1. Application and definitions
“Data Protection Law” means applicable privacy and data-protection law, including POPIA, GDPR, UK GDPR and applicable US state privacy laws. “Customer Personal Data” means personal data contained in Customer Data and processed by Paurtal as processor, operator or service provider. Terms such as controller, processor, data subject and personal data have the meanings given by applicable law.
2. Processing instructions
Paurtal will process Customer Personal Data only on documented instructions contained in the agreement, customer configurations and authorised support requests, unless law requires otherwise. Paurtal will notify the customer if an instruction appears to violate Data Protection Law, unless prohibited. Customer is responsible for lawful instructions, transparency, legal bases, consent and responding as controller.
Personnel processing Customer Personal Data are subject to confidentiality obligations. Paurtal will not sell Customer Personal Data, retain/use/disclose it outside the business relationship except as permitted by law, or combine it with unrelated personal data except to provide and secure the Services as legally permitted.
3. Security measures
Paurtal will maintain measures appropriate to risk, including access control and least privilege; authentication controls; encryption in transit and appropriate encryption at rest; tenant and environment separation; logging and monitoring; secure development and change management; vulnerability and patch management; backups and recovery; vendor risk management; confidentiality training; and incident-response procedures.
4. Subprocessors
Customer authorises Paurtal to appoint subprocessors needed to provide the Services, including providers of cloud hosting, databases, authentication, communications, Meta/WhatsApp connectivity, AI, payments, analytics and support. Paurtal will impose data-protection obligations materially consistent with this DPA and remains responsible for their performance to the extent required by law.
Paurtal will maintain a current subprocessor list and provide reasonable notice of material additions. Customer may object on reasonable data-protection grounds within 15 days; the parties will seek a practical resolution, which may include disabling the affected feature or terminating it without penalty where no reasonable alternative exists.
5. Assistance and compliance
Taking account of the nature of processing, Paurtal will reasonably assist the customer with data-subject requests, security, breach notifications, data-protection impact assessments and regulator consultations. Customer remains responsible for determining whether these obligations apply and may be charged reasonable costs for exceptional assistance beyond standard functionality.
6. Personal data incidents
Paurtal will notify the customer without undue delay after confirming a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Customer Personal Data. Notice will include available information reasonably required for the customer’s obligations. Paurtal’s notice is not an admission of fault. Customer is responsible for notifications to individuals and authorities unless law assigns that duty to Paurtal.
7. International transfers
Where restricted transfers occur, the parties incorporate the then-current standard contractual clauses or other valid transfer mechanism applicable to the transfer. For EEA transfers, the EU controller-to-processor clauses apply as appropriate; for UK transfers, the applicable UK addendum applies. Paurtal will implement supplementary safeguards where reasonably required and comply with POPIA section 72 for transfers from South Africa.
8. Return and deletion
During the subscription, customer may use available export tools. Following termination or written instruction, Paurtal will delete or return Customer Personal Data within a commercially reasonable period, unless retention is legally required. Data in backups will remain protected, unavailable for ordinary use and deleted through normal rotation.
9. Information and audits
Paurtal will provide information reasonably necessary to demonstrate compliance, such as security summaries or independent reports when available. If that is insufficient, customer may conduct one audit per year on reasonable written notice, during business hours, subject to confidentiality, security and non-disruption requirements. Customer bears audit costs unless the audit identifies a material breach by Paurtal.
10. Processing details
| Subject matter | Provision of the contracted Paurtal Services. |
|---|---|
| Duration | Agreement term plus limited deletion, backup and legally required retention periods. |
| Nature and purpose | Hosting, organising, transmitting, analysing, automating, securing, supporting, exporting and deleting data as instructed. |
| Data subjects | Customer users, contacts, leads, consumers, message recipients, event attendees, suppliers and other individuals submitted by customer. |
| Data types | Identifiers, contact and profile details, messages and media, CRM fields, consent records, transaction references, event data, support data, device/log data and customer-configured fields. |
| Sensitive data | Not intended unless expressly supported and lawfully configured by customer. |
Legal notices concerning this DPA may be sent to privacy@paurtal.com.