Legal

Operator Agreement (POPIA Data Processing Agreement)

Last updated: 6 October 2026

When you use BizAI, you decide what personal information is stored and why, and we process it on your behalf. Section 21 of the Protection of Personal Information Act (POPIA) requires a written agreement between you, as the responsible party, and us, as the operator. This agreement sets out how we protect that information.

This agreement forms part of our Terms of Service and applies automatically when you accept them. You do not need to sign anything. If you would like a signed copy for your records, download the PDF, complete your details and sign it, and email it to legal@bizai.co.za. We will countersign and return it.

Download the agreement (PDF)

1. Parties and definitions

This Operator Agreement (the "Agreement") is entered into between:

  • The Client (the "Responsible Party"): the customer that has accepted BIZ AI's Terms of Service or an order form or quote for the Services; and
  • Tulsapax (Pty) Ltd t/a BIZ AI (the "Operator"), registration number 2011/136338/07, of Brand Street, Midrand, Gauteng, South Africa.

It forms part of, and is read with, BIZ AI's Terms of Service and any order form or quote accepted by the Client (together, the "Main Agreement"). If this Agreement and the Main Agreement conflict on the processing of personal information, this Agreement applies.

1.1 Words defined in the Protection of Personal Information Act 4 of 2013 ("POPIA") have the same meaning here, including "personal information", "processing", "data subject", "responsible party", "operator" and "Information Regulator".

1.2 "Client Data" means the personal information that the Client, its users, or its customers place in or send through the BIZ AI platform, or that BIZ AI receives from the Client's connected systems (for example Sage, WhatsApp or email), in order to provide the services.

1.3 "Services" means the BIZ AI Smart CRM platform and related services the Client subscribes to under the Main Agreement.

1.4 "Sub-operator" means a third party that BIZ AI engages to process Client Data on its behalf.

1.5 "Security Compromise" means any situation where there are reasonable grounds to believe that Client Data has been accessed or acquired by an unauthorised person, as described in section 22 of POPIA.

2. Scope of processing

2.1 The Client is the Responsible Party for Client Data and decides why and how it is processed. BIZ AI is the Operator and processes Client Data only to provide the Services.

2.2 The subject matter, nature, purpose, types of personal information and categories of data subjects are set out in Annex C.

2.3 The Client confirms that it has a lawful basis under POPIA for the Client Data it places in the Services, and that it has given data subjects the notices POPIA requires (section 18), including that their information is processed by service providers and may be stored outside South Africa (see clause 5).

2.4 BIZ AI processes its own account and billing information about the Client (for example the Client's contact person and invoices) as a responsible party in its own right. That information is covered by BIZ AI's Privacy Policy, not by this Agreement.

3. BIZ AI's obligations as operator

3.1 Instructions only. BIZ AI processes Client Data only on the Client's documented instructions, which are the Main Agreement, this Agreement and the Client's use and configuration of the Services (POPIA section 20). If a law requires BIZ AI to process Client Data otherwise, BIZ AI will tell the Client first, unless the law forbids it.

3.2 No other use. BIZ AI will not sell Client Data, use it for its own marketing, or combine it with other clients' data. Client Data is kept separate per client (see Annex A).

3.3 Confidentiality. BIZ AI treats Client Data as confidential. Its employees and contractors who can access Client Data are bound by confidentiality obligations and get access only where their role needs it.

3.4 Security safeguards. BIZ AI maintains appropriate, reasonable technical and organisational measures to protect Client Data against loss, damage, and unauthorised access or processing, as required by POPIA sections 19 and 21. The current measures are described in Annex A. BIZ AI may update them, provided the overall level of protection does not decrease.

3.5 Staff support access. BIZ AI support staff access a Client's account only to provide support the Client asked for, to keep the Services running, or to meet a legal duty, and such access is limited to what the task needs.

