Legal
Data Processing Terms
- Version
- v1.3
- Effective
- Not yet effective
Private staging candidate — not yet effective or published.
Version: v1.3
Last updated: 28 September 2026
These Data Processing Terms ("DPT") form part of the Agreement between Whisprr (Pty) Ltd ("Whisprr") and the Customer. They apply when Whisprr processes Personal Information for the Customer in providing the Service.
1. Definitions and priority
1.1 Applicable Data Protection Law means POPIA and other privacy or data-protection law binding on the relevant processing. Customer Personal Information means Personal Information contained in Customer Data that Whisprr processes for the Customer. Operator, Personal Information, Processing, Responsible Party and Regulator have their meanings under POPIA, with equivalent terms under other applicable law read consistently.
1.2 Capitalised terms not defined here have the meaning in the Terms of Service. These DPT prevail over a conflict in the Agreement concerning Processing of Customer Personal Information. They do not reduce a data subject's mandatory rights.
2. Roles, scope and duration
2.1 The Customer is the Responsible Party and Whisprr is its Operator for Customer Personal Information processed to provide the Service. Each party is an independent Responsible Party for information it processes for its own contracting, account, personnel, security, payment, compliance and legal purposes.
2.2 The details of processing are in Schedule 1 and the accepted Order. Processing continues for the Agreement term and the limited export, return, deletion and lawful-retention periods.
2.3 If the Customer acts as operator for another Responsible Party, it warrants that it is authorised to appoint Whisprr and give the instructions in the Agreement. No term makes Whisprr a joint Responsible Party unless the parties expressly agree the particular activity in writing.
3. Customer instructions and duties
3.1 Whisprr will process Customer Personal Information only on documented instructions in the Agreement, Order, approved configuration and lawful support requests, except where law requires otherwise. If law permits, Whisprr will notify the Customer before legally required processing.
3.2 The Customer is responsible for the lawfulness, fairness and transparency of its processing; notices and lawful bases; data-subject and direct-marketing compliance; accuracy and minimisation of Customer Data; its approved knowledge and workflows; and instructions to Whisprr.
3.3 The Customer must not provide unlawful Customer Personal Information or configure the standard Service for solely automated legally significant decisions, children's information, special personal information, criminal-behaviour information, regulated advice or safety-critical decisions without prior written assessment and agreed safeguards.
3.4 Whisprr will promptly tell the Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law, unless prohibited. Whisprr may suspend the affected instruction while the parties resolve it.
4. Confidentiality and personnel
Whisprr will limit access to personnel and authorised providers who need it to perform the Service and are bound by confidentiality and appropriate data-protection duties. Whisprr remains responsible for its compliance with these DPT and will provide appropriate privacy and security awareness to relevant personnel.
5. Security
5.1 Whisprr will establish and maintain reasonable, appropriate technical and organisational measures to protect the confidentiality, integrity and availability of Customer Personal Information, taking account of the nature of the information, foreseeable risks, available measures and cost of implementation.
5.2 Measures may include tenant separation and authorisation controls, least privilege, authentication controls, encryption in transit and at rest where supported, audit and security logging, change and release controls, backup and recovery measures, vulnerability and dependency management, incident procedures, provider due diligence and periodic control review.
5.3 The Customer is responsible for its users, endpoints, credentials, lawful channel configuration, role assignments, integrations and secure transmission to the Service. Each party must promptly notify the other of a material security risk within its control.
6. Security compromises
6.1 Whisprr will notify the Customer without undue delay after it has reasonable grounds to believe Customer Personal Information has been accessed or acquired by an unauthorised person. The notice will include information reasonably available about the nature, affected data and people, likely consequences, containment and remediation, and a contact point. Initial notice need not await a complete investigation.
6.2 Whisprr will take reasonable steps to contain, investigate and remediate the compromise and cooperate with the Customer's lawful notification duties. The Customer, as Responsible Party, decides and makes required notices to data subjects and the Regulator, unless law requires Whisprr to notify directly. Whisprr will not notify third parties on the Customer's behalf without authority, except where law requires it.
6.3 Notice is not an admission of fault. Each party bears its own internal compliance costs; responsibility for other costs follows the Agreement and law.
7. Suboperators and provider register
7.1 The Customer gives general written authorisation for Whisprr to use suboperators required to provide and secure the Service. Current categories include cloud and database infrastructure, workflow automation, AI processing, dashboard or frontend infrastructure, business email and productivity, messaging and Meta services, payment processing, security and support.
7.2 Whisprr maintains a private provider and suboperator register and will provide provider-specific information where reasonably required for the Customer's legal or contractual assessment, subject to confidentiality, security and proprietary-architecture protections.
7.3 Whisprr will impose written privacy, confidentiality and security obligations appropriate to the processing and remains responsible for its obligations where a suboperator performs them.
7.4 Whisprr will give at least 30 days' notice, where practicable, before a new suboperator begins materially different processing of Customer Personal Information. The Customer may object within that period on reasonable, documented data-protection grounds. The parties will seek a commercially reasonable alternative. If none is reasonably available, either party may end the materially affected Service without a penalty for the unused prepaid portion; the Customer may not withhold unrelated fees.
