sendbaze
Menu

Data Processing Agreement

Version 1.0, effective 22 September 2026

In short: This agreement applies automatically to every customer and sets out how Sendbaze, as your operator under POPIA, processes the personal information you send through the Service. It covers instructions, security, sub-operators, breach notification, assistance and deletion.

1. Parties and scope

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Sendbaze (Pty) Ltd, registration number 2026/758394/07 ("Operator") and the Customer ("Responsible Party"). It applies to all personal information contained in Customer Content that the Operator processes on behalf of the Responsible Party in providing the Service.

Terms such as "personal information", "processing", "responsible party" and "operator" have the meanings given in the Protection of Personal Information Act, 2013 ("POPIA"). Where the Responsible Party is subject to the GDPR for some recipients, the Operator processes as a "processor" and this DPA is read accordingly.

2. Details of processing

  • Subject matter: transmission of email and SMS messages and storage of related contact, consent and delivery records.
  • Duration: the term of the Terms of Service plus the retention periods in section 8.
  • Nature and purpose: sending messages the Responsible Party instructs the Operator to send; recording delivery, bounce, complaint and opt-out events; storing consent evidence; providing logs and exports.
  • Data subjects: the Responsible Party's customers, users, subscribers and employees.
  • Types of personal information: names, email addresses, mobile numbers, message contents, consent evidence (source, IP address, timestamp), delivery metadata, tags and metadata supplied by the Responsible Party.

3. Operator obligations

  • Process personal information only on the documented instructions of the Responsible Party, which are given through the API, dashboard and the Terms, unless required by law, in which case the Operator informs the Responsible Party before processing where legally permitted.
  • Ensure persons authorised to process the personal information are bound by confidentiality.
  • Implement the security measures in section 5 in accordance with sections 19 to 21 of POPIA.
  • Assist the Responsible Party in responding to data-subject requests and in meeting its obligations regarding security, breach notification and impact assessments, taking into account the nature of the processing.
  • Delete or return personal information at the end of the Service as set out in section 8.
  • Make available information reasonably necessary to demonstrate compliance with this DPA, and allow audits as set out in section 7.

4. Responsible Party obligations

  • Ensure a lawful basis exists for every message sent, including consent under section 69 of POPIA for direct marketing.
  • Give accurate instructions, classify messages correctly and keep contact and consent records accurate.
  • Not send special personal information or information of children through the Service unless permitted by law and agreed in writing.

5. Security measures

  • Encryption of personal information in transit (TLS 1.2 or higher) and at rest, including column-level encryption of recipient addresses and numbers.
  • API keys stored only as SHA-256 hashes; per-key scopes; per-organisation isolation enforced at the data-access layer.
  • Role-based access for dashboard users; multi-factor authentication available and enforced for owners on eligible plans.
  • Message bodies redacted after 30 days; logging of security events; daily backups with restore tests.
  • Vulnerability management, dependency scanning and secret scanning in the build pipeline.

6. Sub-operators

The Responsible Party authorises the Operator to engage the sub-operators listed in the Privacy Policy, section 6, under written contracts imposing data-protection obligations no less protective than this DPA. The Operator will give at least 14 days' notice by email before adding a sub-operator that processes Customer Content; the Responsible Party may object on reasonable grounds and, if the objection cannot be resolved, terminate the affected part of the Service without penalty.

Where a sub-operator processes personal information outside South Africa, the Operator ensures the transfer complies with section 72 of POPIA.

7. Breach notification and audits

The Operator notifies the Responsible Party without undue delay, and in any event within 48 hours, after becoming aware of a security compromise affecting Customer Content, with the information reasonably available at that time and updates as the investigation progresses.

The Responsible Party may audit compliance with this DPA once per 12 months on 30 days' written notice, during business hours, without disrupting the Service, and subject to confidentiality. The Operator may satisfy an audit request by providing a recent independent audit report or security questionnaire response.

8. Deletion and return

On termination of the Service the Responsible Party may export contacts, consent records and message metadata from the dashboard for 30 days. After that the Operator deletes Customer Content within 30 days, and from backups within a further 30 days, except where retention is required by law.

9. Liability and precedence

The liability limits in the Terms of Service apply to this DPA. In the event of conflict between this DPA and the Terms regarding the processing of personal information, this DPA prevails.

10. Signature

This DPA is accepted by creating an account. A countersigned PDF copy is available on request from legal@sendbaze.com for customers who require one for their records.