LetLoose — GDPR Article 28 Data Processing Agreement
This Data Processing Agreement (“DPA”) is entered into between Future Point Consult (Pty) Ltd, a company registered in South Africa, trading as “LetLoose”, with its registered address at 298 Glenwood Rd, Lynnwood Park, Pretoria, 0081, South Africa (“LetLoose”, “we”, “us”, the “Processor”, and, for international transfers, the “data importer”), and the customer that has entered into this DPA and, where applicable, its authorised users (the “Customer”, “you”, the “Controller”, and, for international transfers, the “data exporter”). LetLoose and the Customer are each a “Party” and together the “Parties”.
This DPA forms part of, and is incorporated by reference into, the LetLoose Terms of Service (the “Terms”) between the Parties. It applies wherever and to the extent that LetLoose processes Personal Data on the Customer's behalf in providing the LetLoose rental-property operations platform (the “Service”). By accepting the Terms and using the Service as a business customer, the Customer agrees to this DPA; no separate signature is required for it to be binding. A counter-signed copy is available to business customers on request at privacy@letloose.run. This DPA governs the processing of Personal Data and, to the extent of any conflict on that subject matter, prevails over the Terms, consistent with section 15 of the Terms (under which the DPA governs the processing of personal data). Capitalised terms not defined here have the meanings given in the Terms.
1.Definitions
1.1. In this DPA, the following terms have the meanings set out below. Terms not defined here take the meaning given to them in Applicable Data Protection Law.
- “Applicable Data Protection Law” means all laws and regulations applicable to the processing of Personal Data under this DPA, including, as applicable: (i) Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”); (ii) the GDPR as it forms part of the law of the United Kingdom by virtue of the European Union (Withdrawal) Act 2018 (the “UK GDPR”) together with the UK Data Protection Act 2018; and (iii) the South African Protection of Personal Information Act 4 of 2013 (“POPIA”).
- “Personal Data” (equivalent to “personal information” under POPIA) means any information relating to an identified or identifiable natural person, and, where POPIA applies, an identifiable existing juristic person, that is processed by LetLoose on behalf of the Customer under this DPA.
- “Processing” (and “ process”) means any operation performed on Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission, dissemination, restriction, erasure or destruction.
- “Controller” (equivalent to “responsible party” under POPIA) means the entity that, alone or jointly, determines the purposes and means of the processing of Personal Data.
- “Processor” (equivalent to “operator” under POPIA) means an entity that processes Personal Data on behalf of, and on the documented instructions of, a Controller.
- “Data Subject” means the identified or identifiable natural (or, under POPIA, juristic) person to whom Personal Data relates.
- “Sub-processor” means any third party engaged by LetLoose (or by a Sub-processor of LetLoose) to process Personal Data on behalf of the Customer in connection with the Service.
- “Personal Data Breach” (a “security compromise” under s22 POPIA) means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data processed under this DPA. For POPIA purposes, a security compromise also includes any case where there are reasonable grounds to believe that Personal Data has been accessed or acquired by an unauthorised person, and the s22 POPIA notification obligations apply on that basis.
- “Customer Data” means Personal Data and other data that the Customer or its authorised users submit to, or generate within, the Service.
- “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, in particular Module Two (Controller-to-Processor).
- “UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under s119A of the UK Data Protection Act 2018.
- “Supervisory Authority” means an independent public authority competent under Applicable Data Protection Law, including the Information Regulator (South Africa) under POPIA.
- “Privacy Policy” means the LetLoose Privacy Policy as updated from time to time.
2.Roles and Scope
2.1. Roles. With respect to Personal Data processed in the course of providing the Service, the Customer is the Controller and LetLoose is the Processor. Where the Customer itself acts as a processor on behalf of a third-party controller, the Customer warrants that it is authorised and instructed by that controller to engage LetLoose as a Sub-processor, and this DPA applies on a controller-to-processor basis between the Parties accordingly.