8. Cross-border processing
8.1 Whisprr will transfer Customer Personal Information outside South Africa only where section 72 of POPIA and other Applicable Data Protection Law permit it, including through adequate legal protection, contractual safeguards, binding corporate rules, consent where valid, or another statutory ground.
8.2 The Customer must identify mandatory localisation or transfer restrictions before activation. Whisprr will provide reasonably available information about relevant regions and safeguards without being required to disclose security-sensitive architecture.
9. Data-subject and regulatory assistance
9.1 Taking account of the nature of Processing, Whisprr will reasonably assist the Customer to respond to lawful requests for access, correction, deletion, objection, restriction, portability where applicable, and review of automated decisions. If Whisprr receives a request concerning Customer Personal Information, it will refer it to the Customer unless law requires a direct response.
9.2 Whisprr will reasonably assist with data-protection impact or prior-authorisation assessments, security obligations, Regulator enquiries and consultations relating to the Service, considering the information available to Whisprr.
9.3 Routine assistance supported by the Service is included. Whisprr may charge agreed reasonable fees for exceptional, repetitive or customer-specific work not caused by Whisprr's breach, after giving an estimate.
10. Return, export, deletion and retention
10.1 The Customer may request an available tenant-scoped export during the Service and for 30 calendar days after termination. That request window does not postpone deletion.
10.2 Subject to law, an active Service and legitimate retention exceptions, Whisprr will delete or irreversibly de-identify identifiable Customer Personal Information in active systems as soon as reasonably practicable and no later than 60 days after termination or a valid deletion instruction.
10.3 Whisprr may retain limited accounting, payment, acceptance, legal, security, fraud and dispute records for their lawful periods, with processing restricted to that purpose. Protected residual copies may remain in backups until the normal lifecycle expires, will not be used for ordinary processing, and deletion or de-identification will be re-applied if restored.
10.4 Genuinely de-identified product-development data may be retained for up to 24 months, then deleted or further aggregated. Irreversible aggregate data that cannot reasonably identify a person may be retained longer.
11. Demonstrating compliance and audit
11.1 Whisprr will make reasonably necessary information available to demonstrate compliance, initially through current policies, control descriptions, provider information, test evidence or independent reports that can be shared lawfully.
11.2 If those materials are insufficient for a documented material risk, the Customer may request a proportionate remote audit no more than once in 12 months, except after a material compromise or regulator request. Audits require reasonable notice, occur during business hours, avoid disruption, respect other customers' confidentiality and Whisprr's security and know-how, and use an independent qualified auditor bound by confidentiality. The Customer bears its audit costs unless the audit identifies a material Whisprr breach.
11.3 No audit permits access to another tenant's information, source code, penetration-test exploit detail, credentials or information whose disclosure would weaken security or breach law or contract. Whisprr will offer reasonable alternative evidence.
12. AI-specific controls
12.1 Whisprr may send the minimum necessary Customer Personal Information to authorised AI providers to perform configured tasks. Customer conversations do not automatically become approved knowledge.
12.2 Whisprr will not use, or permit a provider to use, identifiable Customer conversations to train a public or general-purpose AI model without a separate written lawful basis and agreement.
12.3 The Customer must implement meaningful human oversight, restricted-topic rules and escalation appropriate to its use case. These safeguards do not change the parties' privacy roles.
13. Liability and termination
Liability under these DPT is governed by the Terms of Service, including the enhanced cap for data-protection, confidentiality and security obligations and the stated exclusions from limitation. Termination of the Agreement terminates these DPT, except for provisions that must continue to protect retained information.
14. Changes
Whisprr may update these DPT as permitted by the Terms. A material reduction in data-protection commitments or expansion of processing requires appropriate notice and, where required, renewed acceptance. These DPT do not silently replace terms applicable to a grandfathered v1 customer.
Schedule 1 — Processing details
Subject matter and purpose: Hosting and operating AI-assisted customer communications, messaging, routing, escalation, dashboard, support, security, billing and related functions in the Order.
Duration: The Agreement term plus the export, deletion, backup and lawful-retention periods in clause 10.
Nature of processing: Collection, receipt, organisation, storage, retrieval, consultation, analysis, AI inference, classification, generation, transmission, delivery, support, security monitoring, export, restriction, deletion and de-identification.
Data subjects: Customer personnel and Authorised Users; the Customer's leads, customers, guests, patients or other contacts; suppliers and business contacts; and persons represented in communications.
Information types: Identity and contact details; account and authority records; conversation text and media; channel identifiers and delivery metadata; approved knowledge; booking, enquiry, preference and support information; classifications, summaries and AI output; transaction, subscription and Credit information; consent, opt-out, audit, security and technical logs.
Sensitive information: Not intended for standard use. Any approved health, children's, biometric, criminal-behaviour or other special Personal Information must be expressly scoped, lawful and protected by additional safeguards.
Frequency: As initiated by the Customer, Authorised Users, customer contacts and configured workflows during the Service.
Suboperator categories: Those in clause 7.1 and the private register.
Customer instructions: The Agreement, accepted Order, approved knowledge, configured workflows and lawful support instructions.