Skip to content
Create account

Browser Based Nigeria Limited · RC 803010

Data processing agreement

Last updated 12 September 2026

This agreement (the DPA) governs the processing of personal data that Browser Based Nigeria Limited (BBN), RC 803010, carries out on your behalf when you use bbnsms.com. It is drafted to satisfy Article 28 of the EU General Data Protection Regulation and of the UK GDPR, and it applies alongside the Nigeria Data Protection Act 2023.

It takes effect automatically for every account, without signature: by opening an account and accepting the terms of service you accept this DPA as part of them. If your procurement process needs a countersigned copy, or you would rather we execute your own paper, write to [email protected] and we will sign and return it.

Parties and roles

You — the account holder — are the controller. Browser Based Nigeria Limited is the processor, acting on your instructions.

The split matters, because we are not a processor for everything. We act as a processor for the content you receive and handle through the service: inbound SMS bodies delivered to an OTP activation or a dedicated number, the identifiers of the end users you are verifying, and anything else you choose to put into an order. We act as an independent controller for the data we need to run the business relationship with you — your account email, your password hash, the wallet ledger, invoices and payment references, session cookies and security logs. That controller-side processing is described in the privacy policy, not here.

Subject matter and duration

  • Subject matter. Provision of OTP activations, dedicated US and Canada numbers with inbound SMS, and the prepaid wallet that settles them.
  • Duration. For as long as your account is open, plus any period in which we are required to retain records under clause Return and deletion below.
  • Nature and purpose. Receiving, storing and displaying messages sent to numbers we provision for you; provisioning and releasing those numbers; and the metering that charges each order to your wallet.
  • Types of personal data. Telephone numbers, the content of inbound SMS messages (which may contain one-time codes, names or other identifiers chosen by the sender), the service or brand an activation relates to, timestamps and country.
  • Categories of data subject. The end users you verify or communicate with, and any person whose personal data a third party sends to a number allocated to you.
  • Special categories. The service is not designed for special category data under Article 9, or for data relating to criminal convictions. Do not route it through bbnsms.com.

Our obligations as processor

  • Documented instructions. We process personal data only on your documented instructions — which, for the standard product, are the orders you place and this DPA — including as to transfers, unless law requires otherwise, in which case we tell you first unless that law forbids it.
  • Confidentiality. Every person we authorise to process the data is bound by a duty of confidentiality and has access only where their work requires it.
  • Security. We implement the technical and organisational measures set out under Security measures below, appropriate to the risk, as Article 32 requires.
  • Sub-processors. Engaged only under the conditions in Sub-processors below.
  • Assistance with data subject rights. If a data subject contacts us directly about data we hold for you, we do not answer on your behalf — we forward it to you without undue delay and help you respond, insofar as the nature of the processing makes that possible.
  • Assistance with Articles 32 to 36. We help you with security, breach notification and data protection impact assessments, taking into account the information available to us.
  • Deletion or return. As set out under Return and deletion below.
  • Information and audit. We make available the information needed to demonstrate compliance with Article 28, as set out under Audit below.

If we believe an instruction you give us infringes data protection law, we will tell you.

Sub-processors

You give us general written authorisation to engage sub-processors. The current list — each one named, with the purpose it serves and the region it processes in — is published on the Trust Center and forms part of this DPA. Today it is Stripe (card payments), Platfone (OTP activation supply), Telnyx (US and Canada numbers) and Hetzner (infrastructure, HEL1 Helsinki).

We give at least 30 days’ notice before adding or replacing a sub-processor; ask at [email protected] to be on the notification list. You may object on reasonable data protection grounds within that period, and if we cannot offer you an alternative you may terminate the affected service and be refunded any unused wallet balance. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain fully liable to you for their performance.

International transfers

Our infrastructure is in the EU/EEA — Hetzner’s HEL1 region in Helsinki, Finland — so your account data and the messages we store for you are held inside the EEA. Two flows leave it by design: card payments processed by Stripe, and the provisioning of US and Canada numbers by Telnyx, which necessarily happens in those countries.

