WEBGIANT · LEGAL & COMPLIANCE
Data Processing Agreement
Client-facing terms · incorporate into the applicable quotation, statement of work or service agreement.
1. Parties and scope
This DPA forms part of the agreement between the client (“Client”) and WebGiant (Pty) Ltd (“WebGiant”) and applies to processing of personal information/personal data by WebGiant on behalf of the Client in connection with the services. The parties intend this DPA to satisfy applicable processor/operator/service-provider contract requirements to the extent those laws apply.
2. Roles
The Client determines the purposes and essential means of the Client Personal Data and acts as controller/responsible party/agency/business as applicable. WebGiant acts as processor/operator/service provider to the extent it processes Client Personal Data only for the contracted services and on documented instructions. WebGiant may separately act as controller/responsible party for its own billing, security, legal and business-administration data.
3. Documented instructions
WebGiant will process Client Personal Data only on documented instructions, including the agreement, SOW, support tickets and authorised written directions, unless applicable law requires other processing. If legally permitted, WebGiant will inform the Client before processing required by law. WebGiant will promptly inform the Client if an instruction appears to infringe applicable data-protection law.
4. Confidentiality
WebGiant will ensure persons authorised to process Client Personal Data are bound by confidentiality duties appropriate to their access.
5. Security
- Access control and least privilege appropriate to the service.
- MFA for privileged systems where supported and reasonably practicable.
- Patch and vulnerability management for systems under WebGiant’s control.
- Endpoint and server protections appropriate to risk.
- Backups where included in the service and documented restoration procedures.
- Encrypted transport for administrative access and sensitive transmissions where reasonably practicable.
- Logging/monitoring appropriate to the platform.
- Incident detection and escalation procedures.
6. Subprocessors
The Client gives general authorisation for WebGiant to use subprocessors needed to provide the services, subject to this clause. WebGiant will maintain a current subprocessor register and impose data-protection obligations appropriate to the services. For clients requiring advance notice of material new subprocessors, WebGiant will provide notice through the agreed channel and a reasonable opportunity to raise legitimate data-protection objections.
7. Data-subject requests
Taking into account the nature of the processing, WebGiant will provide reasonable assistance to the Client to respond to verified requests to exercise privacy rights. Unless legally required to respond directly, WebGiant will refer requests relating solely to Client Personal Data to the Client.
8. Breaches and incidents
WebGiant will notify the Client without undue delay after becoming aware of a personal-data/security compromise affecting Client Personal Data and will provide information reasonably available to support the Client’s assessment and notifications. The Client remains responsible for regulator/data-subject notification where it is the responsible party/controller, unless applicable law places a separate duty directly on WebGiant for the relevant processing.
9. Assistance and audits
WebGiant will provide reasonable information necessary to demonstrate compliance with applicable processor/operator obligations and assist with impact assessments, security reviews and regulator enquiries proportionate to the services. Audits should minimise disruption, protect other customers’ confidentiality and, where appropriate, rely first on existing reports/evidence. Additional bespoke audit work may be chargeable where permitted by law and agreement.
10. Return and deletion
On termination of the relevant service and on the Client’s lawful instruction, WebGiant will return or delete Client Personal Data that remains under WebGiant’s control, subject to legal retention obligations, backup cycles, security logs and technical limitations. Data retained in backups will remain protected and be deleted/overwritten through the normal backup lifecycle unless restoration is required for disaster recovery.
11. International transfers
- South Africa: the parties will use a POPIA-compliant transfer ground and protection for cross-border processing where section 72 applies.
- United Kingdom: where the Client makes a restricted transfer of UK personal data to WebGiant or a WebGiant subprocessor outside the UK, the parties will implement a lawful transfer mechanism. If appropriate, the parties will execute or incorporate the then-current UK International Data Transfer Agreement or UK Addendum and complete any required transfer-risk/data-protection assessment.
- New Zealand: where IPP 12 applies to a disclosure, the parties will use a permitted basis and comparable safeguards, including contractual safeguards where appropriate.
- United States: the parties will apply any state-specific service-provider/processor contractual restrictions required by an applicable state privacy law.
12. Conflict and survival
If this DPA conflicts with the main agreement on personal-data protection, this DPA controls to the extent of the conflict. Confidentiality, security, deletion/return, audit evidence and transfer obligations survive for as long as WebGiant retains Client Personal Data.
Schedule 1 — Processing details
| Field | To complete |
|---|---|
| Subject matter | Complete for the applicable service / SOW |
| Duration | Service term plus the applicable backup / deletion period |
| Nature of processing | As described in the applicable SOW and authorised support instructions |
| Purposes | To provide the contracted services on Client instructions |
| Data subjects | Specify for the applicable client / service |
| Data categories | Specify the categories relevant to the applicable client / service |
| Special/sensitive data | None expected unless specifically agreed; describe where applicable |
| Client instructions | Applicable SOW and authorised support channels |
| Approved subprocessors | Refer to WebGiant’s current Subprocessor Register |
| Transfer locations | State the actual processing / transfer locations for the engagement |