Data processing addendum (DPA)

Last updated: 9 June 2026

This DPA forms part of the Terms of service between the customer ("Controller" / "Responsible party") and SalesCollab ("Processor" / "Operator"). It governs processing of personal information by us on behalf of the customer under POPIA and, where applicable, GDPR.

1. Subject matter and duration

Subject matter: provision of the AssetTrack Service. Duration: the term of the customer's subscription plus retention periods set out in our Privacy notice.

2. Nature and purpose of processing

We process personal information solely to provide, secure and support the Service and to comply with documented customer instructions and applicable law.

3. Categories of data subjects and data

  • Data subjects: customer's employees, contractors, asset assignees.
  • Personal information: names, work contact details, role, asset assignment history, attached documents.

4. Operator obligations

We will:

  • process personal information only on documented customer instructions;
  • ensure persons authorised to process it are bound by confidentiality;
  • implement appropriate technical and organisational measures (see Annex A);
  • assist the customer with data subject requests and security obligations to the extent reasonable;
  • delete or return personal information at the end of the engagement, unless retention is required by law;
  • make available information necessary to demonstrate compliance and allow audits on reasonable notice.

5. Sub-processors

The customer authorises the following sub-processors. We will give 30 days' notice of any addition or replacement and the customer may object on reasonable grounds.

  • Supabase (database, auth, storage, edge functions) — EU/US regions.
  • Cloudflare (CDN, edge compute, DNS) — global.
  • Paystack — payment processing (South Africa).
  • Email delivery provider used for transactional mail.

6. International transfers

Where sub-processors process data outside the customer's jurisdiction we rely on Standard Contractual Clauses, adequacy decisions or other lawful POPIA / GDPR transfer mechanisms.

7. Security incident notification

We will notify the customer without undue delay (and in any event within 72 hours of awareness) of any unauthorised access to or loss of personal information processed under this DPA, with the information then available.

8. Liability

Liability under this DPA is subject to the limits in the Terms of service, except where law requires otherwise.

Annex A — Technical and organisational measures

  • TLS 1.2+ in transit; encryption at rest for database and object storage.
  • Row-level security policies enforcing per-organisation isolation.
  • Role-based access control with admin, owner and member roles.
  • Two-factor authentication available and enforceable.
  • Audit logging of administrative and data-changing actions.
  • Automated security scans and dependency vulnerability monitoring.
  • Background and access controls for personnel with production access.

To execute a signed copy of this DPA for procurement purposes, email info@salescollabassettrack.co.za.