Data Processing Agreement
This DPA forms part of our Terms of Service and applies whenever RepletoryReach processes personal data on behalf of your organisation.
Last updated: 2026-05-18
1. Parties & roles
You (the customer) are the Responsible Party / Controller for the personal data of the contacts you message. SJM Innovations Tech (Pty) Ltd (which operates RepletoryReach) is the Operator / Processor. We only process personal data on documented instructions from you (which include using the platform's standard features).
2. Subject matter & duration
The subject is the personal data your contacts share through messaging on the platform. The duration is the term of your subscription, plus a deletion window not exceeding 90 days.
3. Categories of data subjects & data
- Data subjects: your customers, end-users, leads, agents, and any other contacts your organisation chooses to message.
- Categories of data: phone numbers, names, message content, opt-in/out signals, conversation metadata, billing transaction IDs.
4. Operator obligations
- Process personal data only on the Responsible Party's documented instructions.
- Ensure persons with access are bound by confidentiality.
- Implement technical and organisational measures (encryption at rest and in transit with managed key rotation, every record tied to your account at the database level, audit logging, a vulnerability disclosure programme).
- Notify the Responsible Party of any data breach without undue delay, and in any case within 72 hours of becoming aware.
- Assist the Responsible Party with data-subject rights requests within a reasonable time frame.
- Delete or return all personal data at the end of the agreement, except where retention is required by law.
5. Sub-processors
- Our cloud hosting provider: infrastructure hosting in data centres in South Africa.
- Meta Platforms Ireland Limited: WhatsApp Cloud API.
- PayFast (Pty) Ltd: South African card and EFT payments.
- Paystack Payments Limited: Nigerian payments.
- Stripe Payments Europe Limited: international card payments.
- Our AI model providers: AI replies for chatbot flows only, and only when you enable them.
6. International transfers
Your data, where you are a South African customer, is processed and stored in South Africa. Where a sub-processor operates outside SA (e.g. Stripe in the EU), we rely on the European Commission's Standard Contractual Clauses and the South African Information Regulator's Code of Conduct on cross-border transfers.
7. Audit rights
Once per calendar year, the Responsible Party may request an audit on reasonable notice. We will make our security overview and any independent assessment reports available; on-site audits are subject to a mutually agreed scope and fee for our time.
8. Liability
Liability under this DPA is subject to the limitations in the Terms of Service. Each party is liable for damage caused by its own non-compliance with this DPA.