Data Processing Agreement
The terms under which CaseThread processes personal information as operator on behalf of a practice (the responsible party) under POPIA.
Last updated: Draft — not yet published
Roles
For Client Data, the practice is the responsible party and CaseThread (operated by [UPDATE — registered entity name, e.g. Optimiz Solutions (Pty) Ltd], company registration number [UPDATE — CIPC reg no.], of [UPDATE — registered physical address], South Africa) is the operator. We process personal information only on the practice's documented instructions (which include these terms and the practice's use of the Service), and not for our own purposes.
This agreement forms part of our Terms of Service. If it conflicts with the Terms on the processing of Client Data, this agreement prevails.
Subject-matter, nature & purpose
Nature and purpose: providing the CaseThread service — hosting, storing and managing the practice's case records, scheduling, notes, documents, invoicing and related communications. Duration: for as long as the practice uses the Service, plus the return/deletion period below.
Categories of data subjects: the practice's clients and their contacts/guardians, and the practice's own team. Categories of personal information: identity and contact details, case and social-circumstance information (which may include special personal information and children's information), scheduling and billing data.
Operator obligations
We process Client Data only on the practice's lawful, documented instructions; we will tell the practice if, in our view, an instruction breaches POPIA. We treat all Client Data as confidential (POPIA §20–§21).
Persons we authorise to process Client Data are bound by confidentiality obligations.
Security
We maintain appropriate, reasonable technical and organisational measures under POPIA §19 — including encryption in transit and at rest, row-level access control, rate limiting and bot defence, access and admin-action logging, and backup and recovery — to secure the integrity and confidentiality of Client Data.
Sub-processors
The practice authorises us to engage the sub-processors listed on the Sub-processors page to help provide the Service. We impose data-protection terms on each sub-processor no less protective than these, and we remain responsible for their processing. We will give reasonable notice of any intended addition or replacement of a sub-processor so the practice can object.
Assisting the responsible party
Taking account of the nature of the processing, we assist the practice — through the in-app tooling and to a documented schedule — to respond to data-subject requests (access, correction, deletion/export) and to meet its POPIA security, breach-notification and, where relevant, prior-authorisation obligations.
Breach notification
We will notify the practice without undue delay after becoming aware of a security compromise affecting its Client Data, with the information reasonably available, so the practice can meet its notification duties to the Information Regulator and data subjects under POPIA §22.
Cross-border processing
The practice acknowledges that Client Data is hosted on EU-based infrastructure and that some sub-processors operate outside South Africa. Such cross-border processing is carried out under the safeguards required by POPIA §72 (principally binding data-processing agreements imposing adequate protection).
Return & deletion
On termination, or on the practice's request, we return or delete the practice's Client Data per the retention schedule and within the recovery window described in the Terms, unless the law requires us to retain it. A receipt that a deletion was carried out is retained as evidence of compliance — see "What survives an erasure" in the Privacy Policy. The practice can export Client Data from within the Service while the account is active.
Backups and erasure instructions. Client Data is backed up so the Service can be restored after a failure: the database daily, retained approximately seven days by our hosting provider, and uploaded documents nightly to separate encrypted storage in the European Union, retained a maximum of 90 days on a rolling basis. On a documented erasure instruction we delete the Client Data from live systems without undue delay. Residual copies within backups are not separately extracted; they expire on the ordinary cycles above and are overwritten, and they are not restored into live systems except as part of recovering from an incident. Backups are deliberately not made to mirror deletions, because a backup that reproduced every deletion would replicate an accidental or malicious wipe and defeat its own purpose.
Liability & precedence
Liability under this agreement is subject to the limitations in the Terms of Service. [UPDATE — counsel to align liability wording and confirm signature/acceptance mechanism for practices that require a countersigned DPA.]
More: Privacy Policy · Terms of Service · PAIA Manual · Cookie & Tracking Policy · Billing, Refund & Cancellation Policy · Acceptable Use Policy · Sub-processors