Data Processing Agreement
Version 2026-09-29 — draft, pending legal review.
Roles
You (the merchant) are the Responsible Party for your customers' personal information under POPIA. SubCharge acts as your Operator: we process that data only on your instructions, as expressed through your use of the platform — creating customers, issuing invoices, sending the emails you've configured, and recording payments.
What we will not do
We will not process your customers' personal information for our own purposes, sell it, or use it to market to your customers directly. Marketing emails to your customers are sent only on your instruction, only to customers you've attested have given marketing consent, and always with one-click unsubscribe.
Sub-processors
We use the sub-processors below to operate the platform. We'll update this list, and notify you, if that changes.
| Sub-processor | Purpose |
|---|---|
| Neon (on AWS, us-east-1) | Primary database |
| Vercel | Application hosting |
| Resend | Transactional and marketing email delivery |
| Upstash | Rate limiting |
Each payment add-on's provider (PayFast, Paystack or Peach Payments) is your own sub-processor when you connect it, under that provider's own terms — not ours, since you hold the merchant account with them directly.
Security measures
Payment tokens and provider credentials are encrypted at rest and never logged. See /security for the full set of measures.
Breach notification
We will notify you of a data breach affecting your customers' personal information without delay, so you can meet your own notification obligations as Responsible Party.
Deletion and retention
When you delete a customer, their personal fields are anonymised. Financial records (invoices, payments) are retained for 5 years regardless, to meet SARS requirements.