This Data Processing Agreement ("DPA") governs the processing of personal information by Doccu on behalf of the Customer in connection with the Doccu service.
Under the Protection of Personal Information Act No. 4 of 2013 ("POPIA"):
In accordance with Section 21 of POPIA, Doccu covenants and warrants that:
Doccu maintains industry-leading Technical and Organisational Measures ("TOMs") to ensure a level of security appropriate to the risk of processing learnership records:
AES-256 encryption at rest for all stored PDFs and attachments; TLS 1.3 transit encryption; SHA-256 cryptographic chaining on all submission audit events.
Mandatory administrator Two-Factor Authentication (2FA), role-based privilege tiers (Admin, Editor, Viewer), and automated session invalidation.
Automated DAST/SAST vulnerability scans (Aikido Security), real-time crash diagnostics (Sentry), and hardened perimeter firewalls.
Doccu will notify the Customer's designated administrative contact without undue delay and in any event within 36 hours after becoming aware of any confirmed security compromise involving Customer Personal Information in terms of Section 22 of POPIA.
Customer grants general written authorization to Doccu to engage third-party sub-processors. Doccu maintains an up-to-date catalog of approved sub-processors in our public Sub-processors Directory. Doccu imposes data protection obligations on every sub-processor no less protective than those in this DPA.
Doccu provides comprehensive in-app tooling, including cryptographic Master Audit Trails, exportable ZIP packages, and SOC 2 / POPIA security reports to assist Customers during statutory audits conducted by SETA quality assurance verifiers.
Upon service termination, Customer enters a 30-day read-only grace period to export all completed agreements and audit certificates. After 30 days, Doccu irrevocably purges Customer data from production systems, providing written confirmation of destruction upon request.