1Roles
When a Client uses a System we provide, the Client is the responsible party for the personal information in it, such as its customers', suppliers' and staff's details. ANEESD (Pty) Ltd, trading as CODED., processes that information as the Client's operator, under section 21 of POPIA.
2Our commitments as operator
- Process personal information only on the Client's instructions, as set out in the agreement and given through the System and our support channels, unless the law requires otherwise
- Treat it as confidential, and make sure everyone who works with it is bound to confidentiality
- Keep appropriate, reasonable technical and organisational security measures in place (see below)
- Tell the Client without undue delay if we believe personal information has been accessed or acquired by an unauthorised person
- Help the Client respond to data subjects and to the Information Regulator
- Never use Client Data for any purpose of our own
3Sub-operators
We use infrastructure and service partners to host and run Systems. Each is bound in writing to protect personal information to a standard at least equal to these terms. The current list for a Client's System is available to that Client on request.
4Security measures
- Encryption in transit and at rest
- Role-based access, so each person sees only what their role needs
- Two-factor authentication and single sign-on
- Audit logs of significant actions in each System
- Daily backups
- Continuous monitoring
5Transfers outside South Africa
Where a System's infrastructure is outside South Africa, personal information is transferred only with safeguards that meet section 72 of POPIA.
6At the end of the service
For 30 days after a subscription ends, the Client can export its Client Data, or ask us to return it in a standard format. After that, we delete it from the System, unless the law requires us to keep it.
7Audits
On reasonable written notice, we'll give a Client the information it needs to confirm we're meeting these terms.