How Astrium Software Solutions CC processes personal information on behalf of its customers, in accordance with POPIA Section 21.
This Data Processing Agreement ("DPA") forms part of, and supplements, the Terms of Service between Astrium Software Solutions CC ("Astrium", "we", "us", or "Operator") and the customer ("you", "your", "Customer", or "Responsible Party") using any Astrium SaaS product.
This DPA reflects the parties' agreement on the processing of personal information by Astrium on behalf of the Customer in accordance with the Protection of Personal Information Act 4 of 2013 ("POPIA"), specifically Sections 20 and 21.
Terms used in this DPA have the meanings ascribed to them in POPIA. In particular:
The parties agree that, for Personal Information uploaded, stored, or transmitted by the Customer through the Services:
For Personal Information that Astrium collects directly from the Customer (e.g. account registration data, billing information), Astrium acts as an independent Responsible Party, and such processing is governed by our Privacy Policy.
This DPA applies for the duration of the Customer's subscription to any Astrium SaaS product. The subject matter, nature, and purpose of the processing, the types of Personal Information, and the categories of Data Subjects are described in Schedule A below.
In accordance with POPIA Section 21, Astrium shall:
The Customer warrants and undertakes that:
The Customer provides a general authorisation for Astrium to engage Sub-operators to process Personal Information, subject to the following conditions:
The current list of Sub-operators is set out in Schedule C.
Where Sub-operators process Personal Information outside the Republic of South Africa, Astrium shall ensure that the transfer complies with POPIA Section 72, including by:
Astrium shall implement appropriate technical and organisational measures to protect Personal Information as set out in Schedule B.
If Astrium becomes aware of a security compromise affecting Customer Personal Information, Astrium shall:
If Astrium receives a request from a Data Subject relating to Personal Information processed on behalf of the Customer (e.g. access, correction, or deletion requests under POPIA Sections 23–25), Astrium shall:
On termination or expiry of the Customer's subscription:
On the Customer's written request, Astrium will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA. Where the Customer reasonably requires further information, Astrium and the Customer will agree a reasonable scope and schedule for an audit, conducted at the Customer's cost and without causing material disruption to Astrium's business.
The liability of each party under this DPA is subject to the limitation of liability provisions set out in the Terms of Service.
This DPA is governed by the laws of the Republic of South Africa, and subject to the exclusive jurisdiction of the courts of the Republic of South Africa.
For questions about this DPA or to exercise Customer rights:
Information Officer: Corne Beukes
Email: enquiries@astrium.co.za
Entity: Astrium Software Solutions CC (Registration 2002/061588/23)
| Item | Details |
|---|---|
| Subject matter | Provision of SaaS products by Astrium to the Customer |
| Duration of processing | The term of the Customer's subscription, plus a 90-day retention period |
| Nature and purpose | Hosting, storage, transmission, and display of Customer data for the purpose of providing the Services |
| Categories of Data Subjects | The Customer's employees, contractors, end users, customers, and contacts |
| Types of Personal Information | Names, email addresses, phone numbers, account credentials, message content, conversation records, contact database entries, payment and debtor records (as applicable to each product) |
| Special Personal Information | Not processed unless specifically uploaded by the Customer, in which case the Customer warrants compliance with POPIA Chapter 3 Part B |
Astrium implements the following security measures in accordance with POPIA Section 19:
| Sub-operator | Purpose | Location |
|---|---|---|
| Cloud infrastructure provider | Hosting and data storage | South Africa / EU |
| Paystack | Payment processing | South Africa / Nigeria |
| Netcash | Payment processing (legacy) | South Africa |
| Meta (WhatsApp Cloud API) | WhatsApp message delivery (Astrium Connect) | Ireland / USA |
| Telegram | Telegram message delivery (Astrium Connect) | Global |
| OpenAI | AI bot processing (Astrium Connect, when enabled) | USA |
| Anthropic | AI bot processing (Astrium Connect, when enabled) | USA |
| Formspree | Contact form submissions on www.astrium.co.za | USA |
This list is current as at the "Last updated" date at the top of this DPA. Material changes will be notified to active subscribers at least 30 days before they take effect.