2.2. Subject matter and scope. The subject matter, nature and purpose of the processing, the types of Personal Data, the categories of Data Subjects and the duration of the processing are described in Annex I. LetLoose processes Personal Data only to provide, maintain, secure and support the Service and as otherwise instructed by the Customer in accordance with this DPA.
2.3. Customer as Controller. The Customer is the Controller of Personal Data about its own team members, staff, guests, vendors and property owners that it submits to or generates within the Service. The Customer is responsible for the accuracy, quality and lawfulness of Customer Data and for the lawful basis on which it was collected and provided to LetLoose, and for issuing instructions to LetLoose that comply with Applicable Data Protection Law.
2.4. LetLoose as Controller of its own data. LetLoose acts as an independent Controller in respect of a limited set of Personal Data it processes for its own business purposes — for example account administration, billing, security, fraud prevention, service improvement and compliance. Such processing is governed by the LetLoose Privacy Policy and not by this DPA. For the avoidance of doubt, LetLoose's processing for its own “service improvement” and “fraud prevention” purposes under this Clause 2.4 does not extend to the Customer Personal Data processed on the Customer's behalf as Processor, save where such processing is carried out on aggregated or anonymised data that does not identify any Data Subject; the independent-Controller role in this Clause 2.4 does not enlarge the scope of the documented instructions in Clause 3.1.
2.5. Special-category data. No special-category (GDPR Article 9) Personal Data, and no equivalent “special personal information” under s26 POPIA, is intended, required or to be processed under this DPA, and the Customer agrees not to submit such data to the Service. If LetLoose becomes aware that special-category data, special personal information, or other data prohibited by this DPA has been submitted to the Service, it will notify the Customer without undue delay and, on the Customer's instruction, delete or restrict such data. For the avoidance of doubt, the technical and organisational measures in Annex II apply to all Personal Data actually processed under this DPA, regardless of this prohibition.
3.Processor Obligations (GDPR Article 28(3))
LetLoose, as Processor (operator), undertakes the following obligations, which correspond to Article 28(3)(a)–(h) GDPR and the equivalent obligations under POPIA ss19–21.
3.1. (a) Documented instructions. LetLoose processes Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to process by EU, EU member-state, UK or South African law to which LetLoose is subject; in which case LetLoose informs the Customer of that legal requirement before processing, unless the law prohibits such notice on important grounds of public interest. The Terms, this DPA (including its Annexes), the Service's configuration options, and the Customer's use of the Service constitute the Customer's complete and documented instructions for the Personal Data processed on the Customer's behalf. Nothing in this Clause 3.1 authorises LetLoose to process such Personal Data for its own purposes; any processing by LetLoose as an independent Controller is limited as set out in Clause 2.4. LetLoose will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.
3.2. (b) Confidentiality. LetLoose ensures that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and that access is limited to personnel who need it to provide the Service. These confidentiality commitments are of a continuing nature and survive the termination of the relevant person's role or engagement. In accordance with s20 POPIA, LetLoose processes Personal Data only with the knowledge or authorisation of the Customer, treats all Personal Data as confidential, and will not disclose it except where required by law or in the course of the proper performance of its duties under this DPA.
3.3. (c) Security. LetLoose implements and maintains the technical and organisational measures required under Article 32 GDPR and ss19 and 21 POPIA, as described in Annex II and Clause 4, to ensure a level of security appropriate to the risk.
3.4. (d) Sub-processors. LetLoose engages Sub-processors only in accordance with Clause 5, imposing data-protection obligations that are, in substance, equivalent to those in this DPA by way of contract.
3.5. (e) Assistance with Data-Subject rights. Taking into account the nature of the processing, LetLoose assists the Customer by appropriate technical and organisational measures, insofar as possible, to fulfil the Customer's obligation to respond to requests by Data Subjects exercising their rights under Applicable Data Protection Law, as further set out in Clause 7.
