information to contact our EU or UK Member Representatives:
VeraSafe Netherlands BV
Keizersgracht 555
1017 DR Amsterdam
Netherlands
Phone: +420 228 881 031
Webform: https://verasafe.com/public-resources/contact-data-protection-representative
VeraSafe United Kingdom Ltd.
37 Albert Embankment
London SE1 7TL
United Kingdom
Phone: +44 (20) 4532 2003
Webform: https://verasafe.com/public-resources/contact-data-protection-representative
- Definitions
- Authorized Subprocessor” means a third-party entity engaged by Andela to “Process” (as defined herein) “Personal Data” (as defined herein) in order to provide the Services and that has been approved by Client in accordance with Section 6.
- “Andela Account Data” means Personal Data that relates to Andela’s relationship with Client, including the names or contact information of individuals authorized by Client to access Client’s account and billing information of individuals that Client has associated with its account.
- “Andela Usage Data” means Services usage Personal Data collected and processed by Andela in connection with the provision of the Services, including without limitation Personal Data used to identify the source and destination of a communication, activity logs, and similar Personal Data.
- “Data Privacy Framework” means, as applicable, EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and/or the Swiss-U.S. Data Privacy Framework.
- “Data Subject” means a natural person whose Personal Data is protected by Privacy Laws. For the avoidance of doubt, “Data Subject” includes the term “Consumer” under Privacy Laws.
- “Data Subject Request” means a request from a Data Subject to exercise their rights over Personal Data afforded pursuant to Privacy Laws.
- “EU SCCs” means standard contractual clauses approved by the European Commission in Commission Decision 2021/914 dated 4 June 2021, for transfers of personal data to countries not otherwise recognized as offering an adequate level of protection for personal data by the European Commission (as amended and updated from time to time), as modified by Section 9 of this DPA.
- “ex-EEA Transfer” means the transfer of Personal Data subject to the GDPR from the European Economic Area (the “EEA”) to a country where the transfer is not governed by an adequacy decision made by the European Commission in accordance with the relevant provisions of the GDPR.
- “ex-UK Transfer” means the transfer of Personal Data subject to Chapter V of the UK GDPR from outside the United Kingdom (the “UK”) where such transfer is not governed by an adequacy decision made by the Secretary of State in accordance with the relevant provisions of the UK GDPR and the Data Protection Act 2018.
- “Personal Data” means any information provided to Andela by or on behalf of Client in connection with the Services that relates to an identified or identifiable Data Subject and constitutes “personal data,” “personal information,” or equivalent term under Privacy Laws.
- “Privacy Laws” means any applicable laws and regulations in any relevant jurisdiction relating to the Processing of Personal Data including, each to the extent applicable (i) the General Data Protection Regulation (Regulation (EU) 2016/679) (“EU GDPR”) and the EU GDPR as it forms part of the law of England and Wales by virtue of section 3 of the European Union (Withdrawal) Act 2018 (the “UK GDPR”) (together, collectively, the “GDPR”), (ii) the Swiss Federal Act on Data Protection, (iii) the UK Data Protection Act 2018, (iv) the Privacy and Electronic Communications (EC Directive) Regulations 2003, and (v) the California Consumer Privacy Act, as amended by the California Privacy Rights Act of 2020 (the “CCPA); in each case, as updated, amended or replaced from time to time. The terms “affiliates,” “business purpose,” “Controller,” “Processor,” “sell,” “share,” or “supervisory authority,” shall have the meanings set forth for those or equivalent terms under Privacy Laws. For the avoidance of doubt, the terms “Controller” and “Processor” include “Business” and “Service Provider,” respectively, as defined in the CCPA.
- “Process” (and its derivatives) means any operation or set of operations which is performed upon Personal Data, whether or not by automatic means, such as collection, recording, securing, organization, storage, adaptation or alteration, access to, retrieval, consultation, use, disclosure by transmission, dissemination, sale, transfer, or otherwise making available, alignment or combination, blocking, erasure, or destruction.
- “Standard Contractual Clauses” means, as applicable, the EU SCCs and the UK SCCs.
- “UK Addendum” means the template International Data Transfer Addendum issued by the Information Commissioner and laid before Parliament in accordance with s119A of the Data Protection Act 2018 on 2 February 2022 (as may be amended from time to time), as completed by Exhibit D.
- “UK SCCs” means the EU SCCs, as amended by the UK Addendum.
