VULAKOMPLEX™UnKomplexicated. Guaranteed.
FeaturesPricingFor TrusteesFor AgentsAboutContact
Log inSign Up

Legal

Data Processing Agreement

POPIA Operator Agreement

Version 1.7 · Effective 21 September 2026

POPIA roles: For community scheme data (Scheme Data), the Body Corporate, HOA or other Scheme Entity is the Responsible Party and VulaKomplex is the Operator. A Managing Agent accessing a Scheme workspace acts as an authorised administrator of the Scheme Entity — not as the data owner. The Scheme Entity remains responsible for ensuring a lawful basis exists before submitting Personal Information to the Platform.

1. Definitions

POPIAThe Protection of Personal Information Act 4 of 2013 and its regulations.
Information RegulatorThe Information Regulator established under POPIA.
AgreementThe Master SaaS Subscription Agreement (MSA) between VulaKomplex and the Customer, including this DPA and the other documents that form part of it.
CustomerThe Scheme Entity or Managing Agent that has accepted the Agreement with VulaKomplex. Where a Managing Agent is the Customer, it accepts this DPA both in its own name and as agent for each Scheme Entity whose Scheme workspace it administers (see clause 12).
Customer DataData, documents, communications, financial records and other content submitted to or generated through the Platform, including Scheme Data. Customer Personal Information means the Personal Information within Customer Data.
PlatformThe VulaKomplex software, websites, applications, databases and related services described in the MSA.
Scheme EntityA body corporate, HOA, POA, NPC or other governance entity responsible for a community scheme. The Scheme Entity is the Responsible Party for Scheme Data under POPIA.
Scheme DataPersonal Information relating to a community scheme, including owner, resident, occupant, levy, maintenance, access-control, communication and governance records.
Managing AgentA person or entity appointed by a Scheme Entity to administer a Scheme workspace. A Managing Agent may also be the Billing Party for one or more Scheme workspaces, but does not acquire ownership of or Responsible Party status over Scheme Data.
Billing PartyThe Customer, Scheme Entity, Managing Agent or other approved entity responsible for paying VulaKomplex fees. The Billing Party may differ from the Scheme Entity and from the POPIA Responsible Party for Scheme Data.
Personal InformationPersonal information as defined in POPIA, including information relating to an identifiable living natural person and, where applicable, an identifiable juristic person.
Responsible PartyThe party determining the purpose and means of processing Personal Information under POPIA.
OperatorA person or entity processing Personal Information for a Responsible Party under POPIA.
Sub-processorA third party appointed by VulaKomplex to support delivery of the Platform.

4. Categories of data subjects and data

Data subjectsTrustees, owners, residents, occupiers, managing-agent personnel, contractors, visitors, employees, support users and supplier contacts.
Personal informationNames, contact details, unit details, access logs, maintenance requests, communications, documents, meter readings, billing references, images and other platform records.
Special/sensitive dataThe Platform should not intentionally collect special personal information unless required by a specific module and authorised by the Customer.

2. POPIA roles

For Scheme Data, the Scheme Entity is the Responsible Party and VulaKomplex is the Operator. The Scheme Entity determines the purposes and means for processing Scheme Data regardless of whether the Scheme Entity pays VulaKomplex directly, a Managing Agent pays the invoice as part of its service to the Scheme Entity, or a Managing Agent operates the Scheme workspace day-to-day. A Managing Agent does not acquire Responsible Party status through its appointment, platform access or payment of VulaKomplex fees. Where VulaKomplex processes Personal Information for its own purposes — billing, security, legal compliance and CRM — VulaKomplex acts as a Responsible Party for that limited processing.

3. Processing instructions

VulaKomplex will process Customer Personal Information only with the knowledge and authorisation of the Responsible Party and on documented Customer instructions, including instructions contained in the Agreement, configuration settings, user permissions, support requests and lawful written instructions (section 20 of POPIA). VulaKomplex will treat Customer Personal Information as confidential and will not disclose it unless the law requires it or it is necessary in the proper performance of VulaKomplex's duties. Where a Managing Agent gives instructions for Scheme Data, it warrants that those instructions are given under authority from the relevant Scheme Entity. If VulaKomplex receives conflicting instructions from a Scheme Entity and a Managing Agent, VulaKomplex may require proof of authority and may give priority to the Scheme Entity's lawful instruction for its own Scheme Data.

