This Data Processing Agreement (DPA) forms part of the Terms of Service between you (the Controller) and LekkerApps (the Processor). It governs how we process personal data on your behalf in compliance with POPIA, GDPR, and other applicable data protection laws.
Scope and Purpose
LekkerApps processes personal data on your behalf to provide the platform services described in our Terms of Service. This includes storing contact information, form submissions, invoices, support tickets, and other business data you enter into the platform. Processing is limited to what is necessary to deliver the services.
Processor Obligations
As Processor, LekkerApps will process personal data only on your documented instructions, ensure staff are bound by confidentiality obligations, implement appropriate technical and organizational security measures, assist with data subject rights requests, delete or return data upon termination, and make available information necessary to demonstrate compliance.
Sub-Processors
LekkerApps uses approved sub-processors to deliver platform services. A current list is maintained at our Sub-Processor Register. We provide 30 days advance notice of new sub-processor additions, during which you may object. All sub-processors are bound by data processing obligations equivalent to this DPA.
Data Security
We implement encryption at rest and in transit, access controls with role-based permissions, audit logging, regular security assessments, and incident response procedures. For detailed security measures, see our Security Whitepaper.
Breach Notification
In the event of a personal data breach, LekkerApps will notify you without undue delay and no later than 72 hours after becoming aware of the breach. Notification includes the nature of the breach, categories and approximate number of affected records, likely consequences, and measures taken or proposed.
Cross-Border Transfers
Where personal data is transferred outside South Africa or the EEA, transfers are protected by Standard Contractual Clauses (SCCs) and adequate safeguards as required by POPIA Section 72 and GDPR Chapter V.
Request a Signed DPA
Enterprise customers requiring a countersigned DPA can submit a request through our Signed DPA Request form.