Legal
Data Protection Addendum
Addendum describing how personal data is handled for partners and processors working with ZENAPLAY / FidelFlow Group.
Last updated: 22 July 2026
1. Purpose of this addendum
This Data Protection Addendum (“DPA”) supplements our Privacy Policy and any commercial agreement with a partner, publisher, developer, or service provider (“Partner”) that involves personal data connected to ZENAPLAY.
A signed commercial agreement may include a more detailed DPA. Until then, this page states our baseline expectations.
2. Roles
Depending on the activity, FidelFlow Group / ZENAPLAY may act as a data controller for waitlist and platform user data, and a Partner may act as an independent controller or as a processor on our documented instructions.
3. Partner obligations
Partners that receive or process personal data through ZENAPLAY-related work must:
- Process data only for the agreed purpose and lawful basis.
- Apply appropriate technical and organizational security measures.
- Not sell personal data or use it for unrelated marketing.
- Notify us without undue delay of a personal-data breach affecting ZENAPLAY data.
- Assist with data-subject requests where reasonably required.
- Return or delete personal data when the engagement ends, unless law requires retention.
4. International transfers
If processing involves transfer outside Ethiopia, Partners must use lawful transfer mechanisms and protect the data to a standard consistent with applicable Ethiopian requirements and any additional safeguards we specify in writing.
5. Sub-processors
Processors may not engage sub-processors for ZENAPLAY personal data without prior written authorization and a written flow-down of equivalent protections.
6. Contact
Data-protection coordination: Abel.kebede@fidelflowgroup.com.et / reta.belay@fidelflowgroup.com.et.
