Skip to content
E·BIZI Pay
Pricing Guides
Sign in Get Started
Pricing Guides
Get Started Sign in
E·BIZI Pay Data Processing Agreement

Data Processing Agreement

Setting out the terms on which E·BIZI Pay processes Personal Information as an Operator on behalf of a Client

Entity: Digital Solution Foundry (Pty) Ltd (Reg No 2017/144872/07) · Effective date: 1 September 2026 · Legislation: Protection of Personal Information Act 4 of 2013 (POPIA)
1. Background 2. Definitions 3. Roles of the Parties 4. Scope, Nature, and Duration of Processing 5. Client Instructions 6. Operator Obligations 7. Sub-Operators 8. Security Measures 9. Security Compromises 10. Assistance with Data Subject Requests 11. Cross-Border Transfers 12. Return and Deletion of Data 13. Audits and Inspection 14. Liability 15. Term and Termination 16. General 17. Contact Details

This Data Processing Agreement (“DPA”) is incorporated by reference into, and forms part of, the Terms of Use concluded between Digital Solution Foundry (Pty) Ltd, registration number 2017/144872/07, trading as E·BIZI Pay (“the Operator”, “we”, “us”), and the Client identified in the applicable Order Form or account registration (“the Responsible Party”, “you”, “the Client”), collectively “the Parties”.

This DPA applies whenever the Client uploads, submits, or otherwise makes available Personal Information relating to third parties (for example, its employees or customers) through the E·BIZI Pay Platform. Where the Operator processes a Client’s own Personal Information as account holder (billing, account administration), the Privacy Notice, not this DPA, applies.

1. Background

The Client wishes to use the E·BIZI Pay platform to process payroll, bookkeeping, identity-verification, and document-management data, which may include Personal Information relating to the Client’s employees, contractors, and customers.

In providing the Services, the Operator will Process Personal Information on behalf of, and in accordance with the instructions of, the Client.

For purposes of POPIA, the Client is the Responsible Party in respect of such Personal Information, and the Operator processes it strictly as an Operator, as those terms are defined in section 1 of POPIA.

The Parties conclude this DPA to record their respective rights and obligations in relation to such Processing, in accordance with sections 20 and 21 of POPIA.

2. Definitions

“Operator” means has the meaning given in section 1 of POPIA, namely a person who Processes Personal Information for a Responsible Party in terms of a contract or mandate, without coming under the direct authority of that party;

“Personal Information” and “Processing” means bear the meanings assigned to them in section 1 of POPIA;

“Responsible Party” means has the meaning given in section 1 of POPIA, namely a public or private body which, alone or in conjunction with others, determines the purpose of and means for Processing Personal Information;

“Security Compromise” means any incident giving rise to a reasonable belief that Personal Information has been accessed or acquired by an unauthorised person, as contemplated in section 22 of POPIA;

“Special Personal Information” means has the meaning given in section 26 of POPIA;

“Sub-Operator” means any third party engaged by the Operator to Process Personal Information on the Operator’s behalf in connection with the Services;

3. Roles of the Parties

The Parties agree and record that, in respect of Personal Information processed through the Platform relating to persons other than the Client itself: (a) the Client is the Responsible Party and determines the purpose and means of Processing; and (b) the Operator Processes such Personal Information solely on behalf of, and in accordance with the instructions of, the Client, save where Processing is required by South African law, in which case the Operator will, to the extent legally permitted, notify the Client of such requirement before Processing.

4. Scope, Nature, and Duration of Processing

4.1 Subject matter and duration

The Operator will Process Personal Information for the duration of the Client’s subscription to the Platform, and thereafter only to the extent necessary to comply with clause 12 (Return and Deletion of Data) or applicable law.

4.2 Nature and purpose

The Operator will Process Personal Information solely for the purpose of providing the Services selected by the Client (payroll processing and bookkeeping) and for no other purpose, save with the Client’s prior written consent or as required by law.

4.3 Categories of data subjects and Personal Information

ModuleCategories of data subjectsCategories of Personal Information
Pay moduleClient’s employees / former employeesName, ID number, banking details, tax number, remuneration, employment history
Books moduleClient’s customers / suppliersName, contact details, banking details, transaction records

5. Client Instructions

The Operator will Process Personal Information only in accordance with the Client’s documented instructions, which shall be constituted by: (a) the Client’s configuration and use of the Platform; (b) the Terms of Use and this DPA; and (c) any further written instructions issued by the Client from time to time. Should the Operator consider that an instruction infringes POPIA or any other applicable law, it will promptly notify the Client and may suspend performance of that instruction pending resolution.

6. Operator Obligations

In accordance with sections 20 and 21 of POPIA, the Operator undertakes to:

  • Process Personal Information only within the scope of, and for the purposes set out in, the Client’s instructions;
  • treat Personal Information as confidential, and ensure that any employee, contractor, or agent authorised to Process Personal Information is subject to a written confidentiality undertaking;
  • implement and maintain the security measures required under clause 8 of this DPA;
  • notify the Client without undue delay of any Security Compromise, in accordance with clause 9;
  • provide reasonable assistance to the Client in responding to data subject requests, as set out in clause 10; and
  • not transfer Personal Information outside the Republic of South Africa other than in accordance with clause 11.

