Data Processing Agreement
Our standard Data Processing Agreement explains how PeopleWisher, operated by Peoplelayer Technologies Ltd, processes and protects customer data on behalf of organisations using our platform.
This agreement is designed as a reusable framework for customers in different jurisdictions. It addresses data processing, security, data location, service providers, international transfers, data export and deletion, and jurisdiction-specific requirements including POPIA and GDPR where applicable.
1. Parties
This Data Processing Agreement ("DPA") is entered into between Peoplelayer Technologies Ltd, the company operating the PeopleWisher platform ("PeopleWisher", "Peoplelayer", "we", "us" or "Processor/Operator"), and the customer or organisation using PeopleWisher ("Customer", "you" or "Controller/Responsible Party"). This DPA forms part of the agreement under which PeopleWisher provides its software and related services to the Customer.
2. Purpose
This DPA establishes the terms under which PeopleWisher processes personal information submitted, uploaded, transmitted or otherwise made available by the Customer through the PeopleWisher platform. PeopleWisher processes Customer Data for the purpose of providing, maintaining, securing and supporting the PeopleWisher services configured by the Customer.
3. Definitions
“Applicable Data Protection Law” means applicable laws governing personal information or personal data, including where applicable POPIA, the GDPR, the UK GDPR and applicable US state privacy laws. “Customer Data” means personal information or personal data submitted to PeopleWisher by or on behalf of the Customer. “Data Subject” means the individual to whom Customer Data relates. “Processing” has the meaning given under applicable law. “Controller” includes a responsible party or equivalent entity. “Processor” includes an operator or equivalent service provider.
4. Roles of the Parties
The Customer determines the purposes and means for which Customer Data is collected and used. The Customer is responsible for ensuring that it has an appropriate lawful basis and all necessary rights, permissions, notices or consents required to provide Customer Data to PeopleWisher. PeopleWisher acts as a Processor/Operator when processing Customer Data on behalf of the Customer and shall process Customer Data in accordance with the Customer’s documented instructions, this DPA and applicable law.
5. Categories of Data
Depending on the Customer’s configuration, Customer Data may include first name, last name, email address, telephone number, date of birth, anniversary dates, organisation or membership information, custom fields, communication preferences, message history and delivery information, and other information intentionally provided by the Customer. Customers should not upload sensitive or special-category personal information unless the PeopleWisher service specifically supports it and the processing is lawful.
6. Purpose of Processing
PeopleWisher may process Customer Data for hosting and storing Customer Data; managing contacts; tracking birthdays, anniversaries and other configured events; generating and personalising messages; sending configured Email, SMS or WhatsApp communications; providing message delivery and reporting; customer support; platform security; fraud and abuse prevention; backups and business continuity; troubleshooting and reliability; and compliance with legal obligations. PeopleWisher does not sell Customer Data or use Customer Data to build or sell independent marketing databases.
7. Confidentiality
PeopleWisher shall treat Customer Data as confidential and shall ensure that persons authorised to access Customer Data are subject to appropriate confidentiality obligations. Customer Data will not be disclosed except to authorised service providers necessary to provide the service, where instructed by the Customer, where required by applicable law, or where necessary to protect the security, integrity or operation of the service.
8. Security Measures
PeopleWisher maintains reasonable technical and organisational security measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access. Measures include encryption in transit, encryption at rest, authentication and access controls, secure server infrastructure, credential protections, monitoring and logging, backup and recovery procedures, software security controls, restricted administrative access, security updates and incident response procedures.
9. Data Location
Customer Data is currently hosted and processed using infrastructure located in the United States. PeopleWisher may update its hosting infrastructure where reasonably necessary to maintain, improve or secure the service. Where a change materially affects applicable data-transfer requirements, PeopleWisher will take reasonable steps to maintain compliance with applicable law.
10. Subprocessors and Service Providers
PeopleWisher may use selected infrastructure, hosting, communications, security, analytics or other service providers necessary to operate the platform. Such providers may process limited Customer Data only to the extent necessary to provide their contracted services. PeopleWisher remains responsible for its obligations under this DPA and will require applicable service providers to maintain appropriate confidentiality and security obligations. PeopleWisher will not permit service providers to use Customer Data for their own independent advertising or marketing purposes.
11. International Data Transfers
Where Customer Data is transferred across national borders, PeopleWisher shall take reasonable steps to ensure that the transfer and subsequent processing comply with applicable Data Protection Law. Where applicable law imposes specific international transfer requirements, the parties may use additional transfer mechanisms or contractual safeguards where required.
12. Customer Responsibilities
The Customer is responsible for determining the lawful purpose for collecting and processing personal information; providing appropriate privacy notices; obtaining consent where required; maintaining accurate Customer Data; ensuring lawful collection; configuring PeopleWisher appropriately; maintaining secure account credentials; restricting access to authorised personnel; responding to Data Subject requests where legally responsible; and ensuring its use of PeopleWisher complies with applicable law.
