Data Processing Addendum
Last updated: 20 July 2026 · Version: dpa-2026-07-20
This Data Processing Addendum (“DPA”) forms part of, and is incorporated by reference into, the Terms of Service between NexusAgents and the Customer (https://nexusagents.co.za/terms/), and governs the Processing of Personal Information by NexusAgents on behalf of the Customer. In the event of any conflict between this DPA and the Terms of Service, this DPA prevails with respect to the Processing of Personal Information.
1. Definitions
- “Personal Information” has the meaning given in the Protection of Personal Information Act, 2013 (POPIA);
- “Responsible Party” means the Customer (referred to in some jurisdictions as a controller);
- “Operator” means NexusAgents (referred to in some jurisdictions as a processor);
- “Data Subject” means the individual to whom Personal Information relates;
- “Processing” has the meaning given in POPIA;
- “Subprocessor” means any third party engaged by NexusAgents to Process Personal Information on the Customer’s behalf.
2. Roles of the Parties
The Customer determines the purposes and means of Processing and acts as the Responsible Party. NexusAgents acts solely as an Operator, Processing Personal Information on the Customer’s documented instructions.
3. Customer Obligations
You warrant and undertake that: you have a lawful basis for Processing Personal Information; you have provided all required notices to Data Subjects; you have obtained all necessary consents where required; you have the right to disclose Personal Information to NexusAgents; and your Processing instructions comply with applicable law.
4. Instructions
NexusAgents will Process Personal Information only on documented instructions from the Customer. All configurations made through the Service — including agent settings, AI permission settings (read/draft/send), approval and review workflows, automations, templates, integrations, and system settings — constitute your documented instructions. In particular, where you enable automated sending for a conversation, agent, or workflow, that configuration is your documented instruction to send communications without per-message human review.
NexusAgents is not responsible for reviewing, validating, or ensuring the legality of your instructions. If NexusAgents reasonably believes an instruction infringes applicable law, it may notify you and suspend the relevant Processing. NexusAgents does not independently determine the purposes or means of Processing and assumes no responsibility for the content, legality, or outcomes of Processing initiated by you.
5. Purpose and Nature of Processing
Processing includes: receipt, storage, and transmission of customer communications across messaging platforms (including the WhatsApp Business Platform under the Customer’s own WhatsApp Business Account); AI-assisted processing of prompts, inputs, outputs, and communication content, including transient transmission to third-party AI model providers to generate drafts and responses; management of contacts, leads, bookings, orders, tasks, and interaction history; workflow automation; and analytics, reporting, and system monitoring.
The Customer acknowledges that the accuracy, legality, and appropriateness of AI-generated outputs depend on the quality and lawfulness of the data and instructions provided, and that NexusAgents does not warrant that AI outputs will be error-free or suitable for any particular purpose.
6. Duration and Retention
Processing continues for the duration of the subscription and thereafter only for such period as required for backup, archival, legal, or operational purposes in accordance with NexusAgents’ retention practices and its Data Deletion Instructions (https://nexusagents.co.za/data-deletion-instructions/). The Customer is responsible for configuring and managing data retention settings within the Service, where available, to comply with its own policies and section 14 of POPIA. NexusAgents does not monitor or enforce Customer-specific retention policies.
7. Subprocessors
The Customer provides general authorisation for NexusAgents to appoint Subprocessors. The authoritative, current Subprocessor list — including each provider’s legal entity, service provided, data processed, processing location, engagement status, and applicable safeguards — is published at https://nexusagents.co.za/subprocessors/. As at the date of this DPA it includes: RackZar (hosting, South Africa); OpenAI, Anthropic, Google, and xAI (AI model providers, United States, transient processing, engaged at NexusAgents’ discretion per task); Meta Platforms (WhatsApp Business Platform); and PayGate/DPO Group (payments).
NexusAgents will: enter into written agreements with Subprocessors imposing data protection obligations substantially similar to this DPA; remain responsible for the performance of its Subprocessors to the extent required by applicable law; and maintain the list referred to above, providing prior notice of material changes by email, dashboard notice, or update to the published list.
You may object to a new Subprocessor on reasonable data protection grounds, in which case the parties will work in good faith to resolve the objection. If the objection cannot be resolved within a reasonable period, NexusAgents may either provide the affected functionality through an alternative Subprocessor, or permit you to terminate the affected functionality on written notice, with such termination applying only to the specific functionality concerned. Where the affected functionality is material to the Service as a whole and cannot reasonably be provided without the Subprocessor, your sole remedy is termination of the Service with a pro-rata refund of pre-paid, unused fees, and no further liability arises.
8. Security Measures
NexusAgents will implement appropriate, reasonable technical and organisational measures designed to protect Personal Information against unauthorised or unlawful Processing, loss, destruction, or damage, including where appropriate: encryption in transit and at rest; role-based access controls and authentication; multi-factor authentication for administrative access where applicable; logging, monitoring, and anomaly detection; regular updates and vulnerability management; and maintained incident response procedures. NexusAgents will review and update its security measures periodically. Security is a shared responsibility: you are responsible for securing your own credentials, workspace user access levels, configurations, integrations, and end-user environments. No system is completely secure, and absolute security cannot be guaranteed.
