1. Introduction and incorporation
This Data Processing Agreement ("DPA") forms part of the agreement between:
- Zuri Client Lync (Proprietary) Limited, trading as Zuri Client Lync ("Zuri", "Operator", "we", "us"); and
- the business entity or sole proprietor that uses the Zuri platform ("Customer", "you", "Responsible Party").
This DPA applies when you use the Platform to process personal information about your data subjects (including clients, patients, customers, staff, and other individuals whose personal information you upload or generate through the Platform).
This DPA is incorporated into and forms part of our Terms of Service. It should be read with our Privacy Policy. If there is a conflict regarding the processing of personal information in Customer Data, this DPA prevails over the Terms and Privacy Policy.
By using the Platform to process personal information about data subjects, you enter into this DPA on behalf of the Customer.
This DPA is intended to satisfy the requirements of section 21 of POPIA (and related regulations) for a written contract between a responsible party and an operator.
2. Definitions
In this DPA:
- "Customer Data" means data, content, and personal information submitted to or generated through the Platform by or for you, excluding personal information for which Zuri is the responsible party under the Privacy Policy.
- "Data subject" means the individual to whom personal information relates.
- "Personal information" has the meaning in the Protection of Personal Information Act 4 of 2013 (POPIA).
- "Processing" has the meaning in POPIA and includes any operation on personal information, whether automated or not.
- "Responsible party" means the entity that determines the purpose and means of processing personal information — you, for Customer Data about your data subjects.
- "Operator" means a person who processes personal information on behalf of a responsible party — Zuri, for Customer Data processed through the Platform.
- "Security compromise" has the meaning in POPIA (commonly referred to as a data breach).
- "Special personal information" has the meaning in POPIA.
- "Sub-processor" means any third party engaged by Zuri to process Customer Data on our behalf.
Terms capitalised but not defined here have the meanings in the Terms of Service.
3. Roles and scope
3.1 Roles
| Party | POPIA role | Scope |
|---|---|---|
| Customer | Responsible party | Determines why and how personal information about your data subjects is processed; provides notices and obtains consents |
| Zuri | Operator | Processes Customer Data only on your documented instructions to provide the Platform |
Zuri is the responsible party for personal information about your account holders and Authorised Users — that processing is governed by the Privacy Policy, not this DPA.
3.2 Scope of processing
This DPA covers personal information in Customer Data that you or Authorised Users submit to, store in, or transmit through the Platform, including personal information contained in:
- client and patient records, profiles, and notes;
- appointment, session, and treatment data;
- sales, POS, inventory, and dispensary compliance records;
- loyalty, wallet, and payment-related records linked to individuals;
- consent and marketing preference records;
- messages and notifications sent to or received from data subjects;
- files, images, and documents you upload; and
- audit logs relating to the above.
3.3 Exclusions
This DPA does not apply to:
- aggregated or de-identified data that no longer identifies a data subject;
- personal information Zuri processes as a responsible party for its own purposes (see Privacy Policy); or
- third-party services you connect directly outside Zuri's processing environment, except where Zuri acts as an integration conduit on your instructions.
4. Customer obligations (Responsible Party)
You represent, warrant, and agree that:
4.1 Lawful processing
- you have established a lawful basis under POPIA for all processing you instruct through the Platform;
- you have provided data subjects with required notices and obtained required consents, including for direct marketing and cross-border transfers where applicable;
- you will not instruct Zuri to process personal information in violation of POPIA or other applicable law.
4.2 Accuracy and minimisation
- Customer Data is relevant, adequate, and not excessive for your stated purposes;
- you will correct or delete inaccurate data using Platform tools or by instructing us where necessary;
- you will not upload special personal information unless you have lawful authority and appropriate safeguards.
4.3 Authorised users and access
- you control Authorised User access through roles and permissions;
- you will ensure only personnel with a need to know can access Customer Data;
- you are responsible for all processing performed through your account.