3.6. (f) Assistance with Articles 32–36. LetLoose assists the Customer in ensuring compliance with its obligations under Articles 32 to 36 GDPR (and the corresponding POPIA provisions), taking into account the nature of processing and the information available to LetLoose, including with: security of processing; notification of Personal Data Breaches to the Supervisory Authority and Data Subjects; data protection impact assessments; and prior consultation with the Supervisory Authority.
3.7. (g) Return or deletion. At the Customer's choice, LetLoose deletes or returns all Personal Data after the end of the provision of the Service, and deletes existing copies, except where storage is required by Applicable Data Protection Law, as further set out in Clause 10.
3.8. (h) Audits and information. LetLoose makes available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, in accordance with Clause 9.
4.Security of Processing
4.1. LetLoose implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk presented by the processing, in accordance with Article 32 GDPR and ss19 and 21 POPIA. The current measures are described in Annex II and include encryption of Personal Data in transit and at rest, organisation-level data isolation (Row-Level Security), role-based access control, and access-controlled file storage as described in Annex II.
4.2. In assessing the appropriate level of security, the Parties take account of the risks presented by processing — in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data. LetLoose may update the measures from time to time provided that the updates do not materially reduce the overall level of security of the Service.
4.3. POPIA s19 security cycle. In accordance with s19(2)–(3) POPIA, LetLoose, as operator, will: (a) identify all reasonably foreseeable internal and external risks to Personal Data in its possession or under its control; (b) establish and maintain appropriate safeguards against the risks identified; (c) regularly verify that the safeguards are effectively implemented; and (d) ensure that the safeguards are continually updated in response to new risks or deficiencies in previously implemented safeguards. LetLoose will have due regard to generally accepted information security practices and procedures, whether industry-specific or otherwise, that may apply to it.
5.Sub-processing
5.1. General authorisation. The Customer provides LetLoose with a general written authorisation to engage Sub-processors to process Personal Data in connection with the Service, subject to this Clause 5.
5.2. Current Sub-processors. The Sub-processors authorised as at the date of this DPA are listed in Annex III. They are: Supabase (application database, authentication and encrypted file storage; primary data host); Vercel (application hosting and global content-delivery network); Resend (transactional email delivery); and Google (Google Sign-In / OAuth, engaged only where a user chooses to authenticate with Google).
5.3. Notice and objection. LetLoose will give the Customer at least thirty (30) days' advance written notice of any intended addition or replacement of a Sub-processor before that Sub-processor begins processing Personal Data, giving the Customer the opportunity to object on reasonable, data-protection-related grounds. This notice obligation applies to any addition or replacement of a Sub-processor and is not limited to changes LetLoose considers “material”. If the Customer objects within the notice period and the Parties cannot resolve the objection within a reasonable period, then, where technically feasible, LetLoose will not onboard the objected-to Sub-processor for the objecting Customer's Personal Data. Where LetLoose cannot reasonably avoid using the objected-to Sub-processor for the Customer's Personal Data, the Customer may terminate the affected part of the Service by written notice and, in that event, LetLoose will refund any pre-paid fees attributable to the terminated part of the Service for the period after termination on a pro-rata basis. Nothing in this Clause limits or excludes any statutory remedy otherwise available to the Customer.
5.4. Flow-down and liability. Where LetLoose engages a Sub-processor, it does so by way of a written contract imposing data-protection obligations that are, in substance, equivalent to those set out in this DPA, in particular the obligation to provide sufficient guarantees to implement appropriate technical and organisational measures. That contract specifically requires each Sub-processor to (i) establish and maintain security measures consistent with s19 POPIA and Article 32 GDPR, and (ii) notify LetLoose immediately and without undue delay of any Personal Data Breach or security compromise affecting Personal Data, so that LetLoose can meet its obligations under ss21(2) and 22 POPIA and Article 33(2) GDPR to the Customer. Where Personal Data is transferred from South Africa to a Sub-processor outside South Africa, that contract also imposes an adequate level of protection consistent with POPIA, as further described in Clause 8.4. LetLoose remains fully liable to the Customer for the performance of each Sub-processor's data-protection obligations.
