Data Processor Agreement
When we work inside your systems, we process YOUR data subjects' information on your behalf. These are the terms that govern that relationship.
Last updated: 10 July 2026 • Applies to Computer Scientific Solutions (Pty) Ltd, Reg No 2017/103392/07 ("CSS", "we", "us").
Under POPIA, a service provider that processes personal information for a client is an "operator" (the equivalent of a "data processor" in GDPR language). When CSS provides managed services, support, automation, hosting-adjacent or data work that touches personal information under your control, this agreement applies automatically and forms part of our Terms of Service.
1. Roles
- You (the client) are the responsible party for personal information under your control.
- CSS acts as operator, processing that information only on your instructions and only as needed to deliver the agreed services (s20–21, POPIA).
2. Our commitments as operator
- Instruction-bound processing: we process personal information solely with your knowledge or authorisation and for the agreed services — never for our own purposes.
- Confidentiality: everyone at CSS who may touch your data is bound by confidentiality; we treat all client-side personal information as confidential per s20.
- Security (s21): we maintain the security measures described in our POPIA Compliance Statement — access control, managed endpoint security, encrypted transport and least-privilege access.
- Breach notification: we notify you immediately where there are reasonable grounds to believe personal information we process for you has been accessed or acquired by an unauthorised person, so you can meet your s22 duties.
- Return & deletion: at termination of services we return or delete personal information we hold on your behalf, per your instruction, unless law requires retention.
3. Sub-operators
Where delivering a service requires sub-operators (for example cloud backup platforms, RMM/monitoring tooling or courier services), we use reputable providers bound by written terms consistent with this agreement, and will identify them on request.
4. Your responsibilities
- Ensure you have a lawful basis for the personal information in your systems before we work on them.
- Give us accurate scoping instructions — especially for data migration, recovery and backup work.
- Notify us of any special-category (sensitive) information that needs elevated handling.
5. Audits & questions
Reasonable written enquiries about our processing practices are answered within 14 days. Formal written processing agreements for enterprise or compliance-driven clients are available on request — email support@csscomp.co.za.