Where personal data is transferred out of the EEA or the United Kingdom to a country without an adequacy decision, that transfer is made under the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, which are incorporated into this DPA by reference and take effect on these terms:

  • Module Two (controller to processor) applies where you are the controller and we are the processor; Module Three (processor to processor) applies to onward transfers to our sub-processors.
  • Clause 7 (docking) applies. Clause 9 uses Option 2, general written authorisation, with the 30 days’ notice given above. Clause 11 is used without the optional independent dispute resolution body. Clause 17 selects the law of Ireland, and Clause 18(b) the courts of Ireland.
  • Annex I is populated by Parties and roles and Subject matter and duration above and by the sub-processor list on the Trust Center; Annex II by Security measures below; the competent supervisory authority under Annex I.C is that of the EEA member state in which you, as exporter, are established.
  • For UK transfers the International Data Transfer Addendum (version B1.0) issued by the Information Commissioner applies to those clauses, with the tables completed by the same information and neither party able to end the Addendum under Section 19. For Swiss transfers, references to the GDPR are read as references to the FADP and the Federal Data Protection and Information Commissioner is the competent authority.

Where the clauses conflict with the rest of this DPA on a transfer, the clauses win. We will tell you if we receive a legally binding request from a public authority for data we process for you, unless we are prohibited from doing so, and we will challenge a request we consider unlawful.

Security measures

This clause is Annex II for the purposes of the clauses above. Passwords are hashed with Argon2id; sessions use HttpOnly, Secure cookies with short-lived access tokens and rotating refresh tokens; all traffic is served over TLS; application, database and cache run as isolated containers on hardware we control, with secrets held in the host environment and never in source control; the wallet ledger is append-only at the database level so financial records cannot be silently rewritten; money-moving endpoints are idempotent; authentication and order endpoints are rate limited. The full description, kept current, is on the Trust Center.

Personal data breach

We notify you without undue delay, and within 72 hours of becoming aware of a personal data breach affecting personal data we process for you. The notice goes by email to the address on the account and describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed — so that you can meet your own obligation under Article 33. Keep the account email address current; it is the channel we use.

Audit

On request we provide the information reasonably necessary to demonstrate compliance with Article 28, including answering a security questionnaire. You may audit us, or appoint an independent auditor who is not our competitor and who is bound by confidentiality, on at least 30 days’ written notice, no more than once in any 12 months (unless a supervisory authority requires otherwise or a breach has occurred), during business hours, and without disrupting the service or the data of other customers. Each party bears its own costs. We currently hold no SOC 2 or ISO 27001 report to offer in place of an audit, and the Trust Center says so plainly.

Return and deletion

On closure of your account, or at your request at any time, we delete the personal data we process for you as processor — the stored message bodies, activation records and number assignments — or return it to you first if you ask before deletion. Two honest exceptions: the wallet ledger is append-only by design and its rows are not deleted, because the balance is the sum of that history; and we retain what EU, UK or Nigerian law requires us to retain, for example for tax and for payment dispute records. Anything retained stays subject to this DPA for as long as we hold it.

Your obligations

You are responsible for having a lawful basis for the processing you instruct, for giving the notices your own data subjects are owed, and for using numbers we provision only for lawful verification and messaging as the terms of service require. Do not route special category data, and do not use the service to obtain access to accounts you are not entitled to.

Exercising rights and contacting us

Every data protection request — access, rectification, erasure, restriction, portability, objection, or a question about this DPA — goes to [email protected]. We acknowledge within two business days and answer substantively within one month, as Article 12(3) requires. We will need to verify that the request comes from the account holder. You may also write to us at Plot 12 Road 6, Lekki County Homes, Ikota Villa Estate, Lekki, Lagos, Nigeria.

We have not appointed a representative in the European Union or the United Kingdom under Article 27, and we would rather say so than name one that does not exist. Correspondence should be addressed to the company directly, at the mailbox or the registered office above. If that is a blocker for your legal team, tell us — appointing a representative is a step we will take when the EU customer base warrants it.

Liability, precedence and law

This DPA forms part of the terms of service and the liability provisions of those terms apply to it. Where this DPA conflicts with the terms of service or the privacy policy on the processing of personal data, this DPA prevails; where it conflicts with the Standard Contractual Clauses, the clauses prevail. Except as those clauses provide, this DPA is governed by the laws of the Federal Republic of Nigeria, consistent with the terms of service.

If we change this DPA in a material way we update the date at the top of this page and, where the change affects sub-processors, give the 30 days’ notice described above.

© 2026 Browser Based Nigeria Limited (BBN) · RC 803010 · Lagos, Nigeria · Est. 2008