Data Processing Addendum
Under POPIA · last updated 14 July 2026
1. Roles
Your organisation is the responsible party and determines the purpose and means of processing the personal information in the data you upload. VytlRx is the operator, processing it only on your documented instruction (including via your use of the product). On personal-information matters this DPA prevails over the rest of the agreement; the liability cap in the Terms/MSA is not increased by it.
2. Nature & scope
We host, store, organise, retrieve, back up, display and AI-assist your risk-management data to provide the service, for the term of the agreement plus the retention periods in our data-retention policy. Categories of data subjects and personal information are set out in the full DPA.
3. Our operator obligations (POPIA §§19–21)
We: process only on your instruction and never to train any AI model; maintain appropriate security safeguards (row-level tenant isolation, encryption, immutable audit, 2FA, backups); keep your data confidential; assist with data-subject requests; notify you of a security compromise without undue delay (§22); impose no-less-protective terms on sub-processors; and return or delete your data on termination, except records we must keep by law.
4. Cross-border transfers (§72)
Where sub-processing occurs outside South Africa (AI — Anthropic, US; email — Resend), we rely on POPIA §72: recipients are subject to protections affording an adequate level of protection and the transfer is necessary to perform the agreement. See the full sub-processor list on the legal page.
5. Your obligations & contact
You warrant you have a lawful basis to upload the personal information and to instruct the processing. The complete DPA (with annexes) is provided on request: avin@hbdadvisory.com.