← Back to Creative Research Associates Ltd
Trust & Legal Center
CREATIVE RESEARCH ASSOCIATES
Corporate Finance · Sovereign Telemetry · AI Enclaves
DOCUMENT: CRA-DPA-2026
CLASSIFICATION: OFFICIAL REGULATORY NOTICE
VERSION: Version 2026.1 · Build 104
INSTITUTIONAL DATA PROCESSING ADDENDUM

Data Processing Addendum (DPA)

Institutional Controller-to-Processor Agreement (Ghana • Nigeria • Sierra Leone • The Gambia • Liberia • ECOWAS • UK/EU GDPR)

INSTITUTIONAL CONTROLLER-TO-PROCESSOR COVENANTS: This Data Processing Addendum (“DPA”) governs the processing of personal, commercial, and sovereign telemetry data by Creative Research Associates Ltd (“CRA” or “Data Processor”) on behalf of the Client (“Data Controller”). CRA operates under isolated private analytical enclaves with AES-256 encryption at rest, TLS 1.3 in transit, a strict 36-hour breach notification SLA, and an absolute, irrevocable prohibition on public AI training.

1. Scope, Purpose & Statutory Context

1.1. Context: In providing macroeconomic diagnostics, dynamic financial modeling, sovereign investment portals, and virtual data rooms (VDRs), CRA processes certain data on behalf of the Data Controller.

1.2. Statutory Adherence: This DPA establishes the binding data protection covenants of the Parties pursuant to:

Jurisdiction / Organization Governing Data Protection & Cybersecurity Legislation
Republic of Ghana Data Protection Act, 2012 (Act 843)
Federal Republic of Nigeria Nigeria Data Protection Act, 2023 (NDPA)
Republic of Sierra Leone National Communications Authority Act, 2022 (NatCA Act 2022), Cybersecurity and Crime Act, 2021 (Act No. 7 of 2021), and Right to Access Information Act, 2013
Republic of The Gambia Information and Communications Act, 2009 (ICA 2009, Part VII), Data Protection and Privacy Act, 2024, and Cybercrime Act, 2023
Republic of Liberia Telecommunications Act of 2007 (Part VI & Section 48) and Freedom of Information Act, 2010
Regional ECOWAS ECOWAS Supplementary Act A/SA.1/01/10 on Personal Data Protection
African Union African Union Convention on Cyber Security and Personal Data Protection (Malabo Convention)
International (UK / EU) United Kingdom Data Protection Act 2018 (UK GDPR) and Regulation (EU) 2016/679 (EU GDPR)

2. Processing Obligations & Instructions

2.1. Processing on Documented Instructions Only: The Data Processor shall process Personal Data exclusively on the documented instructions of the Data Controller, as set forth in the Principal Agreement and relevant Statement of Work (SOW), unless required to do so by applicable statutory law.

2.2. Purpose Limitation: Processing shall occur solely for the delivery of corporate finance analysis, 3-statement financial modeling, deal room management, and sovereign portal hosting, and for no other commercial or secondary analytical purpose.

SECTION 2.3 — IRREVOCABLE PROHIBITION ON PUBLIC AI TRAINING:

The Data Processor shall not input, upload, transmit, or process any Personal Data, financial statements, or sovereign records into any third-party, commercial, or public artificial intelligence model or large language model (LLM) (including platforms operated by OpenAI, Google, Anthropic, Microsoft, or Meta) that retains, shares, logs, or utilizes user data for algorithmic training or model fine-tuning. All computational modeling pipelines operate exclusively within private, air-gapped enclaves with frozen parameters.

3. Technical & Organizational Measures (TOMs)

The Data Processor implements and maintains rigorous technical and organizational measures to ensure an institutional level of security appropriate to sovereign and corporate finance risks:

Security Domain Technical & Organizational Control Baseline
1. Cryptographic Protection AES-256 bit encryption for all personal, financial, and deal records at rest; TLS 1.3 transport encryption with perfect forward secrecy across all communications.
2. Access Governance Strict Role-Based Access Control (RBAC) enforcing least-privilege principles; mandatory hardware-backed Multi-Factor Authentication (MFA); 90-day automated credential rotation.
3. Logical Segregation Multi-tenant database segregation and encrypted containerized partitioning ensuring Data Controller records remain fully isolated from other client datasets.
4. Personnel Integrity All CRA analysts, econometricians, and senior modeling associates with access to Personal Data are subject to binding non-disclosure agreements and comprehensive background checks.

4. Sub-Processors & Infrastructure Governance

4.1. Authorized Sub-Processors: The Data Controller authorizes the Data Processor to engage vetted third-party cloud infrastructure providers (e.g., ISO 27001 and SOC 2 Type II certified data centers) strictly as necessary to deliver the hosted services.

4.2. Contractual Flow-Down: Where CRA engages a sub-processor, it shall impose data protection obligations no less stringent than those set forth in this DPA by way of a formal, written contract.

4.3. Full Processor Liability: The Data Processor remains fully liable to the Data Controller for the performance of each sub-processor’s obligations.

5. Security Incident & Breach Notification SLA (36-Hour SLA)

RAPID NOTIFICATION COVENANT: In the event of a confirmed Personal Data Breach impacting Data Controller records, CRA shall notify the Data Controller without undue delay, and in any event within thirty-six (36) hours of becoming aware of the incident.

5.2. Breach Dossier: The written notification shall include:

6. Data Subject Rights & Regulatory Assistance

The Data Processor shall assist the Data Controller, insofar as technically feasible, in responding to requests from data subjects exercising their statutory rights under applicable privacy legislation (including rights of access, rectification, erasure, data portability, and objection under Ghana DPA, Nigeria NDPA, Sierra Leone NatCA, Gambia ICA/DPA, Liberia Telecommunications rules, ECOWAS Community law, and UK/EU GDPR).

7. Deletion & Return of Personal Data

Upon termination of the Principal Agreement or completion of the relevant services, the Data Processor shall, at the choice of the Data Controller, securely return or permanently delete all Personal Data, certifying completion in writing within thirty (30) days, unless applicable statutory law requires retention.

8. Governing Law & Precedence

This DPA is governed by the law governing the Principal Agreement (primarily England and Wales, or the Republic of Ghana for regional public sector mandates). In the event of any conflict between this DPA and the Principal Agreement regarding data protection, this DPA shall take precedence.

CREATIVE RESEARCH ASSOCIATES LTD
Joseph A T Demby, MBA, CFA
Founder & Managing Director
Headquarters: London, UK
LEGAL & REGULATORY DESK
Corporate Legal Affairs Group
info@creativeresearch.associates
Version 2026.1 · Build 104