3A. Responsible Party responsibilities

The Responsible Party (the Scheme Entity), and any Managing Agent acting for it, is responsible for: having a lawful ground under POPIA for the Personal Information it submits to the Platform; giving data subjects the notice required by section 18 of POPIA; keeping its instructions to VulaKomplex lawful; ensuring that its Information Officer is appointed and registered as POPIA requires; and deciding whether and how to notify the Information Regulator and data subjects of a security compromise. VulaKomplex may refuse an instruction that it reasonably believes is unlawful.

5. Purpose and duration

Processing is carried out to provide, secure, support, maintain, improve and administer the Platform. Processing continues for the subscription term and any legally required or agreed retention/export period after termination.

6. Security measures

VulaKomplex will establish and maintain the security measures required by section 19 of POPIA: appropriate, reasonable technical and organisational measures to prevent loss of, damage to or unauthorised destruction of Customer Personal Information, and unlawful access to or processing of it. VulaKomplex will identify reasonably foreseeable internal and external risks, maintain safeguards against them, verify regularly that the safeguards are effectively implemented, and update them in response to new risks or deficiencies. These measures include: • Role-based access controls and least-privilege administration. • Encryption in transit and, where technically supported, at rest. • Multi-factor authentication for administrator, managing-agent and trustee roles. • Audit logging for material account, security, data and configuration events. • Secure development and change-management practices. • Backups, monitoring and vulnerability management proportionate to the business stage and risk profile. • Confidentiality obligations for all personnel and contractors.

7. Sub-processors

The Customer authorises VulaKomplex to use Sub-processors necessary to provide the Platform. VulaKomplex will maintain a Sub-processor Register and impose contractual obligations designed to protect Personal Information. VulaKomplex remains responsible to the Customer for Sub-processor performance. The current Sub-processor Register is available on request at legal@vulakomplex.co.za. VulaKomplex will notify the Customer of any intended addition or replacement of a Sub-processor. The Customer may object only in writing, within 14 days of the notice, on reasonable data-protection grounds. If the Customer objects, VulaKomplex will use reasonable efforts to accommodate the objection; where not possible, either party may terminate only the affected service on 30 days' written notice. A Customer that does not object within 14 days is treated as having accepted the change.

8. Cross-border transfers

Customer Personal Information may be hosted, stored or processed outside South Africa by VulaKomplex or its Sub-processors, and the Customer authorises this, only where a ground in section 72 of POPIA is met. In particular, the recipient must be subject to a law, binding corporate rules or a binding agreement that provides an adequate level of protection substantially similar to the conditions for lawful processing in POPIA, or another ground in section 72 must apply. VulaKomplex will disclose cross-border Sub-processors in the Sub-processor Register.

9. Security compromise notification

VulaKomplex will notify the Customer immediately, and in any event within 72 hours, after becoming aware of a security compromise affecting Customer Personal Information, or of reasonable grounds to believe that Customer Personal Information has been accessed or acquired by an unauthorised person (section 21(2) of POPIA). The 72-hour period is an outer limit and does not delay the duty to notify immediately. VulaKomplex will not wait for an investigation to be completed before notifying. Where information is incomplete, VulaKomplex will notify on what it has and update the Customer as its investigation progresses. The notice will describe, as far as it is known: the nature of the compromise; the categories and approximate number of data subjects and records affected; the possible consequences; the measures VulaKomplex has taken or intends to take; the measures the Customer and data subjects may take to reduce the possible adverse effects; and, if known, the identity of the unauthorised person. VulaKomplex will give the Customer the information it reasonably needs to complete the Information Regulator's prescribed security compromise notification form and to notify data subjects. Where the Customer is a Managing Agent, VulaKomplex may give notice to the Managing Agent as the Scheme Entity's authorised administrator, and will also notify the Scheme Entity's registered contact where the Scheme Entity has asked for direct notice or the Managing Agent's authority is in doubt. Under section 22 of POPIA, the Responsible Party must notify the Information Regulator and the affected data subjects as soon as reasonably possible after the discovery of the compromise, unless a public body responsible for the prevention, detection or investigation of offences, or the Information Regulator, determines that notification would impede a criminal investigation. VulaKomplex will assist reasonably and will not itself notify the Information Regulator or data subjects about Scheme Data unless the law requires it or the Responsible Party instructs it.

10. Data subject requests

VulaKomplex will reasonably assist the Customer to respond to data subject requests for access to, or the correction or deletion of, personal information (sections 23 to 25 of POPIA) where the Customer cannot respond using Platform functionality. If a data subject contacts VulaKomplex directly about Scheme Data, VulaKomplex will refer the data subject to the Responsible Party and tell the Customer, unless the law requires otherwise. VulaKomplex may charge reasonable fees for complex, repetitive or manual assistance unless caused by VulaKomplex's breach.