6.Personal Data Breach
6.1. LetLoose notifies the Customer without undue delay, and in any event no later than forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Customer Data, consistent with Article 33(2) GDPR, so that the Customer can meet its own obligation (where applicable) to notify within seventy-two (72) hours under Article 33(1) GDPR. In addition, and as required by ss21(2) and 22 POPIA, where there are reasonable grounds to believe that Personal Data has been accessed or acquired by an unauthorised person (a security compromise under s22 POPIA), LetLoose will notify the Customer immediately (and in any event as soon as reasonably possible and without undue delay), so that the Customer can discharge its duty under s22(1) POPIA to notify the Information Regulator and affected Data Subjects. Notifications are sent to the Customer's designated contact and may be issued from, and queries directed to, privacy@letloose.run.
6.2. The notification will describe, to the extent known and as information becomes available: the nature of the breach (including, where possible, the categories and approximate number of Data Subjects and records concerned); the likely consequences; the measures taken or proposed to address the breach and mitigate its possible adverse effects; and a contact point for further information. To the extent the information is available to it, LetLoose will also provide the Customer with the information the Customer needs to satisfy s22(5) POPIA, including a description of the possible consequences of the security compromise, the measures taken or intended to address it, recommendations regarding measures the Data Subject can take to mitigate the possible adverse effects, and the identity of the unauthorised person who may have accessed or acquired the Personal Data, where known.
6.3. LetLoose provides reasonable assistance to the Customer in connection with the Customer's own obligations to notify the competent Supervisory Authority (including the Information Regulator under s22(1) POPIA) and affected Data Subjects in the manner prescribed by ss22(4)–(5) POPIA and Articles 33–34 GDPR. The Parties acknowledge that LetLoose's notification is not, and may not be construed as, an acknowledgement of fault or liability.
7.Data-Subject Rights
7.1. Taking into account the nature of the processing, LetLoose assists the Customer, by appropriate technical and organisational measures and insofar as possible, in fulfilling the Customer's obligations to respond to requests from Data Subjects to exercise their rights of access, rectification, erasure, restriction, portability and objection, and rights relating to automated decision-making, under Applicable Data Protection Law. Many of these capabilities are available to the Customer directly within the Service.
7.2. If LetLoose receives a request from a Data Subject relating to Customer Data, it will, unless legally prohibited, promptly forward the request to the Customer and will not respond to the request itself except on the Customer's documented instructions or as required by law.
8.International Transfers
8.1. No adequacy decision. The Customer (data exporter) may be established in the EU/EEA or the United Kingdom. LetLoose (data importer) is established in South Africa, which is a third country that, as at the date of this DPA, is not the subject of an adequacy decision by the European Commission or the UK government. Accordingly, the Parties put in place the transfer mechanisms set out in this Clause 8.
8.2. EU Standard Contractual Clauses. Where Applicable Data Protection Law requires an appropriate safeguard under Chapter V GDPR for the transfer of Personal Data from the EU/EEA to LetLoose, the SCCs (Module Two, Controller-to-Processor) are incorporated into this DPA by reference and form part of it, completed as follows:
- (a) Clause 7 (docking clause) applies;
- (b) in Clause 9 (use of sub-processors), Option 2 (general written authorisation) applies, with the notice period and process set out in Clause 5 of this DPA (and in any event a minimum of thirty (30) days' advance notice);
- (c) in Clause 11 (redress), the optional independent-dispute-resolution language does not apply;
- (d) in Clause 17 (governing law), the SCCs are governed by the law of the Republic of Ireland, being the law of an EU member state that allows for third-party-beneficiary rights;
- (e) in Clause 18 (choice of forum and jurisdiction), disputes are resolved before the courts of the Republic of Ireland;
- (f) Annex I to the SCCs is populated by Annex I to this DPA; Annex II to the SCCs is populated by Annex II to this DPA; and the list of Sub-processors in Annex III to this DPA serves as the Sub-processor information for the purposes of the SCCs.