- Role of the Parties; Description of Processing.
- Except as expressly set forth in this DPA or the Agreement, with respect to Personal Data, Client is the Controller and Andela is a Processor of Client Personal Data, or to the extent Client is a Processor to a third-party Controller, Andela is a subprocessor.
- Andela shall Process Personal Data only (i) for purposes set forth in the Agreement, (ii) in a manner consistent with the documented instructions provided by Client, which shall include the Agreement and this DPA, and (iii) as required by Privacy Laws or a supervisory authority; in such case, Andela shall inform Client of that legal requirement before Processing to the extent legally permitted. The subject matter, nature, purpose, and duration of this Processing, as well as the types of Personal Data collected and categories of Data Subjects involved, are described in Exhibit A to this DPA.
- Compliance with Privacy Laws.
- Client shall, in its use of the Services, at all times Process Personal Data, and provide written instructions for the Processing of Personal Data, in compliance with Privacy Laws. Client represents and warrants that it has obtained and documented all necessary consents, permissions, and rights to disclose the Personal Data and that the Personal Data and Andela’s use thereof as permitted by this Agreement will not infringe or misappropriate any intellectual property; violate any moral, literary, privacy, publicity, or other right of any consumer or entity; Privacy Laws, or violate Client’s own policies, or applicable law. Client shall ensure that the Processing of Personal Data in accordance with Client’s instructions will not cause Andela to be in breach of the Privacy Laws. Client is solely responsible for the accuracy, quality, and legality of (i) the Personal Data provided to Andela by or on behalf of Client, (ii) the means by which Client acquired any such Personal Data, and (iii) the instructions it provides to Andela regarding the Processing of such Personal Data. Client shall not provide or make available to Andela any Personal Data in violation of the Agreement or otherwise inappropriate for the nature of the Services and shall indemnify Andela from all claims and losses in connection therewith. Andela shall promptly notify Client if an instruction, in Andela’s opinion, infringes Privacy Laws or instruction of a supervisory authority.
- Use of Personal Data
- Andela shall not: (i) sell or share Personal Data; (ii) retain, use, or disclose Personal Data outside of Andela’s direct business relationship with Client or for any purpose other than for a business purpose under the CCPA on behalf of Client or as necessary to perform the Services for Client pursuant to the Agreement, except as otherwise permitted in the Agreement or by Privacy Laws; and (iii) combine Personal Data received from, or on behalf of, Client with personal data that it receives from, or on behalf of, another party or person, except as necessary to provide the Services or as otherwise instructed by Client.
- Audit
- Andela shall maintain records sufficient to demonstrate its compliance with its obligations under this DPA. Upon Client’s written request at reasonable intervals, and subject to reasonable confidentiality controls, Andela shall, either (i) make available for Client’s review copies of certifications or reports demonstrating Andela’s compliance with prevailing data security standards applicable to the Processing of Client Personal Data, or (ii) if the provision of reports or certifications pursuant to (i) is not reasonably sufficient under Privacy Laws, allow Client’s independent third-party representative to conduct an audit or inspection of Andela’s data security infrastructure and procedures that is sufficient to demonstrate Andela’s compliance with its obligations under Privacy Laws, provided that (a) Client provides reasonable prior written notice of any such request for an audit and such inspection shall not be unreasonably disruptive to Andela’s business; (b) such audit shall only be performed during business hours and occur no more than once per calendar year; and (c) such audit shall be restricted to Personal Data relevant to Client. Client shall be responsible for the costs of any such audits or inspections, including without limitation a reimbursement to Andela for any time expended for on-site audits. If Client and Andela have entered into Standard Contractual Clauses as described in Section 9 (Transfers of Personal Data), the Parties agree that the audits described in Clause 8.9 of the EU SCCs shall be carried out in accordance with this Section 5.
- Authorized Subprocessors.
- Client acknowledges and agrees that Andela may (1) engage its affiliates as well as the Authorized Subprocessors listed in Exhibit B to this DPA to Process Personal Data in connection with the Services and (2) from time to time engage additional subprocessors for the purpose of providing the Services, including without limitation the Processing of Personal Data pursuant to Section 6.2. By way of this DPA, Client provides general written authorization to Andela to engage subprocessors as necessary to perform the Services.
- A list of Andela’s current Authorized Subprocessors (the “List”) will be made available to Client upon written request and such List may be updated by Andela from time to time. Client acknowledges that certain subprocessors are essential to providing the Services and that objecting to the use of a subprocessor may prevent Andela from offering the Services to Client.