7. Sub-Operators

The Client provides general written authorisation for the Operator to engage Sub-Operators to assist in providing the Services, including cloud hosting, payment gateway, and communications providers. The Operator will:

  • maintain an up-to-date list of Sub-Operators, available to the Client on written request;
  • impose data protection obligations on each Sub-Operator that are no less onerous than those set out in this DPA;
  • remain liable to the Client for the acts and omissions of its Sub-Operators to the same extent as if the acts or omissions were those of the Operator; and
  • notify the Client of any intended change concerning the addition or replacement of a Sub-Operator, providing the Client a reasonable opportunity to object on reasonable data protection grounds.

8. Security Measures

In accordance with section 19 of POPIA, the Operator has implemented, and will maintain, appropriate technical and organisational measures to secure the integrity and confidentiality of Personal Information, including:

  • encryption of Personal Information in transit and at rest;
  • role-based access controls, unique user credentials, and multi-factor authentication for administrative and privileged access;
  • logging and monitoring of access to systems containing Personal Information;
  • regular vulnerability scanning, penetration testing, and patch management;
  • secure, redundant backups with defined restoration procedures;
  • a documented information security policy and incident response plan; and
  • periodic security awareness training for personnel with access to Personal Information.

9. Security Compromises

Where the Operator becomes aware of a Security Compromise affecting Personal Information Processed on the Client’s behalf, the Operator will, in accordance with section 22 of POPIA:

  • notify the Client without undue delay and, where reasonably possible, within seventy-two (72) hours of becoming aware of the Security Compromise;
  • provide the Client with sufficient information to allow the Client to meet its own notification obligations to affected data subjects and the Information Regulator, including the nature of the compromise, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address the compromise;
  • take reasonable steps to contain, investigate, and remediate the Security Compromise; and
  • cooperate with the Client and provide reasonable assistance in respect of any related regulatory notification or investigation.

The Parties record that, as between them, the Client (as Responsible Party) is responsible for notifying the Information Regulator and affected data subjects in accordance with section 22 of POPIA, unless the Parties agree otherwise in writing.

10. Assistance with Data Subject Requests

The Operator will, taking into account the nature of the Processing, provide reasonable assistance to the Client (including by appropriate technical and organisational measures, insofar as this is possible) to enable the Client to respond to requests from data subjects seeking to exercise their rights under Chapter 3 of POPIA, including requests for access, correction, or deletion of Personal Information. Where the Operator receives a data subject request directly, it will promptly forward the request to the Client and will not respond directly save on the Client’s written instruction.

11. Cross-Border Transfers

The Operator will not transfer Personal Information Processed on the Client’s behalf to a recipient located outside the Republic of South Africa, save: (a) where the recipient is subject to a law, binding corporate rules, or binding agreement that upholds principles for the reasonable processing of Personal Information substantially similar to POPIA’s conditions for lawful processing, as required by section 72 of POPIA; or (b) in accordance with an applicable exception under section 72(1) of POPIA. Where the Operator engages a Sub-Operator located outside South Africa (for example, an offshore cloud hosting provider), the Operator will ensure that appropriate contractual safeguards are in place with that Sub-Operator prior to any transfer.

12. Return and Deletion of Data

On termination or expiry of the Client’s subscription to the Platform, the Operator will make Client Data, including Personal Information, available to the Client for export for a period of thirty (30) days. Following expiry of that period, the Operator will securely delete or de-identify all Personal Information Processed on the Client’s behalf, save to the extent that retention is required by South African law (for example, statutory retention periods applicable to payroll or tax records), in which case the Operator will continue to protect such Personal Information in accordance with this DPA for the duration of the required retention period.

13. Audits and Inspection

The Operator will make available to the Client, on reasonable written request and no more than once per twelve (12) month period (save where required following a Security Compromise), information reasonably necessary to demonstrate compliance with this DPA, which may include relevant security certifications, audit summaries, or completion of a reasonable security questionnaire. Any on-site audit shall be conducted on reasonable prior notice, during business hours, subject to the Operator’s reasonable confidentiality and security requirements, and at the Client’s cost.

14. Liability

The liability of each Party arising out of or in connection with this DPA shall be governed by the limitation of liability and indemnity provisions of the Terms of Use. Nothing in this DPA limits either Party’s liability for its own breach of POPIA to the extent such liability cannot lawfully be limited or excluded.

15. Term and Termination

This DPA takes effect on the date the Client first uploads Personal Information to the Platform and remains in force for as long as the Operator Processes Personal Information on the Client’s behalf, notwithstanding termination of the Terms of Use, until such Processing ceases in accordance with clause 12.

16. General

16.1 Precedence

In the event of any conflict between this DPA and the Terms of Use in relation to the Processing of Personal Information, this DPA shall prevail.

16.2 Governing law

This DPA is governed by the laws of the Republic of South Africa either party shall be entitled to institute legal proceedings in a court of competent jurisdiction.

16.3 Amendment

The Operator may update this DPA from time to time to reflect changes in applicable law or its Processing practices, by publishing an updated version on the Platform and providing reasonable notice to the Client.

17. Contact Details

Queries relating to this DPA should be directed to:

Digital Solution Foundry (Pty) Ltd

Attention: The Information Officer

Reg No 2017/144872/07

Parktown, Johannesburg, South Africa

Email: paulinah@digitalsolutionfoundry.co.za and timile@digitalsolutionfoundry.co.za

E·BIZI Pay

Payroll built in South Africa, made for small businesses.

Resources

  • Guides
  • Press kit
  • Help centre

Legal

  • Terms
  • Privacy
  • Data processing
© 2026 E·BIZI Pay · Digital Solution Foundry · Made in South Africa
Facebook