Data Processing Agreement
Setting out the terms on which E·BIZI Pay processes Personal Information as an Operator on behalf of a Client
This Data Processing Agreement (“DPA”) is incorporated by reference into, and forms part of, the Terms of Use concluded between Digital Solution Foundry (Pty) Ltd, registration number 2017/144872/07, trading as E·BIZI Pay (“the Operator”, “we”, “us”), and the Client identified in the applicable Order Form or account registration (“the Responsible Party”, “you”, “the Client”), collectively “the Parties”.
This DPA applies whenever the Client uploads, submits, or otherwise makes available Personal Information relating to third parties (for example, its employees or customers) through the E·BIZI Pay Platform. Where the Operator processes a Client’s own Personal Information as account holder (billing, account administration), the Privacy Notice, not this DPA, applies.
1. Background
The Client wishes to use the E·BIZI Pay platform to process payroll, bookkeeping, identity-verification, and document-management data, which may include Personal Information relating to the Client’s employees, contractors, and customers.
In providing the Services, the Operator will Process Personal Information on behalf of, and in accordance with the instructions of, the Client.
For purposes of POPIA, the Client is the Responsible Party in respect of such Personal Information, and the Operator processes it strictly as an Operator, as those terms are defined in section 1 of POPIA.
The Parties conclude this DPA to record their respective rights and obligations in relation to such Processing, in accordance with sections 20 and 21 of POPIA.
2. Definitions
“Operator” means has the meaning given in section 1 of POPIA, namely a person who Processes Personal Information for a Responsible Party in terms of a contract or mandate, without coming under the direct authority of that party;
“Personal Information” and “Processing” means bear the meanings assigned to them in section 1 of POPIA;
“Responsible Party” means has the meaning given in section 1 of POPIA, namely a public or private body which, alone or in conjunction with others, determines the purpose of and means for Processing Personal Information;
“Security Compromise” means any incident giving rise to a reasonable belief that Personal Information has been accessed or acquired by an unauthorised person, as contemplated in section 22 of POPIA;
“Special Personal Information” means has the meaning given in section 26 of POPIA;
“Sub-Operator” means any third party engaged by the Operator to Process Personal Information on the Operator’s behalf in connection with the Services;
3. Roles of the Parties
The Parties agree and record that, in respect of Personal Information processed through the Platform relating to persons other than the Client itself: (a) the Client is the Responsible Party and determines the purpose and means of Processing; and (b) the Operator Processes such Personal Information solely on behalf of, and in accordance with the instructions of, the Client, save where Processing is required by South African law, in which case the Operator will, to the extent legally permitted, notify the Client of such requirement before Processing.
4. Scope, Nature, and Duration of Processing
4.1 Subject matter and duration
The Operator will Process Personal Information for the duration of the Client’s subscription to the Platform, and thereafter only to the extent necessary to comply with clause 12 (Return and Deletion of Data) or applicable law.
4.2 Nature and purpose
The Operator will Process Personal Information solely for the purpose of providing the Services selected by the Client (payroll processing and bookkeeping) and for no other purpose, save with the Client’s prior written consent or as required by law.
4.3 Categories of data subjects and Personal Information
| Module | Categories of data subjects | Categories of Personal Information |
|---|---|---|
| Pay module | Client’s employees / former employees | Name, ID number, banking details, tax number, remuneration, employment history |
| Books module | Client’s customers / suppliers | Name, contact details, banking details, transaction records |
5. Client Instructions
The Operator will Process Personal Information only in accordance with the Client’s documented instructions, which shall be constituted by: (a) the Client’s configuration and use of the Platform; (b) the Terms of Use and this DPA; and (c) any further written instructions issued by the Client from time to time. Should the Operator consider that an instruction infringes POPIA or any other applicable law, it will promptly notify the Client and may suspend performance of that instruction pending resolution.
6. Operator Obligations
In accordance with sections 20 and 21 of POPIA, the Operator undertakes to:
- Process Personal Information only within the scope of, and for the purposes set out in, the Client’s instructions;
- treat Personal Information as confidential, and ensure that any employee, contractor, or agent authorised to Process Personal Information is subject to a written confidentiality undertaking;
- implement and maintain the security measures required under clause 8 of this DPA;
- notify the Client without undue delay of any Security Compromise, in accordance with clause 9;
- provide reasonable assistance to the Client in responding to data subject requests, as set out in clause 10; and
- not transfer Personal Information outside the Republic of South Africa other than in accordance with clause 11.
7. Sub-Operators
The Client provides general written authorisation for the Operator to engage Sub-Operators to assist in providing the Services, including cloud hosting, payment gateway, and communications providers. The Operator will:
- maintain an up-to-date list of Sub-Operators, available to the Client on written request;
- impose data protection obligations on each Sub-Operator that are no less onerous than those set out in this DPA;
- remain liable to the Client for the acts and omissions of its Sub-Operators to the same extent as if the acts or omissions were those of the Operator; and
- notify the Client of any intended change concerning the addition or replacement of a Sub-Operator, providing the Client a reasonable opportunity to object on reasonable data protection grounds.