The Parties have selected Irish law and the Irish courts for the SCCs as a single, consistent governing law and forum for all data exporters under this DPA, irrespective of the member state in which a given data exporter is established. This selection does not affect the identification of the competent Supervisory Authority under Annex I.C, which is determined in accordance with Clause 13(a) of the SCCs as set out in that Annex.
8.3. UK transfers. Where Personal Data is transferred from the United Kingdom, the UK Addendum applies to and amends the SCCs as set out in that Addendum. For the purposes of the Addendum: the SCCs as completed in Clause 8.2 are the “Approved EU SCCs”; Tables 1 to 3 are populated by the corresponding Annexes of this DPA; and in Table 4, the party that may end the Addendum when the Approved Addendum changes is the data importer. For the purposes of Table 2 of the Addendum, the “Addendum EU SCCs” are the SCCs incorporated by Clause 8.2 — namely Module Two (Controller-to-Processor) with the docking clause (Clause 7) and Clause 9 Option 2 (general written authorisation) enabled and the Clause 17 (governing law) and Clause 18 (forum) selections made in Clause 8.2.
8.4. South African law (POPIA) — inbound and onward transfers. On the South African side, the transborder flow of Personal Data is governed by s72 of POPIA. The Parties acknowledge that the safeguards in this Clause 8, together with the obligations in this DPA, are intended to ensure that the recipient of the Personal Data is subject to a law, binding corporate rules or binding agreement providing an adequate level of protection consistent with POPIA. In addition, for any onward transfer of Personal Data from South Africa to a Sub-processor located outside South Africa — including Resend (United States) and Vercel and Google (global infrastructure) — LetLoose ensures a lawful basis under s72(1) POPIA. In particular, LetLoose relies on s72(1)(a) POPIA: each such Sub-processor is bound by a written agreement (as described in Clause 5.4) that imposes an adequate level of protection effectively upholding principles for the reasonable processing of the Personal Data substantially similar to the conditions for lawful processing under POPIA, including provisions substantially similar to s72 in respect of further onward transfers. Where required, LetLoose will additionally rely on any other applicable ground in s72(1) POPIA, including that the transfer is necessary for the performance of the contract between the Customer and LetLoose, or for the conclusion or performance of a contract concluded in the interest of the Data Subject.
8.5. Conflict and updates. In the event of any conflict between the SCCs (and, where applicable, the UK Addendum) and the remainder of this DPA or the Terms, the SCCs (as amended by the UK Addendum) prevail in respect of the international transfer of Personal Data to which they apply. If the relevant transfer mechanism is invalidated, amended or replaced under Applicable Data Protection Law, the Parties will work in good faith to implement an alternative lawful transfer mechanism.
9.Audit Rights
9.1. LetLoose makes available to the Customer all information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, and, on the Customer's reasonable written request, allows for and contributes to audits, including inspections, of the processing activities covered by this DPA.
9.2. Audits are subject to the following safeguards: they take place on at least thirty (30) days' prior written notice (except where Applicable Data Protection Law or a Supervisory Authority requires otherwise); no more than once in any twelve-month period (unless required by a Supervisory Authority, following a Personal Data Breach, or where the Customer reasonably believes LetLoose is in material breach of this DPA); during normal business hours; in a manner that does not unreasonably disrupt LetLoose's operations or compromise the security or confidentiality of other customers' data; and subject to confidentiality obligations.
