Legal centre

Data Processing Addendum

Data-protection terms for personal data Paurtal processes on behalf of customers.

Effective and last updated: 23 July 2026
This DPA forms part of the agreement between the customer (“Controller”) and Paurtal South Africa (Pty) Ltd (“Processor”) when Paurtal processes Customer Personal Data on the customer’s behalf.

1. Application and definitions

“Data Protection Law” means applicable privacy and data-protection law, including POPIA, GDPR, UK GDPR and applicable US state privacy laws. “Customer Personal Data” means personal data contained in Customer Data and processed by Paurtal as processor, operator or service provider. Terms such as controller, processor, data subject and personal data have the meanings given by applicable law.

2. Processing instructions

Paurtal will process Customer Personal Data only on documented instructions contained in the agreement, customer configurations and authorised support requests, unless law requires otherwise. Paurtal will notify the customer if an instruction appears to violate Data Protection Law, unless prohibited. Customer is responsible for lawful instructions, transparency, legal bases, consent and responding as controller.

Personnel processing Customer Personal Data are subject to confidentiality obligations. Paurtal will not sell Customer Personal Data, retain/use/disclose it outside the business relationship except as permitted by law, or combine it with unrelated personal data except to provide and secure the Services as legally permitted.

3. Security measures

Paurtal will maintain measures appropriate to risk, including access control and least privilege; authentication controls; encryption in transit and appropriate encryption at rest; tenant and environment separation; logging and monitoring; secure development and change management; vulnerability and patch management; backups and recovery; vendor risk management; confidentiality training; and incident-response procedures.

4. Subprocessors

Customer authorises Paurtal to appoint subprocessors needed to provide the Services, including providers of cloud hosting, databases, authentication, communications, Meta/WhatsApp connectivity, AI, payments, analytics and support. Paurtal will impose data-protection obligations materially consistent with this DPA and remains responsible for their performance to the extent required by law.

Paurtal will maintain a current subprocessor list and provide reasonable notice of material additions. Customer may object on reasonable data-protection grounds within 15 days; the parties will seek a practical resolution, which may include disabling the affected feature or terminating it without penalty where no reasonable alternative exists.

5. Assistance and compliance

Taking account of the nature of processing, Paurtal will reasonably assist the customer with data-subject requests, security, breach notifications, data-protection impact assessments and regulator consultations. Customer remains responsible for determining whether these obligations apply and may be charged reasonable costs for exceptional assistance beyond standard functionality.

6. Personal data incidents

Paurtal will notify the customer without undue delay after confirming a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Customer Personal Data. Notice will include available information reasonably required for the customer’s obligations. Paurtal’s notice is not an admission of fault. Customer is responsible for notifications to individuals and authorities unless law assigns that duty to Paurtal.

7. International transfers

Where restricted transfers occur, the parties incorporate the then-current standard contractual clauses or other valid transfer mechanism applicable to the transfer. For EEA transfers, the EU controller-to-processor clauses apply as appropriate; for UK transfers, the applicable UK addendum applies. Paurtal will implement supplementary safeguards where reasonably required and comply with POPIA section 72 for transfers from South Africa.

8. Return and deletion

During the subscription, customer may use available export tools. Following termination or written instruction, Paurtal will delete or return Customer Personal Data within a commercially reasonable period, unless retention is legally required. Data in backups will remain protected, unavailable for ordinary use and deleted through normal rotation.

9. Information and audits

Paurtal will provide information reasonably necessary to demonstrate compliance, such as security summaries or independent reports when available. If that is insufficient, customer may conduct one audit per year on reasonable written notice, during business hours, subject to confidentiality, security and non-disruption requirements. Customer bears audit costs unless the audit identifies a material breach by Paurtal.

10. Processing details

Subject matterProvision of the contracted Paurtal Services.
DurationAgreement term plus limited deletion, backup and legally required retention periods.
Nature and purposeHosting, organising, transmitting, analysing, automating, securing, supporting, exporting and deleting data as instructed.
Data subjectsCustomer users, contacts, leads, consumers, message recipients, event attendees, suppliers and other individuals submitted by customer.
Data typesIdentifiers, contact and profile details, messages and media, CRM fields, consent records, transaction references, event data, support data, device/log data and customer-configured fields.
Sensitive dataNot intended unless expressly supported and lawfully configured by customer.

Legal notices concerning this DPA may be sent to privacy@paurtal.com.