4. Security compromises

4.1 BIZ AI will notify the Client without undue delay, and in any event within 72 hours, after becoming aware of a Security Compromise affecting Client Data (POPIA section 21(2)).

4.2 The notice will include, as far as known at the time: what happened, the types of Client Data and roughly how many data subjects are affected, the likely consequences, what BIZ AI has done or will do in response, and a contact person. Information not yet known will follow as it becomes available.

4.3 As Responsible Party, the Client decides whether to notify the Information Regulator and data subjects under POPIA section 22. BIZ AI will give reasonable help, including the information needed for those notices.

4.4 BIZ AI will not notify the Client's data subjects directly unless the Client asks it to or a law requires it.

4.5 BIZ AI will take reasonable steps to contain the Security Compromise and reduce its effects, and will keep a record of it.

5. Sub-operators and cross-border transfers

5.1 Authorised sub-operators. The Client authorises BIZ AI to use the sub-operators listed in Annex B and published at bizai.co.za/legal/sub-processors. Some sub-operators are used only if the Client switches on the related feature (for example WhatsApp, voice or AI features).

5.2 Changes. BIZ AI will give the Client at least 30 days' notice (by email or in the platform) before adding or replacing a sub-operator. If the Client has a reasonable data protection objection, the parties will discuss it in good faith; if it cannot be resolved, the Client may end the affected Services without penalty.

5.3 Same obligations. BIZ AI will have a written agreement with each sub-operator that protects Client Data at least as well as this Agreement, and remains responsible to the Client for its sub-operators' performance.

5.4 Where Client Data is stored. The BIZ AI application runs on servers in Cape Town, South Africa. The primary database that stores Client Data is hosted by Supabase on Amazon Web Services in Singapore. Some sub-operators in Annex B process data in the United States or elsewhere.

5.5 Lawful transfer (POPIA section 72). BIZ AI transfers Client Data outside South Africa only where (a) the recipient is subject to a law, binding corporate rules or a binding agreement that gives an adequate level of protection substantially similar to POPIA, or (b) the transfer is necessary to perform the Services the Client has contracted for. For the primary database, the recipient is subject to Singapore's Personal Data Protection Act 2012 and to Supabase's data processing agreement.

6. Data subject requests, the Regulator and audits

6.1 Data subject requests. If a data subject contacts BIZ AI directly to access, correct, delete or object to the processing of Client Data (POPIA sections 23 to 25), BIZ AI will pass the request to the Client within 5 business days and will not respond itself unless the Client asks it to. Most requests can be handled by the Client in the platform (editing, exporting or deleting records). Where they cannot, BIZ AI will help within a reasonable time.

6.2 Information Regulator. BIZ AI will cooperate with the Client in any enquiry or investigation by the Information Regulator about Client Data, and will tell the Client promptly if the Regulator contacts BIZ AI about it, unless the law forbids this.

6.3 Records. BIZ AI keeps records of the processing it carries out for the Client, as required by POPIA.

6.4 Audits. On reasonable written request, and no more than once in any 12 months (unless there has been a Security Compromise), BIZ AI will provide the information reasonably needed to show compliance with this Agreement, such as a summary of its security measures and answers to a security questionnaire. Any on-site or third-party audit is at the Client's cost, on reasonable notice, during business hours, and subject to confidentiality.

6.5 Information Officer. BIZ AI's Information Officer is its director, who can be contacted at legal@bizai.co.za.

7. Retention, return and deletion

7.1 During the subscription. Client Data is kept for as long as the Client keeps it in the Services. The Client decides how long its records are kept and is responsible for its own legal retention duties (for example under the Tax Administration Act, the VAT Act and the Companies Act). Where Client Data is also sent to the Client's accounting system (such as Sage), that system holds the Client's accounting records.

7.2 Export. For 30 days after the Main Agreement ends, the Client may export its Client Data, and BIZ AI will on request provide a full export in a common format such as CSV.