9.3. Where available, LetLoose may, in the first instance, seek to satisfy an audit request by providing relevant certifications, independent third-party audit reports or summaries, and written responses to a reasonable security questionnaire. However, where such documentation does not exist or is insufficient to demonstrate compliance, following a Personal Data Breach, or where a Supervisory Authority requires it, the Customer retains the right to conduct a full inspection of the relevant processing activities, by itself or by an independent auditor mandated by the Customer (acting under an obligation of confidentiality), notwithstanding the frequency and notice limits in Clause 9.2. The obligation in Clause 9.1 to make available all information necessary to demonstrate compliance applies regardless of whether any third-party certification or audit report exists.
10.Return and Deletion of Personal Data
10.1. On termination or expiry of the Service, the Customer has a window of thirty (30) days (as provided in section 13 of the Terms) during which it may export Customer Data from the Service.
10.2. After the expiry of that export window, LetLoose deletes or anonymises the Personal Data it processes on behalf of the Customer, and deletes existing copies, including from active systems and from backups. Deletion or anonymisation from active systems is completed within ninety (90) days (consistent with the Privacy Policy). Personal Data contained in backups is fully purged no later than ninety (90) days, or, if later, no later than the completion of the next documented backup-rotation cycle, which shall not exceed one hundred and eighty (180) days. Pending such purge, backups containing the Personal Data are isolated, are not restored to or accessed in live systems, and are used for no purpose other than disaster recovery, and remain subject to the confidentiality and security obligations of this DPA.
10.3. Statutory-retention carve-out. LetLoose may retain Personal Data to the extent, and for the period, required by Applicable Data Protection Law — for example records required for tax and accounting purposes (typically retained for approximately seven (7) years, and up to ten (10) years in some countries). Personal Data so retained remains subject to the confidentiality and security obligations of this DPA and is processed only for the purpose, and for the duration, of the applicable legal requirement.
11.Liability
11.1. Subject to Clauses 11.2 and 11.3, each Party's liability arising out of or related to this DPA, whether in contract, delict/tort or under any other theory of liability, is subject to the limitations and exclusions of liability set out in the Terms (section 11). In particular, the aggregate liability of LetLoose to the Customer is capped at the greater of (i) the fees paid or payable by the Customer for the Service in the twelve (12) months preceding the event giving rise to the claim, or (ii) one hundred euros (EUR 100).
11.2. The cap and exclusions in Clause 11.1 do not apply to, and nothing in this DPA or the Terms limits or excludes, the following liabilities of either Party: (a) any liability that cannot be limited or excluded under Applicable Data Protection Law; (b) any liability of LetLoose to the Customer (data exporter) or to Data Subjects under the liability provisions of the SCCs, including Clause 12 of the SCCs, which liability is uncapped to the extent the SCCs so require and prevails over Clause 11.1 as between the Parties; (c) any liability owed directly to Data Subjects, including as third-party beneficiaries under the SCCs; and (d) any civil liability to Data Subjects under s99 POPIA and any administrative fine, penalty or enforcement action imposed by the Information Regulator or any other Supervisory Authority, none of which may be contracted out of.
11.3. For the avoidance of doubt, where the SCCs apply, their liability provisions govern as between the Parties and in respect of Data Subjects' rights notwithstanding the cap in Clause 11.1, and Clause 11.2 prevails over Clause 11.1 in respect of all liability described in Clause 11.2.
12.Term, Termination and Order of Precedence
12.1. Term. This DPA takes effect when the Customer accepts the Terms (into which it is incorporated) and begins using the Service, and continues for as long as LetLoose processes Personal Data on the Customer's behalf, after which the obligations that by their nature should survive (including Clauses 10 and 11) continue to apply.
12.2. Order of precedence. This DPA governs the processing of Personal Data and, to the extent of any conflict on that subject matter, prevails over the Terms (consistent with section 15 of the Terms, under which the DPA governs the processing of personal data). In respect of the international transfer of Personal Data to which they apply, the SCCs (as amended by any UK Addendum) prevail over this DPA and the Terms. Subject to the foregoing, the Terms remain in full force and effect.
