Data Processing Agreement
Last updated: 1 July 2026
1. Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between InnoVisions ("Processor") and the Customer ("Controller") and governs the processing of personal data by the Processor on behalf of the Controller. This DPA reflects the requirements of the Protection of Personal Information Act (POPIA) of South Africa and the EU General Data Protection Regulation (GDPR).
2. Definitions
- Controller: The Customer who determines the purposes and means of processing personal data
- Processor: InnoVisions, which processes personal data on behalf of the Controller
- Personal Data: Any information relating to an identified or identifiable natural person
- Processing: Any operation performed on personal data, including collection, storage, use, and deletion
- Data Subject: The individual to whom the personal data relates
- Sub-processor: A third party engaged by the Processor to assist in processing activities
3. Processing Details
3.1 Nature and purpose of processing: The Processor will process personal data to provide the InnoVisions platform and related services, including data storage, processing, analytics, and support.
3.2 Categories of data subjects: The Controller's customers, employees, suppliers, and other business contacts whose data is entered into the platform.
3.3 Types of personal data: Names, contact details, identification numbers, financial information, employment details, and other business-related personal data as determined by the Controller.
3.4 Duration of processing: For the duration of the Service agreement unless otherwise agreed.
4. Processor Obligations
The Processor shall:
- Process personal data only on documented instructions from the Controller
- Ensure that persons authorised to process the data are subject to confidentiality obligations
- Implement appropriate technical and organisational security measures
- Not engage another sub-processor without prior notice and an opportunity to object
- Assist the Controller in fulfilling its obligations regarding data subject rights
- Assist with data breach notification as required by applicable law
- Delete or return all personal data at the end of the Service term
- Make available all information necessary to demonstrate compliance with this DPA
5. Security Measures
The Processor maintains the following security measures:
- Access control: Role-based access with named permissions and least-privilege principles; passwords stored as one-way (bcrypt) hashes; login attempts limited per IP address
- Separation: Each customer company's data is held in its own database
- Encryption and backup: Encrypted connections (HTTPS) and regular backups on the hosting operated by the Processor
- Audit trail: Every change made through the system is logged with the user and time
- Security compromises: The Controller is notified as soon as reasonably possible after a compromise is discovered, as required by section 22 of POPIA
6. Sub-processors
The Controller authorises the engagement of the following sub-processors:
- Cloud infrastructure provider: For hosting and data storage
- Payment gateway: For card payments made through the customer portal, if used
- Email delivery service: For transactional and notification emails
- AI service provider (OpenAI, United States): Only if the optional AI assistant is switched on
The Processor will notify the Controller of any intended changes to sub-processors and provide an opportunity to object.
7. Data Subject Rights
The Processor shall assist the Controller in responding to data subject requests under POPIA and GDPR, including:
- Right of access to personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to data portability
- Right to object to processing
8. Data Breach Notification
The Processor shall notify the Controller without undue delay (and within 24 hours of becoming aware) of any personal data breach. The notification shall include:
- The nature of the breach
- The categories and approximate number of data subjects affected
- The likely consequences of the breach
- The measures taken or proposed to address the breach
9. International Data Transfers
Where personal data is transferred to countries outside South Africa, the Processor shall ensure appropriate safeguards are in place, including standard contractual clauses or equivalent transfer mechanisms recognised under POPIA and GDPR.
10. Audit Rights
The Processor shall make available all information necessary to demonstrate compliance with this DPA. Upon reasonable request, the Controller may audit the Processor's compliance, subject to confidentiality obligations and at the Controller's expense.
11. Data Retention and Deletion
Upon termination of the Service, the Controller may request a full data export within 30 days. After 90 days from termination, the Processor shall permanently delete all personal data unless retention is required by applicable law.
12. Liability
Each party's liability under this DPA shall be subject to the limitations set out in the Terms of Service. The Processor's liability for data processing activities shall be limited to direct damages arising from its failure to comply with its obligations under this DPA or applicable data protection law.
13. Governing Law
This DPA is governed by the laws of the Republic of South Africa.
14. Contact
InnoVisions
South Africa