4.4 Instructions
- your use of the Platform in accordance with documentation and configuration constitutes documented instructions;
- additional written instructions may be sent to info@zuri-lync.com;
- you will not instruct processing outside Platform functionality except as we agree in writing.
4.5 Data subject requests
- you are primarily responsible for responding to data subject access, correction, deletion, and objection requests;
- you will notify us promptly if you require our assistance.
4.6 Regulatory compliance
- you comply with sector-specific obligations (healthcare, cannabis/dispensary, financial services, legal profession, etc.) that apply to your business;
- you maintain records of processing and consent as required by POPIA.
4.7 Indemnity
You indemnify Zuri against claims arising from your unlawful instructions, missing consents, or breach of this DPA, to the extent permitted by law (see also Terms Section 15).
5. Zuri obligations (Operator)
Zuri will:
5.1 Process on instructions only
Process Customer Data only on your documented instructions, including as necessary to:
- host, store, organise, and display Customer Data;
- execute workflows you configure (appointments, sales, inventory, loyalty, messaging);
- transmit Customer Data to Sub-processors and integrations you enable;
- create backups and disaster-recovery copies;
- generate reports and exports available within your account;
- comply with applicable law where we are legally required to process otherwise (we will inform you unless prohibited).
If we are required by law to process Customer Data contrary to your instructions, we will notify you unless legally prohibited.
5.2 Confidentiality
Ensure personnel authorised to process Customer Data are bound by confidentiality obligations and receive appropriate privacy and security training.
5.3 Security
Implement appropriate technical and organisational measures to protect Customer Data, having regard to:
- the nature of the personal information;
- the risks associated with processing;
- industry practice for SaaS business platforms; and
- cost of implementation.
See Section 8 for further detail.
5.4 Sub-processors
Engage Sub-processors only in accordance with Section 9.
5.5 Assistance
Provide reasonable assistance (at no additional charge for standard requests, or at agreed rates for extensive work) to help you:
- respond to data subject requests;
- conduct privacy impact assessments where required; and
- cooperate with the Information Regulator, subject to applicable law.
5.6 Breach notification
Notify you of Security Compromises in accordance with Section 11.
5.7 Deletion and return
Handle deletion and return of Customer Data in accordance with Section 12.
5.8 Records
Maintain records of processing activities relating to our operator role as required by POPIA.
6. Documented instructions and processing details
6.1 Default instructions
By subscribing to and using the Platform, you instruct Zuri to process Customer Data to provide the services described in the Terms and enabled in your account configuration.
6.2 Nature and purpose of processing
| Purpose | Examples |
|---|---|
| Client management | CRM records, contact details, preferences, notes |
| Scheduling | Appointments, sessions, reminders, calendar sync |
| Commerce | Sales orders, receipts, wallet/loyalty balances |
| Inventory & compliance | Product dispensing logs, audit trails where enabled |
| Communications | SMS, email, WhatsApp, push notifications you trigger |
| Reporting | Dashboards, exports, analytics within your workspace |
| Security & support | Access logs, troubleshooting, abuse prevention |
6.3 Categories of data subjects
Your clients, patients, customers, staff, suppliers' contact persons, and any other individuals whose personal information you choose to store in the Platform.
6.4 Types of personal information
May include: names, contact details, identifiers, appointment and transaction history, payment references (not full card numbers stored by Zuri), health or treatment notes you enter, images and documents, consent records, IP addresses in logs, and special personal information only if you upload it.
6.5 Duration
Processing continues for the Subscription term and any wind-down, backup, or legal retention period described in Section 12 and the Privacy Policy.
7. Confidentiality
Zuri treats Customer Data as confidential. We restrict access to personnel and Sub-processors with a need to know. Confidentiality obligations survive termination of the DPA.
You must likewise protect access credentials and any personal information exported from the Platform.
