Data Processing Agreement

Template version: 1.0 ยท Date: 28 April 2026

1. Parties

2. Scope & Purpose

The Processor processes personal data on behalf of the Controller solely for the purpose of:

  1. Matching study criteria to eligible participants in the Imbazo panel
  2. Facilitating communication between Controller and matched participants via WhatsApp
  3. Tracking study progress, completion status, and quality metrics
  4. Processing payments to participants on behalf of the Controller

The Processor shall not process personal data for any purpose other than those specified above unless instructed in writing by the Controller.

3. Types of Personal Data Processed

CategoryData elementsData subjects
Identification dataName, phone number, emailParticipants
Demographic dataAge, gender, country, city, education, employmentParticipants
Socio-economic dataIncome bracket, internet access typeParticipants
Special personal informationEthnicity, languages (where applicable)Participants
Study interaction dataMatch status, completion timestamps, quality ratingsParticipants
Payment dataPayment method preferences, transaction referencesParticipants

4. Processing Limitations

  1. The Processor shall process personal data only on documented instructions from the Controller (i.e., the study criteria and parameters set in the platform).
  2. The Processor shall not sell, rent, or share personal data with third parties except sub-processors listed in Section 8.
  3. The Processor shall not combine participant data across different Controllers' studies except in aggregate, anonymised form for platform statistics.

5. Security Measures

The Processor implements the following technical and organisational measures:

6. Data Breach Notification

  1. The Processor shall notify the Controller of any personal data breach without undue delay and no later than 72 hours after becoming aware of it.
  2. The notification shall include: nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed.
  3. The Processor shall cooperate with the Controller in notifying the Information Regulator (South Africa) or POTRAZ (Zimbabwe) as required by POPIA Section 22.

7. Data Deletion & Return

  1. Upon study completion or termination, the Controller may request export of all study-related data in a structured format (CSV/JSON).
  2. The Processor shall delete or anonymise participant personal data associated with the study within 30 days of the Controller's written request, unless retention is required by law.
  3. Aggregate, anonymised data (study participation counts, quality metrics) may be retained by the Processor for platform improvement.
  4. Participant panel membership data is not deleted on study completion โ€” it is retained under the Processor's own lawful basis (participant consent).

8. Sub-Processors

Sub-processorLocationServiceData processed
Supabase Inc.United StatesDatabase hostingAll participant & study data
Meta Platforms (WhatsApp)US / IrelandMessagingPhone numbers, message content
Clerk Inc.United StatesAuthenticationResearcher email, auth tokens
Vercel Inc.United StatesWeb hostingServer logs, request metadata

Each sub-processor is bound by data processing terms no less protective than this DPA.

9. Cross-Border Transfers

Personal data may be transferred to the United States and Ireland (see sub-processors above). The Processor ensures adequate protection through:

10. Data Subject Rights

The Processor shall assist the Controller in responding to data subject requests (access, correction, deletion, objection) within 15 business days of the Controller's request.

11. Audit Rights

The Controller may, with 30 days' written notice and at the Controller's expense, audit the Processor's compliance with this DPA. Audits shall be conducted during normal business hours and shall not unreasonably disrupt the Processor's operations.

12. Liability

Each party's liability under this DPA is subject to the limitations set out in the Terms of Service.

13. Term & Termination

This DPA is effective for the duration of the Controller's use of the Platform. It survives termination of the Terms of Service with respect to any personal data still held by the Processor.

14. Governing Law

This DPA is governed by the laws of the Republic of South Africa, including POPIA.


Signatures

For the Data Controller (Researcher):

Name: ________________________________

Title: ________________________________

Institution: ________________________________

Date: ________________________________

Signature: ________________________________


For the Data Processor (Imbazo):

Name: ________________________________

Title: ________________________________

Date: ________________________________

Signature: ________________________________