Legal
Last updated: 1 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms and Conditions between PrimeDesk (Pty) Ltd ("Processor") and the business client ("Controller") and is required for compliance with the Protection of Personal Information Act 4 of 2013 (POPIA).
The Controller is the entity that determines the purposes and means of processing personal information. The Processor (PrimeDesk) processes personal information on behalf of the Controller in providing the platform services.
PrimeDesk processes the following categories of personal information on behalf of the Controller:
PrimeDesk implements the following technical and organisational security measures:
PrimeDesk uses the following sub-processors to deliver the platform:
All sub-processors are bound by data protection agreements that meet POPIA requirements. The Controller will be notified of any new sub-processors before they are engaged.
In the event of a personal data breach, PrimeDesk will:
Upon termination of the service agreement, PrimeDesk will delete all personal information processed on behalf of the Controller within 60 days, unless retention is required by law. The Controller may request immediate deletion in writing. Data retention for legal compliance purposes will be communicated to the Controller.
PrimeDesk will assist the Controller in fulfilling data subject requests, including access, correction, deletion, and objection, by providing the necessary data and tools within the platform.
The Controller has the right to audit PrimeDesk's compliance with this DPA, subject to 30 days' written notice and reasonable confidentiality obligations. Audits will be conducted during business hours and will not unreasonably interfere with PrimeDesk's operations.
For matters relating to this DPA, contact our Information Officer at infoprimedesksa@gmail.com.