9. Confidentiality
NexusAgents will ensure that persons authorised to Process Personal Information are subject to appropriate confidentiality obligations.
10. Data Subject Rights
Taking into account the nature of Processing, NexusAgents will assist the Customer by implementing appropriate measures to support Data Subject rights requests, including data export and deletion functionality where available in the Service. NexusAgents will notify the Customer of any Data Subject request it receives relating to the Customer’s data and will not respond directly unless authorised by the Customer or required by law.
11. Assistance and Compliance
NexusAgents will provide reasonable assistance to enable the Customer to comply with its POPIA obligations, including in relation to impact assessments, security obligations, and regulatory consultations where applicable. NexusAgents may charge reasonable fees for assistance requiring material additional effort.
12. Personal Information Breach
NexusAgents will notify the Customer immediately and without undue delay after it has reasonable grounds to believe that a Personal Information breach affecting Customer Data has occurred, in accordance with section 21(2) of POPIA. Notification will not be delayed pending completion of an investigation or confirmation of the compromise; NexusAgents may provide the available information in phases as its investigation progresses. Notifications will include the information reasonably available to enable the Customer to comply with its obligations under section 22 of POPIA, and NexusAgents will provide reasonable cooperation and updates as further information becomes available.
13. Return and Deletion
Upon termination or expiry of the subscription, NexusAgents will provide a reasonable opportunity to export Personal Information (including conversation history export functionality where available in the Service) and will thereafter delete or anonymise Personal Information in accordance with its retention practices and Data Deletion Instructions (https://nexusagents.co.za/data-deletion-instructions/). NexusAgents may retain Personal Information where required by law. Residual copies may persist in encrypted backups for a limited period, after which they are securely overwritten in accordance with NexusAgents’ backup retention cycle; such copies are not used for any operational purpose.
14. Audits
NexusAgents will make available information reasonably necessary to demonstrate compliance with this DPA. Where required, audits may be conducted no more than once per calendar year, subject to: at least 30 days’ prior written notice; confidentiality obligations; reasonable scope limitations; minimal disruption to NexusAgents’ operations; and cost recovery by NexusAgents where appropriate. NexusAgents may satisfy audit obligations through certifications, summaries, or third-party audit reports. Audit rights may not be exercised in a manner that would compromise the security, confidentiality, or integrity of NexusAgents’ systems or other customers.
15. Cross-Border Transfers
Hosting and primary storage take place in the Republic of South Africa. Limited transient Processing by AI model Subprocessors, and Processing incidental to payments and the WhatsApp Business Platform, takes place outside South Africa as described in the Privacy Policy. NexusAgents ensures that such transfers comply with section 72 of POPIA, including through contractual safeguards binding the recipient to protection substantially similar to POPIA’s conditions for lawful processing, or reliance on jurisdictions providing adequate protection.
16. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service. For clarity, NexusAgents’ total aggregate liability shall not exceed the cap set out in the Terms of Service.
17. Survival
Obligations relating to confidentiality, security, liability, and data protection survive termination of the Terms of Service for as long as NexusAgents Processes Personal Information.
18. General
This DPA forms part of the Terms of Service and, together with the Privacy Policy, constitutes the entire agreement between the parties in relation to the Processing of Personal Information. Acceptance of the Terms of Service constitutes acceptance of this DPA.
Annex 1 — Description of Processing
- Categories of Data Subjects: the Customer’s customers, leads, and prospective customers; the Customer’s employees and workspace users; other end-users communicating with the Customer through connected channels.
- Types of Personal Information: contact information (names, phone numbers, email addresses); communication content (including WhatsApp message content and attachments); identifiers (WhatsApp IDs, platform identifiers); booking, order, and transaction details; usage and technical data.
- Purpose of Processing: customer communication and relationship management; AI-assisted drafting and reply workflows; bookings and order handling; workflow automation; analytics and reporting.
- Processing Activities: collection, storage, transmission, AI-assisted processing (including transient transmission to AI model Subprocessors), organisation, analysis, retrieval, and deletion.
- Special Personal Information and Children. Customer communications may incidentally contain special personal information (including health, financial, or biometric information, or political or religious opinions) or the personal information of children, where lawfully submitted to the Customer by data subjects. NexusAgents processes such information only as part of the communication content on the Customer’s instructions. The Customer is responsible for ensuring that any authorisation, consent, or statutory condition required under POPIA sections 26 to 35 for the processing of such information has been satisfied.
Annex 2 — Security Measures
Controls currently operated:
- Encryption in transit; encrypted storage of platform credentials, access tokens, and sensitive fields
- Role-based access control and authentication; tenant isolation between Customer workspaces
- Logging and monitoring of system and administrative activity
- Regular patching and dependency management
- Encrypted backups retained for a limited period in accordance with NexusAgents’ backup retention cycle
Controls under active implementation, which NexusAgents is committed to operating and will treat as in force under this DPA upon deployment:
- Multi-factor authentication for administrative access
- Automated anomaly detection
- Formally documented incident response procedures
NexusAgents reviews and enhances its security measures periodically in accordance with section 19 of POPIA, and will update this Annex as controls mature.