13.Governing Law and Contact
13.1. Governing law. This DPA and any dispute arising out of or in connection with it (other than the incorporated SCCs) are governed by the laws of the Republic of South Africa, consistent with section 14 of the Terms, and the Parties submit to the exclusive jurisdiction of the South African courts. The incorporated SCCs are governed by the law, and subject to the forum, specified within those clauses (as completed in Clause 8.2), as required by EU law.
13.2. Contact. All notices and requests under this DPA relating to data protection may be directed to LetLoose at privacy@letloose.run and to the Customer at the contact details associated with its account.
14.How This DPA Is Accepted
This DPA is incorporated by reference into the Terms. By accepting the Terms and using the Service as a business customer, the Customer agrees to this DPA. This satisfies the requirement under Article 28(9) GDPR (and s21 POPIA) that the agreement be in writing, including in electronic form, and no separate signature is required for this DPA to be binding.
Business customers who require a counter-signed copy of this DPA — for example for their own procurement or audit records — may request one at privacy@letloose.run, and LetLoose will provide an executable version for signature by both Parties.
Annex I — Description of Processing and Transfer
A. List of Parties
Data exporter (Controller):
- Identity: The Customer — the business that signed up for LetLoose, and its authorised users, as identified in the Customer's LetLoose account.
- Contact details: As set out in the Customer's account record.
- Role: Controller (responsible party).
Data importer (Processor):
- Identity: Future Point Consult (Pty) Ltd, trading as “LetLoose”.
- Address: 298 Glenwood Rd, Lynnwood Park, Pretoria, 0081, South Africa.
- Contact details: privacy@letloose.run.
- Role: Processor (operator).
B. Description of the Transfer / Processing
Categories of Data Subjects whose Personal Data is processed:
- The Customer's team members and staff (including owners, managers, cleaners and service providers); and
- The Customer's guests, vendors and property owners.
Categories of Personal Data processed:
- Account and identity data: name, email address, phone number, avatar, hashed password or Google identifier, and organisation membership/role;
- Contact data: vendor, owner and guest name, company, email, phone, postal address and tax number;
- Guest booking details: name, email, phone, party size, stay dates and amounts;
- Property information;
- Financial and operational records: bookings, invoices, expenses, payment requests, owner statements, monetary amounts, tax/VAT numbers and payment references;
- Uploaded files: expense receipts, task photos, profile avatars and property images;
- Technical and usage data: IP address, browser/device information, server logs, and authentication-session cookies / local storage.
Special categories of Personal Data: None. No special-category (GDPR Article 9) data, and no special personal information (s26 POPIA), is intended, required or to be processed under this DPA. If such data is nonetheless submitted, Clause 2.5 applies.
Frequency of the transfer: Continuous, for the duration of the provision of the Service.
Nature and purpose of the processing: Hosting, storage, transmission, and operation of a rental-property operations platform — including managing properties, bookings, contacts, expenses, invoices, payment requests, budget rules, maintenance quotes, cleaning tasks and owner statements — together with authentication, transactional email delivery, security, support and maintenance of the Service, in each case on the Customer's documented instructions.
Duration of the processing: For the term of the Customer's use of the Service, followed by deletion or anonymisation in accordance with Clause 10, subject to the statutory-retention carve-out.
Retention period: Personal Data is retained for the duration of the Service and then deleted or anonymised after the 30-day export window (within 90 days for active systems, and for backups no later than 90 days or the next documented backup-rotation cycle not exceeding 180 days, as set out in Clause 10.2), except records subject to statutory retention (e.g. tax/accounting records, typically retained for approximately seven (7) years, and up to ten (10) years in some countries).
For transfers to Sub-processors: The subject matter, nature, duration and purpose of processing by Sub-processors are as set out in Annex III.