8. Security Measures
In accordance with section 19 of POPIA, the Operator has implemented, and will maintain, appropriate technical and organisational measures to secure the integrity and confidentiality of Personal Information, including:
- encryption of Personal Information in transit and at rest;
- role-based access controls, unique user credentials, and multi-factor authentication for administrative and privileged access;
- logging and monitoring of access to systems containing Personal Information;
- regular vulnerability scanning, penetration testing, and patch management;
- secure, redundant backups with defined restoration procedures;
- a documented information security policy and incident response plan; and
- periodic security awareness training for personnel with access to Personal Information.
9. Security Compromises
Where the Operator becomes aware of a Security Compromise affecting Personal Information Processed on the Client’s behalf, the Operator will, in accordance with section 22 of POPIA:
- notify the Client without undue delay and, where reasonably possible, within seventy-two (72) hours of becoming aware of the Security Compromise;
- provide the Client with sufficient information to allow the Client to meet its own notification obligations to affected data subjects and the Information Regulator, including the nature of the compromise, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address the compromise;
- take reasonable steps to contain, investigate, and remediate the Security Compromise; and
- cooperate with the Client and provide reasonable assistance in respect of any related regulatory notification or investigation.
The Parties record that, as between them, the Client (as Responsible Party) is responsible for notifying the Information Regulator and affected data subjects in accordance with section 22 of POPIA, unless the Parties agree otherwise in writing.
10. Assistance with Data Subject Requests
The Operator will, taking into account the nature of the Processing, provide reasonable assistance to the Client (including by appropriate technical and organisational measures, insofar as this is possible) to enable the Client to respond to requests from data subjects seeking to exercise their rights under Chapter 3 of POPIA, including requests for access, correction, or deletion of Personal Information. Where the Operator receives a data subject request directly, it will promptly forward the request to the Client and will not respond directly save on the Client’s written instruction.
11. Cross-Border Transfers
The Operator will not transfer Personal Information Processed on the Client’s behalf to a recipient located outside the Republic of South Africa, save: (a) where the recipient is subject to a law, binding corporate rules, or binding agreement that upholds principles for the reasonable processing of Personal Information substantially similar to POPIA’s conditions for lawful processing, as required by section 72 of POPIA; or (b) in accordance with an applicable exception under section 72(1) of POPIA. Where the Operator engages a Sub-Operator located outside South Africa (for example, an offshore cloud hosting provider), the Operator will ensure that appropriate contractual safeguards are in place with that Sub-Operator prior to any transfer.
12. Return and Deletion of Data
On termination or expiry of the Client’s subscription to the Platform, the Operator will make Client Data, including Personal Information, available to the Client for export for a period of thirty (30) days. Following expiry of that period, the Operator will securely delete or de-identify all Personal Information Processed on the Client’s behalf, save to the extent that retention is required by South African law (for example, statutory retention periods applicable to payroll or tax records), in which case the Operator will continue to protect such Personal Information in accordance with this DPA for the duration of the required retention period.
13. Audits and Inspection
The Operator will make available to the Client, on reasonable written request and no more than once per twelve (12) month period (save where required following a Security Compromise), information reasonably necessary to demonstrate compliance with this DPA, which may include relevant security certifications, audit summaries, or completion of a reasonable security questionnaire. Any on-site audit shall be conducted on reasonable prior notice, during business hours, subject to the Operator’s reasonable confidentiality and security requirements, and at the Client’s cost.
14. Liability
The liability of each Party arising out of or in connection with this DPA shall be governed by the limitation of liability and indemnity provisions of the Terms of Use. Nothing in this DPA limits either Party’s liability for its own breach of POPIA to the extent such liability cannot lawfully be limited or excluded.
15. Term and Termination
This DPA takes effect on the date the Client first uploads Personal Information to the Platform and remains in force for as long as the Operator Processes Personal Information on the Client’s behalf, notwithstanding termination of the Terms of Use, until such Processing ceases in accordance with clause 12.
16. General
16.1 Precedence
In the event of any conflict between this DPA and the Terms of Use in relation to the Processing of Personal Information, this DPA shall prevail.
16.2 Governing law
This DPA is governed by the laws of the Republic of South Africa either party shall be entitled to institute legal proceedings in a court of competent jurisdiction.
16.3 Amendment
The Operator may update this DPA from time to time to reflect changes in applicable law or its Processing practices, by publishing an updated version on the Platform and providing reasonable notice to the Client.
17. Contact Details
Queries relating to this DPA should be directed to:
Digital Solution Foundry (Pty) Ltd
Attention: The Information Officer
Reg No 2017/144872/07
Parktown, Johannesburg, South Africa
Email: paulinah@digitalsolutionfoundry.co.za and timile@digitalsolutionfoundry.co.za