Legal
Data Processing Agreement
Version 1.0 · Effective 14 August 2026
1. Definitions
Customer Data means data submitted to or generated through VulaLet by an authorised customer, including property, lease, tenant, applicant, maintenance, inspection, document, communication and financial records.
Personal Information has the meaning given in POPIA.
Responsible Party means the party determining the purpose and means of processing Personal Information.
Operator means a person processing Personal Information for a Responsible Party under POPIA.
Sub-processor means a third party appointed to support delivery, hosting, communications, payments, analytics, security or support.
2. POPIA roles
For tenant, applicant, contractor, property and portfolio records entered by an owner or managing agent, the customer is generally the Responsible Party and VulaLet acts as Operator. For VulaLet account management, billing, security, marketing, legal compliance and platform administration, VulaLet acts as Responsible Party for that limited processing.
3. Processing instructions
VulaLet processes Customer Personal Information only on documented customer instructions, including the agreement, account configuration, user permissions, feature settings, support requests, and lawful written instructions.
4. Purpose and duration
Processing is performed to provide, secure, support, maintain, improve and administer VulaLet. Processing continues for the subscription term and any legally required or agreed retention/export period.
5. Data categories
Data subjects may include owners, co-owners, tenants, applicants, agents, accountants, contractors, support users and supplier contacts. Data may include names, contact details, ID/passport numbers, lease records, application information, communications, maintenance evidence, payment records, bank-import data, documents and audit records.
6. Security measures
VulaLet uses technical and organisational controls including role-based access, row-level database security, encryption in transit, audit logging, secure upload handling, access reviews, backup controls, monitoring and secure development practices proportionate to the platform’s risk profile.
7. Sub-processors and cross-border transfers
The customer authorises VulaLet to use sub-processors required to deliver the platform. Where Personal Information is transferred outside South Africa, VulaLet will use appropriate safeguards consistent with POPIA. Current sub-processor details are available on request at legal@vulakomplex.co.za.
8. Security compromise notification
VulaLet will notify affected customers without undue delay after becoming aware of a confirmed security compromise involving Customer Personal Information, and will provide reasonable information needed for POPIA response obligations.
9. Data subject requests
VulaLet will reasonably assist customers with POPIA requests where the customer cannot respond using platform tools. Requests relating to customer-controlled tenant or applicant data may be referred to the relevant customer as Responsible Party.
10. Return and deletion
On termination, VulaLet will make Customer Data available for export for the period stated in the Terms, MSA or order terms. Data may then be deleted subject to legal retention obligations and backup cycles.