7.3 Deletion. Unless the Client instructs otherwise in writing, at the end of that 30-day period BIZ AI will permanently delete Client Data from the live Services, and confirm the deletion in writing on request. Copies in backups are overwritten on the daily backup cycle, within 7 days, and are not used in the meantime except to restore the Services.

7.4 Legal holds. BIZ AI may keep Client Data for longer only where a law requires it, or where it is needed for a legal claim, and then only for that purpose and for as long as needed (POPIA section 14).

7.5 De-identified data. BIZ AI may keep usage statistics that do not identify the Client's data subjects.

8. Liability, term and general

8.1 Liability. Each party's liability under this Agreement is subject to the limits in the Main Agreement, except that neither party limits liability for fraud or wilful misconduct. In any event, BIZ AI's total liability under this Agreement is limited to the fees paid by the Client in the 12 months before the claim arose.

8.2 Term. This Agreement starts when the Client accepts it or first uses the Services, and continues for as long as BIZ AI processes Client Data. Clauses 4, 6 and 7 survive until all Client Data has been returned or deleted.

8.3 Changes in law. If POPIA or a related regulation changes, the parties will update this Agreement in good faith to keep it compliant.

8.4 Governing law. This Agreement is governed by the law of the Republic of South Africa.

8.5 Whole agreement. This Agreement, with its annexes and the Main Agreement, is the whole agreement on the processing of Client Data. A change is valid only in writing and signed by both parties.

Annex A: Security measures

Area Measure
Separation between clients Each client's data is held in its own database schema, with row-level security as a second layer of separation
Encryption in transit All traffic to the platform and to sub-operators uses TLS (HTTPS)
Encryption at rest The database and backups are encrypted at rest by the hosting provider; credentials for connected systems (such as Sage logins) are additionally encrypted with AES-256-GCM
Access control Users sign in through authenticated sessions; roles limit what each user can see and change; connecting or changing integrations is limited to owners and admins
Audit trail Records carry who created and last changed them, and changes to key records are logged
Deletion safeguards Records are soft-deleted first, so accidental deletions can be recovered before permanent removal
Secrets and logging API keys and passwords are never written to logs, and error reports are scrubbed of keys
Backups Automated daily database backups by the hosting provider, kept for 7 days
Staff Access to client accounts is limited to staff who need it for support or operations

Annex B: Sub-operators

Sub-operator Location Purpose When used
Supabase Inc. (on Amazon Web Services) Singapore Primary database, authentication, file storage Always
Vercel Inc. Cape Town, South Africa (application); United States (company) Application hosting and delivery Always
Meta Platforms, Inc. United States WhatsApp Business messaging If WhatsApp is connected
Sage (Sage Business Cloud Accounting / Sage Evolution) As set by Sage for the Client's own Sage company Sending customers, products, quotes and invoices to the Client's own Sage company If the Client connects Sage
Twilio SendGrid United States Sending emails from the platform If email sending is used
Vercel AI Gateway and the AI model providers it routes to (such as Anthropic) United States AI features such as inbox assistance, summaries and lead scoring If AI features are used
Deepgram Inc., ElevenLabs Inc., Twilio Inc. United States Voice transcription, speech and telephony If voice features are activated

Annex C: Processing details

Item Details
Subject matter Providing the BIZ AI Smart CRM platform and connected services
Purpose Managing the Client's customers, leads, quotes, invoices, products, communications (WhatsApp, email, calls), stock and production, and syncing them with the Client's accounting system
Data subjects The Client's customers and their contact people, leads, suppliers, and the Client's own staff who use the platform
Types of personal information Names, contact details (email, phone, WhatsApp number), addresses, company and VAT details, transaction and order history, message and call content, and any information the Client chooses to store in custom fields
Special personal information Not required by the Services; the Client should not store it unless it has a lawful basis
Duration The term of the Main Agreement, plus the return and deletion period in clause 7