Data Processing Agreement (DPA)
Last Updated: July 9, 2026
This Data Processing Agreement ("DPA") governs the processing of personal information performed by Plinth-Cloud (Pty) Ltd (operating as Plinth) as an Operator on behalf of the Subscriber as a Responsible Party, satisfying Section 21 of the Protection of Personal Information Act, No. 4 of 2013 ("POPIA").
1. Operator Status and Scope of Processing
The Subscriber acts as the "Responsible Party" who determines the parameters and legal justification for managing real estate portfolios and tenant data. Plinth acts strictly as an "Operator" processing personal data exclusively within the functional architecture of the SaaS ecosystem on the documented instructions of the Subscriber.
The processing operations encompass hosting real estate profiles, tracking lease structures, maintaining tenant interaction variables, mapping maintenance requests, and running the 'Plinth Match' auto-reconciliation engine over payment clearance reference matrices extracted from open banking conduits.
2. Technical and Organizational Safeguards
Plinth covenants to maintain industry-standard safeguards required by Section 21(1) of POPIA. Plinth isolates subscriber database views utilizing PostgreSQL Row-Level Security (RLS), preventing any unauthorized cross-tenant data exposure. All infrastructure personnel with access to platform engineering layers are bound to strict, permanent non-disclosure terms.
3. Downstream Sub-Operators
The Subscriber grants general written consent for Plinth to engage downstream technical providers (such as Supabase, Vercel, Resend, AWS, or other transactional layers) to deliver infrastructure. Plinth ensures that all engaged sub-processors mirror or exceed the exact data protection obligations set out in this DPA, and Plinth remains fully accountable to the Subscriber for their performance.
4. 24-Hour Mandatory Security Compromise Notification Protocol
In strict conformity with Section 22 of POPIA, Plinth enforces an absolute notification response framework. Upon establishing reasonable grounds to believe that personal information has been accessed, altered, or acquired by any unauthorized individual, Plinth shall notify the Subscriber's registered administrator via electronic mail immediately, and in all circumstances within twenty-four (24) hours of initial incident confirmation.
Plinth will deliver a comprehensive incident log detailing the nature of the breach, the specific files or data rows impacted, the containment measures executed, and the immediate recommended remediation tracks. Plinth will actively cooperate with the Subscriber to notify the Information Regulator and affected data subjects.
5. Audit and Compliance Verification
Plinth shall provide the Subscriber with necessary technical logs, cryptographic confirmations, and operational summaries to prove compliance with POPIA. The Subscriber may request reasonable technical audits or inspections by giving thirty (30) business days' written notice, provided that such checks are conducted during normal business hours and do not compromise the architectural isolation of other platform subscribers.
6. Deletion and Return of Mandated Records
Upon the closing or termination of a SaaS account subscription, Plinth shall delete or return all personal information held inside its active database configurations following a 30-day soft-delete grace period, unless South African statutory provisions (such as tax tracking frameworks) mandate extended holding periods.
Ready to Simplify Property Management?
Join other South African landlords who've made the switch.
Built for South African landlords.
