Data Processing Agreement (DPA)
For corporate clients whose use of the platform involves us processing personal data on their behalf.
1. Background
This DPA forms part of the Terms of Service between the corporate client (the "Controller") and Afrika Cargo Flow Logistics (Pty) Ltd (the "Processor"), and applies whenever the Processor processes personal data on behalf of the Controller in connection with the freight services.
2. Subject Matter & Duration
- Subject: personal data of the Controller's employees, contractors, customers, and consignees needed to execute freight bookings.
- Duration: the term of the underlying services agreement.
3. Nature & Purpose of Processing
- Quoting, booking, tracking, dispatching, invoicing, and reporting on freight movements.
- Cross-border customs coordination.
- POD capture and delivery confirmation.
4. Categories of Data Subjects
- Employees and contractors of the Controller.
- Senders, receivers, and consignees on the Controller's bookings.
- Drivers and warehouse staff handling the Controller's cargo.
5. Categories of Personal Data
- Identification: name, contact details, ID/passport (where required).
- Operational: pickup/delivery addresses, GPS location, signatures.
- Commercial: cargo description, declared value, invoice data.
6. Processor Obligations
- Process personal data only on documented instructions of the Controller.
- Ensure persons authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational measures (Article 32 GDPR / Section 19 POPIA).
- Assist the Controller in responding to data subject requests.
- Notify the Controller without undue delay of a personal data breach (within 48 hours).
- On termination, return or delete all personal data, save where storage is required by law.
7. Sub-Processors
The Controller authorises the Processor to engage the following sub-processors:
- Cloud infrastructure: Lovable Cloud / Supabase (EU/AF regions), Cloudflare.
- Payment processing: PayFast (Pty) Ltd.
- KYC verification: Smile Identity Inc.
- Mapping & geocoding: Google Maps Platform.
- Email delivery: as listed in the Privacy Policy.
We will notify the Controller of any changes to sub-processors at least 30 days in advance.
8. International Transfers
Where personal data is transferred outside the EU/UK or South Africa, the parties agree to incorporate the relevant Standard Contractual Clauses or POPIA Section 72 safeguards.
9. Audit
On 30 days' written notice and no more than once per year, the Controller may audit the Processor's compliance, at the Controller's cost. The Processor will make available all information necessary to demonstrate compliance.
10. Liability
Each party's liability under this DPA is subject to the limitation of liability provisions of the underlying services agreement.
11. Signed Copy
Corporate clients requiring a counter-signed PDF version of this DPA may request one from legal@afrikacargoflow.com.