11. Return and deletion

On termination, VulaKomplex will make Customer Data available for export for 30 days after termination. Scheme Data may be exported by the Scheme Entity or by a Managing Agent while it remains authorised for that Scheme Entity. After the 30-day export period, VulaKomplex will soft-delete Customer Data, meaning it is removed from the Platform and is no longer accessible to users. VulaKomplex will permanently delete Customer Data from production systems 90 days after termination, in each case subject to legal retention obligations, legal holds and backup cycles. VulaKomplex will not keep Customer Personal Information for longer than this clause allows, except where the law requires or authorises a longer period (section 14 of POPIA), and will then limit its processing to that purpose. Export tools and assistance are as described in clause 20 of the MSA. If a Scheme Entity confirms in writing, within the 30-day export period, that it wishes to continue its Scheme workspace directly or through a replacement Managing Agent, VulaKomplex will not soft-delete or permanently delete that Scheme Data while the transfer is completed (MSA clause 8B).

12. Managing Agent access, Scheme Data ownership and billing

Scheme Data belongs to the Scheme Entity and not to the Managing Agent, VulaKomplex or any individual platform user. Payment of fees by a Managing Agent does not make the Managing Agent the owner of Scheme Data or the Responsible Party for Scheme Data under POPIA. Direct payment by the Scheme Entity does not change VulaKomplex's Operator role for Scheme Data. The Scheme Entity may at any time direct VulaKomplex to remove, replace, suspend or limit a Managing Agent's access. A Managing Agent must promptly notify VulaKomplex if its authority to administer a Scheme workspace ends or is materially disputed. VulaKomplex may require reasonable proof of authority — including a trustee resolution, chairperson confirmation, AGM/SGM resolution, or appointment/termination letter — before making such changes. Where a Managing Agent pays fees on behalf of multiple Scheme Entities, each Scheme Entity remains the Responsible Party for its own Scheme Data. Scheme Data is ring-fenced per scheme workspace. A Managing Agent's payment account may consolidate invoices or allocate costs across schemes, but that billing arrangement does not merge Scheme Data or transfer Scheme Data ownership. Where a Managing Agent accepts this DPA, it does so as agent for each Scheme Entity whose Scheme workspace it administers, and warrants that it has authority to do so. Each such Scheme Entity is bound by this DPA for its own Scheme Data as if it had signed it, so that this DPA is the written contract between that Scheme Entity, as Responsible Party, and VulaKomplex, as Operator, for the purposes of POPIA. A Scheme Entity that signs or accepts this DPA directly also confirms that it has appointed the Managing Agent that administers its Scheme workspace, and authorises that Managing Agent to accept the Master SaaS Subscription Agreement, the Terms of Service and the Subscription Agreement (and updates to them) as its agent for that workspace, as set out in clause 8B of the MSA. VulaKomplex may ask a Scheme Entity to confirm this DPA directly where a Managing Agent's authority is missing, has ended or is disputed.

13. Audits and assurance

The Customer may request reasonable written assurance of VulaKomplex's security and POPIA controls. On-site audits are subject to reasonable notice, confidentiality, security limitations, cost recovery and restrictions protecting other customers and VulaKomplex systems, and may not be requested more than once in any 12-month period unless following a security compromise affecting Customer Personal Information. This Agreement may be executed in counterparts — whether electronically or otherwise — each of which, when executed by the party signing it, shall be deemed an original. All counterparts together constitute one and the same agreement. The parties agree that an electronically executed counterpart has the same legal force as one executed in ink on paper. Questions about this Agreement or data subject requests: Email: legal@vulakomplex.co.za Address: 44 Amhurst Place, Midstream Estate, Olifantsfontein, Gauteng, 1692 Company registration: 2026/311419/07
VULAKOMPLEXUnKomplexicated. Guaranteed.

South Africa's all-in-one platform for body corporate and sectional title scheme management.

Registered in South Africa · ZAR · STSMA aligned

Solutions

  • For Trustees
  • For Managing Agents

Product

  • Features
  • Pricing
  • Referral partner
  • Book a demo
  • Log in

Company

  • About us
  • Contact

Legal

  • Privacy policy
  • Terms of service
  • Cookie policy
  • PAIA manual

© 2026 VulaKomplex. All rights reserved.

Built with ❤ in South Africa 🇿🇦

Log inSign Up