POPIA Posture
How RepletoryReach approaches the Protection of Personal Information Act (POPIA), and what we have built into the platform to support our customers' obligations.
Last updated: 2026-05-18
Our stance, in one sentence
We are an Operator under POPIA. We process personal information on documented instructions from our customers (the Responsible Parties), and we have engineered the platform around POPIA's eight conditions for lawful processing.
Accountability
Our Information Officer is the founder. The role is registered with the Information Regulator. Internal training on POPIA is part of onboarding for everyone with production access.
Processing limitation
We process only what is necessary to operate the service: phone numbers, names, message bodies, opt-in/out signals, conversation metadata, billing transaction IDs. We don't enrich data, profile contacts, or train models on customer content without explicit consent.
Purpose specification
Personal information is processed only for the purposes you (the Responsible Party) instruct us to: sending messages, recording conversations, billing usage, complying with our legal obligations.
Further processing limitation
We do not use your data for any other purpose. We do not sell, rent, or share it for marketing, advertising or analytics outside our service.
Information quality
Your data quality is controlled by you. We provide tooling (deterministic merges, segments, the opt-in/out journal) to help you keep it accurate.
Openness
Our Privacy Policy describes what we collect for our own purposes (account, billing, ops). The Cookies Policy lists every cookie we set on this website.
Security safeguards
- TLS 1.2+ in transit.
- Every record tied to your account at the database level.
- Signed outbound webhooks.
- Automated nightly checks on billing records, and regular restore rehearsals.
Data subject participation
Data-subject requests received by RepletoryReach are forwarded to the relevant Responsible Party within one business day. Customers can fulfil access, correction and deletion requests via the platform's standard tools or the public API.
Cross-border transfers
Your data, where you are a South African customer, is processed and stored in South Africa. Transfers to sub-processors outside SA are covered by the Standard Contractual Clauses and our internal cross-border transfer assessment.
Breach notification
We commit to a 72-hour breach notification window to the Information Regulator and the affected Responsible Parties, where required by section 22 of POPIA.