- If Client reasonably objects to an engagement of a new subprocessor in accordance with Privacy Laws, and Andela cannot provide a commercially reasonable alternative within a reasonable period of time, Client may discontinue the use of the affected Services by providing written notice to Andela. Discontinuation shall not relieve Client of any fees owed to Andela under the Agreement.
- Andela will enter into a written agreement with Authorized Subprocessors imposing on the Authorized Subprocessors data protection obligations comparable to those imposed on Andela under this DPA with respect to the protection of Personal Data. In case an Authorized Subprocessor fails to fulfill its data protection obligations under such written agreement with Andela, Andela will remain liable to Client for the performance of the Authorized Subprocessor’s obligations under such agreement.
- If Client and Andela have entered into Standard Contractual Clauses as described in Section 9 (Transfers of Personal Data), (i) the above authorizations will constitute Client’s prior written consent to the subcontracting by Andela of the Processing of Personal Data if such consent is required under the Standard Contractual Clauses, and (ii) the Parties agree that the copies of the agreements with Authorized Subprocessors that must be provided by Andela to Client pursuant to Clause 9(c) of the EU SCCs may have commercial information, or information unrelated to the Standard Contractual Clauses or their equivalent, removed by Andela beforehand, and that such copies will be provided by Andela only upon written request by Client.
- Confidentiality; Security of Personal Data.
- Andela shall ensure that any person it authorizes to Process Personal Data has agreed to protect Personal Data in accordance with Andela’s confidentiality obligations in the Agreement. Client agrees that Andela may disclose Personal Data to its advisers, auditors or other third parties as reasonably required in connection with the performance of its obligations under this DPA, the Agreement, or the provision of Services to Client.
- Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Andela shall maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk of Processing Personal Data, as described in Exhibit C.
- Personal Data Security Incident.
- In the event of a confirmed breach of security leading to the unauthorized disclosure of, or access to Client Personal Data Processed by Andela or its Authorized Subprocessors under the Agreement (“Personal Data Security Incident”), Andela shall, without undue delay, inform Client of the Personal Data Security Incident and take such steps as Andela in its sole discretion deems necessary and reasonable to remediate such Personal Data Security Incident, to the extent that remediation is within Andela’s reasonable control.
- In the event of a Personal Data Security Incident, Andela shall, taking into account the nature of the Processing and the information available to Andela, provide Client with reasonable cooperation and assistance necessary for Client to comply with its obligations under Privacy Laws with respect to notifying (i) the relevant supervisory authority or regulatory agency and (ii) Data Subjects affected by such Personal Data Security Incident without undue delay.
- The obligations described in Sections 8.1 and 8.2 shall not apply in the event that a Personal Data Security Incident results from the actions or omissions of Client. Andela’s obligation to report or respond to a Personal Data Security Incident under Sections 8.1 and 8.2 will not be construed as an acknowledgement by Andela of any fault or liability with respect to the Personal Data Security Incident
- Transfers of Personal Data.
- The Parties agree that Andela may transfer Personal Data processed under this DPA outside the EEA, the UK, or Switzerland as necessary to provide the Services. Client acknowledges that the transfer of Personal Data to the United States is necessary for the provision of the Services to Client. If Andela transfers Personal Data processed under this DPA to a jurisdiction for which the European Commission has not issued an adequacy decision, Andela will ensure that appropriate safeguards have been implemented for the transfer of Personal Data in accordance with Privacy Laws.
- Ex-EEA Transfers. The Parties agree that ex-EEA Transfers shall either be made pursuant to (i) the Data Privacy Framework to the extent the recipient of the ex-EEA Transfer is certified accordingly, or (ii) the EU SCCs, which are deemed entered into (and incorporated into this herein by reference) and completed as follows:
- Module One (Controller to Controller) of the EU SCCs applies when Andela is processing Personal Data as a controller pursuant to Section 9 of this DPA.
- Module Two (Controller to Processor) of the EU SCCs applies when Client is a controller and Andela is a processor of Personal Data in accordance with Section 2 of this DPA.
- Module Three (Processor to Subprocessor) of the EU SCCs applies when Client is a processor and Andela is a subprocessor of Personal Data in accordance with Section 2 of this DPA.
- For each module, where applicable the following applies:
- The optional docking clause in Clause 7 does not apply.
