This draft DPA framework sets out the terms under which SnagSwift (a product of T.H.E Apps, South Africa) processes personal information as an Operator under South Africa's POPIA (Section 21) and as a Processor under Article 28 of the GDPR on behalf of subscribing Customer organizations.
Status: Draft Standard Contractual Clauses | Applicable Statutes: POPIA (Act 4 of 2013) & GDPR (EU 2016/679)
1. Definitions & Scope
- Responsible Party / Controller: The Customer (architectural practice, project manager, or contractor) determining the purpose of the defect management record.
- Operator / Processor: SnagSwift (T.H.E Apps), processing personal information on behalf of the Customer in accordance with Customer instructions.
- Personal Information: Personal information as defined in Section 1 of POPIA and Article 4(1) of GDPR.
2. Scope of Processing & Purpose
SnagSwift processes data strictly to provide, maintain, and support the defect management service. Processing activities include:
- Hosting and rendering architectural floorplans, elevations, and defect pinpoint markers.
- Storing photographic evidence of construction defects and completed subcontractor rectifications.
- Managing trade contractor contact rosters for automated notification dispatch.
- Providing optional AI inference to assist professionals in drafting defect descriptions and category assignments.
3. Operator Obligations Under POPIA Section 21
In compliance with South African statutory requirements, SnagSwift warrants that it will:
Operator Commitments
- Process personal information only with the knowledge or authorization of the Customer (Responsible Party).
- Treat personal information that comes to its knowledge as confidential and not disclose it unless required by law.
- Notify the Customer immediately where there are reasonable grounds to believe that the personal information of a data subject has been accessed or acquired by an unauthorized person.
4. Technical & Organisational Measures (TOMs)
SnagSwift implements appropriate technical and organizational safeguards to protect against unauthorized or unlawful processing, accidental loss, destruction, or damage:
- Encryption: TLS 1.3 / 1.2 in transit; encrypted storage at rest for cloud databases and storage volumes.
- Access Restrictions: Granular role-based access control preventing trade contractors from inspecting unassigned project data.
- Device Isolation: Sandboxed client-side local caching on mobile inspection devices.
- Zero Training Clause: AI model endpoints do not retain customer photographs or descriptions to train external public foundation models.
5. Subprocessors
The Customer grants general written authorization for SnagSwift to engage infrastructure subprocessors (cloud storage, transactional email delivery, and model inference APIs). SnagSwift maintains written agreements with all subprocessors enforcing equivalent data protection standards.
6. International Data Transfers
Where personal information is transferred across borders (e.g., from South Africa to cloud datacenters in Europe or vice versa), SnagSwift ensures such transfers comply with Section 72 of POPIA and Chapter V of GDPR through adequate country protections or standard contractual clauses.
7. Audits, Export & Deletion Upon Termination
Upon contract termination:
- The Customer has the right to export all historical project schedules, pin locations, and high-resolution photographs in standard PDF and CSV formats.
- SnagSwift will sanitize tenant data from production databases within the agreed retention schedule, unless statutory retention laws require continued preservation.
For practice procurement or enterprise DPA execution, please contact privacy@snagswift.app.