Skip to content

WebGiant

WEBGIANT · LEGAL & COMPLIANCE

Data Processing Agreement

Client-facing terms · incorporate into the applicable quotation, statement of work or service agreement.

South Africa · POPIA / PAIAUnited Kingdom · UK GDPR / PECRNew Zealand · Privacy Act 2020United States · federal + state baseline

1. Parties and scope

This DPA forms part of the agreement between the client (“Client”) and WebGiant (Pty) Ltd (“WebGiant”) and applies to processing of personal information/personal data by WebGiant on behalf of the Client in connection with the services. The parties intend this DPA to satisfy applicable processor/operator/service-provider contract requirements to the extent those laws apply.

2. Roles

The Client determines the purposes and essential means of the Client Personal Data and acts as controller/responsible party/agency/business as applicable. WebGiant acts as processor/operator/service provider to the extent it processes Client Personal Data only for the contracted services and on documented instructions. WebGiant may separately act as controller/responsible party for its own billing, security, legal and business-administration data.

3. Documented instructions

WebGiant will process Client Personal Data only on documented instructions, including the agreement, SOW, support tickets and authorised written directions, unless applicable law requires other processing. If legally permitted, WebGiant will inform the Client before processing required by law. WebGiant will promptly inform the Client if an instruction appears to infringe applicable data-protection law.

4. Confidentiality

WebGiant will ensure persons authorised to process Client Personal Data are bound by confidentiality duties appropriate to their access.

5. Security

  • Access control and least privilege appropriate to the service.
  • MFA for privileged systems where supported and reasonably practicable.
  • Patch and vulnerability management for systems under WebGiant’s control.
  • Endpoint and server protections appropriate to risk.
  • Backups where included in the service and documented restoration procedures.
  • Encrypted transport for administrative access and sensitive transmissions where reasonably practicable.
  • Logging/monitoring appropriate to the platform.
  • Incident detection and escalation procedures.

6. Subprocessors

The Client gives general authorisation for WebGiant to use subprocessors needed to provide the services, subject to this clause. WebGiant will maintain a current subprocessor register and impose data-protection obligations appropriate to the services. For clients requiring advance notice of material new subprocessors, WebGiant will provide notice through the agreed channel and a reasonable opportunity to raise legitimate data-protection objections.

7. Data-subject requests

Taking into account the nature of the processing, WebGiant will provide reasonable assistance to the Client to respond to verified requests to exercise privacy rights. Unless legally required to respond directly, WebGiant will refer requests relating solely to Client Personal Data to the Client.

8. Breaches and incidents

WebGiant will notify the Client without undue delay after becoming aware of a personal-data/security compromise affecting Client Personal Data and will provide information reasonably available to support the Client’s assessment and notifications. The Client remains responsible for regulator/data-subject notification where it is the responsible party/controller, unless applicable law places a separate duty directly on WebGiant for the relevant processing.

9. Assistance and audits

WebGiant will provide reasonable information necessary to demonstrate compliance with applicable processor/operator obligations and assist with impact assessments, security reviews and regulator enquiries proportionate to the services. Audits should minimise disruption, protect other customers’ confidentiality and, where appropriate, rely first on existing reports/evidence. Additional bespoke audit work may be chargeable where permitted by law and agreement.

10. Return and deletion

On termination of the relevant service and on the Client’s lawful instruction, WebGiant will return or delete Client Personal Data that remains under WebGiant’s control, subject to legal retention obligations, backup cycles, security logs and technical limitations. Data retained in backups will remain protected and be deleted/overwritten through the normal backup lifecycle unless restoration is required for disaster recovery.

11. International transfers

  • South Africa: the parties will use a POPIA-compliant transfer ground and protection for cross-border processing where section 72 applies.
  • United Kingdom: where the Client makes a restricted transfer of UK personal data to WebGiant or a WebGiant subprocessor outside the UK, the parties will implement a lawful transfer mechanism. If appropriate, the parties will execute or incorporate the then-current UK International Data Transfer Agreement or UK Addendum and complete any required transfer-risk/data-protection assessment.
  • New Zealand: where IPP 12 applies to a disclosure, the parties will use a permitted basis and comparable safeguards, including contractual safeguards where appropriate.
  • United States: the parties will apply any state-specific service-provider/processor contractual restrictions required by an applicable state privacy law.

12. Conflict and survival

If this DPA conflicts with the main agreement on personal-data protection, this DPA controls to the extent of the conflict. Confidentiality, security, deletion/return, audit evidence and transfer obligations survive for as long as WebGiant retains Client Personal Data.

Schedule 1 — Processing details

Field To complete
Subject matter Complete for the applicable service / SOW
Duration Service term plus the applicable backup / deletion period
Nature of processing As described in the applicable SOW and authorised support instructions
Purposes To provide the contracted services on Client instructions
Data subjects Specify for the applicable client / service
Data categories Specify the categories relevant to the applicable client / service
Special/sensitive data None expected unless specifically agreed; describe where applicable
Client instructions Applicable SOW and authorised support channels
Approved subprocessors Refer to WebGiant’s current Subprocessor Register
Transfer locations State the actual processing / transfer locations for the engagement
WhatsApp