8. Security measures
Zuri maintains a security programme that includes measures such as:
8.1 Organisational measures
- access control policies and role-based permissions in the Platform;
- security awareness for personnel with data access;
- vendor risk review for Sub-processors;
- incident response and escalation procedures.
8.2 Technical measures
- encryption in transit (TLS) for data transmitted over public networks;
- logical separation of Customer Data by organisation/tenant;
- authentication controls, including support for multi-factor authentication via identity providers;
- logging of administrative and security-relevant events;
- regular backups and tested recovery procedures;
- vulnerability management and patching practices for our systems.
8.3 Limitations
You acknowledge that no security is perfect. Zuri does not guarantee that unauthorised access, loss, or alteration can be prevented. You are responsible for configuring permissions, strong passwords, and timely removal of access for departing users.
Further security documentation (e.g. summary security overview) is available on request at info@zuri-lync.com, subject to confidentiality.
9. Sub-processors
9.1 Authorisation
You provide general written authorisation for Zuri to engage Sub-processors to process Customer Data, provided we:
- impose data protection obligations on Sub-processors substantially similar to this DPA; and
- remain liable to you for Sub-processor performance as set out in Section 9.4.
9.2 Current categories
Sub-processors may include providers of:
- cloud infrastructure and database hosting;
- identity and authentication;
- email, SMS, WhatsApp, and push delivery;
- payment processing;
- error monitoring and logging;
- customer support tooling.
9.3 Changes
We will maintain a list of material Sub-processors available on request. We will notify account owners of material Sub-processor changes via email or in-app notice with at least 14 days' notice where practicable. You may object on reasonable POPIA-related grounds by contacting info@zuri-lync.com within that period. If we cannot accommodate a valid objection, you may terminate the affected services or Subscription as your sole remedy.
9.4 Liability
Zuri remains fully liable to you for Sub-processor obligations to the same extent Zuri would be liable if performing the services directly, except where POPIA or other law requires otherwise.
10. International transfers
Customer Data may be processed in South Africa and other countries where Sub-processors operate. Where personal information is transferred outside South Africa, Zuri will implement safeguards required by POPIA section 72, which may include:
- transfers to countries with adequate protection;
- binding agreements with recipients; or
- your consent where required.
You instruct us to make such transfers as necessary to provide the Platform.
11. Security compromises (data breaches)
11.1 Notification to Customer
If Zuri becomes aware of a Security Compromise affecting Customer Data, we will notify you without undue delay and, where feasible, within 72 hours of confirmation, including, to the extent known:
- the nature of the compromise;
- categories and approximate number of data subjects and records affected;
- likely consequences;
- measures taken or proposed to address the compromise; and
- a contact point for further information.
11.2 Your obligations
You are responsible for assessing whether notification to data subjects and the Information Regulator is required. We will provide reasonable assistance consistent with Section 5.5.
11.3 Unauthorised access by third parties
Compromises caused by your compromised credentials, misconfigured permissions, or Authorised User misconduct remain your responsibility, except to the extent caused by Zuri's failure to meet its security obligations under this DPA.
12. Deletion, return, and retention
12.1 During the Subscription
You may export Customer Data using Platform features where available. You may delete records through the Platform subject to audit and compliance features that may retain certain logs.
12.2 Upon termination
After Subscription termination or on your written request:
- we will delete or return Customer Data within 90 days, unless you request an earlier deletion window and we can accommodate it;
- you may download exports before termination — we are not liable for data you fail to export;
- residual copies may persist in encrypted backups for up to 90 days before overwrite in the normal backup cycle; and
- we may retain personal information where required by law, for establishment, exercise, or defence of legal claims, or as documented in our Privacy Policy.
12.3 Certification
On written request, we will provide reasonable confirmation that deletion has been completed, subject to legal retention exceptions.
13. Data subject rights
13.1 Your responsibility
You are the primary contact for data subjects whose personal information you control. Your privacy notices should explain how data subjects can exercise POPIA rights.
