Draft for Legal ReviewThis document is unapproved scaffolding prepared for review by a South African attorney. It is not legal advice and must not be relied upon or published until every placeholder token (e.g. {{LEGAL_ENTITY}}) is filled and the stamp is removed at sign-off.

POPIA s20–21 — Operator processing

Data Processing Addendum

How {{LEGAL_ENTITY}} processes personal information as operator on a subscriber's behalf through the Serve Station Job Card System. Draft for Legal Review — pending attorney sign-off.

Effective date: {{EFFECTIVE_DATE}}

This Addendum is effective from {{EFFECTIVE_DATE}} and forms part of the Terms of Service.

1. Roles of the parties

Responsible party
The subscriber (the organisation using the service)
Operator
{{LEGAL_ENTITY}} (registration {{REG_NUMBER}})
Operator contact
{{IO_EMAIL}}

For personal information processed through the service on the subscriber's behalf, the subscriber is the responsible party and {{LEGAL_ENTITY}} is the operator under sections 20–21 of the Protection of Personal Information Act 4 of 2013 (POPIA). The subscriber determines the purpose and means; we process only to provide the service and on the subscriber's instructions.

2. Processing on documented instruction

We process personal information only:

  • to provide, maintain and support the service;
  • in accordance with the subscriber's documented instructions, including the configuration choices made in the service; and
  • as required by law, in which case we inform the subscriber unless legally prohibited.

We do not process personal information for our own purposes and we do not sell it.

3. Confidentiality

Personnel authorised to process personal information are bound by confidentiality obligations and are made aware of the confidential nature of the information. Access is limited to personnel who need it to provide the service.

4. Security measures (POPIA s19)

Taking into account the nature of the processing, we maintain appropriate, reasonable technical and organisational measures to secure the integrity and confidentiality of personal information, including:

  • encryption of personal information in transit and at rest;
  • tenant isolation enforced on every request (row-level security), so each organisation's data is logically separated;
  • role-based access control on a least-privilege basis, with securely hashed credentials;
  • append-only audit logging of key actions and status changes;
  • secure file handling — access-controlled storage, file type, size and content-shape validation of uploads, and short-lived signed access links; and
  • continuous backups, monitoring and a resilient hosting environment.

5. Sub-operators

The subscriber authorises us to engage sub-operators to support the service. We engage sub-operators only within the categories below, impose data-protection and security obligations on each that are substantially similar to those in this Addendum, and remain responsible for their performance:

  • cloud hosting & database;
  • file & object storage;
  • authentication and session management;
  • transactional email delivery; and
  • monitoring, backups and the deployment pipeline.

The current operator register and signed-agreement status are maintained in the POPIA Information Manual. We give reasonable notice of any intended change so the subscriber may object on reasonable grounds.

6. Assisting the responsible party

Taking into account the nature of the processing, we provide reasonable assistance to enable the subscriber to:

  • respond to data-subject requests under POPIA (access, correction, deletion, objection);
  • meet its own security, notification and compliance obligations; and
  • where a data subject contacts us directly about data we process for the subscriber, we refer the request to the subscriber rather than respond ourselves, except on instruction or as required by law.

Requests to us under this Addendum may be sent to {{IO_EMAIL}}.

7. Security-compromise notification (POPIA s22)

If we become aware of a security compromise affecting personal information processed under this Addendum, we notify the subscriber without undue delay and provide the information reasonably available to us to help the subscriber meet its notification obligations to the Information Regulator and affected data subjects. We take reasonable steps to investigate, mitigate and remediate.

8. Cross-border processing (POPIA s72)

We aim to process and store personal information within South Africa. Where any processing occurs outside South Africa, we ensure an appropriate basis under section 72 of POPIA exists and that the information receives a level of protection substantially similar to that required under POPIA.

9. Return & deletion of data

Personal information is retained in accordance with the retention settings configured by the subscriber and the retention provisions of our Privacy Policy. On termination, and on the subscriber's request made within a reasonable period, we make customer data available for export and then delete or de-identify it, except where retention is required by law. On deletion we remove both the database record and any associated stored file while preserving the immutable audit trail required for accountability.

10. Records & audits

We maintain records of our processing sufficient to demonstrate compliance with this Addendum and make available to the subscriber information reasonably necessary to demonstrate such compliance. The subscriber may, on reasonable prior notice and no more than once per year (unless required by the Information Regulator or following a security compromise), request a reasonable audit, which may be satisfied through up-to-date documentation or a written questionnaire response.

Annex A — Details of processing

Subject-matter
Provision of the Serve Station Job Card System to the subscriber.
Duration
For the term of the subscriber's use of the service, plus any applicable retention period.
Nature & purpose
Hosting, storage, transmission, organisation, retrieval and display of customer data to deliver job management, evidence capture and reporting.
Categories of data subjects
The subscriber's customers and their contacts; individuals appearing in on-site photos; the subscriber's staff and technicians.
Types of personal information
Names and contact details; site addresses and access notes; optional location coordinates; job details, notes and work summaries; on-site photographs; customer signatures and sign-off records; interaction logs; uploaded documents; user account details and roles; and related audit, log and usage data.
Special personal information
Not intended to be processed; the subscriber must not submit special categories of personal information except where strictly necessary and lawful.