Net153 Logo

DATA PROCESSING AGREEMENT (DPA)

Between Net153 (Pty) Ltd ("Operator") and the Customer ("Responsible Party")

1. Purpose

This Data Processing Agreement ("DPA") forms part of the Master Service Agreement between Net153 (Pty) Ltd and the Customer.

Its purpose is to regulate the processing of Personal Information in accordance with the Protection of Personal Information Act, 4 of 2013 ("POPIA").

2. Definitions

Unless otherwise defined, terms used in this Agreement have the meanings assigned to them in POPIA.

  • Operator means Net153 (Pty) Ltd.
  • Responsible Party means the Customer (Church).
  • Personal Information has the meaning assigned by POPIA.
  • Processing includes collecting, recording, organising, storing, updating, retrieving, using, disclosing, transmitting, deleting, or destroying Personal Information.

3. Relationship of the Parties

The Customer acknowledges that it is the Responsible Party and determines:

  • what Personal Information is collected;
  • the purpose of processing;
  • the categories of data subjects;
  • retention periods;
  • who may access the information.

Net153 acts only as an Operator and processes Personal Information solely for the purpose of providing the ChMS.

Nothing in this Agreement transfers the responsibilities of the Responsible Party to Net153.

4. Operator Obligations

Net153 shall:

  • process Personal Information only on documented instructions from the Customer and in accordance with what is required for the provided platform to operated according to design;
  • implement reasonable technical and organisational security safeguards;
  • ensure that authorised personnel are subject to confidentiality obligations;
  • notify the Customer without undue delay after becoming aware of a confirmed security compromise affecting Customer data;
  • assist the Customer where reasonably required to comply with POPIA, subject to applicable fees where extensive assistance is requested.

5. Responsible Party Obligations

The Customer warrants that it:

  • has a lawful basis for processing;
  • has obtained any required consent;
  • complies with POPIA;
  • provides required privacy notices;
  • responds to data subject requests;
  • determines retention periods;
  • ensures information entered into the ChMS is lawful and accurate.

6. Security Measures

Net153 shall maintain commercially reasonable safeguards, including, where appropriate:

  • encryption in transit;
  • secure authentication;
  • role-based access controls;
  • security monitoring;
  • vulnerability management;
  • disaster recovery procedures;
  • regular backups.

7. Sub-Operators

The Customer authorises Net153 to engage trusted third-party service providers necessary to operate the service (such as cloud hosting, email delivery, monitoring, and backup providers).

Net153 shall ensure that such providers are subject to appropriate contractual confidentiality and security obligations.

8. International Processing

Where Personal Information is processed outside South Africa, Net153 shall take reasonable steps to ensure that POPIA requirements relating to cross-border transfers are satisfied.

9. Security Compromises

Where Net153 becomes aware of a confirmed security compromise affecting Customer data, Net153 shall notify the Customer as soon as reasonably practicable after becoming aware of the incident and provide available information to assist the Customer in meeting any legal notification obligations.

10. Deletion or Return of Data

Upon termination of the services and subject to any legal retention obligations, Net153 shall, upon request, make Customer data available for export for a limited period before securely deleting it in accordance with its retention policy.

11. Liability

Nothing in this DPA makes Net153 responsible for the Customer's compliance with POPIA.

The Customer remains solely responsible for determining the lawfulness of all processing undertaken through the ChMS.