13.2 Our assistance
If we receive a request directly from a data subject relating to Customer Data, we will promptly redirect the request to you unless legally required to respond ourselves.
Upon your request, we will provide reasonable technical assistance to help you:
- access, correct, or delete personal information in the Platform;
- export data in a commonly used format where features exist; and
- restrict or object to processing where technically feasible.
We may charge reasonable fees for manifestly excessive or repetitive requests, where permitted by POPIA.
14. Audits and information
14.1 Information on compliance
Upon written request no more than once per 12-month period (unless required by a Security Compromise or regulator), we will provide:
- summaries of relevant security and privacy controls;
- responses to reasonable security questionnaires; and
- Sub-processor information.
14.2 On-site audits
On-site or intrusive audits are not permitted by default. If POPIA or a regulator requires an on-site audit, the parties will agree in good faith on scope, timing, confidentiality, and cost allocation. Audits must not unreasonably disrupt operations or expose other customers' data.
14.3 Regulator requests
We will cooperate with lawful requests from the Information Regulator relating to Customer Data we process on your behalf, and notify you where permitted.
15. Special personal information
Do not upload special personal information unless necessary for your lawful business purposes and you have complied with POPIA section 26 and related requirements.
If you upload special personal information, you instruct us to process it solely to provide the Platform features you use, and you confirm you have obtained explicit consent or another permitted ground under POPIA.
Zuri applies enhanced access controls where practicable but does not warrant that the Platform alone satisfies all sector-specific clinical or cannabis record-keeping rules — that remains your compliance obligation.
16. Limitation of liability
To the maximum extent permitted by law:
- Zuri's aggregate liability under this DPA is subject to the limitation of liability in the Terms (fees paid in the preceding 12 months or ZAR 5,000, whichever is greater, except where law requires otherwise);
- neither party is liable for indirect or consequential damages as set out in the Terms;
- Zuri is not liable for processing performed in accordance with your unlawful instructions or due to your security failures.
Nothing in this DPA excludes liability that cannot be excluded under POPIA or other applicable law.
17. Term and termination
This DPA commences when you first process Customer Data through the Platform and continues until:
- your Subscription terminates and deletion/return under Section 12 is complete; or
- replaced by a superseding written agreement.
Sections that by nature should survive (confidentiality, security, liability, audits, and dispute resolution) survive termination.
18. Changes to this DPA
We may update this DPA to reflect legal, regulatory, or operational changes. Material changes will be notified to account owners with at least 30 days' notice where practicable and may require renewed acceptance through the Platform legal acceptance flow.
Continued processing after the effective date constitutes acceptance, except where POPIA requires explicit consent.
19. Governing law and disputes
This DPA is governed by the laws of the Republic of South Africa. Disputes are subject to the dispute resolution and jurisdiction provisions in the Terms.
20. Contact
Data protection / operator enquiries:
Email: info@zuri-lync.com
Subject line: DPA / POPIA Operator Request
Entity: Zuri Client Lync (Proprietary) Limited
For account-holder personal information (Zuri as responsible party), see the Privacy Policy.
Annex A — Summary of processing (reference)
| Item | Description |
|---|---|
| Responsible party | Customer (your business) |
| Operator | Zuri Client Lync (Proprietary) Limited |
| Subject matter | Provision of the Zuri Platform |
| Duration | Subscription term + wind-down/backup periods |
| Data subjects | Your clients, staff, and other individuals you add |
| Personal information types | As described in Section 6.4 |
| Processing operations | Storage, retrieval, display, transmission, deletion, backup |
| Special categories | Only if uploaded by Customer with lawful basis |
| Cross-border transfers | As described in Section 10 |
| Security | As described in Section 8 |
| Sub-processors | As described in Section 9 |
Related documents
| Document | Purpose |
|---|---|
| Terms of Service | Platform use, billing, general liability |
| Privacy Policy | Zuri as responsible party for account data |
| Marketing Communications Policy | Marketing consent framework |