- In Clause 9, Option 2 (general written authorization) applies, and the minimum time period for prior notice of subprocessor changes shall be 30 days.
- In Clause 11, the optional language does not apply.
- All square brackets in Clause 13 are hereby removed.
- In Clause 17 (Option 1), the EU SCCs will be governed by the laws of the Republic of Ireland.
- In Clause 18(b), disputes will be resolved before the courts of the Republic of Ireland.
- Exhibit B to this DPA contains the information required in Annex I of the EU SCCs.
- Exhibit C to this DPA contains the information required in Annex II of the EU SCCs.
- By entering into this DPA, the Parties are deemed to have signed the EU SCCs incorporated herein, including their Annexes.
- Ex-UK Transfers. The Parties agree that ex-UK Transfers shall either be made pursuant to (i) the Data Privacy Framework to the extent that recipient of the ex-UK Transfer is certified accordingly, or (ii) the UK SCCs, which are deemed entered into and incorporated herein by reference. The UK Addendum (including the EU SCCs incorporated into it) is (1) governed by the laws of England and Wales and (2) any dispute arising from it is resolved by the courts of England and Wales.
- Transfers from Switzerland. The Parties agree that transfers from Switzerland shall either be made pursuant to (i) the Data Privacy Framework to the extent that recipient of the transfer from Switzerland is certified accordingly, or (ii) the EU SCCs with the following modifications:
- The terms “General Data Protection Regulation” or “Regulation (EU) 2016/679” as utilized in the EU SCCs shall be interpreted to include the Federal Act on Data Protection of 19 June 1992 (the “FADP,” and as revised as of 25 September 2020, the “Revised FADP”) with respect to data transfers subject to the FADP.
- Clause 13 of the EU SCCs is modified to provide that the Federal Data Protection and Information Commissioner (“FDPIC”) of Switzerland shall have authority over data transfers governed by the FADP and the appropriate EU supervisory authority shall have authority over data transfers governed by the GDPR. Subject to the foregoing, all other requirements of Clause 13 shall be observed.
- The term “EU Member State” as utilized in the EU SCCs shall not be interpreted in such a way as to exclude Data Subjects in Switzerland from exercising their rights in their place of habitual residence in accordance with Clause 18(c) of the EU SCCs.
- Supplementary Measures. In respect of any transfer of Personal data made pursuant to the Standard Contractual Clauses, the following supplementary measures shall apply:
- If Andela receives a formal legal request from any government intelligence or security service/agencies in the country to which the Client Personal Data is being exported, for access to (or for copies of) such Personal Data (each, a “Government Agency Request"), Andela shall attempt to redirect the Government Agency Request to Client. As part of this effort, Andela may provide Client’s basic contact information to the government agency. If Andela is compelled to disclose Client Personal Data, to the extent legally permitted, Andela shall notify Client of the demand and reasonably cooperate to allow Client to seek a protective order or other appropriate remedy. Andela shall not voluntarily disclose Client Personal Data to any law enforcement or government agency. The Parties shall determine whether all or any transfers of Client Personal Data pursuant to this DPA should be suspended in light of such a Government Agency Request.
- The Parties will confer as appropriate to consider whether: (i) the protection afforded by the laws of the country of Andela to Data Subjects whose Personal Data is being transferred is sufficient to provide broadly equivalent protection to that afforded in the EEA or the UK, as applicable; (ii) additional measures are reasonably necessary for the transfer to comply with Privacy Laws; and (iii) it is still appropriate for Personal Data to be transferred to the relevant jurisdiction; Andela, taking into account all relevant information available, including guidance by supervisory authorities, to the Parties.
- If either (i) any of the means of legitimizing a transfer cease to be valid or (ii) any supervisory authority requires transfers of Personal Data pursuant to those means to be suspended, the Parties agree to amend the means of legitimizing transfers in accordance with Privacy Laws. To the extent necessary to ensure the enforceability of the Standard Contractual Clauses, the Parties shall execute the Standard Contractual Clauses as a separate agreement.
- Data Protection Assessments.
- Taking into account the nature of Andela’s Processing and the information available to Andela, Andela shall reasonably cooperate with Client to conduct any data protection or privacy impact assessments as required by Privacy Laws, including by providing Client with information and documents necessary for such assessments that Client cannot otherwise obtain without Andela’s assistance. Notwithstanding the foregoing, Client and Andela each remain responsible only for the measures respectively allocated to them under Privacy Laws pertaining to any such assessment.
