Data Processing Addendum
Version: 2026-08-18
Effective date: 18 August 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between SMSFlow (Pty) Limited (“SMSFlow”) and the Customer for Services under which SMSFlow processes personal information on Customer’s behalf. It is not a separate privacy policy or alternative terms of service.
1. Definitions
“Applicable Data Protection Law” means POPIA and any other data-protection law that applies to the processing under the agreement.
“Customer Data” means personal information submitted to, generated through, or processed by the Services on Customer’s behalf, including contacts, consent and suppression evidence, message and media content, templates, campaigns, inbox conversations, delivery events, integrations, and related metadata.
“Data Subject”, “operator”, “personal information”, “processing”, and “responsible party” have the meanings given by POPIA. “Subprocessor” means a third party appointed by SMSFlow to process Customer Data on Customer’s behalf.
2. Roles and instructions
Customer is the responsible party and SMSFlow is the operator for Customer Data, except where SMSFlow independently determines a processing purpose described in the Privacy Notice, such as its own account, security, abuse-prevention, audit, billing, legal-compliance, or platform-integrity processing.
SMSFlow will process Customer Data only:
- on Customer’s documented instructions in the agreement, configuration, authorised API calls, support requests, and use of the Services;
- to provide, secure, support, maintain, and bill for the Services;
- to comply with applicable law or a binding authority request; or
- as otherwise expressly agreed in writing.
If SMSFlow believes an instruction infringes Applicable Data Protection Law or provider rules, it may suspend the affected processing and notify Customer where lawful.
3. Customer obligations
Customer warrants that it:
- has authority and a lawful basis for Customer Data and instructions;
- provides all required notices and obtains and retains required consent;
- applies data minimisation, accuracy, retention, suppression, and purpose limitation;
- does not instruct SMSFlow to process prohibited or unauthorised data;
- responds to Data Subjects and regulators as responsible party;
- configures users, permissions, integrations, retention, exports, and channels securely;
- conducts any required impact, prior-authorisation, sector, cross-border, or children’s-data assessment; and
- informs SMSFlow before processing that requires safeguards beyond the contracted Services.
4. SMSFlow operator obligations
SMSFlow will:
- process Customer Data only with Customer’s knowledge or authorisation and treat it as confidential;
- not disclose Customer Data unless required by law, authorised by Customer, or necessary to an approved Subprocessor;
- ensure authorised personnel are subject to confidentiality obligations;
- maintain appropriate technical and organisational security measures;
- notify Customer if SMSFlow has reasonable grounds to believe Customer Data has been accessed or acquired by an unauthorised person, without undue delay and in accordance with the agreed incident process;
- provide reasonable assistance with Data Subject requests, security incidents, impact assessments, prior authorisation, and regulator enquiries, considering the nature of processing and information available;
- delete or return Customer Data on termination as described in this DPA; and
- make reasonable compliance information available and support agreed audits.
5. Security measures
The security programme should include, as appropriate:
- logical tenant isolation and server-authoritative tenant checks;
- role- and permission-based access, least privilege, authentication, and account lifecycle controls;
- encryption in transit and at rest where supported;
- secret storage by reference, credential rotation, and restricted administrative access;
- secure software development, dependency management, review, testing, and change control;
- network, endpoint, application, database, media, and integration safeguards;
- bounded payloads, file validation, malware-scanning hooks, authorised expiring media access, and safe logging;
- audit trails, monitoring, alerting, incident response, and evidence preservation;
- backups, recovery testing, availability safeguards, queue durability, idempotency, and duplicate protection;
- subprocessor security review and contractual protection; and
- secure deletion, de-identification, retention, and legal-hold processes.
SMSFlow is included within the Flownamix group’s ISO/IEC 27001:2022 certification, as stated in the applicable certificate and certified scope. The security measures applied under this DPA are governed by the group’s approved information-security management procedures and the technical and organisational measures applicable to the relevant production Services.
6. Subprocessors
Customer gives general authorisation for SMSFlow to appoint Subprocessors necessary to provide the Services, subject to this section. SMSFlow will:
- conduct reasonable diligence;
- impose written data-protection obligations appropriate to the processing;
- remain responsible for its obligations under this DPA;
- maintain a current public Subprocessor register; and
- provide the approved advance notice of a new or replacement Subprocessor.
Customer may object on reasonable data-protection grounds by sending the objection and reasons to the Privacy Officer within five Business Days or during any longer notice period stated in the Subprocessor register or agreement. The parties will seek a reasonable solution. If none is available, Customer may terminate the materially affected Service and receive a pro rata refund of prepaid fees for the unused portion of that affected Service, excluding non-refundable third-party or provider costs properly incurred for Customer.
7. Cross-border transfers
Customer authorises transfers necessary to provide the selected Services, including transfers to messaging and cloud providers, provided SMSFlow uses an applicable condition under POPIA section 72 and documents the relevant location and safeguard in the Subprocessor register or agreement.
Where an additional transfer instrument is legally required, the parties will execute it. SMSFlow will not rely on blanket consent as the only universal transfer mechanism.
8. Data Subject requests
If SMSFlow receives a request relating primarily to Customer Data, it will, where lawful, refer the requester to Customer and notify Customer. SMSFlow will not independently respond in a way that conflicts with Customer’s lawful instruction unless required by law.
SMSFlow will provide reasonable assistance using available access, correction, export, suppression, and deletion capabilities. Customer is responsible for verifying the requester’s identity, deciding the response, and communicating with the requester, unless otherwise required.
