Data Processing Agreement (DPA)
Last updated: 14 July 2026
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Yotta Prospecting Centre ("Yotta", "we", "us", or the "Processor") and the customer ("Customer", "you", or the "Responsible Party") who uses the Yotta platform (the "Service"). This DPA reflects the parties' agreement on the processing of personal information in accordance with the Protection of Personal Information Act, 2013 ("POPIA").
1. Roles and Responsibilities
The Customer acts as the responsible party (data controller) and determines the purposes and means of processing personal information through the Service. Yotta acts as the operator (data processor) and processes personal information on the Customer's documented instructions as set out in the Terms of Service and this DPA. Yotta will not process personal information for its own purposes except as necessary to provide and maintain the Service, comply with legal obligations, or protect its rights.
2. Scope of Processing
Yotta processes the following categories of personal information on behalf of the Customer:
- Lead data: prospect contact details (names, email addresses, phone numbers, company information) generated, validated, or uploaded through the Service;
- Account information: user names, email addresses, and business details provided during registration;
- Campaign data: email campaign content, sending records, and engagement metrics (opens, replies, bounces);
- Usage data: information about how the Customer interacts with the Service.
The duration of processing is limited to the period of the Customer's active subscription and a reasonable period thereafter for backup, legal compliance, and dispute resolution purposes.
3. Customer Obligations
The Customer warrants that it has a lawful basis under POPIA for collecting and processing the personal information it provides to Yotta, and that it has obtained any necessary consents from data subjects. The Customer is responsible for ensuring that its use of the Service, including lead generation and outreach activities, complies with POPIA, the Consumer Protection Act, and other applicable laws. The Customer must not provide Yotta with personal information that it is not lawfully entitled to process.
4. Security Measures
Yotta implements and maintains appropriate technical and organisational measures to protect personal information against unauthorised or unlawful access, accidental loss, destruction, or damage. These measures include:
- Encryption of data in transit using TLS 1.2 or higher;
- Role-based access controls restricting access to authorised personnel only;
- Secure session management with timeout and HttpOnly, Secure cookies;
- Regular security reviews and monitoring of access logs;
- Encrypted, automated daily backups with defined retention periods;
- Row-level security ensuring each Customer's data is isolated and not accessible to other users.
5. Sub-processors
Yotta may engage third-party service providers to assist in providing the Service (such as hosting, payment processing, and email delivery). Yotta remains responsible for the acts and omissions of its sub-processors and ensures that they are bound by written agreements providing at least the same level of data protection as set out in this DPA. Yotta maintains a list of sub-processor categories and will notify the Customer of any material changes. The Customer may object to the appointment of a new sub-processor on reasonable data protection grounds.
6. Data Subject Requests
Yotta will assist the Customer in responding to data subject requests relating to personal information processed through the Service, including requests for access, correction, or deletion. Where Yotta receives a data subject request directly, it will forward it to the Customer without responding, unless required by law to do otherwise. Yotta will provide reasonable assistance and information to enable the Customer to fulfil its obligations under POPIA within the required timeframes.
7. Breach Notification
In the event of a data breach involving the Customer's personal information, Yotta will notify the Customer without undue delay and no later than 48 hours after becoming aware of the breach. The notification will include the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed to address the breach. Yotta will cooperate with the Customer in notifying the Information Regulator and affected data subjects where required.
8. Data Return and Deletion
Upon termination of the Service or at the Customer's written request, Yotta will return or delete all personal information processed on behalf of the Customer, subject to any legal retention obligations. Deletion will be carried out within a reasonable period following termination, and Yotta will provide written confirmation upon request. Backups containing personal information will be overwritten in accordance with the standard backup retention cycle.
9. Audit Rights
The Customer may, at its own expense and with reasonable notice, request information from Yotta to verify compliance with this DPA. Yotta will provide reasonable cooperation and information, including summaries of its security practices and audit reports where available. On-site audits will be conducted only in exceptional circumstances and subject to a confidentiality agreement.
10. Changes to This DPA
We may update this DPA from time to time. We will post the updated version on this page with a revised "last updated" date. Continued use of the Service after changes constitutes acceptance of the updated DPA.
11. Contact Us
Questions about this DPA can be sent to hello@yotta.co.za or through our contact page.