KiHora

Data Processing Agreement

Version 1.0 · Effective from 23-08-2026

Entered into by MORABEZA TECHLAB, LDA, tax number 210063491, with its address at Ground floor, Nossa Senhora da Graça, Fazenda, Praia, Santiago Island, Cape Verde, hereinafter KIHORA, and the participating establishment that accepts this Agreement in the KiHora Business app, hereinafter the Establishment.

1 Scope of the Agreement

This Agreement governs the processing of personal data carried out by KIHORA on behalf of the Establishment when the Establishment uses the features of the KiHora Business app.

When the Establishment determines the purposes of processing the data it enters on the platform, it acts as the data controller.

In those cases, KIHORA acts as the data processor. It processes the data only to provide the requested features and according to the Establishment's instructions.

This Agreement does not apply to processing for which KIHORA acts as the data controller, including account management, authentication, platform security and technical logs. The Privacy Policy governs that processing.

2 Data covered

This Agreement covers, in particular:

  • data about professionals and employees registered by the Establishment, including name, email address, telephone number and photograph;
  • data about walk-in customers registered by the Establishment, including first name and, when provided, last name, telephone number and email address;
  • data contained in photographs uploaded by the Establishment;
  • booking history associated with those people at the Establishment.

3 Registered customer data and the Establishment's independent responsibility

KIHORA processes data about customers who have their own KIHORA account as the data controller, within its direct relationship with those customers.

The customer's first name, last name, email address and telephone number, where the customer has provided them, together with the gender and profile photograph if the customer has set them, are made available to the Establishment for customers who have a booking with it, because the Establishment cannot deliver the booked service without them.

When the Establishment accesses that data and begins using it on its own initiative, including to contact the customer, organise its activity or keep its own records, the Establishment acts as an independent data controller and not as KIHORA's processor.

For that use, the Establishment is directly responsible to the data subject and undertakes to:

  • use the data only to provide the booked service and for contact required by that service;
  • not use the data for advertising, promotions or any other unsolicited communication;
  • not disclose the data to third parties;
  • not make acceptance of a booking conditional on authorisation to share additional data, or treat a customer who refuses it less favourably;
  • respond to requests made to it by the data subject;
  • delete contact data kept in its own systems as soon as the authorisation that allowed it expires, unless the customer authorised continued retention;
  • delete the data in any event when the data subject requests it or when it is no longer necessary.

The Establishment acknowledges that expiry or revocation of authorisation, or deletion of the customer's account, removes its access to the data in the app. It does not delete information that the Establishment has already seen, noted or stored in its own systems. Deleting that information is the Establishment's responsibility under the preceding paragraph.

4 Responsibility for entered data

The Establishment declares that it has the authority and appropriate legal basis to enter, store, use and share the personal data it puts on the platform.

The Establishment is responsible for:

  • entering only data that is necessary and lawfully obtained;
  • limiting data to what is strictly necessary for booking and providing the service;
  • informing data subjects when collecting their data that it will be recorded in KIHORA;
  • obtaining a professional's consent before uploading their photograph;
  • informing the data subject that an uploaded photograph is accessible through a direct link that does not require authentication, under section 7;
  • not entering sensitive data, including health data;
  • keeping the data up to date;
  • respecting legal retention periods;
  • deleting data when it is no longer necessary;
  • responding to data-subject requests, where applicable;
  • ensuring that only authorised people access the Establishment's account.

5 Information for walk-in customers

When recording a booking for a walk-in customer, the Establishment collects data from a person who does not have an account on the platform and has therefore received no information from KIHORA.

The Establishment must inform that person, when collecting the data and before entering it, that:

  • the name and contact details they provide are recorded in the booking app used by the Establishment;
  • the data is used to manage the booking and attendance history at the Establishment;
  • the person may ask the Establishment at any time to access, correct or delete that data.

KIHORA provides an information notice in the app to help the Establishment meet this duty. Using that notice does not relieve the Establishment of ensuring that the information was actually provided.

6 KIHORA's obligations

KIHORA undertakes to:

  • process the data only to provide the service and according to the Establishment's instructions;
  • not use the data for its own purposes unrelated to providing the service;
  • apply appropriate technical and organisational measures;
  • limit access to authorised personnel;
  • ensure confidentiality obligations;
  • maintain logical separation between establishments so that one establishment cannot access another's data;
  • not create or provide any attendance history, rating or customer list shared between different establishments;
  • use suitable processors under section 9;
  • assist the Establishment with exercising data-subject rights;
  • report relevant security incidents without undue delay;
  • assist the Establishment with its incident-reporting obligations;
  • delete or return data under the applicable rules;
  • keep appropriate processing records and evidence;
  • provide the Establishment with information reasonably needed to demonstrate compliance with this Agreement.

