Compliance

Baseflow is designed to help your organization meet regulatory requirements and maintain compliance with global data protection standards.

Last updated: February 1, 2026

Regulatory Compliance

We maintain compliance with major data protection regulations and industry standards.

Compliant

NDPR

Nigeria Data Protection Regulation

We comply with Nigeria's data protection regulation, ensuring proper handling of personal data for Nigerian users and businesses.

Compliant

GDPR

General Data Protection Regulation

Full compliance with EU data protection requirements, including data subject rights, consent management, and cross-border transfers.

Compliant

POPIA

Protection of Personal Information Act

Compliant with South Africa's data protection law, providing safeguards for personal information processing.

Certified

SOC 2 Type II

Service Organization Control 2

Independent verification of our security, availability, and confidentiality controls by certified auditors.

Compliant

E-Sign Laws

Electronic Signature Regulations

Our electronic signatures comply with Nigerian Evidence Act, ECOWAS regulations, and international e-signature standards.

In Progress

ISO 27001

Information Security Management

Working towards ISO 27001 certification for our information security management system.

Compliance-Ready Features

Built-in tools and features to help you maintain compliance.

Data Residency Options

Choose where your data is stored. We offer regional data centers to meet local data residency requirements.

Audit Trail & Logging

Comprehensive audit logs capture every action, providing full traceability for compliance audits.

Data Export & Portability

Export your data in standard formats at any time. We support data portability requirements.

Consent Management

Built-in tools for managing consent, including cookie preferences and data processing agreements.

Retention Policies

Configure data retention periods to meet regulatory requirements and automatically purge expired data.

Access Controls

Granular permissions and role-based access ensure data is only accessible to authorized personnel.

Our Commitment to Compliance

At Baseflow, we understand that compliance is not just about checking boxes—it's about building trust with our customers and ensuring their data is handled responsibly. We continuously monitor regulatory developments and update our practices accordingly.

Data Protection Principles

We adhere to core data protection principles:

  • Lawfulness, Fairness, and Transparency: We process data lawfully and are transparent about our practices.
  • Purpose Limitation: Data is collected for specific, explicit purposes and not processed incompatibly.
  • Data Minimization: We only collect data that is necessary for the stated purposes.
  • Accuracy: We take steps to ensure personal data is accurate and kept up to date.
  • Storage Limitation: Data is retained only as long as necessary for its purpose.
  • Integrity and Confidentiality: We implement appropriate security measures to protect data.

Electronic Signature Compliance

Our electronic signature capabilities are designed to comply with e-signature laws across multiple jurisdictions:

  • Nigeria: Nigerian Evidence Act 2011 recognizes electronic signatures for most business transactions.
  • South Africa: Electronic Communications and Transactions Act (ECTA) provides legal recognition.
  • Kenya: Kenya Information and Communications Act supports electronic signatures.
  • Ghana: Electronic Transactions Act provides framework for e-signatures.
  • European Union: eIDAS Regulation for cross-border electronic transactions.
  • United States: ESIGN Act and UETA for domestic transactions.

Industry-Specific Compliance

We support compliance requirements across various industries:

  • Financial Services: Support for CBN regulations and financial data handling requirements.
  • Healthcare: Features to support health data protection requirements.
  • Legal: Audit trails and evidence preservation for legal validity.
  • Government: Support for public sector procurement and transparency requirements.

Data Processing Agreements

We offer Data Processing Agreements (DPAs) for customers who require them. Our DPA covers:

  • Nature and purpose of processing
  • Types of personal data processed
  • Duration of processing
  • Sub-processor management
  • Security measures
  • Data subject rights support
  • Cross-border transfer mechanisms

Sub-Processors

We carefully vet all sub-processors and maintain a list of approved vendors. Our sub-processors are contractually bound to provide the same level of data protection as Baseflow. Key sub-processors include:

  • Cloud infrastructure providers (hosting and storage)
  • Payment processors (Paystack, Flutterwave, Stripe)
  • Email service providers
  • Analytics services
  • Customer support tools

International Data Transfers

When transferring data internationally, we implement appropriate safeguards:

  • Standard Contractual Clauses (SCCs) for EU data transfers
  • Adequacy decisions where applicable
  • Binding Corporate Rules for intra-group transfers
  • Data localization options for specific regulatory requirements

Compliance Documentation

Access our compliance documentation and certifications.

Data Processing Agreement

Standard DPA template

Request

SOC 2 Report

Under NDA for customers

Request

Security Whitepaper

Technical security overview

Request

Sub-Processor List

Current approved vendors

Request

Need Compliance Assistance?

Our compliance team is available to answer questions, provide documentation for vendor assessments, and help you meet your regulatory requirements.