- Data Subject Request.
- Andela shall, to the extent permitted by Privacy Laws, notify Client upon receipt of a Data Subject Request. If Andela receives a Data Subject Request in relation to Personal Data, Andela will advise the Data Subject to submit their request to Client and Client will be responsible for responding to such request, including, where necessary, by using the functionality of the Services. Client is solely responsible for ensuring that Data Subject Requests communicated to Andela, and, if applicable, for ensuring that a record of consent to Processing, are maintained with respect to each Data Subject.
- Andela shall, at the written request of Client, and taking into account the nature of the Processing applicable to any Data Subject Request, apply appropriate technical and organizational measures to assist Client in complying with Client’s obligation to respond to such Data Subject Request and/or in demonstrating such compliance, where possible, provided that (i) Client is itself unable to respond without Andela’s assistance and (ii) Andela is able to do so in accordance with all applicable laws, rules, and regulations. Client shall be responsible to the extent legally permitted for any costs and expenses arising from any such assistance by Andela.
- Return or Destruction of Personal Data.
- Upon the termination or expiration of the Agreement, at Client’s choice, Andela shall return or delete Personal Data, unless further storage of such Personal Data is required or authorized by applicable law. If return or destruction is impracticable or prohibited by law, rule or regulation, Andela shall take measures to block such Personal Data from any further processing (except to the extent necessary for its continued hosting or processing required by law, rule or regulation) and shall continue to appropriately protect the Personal Data remaining in its possession, custody, or control. If Client and Andela have entered into Standard Contractual Clauses as described in Section 9 (Transfers of Personal Data), the Parties agree that the certification of deletion of Personal Data that is described in Clause 8.1(d) and Clause 8.5 of the EU SCCs (as applicable) shall be provided by Andela to Client only upon Client’s written request. Notwithstanding the foregoing, Andela may retain Personal Data in accordance with Andela’s records retention and digital archival back-up policies (“Records Management Policy”) provided such retention remains subject to the terms of the Agreement and provided further that such Personal Data is destroyed in due course in accordance with Andela’s Records Management Policy.
- Andela’s Role as a Controller.
- The Parties acknowledge and agree that with respect to Andela Account Data and Andela Usage Data, Andela is an independent controller, not a joint controller with Client. Andela will Process Andela Account Data and Andela Usage Data as a controller (i) to manage the relationship with Client; (ii) to carry out Andela’s core business operations, such as accounting, audits, tax preparation and filing and compliance purposes; (iii) to monitor, investigate, prevent and detect fraud, security incidents and other misuse of the Services, and to prevent harm to Client; (iv) for identity verification purposes; (v) to comply with legal or regulatory obligations applicable to the Processing of Personal Data to which Andela is subject; and (vi) as otherwise permitted under Privacy Laws and in accordance with this DPA and the Agreement. Andela may also Process Andela Usage Data as an independent controller to provide, optimize, and maintain the Services, to the extent permitted by Privacy Laws. Any Processing by Andela as an independent controller shall be in accordance with Andela’s Privacy Policy.
- Miscellaneous
- In the event of any conflict or inconsistency among the following documents, the order of precedence will be: (1) the applicable terms in the Standard Contractual Clauses; (2) the terms of this DPA; (3) the Agreement, and (4) Andela’s privacy policy. Any claims brought in connection with this DPA will be subject to the Agreement, including, but not limited to, the exclusions and limitations set forth in the Agreement.
- Nature and Purpose of Processing: Andela will Process Personal Data as necessary to provide the Services under the Agreement, for the purposes specified in the Agreement and this DPA, and in accordance with Client’s written instructions as set forth in the Agreement and this DPA. The nature of Processing includes, without limitation:
- Receiving Personal Data, including collection, accessing, retrieval, recording, and data entry
- Holding Personal Data, including storage, organization and structuring
- Using Personal Data, including analysis, consultation, and testing
- Updating Personal Data, including correcting, adaptation, alteration, alignment and combination
- Protecting Personal Data, including restricting, encrypting, and security testing
- Disclosing Personal Data, including dissemination, allowing access or otherwise making available
- Returning Personal Data to the data exporter or Data Subject
- Erasing Personal Data, including destruction and deletion
- Duration of Processing: Andela will Process Personal Data as long as required (i) to provide the Services to Client under the Agreement; (ii) for Andela’s legitimate business needs; or (iii) by applicable law or regulation. Andela Account Data and Andela Usage Data will be Processed and stored as set forth in Andela’s privacy policy.