7 Rules for access to photographs

Photographs uploaded by the Establishment are intended to be shown on the establishment page and are public content from the time it is published.

Two aspects of the technical operation must be understood because they do not follow simply from publication.

Each photograph is accessible through a long, non-guessable direct link that does not require authentication. Anyone who knows or obtains that link can open the photograph outside the app. The only way to make the link inoperative is to delete the photograph.

As a result, the link continues to work after the establishment is unpublished or a professional is no longer associated with the establishment, while the photograph has not been deleted.

The Establishment acknowledges this operation, undertakes to inform data subjects before uploading any photograph in which they appear, and to delete the photograph of a professional who leaves the establishment when it wants the photograph to stop being accessible.

8 KIHORA's access to data

KIHORA does not regularly view the Establishment's customer, professional or booking data.

Access may occur only when necessary to:

  • provide requested support;
  • resolve technical failures;
  • prevent fraud;
  • ensure security;
  • comply with legal obligations;
  • respond to a competent authority.

Any access will be limited to what is necessary and subject to confidentiality and internal controls.

9 Technology processors

KIHORA uses providers for hosting, databases, file storage, authentication, notifications, failure diagnosis, traffic distribution and technical monitoring.

Those providers will process data only to the extent necessary to provide their services and will be subject to appropriate confidentiality and data-protection obligations.

The up-to-date list of providers is included in the Privacy Policy.

The Establishment gives general authorisation for the use of these processors. KIHORA will inform the Establishment of material changes to the list through the platform, by email or by updating the Privacy Policy.

Messaging apps that the Establishment uses from its own device to contact customers are not KIHORA's processors. Processing performed by those providers is governed by the relationship between the Establishment and those providers, and the Establishment is responsible for the lawfulness of the contact.

10 Retention and deletion

The Establishment is responsible for managing the life cycle of the data it enters into its account.

When data or a photograph is deleted, it is removed from KIHORA's active systems according to the platform's technical operation.

Temporary copies may remain in the database restoration history until the relevant automatic replacement or deletion cycle, which currently lasts approximately seven days in production.

A restoration window of this size means that the platform does not replace the Establishment's own records. The Establishment must keep its own records of its schedule and customers.

Some operational and audit records related to the existence or deletion of data may be retained when necessary for security, proof of an operation, legal compliance or the defence of rights. Those records do not necessarily include the full content of deleted data.

When the contractual relationship ends, KIHORA will delete or return the data processed on behalf of the Establishment, unless retention is legally required.

11 International transfers

The Establishment acknowledges that the technical infrastructure supporting the platform is located outside Cape Verde, as described in the Privacy Policy, and that providing the service therefore involves international data transfers.

KIHORA undertakes to complete the formalities legally required with the National Data Protection Commission and to appoint providers that offer appropriate protection guarantees.

12 Data-subject rights

When a data subject sends KIHORA a request concerning data processed on behalf of the Establishment, KIHORA will forward the request to the Establishment and provide reasonable assistance so that the Establishment can respond.

When a data subject sends the request to the Establishment, the Establishment must respond and may ask KIHORA for the technical assistance it needs.

For registered customer data covered by section 3, the Establishment is responsible for requests concerning its own use of the data.

13 Each party's responsibility

Each party is responsible for complying with the legal obligations that apply to it.

The Establishment is responsible for the lawfulness, purposes and use of the data it enters and the data it receives under section 3.

KIHORA is responsible for complying with its obligations as controller or processor, depending on the processing involved.

14 Acceptance, versions and changes

The KiHora Business app requires express and separate acceptance of this Agreement through an option the user deliberately selects. Acceptance is required before the establishment-management features can be used.

KIHORA records the account that accepted the Agreement, the accepted version and the date of acceptance.

Each version is identified by a version number and effective date shown at the top of the document. Previously accepted versions are retained for evidentiary and audit purposes.

When a material change makes it necessary, the app will request fresh acceptance before use continues.

15 Applicable law

This Agreement is governed by the general legal framework for the protection of personal data of individuals in force in Cape Verde, approved by Law No. 133/V/2001 of 22 January, as amended by Law No. 41/VIII/2013 of 17 September and Law No. 121/IX/2021 of 17 March, and by any other applicable law.

The acceptance statement

This is the statement shown in the KiHora Business app:

"I have read and accept the Data Processing Agreement and declare that I have the authority and authorisation to process the personal data I enter on the platform, including data about my professionals and customers, and that I inform them that this data is recorded in KiHora."