Legal

Data Processing Agreement

Last updated: 1 July 2026

This Data Processing Agreement ("DPA") forms part of the Terms and Conditions between PrimeDesk (Pty) Ltd ("Processor") and the business client ("Controller") and is required for compliance with the Protection of Personal Information Act 4 of 2013 (POPIA).

1. Roles and Scope

The Controller is the entity that determines the purposes and means of processing personal information. The Processor (PrimeDesk) processes personal information on behalf of the Controller in providing the platform services.

2. Data Processed

PrimeDesk processes the following categories of personal information on behalf of the Controller:

  • Client customer data entered into the POS system (names, contact details, transaction history).
  • Staff management data (names, roles, shift information).
  • Business operational data (sales reports, stock levels, financial summaries).
  • Communication records (support tickets, messages).

3. Security Measures

PrimeDesk implements the following technical and organisational security measures:

  • Encryption in transit (TLS 1.2+) and at rest.
  • Row-level security (RLS) to prevent cross-client data access.
  • Role-based access control with least-privilege principles.
  • Regular security audits and penetration testing.
  • Automated session management with 8-hour token expiry.
  • Secure credential storage with encryption at rest.
  • Audit logging of all system and data access events.

4. Sub-Processors

PrimeDesk uses the following sub-processors to deliver the platform:

  • Cloud hosting infrastructure providers (for server hosting and data storage).
  • Payment gateway providers (for processing client payments — only payment metadata is shared, not full card details).
  • Email delivery services (for transactional emails).

All sub-processors are bound by data protection agreements that meet POPIA requirements. The Controller will be notified of any new sub-processors before they are engaged.

5. Data Breach Notification

In the event of a personal data breach, PrimeDesk will:

  • Notify the Controller within 72 hours of becoming aware of the breach.
  • Provide details of the nature of the breach, the categories of data affected, and the likely consequences.
  • Take immediate steps to contain and remediate the breach.
  • Cooperate with the Controller in notifying the Information Regulator and affected data subjects, where required.

6. Data Deletion on Termination

Upon termination of the service agreement, PrimeDesk will delete all personal information processed on behalf of the Controller within 60 days, unless retention is required by law. The Controller may request immediate deletion in writing. Data retention for legal compliance purposes will be communicated to the Controller.

7. Data Subject Rights

PrimeDesk will assist the Controller in fulfilling data subject requests, including access, correction, deletion, and objection, by providing the necessary data and tools within the platform.

8. Audit Rights

The Controller has the right to audit PrimeDesk's compliance with this DPA, subject to 30 days' written notice and reasonable confidentiality obligations. Audits will be conducted during business hours and will not unreasonably interfere with PrimeDesk's operations.

9. Contact

For matters relating to this DPA, contact our Information Officer at infoprimedesksa@gmail.com.