- Categories of Data Subjects: Client employees and/or contractors; Talent on behalf of Client as Agent on Record.
- Categories of Personal Data: Andela Processes Personal Data contained in Andela Account Data, Andela Usage Data, and any Personal Data provided by Client (including any Personal Data Client collects from its end users and processes through its use of the Services) to provide the Services or as otherwise set forth in the Agreement or this DPA. Categories of Personal Data include name, location, email address, phone or fax number, address
- Sensitive Data or Special Categories of Data: Solely to the extent provided or instructed by the Client in accordance with Privacy Laws. Talent payment data, demographic data, and resume or other professional or employment related data.
- The Parties
- Data exporter(s):Name: Client
Address: As designated within the Client’s account
Signature and Date: By entering into the Agreement, Client is deemed to have signed these Standard Contractual Clauses incorporated herein, as of the date that Client entered into the Agreement.
Role C: As provided in Section 2 of this DPA. - Data importer(s):Name: Andela Inc.
Address: 169 Madison Avenue, STE 15766, New York, New York 10016
Contact: Mrs. Kirsten Canton, General Counsel, [email protected].
Signature and date: By entering into the Agreement, Data Importer is deemed to have signed these Standard Contractual Clauses incorporated herein, as of the Effective Date of the Agreement.
Role Controller/Processor: As provided in Section 2 and Section 13 of the DPA.
- Description of the Transfer
.avif)
- Competent Supervisory AuthorityThe supervisory authority shall be the supervisory authority of the Data Exporter, as determined in accordance with Clause 13 of the EU SCCs. The supervisory authority for the purposes of the UK Addendum shall be the UK Information Commissioner’s Officer.
- List of Authorized SubprocessorsClient can request the List of Andela’s current Authorized Subprocessors by emailing [email protected].
- Confidentiality. Andela maintains electronic access control designed to prevent unauthorized access to or use of Andela’s Personal Data Processing and Personal Data storage systems, including through the use of secure passwords, automatic blocking/locking mechanisms, two-factor authentication, and encryption of data carriers/storage media. Andela’s employees and contractors are bound by written confidentiality agreements, receive training on privacy and security obligations, and are only permitted to Process Personal Data in accordance with the obligations under the Agreement, including this DPA, and Client’s documented instructions.
- Internal Access Controls. Andela has implemented permission-based access controls designed to prevent unauthorized access to, modification of, or deletion of Personal Data through a central management system.
- Isolation Control. Andela segregates Personal Data depending on the purpose for collection, including but not limited to logical segregation on a per client basis.
- Pseudonymisation. Where appropriate, and taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of the Processing, Andela employs pseudonymization to protect Personal Data.
- Data Entry Control. Andela has policies in place designed to provide a process for verification of modification to or deletion of Personal Data, including but not limited to logging of changes and document management
- Availability Control. Andela has implemented policies designed to prevent the accidental destruction or loss of Personal Data, such as through the use of regular backups, a “UPS” or uninterruptible power supply, virus protection, firewalls, reporting procedures, and contingency planning.
- Vendor Controls. Andela has implemented procedures for vendor diligence, contracting, onboarding, and order management designed to provide necessary oversight for Andela’s vendors to mitigate the risk of unauthorized Processing.
- Table 1: Parties

- Table 2: Selected SCCs, Modules and Selected Clauses

- Table 3: Appendix Information
.avif)
- Table 4: Ending this UK Addendum when the Approved UK Addendum Changes

If you have any questions or comments about this Privacy Policy, the ways in which we collect and use your Personal Data or your choices and rights regarding such collection and use, please do not hesitate to contact us at:
Andela Inc.
169 Madison Avenue, Suite 15766
New York, New York 10016
If you are located in the EU or UK, you may use the following information to contact our EU or UK Member Representatives:
VeraSafe Netherlands BV
Keizersgracht 555
1017 DR Amsterdam
Netherlands
Phone: +420 228 881 031
Webform: https://verasafe.com/public-resources/contact-data-protection-representative
VeraSafe United Kingdom Ltd.
37 Albert Embankment
London SE1 7TL
United Kingdom
Phone: +44 (20) 4532 2003
Webform: https://verasafe.com/public-resources/contact-data-protection-representative




.png)