C. Competent Supervisory Authority
- For processing subject to the GDPR, the competent Supervisory Authority is the authority competent for the data exporter, determined in accordance with Clause 13(a) of the SCCs, namely: (i) where the data exporter is established in an EU/EEA Member State, the supervisory authority responsible for ensuring that exporter's compliance with the GDPR; (ii) where the data exporter is not established in an EU/EEA Member State but falls within Article 3(2) GDPR and has appointed an Article 27 representative, the supervisory authority of the Member State in which that representative is established; and (iii) where the data exporter is not so established and has not appointed a representative, a supervisory authority of a Member State in which the affected Data Subjects are located. A business customer that needs a specific competent authority recorded for it may request a counter-signed copy under Clause 14. The choice of Irish law and forum for the SCCs in Clause 8.2 does not alter this identification.
- For processing subject to the UK GDPR, the competent authority is the UK Information Commissioner's Office (ICO).
- For processing subject to POPIA, the competent authority is the Information Regulator (South Africa).
Annex II — Technical and Organisational Security Measures
LetLoose implements and maintains at least the following technical and organisational measures, in accordance with Article 32 GDPR and ss19 and 21 POPIA. These measures apply to all Personal Data actually processed under this DPA.
- Encryption in transit: All data transmitted between users and the Service is encrypted using HTTPS/TLS.
- Encryption at rest: Personal Data stored in the application database and file storage is encrypted at rest.
- Organisation-level data isolation: Row-Level Security (RLS) policies enforce strict logical isolation so that each organisation's data is accessible only within that organisation.
- Role-based access control: Access to data within the Service is governed by role-based access controls, limiting access according to each user's role and need to know.
- Access-controlled file storage: Expense receipts and task photos are stored in private storage buckets whose access policies restrict reading, uploading and deleting to authenticated members of the organisation to which the files belong. Profile avatars and property images are stored in buckets that are publicly readable via unguessable URLs (to allow the Service to display them efficiently); write access to those buckets is restricted to the relevant authenticated user or organisation.
- Confidentiality and least privilege: Access to Personal Data by LetLoose personnel and Sub-processors is restricted to those who require it to provide and support the Service, and is subject to confidentiality obligations that survive the end of the relevant person's role or engagement.
Operator security cycle (s19(2)–(3) POPIA). In addition to the measures above, LetLoose, as operator, will: (a) identify all reasonably foreseeable internal and external risks to the Personal Data in its possession or under its control; (b) establish and maintain appropriate safeguards against the risks identified; (c) regularly verify that the safeguards are effectively implemented; and (d) continually update the safeguards in response to new risks or identified deficiencies; in each case having due regard to generally accepted information security practices and procedures, whether industry-specific or otherwise.
These measures may be updated from time to time, provided that the overall level of security of the Service is not materially reduced.
Annex III — List of Sub-processors
The Customer authorises the following Sub-processors as at the date of this DPA:
| Sub-processor | Role / Purpose | Location / Hosting Region |
|---|---|---|
| Supabase | Application database, authentication, and encrypted file storage; primary data host | Ireland (AWS eu-west-1) |
| Vercel | Application hosting and global content-delivery network (CDN) | Global (CDN edge locations) |
| Resend | Transactional email delivery | United States / provider infrastructure |
| Google Sign-In / OAuth authentication, engaged only where a user chooses to authenticate with Google | Global / provider infrastructure |
Each Sub-processor is engaged under a written contract imposing data-protection obligations that are, in substance, equivalent to those in this DPA, including the s19 POPIA security-maintenance duty and an immediate Personal Data Breach / security-compromise notification duty (Clause 5.4). For onward transfers of Personal Data from South Africa to Sub-processors located outside South Africa (Resend; Vercel; Google), LetLoose relies on a lawful basis under s72(1) POPIA as set out in Clause 8.4.
LetLoose will provide at least thirty (30) days' advance written notice of any addition or replacement of a Sub-processor in accordance with Clause 5.3, and the Customer may object on reasonable, data-protection-related grounds.