Legal
Data Processing Agreement
POPIA Operator Agreement
Version 1.2 · Effective 16 June 2026
POPIA roles: For community scheme data (Scheme Data), the Body Corporate, HOA or other Scheme Entity is the Responsible Party and VulaKomplex is the Operator. A Managing Agent accessing a Scheme workspace acts as an authorised administrator of the Scheme Entity — not as the data owner. The Scheme Entity remains responsible for ensuring a lawful basis exists before submitting Personal Information to the Platform.
1. Definitions
Scheme EntityA body corporate, HOA, POA, NPC or other governance entity responsible for a community scheme. The Scheme Entity is the Responsible Party for Scheme Data under POPIA.
Scheme DataPersonal Information relating to a community scheme, including owner, resident, occupant, levy, maintenance, access-control, communication and governance records.
Managing AgentA person or entity appointed by a Scheme Entity to administer a Scheme workspace. A Managing Agent does not acquire ownership of or Responsible Party status over Scheme Data.
Personal InformationPersonal information as defined in POPIA, including information relating to an identifiable living natural person and, where applicable, an identifiable juristic person.
Responsible PartyThe party determining the purpose and means of processing Personal Information under POPIA.
OperatorA person or entity processing Personal Information for a Responsible Party under POPIA.
Sub-processorA third party appointed by VulaKomplex to support delivery of the Platform.
4. Categories of data subjects and data
Data subjectsTrustees, owners, residents, occupiers, managing-agent personnel, contractors, visitors, employees, support users and supplier contacts.
Personal informationNames, contact details, unit details, access logs, maintenance requests, communications, documents, meter readings, billing references, images and other platform records.
Special/sensitive dataThe Platform should not intentionally collect special personal information unless required by a specific module and authorised by the Customer.
2. POPIA roles
For Scheme Data, the Scheme Entity is the Responsible Party and VulaKomplex is the Operator. The Scheme Entity determines the purposes and means for processing Scheme Data regardless of whether a Managing Agent operates the Scheme workspace day-to-day. A Managing Agent does not acquire Responsible Party status through its appointment.
Where VulaKomplex processes Personal Information for its own purposes — billing, security, legal compliance and CRM — VulaKomplex acts as a Responsible Party for that limited processing.
3. Processing instructions
VulaKomplex will process Customer Personal Information only on documented Customer instructions, including instructions contained in the Agreement, configuration settings, user permissions, support requests and lawful written instructions.
5. Purpose and duration
Processing is carried out to provide, secure, support, maintain, improve and administer the Platform. Processing continues for the subscription term and any legally required or agreed retention/export period after termination.
6. Security measures
• Role-based access controls and least-privilege administration.
• Encryption in transit and, where technically supported, at rest.
• Authentication controls and MFA for privileged access where available.
• Audit logging for material account, security, data and configuration events.
• Secure development and change-management practices.
• Backups, monitoring and vulnerability management proportionate to the business stage and risk profile.
• Confidentiality obligations for all personnel and contractors.
7. Sub-processors
The Customer authorises VulaKomplex to use Sub-processors necessary to provide the Platform. VulaKomplex will maintain a Sub-processor Register and impose contractual obligations designed to protect Personal Information. VulaKomplex remains responsible to the Customer for Sub-processor performance. The current Sub-processor Register is available on request at legal@vulakomplex.co.za.
VulaKomplex will notify the Customer of any intended addition or replacement of a Sub-processor. If the Customer objects, VulaKomplex will use reasonable efforts to accommodate the objection; where not possible, either party may terminate the affected service on 30 days' written notice.
8. Cross-border transfers
Customer Personal Information may be hosted, stored or processed outside South Africa where the relevant requirements of POPIA (including Chapter 9) are met, including appropriate contractual, organisational or legal safeguards. VulaKomplex will disclose cross-border Sub-processors in the Sub-processor Register.
9. Security compromise notification
VulaKomplex will notify the Customer without undue delay after becoming aware of a confirmed security compromise affecting Customer Personal Information. The notice will describe: the nature of the compromise; categories and approximate volume of data affected; likely consequences; mitigation steps taken; and recommended Customer actions.
10. Data subject requests
VulaKomplex will reasonably assist the Customer with data subject requests where the Customer cannot respond using Platform functionality. VulaKomplex may charge reasonable fees for complex, repetitive or manual assistance unless caused by VulaKomplex's breach.
11. Return and deletion
On termination, VulaKomplex will make Customer Data available for export for the period stated in the Data Retention and Deletion Policy or Order Form. After that period, VulaKomplex may delete Customer Data from production systems, subject to legal retention obligations and backup cycles.
12. Managing Agent access, Scheme Data ownership and billing
Scheme Data belongs to the Scheme Entity and not to the Managing Agent, VulaKomplex or any individual platform user. Payment of fees by a Managing Agent does not make the Managing Agent the owner of Scheme Data or the Responsible Party for Scheme Data under POPIA.
The Scheme Entity may at any time direct VulaKomplex to remove, replace, suspend or limit a Managing Agent's access. VulaKomplex may require reasonable proof of authority — including a trustee resolution, chairperson confirmation, AGM/SGM resolution, or appointment/termination letter — before making such changes.
Where a Managing Agent pays fees on behalf of multiple Scheme Entities, each Scheme Entity remains the Responsible Party for its own Scheme Data. Scheme Data is ring-fenced per scheme workspace.
13. Audits and assurance
The Customer may request reasonable written assurance of VulaKomplex's security and POPIA controls. On-site audits are subject to reasonable notice, confidentiality, security limitations, cost recovery and restrictions protecting other customers and VulaKomplex systems.
This Agreement may be executed in counterparts — whether electronically or otherwise — each of which, when executed by the party signing it, shall be deemed an original. All counterparts together constitute one and the same agreement. The parties agree that an electronically executed counterpart has the same legal force as one executed in ink on paper.
Questions about this Agreement or data subject requests:
Email: legal@vulakomplex.co.za
Address: 44 Amhurst Place, Midstream Estate, Olifantsfontein, Gauteng, 1692
Company registration: 2026/311419/07