Data Processing Agreement

Last updated: 1 June 2026 — operator agreement under section 21 of the Protection of Personal Information Act 4 of 2013 ("POPIA")

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you (the "Responsible Party") and Books Xperts (Pty) Ltd ("BooksXperts", "we", "us"), the "Operator". It governs how we process personal information on your behalf when you use the platform, and gives effect to the written-contract requirement in section 21(2) of POPIA.

1. Roles of the parties

For the personal information you and your clients load into BooksXperts (for example customer, supplier and employee records), you are the Responsible Party and BooksXperts is the Operator. We process that information only on your behalf and on your documented instructions, which the use of the platform's features constitutes.

2. Scope and purpose of processing

Subject matterCloud bookkeeping and the compilation of Annual Financial Statements.
DurationFor as long as your account is active, then for the retention period in clause 7.
Nature & purposeStorage, organisation, computation and reporting of accounting and tax data.
Types of personal informationIdentifying, contact, banking and financial data of your customers, suppliers and employees.
Categories of data subjectYour customers, suppliers, employees and the natural persons behind your business contacts.

3. Our obligations as Operator (POPIA s20–21)

We will:

4. Security safeguards (POPIA s19)

We apply appropriate, reasonable technical and organisational measures, including TLS encryption in transit, encryption at rest for sensitive fields, role-based access control with strict per-tenant isolation, optional two-factor authentication, and regular backups. We continually review these safeguards in light of changing risk.

5. Sub-operators

You authorise us to engage sub-operators to deliver the platform. Each is bound by written terms imposing data-protection obligations no less protective than this DPA. Our current sub-operators are:

Sub-operatorPurposeLocation
RailwayApplication hosting & databaseUnited States
PayFastPayment processing (subscription billing)South Africa
AnthropicAI assistant features (where enabled)United States

We will give you reasonable notice of any intended change to this list so you may object on reasonable grounds.

6. Cross-border transfers (POPIA s72)

Some sub-operators process data outside the Republic (see clause 5). Such transfers take place only where the recipient is subject to laws or binding agreements that uphold an adequate level of protection, consistent with section 72 of POPIA. By accepting this DPA you authorise these transfers for the purposes described.

7. Return and deletion

On termination, and subject to the retention periods we are obliged to observe under the Tax Administration Act and Companies Act (see the Privacy Policy), we will, at your choice, return or securely delete the personal information we hold on your behalf. You may export your data at any time from your account.

8. Data subject and regulator requests

Taking into account the nature of the processing, we will assist you with appropriate measures to respond to requests from data subjects and from the Information Regulator, including by providing the export and deletion tools available in your account.

9. Liability and governing law

This DPA is governed by the laws of the Republic of South Africa and is subject to the liability provisions of the Terms of Service. Where this DPA conflicts with the Terms on the processing of personal information, this DPA prevails.

10. Contact

Our Information Officer can be reached at booksxperts@gmail.com, or WhatsApp/call +27 79 199 6369, for any matter arising under this DPA.

This DPA is provided as a standard operator agreement for the BooksXperts platform. It is not a substitute for independent legal advice; if your organisation has specific regulatory obligations you should have your own legal counsel review it.