13. Data Subject Rights
PeopleWisher shall provide reasonable assistance to the Customer in responding to Data Subject requests where such assistance is reasonably necessary and technically available. Depending on applicable law, Data Subjects may have rights including access, correction, deletion, restriction, objection, portability and withdrawal of consent. The Customer remains responsible for determining whether a request is legally valid. PeopleWisher may require verification before processing a request.
14. Data Breaches and Security Incidents
PeopleWisher maintains procedures designed to identify, investigate and respond to security incidents affecting Customer Data. Where PeopleWisher becomes aware of a confirmed security incident involving Customer Data, it shall notify the Customer without undue delay where required by applicable law and provide reasonably available information needed for the Customer’s response.
15. Data Retention
PeopleWisher shall retain Customer Data only for as long as reasonably necessary to provide the services, comply with legal obligations, resolve disputes, enforce agreements, maintain security or otherwise fulfil legitimate business requirements. The Customer may request deletion subject to applicable legal retention requirements.
16. Data Export
The Customer may request an export of its Customer Data in a commonly usable electronic format where such export functionality is available. PeopleWisher shall provide reasonable assistance with data export requests.
17. Data Deletion
Upon termination of the Customer’s use of PeopleWisher, the Customer may request deletion of Customer Data. PeopleWisher shall delete or anonymise Customer Data within a reasonable period, subject to legal retention requirements, security and fraud-prevention requirements, backup retention cycles, and the establishment, exercise or defence of legal claims. Data remaining in backups will remain protected and will be deleted or overwritten according to the applicable backup lifecycle.
18. Audit and Compliance
Upon reasonable request, PeopleWisher shall provide information reasonably necessary to demonstrate compliance with applicable obligations under this DPA. Any audit shall be conducted on reasonable notice, during normal business hours, with minimal disruption, while protecting confidential information, trade secrets and security-sensitive information.
19. Government and Legal Requests
If PeopleWisher is legally required to disclose Customer Data to a government authority or law enforcement agency, PeopleWisher may disclose the information to the extent legally required. Where legally permitted, PeopleWisher will make reasonable efforts to notify the Customer before disclosure.
20. Customer Data Ownership
As between the parties, the Customer retains all rights, title and interest in Customer Data. This DPA does not transfer ownership of Customer Data to PeopleWisher. PeopleWisher receives only the rights necessary to process Customer Data for providing the services.
21. PeopleWisher Service Data
PeopleWisher may collect limited technical and operational information necessary to operate and secure the platform, including account information, authentication information, IP addresses, browser and device information, service logs, delivery and system events, error reports and usage information. This information is processed in accordance with the PeopleWisher Privacy Policy.
22. Privacy Policy
The PeopleWisher Privacy Policy provides additional information concerning personal information handling. Privacy information is available at PeopleWisher Privacy Policy.
23. POPIA
Where the Customer is subject to South Africa’s Protection of Personal Information Act 4 of 2013 (POPIA), the Customer shall act as the Responsible Party where it determines the purpose and means of processing, and PeopleWisher shall act as an Operator to the extent it processes Personal Information on behalf of the Customer. PeopleWisher shall process Personal Information only with the knowledge and authorisation of the Customer except where otherwise required by law, treat it as confidential, maintain appropriate safeguards, and cooperate reasonably with the Customer regarding POPIA obligations.
24. GDPR and Other Data Protection Laws
Where the GDPR, UK GDPR or another applicable data protection law applies, this DPA shall be interpreted to provide the protections required by that law. Mandatory provisions that cannot be contractually excluded shall apply to the extent required.
25. Term and Termination
This DPA remains effective for as long as PeopleWisher processes Customer Data on behalf of the Customer. Obligations concerning confidentiality, security, deletion, data protection and lawful processing survive termination to the extent necessary to fulfil their purpose.
26. Order of Precedence
If this DPA conflicts with another agreement concerning the processing of Customer Data, this DPA controls with respect to data protection matters to the extent required by applicable law.
27. Governing Law
Unless otherwise agreed in writing, this DPA is governed by the laws applicable to the principal agreement between the parties. Mandatory data protection requirements that cannot be contractually excluded prevail.
28. Changes to this DPA
Peoplelayer Technologies Ltd may update this DPA where reasonably necessary to reflect changes to its services, security practices or applicable data protection requirements. Where an amendment materially reduces protections applicable to Customer Data, reasonable notice will be provided where required by law.
29. Contact
Peoplelayer Technologies Ltd, operator of PeopleWisher. Privacy and data protection enquiries: [email protected]. Website: peoplewisher.com.
30. Signatures
Customer / Responsible Party: Organisation Name ____________________ Authorised Representative ____________________ Title ____________________ Email ____________________ Signature ____________________ Date ____________________. Peoplelayer Technologies Ltd: Authorised Representative ____________________ Title ____________________ Email ____________________ Signature ____________________ Date ____________________.
