Legal

POPIA Posture

How RepletoryReach approaches the Protection of Personal Information Act (POPIA), and what we have built into the platform to support our customers' obligations.

Last updated: 2026-05-18

Our stance, in one sentence

We are an Operator under POPIA. We process personal information on documented instructions from our customers (the Responsible Parties), and we have engineered the platform around POPIA's eight conditions for lawful processing.

Accountability

Our Information Officer is the founder. The role is registered with the Information Regulator. Internal training on POPIA is part of onboarding for everyone with production access.

Processing limitation

We process only what is necessary to operate the service: phone numbers, names, message bodies, opt-in/out signals, conversation metadata, billing transaction IDs. We don't enrich data, profile contacts, or train models on customer content without explicit consent.

Purpose specification

Personal information is processed only for the purposes you (the Responsible Party) instruct us to: sending messages, recording conversations, billing usage, complying with our legal obligations.

Further processing limitation

We do not use your data for any other purpose. We do not sell, rent, or share it for marketing, advertising or analytics outside our service.

Information quality

Your data quality is controlled by you. We provide tooling (deterministic merges, segments, the opt-in/out journal) to help you keep it accurate.

Openness

Our Privacy Policy describes what we collect for our own purposes (account, billing, ops). The Cookies Policy lists every cookie we set on this website.

Security safeguards

  • TLS 1.2+ in transit.
  • Every record tied to your account at the database level.
  • Signed outbound webhooks.
  • Automated nightly checks on billing records, and regular restore rehearsals.

Data subject participation

Data-subject requests received by RepletoryReach are forwarded to the relevant Responsible Party within one business day. Customers can fulfil access, correction and deletion requests via the platform's standard tools or the public API.

Cross-border transfers

Your data, where you are a South African customer, is processed and stored in South Africa. Transfers to sub-processors outside SA are covered by the Standard Contractual Clauses and our internal cross-border transfer assessment.

Breach notification

We commit to a 72-hour breach notification window to the Information Regulator and the affected Responsible Parties, where required by section 22 of POPIA.

POPIA Posture · RepletoryReach