POPIA Compliance
Last updated: 9 July 2026
WAPit is committed to POPIA compliance
The Protection of Personal Information Act 4 of 2013 (POPIA) is South Africa's data protection law. We have implemented comprehensive measures to ensure your data is processed lawfully, transparently, and securely.
1. Our Commitment
WAPit operates as both a "responsible party" (for our own data processing) and an "operator" (processing data on behalf of our customers) under POPIA. We take both roles seriously and have implemented appropriate safeguards for each.
2. POPIA Principles We Follow
2.1 Accountability (Section 8)
We have appointed an Information Officer responsible for ensuring compliance with POPIA. We maintain documentation of our processing activities and regularly review our data protection practices.
2.2 Processing Limitation (Section 9-12)
- We only process personal information that is necessary for providing our Service
- We have a lawful basis for all processing (contract, legitimate interest, or consent)
- We collect personal information directly from data subjects where possible
- We do not process personal information for purposes incompatible with the original collection purpose
2.3 Purpose Specification (Section 13-14)
- We clearly communicate the purpose of data collection at the point of collection
- Personal information is only used for the stated purposes
- We retain personal information only as long as necessary for the identified purpose or as required by law
2.4 Further Processing Limitation (Section 15)
We do not use your personal information for purposes other than what was originally communicated without obtaining additional consent or establishing a new lawful basis.
2.5 Information Quality (Section 16)
We take reasonable steps to ensure that personal information is complete, accurate, not misleading, and updated where necessary. Users can update their profile information at any time through the platform.
2.6 Openness (Section 17-18)
- This page and our Privacy Policy are publicly available
- We clearly inform data subjects about what information we collect and why
- Our processing activities are documented and available upon request
2.7 Security Safeguards (Section 19-22)
We implement appropriate technical and organisational measures:
- Encryption: All data in transit is encrypted using TLS 1.2+
- Access control: Role-based access with the principle of least privilege
- Authentication: Secure password hashing (scrypt for dashboard users, bcrypt for API users)
- Infrastructure: Hosted on Google Cloud Platform with SOC 2 and ISO 27001 certification
- Monitoring: Automated health monitoring and anomaly detection
- API security: JWT-based authentication with token expiration
2.8 Data Subject Participation (Section 23-25)
You have the right to:
- Request access to your personal information
- Request correction or deletion of your personal information
- Object to the processing of your personal information
- Request a copy of your personal information in a portable format
- Withdraw consent at any time
3. Your Responsibilities as a WAPit User
When you use WAPit to send messages, youare the "responsible party" for the personal information of your message recipients. This means you must:
- Obtain consent: Ensure you have valid consent or another lawful basis to contact each recipient via WhatsApp
- Provide opt-out: Offer recipients a clear way to unsubscribe from future messages
- Purpose limitation: Only send messages relevant to the purpose for which consent was obtained
- Data accuracy: Ensure contact lists are accurate and up-to-date
- Record keeping: Maintain records of consent for each recipient
- Notify breaches: Inform recipients if their data is compromised
WAPit acts as an "operator" processing data on your behalf. We process recipient information solely to deliver your messages and do not use it for our own purposes.
4. Data Processing Agreement
By using WAPit, you enter into a data processing arrangement with us as contemplated by Section 20-21 of POPIA. We undertake to:
- Process personal information only on your documented instructions
- Ensure persons authorised to process data are bound by confidentiality
- Implement appropriate security measures
- Not engage sub-processors without your knowledge (our sub-processors are listed in our Privacy Policy)
- Assist you in responding to data subject requests
- Delete or return personal information at the end of the service relationship
- Notify you of any security compromise affecting your data
5. Cross-Border Transfers
In terms of Section 72 of POPIA, personal information may only be transferred outside South Africa under certain conditions. Our transfers are compliant because:
- Google Cloud (EU - Belgium): The European Union provides an adequate level of data protection under GDPR
- WhatsApp (WhatsApp Platform):Message delivery requires transmission to WhatsApp's infrastructure; this transfer is necessary to perform the contract between you and your message recipients
- PayFast: Payment processing remains within South Africa
6. Data Breach Response
In the event of a security compromise (as defined in Section 22 of POPIA), we will:
- Notify the Information Regulator as soon as reasonably possible
- Notify affected data subjects in writing
- Provide sufficient information to allow data subjects to take protective measures
- Investigate the breach and implement measures to prevent recurrence
7. Retention and Destruction
| Data Category | Retention Period | Basis |
|---|---|---|
| Account information | Duration of account + 12 months | Contractual necessity |
| Message logs | 90 days | Service delivery & dispute resolution |
| Payment records | 5 years | Tax Act & Companies Act |
| API access logs | 30 days | Security monitoring |
| Webhook logs | 30 days | Technical troubleshooting |
After the retention period, personal information is securely deleted or anonymised.
8. Information Officer
Our Information Officer can be contacted for any POPIA-related enquiries:
- Email: info@wapit.co.za
- Website: wapit.co.za/contact
We will respond to all POPIA-related requests within 30 days of receipt.
9. Information Regulator
If you believe we have not adequately addressed your data protection concerns, you may lodge a complaint with the Information Regulator:
- Website: https://inforegulator.org.za
- Email: complaints.IR@justice.gov.za
- Phone: 012 406 4818
- Address: JD House, 27 Stiemens Street, Braamfontein, Johannesburg, 2001
10. Related Documents
- Privacy Policy — Full details on how we collect, use, and protect your data
- Terms of Service — The rules governing use of our platform