9. Security compromises
SMSFlow will notify Customer immediately when it has reasonable grounds to believe Customer Data was accessed or acquired by an unauthorised person and will not wait for a complete investigation or final confirmation before providing the initial notice required by law. Available notice will describe the nature of the event, affected data and people, likely consequences, measures taken or proposed, and a contact point, subject to ongoing investigation and legal restrictions. SMSFlow will supplement the notice as material information becomes available.
The parties will cooperate on containment, investigation, evidence, notifications, remediation, and reasonable information requests. Customer is responsible for notifications as responsible party, with SMSFlow’s reasonable assistance. Neither party will make a misleading statement about responsibility or findings.
10. Retention, return, and deletion
During the agreement, Customer may use available export and deletion features subject to permissions, provider limitations, legal restrictions, and product bounds.
On termination or written instruction, SMSFlow will return or delete Customer Data within the approved period, except where retention is required for:
- law, tax, accounting, legal hold, claim, or regulatory duty;
- security, abuse, audit, and incident evidence;
- provider-cost, customer-charge, settlement, and reconciliation evidence;
- backups pending scheduled expiry; or
- suppression evidence necessary to prevent unwanted future contact.
Retained data remains protected and is processed only for the retention purpose. Provider-side data is subject to provider systems and terms. SMSFlow cannot delete data controlled independently by Meta, mobile networks, Customer integrations, or other responsible parties.
Customer may request reasonable assistance with an available export for 30 days after termination. Assistance after that period, custom extraction, or recovery from archives or backups may be quoted separately and remains subject to technical availability, law, provider limitations, and the approved retention schedule.
The approved retention periods are stated in the Privacy Notice and PAIA Manual. SMSFlow is implementing those periods across the Services through automated controls and documented operational procedures. Until a relevant automated control is available, SMSFlow applies the approved period through an appropriate operational process, subject to legal holds, backup expiry, provider limitations and the exceptions stated above.
11. Messaging providers and WhatsApp
Customer authorises SMSFlow to disclose Customer Data to the selected telecommunications and messaging providers to transmit messages, receive statuses and replies, manage templates and connections, and provide evidence. Meta/WhatsApp and mobile networks may independently process information under their own terms.
For WhatsApp offboarding, SMSFlow will take commercially reasonable steps to disable new processing, disconnect Customer-configured integrations or webhooks, remove SMSFlow-held secret references, and remove or revoke SMSFlow-held access where the provider supports it, while preserving Customer ownership and portability where possible.
12. Audits and compliance information
On reasonable written request, SMSFlow will provide information reasonably necessary to demonstrate compliance, such as relevant policies, summaries, certifications, penetration-test summaries, or independent reports that are available and appropriate.
If that information is insufficient and law requires further verification, Customer may request an audit no more than once annually, unless a confirmed incident or regulator requires otherwise. Audits must be scoped, scheduled, confidential, non-disruptive, and avoid access to another customer’s data or SMSFlow security-sensitive information.
Any auditor must be independent, suitably qualified and professionally bound by confidentiality obligations, and must not be a competitor of SMSFlow or reasonably likely to create a security or confidentiality risk.
Customer must ensure that its auditors, advisers and representatives are bound by written confidentiality obligations no less protective than those applying under this DPA or the agreement. Audit findings, reports and other information obtained through an audit are SMSFlow Confidential Information and may be used only to verify compliance or satisfy Customer's applicable legal or regulatory obligations.
Customer bears the costs of a Customer-requested audit. However, if an audit conducted in accordance with this section confirms a material breach of this DPA by SMSFlow, SMSFlow will reimburse Customer's reasonable, documented and pre-approved external audit costs directly attributable to verifying that material breach, subject to the applicable liability limitations under the agreement. SMSFlow bears the cost of an audit requested by SMSFlow and its reasonable internal remediation costs for a confirmed breach.
13. Government and legal requests
If SMSFlow receives a binding request for Customer Data, it will verify authority, disclose only what is legally required, and notify Customer before disclosure where legally permitted. SMSFlow may challenge an overbroad request where reasonable but is not required to litigate at its own cost.
14. Liability and conflict
Liability under this DPA is subject to the liability framework in the agreement unless Applicable Data Protection Law requires otherwise. If this DPA conflicts with the Terms about operator processing, this DPA prevails for that subject.
15. Processing details
Subject matter and duration
Provision of the contracted SMSFlow Services for the subscription term, post-termination period, and legally required retention.
Nature and purpose
Collection, import, storage, organisation, validation, deduplication, retrieval, consultation, template and campaign preparation, transmission, receipt, routing, assignment, automation, reporting, support, security, suppression, audit, billing evidence, reconciliation, export, deletion, and other processing instructed through the Services.
Data Subject categories
Customer personnel and users; prospects and customers; message recipients and contacts; inbox participants; supplier or partner contacts; complainants; and other people whose information Customer lawfully submits.
Personal-information categories
Identity and contact details; account and user data; custom contact fields; consent and suppression evidence; message, media, template, campaign, conversation, assignment, note, and automation data; delivery and provider events; device, API, webhook, security, audit, and diagnostic data; and usage, pricing, billing, and reconciliation evidence.
Special personal information
Not intended unless expressly approved in the agreement and protected by appropriate lawful basis and safeguards.
Customer instructions
The agreement, configured settings, authorised user actions, API requests, support instructions, and documented written instructions consistent with the Services.
